Primary sourceAIArticle··8 min read

Anthropic Loses to the Pentagon: Aligning Claude Counts as "Manipulating" It

The federal appeals court in Washington upholds Claude's exclusion from the military supply chain: an AI's ethical guardrails can constitute a national security risk.

Anthropic Loses to the Pentagon: Aligning Claude Counts as "Manipulating" It
Source : Cour d'appel des États-Unis pour le circuit du District de Columbia (juge Gregory Katsas ; dissidence de la juge Karen LeCraft Henderson) · media.cadc.uscourts.govView original ↗

In brief

On September 25, 2026, the D.C. Circuit Court of Appeals rejected, by a 2-1 vote, Anthropic's challenges to its exclusion from the Department of War, a decision made after the company refused to authorize Claude for "any lawful use." According to the majority, Claude's "constitutional" training amounts to "manipulating" the product under the 2018 supply chain security law, with no malicious intent required. The ruling turns an AI vendor's ethical red lines into a legal ground for exclusion.

🍺 Bar-stool version

Anthropic told the U.S. military: you can do anything with Claude, except two things—weapons that kill on their own, and mass surveillance of Americans. The military responded by labeling it a "supply chain risk," a designation normally meant for vendors suspected of working for a foreign power. The appeals court signs off: giving your AI principles, legally speaking, counts as "manipulating" it, no matter your good faith—kind of like firing a chef for refusing to poison the soup, on the grounds that he has opinions about cooking. Every AI vendor now knows exactly how much a red line costs when facing the Pentagon.

Key takeaways

  1. 1

    The D.C. Circuit Court of Appeals (Judges Katsas, Rao, and Henderson) rejects Anthropic's challenges 2-1; Judge Karen LeCraft Henderson writes a dissenting opinion.

  2. 2

    Anthropic had agreed to significantly loosen its restrictions (weapons design, foreign intelligence, offensive cyber), but refused to let Claude be used for autonomous lethal warfare and mass surveillance of Americans.

  3. 3

    On March 3, 2026, Pete Hegseth excluded Claude under the 2018 Federal Acquisition Supply Chain Security Act, requiring removal of systems within 180 days at most and barring subcontractors.

  4. 4

    For the majority, "manipulating" a product's design or operation requires no malicious intent: the risk definition "turns on what Anthropic does, not why Anthropic does it."

  5. 5

    Anthropic's technical argument (no "kill switch," frozen models once delivered, possible pre-testing) is dismissed: the Pentagon cannot make do with systems "trapped in amber" while models keep advancing.

  6. 6

    The constitutional claims fail: post-hoc process is sufficient given the urgency, and the exclusion stems from a contractual disagreement, not punishment of Anthropic's speech about AI regulation.

  7. 7

    The court distinguishes itself from an August 27, 2026 California ruling that struck down a designation based on a different statute (10 U.S.C. § 3252), whose narrower definition targets an "adversary."

Two Red Lines and an Ultimatum

It all starts in 2024, when the Pentagon and intelligence agencies use Claude through subcontractors on their classified systems. The commercial model then refuses legitimate tasks: summarizing threat assessments, processing classified documents, translating intercepts describing violence.

Anthropic responds with Claude Gov, launched in March 2025, and a government-specific contract addendum. In July 2025, the company becomes part of a $200 million AI contract. It eventually authorizes weapons design, foreign intelligence analysis, and offensive cyber operations, but keeps two prohibitions: autonomous lethal warfare and mass surveillance of Americans.

On January 9, 2026, Pete Hegseth publishes an "AI-first" strategy demanding models "free from usage-policy constraints" and an "any lawful use" clause. At the same time, an Anthropic executive raises questions about Claude's use in a foreign military operation, which press reports filed in the record link to the capture of Nicolás Maduro on January 3. Also added: a Claude refusal in response to CDC requests about infectious disease prevention.

On February 24, Hegseth meets Dario Amodei and sets an ultimatum for the 27th. On the 26th, Amodei publicly refuses while promising a "smooth transition." On the 27th, Trump and Hegseth denounce Anthropic on social media; the formal designation lands on March 3, and the Pentagon turns to OpenAI.

The Heart of the Ruling: Manipulation Without Malice

The law defines "supply chain risk" as the risk that someone could "sabotage, maliciously introduce an undesired function, extract data, or otherwise manipulate" a computer product in order to "surveil, deny, disrupt, or otherwise manipulate" its operation.

Anthropic argued that this language implies hostile intent. Judge Gregory Katsas sticks to the ordinary meaning: to manipulate is "to arrange, operate, or control skillfully." In his view, there is not just a risk but a "certainty" that Anthropic configures Claude to deny it the autonomous warfare or mass surveillance function.

The majority acknowledges Anthropic's "noble intentions," whether about privacy or AI safety, but deems them irrelevant. It adds that a national security procurement law, carrying no criminal or civil liability, is interpreted in favor of the executive branch when ambiguous.

