Skip to content
AI.info

The Pulse

D.C. Circuit Upholds Pentagon’s Anthropic Risk Designation

A divided D.C. Circuit panel rejected Anthropic’s challenge to the Pentagon’s supply-chain risk designation under a federal procurement law. The majority said the department could treat Claude’s built-in restrictions as a national-security

D.C. Circuit Upholds Pentagon’s Anthropic Risk Designation

AI.info Team ·

A divided court leaves the designation in place

The D.C. Circuit upheld the Pentagon’s designation of Anthropic as a supply-chain risk on Friday, September 25, rejecting the company’s challenge in a 2-1 decision. The majority said the Department of War had legal grounds to exclude Claude from its supply chain; Judge Karen LeCraft Henderson dissented, arguing the law was meant to address hostile interference with technology, not a supplier enforcing contractual limits.

Judge Gregory Katsas wrote that Anthropic’s safeguards could prevent Claude from carrying out tasks requested by government users, creating uncertainty for military operations. “The President and the Secretary of War” must decide how to balance those competing risks, he wrote. The court denied Anthropic’s petitions for review.

The ruling concerns the department’s use of the Federal Acquisition Supply Chain Security Act of 2018, or FASCSA, to bar Claude from the Department of War’s supply chain. The law can also reach subcontracts using a supplier to perform work for an agency. The decision does not itself declare that Anthropic’s systems have caused a security failure; the majority upheld the department’s assessment of the risk.

Why the majority accepted the Pentagon’s argument

The dispute grew out of Anthropic’s refusal to relax contractual prohibitions on using Claude for lethal autonomous warfare or domestic surveillance. The majority said the record showed that the company trains Claude to refuse certain requests and had, on previous occasions, prevented it from responding to government users. A dispute over whether the contract terms restricted Claude’s use in an overseas military operation also left the department uncertain about the system’s availability, the opinion said.

The judges divided over what counts as a “supply chain risk” under FASCSA. The majority read the law’s definition broadly, concluding that it does not require a supplier to act maliciously. It accepted the Pentagon’s view that restrictions which could affect how Claude performs in government systems fall within the statute, and deferred to the department’s national-security assessment.

The court also rejected Anthropic’s arguments that the action was arbitrary, violated due process or punished the company for its public position on AI safety. On due process, the majority said Anthropic received notice and a chance to challenge the decision after the department acted. On the First Amendment claim, it concluded the department acted over a contract term it considered necessary, rather than over Anthropic’s advocacy.

Henderson says the law targets hostile interference

Henderson’s dissent took a narrower view of the statute. She argued that FASCSA’s examples—including sabotage, maliciously introducing unwanted functions and extracting data—point to deliberately harmful conduct. In her reading, the catch-all phrase “otherwise manipulate” should be limited by those examples, rather than covering a company’s good-faith enforcement of its product restrictions.

“I cannot agree that this is the scenario the Congress had in mind when it enacted FASCSA,” Henderson wrote. She warned that the majority’s reading could allow the government to label a supplier a security risk when the supplier’s contractual or technical limits prevent a government use the department wants. The disagreement reaches beyond Anthropic: it sets competing judicial interpretations of how broadly the statute can be used against a domestic technology supplier.

A separate California ruling addressed a different law

The D.C. Circuit also addressed Anthropic’s earlier win in a Northern California case, where a judge set aside a separate designation under a different statute, 10 U.S.C. § 3252. The appellate majority said that law’s definition is narrower and requires bad motive, while FASCSA’s definition does not. It therefore found the California decision did not control the challenge before it.

That distinction leaves the two court outcomes in place: the California ruling concerned the designation under § 3252, while Friday’s decision upheld the Department of War’s action under FASCSA, 41 U.S.C. § 4713. The D.C. Circuit’s order denied Anthropic’s petitions for review of the latter designation.

Sources

Explore

More articles