Pentagon Can Blacklist Any AI Ethics Policy Under Supply Chain Law FASCSA, Court Rules

September 28, 2026:

Pentagon Can Blacklist Any AI Ethics Policy Under Supply Chain Law FASCSA, Court Rules
U S Secretary War Pete Hegseth speaks
U.S. Secretary of War Pete Hegseth speaks during the Department of War’s 2026 National POW/MIA Recognition Day Ceremony on the Pentagon River Terrace Parade Field on September 18, 2026 in Arlington, Virginia.
Andrew Harnik/Getty Images

A federal appeals court handed the Pentagon a statutory weapon it never asked Congress for: the confirmed legal power to designate any domestic AI company a national security supply chain risk — no evidence of bad faith required, no foreign entanglement needed, no notice to Congress — whenever that company’s built-in ethics restrictions happen to conflict with what a Defense Secretary wants to do with its technology. The 2-1 ruling from the U.S. Court of Appeals for the District of Columbia Circuit arrived Friday in the case of Anthropic PBC v. United States Department of War, but its most consequential sentence belongs not to the two-judge majority but to the lone dissenter, Judge Karen LeCraft Henderson, who spent seventeen pages explaining what the majority had just made possible: “The successor’s choice will be simple: agree to the Secretary’s demands or risk being designated a national security threat.”

That is not a warning about Anthropic’s situation. That is a warning about every AI company’s future.

A Tale of Two Courts and Two Statutes

To understand what Friday’s ruling actually decided, you first have to understand why the same dispute was being fought simultaneously in two federal courts under two different laws.

In early March 2026, Defense Secretary Pete Hegseth signed two separate designation letters declaring Anthropic a supply chain risk. The first invoked 10 U.S.C. § 3252, a 2011 statute that governs Pentagon national-security information systems and — critically — requires the government to show that the designated entity poses the kind of risk associated with a malicious or adversarial actor. The second invoked 41 U.S.C. § 4713, part of the Federal Acquisition Supply Chain Security Act of 2018, known as FASCSA, which governs procurement across the entire federal government and was written with considerably broader language.

Because Congress built each statute with its own definition of supply chain risk and its own venue for judicial review, the two letters spawned two separate lawsuits in two separate courts. Anthropic filed in both venues. The cases traveled on parallel tracks and reached opposite conclusions.

The first track ended in San Francisco. U.S. District Judge Rita Lin issued a permanent injunction on August 27, 2026, ruling that the § 3252 designation was unlawful. Her reasoning: that statute requires a showing of bad motive — the kind of hostile, clandestine intent associated with, say, a Chinese state-linked hardware supplier secretly backdooring firmware — and the government had none to offer against a U.S. company openly encoding ethics limits into its products. Anthropic won that one.

The second track ended Friday in Washington, and it went the other way.

The Ruling: What You Do, Not Why You Do It

Circuit Judges Gregory Katsas and Neomi Rao — both appointed by President Trump — formed the majority. In a 43-page opinion authored by Katsas, the panel upheld the FASCSA designation on every ground Anthropic contested: statutory authority, arbitrariness, due process, and the First Amendment.

The core of the majority’s reasoning is a statutory one. FASCSA, unlike the 2011 law at issue in California, does not require an “adversary.” It applies to “any person” and defines supply chain risk broadly enough to include a contractor who, for whatever reason, is “willing and able” to prevent the government from using its technology for purposes the government deems necessary.

“The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk,” Katsas wrote.

Crucially, the majority acknowledged the obvious. “We have no reason to doubt that Anthropic manipulates Claude’s function, use and operation with noble intentions,” Katsas wrote. But under FASCSA, the court concluded, the statute turns on what a contractor does, not why it does it. Anthropic’s refusal to permit Claude to be used for fully autonomous lethal weapons systems or the mass domestic surveillance of American citizens — encoded directly into the model’s training — constituted “manipulation” of the product in a way the Defense Department reasonably deemed a risk.

The panel also rejected Anthropic’s First Amendment argument. The company argued the Pentagon had retaliated against it for its public advocacy on AI safety, pointing partly to Hegseth’s documented statements about the company’s “sanctimonious rhetoric,” “virtue-signaling,” and “Silicon Valley ideology.” The court found that the government excluded Anthropic “based on the company’s refusal to assent to a contract term that the Department deemed essential, not based on the company’s support” for any particular viewpoint.

The Technical Core: How Claude’s Safety Restrictions Are Built, Not Bolted On

The majority’s statutory analysis turns on the word “manipulate,” and there is a technical dimension to that analysis that the opinion largely ignored — one that matters enormously for what the ruling means going forward.

Claude’s ethics restrictions are not a real-time filter that Anthropic applies on top of an otherwise unconstrained model. They are trained into the model itself through Reinforcement Learning from Human Feedback (RLHF) and Constitutional AI techniques developed by Anthropic’s research team. This is a foundational architectural choice: the behavioral limits are parameters embedded in the neural network’s weights during training, not rules applied at inference time by an external policy engine.

The practical consequence is significant. A Claude model without those restrictions would not be the same model with a switch flipped — it would be a different model, produced by a different training process. Anthropic cannot hand the Pentagon an unrestricted Claude by simply modifying a contract term or removing a content filter. The company would have to build and train an entirely separate model variant.

This distinction matters for statutory interpretation. FASCSA’s definition of supply chain risk covers risk that “any person” may “sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance” of a covered article. The majority read “otherwise manipulate” to cover Anthropic’s publicly-stated, transparently-documented training choices. But the word “manipulate” in its statutory context — surrounded by “sabotage,” “maliciously introduce unwanted function,” and “extract data” — connotes interference by a hostile external actor, not design decisions made openly by the developer building the product for its own legitimate commercial reasons.

What the majority effectively held is that a model’s trained values are a supply chain risk if a government customer wants different ones. That is not an anti-espionage ruling. It is a ruling about who controls the ethical architecture of AI systems that touch government procurement.

“The Secretary’s Choice Will Be Simple”: Henderson’s Dissent

Judge Karen LeCraft Henderson, appointed to the DC Circuit by President George H.W. Bush in 1990, was the lone dissenter. Her dissent focuses on statutory interpretation — she argued that “manipulate” requires “intentionally hostile or clandestine purpose” — but its most important passages are a structural warning about what the majority made possible.

Henderson argued that FASCSA was enacted in direct response to intelligence community concerns about sabotage by malignant foreign powers — specifically, hostile and clandestine interference with hardware and software supply chains. The statute’s phrase “or otherwise manipulate,” she argued, must be read in that context: it captures the kind of covert, hostile action associated with, for example, a Chinese state-linked manufacturer embedding a surveillance chip in server hardware, not a U.S. company openly publishing usage policies that restrict certain applications.

“I cannot agree that this is the scenario the Congress had in mind when it enacted FASCSA,” she wrote.

Her sharpest warning, however, was about the precedent the majority created. Under the majority’s rule, a contractor becomes a supply chain risk the moment it is “willing and able to enforce contractual restrictions,” regardless of whether the government previously accepted those restrictions, whether the contractor is acting in good faith, and whether the restrictions protect against uses that would violate federal law or the Constitution.

The logical endpoint Henderson sketched is precise: a Defense Secretary could tell any AI company to revise its usage policy to permit any function the Department deems necessary — or share Anthropic’s fate. “The successor’s choice will be simple: agree to the Secretary’s demands or risk being designated a national security threat.”

That framing transforms the majority’s ruling from a case-specific outcome into a standing legal instrument.

Pentagon’s New Legal Template: No Bad Faith, No Foreign Ties, No Congressional Notice

FASCSA was enacted in 2018 to protect federal supply chains from the Huawei problem — foreign state-linked companies embedding malicious functionality into hardware and software that ended up in federal systems. Before Friday’s ruling, every known FASCSA designation involved a company with documented ties to a foreign authoritarian state or specific evidence of malicious behavior: Huawei, ZTE, Kaspersky, DJI. Anthropic is the first domestic company ever designated under FASCSA for ethics-policy conduct rather than security misconduct.

The majority’s ruling creates a template with three structural properties that Henderson identified and the majority did not dispute:

First, no bad faith is required. The government does not need to show that an AI company is acting maliciously, is compromised by a foreign power, or intends to harm government operations. It needs only to show that the company’s product, as designed and trained, cannot perform a function the government wants.

Second, no foreign entanglement is required. FASCSA’s “any person” language is not limited to foreign-linked entities. The majority confirmed this reading explicitly, distinguishing FASCSA from the § 3252 statute that Judge Lin applied in California — which does require adversary-adjacent conduct.

Third, no Congressional authorization is required. FASCSA designations are executive-branch decisions. The statute does not require the Defense Secretary to notify Congress before issuing a designation, does not require notice-and-comment rulemaking under the Administrative Procedure Act, and does not require any showing of process beyond the designation letter itself. Unlike legislation or formal regulation, a FASCSA designation can be issued, appealed, and upheld — as happened here — without any formal democratic input.

What that combination produces, as Henderson observed, is a procurement-law mechanism for imposing content requirements on AI models that operates entirely outside normal checks. An AI company that trains its model to refuse certain harmful uses cannot be compelled by Congress to remove those limits without a new law, cannot be compelled by the FTC without a specific enforcement theory, and cannot be compelled by the courts without a specific legal violation. But a Defense Secretary can now threaten a FASCSA designation — with no bad faith showing, no foreign link, no APA process — as leverage to extract precisely that concession. The ruling hands that leverage to every future Defense Secretary as inherited executive power.

From Contract to Blacklist: How the Dispute Began

The dispute traces back to a contract Anthropic signed with the Pentagon in July 2025, reportedly valued at around $200 million, to prototype frontier AI capabilities for the Defense Department. As the two sides began negotiating the specific terms under which Claude would be deployed on the Department of War’s GenAI.mil platform that September, talks collapsed.

The Defense Department’s position was that military contractors must be able to deploy technology “for any lawful purpose.” Anthropic’s position was that it required explicit contractual assurances that Claude would not be used for fully autonomous lethal weapons systems or the mass domestic surveillance of American citizens, consistent with Anthropic’s usage policy as publicly stated since the company’s founding. Neither side budged.

Hegseth accused Anthropic of attempting to “seize veto power over the operational decisions of the United States military” — a characterization Anthropic disputed, arguing it was simply holding to ethics commitments it had publicly stated since the company’s founding.

In February 2026, the standoff became public. By early March 2026, Anthropic had received both designation letters. The FASCSA designation, per a March 2026 memo, gave the Department up to 180 days to complete removal of Anthropic’s products from its systems. Under Secretary Emil Michael — a former Uber chief business officer now running the Defense Department’s AI integration effort — told staff on August 29, 2026, that removal from all Department systems would be complete by the end of September.

Pentagon spokesman Sean Parnell celebrated Friday’s ruling in a post on social media. Michael was more colorful: “The hammer of justice has smashed @AnthropicAI arguments… Warfighters will sleep better knowing that no private company will insert their opinions in the chain of command.”

What Happens to Defense Contractors Now

Friday’s ruling removes the main legal uncertainty for the large universe of companies holding Defense Department contracts. The § 4713 FASCSA designation — the one governing defense work — has been upheld on the merits. Under FAR supply chain clauses 52.204-28, -29, and -30, defense contractors are now required to:

  • Monitor actively for covered use of Anthropic’s products (including Claude) in systems supporting covered contracts
  • Conduct reasonable inquiry when potential covered use is identified
  • Report within three business days when covered use is discovered
  • Take mitigation steps, which may include removal of the product

These obligations flow down the supply chain through FAR’s standard subcontractor requirement provisions, meaning a prime contractor is responsible for ensuring that its sub-contractors — and their sub-contractors — are also complying. A small defense-tech company using Claude’s API to assist with technical documentation or code generation in a covered contract environment is now in a compliance-obligated situation, whether it knows it or not.

What remains in place, for now, is the California court’s August 27 permanent injunction covering the § 3252 designation. That injunction protects civilian agencies and contractors without direct ties to defense-mission work. The DC Circuit noted it will delay the effect of Friday’s ruling to give Anthropic time to seek further review, leaving the practical status quo temporarily unchanged while the company weighs its options.

Anthropic’s response was measured. “We respectfully disagree with the court’s decision,” an Anthropic spokesperson said. “Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review.”

A Circuit Split and a Road to the Supreme Court

Friday’s outcome creates a clean inter-circuit conflict: a California federal court has issued a permanent injunction finding that the § 3252 designation was unlawful because bad faith was required and not shown; a DC Circuit panel has upheld the § 4713 FASCSA designation because bad faith is not required under that statute.

The two statutes are different, which complicates the circuit-split analysis. A classic circuit split — the kind that almost automatically generates Supreme Court review — involves two courts reaching opposite conclusions on the same legal question. Here, the legal questions are technically different: § 3252 and § 4713 define supply chain risk differently and the courts applied different standards precisely because the statutes are different.

The more tractable Supreme Court question, however, may be the First Amendment one. Judge Henderson’s dissent implicitly invites SCOTUS to consider whether the government can exclude an AI company from defense contracting based on that company’s published ethics positions — particularly when senior officials like Hegseth left an extensive paper trail of statements expressing contempt for those positions. If the California injunction survives the Ninth Circuit appeal and the DC Circuit ruling stands, the diverging outcomes on the First Amendment analysis in particular could provide a vehicle for Supreme Court review.

