Cybersecurity Policy Report, Court Upholds DoD’s Decision That Anthropic Poses Security Risk, (Sep 25, 2026)
Organizations Mentioned:Computer & Communications Industry Association

A federal law on technology supply-chain threats provided sufficient authority for the Department of Defense to designate Anthropic as a national security threat after the company refused to allow the use of its AI (artificial intelligence) systems for mass domestic surveillance or autonomous weaponry, an appeals court ruled today.
But the ruling by the U.S. Court of Appeals for the District of Columbia Circuit is at odds with a decision by the U.S. District Court for the Northern District of California that found that DoD blacklisted Anthropic over the AI developer’s vocal advocacy for ethical use of AI, which the Northern District said was a violation of the company’s First Amendment rights (CPR, Aug. 28).
The D.C. Circuit, however, noted that the two courts were parsing different provisions of federal law in their respective decisions. The Northern District court focused on 10 U.S.C. § 3252, which offers a narrower definition of “supply chain risk” than 41 U.S.C. § 4713, which was the basis of the D.C. Circuit’s ruling, the court explained.
“We have no quarrel” with the Northern District court’s conclusion “that bad motive is required” to support a supply-chain threat designation under section 3252, according to the D.C. Circuit opinion authored by Circuit Judge Gregory Katsas and joined by Circuit Judge Neomi Rao (Anthropic PBC v. United States Department of War, et al., No. 26-1049 (D.C. Cir. Mar. 9, 2026)).
“Likewise, we have no quarrel with the Northern District’s conclusion that Anthropic has acted with no such bad motive in its dealings with the Department. But ... no such bad motive is required to support a designation under the much broader definition set forth in section 4713,” it said.
The D.C. Circuit rejected Anthropic’s claim that DoD was retaliating against it for its speech. “The First Amendment squarely protects Anthropic’s advocacy regarding the safe and appropriate use of AI products,” it said, but the record in the case “makes clear that the Department removed Anthropic from its supply chain not because of its advocacy, but because Anthropic refused to agree to a contract term the Department deemed essential to national security.”
“The nub of this dispute was contractual, and the First Amendment did not require the Department to continue a contractual relationship that it viewed as creating a national-security risk,” it added.
“The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk,” the court said.
“As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent. On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users,” it noted.
“This case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology,” it said.
“But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution,” it concluded.
A dissent in the case written by Circuit Judge Karen LeCraft Henderson focused on how to interpret the phrase “or otherwise manipulate” in the 2018 Federal Acquisition Supply Chain Security Act (FASCSA). Her reading of the phrase, she said, would require Anthropic to have some “intentionally hostile or clandestine purpose” if it were to manipulate its AI models to prevent certain actions.
The majority opinion’s broad definition of “manipulate” gives DoD more power than Congress intended to blacklist contractors, she argued.
“I cannot agree that this is the scenario the Congress had in mind when it enacted FASCSA. It enacted the statute in response to calls from the U.S. intelligence community for legislation to meet the threat of ‘[h]ostile nation state and other bad actors’ infiltrating the federal government’s information and technology systems through its supply chains,” Judge Henderson said quoting from a Senate report.
She raised the possibility that, under the majority’s interpretation of FASCSA, DoD could ask “Anthropic’s presumed replacement to change its AI-use policies to permit any ‘functions that the Department deems necessary’ or it will share the same fate as Anthropic.”
The Computer & Communications Industry Association (CCIA), which had filed an amicus brief in the case, expressed concern about the D.C. Circuit’s ruling.
“By green-lighting the Pentagon’s circumvention of standard procurement procedures to target Anthropic in this fashion, this ruling should alarm any government contractor,” CCIA President & Chief Executive Officer Matt Schruers said in a statement.
“Designating a company as a supply chain risk, a tool normally reserved for foreign adversaries, must be used with discretion and proper procedure—not as punishment for a company over a disagreement,” he added. “Despite acknowledging that the government cannot take adverse action against a company in response to speech, the court dismisses the government’s public denunciations of Anthropic when announcing its action.”
Similar concerns were expressed by TechNet, which also filed an amicus in the case in support of Anthropic.
“The D.C. Court of Appeals’ ruling grants the federal government vast powers to blacklist private companies arbitrarily without due process,” Bryn McDonough, general counsel for TechNet, said in a statement. “This would be a dangerous new precedent with far-reaching consequences for our national security—it threatens existing business contracts and downstream supply chains, and discourages U.S. companies from investing in products and services for the federal government.”
MainStory: TopStory FederalLegislation LitigationEnforcement DataPrivacy AINews