Pentagon Blacklisting of Anthropic Upheld: Appeals Court Rules Military Can Exclude AI Firms Over Withheld Features

Sep 26, 2026 | Abuses of Power

Pentagon blacklist Anthropic

A federal appeals court has handed the Trump administration a significant legal victory, ruling that the Department of Defense had the authority to blacklist Anthropic — maker of the Claude AI assistant — after the company refused to remove ethical restrictions on its models for military use. The 2-1 ruling from the US Court of Appeals for the District of Columbia Circuit leaves one of America’s most prominent AI companies caught between its own stated principles and the demands of its most powerful former client.

The Ruling and What It Means

In a decision issued by the DC Circuit, the panel acknowledged the extraordinary stakes involved. The court wrote that the case “raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology.” On one side, the US government raised “the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail.” On the other, Anthropic raised “the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force.”

The court concluded that President Trump and Defense Secretary Pete Hegseth “must determine how best to balance the competing risks,” and that in blacklisting Anthropic, the Secretary “did not transgress any limits on his authority.” Accordingly, the court denied Anthropic’s petitions for review. The two judges who ruled against Anthropic — Judge Gregory Katsas and Judge Neomi Rao — were both appointed by Trump and previously served in his first administration. Judge Katsas served as deputy counsel to the president, while Judge Rao held a position in the Office of Management and Budget.

Two Courts, Two Contradictory Verdicts

The legal picture is far from resolved. A federal judge in the US District Court for the Northern District of California ruled last month that the blacklisting was illegal, finding that Anthropic does not meet the statutory definition of a supply-chain risk. Under 10 U.S.C. § 3252, supply-chain risk is limited to situations where “an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert” a covered system. The California court found that Anthropic’s refusal to enable certain features does not constitute malicious action by an adversary.

The DC Circuit did not dispute this finding. Instead, it argued that it was reviewing the blacklisting under a separate and more permissive statutory authority — 41 U.S.C. § 4713 — which does not carry the same requirement that a company act with bad intent. Crucially, Congress granted the DC Circuit exclusive jurisdiction to review procurement actions taken under Section 4713 designations. The court stated plainly: “We have no quarrel with the Northern District’s conclusion” that bad motive is required under Section 3252, but that analysis did not apply to the authority the appeals court was evaluating.

The result is a split legal landscape: one court has found the blacklisting unlawful under one statute, while another has found it permissible under a different one. Anthropic now faces a decision on whether to seek an en banc review before the full DC Circuit or petition the Supreme Court.

How the Dispute Began

The conflict between Anthropic and the Pentagon did not emerge overnight. In July 2025, the Department of Defense awarded Anthropic a $200 million contract through its Chief Digital and Artificial Intelligence Office, making Claude the first frontier AI system cleared for classified military use. Claude was subsequently deployed by US military and intelligence personnel for analytical and operational support, including in an operation to capture Venezuela’s former president, Nicolás Maduro.

The relationship deteriorated during negotiations over the Pentagon’s GenAI.mil platform, a government-certified AI hub intended to provide frontier AI tools across the Department of Defense. The Pentagon asked Anthropic to allow the agency to use Claude for “any lawful use,” rather than under the company’s standard terms of service. Anthropic largely agreed but drew firm lines: Claude would not be used for autonomous lethal weapons or mass domestic surveillance of Americans.

Those limits proved unacceptable to Pentagon leadership. After Anthropic CEO Dario Amodei reportedly told Defense Secretary Hegseth that the company would not comply with demands to expand Claude into those areas, the DoD sent what it described as a “last and final offer” — allow the Pentagon access to Claude for all lawful purposes, with a response deadline of Friday at 5:01 p.m. Eastern. Amodei’s public statement in response said the company could not “in good conscience” agree, citing two categories of concern: mass surveillance of Americans and autonomous weapons systems capable of selecting targets without human intervention.

Pentagon Chief Technology Officer Emil Michael responded sharply on social media, stating that the DoD wanted to “use AI without having to call [Amodei] for permission to shoot down an enemy drone swarm that would kill Americans.” The standoff proved irreconcilable, and in March 2026, the DoD formally designated Anthropic as a supply-chain risk, ordered all federal agencies to cease using Anthropic systems, and warned that continued use could trigger contractual penalties.