Anthropic’s options are substantial. It can petition the three-judge panel for rehearing, seek en banc review before the full eleven-judge DC Circuit, or petition the Supreme Court directly. Given that no Supreme Court has ever weighed in on whether FASCSA can be used to blacklist a domestic AI company for publicly-disclosed safety guardrails, and given that Friday’s ruling extends the statute well beyond its documented legislative purpose, certiorari is at minimum a serious possibility.

IPO Shadow: What the Ruling Means for Anthropic’s Market Ambitions

Friday’s ruling arrives at an awkward moment for Anthropic’s market ambitions. The company has been laying the groundwork for what analysts will widely expect to be one of the largest IPOs in history, targeting a valuation in the range of $2 trillion, with a potential offering window projected for late 2026. Anthropic’s most recent private funding round — a Series G — valued the company at approximately $380 billion.

The defense contractor channel represents a meaningful slice of enterprise AI revenue. The FASCSA designation means that no contractor, supplier, or partner conducting military-adjacent work can use Anthropic’s paid services — including all Claude API tiers — without triggering FAR compliance obligations. Given that the defense industrial base includes most major U.S. technology companies in some capacity, the addressable market restriction is broader than it might appear from the outside.

Prospective public market investors reviewing Anthropic’s eventual S-1 filing will need to assess how material the defense exclusion is, how durable the California injunction protecting civilian use will prove to be, and what the legal cost of a sustained Supreme Court campaign will add to operating expenses. The pending Ninth Circuit appeal of the California permanent injunction — filed by the Defense Department after Judge Lin’s August ruling — adds a second layer of uncertainty: if the Ninth Circuit reverses Lin, both designations would stand, and Anthropic would face total exclusion from federal AI procurement.


Frequently Asked Questions

What does FASCSA’s “any person” standard actually mean for AI companies that aren’t Anthropic?

It means any AI developer whose trained models include restrictions that conflict with a Defense Secretary’s operational requirements is now legally exposed to the same mechanism the government used against Anthropic. FASCSA — as the DC Circuit majority interpreted it Friday — does not require the government to show that an AI company has foreign ties, acted maliciously, or even acted in bad faith. It requires only that the company’s product, as designed and trained, is “willing and able” to prevent the government from using it for purposes the Department deems necessary. OpenAI, Google, Meta, and every other AI lab that encodes limits into its models faces a legally cognizable (if currently theoretical) path to a FASCSA designation if a future Defense Secretary decides those limits conflict with military operational needs.

What is Judge Henderson’s dissent actually arguing?

Henderson’s dissent makes two related claims. The narrower claim is about statutory interpretation: the word “manipulate” in FASCSA’s supply chain risk definition — read in context alongside “sabotage,” “maliciously introduce unwanted function,” and “extract data” — requires some intentionally hostile or clandestine purpose, and openly-disclosed training decisions by a U.S. company do not qualify. The broader claim is structural: the majority’s reading hands the Defense Secretary a procurement-law mechanism that operates without bad-faith showing, without foreign-link requirement, and without Congressional notice — allowing any future Secretary to threaten a FASCSA designation as leverage to strip ethics restrictions from any AI model, with no APA review and no statutory check.

Why does it matter that Claude’s restrictions are trained into the model rather than applied as a filter?

Claude’s behavioral limits are embedded in the model’s neural network weights through Constitutional AI and RLHF training — they are architectural, not a downstream content policy. This means Anthropic cannot simply flip a switch to produce a version of Claude without those limits; it would need to train a fundamentally different model. The majority’s ruling treated those training-time decisions as “manipulation” of the product’s “function, use and operation” under FASCSA — extending the statute to cover design choices made openly by the developer, not interference introduced covertly by a malicious actor. That extension matters beyond Anthropic: it means any AI model’s trained values are a potential target of a FASCSA designation if a government customer wants different ones.

What should Anthropic investors be watching for before a potential IPO?

Three legal developments are the most significant near-term signals. First, Anthropic’s decision on whether to seek en banc DC Circuit review or proceed directly to a SCOTUS petition — the choice shapes the timeline and the venue where the “any person” question gets resolved. Second, the Ninth Circuit’s ruling on the Defense Department’s appeal of the California permanent injunction — if the Ninth Circuit reverses Judge Lin, both FASCSA designations would stand, dramatically expanding the compliance burden on civilian agencies. Third, any Congressional response to the ruling — the absence of legislation limiting FASCSA’s domestic scope is currently the governance gap Henderson identified; if Congress acts to restore the statute’s original foreign-adversary focus, the legal landscape shifts entirely.

Source link