On 27 August, a federal judge in San Francisco set aside the Pentagon’s designation of Anthropic as a supply chain risk. On 25 September, a federal appeals court in Washington upheld the Pentagon’s exclusion of Anthropic as a supply chain risk. The headlines say the second ruling overturned the first. It did not.
The two courts were not looking at the same decision. They were looking at two decisions made under two statutes, and the statutes define “supply chain risk” in words that differ by only a handful of terms. Read side by side, the rulings barely disagree about the facts. The D.C. Circuit says it has “no quarrel” with the district court’s finding that Anthropic acted without bad motive. It ruled against Anthropic anyway, because the statute in front of it doesn’t ask about motive.
Disclosure: I use Anthropic’s models, Claude among them, in my own work. I have tried to stay with what the two opinions say.
One dispute, two statutes
The facts that follow are taken from the two opinions. Anthropic had sold Claude into defense work through contractors since 2024 and was part of a $200 million Department of Defense AI contract awarded in July 2025. Over time it loosened its usage policy for national-security customers. The majority opinion lists the uses it came to allow: designing weapon systems, analyzing foreign intelligence, offensive cyber operations. Two prohibitions stayed: “lethal autonomous warfare” and “mass surveillance of Americans.” On 9 January 2026, Secretary Pete Hegseth’s AI strategy directed the department (now styling itself the Department of War) to write “any lawful use” language into AI contracts. On 24 February he gave Dario Amodei until 27 February to agree to it. Amodei refused publicly on 26 February. On 27 February President Trump and Hegseth denounced the decision on social media, and Hegseth began removing Claude from the department’s supply chain.
On 3 March Hegseth signed a formal determination under the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA), 41 U.S.C. § 4713. Three days later the department’s chief information officer ordered Anthropic products removed from its systems “as soon as practical” and within 180 days, and barred contractors from using them in department work. Separately, according to Judge Rita Lin’s order, the department designated Anthropic under an older defense statute, 10 U.S.C. § 3252, and a directive told defense contractors to stop doing any business with Anthropic, military or not.
The two statutes send challenges to different courts. FASCSA gives the D.C. Circuit exclusive jurisdiction over its procurement actions and bars review anywhere else (41 U.S.C. § 1327). Anthropic therefore filed two cases on 9 March: a petition for review in the D.C. Circuit over the § 4713 action, and a suit in the Northern District of California over the rest.
The words that differ
Here are the two definitions. Everything the courts disagreed about is in the differences.
Judge Lin, reading § 3252, held that the designation broke the statute and was arbitrary and capricious. She also held that it was unconstitutional retaliation for Anthropic’s public criticism, and that Anthropic had been denied the process it was due. Her description of the record was blunt: “The record is slim. A four-page memorandum, which post dates two of the three challenged actions, provides the entirety of the government’s rationale.” In her account, the government had dropped the claim that Anthropic kept backdoor access to deployed models and conceded that its technology is no riskier than “any other ‘black box’” AI model. She ended: “The empty invocation of national security is not a blank check to punish and retaliate against government critics.”
Writing for the D.C. Circuit, Judge Gregory Katsas accepted most of that. He wrote that the court had “no quarrel” with the district court’s conclusion that the word adversary, together with “the sinister connotation fairly pervading” sabotage, maliciously introduce and otherwise subvert, means § 3252 requires bad motive. He also had “no quarrel” with the finding that Anthropic had none. Then: “no such bad motive is required to support a designation under the much broader definition set forth in section 4713.”
“Manipulate,” two ways
The majority takes manipulate in its plainest dictionary sense: “to move, arrange, operate, or control by the hands … or by mechanical means.” In that sense, training a model to refuse a class of request is manipulating the model’s design. On that reading the court says there is “not only a ‘risk’—but a certainty—that Anthropic will so manipulate the ‘design’ or ‘operation’ of Claude to deny it the ‘function’ of conducting lethal autonomous warfare or mass domestic surveillance.” The paragraph that decides the case is short:
Judge Karen LeCraft Henderson’s dissent reads the same word by the company it keeps. Sabotage and malicious introduction are hostile acts. A catch-all at the end of that list should mean the Oxford sense, “to manage, control, or influence in a subtle, devious, or underhand manner.” She illustrates with a sign for a library: “Do not shout, loudly talk on the phone, play music, or otherwise disturb others.” Nobody reads that sign as banning headphones. The majority answers that “maliciously” modifies only the verb next to it, and that “extract data” is a fair example of manipulation whether or not it is done with malice.
The two sides of this argument have an odd history. In 2023, in United States v. Fischer, Judge Katsas wrote a dissent urging that a residual “otherwise” clause in the January 6 obstruction statute be read narrowly, in light of the specific acts listed before it. The Supreme Court adopted that reading in 2024. Henderson’s dissent quotes Katsas’s Fischer dissent back at him several times. His majority opinion concedes that her arguments “have some force.” It distinguishes Fischer on several grounds: that statute was criminal, a broad reading would have made most of its list redundant, and it would have reached protected speech. A procurement statute about national security, the majority says, calls for “the opposite interpretive presumption.”
