The U.S. Court of Appeals for the D.C. Circuit upheld the Department's procurement exclusion of Anthropic's Claude for Department work and its contractor chain. The decision matters because the majority held that enforceable model restrictions can qualify as a supply-chain reliability concern even when a supplier says those restrictions are good-faith safety measures. It is a procurement ruling, not a blanket ban on Anthropic or a finding that Claude is generally unreliable.
Key facts
- The September 25, 2026 decision was a 2–1 merits ruling denying Anthropic's petitions for review.
- It rests on the Federal Acquisition Supply Chain Security Act authority in 41 U.S.C. §4713.
- The court says the Department was “uncertain whether Claude would perform as needed and intended.”
- Primary source: the D.C. Circuit opinion, No. 26-1049.
The case grew out of a clash between the Department's desire for “all lawful uses” of an AI system and Anthropic's restrictions on lethal autonomous warfare and mass surveillance of Americans. The public opinion describes a disagreement over an overseas military operation but does not identify it and says it cannot know every underlying fact. Anthropic characterized the dispute as a misunderstanding; the government portrayed it as a serious operational risk.
The court's careful wording matters. It did not say Claude is unreliable in general, that Anthropic sabotaged a system, or that the company maintained a remote kill switch. Its narrower account is that restrictions built through training, technical interventions, model updates, and contracts could make the Department unsure whether an integrated system would perform a function it considered necessary. The majority quotes concern that a critical system might “fail[] to engage.”
That finding arose under a specific statute. Section 4713 lets the government exclude sources from covered procurements, proposal evaluation, or subcontracting when a supply-chain risk is found. It covers software, information technology, and cloud-computing services, but it does not automatically reach every buyer of a provider's service. The decision describes the practical boundary as Department systems, contracts, and contractor or subcontractor work performed for the Department. This is why a claim that “Bedrock is illegal” or that every commercial Anthropic relationship ended would be wrong. The opinion never mentions Amazon Bedrock.
The majority's legal mechanism is broader than a common shorthand suggests. It read “otherwise manipulate” in the statute to include arranging, operating, or controlling a product's function without requiring bad motive. The judges accepted that Anthropic's intent could be safety- and privacy-driven while still finding that the Department may treat a possible functional refusal as procurement risk. The court also distinguished a separate California ruling under 10 U.S.C. §3252, where language about an adversary and subversion led to a narrower result. Same political confrontation, different statutory definitions.
Anthropic's own pre-ruling statement framed the conflict differently. The company said its red lines were limited, that unrelated commercial business should not be affected, and that it would challenge a designation. The new ruling is more damaging than a preliminary stay denial because it resolves the merits in the government's favor at this appellate level. The public sources reviewed in the dossier did not establish a subsequent en banc petition, Supreme Court filing, or new Department statement.
Judge Henderson's dissent is the strongest counterargument and the part future suppliers will study. She argued that “manipulate” should be read alongside concepts such as sabotage, maliciously inserted functionality, surveillance, denial, and disruption. On that reading, a company enforcing a published safety restriction is not the sort of hostile supply-chain actor Congress meant to target. Her warning is practical: if a vendor's refusal to enable a requested use is enough, any frontier lab that retains policy limits could face pressure to remove them or risk exclusion.
The majority's response is also practical. The Department is not required to buy a component it believes could decline a required mission function, and national-security procurement receives considerable deference. For a military buyer, the distinction between an intentional safety boundary and a failure mode may not matter if the relevant system needs the function at a critical moment. In that sense, the case makes a safety policy part of a vendor's reliability profile.
The business implication is not that safety commitments are impossible in government markets. It is that labs will need clearer separation between civilian and government offerings, frozen versions, explicit acceptance tests, scoped credentials, human authorization, and contract language describing what a deployed model can and cannot do. Those measures cannot erase the underlying political question: who gets final authority over a model's permitted use?
The ruling is therefore a precedent about governance architecture more than a verdict on one model's intelligence. It says that a model supplier's continuing ability to shape behavior before delivery or through later versions can be material to procurement. The dissent says that theory risks converting a refusal to participate in harmful conduct into evidence of threat. Both positions are now on the record, and every AI company selling into sensitive government systems has reason to design—and document—its safety controls with this legal exposure in mind.
Originally published on Ground Truth, where every claim is checked against the primary source.
Top comments (0)