NEWS
A 2018 Sabotage Law Now Bars Claude From the Pentagon
A D.C. Circuit panel left Anthropic labeled a Pentagon supply chain risk for keeping Claude’s bans on autonomous weapons and domestic surveillance.
A 2-1 D.C. Circuit panel on September 25, 2026, left Anthropic labeled a Pentagon supply chain risk, so Claude stays off military systems. Circuit Judge Gregory Katsas wrote for the court, joined by Circuit Judge Neomi Rao. Circuit Judge Karen LeCraft Henderson dissented.
The Department of War, as the administration now calls the Pentagon, acted after Anthropic refused to drop contract limits on lethal autonomous warfare and domestic surveillance. Those limits, the majority said, were enough to treat further use of Claude as a covered national-security risk under a 2018 buying law written for sabotage of federal systems.
The D.C. Circuit Leaves One Blacklist Standing
The petitions in Anthropic PBC v. United States Department of War, Nos. 26-1049 and 26-1162, were argued on May 19 and denied on September 25. Katsas’s the D.C. Circuit majority opinion runs 43 pages. Henderson’s dissent runs 8.
Anthropic had called the exclusion arbitrary, beyond the statute, and unconstitutional. The panel rejected all three claims. Katsas and Rao were appointed in the first Trump administration. Henderson was appointed by President George H. W. Bush.
The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk.
Circuit Judge Gregory Katsas, D.C. Circuit, Anthropic PBC v. United States Department of War
The company encodes limits into Claude that stop tasks Anthropic wants to block, the court said, and those limits had more than once stopped Claude from doing work government users asked for. A later fight over whether the contract barred Claude in an ongoing overseas military operation left the Department unsure the model would perform as needed.
On process, the majority said the Department gave prompt notice and a fair chance to contest the exclusion. On speech, it said the Pentagon acted over a contract term it treated as essential, not over Anthropic’s support for tighter AI rules. “In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks,” Katsas wrote.
Charlie Bullock, a senior research fellow at the Institute for Law & AI, said the panel makeup made the result unsurprising, and that Anthropic’s chances would be better before the full D.C. Circuit or the Supreme Court, though those paths are discretionary. An Anthropic spokesperson said the company disagrees, remains confident, and is considering all options, including further review.
What the Residual Clause Now Covers
Secretary of War Pete Hegseth’s March 3, 2026, written finding used the Federal Acquisition Supply Chain Security Act of 2018, codified at 41 U.S.C. § 4713. That law lets an agency head bar a supplier from agency contracts and from subcontracts on agency work after finding that the step is needed to cut supply chain risk and that less intrusive measures are not reasonably available.
The section 4713 supply chain risk definition is the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate covered information technology so as to surveil, deny, disrupt, or otherwise manipulate how those products work. Review of a covered action sits only in the D.C. Circuit, on a petition filed within 60 days. The authority sunsets on December 31, 2033.
The Pentagon also used a separate Defense statute, 10 U.S.C. § 3252, whose Defense supply chain risk rules speak of an adversary who may sabotage or subvert a covered national security system. That is the designation a San Francisco court later wiped out. Friday’s panel left the 2018 civilian procurement law in place.
TWO STATUTES, TWO FORUMS
| Law | Who it names | Where it is reviewed | Status |
|---|---|---|---|
| FASCSA, 41 U.S.C. § 4713 | Any person who may sabotage, extract data, or otherwise manipulate covered IT | D.C. Circuit only, 60 days | Upheld September 25, 2-1 |
| 10 U.S.C. § 3252 | An adversary who may sabotage or subvert a covered national security system | N.D. Cal., case 3:26-cv-01996 | Vacated August 27 |
Henderson said the whole case turns on the leftover phrase “or otherwise manipulate.” Anthropic read it as sneaky, hostile acts. The majority read it more like turning a doorknob: moving or controlling the product, motive aside. She would have stopped there.
Congress passed the law after intelligence warnings that hostile states and other bad actors were getting into federal systems through suppliers, she wrote. That history, in her view, does not cover “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.” The majority refused to add a stealth requirement, and noted that the 2018 text covers “any person,” not only foreign firms.
Katsas also wrote that both sides had raised hard operational fears: models so constrained they fail mid-mission, and models so loose they hallucinate targets for lethal force. The court left the balance to the president and the secretary.
Anthropic Would Not Drop Two Claude Bans
Anthropic did not refuse military work as a category. In July 2025 the Department’s Chief Digital and Artificial Intelligence Office awarded prototype other-transaction deals with ceilings of up to $200 million each to Anthropic, OpenAI, Google, and xAI. Claude had already been used on classified systems. The break came when the Department demanded a new term, “any lawful use” or “all lawful uses,” and Anthropic kept two carve-outs.
Dario Amodei, Anthropic’s chief executive, said in a February 26 company statement that the firm would not agree to fully autonomous weapons or mass domestic surveillance of Americans, the two requested safeguards on Claude it still treats as non-negotiable. “We cannot in good conscience accede to their request,” he wrote. The company said present-day frontier models are not reliable enough to run fully autonomous weapons, and that mass domestic surveillance of Americans violates fundamental rights.
The opinion describes three layers of control: safety trained into the model, including a constitution Anthropic writes for Claude; technical monitors stacked on top because, as the company told the court, all models can be jailbroken; and contract bans. The Palantir Technologies usage policy in the record bars, among other things, using Claude to invade privacy, monitor people’s physical locations, or design weapons. Anthropic told the court those limits are “the very purpose for which our company was founded.”
It also told the court it had already dropped most other Department restrictions and was willing to go further, short of those two uses. Hegseth’s January 9, 2026, memo had directed the Department to buy models “free from usage policy constraints that may limit lawful military applications” and to put “any lawful use” language into Department contracts.
HOW THE DESIGNATION LANDED
- January 9, 2026: Hegseth directs the Department to drop usage-policy limits that may constrain lawful military applications.
- February 24, 2026: Hegseth meets Amodei and sets a February 27 afternoon deadline for “all lawful uses.”
- February 27, 2026: The deadline passes. Hegseth announces a supply-chain-risk designation. President Trump tells agencies to cease Anthropic use. OpenAI announces its own classified deal.
- March 3, 2026: Hegseth signs the written FASCSA finding, including that less intrusive measures are not reasonably available and that an urgent national-security interest requires immediate action.
- March 9, 2026: Anthropic files in the D.C. Circuit and in San Francisco.
- March 26, 2026: Judge Rita F. Lin grants a preliminary injunction on the 3252 track.
- August 27, 2026: Lin issues final relief vacating the 3252 designation.
- September 25, 2026: The D.C. Circuit denies the FASCSA petitions, 2-1.
Hegseth had accused Anthropic of trying to seize veto power over operational decisions of the United States military. Pentagon spokesman Sean Parnell said Friday’s ruling “completely validates the Department’s position.”
Seven Firms Took Classified Deals in May
OpenAI announced a classified-environment deal on February 28, the day after Anthropic’s deadline. Its post published all lawful purposes contract language that still claims three red lines: no mass domestic surveillance, no directing autonomous weapons, and no high-stakes automated decisions such as a social-credit system.
The contract says the Department of War may use the system “for all lawful purposes, consistent with applicable law, operational requirements, and well-established safety and oversight protocols,” and that the system will not independently direct autonomous weapons where law, regulation, or Department policy requires human control. A March 2 addendum added that the system “shall not be intentionally used for domestic surveillance of U.S. persons and nationals.” OpenAI said the deal is cloud-only, keeps its safety stack, and keeps cleared staff in the loop. It also said Anthropic should not be designated a supply chain risk.
On May 1 the Pentagon said it had reached classified-use agreements with seven companies, and Anthropic was not among them.
CLASSIFIED PARTNERS NAMED ON MAY 1
- Model labs: OpenAI, Google, and xAI, on top of the July 2025 prototype ceilings.
- Cloud and chips: Microsoft, Amazon, and Nvidia, which already sat inside Defense networks as hosts and hardware suppliers.
- New name: Reflection AI, a startup added in the same announcement.
- Missing: Anthropic, which had been the first lab with Claude cleared for classified work.
The July 2025 other-transaction ceilings and the May classified deployment pacts are separate instruments. The first four labs each had a $200 million prototype cap. The May list is about who may run models on classified nets under “lawful operational use.” Defense contractors that had been routing Claude through those nets, including work Anthropic had allowed with Palantir, now sit under the FASCSA bar for Department work.
Judge Lin Vacated the Parallel Order in August
The two statutes forced two lawsuits. In San Francisco, Judge Rita F. Lin treated the 10 U.S.C. § 3252 campaign as retaliation and as a debarment imposed without the process that statute and the Fifth Amendment require. On March 26 she blocked the February 27 Hegseth order and the presidential cease-use directive. On August 27 she converted that relief into a 59-page final judgment.
