What the DC Circuit Actually Ruled
On September 25, 2026, a divided panel of the United States Court of Appeals for the District of Columbia Circuit issued a 2-1 ruling that declined to overturn the Trump administration's blacklisting of Anthropic. The majority found that federal officials held the authority under the Supply Chain Security Act to place the AI company on a government exclusion list — not because Anthropic acted with malicious intent, but because it declined to enable certain capabilities in its Claude AI system that the Defense Department sought for military applications.
That distinction matters enormously. Blacklisting under national security statutes has historically required some showing of bad faith, foreign entanglement, or affirmative threat. The DC Circuit's majority opinion appears to shift that bar, suggesting that a company's product configuration choices — including decisions driven by internal safety policy rather than adversarial intent — can be sufficient grounds for exclusion from federal contracting and procurement. The dissenting judge's position is not publicly detailed in available reporting, but the 2-1 split signals genuine legal disagreement on the panel itself.
This ruling did not arrive without warning. The same circuit court denied Anthropic's emergency motion for a stay in April 2026, signaling early on that the judges were disinclined to halt the blacklisting while litigation proceeded. That earlier procedural defeat meant Anthropic operated under active exclusion for months before the full merits ruling landed — a significant commercial and reputational burden that the final decision now makes permanent, absent a successful appeal to the Supreme Court.
How Anthropic Ended Up on a Government Blacklist
The legal conflict traces back to the collision between Anthropic's safety-focused product philosophy and the federal government's operational requirements for AI in defense contexts. Anthropic, which was founded by former OpenAI researchers and has built its brand around responsible AI development, designed Claude with behavioral guardrails intended to prevent the model from performing certain tasks. The company declined to remove or disable those constraints at the government's request.
Read next Laika's Wildwood: Stop-Motion Fantasy at TIFF 2026The Trump administration, led on this front by Defense Secretary Pete Hegseth, invoked the Supply Chain Security Act — a statute designed primarily to exclude companies with ties to foreign adversaries from sensitive federal supply chains — as the legal vehicle for the blacklisting. The theory, which the DC Circuit majority accepted, is that the Act's language is broad enough to encompass situations where a domestic AI vendor's product configuration poses a risk to military operations, regardless of whether the vendor has any hostile intent.
That interpretive move is striking to national security law scholars. The Supply Chain Security Act was architected in response to concerns about hardware backdoors and foreign intelligence infiltration — the kind of risk associated with Huawei equipment in telecommunications infrastructure. Applying it to a domestic AI company's software feature decisions represents a significant doctrinal expansion. Legal analysts at institutions including Georgetown Law's Institute for Technology Law and Policy have noted that the statute's breadth was always a latent risk, and this ruling makes that risk concrete.
Two Sobering Scenarios the Court Was Forced to Weigh
The opinion's most arresting passage does not read like typical appellate prose. The court acknowledged directly that "the case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology." It then articulated two distinct catastrophic scenarios that framed the entire legal analysis.
The government's position rested on what the court called "the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail." This is not a hypothetical concern. Research into AI system reliability in high-stakes environments — including work published by RAND Corporation and the Brookings Institution on autonomous and AI-assisted military systems — consistently flags operational failure modes as a serious risk. If an AI system refuses a lawful command at a critical moment because its safety filters misclassify the request, the operational consequences can be catastrophic.
Anthropic's counter-argument, which the court also credited as legitimate, identified the opposite danger: "unconstrained AI models hallucinating inappropriate targets for lethal military force." Hallucination — the tendency of large language models to generate confident but factually incorrect outputs — is among the most studied failure modes in contemporary AI research. Studies published in journals including Nature Machine Intelligence and by research groups at Stanford's Human-Centered AI Institute have documented hallucination rates in frontier models that range from low single digits to over 20 percent depending on task type and evaluation methodology. In a lethal targeting context, even a fraction of a percent represents an unacceptable error rate with irreversible consequences.
The court did not resolve which risk is greater. It explicitly declined to do so, and that restraint is legally significant. Rather than declaring one scenario more dangerous, the majority concluded that weighing these competing catastrophic possibilities is a function of executive discretion, not judicial evaluation. The court treated the balance as inherently political and operational — beyond the judiciary's technical competence to adjudicate.
Who Makes the Final Call: Hegseth, Trump, and Executive Authority
Having declined to resolve the substantive risk balance, the DC Circuit handed that determination back to the executive branch in explicit terms. "Trump and Defense Secretary Pete Hegseth must determine how best to balance the competing risks," the ruling states. The Secretary, the majority concluded, "did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution."
That framing grants the Defense Department substantial discretion to set AI procurement standards based on capability criteria that extend well beyond the traditional national security concerns — foreign ownership, espionage risk, hardware integrity — that supply chain statutes were originally designed to address. Going forward, a defense secretary could theoretically exclude any AI vendor whose product does not meet specified behavioral benchmarks, whether those benchmarks favor maximum capability or maximum restraint, depending on current policy priorities.
The constitutional dimension is also significant. Anthropic evidently argued that the blacklisting violated its rights — presumably raising First Amendment questions about whether an AI system's output constitutes protected expression, or due process questions about the adequacy of notice and the opportunity to contest exclusion. The court rejected those arguments without, based on available reporting, finding them meritorious. Constitutional challenges to supply chain exclusions have historically faced steep odds, given courts' traditional deference to executive branch judgments on national security matters.
Legal Precedent and What It Means for the Broader AI Industry
The Anthropic blacklist ruling will be studied carefully by every major AI company with federal government contracts or aspirations. The practical implications reach well beyond Anthropic's specific situation.
First, the ruling signals that feature-level product decisions are now cognizable national security considerations under existing statute. An AI company that ships a model with safety filters, content policies, or capability restrictions that conflict with government operational requirements could face exclusion — not because of who built the model or where it was trained, but because of how it behaves. That changes the risk calculus for safety investments in fundamental ways.
Second, the 2-1 split and the presence of strong competing arguments suggests this area of law is genuinely unsettled. A petition to the full DC Circuit for en banc review, or a certiorari petition to the Supreme Court, would have reasonable legal basis. The dissenting judge's position — whatever it is — represents a live alternative legal interpretation. The industry will be watching whether Anthropic pursues further appeals and, if so, how higher courts handle the question of whether feature-withholding absent malicious intent constitutes a supply chain security risk.
Third, and most consequentially, the ruling creates a template. Other agencies beyond Defense could invoke similar authority. If the precedent holds, any federal department could theoretically seek to blacklist AI vendors based on product configuration mismatches with government requirements. The AI industry has operated under the assumption that safety-motivated product decisions are largely insulated from government coercion in a domestic context. That assumption is now far less secure.
The court closed its opinion with notable intellectual honesty, acknowledging the genuine difficulty of the questions presented. Profoundly difficult questions, decided by a divided court, under a statute never designed for this technology. That summary captures where the law now stands.
Source: AI - Ars Technica



