September 26, 2026·5 min read·AIgentic.media

Court Says Pentagon Can Blacklist Anthropic for Refusing Military AI Features

anthropicai-safetypolicy-regulationus-military
Court Says Pentagon Can Blacklist Anthropic for Refusing Military AI Features

An AI lab told the Pentagon it could not have certain features. The Pentagon told the lab it could not have its business. A federal court just said the Pentagon was right.

The US Court of Appeals for the DC Circuit ruled 2-1 on Friday that the Department of Defense can designate Anthropic, the company behind the Claude model family, as a national security supply chain risk. The ruling stems from Anthropic's refusal to implement specific Claude features requested by the military, which the company said would violate its Responsible Scaling Policy.

The decision creates the first major legal precedent on a question the AI industry has been circling for years: what happens when an AI lab's safety commitments collide with the US government's procurement power?

The supply chain risk label

The Pentagon used its supply chain risk management authority to classify Anthropic as a risk to national security. Defense Secretary Pete Hegseth argued that Anthropic's refusal to enable certain Claude capabilities for military use could jeopardize defense operations. The classification effectively bars Anthropic from winning or participating in Pentagon contracts.

The 2-1 ruling from the DC Circuit upheld this designation. Judge Patricia Millett, writing for the majority, concluded that the Pentagon acted within its legal authority under federal procurement law when it determined that Anthropic's safety restrictions created an unacceptable supply chain risk for military applications.

Anthropic has called the decision a "dangerous precedent" and said it is evaluating its legal options, including a potential appeal to the Supreme Court.

Hegseth's argument centered on operational risk: if Claude is deployed in a military context and Anthropic's safety protocols prevent the system from performing a critical function at the moment it is needed, the consequences could be measured in lives, not revenue. The Pentagon's供应链 risk framework allows it to exclude vendors whose policies could compromise mission effectiveness, even when those policies stem from ethical commitments rather than technical failures.

The split verdict : what the court rejected

Importantly, the appeals court did not give the Pentagon everything it wanted. The ruling blocked a separate classification under a different legal authority, calling it unlawful retaliation against Anthropic for its AI safety advocacy.

This part of the decision is arguably as significant as the part the government won. The court acknowledged that the government cannot use one legal theory to punish a company for taking public positions on AI safety, even while it can use another theory to exclude that same company from contracts based on operational risk.

The distinction creates a narrow but important boundary: the government can restrict business with an AI lab whose policies conflict with military needs, but it cannot retaliate against that lab for advocating safety positions the administration disagrees with. In the current political climate, where Anthropic has accused the Trump administration of targeting it as "left-leaning" and "woke," this distinction matters.

What the ruling means for the AI industry

The immediate impact on Anthropic is severe. The company has estimated the blacklist has cost it billions in lost Pentagon contracts and related business opportunities. But the ruling's implications extend far beyond one company.

Every frontier AI lab now faces a strategic question: how far are they willing to let government procurement policy override their safety policies? When the Pentagon requests a feature that a lab's internal safety review process has rejected, the consequences are no longer hypothetical. A federal court has confirmed that the refusal itself can trigger exclusion from the entire military market.

For smaller labs without Anthropic's funding or market position, the pressure to comply will be even greater. A startup that cannot afford to lose the DoD as a customer may think twice before maintaining a safety restriction the Pentagon finds inconvenient.

The ruling also creates uncertainty about what "supply chain risk" means in the context of AI. Traditional supply chain risk covers physical components, software dependencies, and cybersecurity vulnerabilities. Applying it to an AI company's ethical policies represents an expansion of the concept that industry lawyers will be scrutinizing for months.

The broader collision

Behind the legal arguments lies a fundamental tension. AI safety advocates argue that frontier models need careful deployment restrictions, especially in high-stakes military contexts where misuse could have catastrophic consequences. The Pentagon, like any military organization, wants maximum capability from the tools it deploys, with minimum external constraints on when and how those tools are used.

This tension is not new, but the Anthropic ruling makes it concrete in a way it has never been before. Previous debates about military AI : around Project Maven, autonomous weapons, and the Pentagon's broader AI strategy : involved questions about what the government should build. The Anthropic dispute asks a different question: what happens when an AI company refuses to build something the government wants, and the government responds by shutting that company out of its entire procurement system?

The answer, according to Friday's ruling, is that the government can : within limits.

The court's decision to block the retaliatory classification suggests that the judiciary is aware of the risks of allowing procurement power to become a tool for political punishment. But the core holding : that the Pentagon can exclude an AI lab based on its safety policies : opens a door that other agencies may now walk through.

Sources

Want to learn more?

Let's discuss how AI can transform your business.

Get in Touch