Lin granted Anthropic summary judgment in part on the First Amendment, due process, and Administrative Procedure Act claims tied to the 3252 designation. She declared that designation arbitrary, capricious, and in excess of statutory authority, then vacated, set aside, and remanded it. She wrote that the broad measures were “illegal and baseless,” and that “the empty invocation of national security is not a blank check to punish and retaliate against government critics.” An IT vendor, she wrote, does not become a potential adversary of the United States whenever it insists on particular contracting terms.
That judgment still stands on the 3252 track. Friday’s D.C. Circuit decision does not reverse Lin. It leaves a different label in force, under a different definition, in a court Congress made the exclusive forum for FASCSA fights. Anthropic’s spokesperson pointed to that split after the ruling: another federal court had already held the government’s parallel designation unlawful.
Amici in the D.C. Circuit included former Defense Secretary Leon Panetta, 149 former judges, the ACLU, and, in their personal capacities, employees of OpenAI and Google. The majority still deferred. Henderson would have read the residual clause against the Department and never reached the constitutional claims.
The Label Still Bars Claude on Defense Work
FASCSA does not, on its face, let a secretary ban all commercial activity with a supplier. Anthropic told customers in February that a 3252 label could reach Claude only as a direct part of Department of War contracts. Friday’s decision is the 2018 statute, which can bar Department contracts and the subcontracts that use the supplier to perform Department work. For anyone selling into those programs, that is still a hard stop on Claude.
WHERE THE LABEL REACHES NOW
- Department systems: Claude stays out of the Department of War supply chain under the March 3 FASCSA finding.
- Contractor work for the Department: Covered subcontracts that would use Anthropic to perform that work remain off limits.
- The 3252 overlay: Lin’s August 27 order still vacates the separate adversary-sabotage designation and the broader secondary boycott that came with it.
- Further review: Anthropic is weighing an en banc petition or Supreme Court review. Neither is automatic.
On Friday evening Hegseth posted a short confirmation that quoted Assistant Attorney General Brett Shumate’s note on the ruling.
Confirmed: @AnthropicAI = Supply Chain Risk.
The @DeptofWar does what is right for the Country and our Warriors. https://t.co/xERtGRh6Kc
— Pete Hegseth (@PeteHegseth) September 25, 2026
The thread under that post treated the case as a fight over who writes the rules for lawful military use, not as a claim that Claude is a weak model. That is also the fight Henderson isolated in the statute. Under this panel’s reading, a vendor that says up front what its product will not do can still be frozen out of Defense work if the secretary finds those limits disable lawful tasks.
Two days before the opinion, on September 23, Amodei briefed the U.N. Security Council by video and asked governments to start with narrow bans, including on AI-assisted biological weapons. “If managed poorly, I even believe that AI could be a risk to humanity as a whole,” he said. On September 25 the D.C. Circuit held that his company’s own published limits on Claude were a supply chain risk to the Pentagon.
Disclaimer: This article is news reporting on a court decision and related government contracting actions. It is informational only and is not legal advice, is not a prediction of how later courts will rule, and is not a recommendation to enter, exit, or structure any government contract or commercial relationship. Readers who need advice on procurement, litigation, or compliance should consult a qualified attorney licensed in the relevant jurisdiction. Figures, docket statuses, and contract terms reflect the public court opinions, statutes, and company statements described above and may change if Anthropic seeks further review or if the Department revises its findings.
-
NEWS3 weeks agoTrend Micro’s AI Boom Cuts Its 2026 Operating Profit
-
NEWS3 weeks agoAn Oral DHB Prodrug Clears Mouse Tumors With PD-1
-
NEWS4 weeks agoApple Freezes the iOS 27 Public Beta Before the Event
-
NEWS3 weeks agoUS-China AI Safety Talks Rest on a No-New-Law Pact
-
NEWS3 weeks agoGPT-6 Astra Ships as OpenAI’s Scientist Urges Caution
-
NEWS3 weeks agoBell Wins the Southern 500 and Closes to 12 Points
-
NEWS3 weeks agoHafner Bets World Models Can Skip the Robot Data War
-
NEWS3 weeks agoAI Notetaker Suits Leave Meeting Hosts Holding the Risk
