Regulation
D.C. Circuit Upholds Pentagon’s Supply-Chain Exclusion of Anthropic

The U.S. Court of Appeals for the District of Columbia Circuit on September 25, 2026 denied Anthropic’s petitions for review of the Department of War’s decision to exclude the company’s Claude models from its supply chain under the Federal Acquisition Supply Chain Security Act of 2018.
A per curiam judgment in Anthropic PBC v. United States Department of War ordered the consolidated petitions denied in accordance with the court’s opinion. Circuit Judge Katsas wrote the 43-page opinion for the court, and Circuit Judge Henderson filed an eight-page dissent. The panel, which also included Circuit Judge Rao, heard argument on May 19, 2026.
The Statute and the Exclusion
The Federal Acquisition Supply Chain Security Act of 2018 authorizes covered procurement actions, such as barring agency contracts with a particular supplier, once an agency head determines in writing that the action is necessary to protect national security by reducing supply chain risk and that less intrusive measures are not reasonably available. The statute defines supply chain risk as the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate covered information-technology products so as to surveil, deny, disrupt, or otherwise manipulate those products or the information they store or transmit. It channels judicial review exclusively to the D.C. Circuit on a petition filed within 60 days of notification.
The dispute involves the Department of Defense, which the opinion notes now calls itself the Department of War. On March 3, 2026, Secretary of War Pete Hegseth determined in writing that using Claude in Department systems presented a significant supply chain risk, that removing it was necessary to reduce that risk, that no less intrusive measures were reasonably available, and that an urgent national security interest required immediate action. The determination rested on a recommendation from senior officials built on a memorandum from Emil Michael, the Under Secretary for Research and Engineering, who cited Anthropic’s refusal to permit all lawful uses of Claude, its ability to alter system guardrails and model weights, and its questioning of the Department’s use of Claude in a sensitive military mission abroad. Notice went to Anthropic by a letter dated March 3, 2026 and emailed on March 4, 2026; it was effective immediately and gave the company 30 days to seek reconsideration.
On March 6, 2026, the Department’s Chief Information Officer ordered Anthropic products removed from Department systems as soon as practical and in any event within 180 days, and barred contractors from using them in work for the Department. The Department also moved to expand its contractual relationship with OpenAI. Anthropic petitioned for review on March 9, 2026 and sought a stay; the court denied the stay on April 8, 2026 while expediting merits review. Hegseth denied reconsideration on June 3, 2026, Anthropic filed a second petition on June 17, 2026, and the court consolidated the cases on June 24, 2026.
The Dispute Leading to the Determination
According to the opinion’s recitation of the record, Anthropic layers three kinds of restrictions on Claude: safety training embedded in the model itself, technical monitoring measures it began developing around mid-2025, and contractual usage-policy prohibitions. The company gradually permitted the Department to use Claude to design weapon systems, analyze foreign intelligence, and conduct offensive cyber operations, but it retained prohibitions on lethal autonomous warfare and mass surveillance of Americans.
Commercial Claude models used in classified systems during 2024 refused national-security tasks, and Anthropic responded by releasing a Claude Gov model in March 2025 alongside a government-specific addendum to its usage policy. In fall 2025, negotiations toward a direct contractual relationship stalled over the Department’s demand for permission to deploy Claude for all lawful uses. On January 9, 2026, Hegseth issued a Department AI strategy directing the agency to become an AI-first warfighting force and to write any-lawful-use language into AI contracts.
Around the same time, an Anthropic executive questioned a contractor’s use of Claude in a sensitive military operation abroad. The Department believed the governing usage policy clearly permitted the engagement, but the episode alarmed officials and raised material doubts about whether the software would perform as expected. Media reports Anthropic placed in the record tied the concern to Palantir Technologies, which analyzes data for the Department, and to the January 3, 2026 operation to capture Venezuela’s president, Nicolás Maduro. The Department had also learned that Claude refused queries from the Centers for Disease Control and Prevention about sensitive research on preventing the spread of infectious disease.
At a February 24, 2026 meeting, Hegseth praised Claude’s capabilities but demanded that Anthropic accept an all-lawful-uses term by February 27, 2026. Anthropic refused on February 26, 2026, and in a public statement quoted in the opinion, Chief Executive Officer Dario Amodei called mass domestic surveillance, although legal, “incompatible with democratic values,” adding that fully autonomous weapons could eventually prove critical to national defense but that AI was not yet reliable enough to power them. A day later, President Trump and Hegseth denounced the decision on social media, and the Secretary began the removal process.
The Court’s Holdings
The court held that the Secretary reasonably concluded removal was necessary. It pointed to undisputed evidence that Anthropic controls how Claude responds through training, that those restrictions had caused Claude to refuse legitimate government tasks, and that the dispute over the overseas operation left the Department uncertain whether Claude would perform as needed. The court rejected Anthropic’s responses that it retains no back door or remote kill switch and that the Department could test each new model before deployment, citing the opacity of models whose parameters number approximately 5 to 10 trillion per model, as a Department declaration stated, and the rapid pace of new model releases.
Applying the ordinary meaning of manipulate and deny in the statute’s definition, the majority rejected the narrowing constructions urged by Anthropic and the dissent, concluding that the definition turns on what a supplier does rather than why. The majority distinguished the Northern District of California’s August 27, 2026 decision setting aside a separate supply-chain-risk designation under a Defense Department statute that defines the risk in terms of an adversary, and it held that decision not preclusive, noting that Congress gave the D.C. Circuit exclusive review of procurement actions under the 2018 law.
The court upheld the finding that less intrusive measures were not reasonably available, holding that Anthropic’s one-sentence proposal to narrow any restriction to certain systems was unpreserved and that the Secretary’s clean break was a reasonable, fact-based national-security judgment. In response to Anthropic’s argument that the designation branded it a national-security threat, the opinion observed that rapid valuation increases since the determination had reportedly made the company one of the most valuable business concerns in the world, citing a Wall Street Journal report describing investment offers valuing Anthropic at more than $900 billion.
On urgency, the court applied the prejudicial-error rule and found no prejudice, because the Department had given Anthropic the determination and supporting materials by March 19, 2026, invited its opposition, and maintained the exclusion on June 3, 2026 after reviewing the company’s full submission.
The court rejected the due-process claim, holding that post-deprivation process sufficed given the need to move quickly, and noted that two days after Anthropic’s refusal the United States began offensive military operations in Iran, reportedly using Claude in connection with the strikes. It rejected the First Amendment retaliation claim for lack of causation, tracing a timeline in which the Department included Anthropic in a $200 million AI contract in July 2025 and continued negotiating after Amodei’s January 2026 essay calling for limits on AI-powered weapons, acting only after the contract talks collapsed. Hegseth’s February 27, 2026 post, the majority noted, described Anthropic’s behavior as a “textbook case of how not to do business” with the Pentagon and framed the dispute as contractual. Balancing the competing risks of overly constrained and unconstrained AI models, the court concluded, belongs to the President and the Secretary of War, and the Secretary exceeded no statutory or constitutional limits.
Judge Henderson’s Dissent
Henderson would have read the statute’s residual phrase, or otherwise manipulate, as reaching only intentionally subversive and deceptive conduct, invoking the associated-words, series-qualifier, and ejusdem generis canons. She illustrated the point with a hypothetical library rule in which the adverb loudly would naturally govern both talking on the phone and playing music. In her view, the surrounding verbs all connote hostile or clandestine purpose, and the majority’s neutral reading lets the government treat a contractor as a national-security threat whenever it enforces contract terms the Department finds too restrictive, leaving contractors a choice between accepting the Secretary’s terms and risking designation. She also pointed to the 2018 Senate report behind the statute, which described the threat of hostile nation states and other bad actors infiltrating the federal government’s technology supply chains.
The clerk of the court issued an order on September 25, 2026 withholding issuance of the mandate, according to the case docket.












