On September 25, 2026, the U.S. Court of Appeals for the District of Columbia Circuit denied Anthropic’s petitions for review in Anthropic PBC v. U.S. Department of War (No. 26-1049, consolidated with 26-1162). Judge Gregory Katsas wrote the opinion, joined by Judge Neomi Rao; Judge Karen LeCraft Henderson dissented. The case challenged Secretary Pete Hegseth’s March 3, 2026 determination under the Federal Acquisition Supply Chain Security Act of 2018 (41 U.S.C. Section 4713) that use of Claude in Department systems “presents a significant supply chain risk,” a decision the Department took after Anthropic refused to relax contractual prohibitions on using Claude for lethal autonomous warfare or domestic surveillance.
The majority rejected all three of Anthropic’s lines of attack. On the statute, it read “supply chain risk” - which includes the risk that any person may “otherwise manipulate” a covered system - broadly enough to cover a vendor that encodes restrictions into its model that stop it performing tasks the government wants. The court pointed to occasions when those restrictions had blocked tasks requested by government users, and to a dispute over whether the contract terms barred Claude’s use in an ongoing overseas military operation, which left the Department “uncertain whether Claude would perform as needed and intended.” On due process, it held the Department gave prompt notice, a rationale and a fair chance to contest. On the First Amendment, it agreed that Anthropic’s safety advocacy is protected speech and that the exclusion was a materially adverse action, but found no causal link: in the majority’s reading the record shows the exclusion followed Anthropic’s refusal of a contract term, not its advocacy.
The opinion explicitly distinguishes the August 27, 2026 district court ruling in the Northern District of California that vacated a separate designation of Anthropic as a supply chain risk under 10 U.S.C. Section 3252. The panel said that statute’s definition, which turns on the risk that an “adversary” may subvert a system, is much narrower than the Section 4713 definition at issue here. Judge Henderson’s dissent argued the opposite reading of “otherwise manipulate”: placed next to “sabotage” and “maliciously introduce unwanted function,” the word should mean intentionally subversive, deceptive acts, not a vendor openly enforcing usage restrictions.
The ruling matters because it is the first appellate decision on whether a government can treat an AI lab’s built-in usage limits as a security risk in itself, and it leaves the two federal courts that have looked at the dispute pointing in different directions under two different statutes. It does not decide whether Anthropic’s restrictions are wise, and it does not reverse the California judgment, which rested on Section 3252. Whether Anthropic seeks rehearing en banc or Supreme Court review was not known at the time of writing.