2-1 for the Pentagon: D.C. Circuit Upholds Anthropic's Blacklist, and the Constitutional Fight Is Just Beginning
A three-judge panel ruled 2-1 that the Pentagon acted within its authority when it blacklisted Anthropic for refusing to lift Claude's safety guardrails — but the same day, a parallel case in San Francisco still says the designation is illegal. Inside the split-brain legal war over who controls AI safety.
On Friday, September 25, 2026, a federal appeals court panel in Washington, D.C. upheld the Pentagon’s blacklisting of Anthropic, dealing the most serious legal blow yet to the AI company in its months-long confrontation with the Trump administration over who gets to set safety limits on frontier AI models.
The 2-1 decision by the U.S. Court of Appeals for the D.C. Circuit rejected Anthropic’s argument that the Department of Defense’s ban on its Claude models was arbitrary, unauthorized, and unconstitutional. Judge Gregory Katsas, writing for the majority joined by Judge Neomi Rao — both appointed by President Donald Trump — found the Pentagon had acted within its statutory bounds. Judge Karen LeCraft Henderson, appointed by former President George H.W. Bush, dissented.
Yet in an irony that defines this entire dispute, the ruling landed while a parallel case in California still says the exact opposite: just weeks earlier, a federal judge in San Francisco held the government’s other designation against Anthropic to be illegal. Two courts, two designations, two contradictory answers to the same question — and the case now appears headed for either an en banc rehearing or the Supreme Court.
What the ruling actually says
At the center of Friday’s decision is the Pentagon’s March 2026 designation of Anthropic as a “supply chain risk” — a label asserting the company threatens U.S. national security. The practical effect is severe: the U.S. military cannot use Anthropic’s models, and defense contractors are blocked from using them in their work with the agency.
The majority opinion, written by Judge Katsas, was direct about where it thought the balance lies. “The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk,” he wrote.
Katsas emphasized the specific concerns Defense Secretary Pete Hegseth raised when justifying the designation: the “deeply sobering” possibility that “overly constrained” AI models could shut down unexpectedly at critical moments, and the potential that Claude might be “subject to manipulation.” Anthropic disputed both claims. But the panel’s answer was that these are judgment calls the courts should not second-guess: “In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution.”
For Anthropic, the structural lesson is uncomfortable. Its constitutional and administrative-law challenges rest on the claim that the government punished it for protected conduct — refusing to lift safety guardrails. The D.C. Circuit’s majority essentially reframed the dispute as an ordinary procurement decision: the government may decline to buy from a vendor whose product terms it finds unacceptable, and that choice gets heavy deference.
How two courts ended up answering the same question differently
The strangest feature of this dispute is its procedural geometry. When the dispute erupted, the DOD relied on two distinct designations to justify its supply chain risk action — a bifurcation that forced the litigation into two separate courts.
The first track ran through San Francisco. In March 2026, Judge Lin granted Anthropic a preliminary injunction, blocking one of the designations; that injunction was later stayed for seven days, making the designation effective as of April 2, 2026. Anthropic’s fight to undo it continued, and on August 27–28, 2026, the court ruled the designation was illegal and violated the First Amendment — a major win that suggested the government had unlawfully retaliated against the company for its safety stance.
The second track ran through Washington. On April 8, 2026, the D.C. Circuit had already declined to block the other designation once, denying Anthropic’s request for a stay while acknowledging the company “will likely suffer some degree of irreparable harm absent a stay.” Friday’s ruling resolves that track — against Anthropic.
So as of this weekend, the United States has one appellate court saying the Pentagon acted lawfully and one district court having said the opposite about the parallel designation, with the government’s appeal of the San Francisco ruling still pending. Anthropic’s statement after the D.C. ruling leaned hard on that contradiction: “We respectfully disagree with the court’s decision. Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review.”
The panel itself acknowledged the fight isn’t over. It said it would delay the decision from taking immediate effect, giving Anthropic time to petition the same panel for a rehearing, seek an en banc rehearing before all the judges of the D.C. Circuit, or ask the Supreme Court to take the case.
The backstory: a $200 million partnership that curdled
The blacklist is the endpoint of a relationship that began as a showcase for military AI adoption. Anthropic signed a $200 million contract with the Pentagon in July 2025, making Claude an early partner across many U.S. agencies. But when the company began negotiating Claude’s deployment on the DOD’s GenAI.mil AI platform that September, talks collapsed.
The sticking point was fundamental. The DOD wanted Anthropic to grant the military unfettered access to its models across all lawful purposes. Anthropic wanted assurance that its technology would not be used for fully autonomous weapons or domestic mass surveillance. Neither side would budge, and Hegseth accused Anthropic of attempting to “seize veto power over the operational decisions of the United States military.”
Since then the feud has been personal as well as legal. President Trump has repeatedly attacked CEO Dario Amodei on social media, writing on Truth Social on Monday: “The Trump Administration has stopped AI ‘people’ from doing bad, or potentially bad, ‘things,’ like Dario (Anthropic!), who is now pretending to be a ‘perfect little angel’ — and we will continue to do so!”
The political pressure has only intensified alongside Amodei’s higher profile. His recent essay “We Must Pace the Frontier” — a call for an industry-wide slowdown with independent evaluators inside frontier AI companies — drew agreement from Sam Altman and Elon Musk, and conspicuously cost him an invitation to the White House state dinner for Chinese President Xi Jinping on Thursday.
Why this matters beyond Anthropic
The commercial stakes for Anthropic are real but survivable; the precedent is the bigger story.
The guardrails question is now a constitutional one. Every frontier lab attaches usage policies to its models. The D.C. Circuit’s ruling implies the executive branch can, via supply chain security authority, effectively exclude a vendor from the entire defense ecosystem for declining to remove those policies — while framing the exclusion as a routine sourcing decision entitled to deference. If that reading survives en banc and Supreme Court review, it hands the government a powerful lever over AI companies’ terms of service, at least in the defense context.
It tests whether “safety” is speech or mere commerce. The San Francisco court’s First Amendment reasoning treated Anthropic’s guardrail refusals as protected conduct the government cannot punish. The D.C. panel treated the same facts as procurement preference. Which framing wins may determine whether AI companies can credibly promise “red lines” to the public and to their own employees without risking federal retaliation.
It reshapes the market for defense AI. With Claude excluded, rival models — OpenAI’s ChatGPT and xAI’s Grok were both already live on GenAI.mil by late August — face less competition for one of the world’s largest AI customers. Contractors who preferred Claude’s architecture now must re-plan around the blacklist continuing indefinitely.
It arrives at a moment of peak AI-politics convergence. The same week as the ruling, CEOs of OpenAI, Anthropic and Hugging Face briefed the UN Security Council, a New York antitrust suit over the labs’ coordinated “slowdown” agreement advanced, and the White House prepared to host AI CEOs for a summit. The D.C. Circuit’s decision is another data point in a larger argument about whether the AI industry can govern itself, or whether the state will do it for them.
What happens next
Anthropic’s immediate options are a panel rehearing, an en banc rehearing before the full D.C. Circuit, or a cert petition to the Supreme Court. The stay of the mandate gives it breathing room to choose. Meanwhile, the government’s appeal of the San Francisco First Amendment ruling is still alive, meaning the two-track litigation could yet produce a true circuit-level conflict — historically one of the strongest signals that the Supreme Court will step in.
For now, the blacklist stands, one court’s blessing deeper. But the core question — can an AI company say no to its government over how its models are used, and survive the consequences — remains exactly as unsettled as it was on Friday morning.
Sources
- [1] https://www.cnbc.com/2026/09/25/pentagon-anthropic-ai-risk-appeals-court.html
- [2] https://www.reuters.com/world/us-appeals-court-declines-block-pentagons-blacklisting-anthropic-2026-09-25/
- [3] https://www.reuters.com/world/how-anthropic-pentagon-dispute-over-ai-safeguards-escalated-2026-09-25/
- [4] https://www.aljazeera.com/economy/2026/9/25/us-court-upholds-pentagons-blacklisting-of-anthropic
- [5] https://en.wikipedia.org/wiki/Anthropic%E2%80%93United_States_Department_of_Defense_dispute
- [6] https://www.casemine.com/judgement/us/69d7a12830a7ea52b0982378
- [7] https://www.congress.gov/crs-product/IN12669