US AI regulation

The D.C. Circuit's Anthropic Ruling Lets Procurement Law Punish Disclosed Safety Limits, and Congress Should Narrow It

A 2-1 D.C. Circuit ruling reads a 2018 supply-chain law to cover a vendor's openly stated AI use restrictions, a scope Congress should clarify.

Anthropic v. Department of War at a glance People of Internet Research · US 2-1 D.C. Circuit panel vote Judge Henderson dissented from the… 2018 Year FASCSA enacted Enacted as Title II of the SECURE … 30 Days to respond to notice Sources get 30 days to oppose an e… peopleofinternet.com
Anthropic v. Department of War at a gl… People of Internet Research · US 2-1 D.C. Circuit panel vote 2018 Year FASCSA enacted 30 Days to respond to notice peopleofinternet.com

Key Takeaways

On September 25, 2026, the D.C. Circuit denied Anthropic's petitions for review in Anthropic PBC v. United States Department of War, No. 26-1049. The court upheld the Pentagon's decision to treat Claude as a national-security supply-chain risk. The vote was 2-1, with Judge Karen LeCraft Henderson dissenting, according to ABC News. The Pentagon's dispute with Anthropic began because the company would not let Claude be used for mass surveillance of Americans or for lethal autonomous weapons. The result gives every AI vendor a reason to reconsider what it writes into its usage policies.

The strongest case for the Pentagon

The government's position deserves a fair statement. A military that runs on software cannot have a supplier decide, mid-operation, which lawful missions its tools will support. Model-level refusals are baked into the system in a way a contract clause is not, and a commander cannot negotiate with a model in the field. The majority accepted this logic. It found the department had enough evidence to conclude that Claude's built-in restrictions, combined with the unresolved contract dispute, could make it unreliable for military operations. The court also rejected Anthropic's free-speech and due-process claims.

That is a legitimate procurement concern. The Defense Department is entitled to buy tools that do what it needs, and to walk away from ones that do not.

What the ruling actually does

The designation rests on the Federal Acquisition Supply Chain Security Act of 2018, which is Title II of the SECURE Technology Act, Public Law 115-390. That law lets the Secretaries of Homeland Security and Defense, and the Director of National Intelligence, issue exclusion and removal orders covering their own systems. The statute's process protections include notice to the affected source and 30 days to respond, and recommendations must address the less intrusive measures that were considered.

As reported, Judges Katsas and Rao read the statute broadly. Their opinion said the Department had "ample support" to conclude that continued integration of Claude into its information systems, by the Department or its contractors, presented a statutorily covered national-security risk. Coverage of the opinion says that under this reading good intent is irrelevant, and what matters is what a contractor's product, as designed, prevents the government from doing.

The key point is that a vendor's restriction was fully disclosed. Nothing was hidden or sabotaged. Anthropic stated its limits, the government objected, and the limits were then recast as a security threat.

Judge Henderson's dissent addressed this directly. She wrote that the law does not treat "a contractor's honest and upfront enforcement of restrictions" as the kind of supply-chain risk that justifies blacklisting. She also argued that Congress aimed at hostile or deceptive interference with government technology, such as foreign-government and malicious-actor threats. Her warning about the incentive effect was plain: future vendors will face a simple choice between agreeing to the Secretary's demands and risking designation as a national-security threat.

The apparent conflict is partly a statutory split

The ruling is often described as contradicting the district court, but the two cases are less directly opposed than that framing suggests. On August 27, 2026, Judge Rita Lin of the Northern District of California ordered a designation under a different statute, 10 U.S.C. § 3252, removed. She found the Defense Department's actions "constituted unlawful retaliation in violation of the First Amendment", according to the Electronic Frontier Foundation's summary. ABC reports she found the actions were based on a desire to make a public example of Anthropic.

So one court found retaliation under one statute, and another found sufficient grounds under a different statute. The D.C. Circuit majority, as reported, treated the FASCSA designation as a response to Anthropic's contractual refusal, not to its viewpoint, even though the Secretary had publicly criticized the company's rhetoric. Both outcomes can stand at once. That is the problem. The government now holds two overlapping tools, and the one that survived review is the one with the lower bar.

Why this matters for innovation and speech

The pro-innovation case for a narrower reading rests on three points.

None of this requires the Pentagon to accept Anthropic's terms. It requires only that the tool for punishing a vendor be matched to the harm, which is the proportionality principle we apply to regulation of the private sector too.

What should happen next

Anthropic can seek rehearing en banc or Supreme Court review, and the divergence between the D.C. Circuit's reading and the district court's is the kind of tension those courts resolve. But litigation is a slow and uncertain fix. Congress wrote FASCSA in 2018 with foreign adversaries in mind, and it should say so. Three amendments would do the job: define "supply chain risk" to require deception, sabotage, or adversary control; state that a vendor's disclosed, contractually stated use restrictions are a matter for procurement negotiation and not for exclusion orders; and require the notice-and-response process to include a written statement of why less intrusive measures, such as choosing another supplier, were insufficient.

The government should be able to buy AI that fits its missions. It should not be able to treat a company's stated principles as a national-security defect, because vendors will respond by keeping their principles to themselves.

Sources & Citations

  1. Anthropic PBC v. Department of War, No. 26-1049 (D.C. Cir.), GovInfo record
  2. SECURE Technology Act, Pub. L. 115-390 (includes FASCSA)
  3. ABC News: appeals court upholds Pentagon designation
  4. EFF: Judge Rules DOD Unlawfully Retaliated Against Anthropic
  5. Tech Times: ruling analysis