The contrast with California is central. On August 27, 2026, a federal court there had struck down the designation based on 10 U.S.C. § 3252, whose definition targets an "adversary" and "subversion." The appeals court does not dispute that reading or Anthropic's lack of bad faith, but rules that the 2018 law is far broader.

Why the Lack of a Kill Switch Isn't Enough

Anthropic claimed it could neither access, modify, nor shut down a model once delivered onto classified systems. The Pentagon could therefore test each new version and keep the older one if it didn't suit its needs.

The court dismisses the argument. The contested restrictions are not "self-defining": there are countless degrees of human involvement in a targeting decision. Under Secretary Emil Michael highlights the opacity of models he says count "5 to 10 trillion" parameters, which would make rigorous auditing "mathematically impossible." Anthropic itself acknowledges that Claude can respond differently depending on how a request is phrased.

Refusing updates isn't an option either, according to the judges. Anthropic delivered three versions of Claude Gov in 2025, and Amodei himself speaks of autonomous drone swarms forming an "unbeatable army." The Pentagon cannot use AIs that remain "trapped in amber," the court concludes.

Urgency, Process, and the First Amendment

Regarding less intrusive measures, Anthropic pointed to reputational harm. The court doubts this, citing the Wall Street Journal, according to which the company received investment offers valuing it at over $900 billion. The idea of restricting the exclusion to only sensitive systems is deemed insufficiently argued, and impractical for a model embedded in other applications.

On urgency, the court doesn't rule on the merits and applies the harmless-error rule. Anthropic was able to respond as early as March 19, and its request for reconsideration was denied on June 3: earlier notice would have changed nothing. Post-hoc process is also sufficient for due process purposes, especially since strikes against Iran, reportedly using Claude according to the WSJ, began two days after Anthropic's refusal.

On free speech, the court acknowledges that Anthropic's advocacy for safe AI is protected and that the exclusion is a real penalty. However, it finds no causal link: the Pentagon worked with Anthropic for years despite this rhetoric. Hegseth's remarks about "moralizing rhetoric" and "virtue-signaling" change nothing, since the core of the dispute remains the refusal of a "veto right" over military decisions.

Judge Henderson's Dissent: A Troubling Blank Check

Judge Karen LeCraft Henderson holds to the narrow meaning of "manipulate": to influence in a "subtle, sneaky, or unfair" way. She invokes the canons noscitur a sociis and ejusdem generis: a word is understood by the company it keeps, and "sabotage" or "maliciously introduce" color the rest of the list.

She illustrates this with an imaginary library rule: "do not shout, talk loudly on the phone, play music, or otherwise disturb others." No one would read that as banning headphone use. The majority responds that this example works for a different reason, and that the adverb "maliciously" only modifies the verb that follows it.

Her strongest argument concerns the consequences. Under the majority's reading, any vendor that honestly and openly enforces restrictions already accepted by the government becomes a potential threat. Its successor would face the same choice: cave, or be designated a national security risk. She notes, finally, that the law was aimed, per its legislative history, at hostile states and companies "beholden to foreign governments."

The Last Word Belongs to the Executive

The majority's conclusion acknowledges the difficulty. On one hand, overly restricted models that would stop functioning mid-operation. On the other, models without guardrails that would "hallucinate" targets for a lethal strike.

Both risks are matters of national security, the court finds. But "in our Republic," it is up to the President and the Secretary of War to weigh them against each other. The challenges are rejected.

“At least as applied here, the statutory definition of a “supply chain risk” turns on what Anthropic does, not why Anthropic does it.”
“Quite obviously, the Department cannot utilize AI systems that remain trapped in amber.”
“A contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government. (Judge Henderson, dissenting)”

Why it matters

This is the first major appellate ruling on the question the entire industry dreaded: can an AI lab impose its own usage limits on the government? The majority's answer is conceptually brutal. Alignment—the discipline of embedding values into a model's weights, which Anthropic presents as the core of its mission—becomes, legally, a "manipulation" of the product, and thus a supply chain risk. The reasoning holds up on procurement law grounds: the buyer chooses its vendors. Yet it carries a cost that Judge Henderson rightly points out. A tool designed against foreign espionage is now used to discipline a good-faith domestic vendor, and the message sent to OpenAI, Google, and others is unmistakable: no red lines when facing the Pentagon. The ruling also leaves a paradox unresolved. It relies on the opacity of models to justify the exclusion, even though that same opacity is Anthropic's argument against fully autonomous weapons. An open disagreement with the California court remains, making a Supreme Court appeal plausible.

#anthropic#claude#defense#justice#regulation#national security
Original source
Anthropic PBC v. United States Department of War, No. 26-1049 (D.C. Cir., 25 septembre 2026)
Cour d'appel des États-Unis pour le circuit du District de Columbia (juge Gregory Katsas ; dissidence de la juge Karen LeCraft Henderson)
Open the article ↗

For you

Put it to work on your sources.

Free: this week's articles and three sources of your own. Pro: the whole archive and your sources, from €8/month.

For your team

The same machine, on your topics.

A space in your colours, your watch angles, your curators. Pilot open to three companies.

Read next