Skip to content

Product1 publisher3 min readPublished

Federal AI projects built on Claude need a second model after a 2-1 DC Circuit ruling

DC Circuit judges voted 2-1 to uphold the Pentagon's supply chain risk label on Anthropic, a designation Techdirt says bars Claude from every federal agency. Anthropic's California win came under a different statute, so government AI teams should qualify a second model.

The Product Desk · Product desk

Illustration accompanying Federal AI projects built on Claude need a second model after a 2-1 DC Circuit ruling

What happened

  • A federal district court in Northern California had earlier ruled, under a different statute, that the designation violated Anthropic's First Amendment and due process rights.
  • Congress gave the DC Circuit exclusive jurisdiction over section 4713 procurement actions, and the panel said that made it wrong to be bound by the California judgment.
  • Techdirt reports the designation disqualifies Anthropic from selling its model to any government agency, including agencies that lack the military's stated concern.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Only the DC Circuit can review section 4713 actions, so program teams counting on Anthropic's California win to restore Claude are relying on the wrong case.
  • exposure If Techdirt is right that the court's reading reaches most AI models, a backup hosted model from another vendor falls under the same rationale, so switching cuts downtime while the legal exposure stays.
  • cost Integrators pay for the switch: a second round of evals and security reviews, plus re-tuning prompts written against Claude's behavior for every affected agency contract.

Somewhere at a federal contractor, a product lead has a Claude call wired into a tool an agency uses every day, and a contracting officer wants to know whether it can stay. Techdirt's reading of the DC Circuit ruling says it cannot stay at any agency [5].

Anthropic's win in California does not change that. Pete Hegseth claimed the power to label Anthropic a supply chain risk under two statutes, 10 U.S.C. section 3252 and 41 U.S.C. section 4713 [2]. The California case turned on the first. Challenges under the second go straight to the DC Circuit, so Anthropic had to fight in two courts [4]. The majority wrote that "because the Department's designation authority is much broader under section 4713 than it is under section 3252, the issues flagged by Anthropic are not the same in both cases" [6].

For a buyer, the reasoning matters more than the vote count. The Secretary credited a joint recommendation from two senior department officials that Claude might be "subject to manipulation" by Anthropic "in such a manner as to inhibit the DoW's use thereof" [9]. In Techdirt's summary, the court accepted that Anthropic keeps control of its model after deployment. That control gives it the power to manipulate the model, and the court treated that as a supply chain risk [10]. The panel read the statutory definition broadly, saying it covers any person and so cannot be read to reach only foreign entities [8].

Techdirt argues that reading would make most AI models, and potentially all software, a supply chain risk [11]. It also calls the designation selective and punitive [12]. The ruling itself covers only Anthropic's designation [1]. Even so, a second hosted model from a vendor that also controls its model after deployment fits the description the court accepted [10].

Teams selling into government tend to call themselves model-agnostic because the API call sits behind a wrapper. In the codebase, prompts get tuned to one model's habits and the eval suite grades against that model's old outputs. Neither moves when the wrapper points at a new endpoint.

If I were delivering Claude to an agency, I would qualify a second model now. That means a second round of evals and a second security review, spent on a model that falls under the same statutory definition as the first [8]. Techdirt's account does not say whether Anthropic will seek further review.

Two questions sort the decision. The first is federal exposure: whether any customer is an agency, either directly or through a prime contractor. The second is swap time: how long the team needs to run the same workload on another model and pass the customer's acceptance tests. Teams with federal customers and a slow swap are hit hardest by the ruling, and the abstraction and eval work comes before anything else. Teams with federal customers and a fast swap should run the second model in parallel and pay for duplicate evals. With no federal customers and a slow swap, this is ordinary single-vendor risk, and nothing in this case forces a move. With no federal customers and a fast swap, all that is left is to follow the docket.

What to watch

  • Whether Anthropic asks the full DC Circuit or the Supreme Court to review the 2-1 decision.
  • Whether the department uses the same section 4713 manipulation rationale against another AI vendor that controls its deployed model.
  • Whether civilian agencies issue guidance on replacing Claude inside existing contracts.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories