Quick Answer
Anthropic’s supply-chain-risk designation remains in effect after a federal appeals court ruled 2-1 for the Department of War on September 25, 2026. The ruling allows the Pentagon to keep Claude out of its systems and bar Anthropic from Defense Department work. Businesses using Claude are not directly affected, but federal contractors should review agency requirements before relying on Anthropic products.
Key Takeaways
- The D.C. Circuit ruled 2-1 for the Department of War on September 25, 2026.
- The ruling preserves Anthropic’s supply-chain-risk designation for Defense Department purposes.
- The Department excluded Claude after Anthropic rejected requested contract changes involving lethal autonomous warfare and domestic surveillance.
- The court found ample support for the Department’s national-security conclusion.
- Anthropic said it respectfully disagrees and is considering further review options.
What did the appeals court rule in Anthropic’s Pentagon dispute?
The U.S. Court of Appeals for the D.C. Circuit allowed the Department of War to retain its supply-chain-risk designation for Anthropic and its Claude AI products. A three-judge panel ruled 2-1 in the Department’s favor on September 25, 2026, in Anthropic PBC v. United States Department of War, docket numbers 26-1049 and 26-1162.
The D.C. Circuit’s official September 25 opinion says the Department had “ample support” for its conclusion that continued integration of Claude into Department systems created a covered national-security risk. That finding is the central legal result because it permits the designation to continue rather than requiring the Department to restore Anthropic’s access.
The Anthropic supply-chain-risk ruling concerns the Department of War’s procurement and systems decisions, not a general finding that Claude is unavailable to consumers or private companies. The practical distinction matters because organizations outside Defense Department work should not treat the decision as a blanket prohibition, while contractors and vendors serving the Department must account for the restriction.
What does the supply-chain-risk designation allow the Pentagon to do?
The Anthropic supply-chain-risk designation allows the Pentagon to continue excluding Claude from its systems and to bar Anthropic products from Defense Department work. The ruling therefore preserves the Department’s ability to maintain the existing restriction while the legal dispute continues or while Anthropic considers further review.
The Associated Press reported that the decision permits the Pentagon to keep removing Claude from its systems and prevents Anthropic from participating in Defense Department work. The consequence is operational as well as contractual: a tool already integrated into a Department environment can remain subject to removal, and prospective work can remain unavailable to the company.
| Area affected | What the ruling preserves | Practical meaning |
|---|---|---|
| Department systems | The Pentagon can continue removing Claude. | Claude can remain excluded from covered Department environments. |
| Defense contracts | The Pentagon can continue barring Anthropic products. | Anthropic cannot rely on Defense Department work covered by the designation. |
| Private-sector use | The ruling does not establish a consumer or commercial ban. | Non-Defense users should separately assess their own policies and contracts. |
The supply-chain-risk ruling also illustrates why organizations using AI services need to separate technical capability from procurement eligibility. A model can be useful for ordinary work while still being unavailable in a specific government environment because the agency’s contract and security requirements differ. Businesses building AI workflows should document which provider dependencies could affect government-facing work.
Why did the Department of War exclude Claude?
The Department of War excluded Claude after Anthropic refused to relax contractual restrictions on the use of Claude for lethal autonomous warfare and domestic surveillance. The D.C. Circuit’s opinion identifies that disagreement as the basis for the Department’s action and for its assessment of continued Claude integration as a national-security risk.
The court’s description is important because the dispute was not framed solely as a disagreement over Anthropic’s public policy positions. The majority concluded that the Department acted after Anthropic declined a contract term the Department considered essential. That distinction shaped the court’s treatment of Anthropic’s constitutional arguments.
The case also places a sharper focus on the contractual limits that AI providers set for sensitive uses. Organizations evaluating autonomous systems should recognize that a vendor’s usage restrictions can affect whether its models are available for a particular deployment. Security teams already reviewing third-party software exposure can apply similar scrutiny to AI suppliers after incidents such as the Brevo supply-chain attack showed how vendor dependencies can create wider operational consequences.
How did the court address Anthropic’s due-process and First Amendment claims?
The D.C. Circuit rejected Anthropic’s due-process claim because the Department notified the company of the exclusion, explained its rationale, and gave Anthropic an opportunity to contest the action. The court therefore found that the process provided to Anthropic was sufficient for the challenged designation.
The D.C. Circuit also rejected Anthropic’s First Amendment claim. The opinion found that the exclusion rested on Anthropic’s refusal to accept a contract term the Department viewed as essential, rather than on Anthropic’s AI-policy views. The court’s reasoning matters because it treats the action as a procurement and national-security decision tied to contract conditions.
