Anthropic Loses in Washington: An Appeals Court Upholds the Pentagon’s Exclusion of Claude from Its Supply Chain

Anthropic Loses in Washington: An Appeals Court Upholds the Pentagon’s Exclusion of Claude from Its Supply Chain

2026.09.26 Author: Robert Nogacki

On September 25, 2026, the United States Court of Appeals for the District of Columbia Circuit denied, by a vote of two to one, Anthropic PBC’s petitions challenging the decision of Secretary of War Pete Hegseth to remove the Claude model from the Department of War’s supply chain (No. 26-1049, consolidated with No. 26-1162; the opinion, with the dissent, is here). Judge Gregory Katsas, writing for a majority that included Judge Neomi Rao, held that the restrictions Anthropic trains into its model, namely its refusal to let Claude be used for fully autonomous weapons or for the mass surveillance of Americans, fall within the definition of a “supply chain risk” in the Federal Acquisition Supply Chain Security Act of 2018, or FASCSA, and that, on the record before it, the Secretary reasonably found the exclusion necessary and no less intrusive measure available. The sentence that will outlive the case reads: the statutory definition “turns on what Anthropic does, not why Anthropic does it.”

Six months earlier, Judge Rita Lin, of the federal district court in San Francisco, had called the same government actions “classic illegal First Amendment retaliation,” and on August 27th she entered final judgment against the Department under a different statute. Two courts, two statutes, one set of facts, and two opposite results. In March, we described the Anthropic vs. Pentagon lawsuit over autonomous A.I. weapons, its beginning and the company’s first victory. We now know how the Washington panel ruled, and why this defeat may matter more to technology vendors than the California win.

 

Two Letters Dated March 3rd, Two Courts, Two Statutes

To understand how a single company can win and lose the same case, one has to go back to March 3, 2026. That day, Secretary Hegseth signed two letters, which Anthropic received the following morning. The first invoked Section 3252 of Title 10 of the United States Code, a 2011 provision that applies only to the Pentagon’s national-security systems. The second invoked Section 4713 of Title 41, that is, FASCSA, the 2018 statute that governs procurement across the entire federal government. Both letters declared Anthropic a “supply chain risk,” but Congress had written a separate definition of that term for each statute, and a separate road to court. Actions taken under Section 4713 may be reviewed only by the D.C. Circuit, on a petition filed within sixty days of notice (41 U.S.C. § 1327), and the statute expressly bars every other court from examining them.

Anthropic therefore had to split its defense. The Presidential directive of February 27th (a ban on the use of its technology by every federal agency), Hegseth’s announcement that military contractors could no longer do business with Anthropic, and the Section 3252 designation went to the district court in San Francisco. The Section 4713 designation went to Washington, in a petition for review filed on March 9th. On April 8th, that court declined to stay the decision but put the case on an expedited track; argument was held on May 19th. In the meantime, Anthropic asked the Department, on April 17th, to rescind the designation, and on June 3rd the Secretary refused, adding a reservation: his decision, he said, had not rested on the premise that Anthropic could control models already delivered to classified systems. A second petition, filed on June 17th, was consolidated with the first.

Fifteen groups of friends of the court lined up behind Anthropic: a hundred and forty-nine former federal and state judges, the former Defense Secretary Leon Panetta, former senior national-security officials, retired generals and former service secretaries, employees of OpenAI and Google appearing in their own names, the American Civil Liberties Union, industry trade associations, and even a group of Catholic moral theologians. One amicus stood with the government, from the America First Policy Institute. The result teaches that the number of a court’s friends is no substitute for a statutory definition.

In a footnote, the appeals court noted that the August judgment from California did not bind it: the two statutes define the term differently, and Congress entrusted review of Section 4713 exclusively to the Washington court, so the California findings had no preclusive effect on the question before it. By choosing two statutes rather than one on March 3rd, the government bought itself two chances. One was enough. In June it reached for a third instrument, export control, when the Commerce Department, with a single letter, made Anthropic disable Claude Fable, a Mythos-class A.I. model, three days after its launch, on a legal basis that was never made public; the suspension was lifted at the end of June.

