Anthropic Won Under 'Adversary' and Lost Under 'Any Person'

On 27 August, a federal judge in San Francisco set aside the Pentagon’s designation of Anthropic as a supply chain risk. On 25 September, a federal appeals court in Washington upheld the Pentagon’s exclusion of Anthropic as a supply chain risk. The headlines say the second ruling overturned the first. It did not.

The two courts were not looking at the same decision. They were looking at two decisions made under two statutes, and the statutes define “supply chain risk” in words that differ by only a handful of terms. Read side by side, the rulings barely disagree about the facts. The D.C. Circuit says it has “no quarrel” with the district court’s finding that Anthropic acted without bad motive. It ruled against Anthropic anyway, because the statute in front of it doesn’t ask about motive.

Disclosure: I use Anthropic’s models, Claude among them, in my own work. I have tried to stay with what the two opinions say.

One dispute, two statutes

The facts that follow are taken from the two opinions. Anthropic had sold Claude into defense work through contractors since 2024 and was part of a $200 million Department of Defense AI contract awarded in July 2025. Over time it loosened its usage policy for national-security customers. The majority opinion lists the uses it came to allow: designing weapon systems, analyzing foreign intelligence, offensive cyber operations. Two prohibitions stayed: “lethal autonomous warfare” and “mass surveillance of Americans.” On 9 January 2026, Secretary Pete Hegseth’s AI strategy directed the department (now styling itself the Department of War) to write “any lawful use” language into AI contracts. On 24 February he gave Dario Amodei until 27 February to agree to it. Amodei refused publicly on 26 February. On 27 February President Trump and Hegseth denounced the decision on social media, and Hegseth began removing Claude from the department’s supply chain.

On 3 March Hegseth signed a formal determination under the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA), 41 U.S.C. § 4713. Three days later the department’s chief information officer ordered Anthropic products removed from its systems “as soon as practical” and within 180 days, and barred contractors from using them in department work. Separately, according to Judge Rita Lin’s order, the department designated Anthropic under an older defense statute, 10 U.S.C. § 3252, and a directive told defense contractors to stop doing any business with Anthropic, military or not.

The two statutes send challenges to different courts. FASCSA gives the D.C. Circuit exclusive jurisdiction over its procurement actions and bars review anywhere else (41 U.S.C. § 1327). Anthropic therefore filed two cases on 9 March: a petition for review in the D.C. Circuit over the § 4713 action, and a suit in the Northern District of California over the rest.

Two tracks, one dispute: the Anthropic supply-chain cases, February to September 2026 A timeline from February to September 2026 in three rows. Department of War row: 26 February, Anthropic refuses the any-lawful-use term; 3 March, determination under 41 U.S.C. 4713, plus a separate designation under 10 U.S.C. 3252; 6 March, removal order with a 180-day outer limit; 3 June, reconsideration denied. Northern District of California row (10 U.S.C. 3252 designation and contractor directive): suit filed 9 March; preliminary injunction 26 March; 27 August, summary judgment for Anthropic on the First Amendment, due process and APA claims, with the designation set aside. D.C. Circuit row (41 U.S.C. 4713 exclusion, exclusive jurisdiction): petition filed 9 March; 8 April, stay denied and review expedited; 19 May, argument; 25 September, petitions denied 2 to 1. TWO STATUTES, TWO COURTS · FEB–SEP 2026 · FROM THE TWO OPINIONS MarAprMayJunJulAugSep Department N.D. Cal. D.C. Circuit of War § 3252 + directive § 4713 only 26 Feb 2026 — Amodei publicly refuses the any-lawful-use term 3 Mar 2026 — determination under 41 U.S.C. 4713; separate 10 U.S.C. 3252 designation 6 Mar 2026 — CIO removal memo, 180-day outer limit 3 Jun 2026 — reconsideration denied refusal 26 Feb 3 Mar determination · 6 Mar removal order (≤180 days) 3 Jun reconsideration denied 9 Mar 2026 — Anthropic sues in N.D. Cal. 26 Mar 2026 — preliminary injunction issued 27 Aug 2026 — summary judgment for Anthropic; 3252 designation set aside 9 Mar suit · 26 Mar injunction 27 Aug: set aside bad motive required; none found 9 Mar 2026 — petition for review filed 8 Apr 2026 — stay denied, review expedited 19 May 2026 — oral argument 25 Sep 2026 — petitions denied, 2–1 9 Mar petition 8 Apr stay denied 19 May argued 25 Sep: upheld, 2–1 no motive needed Filled square: ruling for Anthropic. Open square: for the Department. Each court reviewed only its own statute.
The same refusal set off two legal tracks. Each court reviewed a different action under a different statute, so the September ruling did not overturn the August one.

