A federal appeals court in Washington has upheld the Pentagon's decision to exclude Anthropic from military contracts, ruling 2-1 that the designation of the AI developer as a national security supply chain risk was lawful. The dispute centers on Anthropic's refusal to permit use of its models for autonomous weapons and mass surveillance. CNBC reported the decision, which keeps the procurement barrier in place. For business buyers, the case shows how a vendor's usage policy can directly determine eligibility for defense work.
Why the Pentagon imposed the risk label
The majority backed the position advanced by Defense Secretary Pete Hegseth, who argued that Anthropic's safety restrictions could jeopardize military operations. The 2-1 decision leaves the supply chain risk label in place for Pentagon procurement. Anthropic rejected the ruling and said it is weighing its next steps. According to the company, the designation has already cost it billions and is complicating its planned IPO. The outcome therefore affects not only current contracts but the startup's access to capital and its standing with enterprise customers watching the dispute.
At the core is a conflict over permitted use. Anthropic declined to authorize its technology for autonomous weapons and mass surveillance, maintaining guardrails tied to its AI safety stance. The Pentagon treats such restrictions as incompatible with operational requirements, where systems must function without vendor-imposed limits on missions. The supply chain risk label then operates as a procurement barrier, barring the company from military contracts. In effect, the government is treating control over how models can be used as a supply criterion, not only model capability or price.
The ruling does not settle the matter nationally. In late August, a federal judge in San Francisco blocked a parallel classification issued under a different law, describing it as unlawful retaliation against Anthropic's safety position. At the same time, US intelligence agencies remain heavy users of Anthropic's models, a fact that sits uneasily with a supply chain risk finding. Parts of the tech industry and former military officials have backed Anthropic in the fight. The dispute also carries a political charge, with the Trump administration described as viewing the company as "left-leaning" and "woke," a characterization President Trump has stated explicitly.
What this means for AI vendors and buyers
For companies that build on third-party models, the immediate lesson concerns procurement continuity. A model available for commercial or intelligence use can still be unavailable for defense contracts if usage terms clash with the customer's mission rules. Small contractors that resell or integrate Anthropic models into bids for military work face direct exclusion, while larger enterprises face a subtler problem of maintaining two model stacks for different customers. Vendor selection now requires checking not only performance and cost but whether safety policies permit the specific deployment a client intends.
The decision leaves several conditions for buyers to verify before committing to a roadmap. It is unclear how long the Pentagon label will remain, whether Anthropic will appeal further, and whether the conflicting San Francisco decision will narrow the government's approach under other statutes. The ruling by itself does not establish that Anthropic models are technically insecure, only that usage restrictions were deemed an operational risk. Buyers should ask vendors which use cases are prohibited in writing, how restrictions are enforced in the product, and what happens to existing deployments if a procurement status changes.
The marker to follow is Anthropic's next legal move and any change in Pentagon procurement status. A further appeal, a revised usage agreement, or a decision that reconciles intelligence use with the military ban will show whether safety guardrails and defense eligibility can coexist. If the split persists, vendors will need to plan for a divided public-sector market.