What the reasoning reaches
The majority’s facts are specific to Anthropic, and I think they reach well beyond it. Its evidence of risk was that Anthropic trains Claude to refuse certain tasks and that the training works. It cites two episodes. Early commercial versions of Claude refused tasks such as summarizing threat assessments and processing classified documents. And the department learned in 2025 that Claude had refused queries from the CDC about infectious-disease research. The third piece of evidence was a dispute in early 2026 over whether the contract barred Claude’s use in an overseas military operation. The department calls it a near-disaster and Anthropic a misunderstanding, and the court says it does not know exactly what happened. The court wrote that the point “is not that these model or usage restrictions were arbitrary.” The point is that “Anthropic’s model training does effectively enforce contractual usage restrictions.”
Nearly every frontier model is trained to refuse something. Under this reading, a model becomes a supply chain risk by working as its maker intended, whenever the maker’s intentions and the buyer’s differ. The majority also closes off the obvious fix. Anthropic argued that the department could test each new model before accepting it and keep the old one if the new one refused too much. The court’s answer was that “the Department cannot utilize AI systems that remain trapped in amber.” It also repeated the department’s claim that models with “approximately 5 to 10 trillion” parameters make “rigorous analysis or auditing of its output mathematically impossible.” That is the department’s own assertion, quoted by the court. Neither opinion tests it.
Henderson spells out where this leads. Suppose the Secretary tells Anthropic’s replacement to allow whatever uses “the Department deems necessary” or be excluded the same way. Under the majority’s reading, she writes, that vendor must “agree to the Secretary’s demands or risk being designated a national security threat.” The designation then covers “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.” The Under Secretary who wrote the memorandum behind the exclusion, Emil Michael, reacted on X after the ruling: “Warfighters will sleep better knowing that no private company will insert their opinions in the chain of command.”
The ruling is narrower than that post suggests. Section 4713 is a procurement statute. It governs what the department buys and what its contractors use on department work. The majority notes that Anthropic itself does not dispute the department’s “fundamental prerogative” to choose its vendors. The August judgment, which covers the § 3252 designation and the directive barring contractors from any business with Anthropic, military or not, was not before the appeals court. The D.C. Circuit said that judgment does not bind it, and its own ruling does not touch it. The constitutional claims went the other way in Washington. The majority found no retaliation, holding that “the nub of this dispute was contractual.” It held that any flaw in skipping advance notice was harmless, because Anthropic’s later submissions had not changed the Secretary’s mind in June. Anthropic says it is “considering all options, including further review.” Pete Hegseth’s post on X read: “Confirmed: @AnthropicAI = Supply Chain Risk.”
A few days ago I wrote that renaming AI in executive orders changed no definition in force, because the operative definitions live in statutes that nobody had amended. This case is the reverse: nobody renamed anything, and one definition did all the work. Congress wrote “an adversary” into the defense provision that became § 3252 and “any person” into FASCSA in 2018. Henderson’s dissent traces the 2018 wording to intelligence-community warnings about hostile states and companies “beholden to foreign governments.” The majority rejects that history as a guide to what the words mean. Engineers who study these frameworks had read the statute her way. A 2025 review of military supply-chain risk frameworks in IEEE Access, by Ahn and colleagues, described FASCSA as addressing intentional threats only. If “any person … otherwise manipulate” is meant to exclude an American vendor for enforcing its own usage policy, the courts have now said the statute allows it. If Congress did not mean that, fixing it would take one amendment: add a motive requirement, or bring back the word “adversary.” Until then, any AI vendor with a usage policy sells to the Pentagon on the terms this ruling sets. Anyone following the department’s AI plans, including how it verifies what chatbots tell it, should expect that.
References
- U.S. Court of Appeals for the D.C. Circuit (2026). Anthropic PBC v. United States Department of War, No. 26-1049 (consolidated with No. 26-1162). Opinion of Katsas, J., joined by Rao, J.; Henderson, J., dissenting. Argued 19 May 2026, decided 25 September 2026. Also on CourtListener.
- U.S. District Court for the Northern District of California (2026). Anthropic PBC v. U.S. Department of War, No. 26-cv-01996-RFL, Order on Cross Motions for Summary Judgment. Lin, J., 27 August 2026 (Dkt. 250).
- 10 U.S.C. § 3252, Requirements for information relating to supply chain risk, definition at (d)(4). Legal Information Institute, accessed 25 September 2026.
- 41 U.S.C. § 4713, Authorities relating to mitigating supply chain risks in the procurement of covered articles, definition at (k)(6). Legal Information Institute, accessed 25 September 2026.
- 41 U.S.C. § 1327, Judicial review procedures. Legal Information Institute, accessed 25 September 2026.
- United States v. Fischer, 64 F.4th 329 (D.C. Cir. 2023) (Katsas, J., dissenting); Fischer v. United States, 603 U.S. 480 (2024). As discussed in reference 1.
- Defense One (2026). Anthropic loses legal fight to shed DOD’s designation as a ‘supply-chain risk’. 25 September 2026. Source for the Anthropic statement and Emil Michael’s post.
- ABC News (2026). Federal appeals court upholds Pentagon designation of Anthropic as supply chain risk. 25 September 2026. Source for Pete Hegseth’s post.
- Ahn, J. K. et al. (2025). Comprehensive Analysis and Recommendation of Supply Chain Risk Management Framework for the Military Domain. IEEE Access, 13, 96813–96833.