D.C. Circuit Holds in Anthropic v. Department of War That AI Use Limitations Are A Security Risk

The article examines the divided D.C. Circuit decision concerning Anthropic’s supply chain exclusion. It considers model-enforced use restrictions, the statutory disagreement and the possible consequences for government technology vendors.

D.C. Circuit Holds in Anthropic v. Department of War That AI Use Limitations Are A Security Risk

D.C. Circuit Holds in Anthropic v. Department of War That Enforcing AI Use Limits Can Make a Vendor a Supply Chain Risk

Anthropic PBC v. U.S. Department of War, No. 26-1049 (D.C. Cir. Sept. 25, 2026)

J.R. Howell

Anthropic had agreed to let the Department of War use Claude to design weapons systems, analyze foreign intelligence, and conduct offensive cyber operations. It refused two uses, lethal autonomous warfare and mass surveillance of Americans, and it controls what Claude will do through the way it trains the model. The Department answered by excluding Claude from its supply chain as a national-security risk. On September 25, 2026, a divided panel of the D.C. Circuit upheld the exclusion and denied Anthropic’s petitions for review.[1]

The court held that Anthropic’s control over Claude was itself the risk. Using that control to withhold functions the government considers lawful and necessary is, on the court’s reading, a way to “manipulate” the product within the statutory definition of “supply chain risk,” whatever the vendor’s motive.[2] Judge Katsas wrote for the court, joined by Judge Rao. Judge Henderson dissented.[3]

The Department Demanded “All Lawful Uses” and Anthropic Refused

Anthropic restricts Claude through safety training built into the model, technical measures layered on top, and contractual usage policies.[4] As the Department expanded its use of AI, Anthropic loosened those restrictions for national-security work and released a special Claude Gov model in March 2025. It kept its prohibitions on “lethal autonomous warfare” and “mass surveillance of Americans.”[5] In the fall of 2025, the Department asked for permission to use Claude for “all lawful uses,” and negotiations stalled over the two exceptions.[6]

On January 9, 2026, Secretary Pete Hegseth directed that the Department’s AI contracts include “any lawful use” language.[7] Around the same time, an Anthropic executive “questioned the propriety” of a contractor’s use of Claude “for a sensitive military operation abroad.” Media reports that Anthropic placed in the record tied its concerns to the January 3 operation to capture Venezuela’s president, Nicolás Maduro.[8] The Secretary set a February 27 deadline to accept an “all lawful uses” term, and Anthropic refused on February 26.[9]

On March 3, the Secretary found that Claude “presents a significant supply chain risk,” that no “less intrusive measures” were “reasonably available,” and that an “urgent national security interest” required immediate action.[10] A Department-wide memorandum then ordered Anthropic products removed from Department systems and barred contractors from using them in their work for the Department.[11] Anthropic petitioned for review on March 9, and the Secretary denied reconsideration on June 3.[12]

The Court Held That Motive Does Not Matter Under Section 4713

It was undisputed, the court observed, that Anthropic “can and does control how Claude responds,” chiefly through model training. Claude had refused legitimate government requests, including CDC queries on infectious-disease research, and the dispute over the overseas operation left the Department uncertain whether Claude would perform when needed.[13]Advance testing of each new model was no answer, because the contested restrictions “are hardly self-defining” and “the Department cannot utilize AI systems that remain trapped in amber.”[14]

The statute defines “supply chain risk” as “the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, . . . operation, . . . or retirement of covered articles so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation” of those articles.[15] Anthropic argued that “sabotage” and “maliciously introduce” import a requirement of bad motive. The majority gave the words their ordinary meaning instead. To manipulate is “[t]o move, arrange, operate, or control,” and to deny is “[t]o decline to grant or allow.” On that reading, the record showed “not only a ‘risk’—but a certainty—that Anthropic will so manipulate the ‘design’ or ‘operation’ of Claude to deny it the ‘function’ of conducting lethal autonomous warfare or mass domestic surveillance.”[16]

