The Rundown AI homepage
Artificial intelligence/News & analysis

Anthropic loses Pentagon blacklist appeal over Claude’s safeguards

A court upheld the Pentagon’s blacklist of Anthropic over Claude’s safeguards, a ruling that could pressure AI firms to relax limits on military use.

By The Rundown Editorial TeamReviewed by Kelly Pitts3 min read
Anthropic loses Pentagon blacklist appeal — newsletter story image
Image source: U.S. Courts

A federal appeals court upheld the Pentagon’s decision to blacklist Anthropic on Sept. 25 over Claude’s limits on fully autonomous weapons and mass domestic surveillance. The 2–1 decision gives the Pentagon legal backing to treat those safeguards as a supply chain risk, as The Rundown reported.

The U.S. Court of Appeals for the D.C. Circuit ruled that the record “amply supports” the designation. The majority accepted that Anthropic lacked bad intent, but held that the law governing this designation did not require it. The judges focused on whether Claude’s restrictions and uncertainty over contract terms could undermine military reliability.

The dispute over Claude’s limits

In a Feb. 26 statement, CEO Dario Amodei said Anthropic supported military and intelligence applications while maintaining restrictions on mass domestic surveillance and fully autonomous weapons. He cited reliability and human oversight as reasons for the weapons restriction and described existing applications in intelligence analysis, operational planning and cyber work.

Dissenting Judge Karen LeCraft Henderson challenged the majority’s reading of the law. She argued that the statute targets deceptive interference and disputed treating a contractor’s openly enforced restrictions as that kind of conduct.

The ruling covers one of two Pentagon designations issued under different laws. A California judge set aside the other on Aug. 27, and that order blocks broader restrictions on Anthropic.

Anthropic said it disagreed with the decision and was considering further review on Sept. 25.

Why it matters

The decision strengthens the Pentagon’s position in negotiations over military AI. Under the majority’s interpretation, a supplier can act in good faith and still face exclusion if its safeguards create what the Pentagon sees as an operational risk. A company’s safety policy can therefore become grounds for losing defense work.

That could put AI companies under pressure to relax limits they consider essential. Anthropic said in February that the Pentagon had demanded it relax its two restrictions to retain the relationship. Companies considering defense contracts may need to decide which safeguards they would preserve even if doing so costs them that business.

The upheld exclusion reaches Pentagon supply chain work, including contractors. For firms that depend on Claude in that work, the practical question is which contracts and planned deployments fall within its scope. That makes the legal dispute relevant to suppliers building services around the model as well as to Anthropic itself.

Other contract structures may offer room to negotiate. In a Feb. 28 announcement, updated March 2, OpenAI said its Pentagon agreement preserved restrictions on mass domestic surveillance and autonomous weapons through deployment only in the cloud, safety systems, staff with security clearances and contract terms. The company also said it retained control of its safety systems and could end the agreement for a breach.

OpenAI’s account describes an attempt to combine safeguards with defense access. How its protections would hold up during a dispute over military use remains uncertain. Future negotiations could turn on who controls safety systems, who checks for prohibited uses and when a vendor can end access after a contract violation.

Sources & further reading

This story builds on reporting from The Rundown newsletter on September 28, 2026.