Sophie Laurent, YuSMP Group
Sophie Laurent Legal & Compliance Lead, YuSMP Group · AI regulation and vendor risk for US and EU teams
A classical courthouse with stone columns at dusk, with a laptop in the foreground showing a glowing network diagram

The short answer

The D.C. Circuit has let the Pentagon keep Anthropic out of its supply chain, so Claude cannot be used for Defense Department work while the designation stands. The panel accepted the department’s argument that a model with built-in usage limits might refuse tasks during military operations, and that this is a national-security risk the statute covers.

For most commercial teams nothing changes today. For anyone who sells software into the defense supply chain, it is a compliance problem now. And for everyone building on Anthropic’s Claude models, it is a reminder that a single model vendor can become unavailable to a whole customer segment for reasons that have nothing to do with engineering.

What did the court decide?

The panel denied Anthropic’s challenge to the Pentagon’s designation. Writing for the majority, Judge Katsas said the department had adequately shown that keeping Claude embedded in its information systems created a national-security risk covered by the statute, and that the designation did not violate the Constitution. He pointed to “the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail,” as quoted by Reuters.

Judge Henderson disagreed. In her reading, the law targets subversive or deceptive interference with government technology, not a company that openly enforces known limits on its own product. That split is likely to feature in any request for a rehearing. For now, though, the designation is in force for DoD systems and DoD contract work.

Why did the Pentagon blacklist Anthropic?

The conflict started with a $200 million contract and a question of control. The Defense Department wanted Anthropic’s models available for any lawful military use without restriction. Anthropic asked for written guarantees that Claude would not be used in fully autonomous weapons or for mass surveillance of the US population. Talks broke down in late February, and Defense One reports the formal designation followed in early March. Anthropic filed two lawsuits that month.

The two cases have now split. In August, a federal judge in San Francisco set aside a designation under a different statute, found the administration had unlawfully retaliated against Anthropic, and blocked both a government-wide ban and an order barring military contractors from doing any business with the company. The D.C. Circuit ruling leaves a narrower but still significant restriction standing: no Claude for DoD work.

What it means for US & EU software teams

First, vendor eligibility is now a per-customer attribute. The same product can be fine for a bank and prohibited for a defense prime. Defense One reports that contractors are already reducing their use of Claude tools. If you build software for companies anywhere in the defense supply chain, they will ask which models your product calls, for which features, and whether you can turn them off for their tenant.

Second, model usage policies are contract terms, not fine print. This case turned on what a model provider will and will not let its model do. Every major provider has an acceptable-use policy, and those policies can conflict with a customer’s requirements. Procurement and legal teams should review them alongside data-processing terms, not after deployment.

Third, this mirrors what EU regulation already expects. For financial entities, DORA requires managing ICT third-party concentration risk and credible exit strategies for critical providers. A single-LLM architecture with no tested alternative is exactly the kind of concentration that auditors now question. The Pentagon case shows the risk is not theoretical, and the same design fixes both.

What to do now

  1. Build an AI inventory. List every feature, internal tool and coding assistant that calls an LLM, which model it uses and which customer contracts it serves.
  2. Isolate DoD-bound work. If you are a defense contractor or subcontractor, confirm with counsel which systems count as DoD business and remove Claude from them, including developer tools.
  3. Put a gateway in front of models. Route all LLM calls through one layer with per-tenant allow and deny lists, logging and fallback rules.
  4. Keep a second model qualified. Maintain evaluation suites that run against at least two providers, so a switch is tested before you need it.
  5. Update contracts. Add model-disclosure and model-substitution clauses to client agreements, and track provider usage policies as part of vendor review.

Frequently asked questions

What did the appeals court decide about Anthropic?

On September 25, 2026, a three-judge panel of the U.S. Court of Appeals for the D.C. Circuit ruled 2-1 that the Defense Department lawfully designated Anthropic a supply-chain risk. Judge Gregory Katsas, joined by Judge Neomi Rao, found the department had adequately shown that keeping Claude embedded in its systems posed a national-security risk covered by statute. Judge Karen LeCraft Henderson dissented.

Can defense contractors still use Claude?

Not for Defense Department work while the designation stands. Defense One reports the designation bars DoD employees and contractors from using Anthropic products for DoD business. A separate August ruling in San Francisco blocked a government-wide ban and an order barring contractors from doing any business with Anthropic, so commercial use outside DoD work is a different question. Check your contracts with counsel.

Why did the Pentagon label Anthropic a supply-chain risk?

The dispute grew out of a $200 million contract. The Pentagon wanted Claude available for any lawful military use; Anthropic sought written guarantees that Claude would not power fully autonomous weapons or mass domestic surveillance. The court accepted the argument that built-in model restrictions could cause Claude to refuse tasks during military operations.

Is the case over?

No. Anthropic said it respectfully disagrees with the decision and is considering all options, including further review. That could mean asking the full D.C. Circuit to rehear the case or petitioning the Supreme Court. The parallel San Francisco ruling on a different statute also remains part of the picture.

What should companies building on Claude do now?

Map where Claude is used and which contracts those systems serve, isolate any DoD-bound workloads, and put a model gateway in front of your LLM calls so you can switch providers per customer or contract. Keep evaluation suites for a second model ready, and write model-substitution rights into client agreements.

Sources

CNBC — U.S. appeals court upholds Pentagon designation of Anthropic as supply chain risk
Reuters via Military Times — US appeals court upholds Pentagon’s blacklisting of Anthropic
The Washington Post — Federal appeals court rules Pentagon can blacklist Anthropic
Defense One — Anthropic loses legal fight to shed DOD’s designation as a ‘supply-chain risk’