The court rejected the associated-words, ejusdem generis, and series-qualifier canons, reasoning that the listed verbs share no common connotation of bad motive and do not appear in a tight parallel list.[17] It accepted that Anthropic acts “with noble intentions” and held that this does not matter: “at least as applied here, the statutory definition of a ‘supply chain risk’ turns on what Anthropic does, not why Anthropic does it.”[18] Section 4713 “imposes no criminal liability,” and the court construes ambiguities in national-security statutes “in favor of the government.”[19] The statute also reaches domestic companies, because the definition covers “any person.”[20]

The Department had also designated Anthropic under a second statute, 10 U.S.C. § 3252, which speaks of “an adversary” who may “sabotage, maliciously introduce unwanted function, or otherwise subvert” a covered system. In August, the Northern District of California set that designation aside.[21] The D.C. Circuit had “no quarrel” with the conclusions that § 3252 requires bad motive and that Anthropic acted with none. Section 4713 is “much broader,” the court held, and the district court’s judgment does not constrain review of a § 4713 action, which Congress committed exclusively to the D.C. Circuit.[22]

The Procedural and Constitutional Challenges Failed

The court held its jurisdiction secure because Anthropic petitioned five days after notice of actions that took effect immediately.[23] On less intrusive measures, Anthropic argued that ordinary contract termination would have spared it the stigma of being branded a national-security threat. The court doubted any harm, citing a press report of investment offers valuing Anthropic at more than $900 billion, and noted that Anthropic had not explained why the stigma would be smaller under another authority.[24]

The urgency finding let the Secretary act before giving notice. Assuming without deciding that the finding was reviewable and wrong, the court held any error harmless, because Anthropic later received the underlying materials, made its submission, and lost on reconsideration. “When a petitioner has already mounted a failed challenge,” the court wrote, it “can no longer show prejudice from failing to receive an earlier opportunity to be heard.”[25]

On due process, the court assumed a protected interest and held postdeprivation process sufficient given the need to act quickly. It pointed to the pace of AI development, the controversy over the overseas operation, and a report that the United States began offensive military operations in Iran two days after Anthropic’s refusal, reportedly using Claude in connection with its strikes.[26]

The First Amendment claim failed on causation. The court agreed that Anthropic’s safety advocacy is protected and that the exclusion was materially adverse. But the Department had included Anthropic in a $200 million AI contract in July 2025 and kept negotiating through years of that advocacy. It acted only when the negotiations broke down. The Secretary’s social media post derided Anthropic’s “sanctimonious rhetoric” and “Silicon Valley ideology,” but the court read the post as one that “squarely addresses Anthropic’s refusal” to accept the contract term. “The nub of this dispute was contractual,” the court concluded.[27]

Judge Henderson Would Have Required Hostile or Deceptive Conduct

Judge Henderson read “manipulate” in the narrower sense its neighbors suggest: “[t]o manage, control, or influence in a subtle, devious, or underhand manner.”[28] Every act the definition lists, in her view, connotes intentionally subversive and deceptive conduct, and noscitur a sociis and ejusdem generis require the residual clause to be read in that company.[29] She drew repeatedly on Judge Katsas’s own dissent in United States v. Fischer, which urged a narrow contextual reading of a different statute, a reading the Supreme Court later adopted. The majority allowed that her arguments “have some force.”[30] She also relied on legislative history tying the statute to the threat of “[h]ostile nation state and other bad actors.”[31]

Her sharpest point concerned the next vendor. If the Secretary tells Anthropic’s replacement to permit any function the Department deems necessary, “that contractor will have a choice: Agree to the Secretary’s demands or risk being designated a national security threat under FASCSA.”[32] On her reading, the conduct that now gives rise to a supply chain risk is “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.”[33]

Vendors That Enforce Use Limits in the Model Now Carry Section 4713 Risk

The reasoning reaches past Anthropic’s two limits. It rests on three features of the record: control over what a model will do through training, a demonstrated willingness to use that control to enforce contract terms, and a disagreement with the government about what those terms cover.[34] Any vendor with those features fits the pattern the court held sufficient. That is an inference from the opinion, and the court’s “as applied here” framing leaves room to distinguish vendors whose limits are narrower or uncontested.

