Leadership2 publishers2 min readPublished
Claude's coded restrictions support a Pentagon blacklist, appeals court rules
Anthropic can be blacklisted from Pentagon contracts because Claude carries coded usage limits, the D.C. Circuit ruled 2-1 on Friday. For defense contractors built on Claude, the vendor's usage policy is now a compliance risk.
The Board Room · Leadership desk
What happened
- The court wrote that integrating Claude into the department's information systems, whether by the department or its contractors, was a statutorily covered national-security risk.
- Anthropic has said it will not allow its products to be used for autonomous weapons or mass domestic surveillance.
- The ruling came in a lawsuit Anthropic filed against its supply-chain designation, and ABC News reported the court declined to block the blacklisting.
- Anthropic has said the label will bring significant reputational stigma and cost it hundreds of millions of dollars in revenue.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- precedent Other US AI vendors that code use limits into their models can be tagged under the same authority that, according to Politico, the ruling confirms for US and foreign-owned firms alike.
- constraint If a model vendor keeps coded limits on defense uses, it now gives up eligibility for Pentagon work and for the contractor stacks built around its model.
- exposure Contractors that standardised on Claude alone have no second model already integrated to switch to, so the designation hits the least diversified defense stacks hardest.
The court built its finding on a point Anthropic concedes. "As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," the court wrote [5]. The panel held that the department had good reason to treat those coded limits as a supply-chain risk to itself and its contractors [2].
The board-deck version is that Anthropic lost and Claude leaves defense work. That version skips the question of posture. In Politico's report, the court found "ample support" for the department's conclusion [4]. ABC News described a court that declined to block the blacklisting [8]. A contractor planning around an interim refusal to block plans differently from one planning around a final ruling on the merits. Neither report says which this is, what the dissenting judge argued, or what contractors must remove and by when [9].
The contractor language in the opinion is tied to the department's information systems [4], and the blacklist as reported covers Pentagon contracts [1]. A firm running Claude inside a system it operates for the department falls within that language. A firm using Claude only in commercial work falls outside it. In my view the compliance risk is concrete for the first group and unproven for the second.
A skeptic would say this is one vendor's quarrel with one administration, and that contractors can wait for the litigation to finish. The court's stated reason cuts against waiting. It rests on restrictions a vendor codes into its own model [2], and any AI vendor selling a restricted model into defense work fits that description.
For a defense contractor with Claude in its stack, this quarter's decision is whether to start replacing it before the case ends. Starting now spends engineering time on a migration that a later ruling could make unnecessary. Waiting bets that the panel's 2-1 decision does not hold [1].
Next quarter's consequence follows from either choice. The replacement model will be judged on its usage policy as well as its capability. Under this court's reasoning, a vendor's coded limits count against it in a defense review [2].
What to watch
- Whether Anthropic seeks further review of the 2-1 decision, and what the dissenting judge wrote.
- Any Pentagon guidance telling contractors what they must remove from department systems and on what timeline.
- Whether the department applies the supply-chain label to a second AI vendor over coded usage restrictions.