A federal appeals court just told Anthropic that its own safety features are the reason it can’t sell AI to the Pentagon.
In a 2-1 decision handed down Friday, Sept 25, the US Court of Appeals in Washington, DC upheld the Defense Department’s blacklisting of the AI startup, siding with Defense Secretary Pete Hegseth in a fight that has now cost Anthropic billions of dollars in lost contracts and scrambled one of the most important commercial relationships in military AI.
The dispute began in February, when Hegseth demanded that Anthropic strip out safeguards built into Claude that block two uses: fully autonomous lethal weapons, and mass domestic surveillance of Americans. The company refused. In March, the Pentagon formally designated Anthropic a national security supply chain risk under the Federal Acquisition Supply Chain Security Act, canceling its military contracts and barring defense contractors from using its technology.
Anthropic sued, arguing the blacklisting was retaliation for its safety views. The court disagreed.
Why the court sided with the Pentagon’s Anthropic blacklisting
The majority opinion, written by Judge Gregory Katsas, accepted the Pentagon’s argument that Anthropic’s embedded restrictions were themselves an operational risk. His reasoning was blunt: a military commander can’t count on an AI system that might decide, mid-mission, to refuse an authorized command or shut down unexpectedly.
“The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail,” Katsas wrote.
The ruling doesn’t force Anthropic to change its models, and the majority was careful to say the court wasn’t creating a general obligation for companies to supply AI without limits. But it validated a reading of the law that other AI vendors are now studying closely: safeguards a supplier builds into its own model can be treated as supply-chain risk when they make the government uncertain the software will do what it’s told.
The dissent disagreed sharply. One of the three judges would have sided with Anthropic, though the full dissenting opinion hadn’t changed the outcome.
The Maduro operation that raised the alarm
The opinion revealed one of the moments that turned Pentagon leadership against Anthropic. According to the decision, an Anthropic executive had questioned the use of Claude by defense contractor Palantir during the military operation that captured Venezuelan president Nicolás Maduro on Jan 3.
That objection, Under Secretary of Defense Emil Michael said, “led to alarm” and “raised material doubts as to whether they would cause their software to stop working or cause some other disastrous action that would put our warfighters’ lives in danger.”
The military had been running Claude across a range of classified and sensitive systems. Anthropic insists it cannot alter models once delivered to the military. The court found otherwise: the company controls the behavior of each new version, and the military has to keep up to date with the latest releases.
Why this matters
This is the sharpest test yet of a question Silicon Valley has been ducking for years: who gets to write the guardrails on AI that the military uses — the company that built it, or the government that buys it?
Anthropic drew a line at autonomous killing machines and domestic mass surveillance. The Pentagon read that line as a liability. Now a federal court has agreed, at least for now, that the government can walk away from a vendor whose safety features it considers a mission risk.
The practical fallout is already massive. Anthropic says the blacklisting has cost it billions in lost business and hurt its reputation ahead of a widely anticipated IPO. There’s an irony the tech industry keeps pointing at: US intelligence agencies remain some of the heaviest daily users of Claude models, even as the Defense Department treats the company as a supply chain risk.
And the legal fight isn’t over. A separate battle is already running in parallel: in late August, a federal judge in San Francisco blocked a similar classification on different legal grounds, calling it unlawful retaliation tied to Anthropic’s safety positions. That split makes it likely this question climbs higher.
Anthropic said in a statement Friday that it respectfully disagrees with the ruling but remains confident in its position, and is considering its options — including asking the full appeals court to review the panel’s decision. The White House and the Department of Defense did not immediately respond to requests for comment.
What’s next
Watch two tracks. First, whether Anthropic seeks review by the full DC Circuit, which would keep the case alive deep into 2027. Second, how OpenAI and Google — both of which signed the Pentagon’s unrestricted-use contracts — treat this ruling as precedent. They accepted terms Anthropic wouldn’t.
The stakes go beyond one vendor. If embedded safeguards count as supply-chain risk, every AI company selling to the government now has to price in a choice: build the guardrails and risk losing the contract, or drop them and risk everything else.
FAQ
Why did the Pentagon blacklist Anthropic? The Pentagon designated Anthropic a national security supply chain risk in March 2026 after the startup refused Defense Secretary Pete Hegseth’s demand to remove Claude safeguards blocking fully autonomous lethal weapons and mass domestic surveillance of Americans.
What did the appeals court decide on Sept 25, 2026? The US Court of Appeals in Washington, DC ruled 2-1 that the blacklisting was reasonable, finding Anthropic’s embedded safeguards created uncertainty about whether its AI could refuse or disrupt authorized military missions.
How much has the blacklisting cost Anthropic? Anthropic says the designation has cost it billions of dollars in lost military contracts and damaged its reputation ahead of a highly anticipated IPO.
Can Anthropic still challenge the decision? Yes. Anthropic said it respectfully disagrees with the ruling but remains confident in its position, and is considering asking the full appeals court to review the three-judge panel’s decision.
Sources: Reuters (via The Straits Times), Channel News Asia, CNBC reporting as cited by AI Daily Post.