The ruling does not resolve every broader question about government AI procurement or vendor safeguards. It does establish that, on the record before the court, Anthropic did not prevail on the notice, opportunity-to-contest, or speech-based arguments it raised. Companies negotiating sensitive government work should treat contract terms governing model use as central business and compliance conditions.
What does the Anthropic supply-chain-risk ruling mean for Anthropic?
The Anthropic supply-chain-risk ruling leaves Anthropic unable to challenge the designation successfully at the D.C. Circuit at this stage. Reuters reported that the Pentagon can continue blacklisting Anthropic from military contracts, while Anthropic had said the designation cost the company billions of dollars in lost business and damaged its reputation.
The reported business impact explains why the case matters beyond a narrow legal dispute. Defense Department access can affect direct contracts, technical integrations, and a company’s ability to compete for work involving federal systems. The ruling does not establish the precise future financial effect, but it preserves the restriction that Anthropic said had already caused substantial harm.
Anthropic told the Associated Press that it “respectfully disagrees” with the ruling and is considering further review options. The company has not announced a specific next legal step in the information available here. Readers should distinguish the court’s current decision from any later appeal or review request, because the legal posture could change if Anthropic pursues one.
What does the ruling mean for federal contractors using AI tools?
Federal contractors using AI tools should confirm whether their work involves Department of War systems, contracts, or procurement rules affected by the Anthropic designation. The decision allows the Department to keep Claude excluded from covered work, so a contractor cannot assume that a commercially available model is also acceptable for a Defense Department deployment.
The most sensible response is to identify every AI provider used in a government-facing workflow and check the contract language before expanding deployment. Procurement teams should also determine whether a model is used directly, through a third-party platform, or as part of a broader automation service. Those details can affect whether an exclusion creates a practical delivery problem.
- Review active Defense Department contracts and statements of work for AI-related requirements.
- Identify whether Claude appears in internal tools, vendor platforms, or planned deployments.
- Confirm acceptable alternatives with the contracting officer or agency security contact before changing a covered workflow.
- Document the decision and any approved replacement model for audit and continuity purposes.
Federal contractors should stop before making a unilateral change to a covered system if the contract language is unclear. The appropriate next step is to seek written direction from the contracting officer, agency counsel, or the relevant security office, because an internal interpretation may not satisfy the Department’s requirements. Questions about potential AI-agent responsibility also remain relevant as agencies consider how automated systems can affect users and operations, as covered in the discussion of AI developer liability for agent harm.
Should private Claude users change how they use the service?
Private Claude users do not need to stop using Claude because of the Anthropic supply-chain-risk ruling. The court decision concerns the Department of War’s ability to exclude Anthropic from Defense Department systems and contracts, and the available ruling does not impose a consumer-facing restriction on Claude.
Private users should still apply ordinary AI privacy judgment to any chatbot service. Do not enter confidential employer material, sensitive financial information, or personal records unless the organization has approved that use and the applicable settings and contract terms support it. The practical privacy question is separate from the Pentagon’s procurement decision, as explained in guidance on AI chatbot privacy settings and data retention.
Business users should be especially careful when a private-sector project could later move into a federal environment. A workflow built around one provider may need redesign if an agency customer cannot use that provider. The most reliable approach is to evaluate model access, contractual restrictions, and data-handling requirements before an AI tool becomes embedded in a critical process.
FAQ
Did the D.C. Circuit ban Claude for all users?
No, the D.C. Circuit ruling does not ban Claude for all users. The decision allows the Department of War to keep Claude out of covered Pentagon systems and Defense Department work.
Why did the Department of War exclude Anthropic?
The Department of War excluded Anthropic after the company refused to relax contractual restrictions involving lethal autonomous warfare and domestic surveillance. The court said the Department had ample support for its national-security conclusion.
Did Anthropic win any of its constitutional claims?
No, Anthropic did not win its due-process or First Amendment claims in the D.C. Circuit ruling. The court found that Anthropic received notice, a rationale, and an opportunity to contest the exclusion.
Can the Pentagon continue removing Claude from its systems?
Yes, the Pentagon can continue removing Claude from its systems under the ruling. The Associated Press reported that the decision also permits the Department to bar Anthropic products from Defense Department work.
Will Anthropic seek another appeal?
Anthropic is considering further review options, according to its statement to the Associated Press. The company said it respectfully disagrees with the D.C. Circuit’s decision.