Unprecedented Application of a Security Statute

Legal analysts and former defense officials noted early on that the supply-chain risk statute had historically been applied only to foreign companies with alleged ties to hostile governments — never to an American firm that had, until recently, been a trusted defense contractor. A former senior defense official, speaking anonymously to DefenseScoop before the blacklisting was formalized, called the move “beyond punitive” and “bullying,” adding that designating “one of the great American tech companies” as a supply-chain risk was “so far beyond the pale that it’s hard to fathom it’s even being considered.”

Anthropic’s lawsuit, filed in federal court in California in March 2026, raised three central claims: that the designation violated its First Amendment rights by punishing the company for its expressed views on AI ethics in warfare; that it violated Fifth Amendment due process guarantees by imposing severe economic consequences without notice or opportunity to contest; and that it violated the Administrative Procedure Act as an arbitrary and capricious agency action. The complaint noted that even as the Pentagon labeled Claude a national security threat, it continued deploying Anthropic systems in active military operations.

Adding to the contradictions, President Trump’s public posts referred to Anthropic as a “RADICAL LEFT WOKE COMPANY,” language that Anthropic cited as evidence the blacklisting was motivated by viewpoint hostility rather than genuine security concerns.

A Chilling Effect on the Frontier AI Industry

The broader implications of the ruling extend well beyond Anthropic. Multiple sources told DefenseScoop in February that such a designation, if carried through, could have “a chilling effect on the broader frontier AI industry.” The question now facing other frontier AI companies — including those holding their own DoD contracts — is whether maintaining ethical guardrails on military applications could expose them to similar treatment.

The DC Circuit ruling effectively establishes that under Section 4713’s procurement authority, the Defense Secretary can exclude a domestic AI company from contracting not because it poses a genuine adversarial threat, but simply because it declines to enable features the military wants. No finding of malicious intent is required.

Commerce Secretary Howard Lutnick stated in early September that the Trump administration and Anthropic have “patched up” their relationship and are “in tune.” Anthropic’s own spokesperson pushed back following the ruling, stating the company “respectfully disagrees” with the decision and noting that another federal court has already held the parallel designation unlawful. The company said it is “considering all options, including further review.”

What Comes Next

The legal and policy battle over who controls the ethical guardrails of AI systems deployed in military contexts remains unresolved. Two courts have reached contradictory conclusions under two different statutory frameworks. The Supreme Court has not yet weighed in. Meanwhile, the technology at the center of the dispute — large-scale AI models capable of supporting military operations — continues to develop at a pace that outstrips the legal and regulatory infrastructure designed to govern it.

Whether Anthropic’s refusal to enable autonomous targeting capabilities represents responsible stewardship or an unacceptable constraint on national defense is a question the courts have declined to answer on the merits. That judgment, for now, has been left to the Secretary of Defense.

This article draws on reporting from Ars Technica, Syracuse University Law Review, DefenseScoop, and PBS NewsHour.

Why did the Pentagon blacklist Anthropic?

The Pentagon blacklisted Anthropic after the company refused to allow its Claude AI to be used for autonomous lethal weapons and mass domestic surveillance, insisting on ethical restrictions the DoD viewed as unacceptable limits on military use.

What did the appeals court rule about the Anthropic blacklisting?

The US Court of Appeals for the DC Circuit ruled 2-1 that the Defense Secretary had authority under 41 U.S.C. § 4713 to exclude Anthropic from contracting without needing to prove malicious intent, upholding the blacklisting under that specific statute.

Is the Anthropic Pentagon blacklisting legal?

Two courts have reached conflicting conclusions: a California federal court found the blacklisting illegal because Anthropic does not qualify as a supply-chain risk under 10 U.S.C. § 3252, while the DC Circuit upheld it under a separate, more permissive statutory authority.

Want to go deeper? Ask NEX, the Decrypted Matrix research assistant, about the documents behind this story. It indexes every article here the day it is published and cites its sources.

Related Posts