AI Policy · National Security · Updated September 27, 2026

Pentagon Rules Claude a National Security Supply Chain Risk: The Ban, the Reasons and the Court Fight

The U.S. military has formally classed Anthropic's Claude as a national security supply chain risk — the first time that label has ever been applied to an American company — and on September 25, 2026 a federal appeals court in Washington upheld it. This page lays out why the Pentagon sees Claude as a risk, exactly which systems the ban covers, the two lawsuits Anthropic filed, and what the 2–1 ruling against the company means for defense contractors and for Anthropic's planned IPO.


Satirical illustration: a uniformed Pentagon official slapping an Anthropic AI mascot at a Pentagon podium, commentary on the Pentagon ruling Claude a supply chain risk

Satirical illustration — not a photograph of any real official.

What the Pentagon Ruled

Quick answers (updated September 27, 2026)

Is Claude a Pentagon supply chain risk? Yes. Defense Secretary Pete Hegseth directed the designation on February 27, 2026; letters dated March 3 made it formal, “effective immediately.”

Why? Anthropic refused to drop two limits on Claude — no mass domestic surveillance of Americans and no fully autonomous weapons — while the Pentagon demanded use for “all lawful purposes.”

Did Anthropic win in court? Partly. A California judge struck down one designation in August, but on September 25 the D.C. Circuit upheld the other, 2–1.

Is it the first time? Yes — the first supply chain risk designation ever applied to an American company.

The Department of War — the Pentagon's secondary name since September 2025 — did not simply cancel a contract with Anthropic. It reached for the most serious tool in federal procurement: a formal finding that a supplier poses a supply chain risk to national security. On February 27, 2026, the same afternoon a Pentagon deadline for Anthropic to drop its usage restrictions expired, President Trump directed every federal agency to stop using Anthropic's technology, giving agencies including the Pentagon six months to phase it out, and Secretary Hegseth directed the supply chain designation.

Letters dated March 3, 2026 formally notified the company, and by March 6 the Pentagon was describing the label as effective immediately. Law firms advising contractors identified two authorities behind it: the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA, 41 U.S.C. § 4713), which reaches across federal procurement, and 10 U.S.C. § 3252, the Defense Secretary's power to exclude sources from national security system contracts. The General Services Administration also removed Anthropic from USAi.gov, the government's central AI testing platform.

These authorities were built with foreign adversaries in mind — the kind of exclusion better known from Chinese telecom and security vendors. Anthropic called the move unprecedented and legally unsound, an action “never before publicly applied to an American company.”

Claude designated a Pentagon supply chain risk: first American company, FASCSA and 10 U.S.C. 3252, six-month phase-out Two statutes behind the Anthropic supply chain label: FASCSA 41 U.S.C. 4713 and 10 U.S.C. 3252

Why the Pentagon Sees Claude as a Security Risk

Anthropic's two red lines: no mass domestic surveillance, no fully autonomous weapons; Pentagon demanded all lawful purposes Quote from Judge Gregory Katsas: continued integration of Claude presented a statutorily covered national-security risk

The dispute is not about hackers, foreign ownership or a hidden backdoor. It is about who controls how the model is used. In July 2025 Anthropic and the Pentagon signed a contract that made Claude the first frontier AI model approved for the military's classified networks, under Anthropic's acceptable use policy — which ruled out mass domestic surveillance and fully autonomous weapons. Claude was reportedly used in the U.S. operation in Venezuela in early 2026.

By January 2026 the Pentagon wanted those terms renegotiated so the military could use Claude for “all lawful purposes” without company-imposed exceptions. After weeks of talks, Anthropic said the final offer still left the door open to the surveillance and weapons uses it had refused, and it let the February 27 deadline pass.

From the Pentagon's side, that refusal is the risk. A model whose developer can decline certain missions — and which is trained to refuse certain requests on its own — is, in this view, a component the military cannot fully rely on in an operation. The D.C. Circuit majority accepted that framing: it found the Department had enough evidence to conclude that Claude's built-in restrictions and the unresolved contract dispute could make it unreliable for military operations, noting the restrictions had more than once stopped Claude from doing tasks government users asked for.

Anthropic's position is the mirror image: the company says it was punished for its public stance against lethal autonomous warfare and surveillance of Americans, and that the supply chain statutes were designed to stop sabotage by adversaries, not to settle a contract negotiation with a U.S. supplier that disclosed its limits up front. Defense Secretary Hegseth's response to the court win summed up the government's view: “The @DeptofWar does what is right for the Country and our Warriors.”

What the Ban Covers — and What It Doesn't

The headline — “Pentagon bans Claude” — is broader than the law behind it. Under 10 U.S.C. § 3252, the exclusion applies to covered systems: information technology used for intelligence, cryptologic activities, military command and control, and weapons systems. Routine administrative applications such as payroll, HR and finance are outside that authority. Legal analysts at Just Security stressed that § 3252 is “a procurement authority, not a sanctions authority”: it lets the Department keep a supplier out of sensitive contracts and require prime contractors to drop it from subcontracts, but it does not force anyone to divest from, or stop doing ordinary business with, the company.

