Skip to main content
Live
Main content

DC Circuit upholds Trump blacklist of Anthropic in 2-1 ruling

Appeals court says Pentagon can designate Anthropic a supply chain risk for restricting Claude features, even absent malicious intent.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

The US Court of Appeals for the District of Columbia Circuit ruled 2-1 on September 25, 2026 that the Trump administration can blacklist Anthropic as a supply chain risk for refusing to enable certain Claude features requested by the Pentagon. The decision upholds an order from Defense Secretary Pete Hegseth barring federal agencies and defense contractors from doing business with Anthropic, and it splits directly with a Northern District of California ruling last month that found the same blacklisting illegal.

The majority opinion said the case "raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology." The court framed the dispute as a balance between "overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail" and "unconstrained AI models hallucinating inappropriate targets for lethal military force."

Judges Gregory Katsas and Neomi Rao, both Trump appointees who served in his first administration, ruled that Hegseth "did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution." The same panel denied Anthropic's emergency motion for a stay in April 2026.

Key facts

  • 01The DC Circuit ruled 2-1 on September 25, 2026 that the Trump administration can blacklist Anthropic as a supply chain risk.
  • 02The appeals court found bad motive is not required under 41 U.S.C. § 4713, the broader of two statutes at issue.
  • 03A Northern District of California judge ruled the parallel blacklisting illegal last month under 10 U.S.C. § 3252.
  • 04Both judges in the majority — Gregory Katsas and Neomi Rao — were appointed by Trump and served in his first administration.
  • 05Anthropic sued in March 2026 after Hegseth ordered federal agencies and defense contractors to stop doing business with the company.

The split between the two courts turns on which statute applies. The California district court, presided over by Biden appointee Judge Rita Lin, reviewed the designation under 10 U.S.C. § 3252, which limits supply chain risks to malicious actions by adversaries. The DC Circuit reviewed the same action under 41 U.S.C. § 4713, a broader statute where Congress granted the appeals court exclusive jurisdiction to review procurement decisions.

The majority wrote that it had "no quarrel" with the district court's conclusion that section 3252 requires bad motive, and no quarrel with the finding that Anthropic "acted with no such bad motive." But it held that "no such bad motive is required to support a designation under the much broader definition set forth in section 4713." The definition covers "any person" who may manipulate covered technology, not just foreign adversaries.

“We respectfully disagree with the court's decision”
— Anthropic spokesperson, Anthropic

Anthropic told CNBC it "respectfully disagrees with the court's decision" and pointed to the parallel California ruling in its favor. "We remain confident in our position and are considering all options, including further review," a spokesperson said. The company can seek an en banc rehearing before the full DC Circuit or petition the Supreme Court.

The underlying dispute stems from restrictions Anthropic encodes into Claude to prevent uses it disallows, including lethal autonomous warfare and mass surveillance. The appeals court noted that "on more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users," and that a recent dispute arose over whether contractual prohibitions barred Claude's use in an ongoing overseas military operation. Anthropic sued in March 2026 after Trump and Hegseth issued the blacklist order.

Judge Karen Henderson, a George H.W. Bush appointee, dissented. She argued the section 4713 verbs, read in context, target "deliberately impeding or eavesdropping on the 'function, use, or operation' of a covered article," and that Congress passed the statute to counter "[h]ostile nation state and other bad actors" infiltrating federal supply chains — not to cover "a contractor's honest and upfront enforcement of restrictions on a covered article's use disfavored by the government."

“The empty invocation of national security is not a blank check to punish and retaliate against government critics”
— Rita Lin, US District Judge, Northern District of California
Related · from this week
Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation
Jaeden Schafer · 5 min read →

Judge Lin's California ruling had gone further, finding the blacklisting violated the First Amendment as retaliation against Anthropic for refusing to drop its use restrictions. The DC Circuit did not reach that question, ruling only on the statutory authority under section 4713. The two decisions now stand in direct tension, setting up a likely path to further appellate review.

The commercial picture is more ambiguous than the litigation suggests. Commerce Secretary Howard Lutnick recently said the Trump administration and Anthropic have patched up their relationship and are "in tune," even as the court fight continues. Anthropic's founders are separately pursuing 50.1% voting control ahead of a potential IPO, and the company signed an $11.6B cloud deal with Akamai last month.

The ruling gives the Pentagon a workable legal theory to police how AI vendors write their acceptable-use policies, at least within the DC Circuit's reading of section 4713. For frontier labs that maintain hard restrictions on military and surveillance uses — a category that includes Anthropic by design and, to varying degrees, OpenAI and Google — the decision means those restrictions can now themselves be treated as a procurement risk. The Supreme Court may ultimately have to reconcile the split, but until it does, the practical leverage in vendor-Pentagon negotiations has shifted.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Judge strikes down Pentagon's Anthropic blacklist as illegal retaliation

A federal judge vacated the Department of Defense's supply-chain risk designation, calling the sanctions across nine agencies baseless and unconstitutional.

Jaeden Schafer5 min read
Anthropic logo
Security

AI warfare is already here as Anthropic fights Pentagon over autonomous weapons

The DOD has embedded AI in military operations for 70 years; fully autonomous lethal systems remain the final frontier.

Jaeden Schafer5 min read
Anthropic logo
Business

Anthropic hits near-$1T valuation while warning AI could destroy the world

Founded in 2021 by OpenAI defectors, Anthropic now sells Claude to the Pentagon and argues that dominating AI is the only way to make it safe.

Jaeden Schafer5 min read