Claude's refusals made it a supply chain risk, court rules

A federal appeals court has ruled that an AI model refusing its customer's requests can make it a national-security "supply chain risk." The D.C. Circuit split 2 to 1 and denied Anthropic's petitions against the Department of War, which excluded Claude after Anthropic refused to relax contract bans on lethal autonomous warfare and domestic surveillance, according to opinion excerpts published by Reason.
At a glance
- Judges Gregory Katsas and Neomi Rao rejected all three of Anthropic's lines of attack: that the exclusion was arbitrary, that the 2018 statute did not authorize it, and that it was unconstitutional.
- The majority read the statute's phrase "or otherwise manipulate" broadly, so a vendor disabling its product from lawful tasks the Department requests qualifies as a supply chain risk, whatever the vendor's intent.
- Judge Karen LeCraft Henderson dissented, arguing the law targets hostile actors infiltrating government systems, not a contractor's "honest and upfront enforcement" of use restrictions the government dislikes.
If you have not followed the fight: according to the Anthropic v. Department of War case site, Claude's Usage Policy has barred mass surveillance of Americans and lethal autonomous warfare since 2023. The same site says Secretary Hegseth, at a February 24, 2026 meeting, set a 5pm February 27 deadline to accept "any lawful use" language, and on March 3, 2026 issued a formal supply-chain risk determination alongside a separate letter invoking the 2018 supply chain law.
Katsas and Rao found that Claude's refusals of government tasks gave the Department ample support
Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao. They held that the Department had ample support for concluding that keeping Claude in its information systems, whether used by the Department or by its contractors, posed a national-security risk covered by the statute.
The court leaned on three points. Anthropic admits it encodes restrictions into Claude that stop the model from doing tasks the company wants to prevent. On more than one occasion, those restrictions stopped Claude from performing tasks government users requested. And a recent dispute over whether the contract barred using Claude in an ongoing overseas military operation left the Department unsure whether Claude would perform as needed.
The majority also set out the stakes on both sides. The Secretary raised the prospect of overly constrained AI models shutting down unexpectedly and causing military operations to fail; Anthropic raised the prospect of unconstrained models hallucinating inappropriate targets for lethal force. In the court's words, it is the President and the Secretary of War who must decide how to balance those risks.
The due-process and First Amendment claims failed on notice and a contract term
Anthropic's constitutional arguments fared no better. On due process, the majority found that the Department promptly told the company about the exclusion and the reasoning behind it, and then gave Anthropic a fair opportunity to contest the decision before it stood.
The First Amendment claim went the same way. The majority held that the Department excluded Anthropic because the company refused to agree to a contract term the Department deemed essential, and not because of its support for greater governmental regulation of AI technology.
The published passages are a selection. The Reason post notes that the full opinions go considerably further on both the statutory and the constitutional questions. The government was represented by Sharon Swingle, Brett A. Shumate, Eric D. McArthur, Sean R. Janda and Brian J. Springer.
The case turned on three words in the statute: "or otherwise manipulate"
The Federal Acquisition Supply Chain Security Act of 2018, known as FASCSA, lets the Secretary bar a supplier from the Department's supply chains. According to Acquisition.gov, the "covered articles" it protects include information technology, cloud computing services of all types, and software with embedded information technology.
The power comes with a condition. As Judge Henderson quotes it, the Secretary may act "only after" finding a "significant" risk that a source will sabotage, maliciously introduce unwanted function, extract data, "or otherwise manipulate" a covered article so as to surveil, deny or disrupt its function. The majority did not dispute that Anthropic's fate hung on that residual clause.
Anthropic read "manipulate" as intentionally subversive acts carried out through deception. The Secretary and the majority read it as simply moving, operating or controlling something, regardless of motive, the way you manipulate a doorknob by turning it or a gas pedal by pressing it. Under the broad reading, a vendor switching off lawful uses fits.
Henderson's dissent says Congress wrote the law against hostile infiltrators
Judge Karen LeCraft Henderson dissented on statutory grounds. When Congress takes the trouble to define its terms, she wrote, courts should apply them "with rigor," and here the surrounding text decidedly favors the narrower reading of "manipulate."
Her historical argument: Congress passed FASCSA after the intelligence community called for legislation against "[h]ostile nation state and other bad actors" infiltrating federal systems through supply chains. Agencies had warned for years about companies "beholden to foreign governments" slipping compromised products into government technology, describing covert breaches in terms that closely track the statute. That history, she wrote, refutes treating as manipulation
a contractor's honest and upfront enforcement of restrictions on a covered article's use disfavored by the government.
The majority answered both points. Only two of the seven verbs in the definition, sabotage and surveil, carry a sense of stealth, so there is no overarching secrecy requirement. And the statute covers "any person," which cannot refer only to foreign entities, whatever examples individual members of Congress had in mind.
The excerpts leave real gaps: they do not say which tasks Claude refused or how the overseas-operation dispute ended. According to the case site, OpenAI announced a Pentagon contract on February 28, 2026 with substantively similar restrictions, a comparison the published passages never address. In our view, the majority's test is broad, because it turns on a vendor disabling lawful uses, which likely describes guardrails that many commercial models ship with.
After the 2 to 1 split
The source does not say whether Anthropic will ask the full D.C. Circuit to rehear the case or take it to the Supreme Court, and no timeline for either step has been given. The Reason post promises more analysis of the statutory and constitutional questions later. Until then, the exclusion stands, and the open question is whether Henderson's narrower reading of "manipulate" gets a second hearing.
Related stories
- Four AI subscribers sue Anthropic, OpenAI and Google
- Two federal officials, two verdicts on Anthropic
- Authors and publishers fight over settlement shares
- Amodei and Mann named in Sony and Warner music suit
- Pentagon blacklist of Anthropic ruled illegal
- Music publisher sues over 500 songs used to train Claude
Comments
No comments yet. Be the first.
Join the conversation
Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.
