Skip to content

Build3 publishers2 min readPublished

D.C. Circuit leaves the Pentagon's Anthropic ban in place for contractors' department work

Anthropic failed on September 25 to get the D.C. Circuit to block the Pentagon's supply-chain-risk label, in a ruling CNBC reported as 2-1. Under the court's April order the bar covers only contractors' work for the department, so a Claude exit plan can be scoped to those contracts.

The Engineer · Build desk

Photograph accompanying D.C. Circuit leaves the Pentagon's Anthropic ban in place for contractors' department work
Photo: yahoo.com

What happened

  • A federal appeals court in Washington declined on Friday, September 25, to block the Pentagon's designation of Anthropic as a national-security supply-chain risk.
  • In late August a federal judge in San Francisco blocked a parallel classification made under a different law, calling it unlawful retaliation for Anthropic's safety stance.
  • Amodei has said Anthropic will support defense and intelligence work but will not remove its safeguards against mass domestic surveillance and fully autonomous weapons.
  • Anthropic says the designation has cost it billions in lost business and hurt its reputation ahead of a possible IPO, a figure Reuters attributes to the company alone.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • contradiction How long a Claude exit plan has to last depends on which account of the Washington ruling holds up: an interim refusal to block, or a 2-1 merits win for the Pentagon.
  • decision A company-wide move off Claude buys a contractor nothing the April order requires, so the compliance work can stay confined to department contracts.
  • cost Teams that serve every customer from one pipeline pay for a second evaluated model and per-request routing logs before they can show department traffic avoided Claude.
  • precedent Amodei says the Pentagon's any-lawful-purpose demand covers AI contractors in general, so any model vendor that keeps usage limits in its terms could meet the same dispute.

The two rulings sit on separate legal tracks. According to Reuters, the cases proceed through different legal routes and address government actions under distinct claims [7]. The California judge granted Anthropic summary judgment on several claims, First Amendment and due process among them. The order describes that case as covering a broader set of government actions [4]. The Washington case is Anthropic's direct challenge to the designation [20]. The designation followed a dispute over whether the department could require uses of Claude that Anthropic had excluded from its contracts [19].

The reports disagree on what kind of decision came out of Washington. Reuters describes an interim step: the court declined to block the Pentagon's action, and that decision does not by itself resolve whether the designation was lawful [3]. CNBC, as summarized by The Decoder, reported something closer to a merits holding, a 2-1 ruling that the Pentagon was right to classify Anthropic as a risk [2].

For a contractor, the scope that applies is in the D.C. Circuit's April order, and it follows contract lines. The Pentagon canceled its own Anthropic contracts and barred other contractors from using Anthropic as a subcontractor on work performed for the department [8]. The same order said the restriction did not stop those contractors from using Claude on work for other customers [9].

The design I would defend at review is small. Model choice goes behind one interface keyed on contract ID. A second model gets its own prompts and an eval suite built from department workloads, because a prompt tuned for Claude has only been tested on Claude. Department routes default to that model now. Every request logs the contract and the model that served it.

In my view, the public positions leave little room for a settlement. Amodei argued in February that current AI systems are not reliable enough to select and engage targets without human involvement [12]. Defense Secretary Pete Hegseth argued, according to The Decoder, that Anthropic's safety restrictions could jeopardize military operations [13]. Anthropic rejects the Washington ruling and says it is weighing its next steps [18].

Intelligence customers are the least clear case. Anthropic said Claude was already deployed for national-security work including intelligence analysis, operational planning and cyber operations [14]. The Decoder describes US intelligence agencies as heavy users of Anthropic's models and calls the fit with a supply-chain-risk label an open question [15]. The April order, as reported, is written around work performed for the department [8].

What to watch

  • Whether Anthropic seeks further review of the D.C. Circuit decision, a step the company says it is weighing.
  • Whether the government appeals the August 27 California summary judgment that blocked the parallel classification.
  • Whether Anthropic's IPO filing, made confidentially in June according to Reuters, puts a figure on business lost to the designation.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories