Refusing to give the military unrestricted access to its AI model just cost Anthropic. A federal appeals court in Washington ruled on Friday that the Department of Defense may keep the company listed as a "supply chain risk," a category historically used for vendors tied to espionage or sabotage.

The 2-1 decision, reported by CNBC, rejected all three of Anthropic's arguments: that the exclusion was arbitrary, unauthorized by law, and unconstitutional. According to the D.C. Circuit panel, the Department "had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk."

How caution became the risk

The case goes back to July 2025, when Anthropic signed a $200 million contract with the Pentagon. Talks to deploy Claude on the DOD's GenAI.mil platform collapsed months later: the Department wanted unrestricted access to the model for any lawful purpose, while Anthropic wanted assurance its technology would not be used for fully autonomous weapons or domestic mass surveillance.

That standoff is the strange core of the ruling. According to the judges, a system a military customer cannot fully predict counts, by definition, as a supply chain problem, whatever the reason for that unpredictability. The safety guardrails Anthropic built on purpose, to block certain uses, were read by the court as the very source of the risk. It is hard to imagine a more uncomfortable incentive for any AI vendor trying to hold an ethical line in military contracts.

Two courts, two opinions

The opinion was written by Circuit Judge Gregory Katsas, joined by Circuit Judge Neomi Rao; Circuit Judge Karen LeCraft Henderson dissented. The outcome contrasts with a San Francisco federal judge's ruling last month, which found a parallel designation against Anthropic unlawful under the First Amendment. Two federal courts splitting on the same kind of designation, within weeks of each other, signals that the legal doctrine around "supply chain risk" applied to AI models is still being written, not settled.

The D.C. Circuit panel stayed its decision to give Anthropic time to seek rehearing by the same panel or by the full court. Petitioning the Supreme Court is also on the table. In a statement, the company said it "respectfully" disagreed with the ruling, noting that another federal court has already found the government's parallel designation unlawful.

What it means for anyone with a government contract

Beyond the political headlines, this matters to any team negotiating AI deals with the US government, or with any institutional customer that makes unrestricted model access a condition of the contract. The practical lesson so far: refusing to remove safety guardrails can be treated legally as evidence of risk, not as prudence. Worth watching whether the D.C. Circuit's precedent survives rehearing, or whether the Supreme Court takes up the merits. Until then, the question hangs there: if a vendor's caution can be reclassified as a threat, which company keeps saying no to a military contract?