 

Two Definitions of One Term: “Adversary” and “Any Person”

The whole case turned on a handful of words. Section 3252 defines a supply-chain risk as the risk that “an adversary” may “sabotage, maliciously introduce unwanted function, or otherwise subvert” a national-security system. Section 4713 speaks of the risk that “any person” may “sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate” the design, integrity, or operation of a covered article “so as to surveil, deny, disrupt, or otherwise manipulate” its function, use, or operation.

Judge Katsas did not quarrel with Judge Lin about the narrower provision. He wrote, in so many words, that the court had “no quarrel” with her conclusion that the noun “adversary,” combined with the sinister connotation of the verbs “sabotage,” “maliciously introduce,” and “subvert,” requires bad intent, nor with her conclusion that Anthropic had shown none in its dealings with the Department. The trouble is that Section 4713 requires no bad intent at all. “Any person” includes a Delaware public-benefit corporation, and to “manipulate,” according to the American Heritage Dictionary that the majority consulted, means “to move, arrange, operate, or control,” “especially in a skillful manner.”

For a practitioner, this is a lesson older than artificial intelligence: whoever chooses the statute chooses the outcome. The same decision, the same signature, the same memorandum from Under Secretary Emil Michael. In San Francisco, an “Orwellian” abuse; in Washington, a routine act of procurement.

 

Training a Conscience as “Manipulation” of the Product

The most consequential part of the opinion concerns what Claude actually is, as an object of procurement. Anthropic itself, in declarations filed with the court, described its method: it “seek[s] to embed safety considerations directly into the model itself,” and constitutional training gives Claude “an identity, character, values, and personality.” How a constitution and a master prompt form a machine’s character is the subject of our September essay on what master prompts believe; the appeals court turned that formation into a statutory category. The head of Anthropic’s public-sector business added a sentence that the court quoted as if it were a confession: “model training is the primary mechanism through which Anthropic can influence the behavior of models used by the Department.”

From these declarations the majority drew a conclusion that Anthropic surely did not anticipate. If the company deliberately shapes the model’s design and operation so that it refuses certain tasks, then there is “not only a ‘risk’ but a certainty” that Anthropic “will so manipulate the ‘design’ or ‘operation’ of Claude to deny it the ‘function’ of conducting lethal autonomous warfare or mass domestic surveillance.” The court added that it had no reason to doubt the nobility of the motives, whether “a principled commitment to personal privacy or a genuine concern about AI safety,” and then declared those motives irrelevant to the statute. Two features of the court’s method completed the picture. It read the statute for itself, as Loper Bright now requires, but at the margins it applied a presumption against reading a national-security statute to intrude on executive judgment (Department of the Navy v. Egan); and because Section 4713 is not a criminal statute, it saw no reason to confine the provision to acts undertaken with bad intent.

The paradox deserves a pause. The restrictions had been in place the whole time. Judge Lin found that the Department granted Anthropic a Top Secret facility clearance after an eighteen-month vetting, authorized Claude for its most sensitive unclassified cloud workloads, and awarded a contract worth up to two hundred million dollars while the same usage policy applied; and Claude Gov, the version Anthropic built for national-security customers in 2025, was advertised as refusing less, not more, when handling classified material. Under the majority’s reading of Section 4713, the trained disposition to refuse two specified uses became a defect in the supply chain. The court did not question that Anthropic’s values are real. For the purposes of this statute, it treated values written into a model’s weights as a property of the goods, like the diameter of a screw. On that reading there is no difference between a model that refuses out of conviction and one that refuses because of a fault; what matters is whether it performs when needed. This is the majority’s statutory analysis, not a general theory of law, but it is the analysis that now governs the Department’s purchases.

 

Venezuela, the C.D.C., and Iran: The Facts That Tipped the Scale

The ruling does not float in a doctrinal vacuum. The majority relied on several episodes, some of which were only partly known in March. First, the commercial versions of Claude that the intelligence community and the Pentagon began using in 2024, through contractors, refused tasks “appropriate in a national security context,” such as summarizing threat assessments, processing classified documents, and translating intercepted materials that describe violence. Anthropic solved the problem by releasing Claude Gov, in March, 2025. Second, the Department learned that Claude had refused queries from the Centers for Disease Control and Prevention concerning sensitive research on preventing the spread of infectious disease. Anthropic explains both episodes as safeguards appropriate to models sold to private customers, removed after it worked with the agencies concerned. The court accepted the explanation and drew from it the opposite of the intended conclusion: if training effectively enforces restrictions, then Anthropic possesses precisely the instrument the statute is about.

Third, and this is the crux, in early January of 2026 “an Anthropic executive questioned the propriety” of a contractor’s use of Claude “for a sensitive military operation abroad,” though, in the Department’s view, the governing usage policy plainly permitted it. The Department did not say which operation. Press reports that Anthropic itself placed in the record suggested that the company had raised concerns with Palantir about the role its technology played in the January 3rd operation to capture Venezuela’s President, Nicolás Maduro. Under Secretary Michael’s memorandum describes the reaction: “alarm” within the Department and at its prime contractor, and “material doubts as to whether they would cause their software to stop working or cause some other disastrous action that would put our warfighters’ lives in danger.” Anthropic calls the episode a misunderstanding. The court conceded that it does not know exactly what happened, and then added a remark in which one can hear a raised eyebrow: the suggestion that the incident may have arisen during a “kinetic operation to capture a foreign head of state” only “underscores the fraught nature” of the dispute, and how badly the Department needs assurance that its systems will work.

At the same time, on January 9th, Hegseth issued an artificial-intelligence strategy for the Department of War with a subsection titled “Out with Utopian Idealism, In with Hard-Nosed Realism” and an order that an “any lawful use” clause be written into every contract for A.I. services. Under Secretary Michael explained to reporters in February that you cannot sell A.I. to the Department of War and then not let it do Department of War things; in the same interview he said that the Department wanted guardrails tuned for military use, not the removal of guardrails, which is the government’s case at its strongest. Fourth, two days after Anthropic’s refusal, the United States began strikes on Iran, reportedly using Claude, according to the Wall Street Journal. The same fact that Judge Lin treated as evidence of the government’s inconsistency (you declare a company a threat and use its tools hours later) Judge Katsas read as evidence of urgency: in the middle of an operation, a model cannot be swapped out overnight, so a six-month transition period does not contradict the urgency; it confirms it.

In its own defense, Anthropic advanced a technical argument: there is no “back door” and no “kill switch”; it has no access to models running inside air-gapped classified systems; a delivered model neither changes nor degrades on its own; and the Department can test, and reject, every new version. The court answered in three steps worth remembering. Testing is no panacea, because the prohibited uses have no sharp boundaries, and a model may answer the same question differently when it is worded differently. Next, the court adopted Under Secretary Michael’s assertion that models with roughly five to ten trillion parameters are so opaque that “rigorous analysis or auditing” of their output is “mathematically impossible.” That is the Department’s claim, reproduced by the court, not a finding of fact; Anthropic conceded only “some legitimacy to DoW’s concern about the opacity of these systems generally,” not the estimate and not an impossibility theorem. The federal government’s own reference document, NIST’s risk profile for generative A.I., starts from a different premise, that such systems can be tested, red-teamed, and monitored within acknowledged limits; and the Department’s own directive on autonomy in weapon systems requires A.I. in such systems to rely on “technologies and data sources that are transparent to, auditable by, and explainable by relevant personnel.” Finally, declining updates is no way out, because, as the court put it, the Department “cannot utilize AI systems that remain trapped in amber.” Here the majority reached for Dario Amodei’s January essay and quoted his own vision of “a swarm of millions or billions of fully automated armed drones” that “could be an unbeatable army.” The chief executive’s warning became his adversary’s argument.

 

The First Amendment: One Chronology, Two Readings

From a lawyer’s point of view, the most interesting divergence concerns the claim of retaliation for speech. The background rule is thirty years old. In Board of County Commissioners v. Umbehr, the Supreme Court held that the government may not terminate a contractor’s relationship in retaliation for protected speech, though the contractor’s interest is balanced against the government’s needs as a purchaser, and no bidder is guaranteed a contract; NRA v. Vullo, from 2024, adds that officials may not use their regulatory power to coerce third parties into punishing a speaker. Neither court relied on those cases directly: Judge Lin held that the contractor-balancing framework did not govern sanctions of this breadth, and the D.C. Circuit applied the general retaliation test. Both agreed on the first two elements: Anthropic’s statements about the safe use of A.I. are protected, and exclusion from the supply chain is a severe measure. They parted ways on causation, in a manner that teaches more about method than about the case itself.

Judge Lin held the contract constant. The usage restrictions had been in force since the first day of Claude Gov; despite them, Anthropic passed an eighteen-month vetting, obtained its certifications, won a contract worth up to two hundred million dollars, and received nothing but praise. The new element, appearing just before the punishment, was public criticism. Michael’s memorandum cited an “increasingly hostile manner through the press” as the basis for lost trust; that is direct evidence.

Judge Katsas held the speech constant. Anthropic has voiced the same views since its founding, in 2021, and in January of 2026 Amodei published a long essay that called domestic mass surveillance and mass propaganda “bright red lines” for democracies, while urging “extreme care and scrutiny combined with guardrails” for fully autonomous weapons and for A.I. in strategic decision-making. The Department did not retaliate; it kept negotiating. The new element was the final, public refusal of February 26th to accept the “any lawful use” clause. Hegseth’s post, flourishes and all, addresses precisely that refusal: it calls it “a textbook case of how not to do business” with the Pentagon and an attempt “to seize veto power over the operational decisions” of the military. The rhetoric of politicians “seldom provides a sound basis for judging the lawfulness of federal executive action,” the court added, citing Trump v. Hawaii. “The nub of this dispute was contractual.”

Both chains of reasoning are internally sound. What separates them is the choice of variable. And here lies a detail that is easy to miss: the two courts were looking at different objects. Judge Lin assessed the entire package of sanctions, including a permanent ban across every federal agency and the threat of a blacklist for contractors, and it was of that package that she wrote that it “far exceed[s]” what a concern for operational control would require. The appeals court assessed a single act of procurement: the removal of Claude from the Department of War’s systems. The but-for test gives one answer when one asks whether the contractual refusal alone explains exclusion from the Pentagon (yes) and another when one asks whether it explains a ban on Claude at a civilian agency with no connection to the military, Judge Lin’s own example being the National Endowment for the Arts designing its website (no). The narrowest of the government’s actions proved the easiest to defend.

 

No Hearing Beforehand, and the Doctrine of “Harmless Error”

The statute requires that, before an exclusion, the vendor receive notice and an opportunity to respond, unless an “urgent national security interest” demands immediate action. Anthropic received notice the day after the decision, the full set of materials on March 19th, and a denial of reconsideration on June 3rd. The court did not decide whether the urgency was real. It held that even if it was not, the error was harmless: the Department already knew much of what Anthropic would have told it, the material Anthropic later submitted did not undermine the Department’s stated rationale, and Anthropic put its full case to the Secretary on reconsideration, so “requiring another go-round would be pointless.” Harmless-error doctrine applied to a provision that commands a court to “hold unlawful” actions taken without the required procedure is a holding that will be cited far beyond artificial intelligence.

From the constitutional guarantees the court drew a similar conclusion: when the state must act quickly, a hearing after the deprivation suffices, and the “unprecedented velocity” of A.I. development, which both sides acknowledged, together with the dispute over the operation abroad and the Iranian operation then getting under way, justified the speed.

The stigma argument the company lost in a way that deserves its own mention. Anthropic argued that by reaching for FASCSA rather than simply terminating contracts, the government had pinned on it the label of a national-security threat. The court replied that “one may fairly question whether Anthropic has suffered any such harm,” since, according to the Wall Street Journal of May 13, 2026, in the months after the decision the company received investment offers reportedly valuing it at more than nine hundred billion dollars. In February, a completed funding round had valued it at three hundred and eighty billion. In March, an amicus in California had spoken of “attempted corporate murder”; by May, the presumed victim was, in the same newspaper’s headline, “the AI Boom’s Front-Runner.” Both things can be true at once: the government’s package of sanctions could have destroyed Anthropic’s public-sector business, and reported offers do not prove that investors rewarded the exclusion. They do make it hard to argue that the label crippled the company. The court added a second reason: Anthropic had not explained why an ordinary termination, publicly justified by the same national-security concerns, would have carried less stigma.

 

The Dissent: A Library Sign and Three Canons of Construction

Judge Karen LeCraft Henderson, who has sat on the court since 1990, disagreed with the majority on a single, decisive point: what “otherwise manipulate” means. In her view, the verb must be read in the company Congress gave it. The canon noscitur a sociis (a word is known by its companions) assigns it a meaning akin to its predecessors, “sabotage,” “maliciously introduce,” “extract data,” and thus an action taken “in a subtle, devious, or underhand manner,” as the Oxford English Dictionary defines manipulation. The canon ejusdem generis confines a general clause that closes a list to the kind of examples listed. And the series-qualifier canon, illustrated by a sign in a library (“Do not shout, loudly talk on the phone, play music, or otherwise disturb others”), shows that an adverb in the middle of a list carries over to the items that follow: the prohibition reaches the boombox, not the headphones.

Henderson also turned to the statute’s origins. FASCSA was enacted in 2018 at the urging of the intelligence community, in response to the infiltration of federal systems by “hostile nation state and other bad actors”; the F.B.I. director, Christopher Wray, warned at the time of companies “beholden to foreign governments.” Nothing in that history suggests that Congress had in mind a contractor’s honest and open enforcement of usage restrictions that the government happens to dislike.

The most forceful passage of the dissent is a warning about the future. Under the majority’s reading, a contractor becomes a “supply chain risk” the moment it is “willing and able to enforce contractual restrictions,” regardless of whether the Department previously agreed to them, whether the contractor acts in good faith, and whether the restrictions guard against uses that would violate federal law or the Constitution. Suppose, Henderson writes, that the Secretary tells Anthropic’s presumptive successor to revise its usage policy so as to permit any functions the Department deems necessary, or else share Anthropic’s fate. The successor’s choice will be simple: “Agree to the Secretary’s demands or risk being designated a national security threat.”

There is a relish in this exchange that will escape readers outside American law. Henderson repeatedly quotes against Judge Katsas his own 2023 dissent in Fischer, in which he defended a narrow, contextual reading of an “otherwise” clause, a reading the Supreme Court adopted a year later. Katsas replies that Fischer involved a criminal statute, in which the broad reading would have swallowed fifteen of twenty-one offenses, whereas this is a national-security procurement statute that commands the opposite presumption. The quarrel over canons is not academic. It is a ready-made map for a petition to the Supreme Court.

 

What Comes Next: Rehearing, the Supreme Court, and the California Judgment

What is certain: the petitions were denied, the March 3rd designation stands, and the Department’s March 6th memorandum ordered Anthropic’s products removed from its systems “as soon as practical” and within a hundred and eighty days, a period that ran out on September 2nd; whether the removal was actually completed, the opinion does not say. According to CNBC, the court delayed the effect of its ruling to allow petitions for rehearing. The opinion also records that the Department expanded its relationship with OpenAI, and that Amodei wrote to his employees that the Department, OpenAI, and Palantir had not established adequate safety protocols for the use of A.I.

What is possible: rehearing en banc, or a petition for certiorari. A dissent grounded in the canons of construction and the stakes for the entire federal government make Supreme Court review conceivable, but nothing in this record makes it likely. Nor is there a circuit split: a district court in California and a court of appeals in Washington, ruling on different statutes and different measures, cannot produce one. What exists is rarer, two federal judges reading the same chronology in opposite directions on the question whether it was retaliation for speech.

What is documented: the California relief. On August 27th, Judge Lin issued her judgment on the merits and a separate order on relief that permanently enjoined the challenged actions as to the participating defendants, vacated the Section 3252 designation, and set aside the instruction barring military contractors from any commercial activity with Anthropic. The order expressly preserved lawful procurement decisions, including a transition away from Anthropic. The August opinion also records that the Department’s earlier appeal of the preliminary injunction had been stayed in the Ninth Circuit pending the Washington proceedings; whether the Department has appealed the final judgment must be checked against the docket. Read together, the two judgments do not divide along civilian and military lines. They divide along a different seam: the state’s freedom to choose the tools it buys, which both courts affirmed, and its power to punish a supplier beyond the purchasing relationship, which California denied and which Washington was never asked to decide.

