Background
Anthropic develops Claude, a family of artificial-intelligence models. The Department of War integrated Claude into military systems but sought contractual permission for uses that Anthropic’s policies prohibited, including lethal autonomous warfare and mass domestic surveillance. After Anthropic declined to relax those restrictions, the Department designated the company a supply-chain risk under the Federal Acquisition Supply Chain Security Act and began excluding Claude from Department systems and contracts.
Anthropic petitioned the D.C. Circuit for direct review. It argued that the designation exceeded the statute, lacked adequate factual support, denied due process, and retaliated against protected expression. The case also required the court to address the effect of Anthropic’s request for agency reconsideration while judicial review was pending.
The Court’s Holding
A divided panel denied the petitions. The majority held that jurisdiction was secure and that the Department reasonably treated continued integration of Claude as a covered supply-chain risk. In the majority’s view, the statute allowed the Department to consider whether a supplier’s contractual restrictions could impair access to or use of technology in national-security systems. The dispute was not limited to whether Anthropic could secretly manipulate a deployed model; the Department could also consider the operational risk created by depending on a supplier unwilling to authorize uses the military considered necessary.
The majority rejected Anthropic’s procedural challenge because the company ultimately received notice, an opportunity to seek reconsideration, and a reasoned final agency decision. Any earlier procedural defect caused no prejudice after that process occurred.
The First Amendment claim also failed. The court accepted that Anthropic’s public positions and usage policies implicated expression, but concluded that the Department acted because of a contractual and operational disagreement over permitted uses of Claude, not to punish Anthropic for its viewpoint. Judge Henderson dissented.
Key Takeaways
- Federal supply-chain authority can reach contractual restrictions that affect how an agency may deploy an AI product, not only technical backdoors or cybersecurity flaws.
- A later reconsideration process can defeat a due-process claim when it supplies meaningful notice and review without demonstrated prejudice.
- An AI provider’s ethical use restrictions may involve protected expression, but procurement consequences do not automatically establish unconstitutional retaliation.
Why It Matters
The ruling puts a major legal marker on the relationship between frontier-model providers and government customers. AI companies often use licenses and acceptable-use policies to prevent deployment in sensitive contexts. The decision gives national-security agencies substantial room to treat those restrictions as supply-chain considerations when they conflict with mission requirements.
For contractors, the practical lesson is that model-governance terms can affect eligibility throughout a federal supply chain, including subcontracting. For policymakers, the case highlights a difficult boundary: companies may articulate ethical limits on their technology, while the government retains broad discretion to choose suppliers that will support authorized missions. The dissent signals that the constitutional and statutory limits of that discretion remain contested.
Your browser cannot display this PDF inline.
Download the full opinion (PDF)