US Appeals Court Upholds Pentagon Blacklisting of Anthropic
A divided panel of the US Court of Appeals for the District of Columbia Circuit has upheld the Pentagon’s decision to blacklist Anthropic. The ruling allows the Trump administration to prevent federal agencies from using Anthropic products and bars defense contractors from doing business with the company.
The case is not primarily about whether Anthropic acted in bad faith. It concerns whether the company’s refusal to remove certain restrictions on Claude was enough for the Defense Department to invoke supply-chain security powers.
What the court decided
Anthropic has restricted Claude’s use for lethal autonomous warfare and mass surveillance of Americans. The company has also maintained that the model should not perform tasks it considers inappropriate. Anthropic argued that the government’s response—ending federal use and prohibiting defense contractors from working with the company—was unlawful retaliation for those policies.
A federal judge in California previously ruled against the administration. That court concluded that Anthropic did not fit the relevant definition of a supply-chain risk and found that the government’s action raised First Amendment concerns. The DC Circuit did not directly reject the California court’s interpretation of one statute. Instead, it said the district court was reviewing a decision under 10 USC § 3252, while the appeals court had exclusive jurisdiction over the procurement action under 41 USC § 4713.
The distinction was decisive. The California court read Section 3252 as focusing on risks associated with adversaries, sabotage, malicious insertion, or other deliberate subversion. The appeals court said Section 4713 uses broader language, including the phrase “any person.” It also emphasized that the statute covers risks that could deny, disrupt, or otherwise manipulate the operation or use of covered technology.
The majority therefore accepted the Pentagon’s concern that Anthropic’s restrictions could prevent Claude from carrying out lawful actions requested by military users. In the court’s view, the government could reasonably fear that the model might not perform as required during a national-security operation, even without any malicious intent by Anthropic.
Two competing safety concerns
The court described the policy problem as a conflict between two serious risks. An overly constrained model might unexpectedly refuse a task and cause an important operation to fail. An unconstrained model might hallucinate unsuitable targets for lethal military force. The majority said that balancing these risks belongs to the president and the defense secretary, provided they remain within the limits of their legal authority.
Judge Karen Henderson dissented. She argued that the statute was designed to address hostile states and other bad actors infiltrating government systems through supply chains. In her view, it should not be stretched to cover a contractor’s open and good-faith enforcement of usage restrictions that the government dislikes.
Why the decision matters
The ruling creates additional uncertainty for AI companies seeking government and military contracts. Providers must assess not only model safety and reliability, but also whether their refusal to support certain applications could be treated as a threat to mission continuity. A government purchaser may view deployment limits as a procurement risk rather than simply as a product policy.
The litigation is not over. Anthropic said it disagrees with the decision and is considering an en banc petition or an appeal to the Supreme Court. The administration’s relationship with Anthropic may also remain fluid: Commerce Secretary Howard Lutnick recently said the two sides had repaired their relationship. Whatever happens next, the case could shape how much room AI developers have to impose safety boundaries when their models are used by the military.
Source: Ars Technica AI
Comments
Checking sign-in status...
Loading comments...