
Anthropic's fight with the Pentagon just took a bad turn. On September 25, 2026 (UTC-4), the U.S. Court of Appeals for the D.C. Circuit upheld the Pentagon's decision to blacklist Anthropic from military contracts in a 2-1 ruling. The decision keeps one of the world's most advanced AI companies locked out of defense work — and it exposes a deepening legal split over whether the government can punish AI labs for refusing to enable autonomous weapons and mass surveillance.
How we got here
The conflict traces back to February 27, 2026 (UTC-5), when President Trump signed an executive order directing all federal agencies to stop using Anthropic products. In March, Defense Secretary Pete Hegseth designated Anthropic a national security supply-chain risk under two separate laws. The trigger: Anthropic refused to remove guardrails preventing its Claude models from being used for autonomous weapons or domestic mass surveillance.
Months of negotiations collapsed into public recriminations. Hegseth and Trump accused Anthropic of endangering American lives with "ideological posturing." Anthropic countered that AI isn't reliable enough for autonomous weapons and that domestic surveillance violates fundamental rights. The company says the blacklisting has already cost it billions in lost business and damaged its reputation ahead of a planned IPO.
| Court | Date | Ruling |
|---|---|---|
| N.D. California (Judge Rita Lin) | August 28, 2026 (UTC-7) | Government illegally retaliated against Anthropic for protected speech; blocked government-wide ban |
| D.C. Circuit (Katsas, Rao majority; Henderson dissent) | September 25, 2026 (UTC-4) | Upheld Pentagon's supply-chain risk designation; 2-1 |
Sources: U.S. Court of Appeals for the D.C. Circuit, Reuters, CBS News.
The D.C. Circuit majority, written by Judge Gregory Katsas and joined by Judge Neomi Rao — both Trump appointees — found it reasonable for the Pentagon to designate Anthropic after it refused to allow its products for autonomous weapons or mass surveillance. "The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail," the opinion reads. The court rejected Anthropic's claim that the Pentagon was retaliating for its views on AI safety and ethics.
Judge Karen LeCraft Henderson dissented. In a separate case in San Francisco, U.S. District Judge Rita Lin last month struck down a parallel designation under a different law, finding the administration had unlawfully retaliated against Anthropic for constitutionally protected expression. Lin also blocked Trump's government-wide ban on Anthropic and Hegseth's order barring military contractors from doing business with the startup.
Anthropic said in a statement that it "respectfully disagrees" with the D.C. Circuit decision and is considering its options, including review by the full appeals court en banc.
Why it matters
This is the first major legal collision between AI safety commitments and national security power, and the split verdict tells you everything about where this is headed. Two federal courts, applying two different laws, have reached opposite conclusions — one says the government illegally retaliated for speech, the other says the Pentagon reasonably assessed a supply-chain risk. That kind of circuit split is precisely what the Supreme Court exists to resolve.
The composition of the D.C. Circuit majority is impossible to ignore. Both judges in the majority were appointed by Trump and served in his first administration. The ruling reads less like a neutral assessment of supply-chain risk and more like a judicial endorsement of the administration's position that AI labs must make their models available for military use without restrictions. If that precedent holds, every AI company that refuses to enable autonomous weapons or surveillance faces the same treatment — not through legislation, but through executive fiat backed by a compliant court.
The chilling effect on the industry is real and immediate. OpenAI has worked closely with the defense establishment; Anthropic staked out a harder line on safety. The message from Friday's ruling is that taking the harder line has a financial cost measured in billions. Watch whether other labs quietly relax their weapons-use policies in the coming months — not because their technical assessments changed, but because the legal risk of holding the line just went up.
For Anthropic specifically, the timing could hardly be worse. The company is preparing for what could be the largest AI IPO in history, and a running legal war with the Pentagon is the kind of overhang that moves valuations. The California ruling gives Anthropic a partial win — the government-wide ban is blocked — but the D.C. Circuit ruling means the defense market, one of the biggest AI buyers on earth, remains closed. Investors will price that gap.
The deeper question is whether "overly constrained AI models shutting down unexpectedly" is a serious military risk or a speculative one. The majority opinion treats it as plausible; Anthropic argues it's a pretext. What's missing from the public record is any evidence that a constrained Claude model actually failed in a military context. The Pentagon's designation was based on the possibility of failure, not a documented incident. That standard — banning a vendor because its safety guardrails might someday cause a problem — is extraordinarily broad, and if it survives appeal, it gives the defense establishment effective veto power over any AI company's safety policy.
What to watch
Track whether Anthropic files for en banc review by the full D.C. Circuit — that's the next procedural step and would signal the company is playing for a Supreme Court showdown. Watch for other AI labs to adjust their weapons-use policies in response; if even one major player relaxes its stance, that's the chilling effect made visible. And pay attention to whether the IPO timeline shifts — if Anthropic delays its public offering until the litigation resolves, you'll know the Pentagon ruling did real financial damage.
Prediction: this case reaches the Supreme Court within 18 months. The circuit split is too clean, the constitutional question (government retaliation for speech vs. national security authority) too fundamental, and the stakes too high for it to end at the appellate level. When it does, the Court's decision will define whether AI labs can set their own safety boundaries or whether the Pentagon gets to set them.
No comments yet