TheTriFusion

← Back to Blog
September 26, 2026•17 min read•Trends & News

Anthropic Pentagon Ban: Claude AI Ruling Explained

A US appeals court upheld the Pentagon’s exclusion of Anthropic after Claude safeguards on autonomous weapons and mass surveillance stayed in place. What the order does and does not do.

T

TheTriFusion Team

Published on September 26, 2026

The sentence racing through tech timelines on the morning of 26 September is shorter than the case. It says the Pentagon banned Claude. The document that actually issued is narrower, and it is a procurement opinion, not a switch that turns Anthropic’s consumer chatbot off. On 25 September 2026 the US Court of Appeals for the District of Columbia Circuit denied Anthropic’s petitions and left in place the Department’s decision to exclude Claude from its supply chain. The opinion, written by Judge Katsas, is a 2–1 ruling. Judge Henderson dissented. The case number on the slip opinion is 26-1049, consolidated with 26-1162, and the caption names the United States Department of War and Secretary Pete Hegseth. News desks still say “Pentagon”. Both labels are describing the same exclusion fight.

Verification note: This page was written on 26 September 2026 from the D.C. Circuit opinion decided 25 September 2026, plus same-week reporting by Military Times, Ars Technica and The Washington Post. Quotes below that are attributed to Dario Amodei are the court’s summary of his 26 February statement, not a fresh interview. A separate San Francisco case is described only as those outlets reported it. This site has not read that district-court order line by line, so it is not treated as if it were merged into the D.C. Circuit judgment.

Companies that need a plain-language page when a model vendor is in a government dispute — with the holding separated from the headline — are the kind of publishing work we do through AI development and web development. TheTriFusion does not sell Claude access and does not advise on defence contracts.

What the appeals court actually held

Anthropic asked the D.C. Circuit to review the Department’s use of the Federal Acquisition Supply Chain Security Act of 2018. That statute, at 41 U.S.C. § 4713, lets an agency take covered procurement actions when a written determination says the action is necessary to protect national security by reducing supply-chain risk, and that less intrusive measures are not reasonably available. Covered actions include barring contracts with a supplier and barring subcontracts that use that supplier.

The court rejected Anthropic’s arguments that the exclusion was arbitrary, outside the statute, or unconstitutional. Judge Katsas wrote that the Department had support for treating continued integration of Claude into Department systems, by the Department or its contractors, as a covered national-security risk. The opinion says Anthropic encodes restrictions into Claude that stop the model from performing tasks Anthropic wishes to prevent, that those restrictions have stopped Claude from performing tasks requested by government users, and that a dispute over whether contractual prohibitions barred use in an ongoing overseas military operation left the Department uncertain whether Claude would perform as needed.

On the constitution, the court said the due-process claim failed because the Department notified Anthropic of the exclusion and its rationale and gave a chance to contest it. The First Amendment claim failed, in the court’s words, because the exclusion rested on refusal to assent to a contract term the Department deemed essential, not on Anthropic’s support for greater governmental regulation of AI. The panel denied the petitions for review. An earlier emergency stay had already been denied in April 2026.

The dissent, stated without a winner’s caption

A 2–1 opinion is not a unanimous one. Judge Henderson filed a dissent. This page does not pretend the dissent is the holding, and it does not pretend a majority erases the disagreement. Anyone quoting “the court said” should say which opinion. The majority is the law of this petition. The dissent is the record of what one judge would have decided instead.

The two safeguards the contract fight was about

The opinion’s own history is the cleanest account of the dispute. Over the previous two years the Department expanded its use of commercial AI. Anthropic had already relaxed some limits. It built a “Claude Gov” model, released in March 2025, after the ordinary model refused tasks the court describes as appropriate in a national-security context, such as summarising threat assessments. A government-specific addendum allowed some uses Anthropic would deny to private customers. The court says Anthropic came to permit use of Claude to design more effective weapon systems, to analyse foreign intelligence, and to conduct offensive cyber operations.