Barred
Claude in the Pentagon's national security systems, and in contractors' performance of covered defense work.
Phase-out
Six months for federal agencies, including the Pentagon, under President Trump's February 27 directive.
Not covered by § 3252
Payroll, HR, finance and other routine administrative IT; contractors' purely commercial use of Claude.
The grey zone
Hegseth's statement said contractors working with the military could not conduct any commercial activity with Anthropic — wider than the statutes themselves contemplate, according to Mayer Brown and Just Security.

The Pentagon's own supply chain framework explains why AI models now fall under this lens at all. The Department of War CIO's memorandum on commercial off-the-shelf information and communications technology supply chain risk management directs components to treat commercial software as part of the warfighting supply chain and to verify its security and reliability, rather than relying on vendor self-attestation. A frontier model sitting inside classified networks is exactly that kind of commercial component.

What the Pentagon Claude ban covers: intelligence, cryptologic, command and control and weapons systems, not payroll or HR Just Security: 10 U.S.C. 3252 is a procurement authority, not a sanctions authority Pentagon ICT supply chain framework: commercial software including AI models treated as warfighting supply chain

Timeline: From Classified Contract to Blacklist

Timeline of the Pentagon Anthropic dispute: lawsuits March 9, injunction March 26, Lin ruling August 28, D.C. Circuit September 25 Six-month federal phase-out of Claude ordered February 27 2026; GSA removed Claude from USAi.gov Two courts, two outcomes: N.D. California ruled the designation unlawful, D.C. Circuit upheld it

Seven months separate the Pentagon's ultimatum from the appeals ruling. The sequence below is drawn from court rulings, company statements and reporting by NPR, CNN, ABC News, CNBC and TechCrunch.

Pentagon–Anthropic supply chain dispute, as of September 27, 2026
DateEventStatus
Jul 2025Anthropic and the Pentagon sign a contract making Claude the first frontier AI model approved for classified networks.Company-confirmed
Sep 5, 2025The Department of Defense adopts “Department of War” as a secondary name.Official
Jan 2026The Pentagon seeks to renegotiate so Claude can be used for “all lawful purposes.”Reported
Feb 23, 2026xAI reaches a deal for Grok to be used in classified systems.Reported
Feb 27, 2026Hegseth's 5:01 p.m. deadline passes. Trump orders all federal agencies to stop using Anthropic (six-month phase-out); Hegseth directs the supply chain risk designation. OpenAI announces its own Pentagon agreement the same day.Official
Mar 3, 2026Letters formally notify Anthropic of the designation.Company-confirmed
Mar 6, 2026The Pentagon says the label is effective immediately.Official
Mar 9, 2026Anthropic sues in two courts: the Northern District of California and the D.C. Circuit.Court record
Mar 26, 2026Judge Rita Lin grants a preliminary injunction in California.Court record
Apr 2026The D.C. Circuit declines to stay the designation while the case proceeds.Court record
Aug 28, 2026Judge Lin rules the parallel designation unlawful: First Amendment retaliation, due process violation, arbitrary and capricious.Court record
Sep 25, 2026The D.C. Circuit upholds the designation under the 2018 supply chain law, 2–1 (Katsas and Rao; Henderson dissenting).Court record

The California Ruling That Went the Other Way

Judge Rita Lin's August 2026 ruling: First Amendment retaliation, due process, arbitrary and capricious Judge Rita Lin quote: a desire to make a public example out of Anthropic for its arrogance in criticizing the government

The appeals ruling was a reversal of fortune, because Anthropic had won the first round decisively. On March 26 U.S. District Judge Rita Lin in San Francisco granted a preliminary injunction, and on August 28, 2026 she ruled the parallel designation unlawful on three separate grounds:

First Amendment
Unlawful retaliation. Lin found the government's actions “were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government.”
Fifth Amendment
Anthropic was denied the due process the Constitution requires.
Administrative law
The decision was “arbitrary and capricious.”

The two rulings do not directly cancel each other out. They concerned two parallel designations, which is why Anthropic filed in two courts on March 9; the D.C. Circuit case concerned the one made under the 2018 supply chain security law. The practical result after September 25 is a split outcome: one label struck down in California, the other left standing in Washington — and the Pentagon's exclusion of Claude from covered national security work continues while Anthropic decides on its next move.

OpenAI, xAI and Google Fill the Gap

The Pentagon did not go without frontier AI. OpenAI announced its own agreement on the same day Anthropic was cut off. It accepted the “all lawful purposes” framework but layered on its own controls: cloud-only deployment, a proprietary safety stack the Pentagon agreed not to override, and cleared OpenAI engineers embedded with the programme. OpenAI later revised the deal after critics raised surveillance concerns. xAI had already reached a deal on February 23 for Grok to run in classified systems, and Google's Gemini had been the first model on the Pentagon's GenAI.mil platform in December 2025.