The two Anthropic decisions now sit side by side. Under § 3252, a designation requires bad motive. Under § 4713, motive is irrelevant, the Secretary’s national-security judgments receive heightened deference, and ambiguity runs in the government’s favor.[35] A reasonable prediction is that § 4713 will become the Department’s preferred instrument in disputes with domestic technology vendors, because it asks less of the government on every contested element.

The court was direct about who decides: “in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks.”[36] Anthropic conceded the Department’s “fundamental prerogative” to choose its contractors. The decision adds a further power: to designate a vendor that will not yield as a supply chain risk and to bar every Department contractor from using its products.[37]

What to Watch

The first question is further review. The panel split on a pure question of statutory meaning, and the dissent built its case on the majority author’s own Fischer reasoning, which gives Anthropic an evident basis to seek rehearing en banc. The second is vendor contracting, as AI companies decide whether to keep training-enforced limits in government deployments or accept “all lawful uses” terms. The third is Congress. Judge Henderson’s reading of the legislative history is a ready template for narrowing § 4713(k)(6), and the authority terminates at the end of 2033, so reauthorization would be a natural vehicle.[38]

Notes

Sourcing note: The D.C. Circuit opinion, including the dissent, was read in full. The text of 41 U.S.C. § 4713(k)(6), (b)(3), and (j) was checked against the current code. The Northern District decision, 10 U.S.C. § 3252, and the authorities cited within the opinion (including Fischer and the Senate Report) were not independently reviewed and are described as the D.C. Circuit presents them. Pincites are to the slip opinion and should be updated when the F.4th citation issues.


[1] Anthropic PBC v. U.S. Dep’t of War, No. 26-1049, slip op. at 7-9, 11-12, 43 (D.C. Cir. Sept. 25, 2026) [hereinafter Anthropic] (describing the uses Anthropic permitted and the two it refused, and denying the petitions for review). The case was consolidated with No. 26-1162. The dissent is separately paginated and is cited as such.

[2] Id. at 20, 24, 31-32 (concluding that “the Secretary’s concern about Anthropic disabling Claude from performing lawful actions requested by the Department qualifies as a ‘supply chain risk’ within the meaning of section 4713”).

[3] Id. at 4 (identifying the panel and the authors of the opinion for the court and the dissent).

[4] Id. at 7-8 (describing Anthropic’s model training, including a “constitution,” its technical measures, and its contractual usage restrictions).

[5] Id. at 8-9 (noting that the Department of Defense “now calls itself the Department of War,” and describing Claude Gov and the two retained prohibitions).

[6] Id. at 9 (describing the fall 2025 negotiations and their stalling over the two exceptions).

[7] Id. at 9-10 (describing the Secretary’s January 9, 2026 AI strategy).

[8] Id. at 10 (recounting the executive’s inquiry and describing media reports Anthropic placed in the record stating that it had raised concerns about its technology’s role in the operation).

[9] Id. at 10-11 (describing the February 24 meeting, the February 27 deadline, and Anthropic’s February 26 refusal).

[10] Id. at 11 (describing the Secretary’s March 3, 2026 determination); 41 U.S.C. § 4713(b)(3)(A)-(B), (c) (requiring written findings of necessity and of the unavailability of less intrusive measures, and permitting delayed notice for an urgent national security interest).

[11] Anthropic, slip op. at 12 (describing the March 6 memorandum ordering removal “as soon as practical” and in any event within 180 days, and barring contractors from using Anthropic products in their work for the Department).

[12] Id. at 12-13 (recounting the March 9 petition, the April 8 order denying a stay and expediting review, and the June 3 denial of reconsideration).

[13] Id. at 18-20 (quoting the head of Anthropic’s public-sector business describing model training as “the primary mechanism through which Anthropic can influence the behavior of models used by the Department,” and describing Claude’s refusals of government requests and the dispute over the overseas operation).

[14] Id. at 20-22 (rejecting Anthropic’s argument that advance testing of new models would answer the Department’s concerns).

[15] 41 U.S.C. § 4713(k)(6) (defining “supply chain risk”), quoted in Anthropic, slip op. at 23-24.

