A federal appeals court in Washington ruled Friday that the Pentagon may continue barring Anthropic’s Claude AI system from its supply chain after the company refused to let the military use Claude for “all lawful purposes.”
The D.C. Circuit’s 2-1 decision in Anthropic PBC v. Department of War rejected the company’s challenge to a March determination by Secretary of War Pete Hegseth that Claude posed a supply-chain risk. Judges Gregory Katsas and Neomi Rao, both Trump appointees, formed the majority. Judge Karen LeCraft Henderson, appointed by George H.W. Bush, dissented.
Anthropic has allowed Claude to be used by the military for weapons development, foreign-intelligence analysis and offensive cyber operations. But the company drew the line at two uses: lethal autonomous weapons and mass domestic surveillance. The Pentagon wanted an unrestricted agreement covering all lawful purposes, and Anthropic wouldn’t sign off.
The fight escalated after Anthropic flagged concerns about Claude’s role in a sensitive overseas operation. The company itself entered media reports into the case record identifying that operation as the January capture of Venezuelan leader Nicolás Maduro. That episode led defense officials to question whether Claude would perform reliably during military operations, and Hegseth formally designated Claude a supply-chain risk under the Federal Acquisition Supply Chain Security Act, ordering it stripped from department systems and barring contractors from using it.
The word that decided the case
The ruling turned on the statutory term “manipulate.” The law lets the government act against technology whose design or operation “may be manipulated” in a way that denies or disrupts its function. Anthropic argued Congress meant sabotage or foreign compromise, not a company’s own transparent safety rules.
The majority disagreed. Because Anthropic deliberately trains Claude to refuse certain tasks, Judge Katsas wrote, the company is manipulating the system’s function as a matter of certainty, not just risk. He added that the court had “no reason to doubt that Anthropic manipulates Claude’s function, use and operation with noble intentions.” But under the statute, the majority held, intent doesn’t matter — conduct does.
That reasoning let the court reconcile Friday’s outcome with a separate win Anthropic secured in August, when a federal judge in California threw out a different Pentagon supply-chain designation under another law. The D.C. Circuit said that other statute targeted “adversary” conduct implying malicious intent, while FASCSA applies to “any person” and requires no bad motive at all.
Anthropic also argued the Pentagon was retaliating for its public stance on AI safety, citing Hegseth’s public criticism of the company’s “sanctimonious rhetoric,” “virtue-signaling” and “Silicon Valley ideology.” The majority agreed that speech is protected but found the exclusion was driven by Anthropic’s refusal to accept the “all lawful purposes” condition, not by its advocacy.
Judge Henderson’s dissent argued the majority stretched “manipulate” too far, reading it to cover a company openly enforcing known limits on its own product rather than the subversive interference she believes Congress had in mind.
Whose call is it
The majority framed the dispute as a clash between two real risks: an AI system that shuts down mid-operation because it was told to refuse certain tasks, versus an AI system with no restraints that might identify the wrong lethal target. The court said it isn’t its job to decide which risk is worse.
“But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution. Accordingly, we deny the petitions for review.”
Anthropic can still seek rehearing before the full D.C. Circuit or ask the Supreme Court to take the case. For now, the Pentagon’s exclusion of Claude stands.