D.C. Circuit Upholds Pentagon's Decision to Exclude AI Provider Anthropic due to Supply-Chain Risk
Authors
Bret S. Wacker , Melissa K. Ventrone , Ronald D. Sullivan , J. Chris White
On Friday, September 25, 2026, a divided U.S. Court of Appeals for the D.C. Circuit upheld the Department of War’s decision to exclude Anthropic PBC and its Claude artificial-intelligence models from Department systems and contractor-supported work.
This ruling establishes a significant precedent for federal contractors: The government may invoke the Federal Acquisition Supply Chain Security Act of 2018 (“FASCSA”) against a domestic technology supplier when vendor-controlled product restrictions prevent technology from performing functions the government considers contractually authorized and operationally necessary.
Background and the Core Dispute
The dispute arose when Anthropic refused to allow the government to deploy Claude for “all lawful uses,” maintaining that this stems from prohibitions on lethal autonomous warfare and the mass surveillance of Americans. In March 2026, the Secretary of War, Pete Hegseth, determined that these “guardrails” articulated by Anthropic presented a significant “supply chain risk” to national security under FASCSA and directed the removal of Anthropic products from Department systems and contractor-supported work. Anthropic challenged the exclusion on statutory, First Amendment, and Fifth Amendment grounds.
The Majority Opinion
Judges Gregory Katsas and Neomi Rao ruled in favor of the government, focusing on statutory interpretation and judicial deference to national-security determinations:
- Intent versus action. FASCSA defines supply-chain risk to include the potential for a supplier to “manipulate” a technology so as to “deny” or disrupt its function. The majority held that the statute concerns what a supplier does, regardless of why it does so. Thus, even without malicious intent, Anthropic’s deliberate training and configuration of Claude to decline certain tasks could fall within the statutory definition.
- Lack of reasonably available alternatives. Because AI models may be opaque, evolve rapidly, and respond differently to variations in prompts, the court agreed that pre-deployment testing or system-by-system exclusions would not necessarily address the Department’s concerns. The majority treated a “clean break” as a reasonable national-security judgment.
- Constitutional claims rejected. The court held that the post-deprivation process provided to Anthropic satisfied Fifth Amendment due process in the asserted urgent national-security context. It also rejected Anthropic’s First Amendment retaliation claim, concluding that the exclusion resulted from the parties’ contractual and operational dispute rather than Anthropic’s public advocacy concerning AI safety.
The Dissent
Judge Karen LeCraft Henderson dissented, arguing for a narrower reading of FASCSA based on the statutory language and legislative history. In her view, the statute targets intentionally subversive, malicious, or deceptive conduct by hostile actors, not a vendor’s transparent, good-faith enforcement of disclosed technical or contractual restrictions.
Judge Henderson warned that the majority’s broad interpretation could allow the government to characterize almost any vendor-imposed limitation as a national-security supply-chain risk, leaving contractors to choose between accepting the government’s demanded terms and risking a designation with serious commercial and reputational consequences.
Implications for Federal Contractors
- Product controls may become procurement risks. Contractors should identify technical guardrails, licensing conditions, usage policies, update mechanisms, and embedded limitations that could prevent performance of an agency’s anticipated mission functions.
- Flow-down exposure is significant. FASCSA expressly reaches subcontracts that use an excluded supplier to perform government work. Prime contractors and integrators should therefore understand which AI models and software components their subcontractors use.
- Contract negotiations may shape later risk determinations. The opinion relied heavily on the parties’ negotiating history, operational incidents, product behavior, and written statements. Contractors should clearly document the scope, purpose, and technical effect of proposed restrictions.
- Testing alone may not provide a complete answer. For rapidly changing or opaque technologies, the government may determine that pre-deployment testing does not eliminate concerns about future versions or scenario-dependent performance.
- Procedural remedies may be limited. Contractors should respond quickly and comprehensively to supply-chain notices because later administrative process may cure deficiencies in pre-deprivation notice absent demonstrable prejudice.
- Different statutes may produce different outcomes. A California court invalidated a parallel designation under a separate statute containing narrower language focused on an adversary. The D.C. Circuit distinguished that decision and emphasized FASCSA’s broader reference to “any person.”
Contractor Takeaway
Federal contractors using AI or other dynamically updated technologies should review their agreements, product dependencies, acceptable-use restrictions, model-update procedures, and subcontractor inventories before a dispute arises. The decision does not hold that safety guardrails are improper. It does, however, permit the government to treat them as a procurement and national-security concern when they may undermine the government’s confidence that a system will perform as expected.
The central message is clear: in mission-critical procurements, a supplier’s control over what its technology will or will not do may itself become part of the government’s supply-chain risk analysis, regardless of the supplier’s good-faith motives.
Contact Clark Hill Attorneys
If you have questions regarding this decision or its implications for federal contractors, AI developers, technology providers, or companies operating within the federal procurement ecosystem, please contact the authors of this article.
- Melissa Ventrone (mventrone@clarkhill.com; 312.485.0540)
- Bret S. Wacker (bwacker@clarkhill.com; 202.772.0906)
- Ronald D. Sullivan (rsullivan@clarkhill.com; 202.809.2235)
- Chris White (jcwhite@clarkhill.com; 517.318.3011)
Click here to find our Clark Hill Government Contracts Attorneys.
Click here to find our Clark Hill Data Privacy, Protection & Cybersecurity Attorneys.
Subscribe here to receive future Clark Hill alerts directly in your inbox.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual authors only and are not necessarily the views of Clark Hill PLC. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.