[16] Anthropic, slip op. at 24 (applying the ordinary dictionary meanings of “manipulate” and “deny” to the record).

[17] Id. at 25-27 (rejecting the associated-words, ejusdem generis, and series-qualifier canons).

[18] Id. at 28 (holding that Anthropic’s motive does not bear on whether its conduct falls within the statutory definition).

[19] Id. at 28-29 (emphasis in original) (reasoning that the statute’s procurement and national-security context favors the government’s reading).

[20] Id. at 31 (rejecting the argument that the statute reaches only foreign entities).

[21] Id. at 30 (discussing Anthropic PBC v. U.S. Dep’t of War, No. 26-cv-01996 (N.D. Cal. Aug. 27, 2026), and quoting 10 U.S.C. § 3252(d)(4)). The Northern District decision is described here only as the D.C. Circuit describes it.

[22] Id. at 30-31 & n.1 (distinguishing section 3252 and declining to let the Northern District’s judgment constrain review, given the D.C. Circuit’s exclusive jurisdiction under 41 U.S.C. § 1327).

[23] Id. at 14-15 (holding jurisdiction secure under 41 U.S.C. § 1327(b)(1), and declining to decide whether Anthropic’s April 17 request for rescission rendered the first petition incurably premature because the second petition secured jurisdiction either way).

[24] Id. at 32-33 (rejecting the reputational-harm argument, and holding that Anthropic’s one-sentence suggestion to narrow the exclusion was a “fleeting statement” that “did not preserve the point”).

[25] Id. at 33-38 (assuming without deciding that the urgency finding was reviewable and wrong, and holding any error harmless because Anthropic received the materials by March 19 and the Secretary maintained the exclusion after considering its submission). The quoted passage appears at 38, and the emphasis is in the original.

[26] Id. at 38-41 (assuming a protected interest and holding postdeprivation process sufficient).

[27] Id. at 41-43 (holding that Anthropic established protected speech and adverse action but not causation, and noting the Department’s inclusion of Anthropic in a $200 million AI contract in July 2025).

[28] Anthropic, slip op. at 2 (Henderson, J., dissenting) (quoting the Oxford English Dictionary definition of “manipulate”).

[29] Id. at 2-3, 6 (Henderson, J., dissenting) (invoking noscitur a sociis and ejusdem generis).

[30] Anthropic, slip op. at 24 (majority opinion) (noting that the dissent “quotes repeatedly from the dissent in United States v. Fischer, 64 F.4th 329, 363–83 (D.C. Cir. 2023) (Katsas, J., dissenting), which urged a narrow contextual reading of a different statute, and from the Supreme Court decision adopting that reading, Fischer v. United States, 603 U.S. 480 (2024),” and acknowledging that the dissent’s arguments “have some force”).

[31] Anthropic, slip op. at 7-8 (Henderson, J., dissenting) (relying on S. Rep. No. 115-408, at 2 (2018)).

[32] Id. at 7 (Henderson, J., dissenting) (posing the replacement-contractor hypothetical).

[33] Id. at 8 (Henderson, J., dissenting) (arguing that the statute’s history refutes the majority’s reading).

[34] Anthropic, slip op. at 18-20 (majority opinion) (grounding the finding in Anthropic’s control of Claude through training, its demonstrated willingness to enforce usage restrictions, and the disputed scope of those restrictions).

[35] Id. at 16-17, 28-30 (describing heightened deference to national-security fact-finding, construing ambiguity in the government’s favor, and contrasting section 3252).

[36] Id. at 43 (concluding that the Secretary did not exceed his authority under the statute or the Constitution).

[37] Id. at 28 (noting Anthropic’s concession of the Department’s “fundamental prerogative” to choose its contractors); id. at 12 (describing the memorandum barring contractors from using Anthropic products in their work for the Department).

[38] 41 U.S.C. § 4713(j) (providing that the authority under subsection (a) “shall terminate on December 31, 2033”); Anthropic, slip op. at 7-8 (Henderson, J., dissenting) (tying the statute’s enactment to the threat of hostile nation states and other bad actors).

Subscribe to The American Counsel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe