Appeals Court Lets Pentagon Keep Blacklisting Anthropic Over Claude Weapon and Surveillance Limits
A 2-1 DC Circuit panel upheld the Pentagon's supply-chain risk label on Anthropic after it refused to drop Claude's limits on autonomous weapons and mass surveillance.

Anthropic told the Pentagon that Claude would not help build fully autonomous killing machines or run mass surveillance on Americans. The Pentagon responded by branding the company a supply-chain risk. On September 25, a federal appeals court said the government was allowed to do that.
A divided panel of the US Court of Appeals for the DC Circuit ruled 2-1 to uphold the designation, with Judges Gregory Katsas and Neomi Rao in the majority and Judge Karen Henderson dissenting. The label blocks the military from using Claude and bars defense contractors from using Anthropic products in their Pentagon work.
The fight started over contract language. The Department of Defense wanted Anthropic to accept an "all lawful uses" term. Anthropic refused and kept two hard lines in place: no fully autonomous lethal weapons and no mass domestic surveillance. According to the court's account, Claude's built-in restrictions stopped government tasks more than once, and a dispute flared over its use in an ongoing overseas military operation.
Why the statute mattered
The government used 41 USC 4713, part of the Federal Acquisition Supply Chain Security Act. The majority read that law as requiring no showing of bad motive and no link to a foreign adversary. As Reason's Volokh Conspiracy noted, the court framed the designation as the result of Anthropic refusing contract terms, not punishment for its speech.
That is the quiet detail with the biggest consequences. Last month, Northern District of California Judge Rita Lin found a parallel designation under a different law, 10 USC 3252, unlawful, a ruling we covered when a judge first called the blacklist illegal. Friday's decision does not overturn that one. The government simply won on the other track, and the two statutes now point in opposite directions.
The majority also leaned into the military's view of risk. Katsas wrote about the danger of AI that is overly constrained in combat, a framing that sits awkwardly next to the worry that has driven Anthropic's limits in the first place: models hallucinating lethal targets.
What happens next
The court delayed its decision from taking effect so Anthropic can ask for panel rehearing, a full en banc review, or go to the Supreme Court. The same DC Circuit had already denied Anthropic an emergency stay back in April, so the odds at home look thin.
Anthropic told CNBC it respectfully disagrees with the ruling, pointed to the California decision, and said it is weighing further review.
None of this amounts to a finding that Anthropic behaved like a hostile adversary, and it is not the final word. It does mean that, for now, an AI company that keeps its own red lines on weapons can be shut out of the defense market for it, a question that is only getting louder as Washington leans on OpenAI and Anthropic over how their models get used.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free