Appeals Court Rules Pentagon Can Blacklist Anthropic: When AI Safety Guardrails Became a “National Security Risk”

  • AI
  • September 26, 2026

The Ruling: 2-1, Pentagon Wins

On September 25, 2026, the U.S. Court of Appeals for the D.C. Circuit ruled 2-1 that the Pentagon acted lawfully when it blacklisted Anthropic as a “national security supply chain risk.” The decision hands a landmark victory to the executive branch: it can now effectively tag American companies — not just foreign-owned ones — with the supply chain risk label and exclude them from all military contracts.

Writing for the majority, Judge Gregory Katsas penned a line destined to be quoted for years: “The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk.” The court pointed straight at the heart of the dispute: “As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent.”

Military ceremony on the Pentagon River Entrance parade field
The Pentagon, headquarters of the U.S. Department of Defense. Image: Wikimedia Commons (Public Domain)

How the Conflict Began: Guardrails vs. Military Demands

The confrontation started when Anthropic refused to remove safety guardrails from its Claude models — specifically, the company would not permit its AI to be used for autonomous weapons or mass domestic surveillance. After months of failed negotiations and public recriminations, Defense Secretary Pete Hegseth designated Anthropic as a risk under two different laws, the White House issued a government-wide ban, and military contractors were ordered to cut all business with the startup.

The majority sided with Hegseth’s argument, even invoking a chilling scenario: “The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail.” The court rejected Anthropic’s claim that the Pentagon had retaliated against it for its views on AI safety and ethics.

Crucially, this is only half the story. In August, U.S. District Judge Rita Lin in San Francisco struck down a parallel designation under a different law, finding the administration had unlawfully retaliated against Anthropic for its safety stance — and blocked both the government-wide ban and Hegseth’s contractor order. The same war, fought on two fronts, has produced opposite outcomes: the executive branch has now decisively won the “supply chain risk” front.

United States Supreme Court building
The U.S. judicial system. Image: Wikimedia Commons (CC BY-SA 4.0)

The Balance Between “Safety” and “Compliance” Is Tilting

The deepest consequence of this case lies beyond one company’s balance sheet. The ruling establishes sweeping authority for the executive branch to label businesses — foreign and domestic — as supply chain risks. Anthropic has told courts the designation carries serious “reputational stigma” and will cost hundreds of millions in revenue; the company says the blacklist has already cost it billions in lost business and damaged its reputation ahead of a highly anticipated IPO.

From an industry perspective, this is a chilling precedent for the entire AI safety movement. When “encoding restrictions that prevent a model from performing certain tasks” can itself be deemed a national security risk, the choice between safety guardrails and government contracts stops being a technical judgment and becomes a political one. Anthropic’s position — that AI is not yet reliable enough for autonomous weapons, and that mass domestic surveillance violates fundamental rights — was celebrated as responsible AI in 2023. In 2026, it became the “offense” for which the company was blacklisted.

Code on a computer monitor, symbolizing restrictions encoded into AI models
Restrictions encoded into AI models became the core of the legal dispute. Image: Wikimedia Commons (CC0)

What’s Next: En Banc Review and the Final Battle

Anthropic said in a statement that it “respectfully disagrees” with the decision, remains confident in its position, and is weighing its options — including seeking review of the three-judge panel’s ruling by the full appeals court (en banc). The White House and the Department of Defense did not immediately respond to requests for comment.

Most observers expect this case to eventually reach the Supreme Court. When it does, the justices will have to answer a defining question of this era: when an AI company is blacklisted by the state for “refusing to remove safety restrictions,” is that a legitimate act of national defense — or a constitutional violation of corporate speech and conscience? The split between August’s San Francisco ruling and September’s D.C. appellate ruling has already signaled the weight of the final showdown.

Conclusion: AI Governance at a Crossroads

Three takeaways worth remembering: first, “supply chain risk” is becoming the executive branch’s new regulatory weapon against AI companies — and the courts have just blessed it; second, the tension between AI safety commitments and government commercial interests has escalated from a war of ideas to a war of lawsuits; third, whatever the final outcome, the Anthropic affair will be the citation of origin for AI governance debates for the next decade. When safety itself becomes the risk, no one can afford to sit this one out.

Sources: Reuters, POLITICO (via Business Insider), The Straits Times, Ars Technica, The New York Times (September 25, 2026 reporting)

Related Posts

  • September 25, 2026
Google’s One-Two Punch: Gemini “Call for Me” Phones Businesses for You as Live Avatar Gives AI a Face

Google shipped two major Gemini updates on September 24: “Call for Me” lets the AI dial businesses from your own number to book reservations, check stock, and wait on hold — with a live transcript and instant takeover — while Gemini 3.8 Live’s new “Live Avatar” gives enterprise AI a lip-synced, expressive face that switches across 97 languages in real time. Together they mark Google’s push from chatbot to true AI agent.

  • September 24, 2026
Figure’s $1 Billion Bet Pays Off: Helix 2.5 Humanoid Robot Nails 56% of Chores in 30 Unseen Homes — a 6X Jump

Figure AI’s latest neural network, Helix 2.5, completed 237 household tasks across 30 Bay Area homes its robots had never entered, hitting a 56% success rate — a 6X jump over the 9% baseline of a model trained from scratch. Bed making hit 67%, towel folding 62%, and toy tidying lagged at 40%. CEO Brett Adcock calls zero-shot generalization the industry’s holy grail, powered by the new Index data platform. Qualcomm’s same-week acquisition of PickNik signals the physical AI arms race is heating up.