That contrast is the clearest illustration of how the Pentagon draws the line. Every major lab keeps safety policies; the difference is whether the government or the vendor has the final say over which lawful missions are off-limits. OpenAI's structure left that decision with the Department; Anthropic's two contractual exceptions did not.

Rival AI suppliers the Pentagon turned to: OpenAI all lawful purposes deal, xAI Grok classified, Google Gemini on GenAI.mil

What Defense Contractors Must Do Now

What FAR 52.204-30 requires of defense contractors: quarterly SAM.gov checks, report in 3 business days, mitigation plan in 10 FASCSA flow-down obligations reach every subcontractor tier; mitigation plan due in 10 business days

For companies that sell to the federal government, the designation is a compliance task, not a headline. Under the FASCSA contract clause, FAR 52.204-30, contractors must check SAM.gov for exclusion orders at least quarterly, make reasonable inquiries to find any covered use of the designated product, report within three business days if it was provided to the government, and file a mitigation plan within ten business days. Those duties flow down to every subcontractor tier.

The open question is how far “use” extends. The statutes restrict Claude in federal contract performance, but Hegseth's broader statement about contractors' commercial activity left the boundary for internal, non-contract use unclear. Firms running AI coding assistants, document tools or agent platforms built on Claude should map exactly which workflows touch covered contracts, and get advice from counsel rather than relying on press summaries — including this one.

For data centre developers and infrastructure buyers, the case shows why AI supplier risk is now a procurement line item. Our AI Build Configurator models the power and capital side of an AI build; the supply chain side increasingly depends on which model vendors a site's tenants are allowed to run.

What Happens Next

Anthropic has two obvious routes in the D.C. Circuit case: ask the full court to rehear it en banc, leaning on Judge Henderson's dissent about what the 2018 statute actually covers, or petition the U.S. Supreme Court. A case asking whether a national security procurement law can be used against a domestic supplier over its usage policy — with the executive branch and a district court on opposite sides — is the kind of question the higher courts take seriously.

The timing matters for a second reason. Anthropic is expected to go public in November 2026, and a live federal blacklist is precisely the kind of dispute that has to be disclosed in an IPO prospectus. Follow our Anthropic IPO date and price tracker for how the filing treats it, our Anthropic AI page for the company background, and our AI data center stocks list for the companies on both sides of this build-out.

What happens next for Anthropic after the D.C. Circuit ruling: en banc rehearing, Supreme Court petition, IPO risk factor

Frequently Asked Questions

Did the Pentagon rule Claude a national security supply chain risk?

Yes. On February 27, 2026, Defense Secretary Pete Hegseth directed that Anthropic be designated a supply chain risk, letters dated March 3 formally notified the company, and the Pentagon described the label as effective immediately. It was the first time the designation had been applied to an American company. On September 25, 2026, the U.S. Court of Appeals for the D.C. Circuit upheld the designation 2-1.

Why does the Pentagon see Claude as a security risk?

The dispute began when Anthropic refused to let the military use Claude for mass domestic surveillance of Americans or for fully autonomous weapons, while the Pentagon wanted access for all lawful purposes. The Pentagon's position, which the D.C. Circuit majority accepted, is that Claude's built-in restrictions and the unresolved contract dispute could make it unreliable for military operations; the court noted the restrictions had more than once stopped Claude from doing tasks government users asked for.

Is Claude banned from all Pentagon systems?

The designation bars Claude from covered national security systems - IT used for intelligence, cryptologic activities, military command and control and weapons systems - and requires defense contractors to keep it out of that work. The statutory authority does not reach routine administrative systems such as payroll or HR, and it is a procurement authority rather than a sanctions authority. Separately, President Trump directed all federal agencies to stop using Anthropic technology, with a six-month phase-out.

What was the legal setback for Anthropic?

On September 25, 2026, a D.C. Circuit panel ruled 2-1 against Anthropic. Judge Gregory Katsas wrote the majority opinion, joined by Judge Neomi Rao, finding the Department had ample support for treating Claude's continued integration into its systems as a covered national security risk. Judge Karen LeCraft Henderson dissented.

Didn't a judge rule the designation unlawful?

Yes, in a separate case. In August 2026, U.S. District Judge Rita Lin in California ruled that a parallel designation was unlawful First Amendment retaliation, violated due process and was arbitrary and capricious. The D.C. Circuit ruling leaves the second designation, made under a 2018 supply chain security law, in place.

What happens next?

Anthropic said it remains confident in its position and is considering all options, including further review - which could mean asking the full D.C. Circuit to rehear the case or petitioning the Supreme Court. The dispute is also a live risk factor as Anthropic prepares for its expected November 2026 IPO.