The words that differ

Here are the two definitions. Everything the courts disagreed about is in the differences.

The two statutory definitions of supply chain risk, clause by clause A clause-by-clause comparison of 10 U.S.C. 3252(d)(4) and 41 U.S.C. 4713(k)(6). Who: "an adversary" versus "any person". Acts: "sabotage, maliciously introduce unwanted function" in both, with "extract data" added in 4713. Catch-all act: "or otherwise subvert" versus "or otherwise manipulate". Target: "the design ... operation, or maintenance of a covered system" versus the same list plus "disposition, or retirement" of "covered articles". Effect: "surveil, deny, disrupt" in both. Catch-all effect: "or otherwise degrade" versus "or otherwise manipulate", with 4713 adding "information stored or transmitted". Bottom row: the Northern District of California read 3252 to require bad motive, and the D.C. Circuit agreed; the D.C. Circuit majority read 4713 to require none. "SUPPLY CHAIN RISK" MEANS THE RISK THAT … · BOLD = WORDING THAT DIFFERS 10 U.S.C. § 3252(d)(4) · defense statute 41 U.S.C. § 4713(k)(6) · FASCSA, 2018 Who Acts Catch-all act Target Effect Catch-all effect an adversary any person sabotage, maliciously introduce unwanted function, sabotage, maliciously introduce unwanted function, extract data, or otherwise subvert or otherwise manipulate design … operation, or maintenance of a covered system design … maintenance, disposition, or retirement of covered articles so as to surveil, deny, disrupt, so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation or otherwise manipulate the function, use, or operation, or information … Read by courts as D.C. Circuit majority, 25 Sep 2026 bad motive required (N.D. Cal.; D.C. Cir. agrees) no motive required (D.C. Cir., 2–1) Statutory text from law.cornell.edu (U.S. Code). Ellipses shorten the shared list of lifecycle stages.
The two definitions share almost all their wording. The older one names an adversary who might subvert a system. The newer one covers any person who might manipulate it. The appeal turned on the word "manipulate."

Judge Lin, reading § 3252, held that the designation broke the statute and was arbitrary and capricious. She also held that it was unconstitutional retaliation for Anthropic’s public criticism, and that Anthropic had been denied the process it was due. Her description of the record was blunt: “The record is slim. A four-page memorandum, which post dates two of the three challenged actions, provides the entirety of the government’s rationale.” In her account, the government had dropped the claim that Anthropic kept backdoor access to deployed models and conceded that its technology is no riskier than “any other ‘black box’” AI model. She ended: “The empty invocation of national security is not a blank check to punish and retaliate against government critics.”

Writing for the D.C. Circuit, Judge Gregory Katsas accepted most of that. He wrote that the court had “no quarrel” with the district court’s conclusion that the word adversary, together with “the sinister connotation fairly pervading” sabotage, maliciously introduce and otherwise subvert, means § 3252 requires bad motive. He also had “no quarrel” with the finding that Anthropic had none. Then: “no such bad motive is required to support a designation under the much broader definition set forth in section 4713.”

“Manipulate,” two ways

The majority takes manipulate in its plainest dictionary sense: “to move, arrange, operate, or control by the hands … or by mechanical means.” In that sense, training a model to refuse a class of request is manipulating the model’s design. On that reading the court says there is “not only a ‘risk’—but a certainty—that Anthropic will so manipulate the ‘design’ or ‘operation’ of Claude to deny it the ‘function’ of conducting lethal autonomous warfare or mass domestic surveillance.” The paragraph that decides the case is short:

A paragraph from page 28 of the D.C. Circuit's opinion in Anthropic PBC v. Department of War, ending with the sentence: at least as applied here, the statutory definition of a supply chain risk turns on what Anthropic does, not why Anthropic does it.
The court grants Anthropic "noble intentions" and then rules those intentions irrelevant. Note the qualifier "at least as applied here," which is easy to drop when the case is cited later. Image: U.S. Court of Appeals for the D.C. Circuit, Anthropic PBC v. U.S. Department of War, No. 26-1049, slip op. at 28 (25 September 2026). U.S. government work, public domain. Cropped to one paragraph.

Judge Karen LeCraft Henderson’s dissent reads the same word by the company it keeps. Sabotage and malicious introduction are hostile acts. A catch-all at the end of that list should mean the Oxford sense, “to manage, control, or influence in a subtle, devious, or underhand manner.” She illustrates with a sign for a library: “Do not shout, loudly talk on the phone, play music, or otherwise disturb others.” Nobody reads that sign as banning headphones. The majority answers that “maliciously” modifies only the verb next to it, and that “extract data” is a fair example of manipulation whether or not it is done with malice.

The two sides of this argument have an odd history. In 2023, in United States v. Fischer, Judge Katsas wrote a dissent urging that a residual “otherwise” clause in the January 6 obstruction statute be read narrowly, in light of the specific acts listed before it. The Supreme Court adopted that reading in 2024. Henderson’s dissent quotes Katsas’s Fischer dissent back at him several times. His majority opinion concedes that her arguments “have some force.” It distinguishes Fischer on several grounds: that statute was criminal, a broad reading would have made most of its list redundant, and it would have reached protected speech. A procurement statute about national security, the majority says, calls for “the opposite interpretive presumption.”

What the reasoning reaches

The majority’s facts are specific to Anthropic, and I think they reach well beyond it. Its evidence of risk was that Anthropic trains Claude to refuse certain tasks and that the training works. It cites two episodes. Early commercial versions of Claude refused tasks such as summarizing threat assessments and processing classified documents. And the department learned in 2025 that Claude had refused queries from the CDC about infectious-disease research. The third piece of evidence was a dispute in early 2026 over whether the contract barred Claude’s use in an overseas military operation. The department calls it a near-disaster and Anthropic a misunderstanding, and the court says it does not know exactly what happened. The court wrote that the point “is not that these model or usage restrictions were arbitrary.” The point is that “Anthropic’s model training does effectively enforce contractual usage restrictions.”

Nearly every frontier model is trained to refuse something. Under this reading, a model becomes a supply chain risk by working as its maker intended, whenever the maker’s intentions and the buyer’s differ. The majority also closes off the obvious fix. Anthropic argued that the department could test each new model before accepting it and keep the old one if the new one refused too much. The court’s answer was that “the Department cannot utilize AI systems that remain trapped in amber.” It also repeated the department’s claim that models with “approximately 5 to 10 trillion” parameters make “rigorous analysis or auditing of its output mathematically impossible.” That is the department’s own assertion, quoted by the court. Neither opinion tests it.

Henderson spells out where this leads. Suppose the Secretary tells Anthropic’s replacement to allow whatever uses “the Department deems necessary” or be excluded the same way. Under the majority’s reading, she writes, that vendor must “agree to the Secretary’s demands or risk being designated a national security threat.” The designation then covers “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.” The Under Secretary who wrote the memorandum behind the exclusion, Emil Michael, reacted on X after the ruling: “Warfighters will sleep better knowing that no private company will insert their opinions in the chain of command.”

The ruling is narrower than that post suggests. Section 4713 is a procurement statute. It governs what the department buys and what its contractors use on department work. The majority notes that Anthropic itself does not dispute the department’s “fundamental prerogative” to choose its vendors. The August judgment, which covers the § 3252 designation and the directive barring contractors from any business with Anthropic, military or not, was not before the appeals court. The D.C. Circuit said that judgment does not bind it, and its own ruling does not touch it. The constitutional claims went the other way in Washington. The majority found no retaliation, holding that “the nub of this dispute was contractual.” It held that any flaw in skipping advance notice was harmless, because Anthropic’s later submissions had not changed the Secretary’s mind in June. Anthropic says it is “considering all options, including further review.” Pete Hegseth’s post on X read: “Confirmed: @AnthropicAI = Supply Chain Risk.”

A few days ago I wrote that renaming AI in executive orders changed no definition in force, because the operative definitions live in statutes that nobody had amended. This case is the reverse: nobody renamed anything, and one definition did all the work. Congress wrote “an adversary” into the defense provision that became § 3252 and “any person” into FASCSA in 2018. Henderson’s dissent traces the 2018 wording to intelligence-community warnings about hostile states and companies “beholden to foreign governments.” The majority rejects that history as a guide to what the words mean. Engineers who study these frameworks had read the statute her way. A 2025 review of military supply-chain risk frameworks in IEEE Access, by Ahn and colleagues, described FASCSA as addressing intentional threats only. If “any person … otherwise manipulate” is meant to exclude an American vendor for enforcing its own usage policy, the courts have now said the statute allows it. If Congress did not mean that, fixing it would take one amendment: add a motive requirement, or bring back the word “adversary.” Until then, any AI vendor with a usage policy sells to the Pentagon on the terms this ruling sets. Anyone following the department’s AI plans, including how it verifies what chatbots tell it, should expect that.

References

  1. U.S. Court of Appeals for the D.C. Circuit (2026). Anthropic PBC v. United States Department of War, No. 26-1049 (consolidated with No. 26-1162). Opinion of Katsas, J., joined by Rao, J.; Henderson, J., dissenting. Argued 19 May 2026, decided 25 September 2026. Also on CourtListener.
  2. U.S. District Court for the Northern District of California (2026). Anthropic PBC v. U.S. Department of War, No. 26-cv-01996-RFL, Order on Cross Motions for Summary Judgment. Lin, J., 27 August 2026 (Dkt. 250).
  3. 10 U.S.C. § 3252, Requirements for information relating to supply chain risk, definition at (d)(4). Legal Information Institute, accessed 25 September 2026.
  4. 41 U.S.C. § 4713, Authorities relating to mitigating supply chain risks in the procurement of covered articles, definition at (k)(6). Legal Information Institute, accessed 25 September 2026.
  5. 41 U.S.C. § 1327, Judicial review procedures. Legal Information Institute, accessed 25 September 2026.
  6. United States v. Fischer, 64 F.4th 329 (D.C. Cir. 2023) (Katsas, J., dissenting); Fischer v. United States, 603 U.S. 480 (2024). As discussed in reference 1.
  7. Defense One (2026). Anthropic loses legal fight to shed DOD’s designation as a ‘supply-chain risk’. 25 September 2026. Source for the Anthropic statement and Emil Michael’s post.
  8. ABC News (2026). Federal appeals court upholds Pentagon designation of Anthropic as supply chain risk. 25 September 2026. Source for Pete Hegseth’s post.
  9. Ahn, J. K. et al. (2025). Comprehensive Analysis and Recommendation of Supply Chain Risk Management Framework for the Military Domain. IEEE Access, 13, 96813–96833.