Appeals Court Upholds Pentagon's Supply Chain Risk Label on Anthropic
A DC appeals court ruled 2-1 that the Pentagon can keep Anthropic designated a supply chain risk, leaving Claude excluded from federal systems as Anthropic eyes an IPO.

Updated
Why it matters
- A 2-1 DC Circuit appeals panel on Friday upheld the Pentagon's supply-chain risk designation of Anthropic, keeping Claude excluded from DoD and federal systems.
- A San Francisco federal judge had tossed out the second designation in March and confirmed that ruling last month, setting up years of parallel appeals.
- The court rejected Anthropic's due process and free speech claims, calling the dispute standard contract negotiations over a term the Pentagon deemed essential.
- Anthropic spokesperson Danielle Cohen says the company is considering all options, including en banc review or a Supreme Court appeal.
- The ruling lands as Anthropic moves toward a potential IPO later this year and as the Pentagon weighs replacements including SpaceX's Grok, Google's Gemini, and OpenAI's GPT models.
A federal appeals court in Washington, DC, has refused to overturn the Pentagon's designation of Anthropic as a supply chain risk, dealing the AI company a legal defeat that keeps its Claude models locked out of the Department of Defense and other parts of the federal government.
The ruling landed on Friday. It came from a three-judge panel of the DC Circuit Court of Appeals, which decided 2-1 against Anthropic after months of litigation over one of two supply-chain risk labels the Department of Defense placed on the company earlier this year.
"The department had ample support for its conclusion that the continued integration of Claude into the department's information systems, by the department or its contractors, presented a statutorily covered national-security risk," the judges wrote in the majority opinion.
The court's reasoning cuts to the heart of the dispute. Anthropic builds usage restrictions into Claude that block the model from performing tasks the company does not want it to perform. The Pentagon, and now the court, treated that design choice as the basis for a national security concern.
"As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," the judges wrote.
Why the Pentagon acted
The conflict traces back to Anthropic's own red lines. Company executives have said publicly that Anthropic would not permit the government to deploy its current AI models in support of autonomous weapons or domestic surveillance. Secretary of Defense Pete Hegseth deemed that stance a significant national security risk.
Earlier this year, the Pentagon invoked a pair of separate supply-chain laws to sanction Anthropic and force the removal of Claude models from the military and other parts of the federal government by this month. Those two designations had to be challenged in separate courts, and they have produced sharply divergent outcomes.
A federal judge in San Francisco tossed out one of the supply-chain risk labels in March and confirmed that decision last month. Friday's ruling means the other label will stay in place indefinitely, so the Pentagon's blocking of Anthropic can continue. Both rulings now face the prospect of years of appeals before the legal questions are fully resolved.
Anthropic is not out of options. Spokesperson Danielle Cohen says the company remains confident in its position and is considering all options. That could include appealing to a broader panel of the DC Circuit Court of Appeals, a procedural move known as an en banc review, or taking the case to the US Supreme Court.
Due process and free speech claims rejected
Anthropic had argued on two constitutional fronts as well. The company claimed the designation violated its due process and free speech rights. The majority rejected both claims. The judges found that the government followed proper procedure and characterized the dispute as ordinary contract negotiation rather than retaliation for Anthropic's political positions.
The Pentagon "excluded Anthropic from its supply chain based on the company's refusal to assent to a contract term that the Department deemed essential, not based on the company's support for greater governmental regulation of AI technology," the judges wrote.
That framing matters. It draws a line between punishing a vendor for its policy advocacy, which would raise First Amendment concerns, and declining to do business with a vendor that will not accept terms the buyer considers essential. Under the court's reading, the Pentagon's action falls on the permissible side of that line.
Anthropic had also argued that the government had acted beyond what the supply-chain law allows. Friday's decision forecloses that argument for now, at least at the panel level.
The writing was on the wall
The outcome was somewhat expected. In April, the same panel declined to temporarily block the supply-chain risk designation, finding that Anthropic had failed to meet the "stringent requirements" for an immediate reprieve.
During a hearing ahead of the ruling, the three judges on the panel pressed both Anthropic and the US government on their arguments and appeared divided on how to rule on blocking the designation completely. The final split, 2-1, confirmed that the case was close. A dissent from one judge signals that appellate judges view the underlying legal questions differently, which strengthens the case for further review.
Stakes for Anthropic's business
The commercial consequences began immediately after the designations. Anthropic said in the aftermath that it lost revenue because customers grew wary of doing business with a company labeled a government pariah. The company has not provided further updates on how the designations have affected its bottom line.
The timing compounds the pressure. Anthropic has generally touted growing sales in recent months and is moving toward a potential initial public offering of its shares later this year. Entering that process with an unresolved federal designation — and a binding appellate ruling against it — creates a disclosure problem that underwriters and investors will scrutinize. The court's decision means the Pentagon and much of the rest of the Trump administration will be able to continue steering clear of Claude as Anthropic prepares to go public.
The market Anthropic left behind
The Pentagon, for its part, has not provided detailed updates on its progress replacing Claude with alternatives. The candidates named include SpaceX's Grok, Google's Gemini, and OpenAI's GPT models.
That replacement process has generated its own friction. Some employees at Google and OpenAI have objected to their employers striking a deal with the US military that Anthropic had rejected, citing ethical concerns. The companies have brushed aside the protests and described supporting the US government as crucial.
The episode now serves as a test case for a question the AI industry has avoided answering directly: what happens when a model provider sets limits on how its technology can be used by a sovereign customer with enormous purchasing power. Anthropic drew a line at autonomous weapons and domestic surveillance. The Pentagon responded with supply-chain sanctions, and a federal appeals court has now held that response within the government's legal authority.
What comes next
For now, the designation stands, the exclusion of Claude from federal systems continues, and the San Francisco ruling striking the other label remains in force. The split outcomes across two courts, combined with a 2-1 appellate split, virtually guarantee that the legal fight over whether an AI company can refuse military use cases — and whether the government can punish that refusal — will move to a broader panel of the DC Circuit or the Supreme Court before it is finally settled. Until then, Anthropic proceeds toward its expected IPO carrying a court-sanctioned national security risk label, and its competitors collect the federal business it declined.
Source: Wired AI
More from James Calloway
Show full bio
News editor covering industry trends and analytics at AI In Context.
119 articles