What Anthropic did not drop were contractual prohibitions on two uses: lethal autonomous warfare, and mass surveillance of Americans. In the fall of 2025 the Department asked for contractual permission to deploy Claude for “all lawful uses”. Anthropic agreed to relax other limits and kept those two exceptions. Negotiations stalled.

On 9 January 2026 Secretary Hegseth issued an AI strategy that, as the court recounts it, directed the Department to use models free from usage-policy constraints that might limit lawful military applications, and to put “any lawful use” language into AI contracts. On 24 February Amodei met Hegseth. The Secretary wanted the “all lawful uses” term by 27 February. On 26 February Anthropic refused. The court summarises Amodei’s statement this way: mass domestic surveillance, although legal, was incompatible with democratic values and presented serious risks to fundamental liberties; fully autonomous weapons that take humans out of the loop may prove critical for national defence in the future, but the technology was not yet reliable enough to power such weapons now. Amodei also said it was the Department’s prerogative to select contractors aligned with its vision, and he pledged a smooth transition if the Department offboarded Anthropic.

The next day, the court says, the President and the Secretary denounced that decision on social media and removal from the supply chain began. On 3 March 2026 the Secretary made a formal determination under the Supply Chain Security Act. A Department-wide memo on 6 March ordered Anthropic products off Department systems as soon as practical and within 180 days, and told contractors not to use those products in Department work. Anthropic filed for review on 9 March. Reconsideration was denied on 3 June. The September opinion is the merits decision on that petition.

This is not a consumer ban, and it is not the only case

Nothing in the D.C. Circuit opinion tells a business in Jaipur, a student in Pune, or a developer on a public Claude plan to stop using the product. The exclusion is about Department systems and contractors performing Department work. Headlines that say “Claude is illegal” or “Anthropic is shut down” are not what the slip opinion says.

There is a second case, and collapsing it into this one is how bad summaries spread. Military Times reported that a federal judge in San Francisco, Judge Rita Lin, had struck down a parallel designation under a different law, finding unlawful retaliation for Anthropic’s views on AI safety, and had blocked a government-wide ban plus an order barring military contractors from any business with the startup. The Washington Post’s 25 September story noted that the appeals loss came after Anthropic had prevailed in a connected San Francisco case. Those are news reports of a different order. Until you read that order, do not write that Friday’s appeals ruling “overturned” it or that the San Francisco order “cancels” the supply-chain exclusion. They are parallel tracks. A company counsel who needs to know which track binds a particular contract should read both dockets, not a screenshot.

What “supply-chain risk” meant here

The statute’s definition of supply-chain risk, quoted in the opinion, is about sabotage, malicious unwanted function, data extraction, or other manipulation of a technology product. Anthropic argued, in the reporting, that it had no malicious intent. Ars Technica’s account of the ruling says the court held the government could blacklist the company for withholding features even without malicious intent. The majority’s practical point, as Ars quoted it, is a pair of risks: overly constrained models shutting down in a military operation, and unconstrained models hallucinating targets. The court said the Secretary had to balance those risks and had not crossed the statute or the Constitution in doing so. That is a holding about executive procurement authority. It is not a finding that Anthropic planted malware.

Where OpenAI, Google, Microsoft and xAI sit in the same story

The exclusion did not freeze military AI procurement. On 1 May 2026 the Department of War announced agreements with SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft, Amazon Web Services and Oracle to deploy AI on classified networks — Impact Level 6 and Impact Level 7 — for what the release called lawful operational use. Anthropic is not on that list. The Verge and Breaking Defense both noted the absence and tied it to the supply-chain designation.

xAI needs a separate sentence. Axios reported on 23 February 2026 that Elon Musk’s xAI had signed an agreement for Grok to be used in classified systems, confirmed to Axios by a defence official, at a moment when Claude was described as the model already inside the most sensitive systems. xAI’s name does not appear in the eight-company list in the 1 May release. “xAI signed” and “xAI is on the May classified-network list” are different claims. This page treats the February Axios report as a report, and the May release as the list the Department published that day.

Google’s deal, as Reuters described a report in The Information on 28 April 2026, included safety filters and excluded domestic mass surveillance and autonomous weapons without human oversight, while still being framed as use for any lawful government purpose. If that reporting is right, “signed a military agreement” does not mean every lab accepted an identical red-line deletion. Compare the contract text, not the headline verb.

Why the story is travelling in India

Indian search interest in a US defence ruling is not mysterious. Claude, ChatGPT and Gemini are already in Indian company workflows, and a “ban” headline gets forwarded into founder groups by lunch. The useful local reading is commercial, not strategic. A vendor’s government contract can change without your API key changing. It can also change a vendor’s roadmap, hiring, and willingness to sign enterprise terms. None of that is a reason to migrate a production assistant over a weekend because a reel said the model was banned.

Teams comparing assistants for Indian businesses already have two explainers on this site that stay on the product question: ChatGPT for Indian businesses and Gemini and ChatGPT side by side. A third, multimodal AI and Astra-style apps, is about product shape, not procurement law. None of those pages is a substitute for the D.C. Circuit opinion if your question is whether a defence subcontract may still call Claude.

The canonical page for this explainer is https://thetrifusion.in/blog/anthropic-pentagon-claude-ai-ban-explained. For a policy or product page that names the court, the date and the limit of the holding, contact TheTriFusion or book an appointment.

How to read the next headline

  • Say “D.C. Circuit, 25 September 2026, supply-chain exclusion upheld, 2–1” before you say “ban”.
  • Name the two contractual lines: fully autonomous lethal weapons, and mass domestic surveillance.
  • Do not tell consumer users the public chatbot was switched off. The opinion does not say that.
  • Keep the San Francisco order as a separate case until you have read it.
  • If you list other labs, use the 1 May Department release for the eight names, and label the xAI report as Axios.
  • Do not add a quote from Amodei that is not in the opinion or a primary statement you have opened.

Anthropic can still seek further review. This page does not predict whether it will, and it does not guess a Supreme Court vote. If a later order stays or narrows the exclusion, the sentence at the top of this page has to change with it. The March determination date does not change.

FAQ

Did a US court ban Claude for everyone?

No. On 25 September 2026 the D.C. Circuit upheld the Department’s exclusion of Anthropic from its supply chain under the Federal Acquisition Supply Chain Security Act. That is a procurement ruling about Department systems and Department work, not a consumer shutdown of Claude.

Why was Anthropic excluded?

The Department acted after Anthropic refused to drop contractual prohibitions on lethal autonomous warfare and mass surveillance of Americans, and would not accept an “all lawful uses” term. The formal supply-chain-risk determination is dated 3 March 2026.

Was the ruling unanimous?

No. Judge Katsas wrote the majority. Judge Henderson dissented. It is a 2–1 decision.

Did OpenAI, Google and Microsoft sign military AI agreements?

Yes, they are named in the Department of War’s 1 May 2026 release on classified-network agreements, along with SpaceX, NVIDIA, Reflection, Amazon Web Services and Oracle. Axios separately reported an xAI classified-systems agreement in February 2026. xAI is not in that May list.

What about the San Francisco case?

Military Times and The Washington Post reported a separate district-court order that went Anthropic’s way on a parallel designation. This appeals ruling does not, by itself, tell you that order is gone. Read that docket before you merge the two.

Does this page tell companies to stop using Claude?

No. It explains a US military procurement case. Ordinary commercial use is outside the holding described here.

Next step

Want this built for your business?

Jaipur team · Hindi + English · GST invoicing. Ecommerce live in 48h packages from ₹25,000, or a scoped custom website / app / AI build.

Share this article