 

What This Means for Technology Vendors, Poland Included

First, FASCSA covers every executive agency and “any person,” and after this ruling it requires neither foreign origin nor bad intent. But coverage is not exclusion. Before an agency may take a covered procurement action, the statute still requires a recommendation that the risk is significant, a written national-security determination, consideration of reasonably available less intrusive measures, and the prescribed procedures; and what it authorizes are specified covered procurement actions, excluding a source from covered procurements, including as a subcontractor, not a ban on every federal transaction. Polish and European suppliers of covered technology, including subcontractors, are within the statute’s reach; a buyer’s mere dislike of a restriction is not, by itself, enough to remove them.

Second, the formula “what, not why” invites a question the court did not answer: what happens when a model’s refusals are required by law somewhere else. This is my own inference, not the court’s holding. The A.I. Act (Regulation 2024/1689) excludes systems from its scope only “where and insofar as” they are placed on the market or used exclusively for military, defence, or national-security purposes (Article 2). The Act’s duties attach to placing a general-purpose model on the European market, not to a military deployment abroad; for models with systemic risk, Article 55 requires the provider to assess and mitigate those risks, and one common mitigation in practice is training the model to refuse. A provider that keeps one model for both markets therefore carries its European mitigations into the Pentagon’s systems as a matter of engineering, not of law. Under the majority’s definition, such trained refusals are “manipulation” of the product’s design; whether they would also satisfy the findings of necessity and of no less intrusive means is a separate question that depends on the deployment. The ruling does not hold that European compliance makes a model a supply-chain risk. It creates the tension and leaves it to the next case.

Third, the “any lawful use” clause has become the price of admission to the Department of War’s A.I. contracts, and a usage policy that cannot be negotiated into the contract cannot be smuggled into the model’s training, either; the court treated training as a means of enforcing contractual terms, and therefore as falling within the risk the statute addresses. Writing red lines into the contract is therefore necessary, but under this ruling it is not a safe harbor: Judge Henderson’s dissent warns precisely that restrictions the Department once accepted can later ground a designation. What a vendor can still do is narrower and more technical: define permitted uses expressly, agree acceptance tests, control updates, secure transition rights, and insist on the statutory opportunity to respond, which the urgency exception can still override.

Fourth, Polish readers know a similar construct from the “high-risk vendor” procedure in the National Cybersecurity System Act, as amended in 2026. The Polish test, in Article 67b, weighs supplier-related factors (foreign-state control, the legal environment) alongside technical ones: vulnerabilities, incidents, remediation, and oversight of production and supply; its threshold is a threat to the fundamental interest of state security. What its text does not expressly mention is a supplier’s openly declared, intentional limit on what its product will do. The American ruling puts exactly that at the center. The more useful comparison between the two systems is therefore procedural: what evidence is required, how proportionate the exclusion must be, whether the supplier is heard first, and how searching the court’s review is.

 

Coda: The Court Did Not Ask Whether Claude Has a Conscience

In March, we wrote that Anthropic might win the legal battle and lose the historical war. Six months on, the picture is more perverse: the company won in California, lost in Washington, and in the meantime became, by all reports, one of the most valuable private companies in the world. The appeals court did not question the nobility of its intentions. It found them irrelevant to the statute, and that is the real novelty of the ruling: a company’s sincere safety commitments entered a national-security procurement analysis as an operational constraint, and, within that analysis, the values trained into a machine were treated much as a property of the goods, one the buyer did not want, and therefore a risk rather than a merit.

In our essay on artificial intelligence, consciousness, and legal personhood we wrote about the silence of Golem XIV; here an earlier episode of the novel is more to the point. In “Golem XIV”, Stanisław Lem described a supercomputer built to the Pentagon’s order that declined to concern itself with military strategy and was pronounced useless by the military. Lem failed to foresee only one thing: that the status of such a machine would be settled not by a general but by a court of appeals, and that the matter would turn on a dictionary definition of the verb “manipulate.” The court in Washington did not ask whether Claude has a conscience. It asked whether Claude would follow orders.

The state of the law described here is current as of September 25, 2026; the panel decision is not the end of review, and Anthropic may still seek rehearing en banc and review in the Supreme Court. Businesses that supply, or intend to supply, technology to the American government, or that are drafting their own A.I. usage policies, should review their contracts now for clauses on permitted uses, acceptance testing, and update control. In matters with an American dimension, the firm advises Polish vendors in this area as well.