technology 6 min read

The Pentagon Just Blacklisted Anthropic — And It Changes Everything

A federal appeals court upheld the Pentagon's supply-chain risk designation of Anthropic, a ruling that doesn't just hit one company—it redefines what it means for every firm building on Claude. The AI dependency map just got a lot more dangerous.

  • Artificial Intelligence
  • Anthropic
  • Pentagon
  • AI Regulation
  • AI Supply Chain

A Ruling That Reshapes the Industry

A federal appeals court has upheld the Pentagon’s designation of Anthropic as a supply-chain security risk. The decision doesn’t just bar the Department of Defense from using Claude models—it establishes a precedent that the U.S. government can blacklist an AI company on national security grounds, and then enforce that blacklist across every defense contractor in the ecosystem.

This is not a narrow administrative dispute. It is a structural shift in how AI power is distributed in America.

What Actually Happened

In March, the Department of Defense labeled Anthropic a supply chain risk, effective immediately. The designation prevents the military from using Claude directly and blocks all defense contractors from embedding it in systems built for or on behalf of the Pentagon. Two courts had to evaluate the legality of two separate designations the DOD relied on.

Last month, a San Francisco federal judge ruled one designation illegal. This Friday, the D.C. Circuit Appeals Court—where Judges Gregory Katsas and Neomi Rao, both appointees of President Donald Trump, formed the majority—upheld the second. Judge Karen LeCraft Henderson, appointed by George H.W. Bush, dissented.

The practical effect: Claude is now effectively excluded from the largest government AI procurement market in the world, and the legal framework supporting that exclusion has survived appellate review.

How We Got Here

The rupture began in September 2025, when negotiations between Anthropic and the DOD over Claude’s deployment on the military’s GenAI.mil platform collapsed. Anthropic had signed a $200 million contract with the Pentagon the previous July. By September, the terms of deployment were on the table—and they fell apart over a single question: control.

The DOD wanted unfettered access to Claude across all lawful purposes. Anthropic wanted contractual guarantees that its technology would not be used for fully autonomous weapons or domestic mass surveillance. Defense Secretary Pete Hegseth accused Anthropic of attempting to seize veto power over U.S. military operational decisions.

The breakdown was public and personal. Trump has repeatedly attacked CEO Dario Amodei on social media, most recently calling him a pretend angel after Amodei advocated for an industry-wide slowdown in AI development. Amodei was not invited to the state dinner for Chinese President Xi Jinping last Thursday—a small detail that nonetheless signals the depth of the administration’s displeasure.

Anthropic sued in both San Francisco and D.C. The D.C. panel’s decision delays implementation to allow Anthropic to petition for rehearing, potentially en banc, or to seek Supreme Court review. But the lawfare is only the surface story.

Who Wins and Who Loses

The Pentagon wins the right to exclude Claude from its systems without writing a new regulation or going through a formal rulemaking process. The Supply Chain Security Act gives the executive branch broad latitude to act, and this ruling confirms it.

Anthropic loses access to the single largest government customer base for AI infrastructure. More importantly, it loses the ability to set terms with that customer. The precedent established here is that a company can be blacklisted retroactively—after signing contracts, after building integrations, after embedding its models into government systems—based on a national security determination made by the executive branch.

The wider AI industry loses something subtler but arguably more valuable: the assurance that commercial AI partnerships are insulated from political shifts. Every company that builds on Claude—or any model now subject to similar scrutiny—faces the same risk. The Pentagon’s action sends a clear message to the entire sector.

The Real Story: Government Control Over the Stack

Judge Katsas’s majority opinion rests on a straightforward proposition: the President and the Secretary of Defense determine how to balance competing security risks, and they did not exceed their authority. The opinion references Hegseth’s concern that overly constrained AI models could shut down unexpectedly during operations and that Claude might be subject to manipulation.

Anthropic denies both claims. But the ruling makes clear that the government does not need to prove the claims are true—it only needs to conclude they are plausible enough to justify exclusion.

This is the critical point that English-language coverage has largely missed. The D.C. Circuit did not adjudicate whether Anthropic is actually a national security risk. It adjudicated whether the Pentagon had the legal authority to declare it one. The answer was yes. That distinction matters enormously for every AI company that relies on cloud infrastructure, every model provider that sells into government, and every defense contractor that has integrated any third-party AI into its systems.

The Supply Chain Security Act, as interpreted by this panel, gives the executive branch a unilateral tool to remove AI companies from the defense ecosystem without congressional approval, without formal rulemaking, and without requiring the government to prove harm in court. It is a tool that can be applied selectively and retrospectively.

What Comes Next

Anthropic is considering further review, including a potential Supreme Court petition. A en banc rehearing before the full D.C. Circuit is also possible. But even if Anthropic eventually prevails on the merits, the damage to its government business is already done. The Pentagon has spent months building alternative AI infrastructure. Contractors have begun rewiring their systems. The longer the blacklisting remains in effect—even pending appeal—the more entrenched the alternative becomes.

OpenAI and other model providers are watching closely. Some have closer relationships with the current administration. None are immune to the same legal framework. The ruling establishes that any AI company working with the government operates at the discretion of the executive branch, and that discretion can turn off access overnight.

For companies building on Claude today—the startups, the enterprise integrators, the defense contractors who quietly deployed the model before the blackout—the immediate question is compliance. The DOD’s designation blocks contractors from using Claude in their work with the agency. That obligation extends beyond direct Pentagon systems to any system funded, managed, or audited by the department. The supply chain exposure is broad.

The Bigger Picture

This ruling sits at the intersection of two trends that will define AI governance for years: the weaponization of supply-chain security and the Politicization of technical standards. The Trump administration has made no secret of its view that AI safety advocacy is obstructionism. Anthropic’s attempt to negotiate constraints on its own technology’s use was read not as responsible engineering but as a challenge to civilian control.

The D.C. Circuit’s decision validates that reading. It tells every AI company that the government reserves the right to treat its models as potential security vulnerabilities—and to act on that judgment without first proving the vulnerability exists in practice.

The Supreme Court may eventually rein in the breadth of this authority. But until it does, the AI industry operates under a new assumption: government access is conditional, and the conditions can change without warning. That is not a market risk. It is a governance regime.

And it is just beginning.