Anthropic vs. the Pentagon: The Contract Fight Behind Two Very Different Court Rulings
Updated: 2 days ago
The fight between Anthropic and the Pentagon started as a contract dispute over two limits Anthropic refused to remove from Claude. It eventually produced several government actions, two statutory tracks and federal courts reaching very different conclusions.
The Pentagon wanted Claude available for any lawful military use.
Anthropic was already allowing extensive national-security use, including intelligence analysis, offensive cyber operations and weapons-related work. But it would not remove two remaining safeguards: mass domestic surveillance of Americans and lethal autonomous warfare without meaningful human control.
When negotiations collapsed in February, the government did more than stop buying Claude. It moved to cut Anthropic off across the federal government and defense supply chain while separately invoking a procurement statute to remove Claude from Pentagon systems.
Those actions ended up in different courts.
The result is not really “Anthropic won, then Anthropic lost.”
The more accurate story is that one court found serious constitutional and statutory problems with the government's broader punitive actions, while another upheld a narrower procurement exclusion after reading the contract dispute and evidence of operational risk differently.

Context image: Pentagon AI leadership at the Department of Defense. U.S. Air Force photo by Senior Airman Madelyn Keech / Office of the Secretary of War Public Affairs. Public domain.
Claude was already inside the national-security system
This was never a dispute over whether Anthropic was willing to work with the military.
The D.C. Circuit record says the Department of War and intelligence community had been using Claude in classified systems since 2024.
Anthropic later developed Claude Gov, a version designed specifically for government work, and loosened many restrictions that applied to ordinary commercial users.
By 2025, Claude could be used for foreign-intelligence analysis, offensive cyber operations and weapons-system design.
In July 2025, Anthropic was one of several AI companies selected for work under a Department contract with a ceiling of $200 million per company. Negotiations then moved toward a broader direct relationship.
That history matters because the eventual disagreement was not military access versus no military access. It was about who would control the final boundaries.
The two limits Anthropic would not remove
The Department wanted Anthropic to agree that Claude could be used for all lawful military purposes.
Anthropic agreed to broad national-security use but kept two exceptions: mass domestic surveillance of Americans and lethal autonomous warfare.
Anthropic argued that current AI systems were not reliable enough to make autonomous lethal targeting decisions without meaningful human control and that AI could transform scattered personal data into surveillance capabilities at a scale that raised serious civil-liberties concerns.
The company did not argue that autonomous weapons could never have a military role. Its position was that current systems were not ready for that responsibility.
The Pentagon saw a different risk. A model embedded in military operations could not become unavailable, refuse a lawful task or be subject to intervention by a private company at the moment commanders needed it.
An overseas operation sharpened the Pentagon's concern
The D.C. Circuit record describes an incident involving a sensitive overseas military operation.
According to the government's account, an Anthropic executive questioned whether Claude should be used for a proposed task even though the requested use was permitted under the parties' existing terms.
Officials said the episode alarmed the Department and the prime contractor supplying Claude because it raised doubts about whether Anthropic might interfere with, or cause uncertainty around, Claude's availability during an operation.
Anthropic characterized the episode as a misunderstanding. The public record does not disclose enough operational detail to independently determine exactly what happened.
But the incident matters because it helps explain why the Pentagon framed the conflict as an operational-reliability problem rather than simply a disagreement over AI ethics.
February: negotiations collapse
On February 24, Secretary Pete Hegseth met with Anthropic CEO Dario Amodei.
The court record says Hegseth praised Claude's capabilities but demanded agreement to an all-lawful-uses term by February 27.
Anthropic publicly rejected that demand on February 26. Amodei said the company supported virtually all lawful national-security uses but would not remove its two remaining safeguards.
The dispute then moved quickly beyond contract negotiations. President Donald Trump and Hegseth publicly criticized Anthropic's position. Hegseth announced that the company would be treated as a national-security supply-chain risk.
But there was no single “Anthropic ban.” The government took several different actions. That distinction explains much of what happened in court.

The government went far beyond ending one contract
The California litigation challenged a broad package of measures.
According to the Northern District of California's August ruling, those included a presidential directive for federal agencies to stop using Anthropic products, a Hegseth directive aimed at commercial dealings between Anthropic and military contractors or partners, a supply-chain-risk designation under 10 U.S.C. § 3252 and agency actions implementing those directives.
The district court later said the government did not defend a statutory basis for the broad commercial restriction contained in Hegseth's directive.
Separately, the Department used another law, the Federal Acquisition Supply Chain Security Act, to remove Claude from its own supply chain. That action relied on 41 U.S.C. § 4713. Anthropic challenged it directly in the D.C. Circuit.
So by spring, the original contract dispute had produced two materially different legal tracks: California reviewed the broader directives and § 3252 designation; Washington reviewed the separate § 4713 procurement exclusion.
The government's behavior complicated its own narrative
The California court paid close attention to what happened around the same time the government was describing Anthropic as a serious national-security concern.
Days before the designation, Hegseth had discussed potentially using the Defense Production Act to compel access to Anthropic's technology. After the designation, senior Pentagon officials continued negotiating with the company.
The California record included a March 4 email from Under Secretary Michael saying the parties were “very close” to a contract. As the litigation continued, federal officials also remained interested in Anthropic's newer Mythos model for sensitive cybersecurity work.
The California court viewed those facts as important. They did not necessarily answer whether the Pentagon could reject Claude under a particular procurement statute, but they complicated the idea that every government action reflected one undifferentiated security concern.

March: California blocks the broader measures
On March 26, the Northern District of California issued preliminary relief restoring much of the status quo that existed before the challenged actions.
The court did not rule that the Pentagon had to keep buying Claude. The Department remained free to transition to another AI provider through lawful procedures.
The issue was whether the government could impose the much broader consequences it had chosen.
August: the California court finds constitutional and statutory violations
On August 27, Judge Rita Lin issued the major merits ruling in the California case.
The court sided with Anthropic on several First Amendment, due-process and Administrative Procedure Act claims while rejecting others.
Its First Amendment analysis focused heavily on evidence of motive. The government's own record discussed Anthropic's criticism of administration AI policy, deterioration in the relationship and what officials characterized as the company's hostile public posture.
The district court concluded that the broader measures were driven substantially by retaliation for Anthropic's protected criticism rather than by an established threat that Anthropic would sabotage deployed systems.
The continuing negotiations and government interest in Anthropic's newer technology also mattered. That ruling concerned the broader § 3252/directive track. It did not resolve the separate § 4713 procurement case.

Receipt visual based on N.D. Cal. Filing 250, Aug. 27, 2026. Recreated for readability from the court record; not a screenshot of the original page.

The procurement case was developing differently
The Department's separate § 4713 determination took effect in early March. Anthropic went directly to the D.C. Circuit.
On April 8, the appellate court declined to temporarily block the procurement action while the case proceeded, although it expedited review.
Anthropic later asked the Department to reconsider. In June, Hegseth denied reconsideration and clarified that the Department's concern did not depend on Anthropic having a literal remote “kill switch” capable of shutting down a model already delivered into a classified system.
The government instead focused on Claude's encoded restrictions, previous refusals and uncertainty over whether the model would reliably perform every lawful function the military required.
September: the D.C. Circuit sides with the Pentagon
On September 25, a divided D.C. Circuit panel upheld the § 4713 procurement exclusion.
The majority treated the case largely as a procurement and operational-reliability dispute.
Anthropic had intentionally designed Claude to refuse certain categories of tasks, refused to remove two remaining restrictions, and the Department pointed to previous refusals and the dispute surrounding the sensitive overseas operation.
From that record, the majority concluded that the Department could decide Anthropic's restrictions created a supply-chain risk under § 4713.

Receipt visual based on the D.C. Circuit opinion in Nos. 26-1049 & 26-1162, Sept. 25, 2026. Recreated for readability from the court record; not a screenshot of the original page.
The courts also disagreed about retaliation
This is where the story becomes more interesting than “different statutes produced different answers.”
The D.C. Circuit agreed that Anthropic's public advocacy about AI safety was protected speech and that excluding Claude from the Pentagon supply chain was a materially adverse government action.
But the majority rejected Anthropic's retaliation claim because it found the missing link was causation.
Anthropic had publicly advocated AI-safety restrictions for years while the Pentagon continued expanding its relationship with the company. In the majority's view, the decisive event was not Anthropic criticizing the administration. It was Anthropic refusing the contract term the Pentagon considered essential.
The California court had looked at the broader government campaign and reached a different conclusion about motive.
The courts therefore reviewed different government actions under different statutes, but they also examined different records and drew different conclusions about what caused the government's conduct.
A broad reading of “supply chain risk”
The D.C. Circuit decision could matter beyond Anthropic because of how the majority interpreted the procurement statute.
Anthropic argued that “supply chain risk” should be understood primarily in terms of hostile conduct such as sabotage, malicious manipulation or foreign interference.
The majority rejected that narrow interpretation. It concluded that deliberately designing Claude to refuse particular lawful functions could itself qualify if those restrictions might deny capabilities the Department considered necessary.
Judge Karen Henderson dissented. Her disagreement focused heavily on whether Congress really intended this supply-chain-security law to reach an American supplier openly imposing known contractual restrictions rather than malicious interference with government systems.
The six-month transition does not mean the Pentagon considered Claude harmless
Anthropic also pointed to the Department's transition period. If Claude posed an urgent security risk, why allow as long as six months to remove it?
The D.C. Circuit majority accepted the government's explanation: the Department had ordered removal as soon as practical, with six months functioning as an outside deadline because removing an AI system already integrated into active military infrastructure could itself create operational and technical risks.
Then came Mythos
The story became even less tidy while the litigation continued.
Anthropic announced Claude Mythos Preview through Project Glasswing, describing a frontier model with unusually powerful cybersecurity capabilities. The company also said it remained in discussions with U.S. government officials about the model.
The California court cited evidence of continuing federal interest in Anthropic technology when questioning the breadth of the government's security rationale.
That does not prove the Pentagon's concerns about Claude's restrictions were unfounded. It does show why saying simply that “Anthropic was declared a national-security risk” loses important context.

Why both rulings can be true at the same time

TVN explainer: the same contract dispute produced different government actions, statutes, records and court rulings.
What government action was challenged?
California reviewed the broader directives, § 3252 designation and agency implementation. The D.C. Circuit reviewed the separate § 4713 procurement exclusion.
What authority did the government invoke?
The cases involved different statutes with different language and different limits.
What evidence did each court emphasize?
The California court focused on public criticism, internal trust and hostility language, the breadth of the government's actions and continued dealings with Anthropic. The D.C. Circuit focused on the failed contract negotiation, encoded model restrictions, previous refusals and operational uncertainty.
What remedy was Anthropic seeking?
Stopping broad government penalties is not the same as forcing the Pentagon to continue using Claude. Even the California court left the Department free to choose another AI provider through lawful procedures.

The next court to watch may be the Ninth Circuit
The litigation is not necessarily finished. Anthropic can seek rehearing or rehearing en banc in the D.C. Circuit and potentially seek Supreme Court review.
There is also a separate Ninth Circuit appeal arising from the California litigation. That appeal had been placed on hold while the D.C. Circuit case proceeded.
Under the Ninth Circuit's April order, the government must seek appropriate relief within 21 days after the D.C. Circuit matter is resolved if the stay remains in place.
That makes the Ninth Circuit docket one of the next important records to watch, along with any D.C. Circuit rehearing filing, Pentagon implementation of the § 4713 exclusion, continued federal work involving Claude or Mythos, and changes to the Department's all-lawful-uses contracting requirement.
The bigger question is not really about one AI company
The Anthropic dispute exposes a problem that will become more important as commercial AI becomes part of military infrastructure.
A military customer wants certainty that a system will perform when lawfully ordered to do so. An AI developer may believe that some lawful uses remain too dangerous, unreliable or rights-invasive to permit.
Both positions create risks. A privately imposed restriction could interfere with military operations. Removing every private safeguard could place increasingly capable systems into uses their developers believe current technology cannot safely perform.
The legal question is where that disagreement stops being ordinary contracting and becomes a national-security supply-chain issue.
The constitutional question is different: how far can the government go when a contractor publicly opposes the government's preferred policy?
The takeaway
“Anthropic won” is incomplete. “Anthropic lost” is incomplete. And “the courts contradicted each other” is too simple.
One contract dispute produced several government responses. Those responses had different scopes, relied on different statutory authorities and generated different factual records.
The California court saw retaliation and statutory overreach in the government's broader punitive measures. The D.C. Circuit majority saw a lawful procurement decision arising from a failed contract negotiation and operational-reliability concerns.
That is the real reason the outcomes diverged.
The headline is two rulings. The story is everything that happened between the contract table and the courtroom.
The Receipts
The sources below are the records this article relies on. Open them directly and check what they establish for yourself.
Primary court opinion
D.C. Circuit: Anthropic PBC v. U.S. Department of War
September 25 opinion upholding the separate 41 U.S.C. § 4713 procurement exclusion and distinguishing the California litigation.
Open the record ↗ (opens in a new tab)Primary court ruling
N.D. Cal.: Anthropic PBC v. U.S. Department of War, Filing 250
August 27 merits ruling addressing the separate § 3252/directive track and related constitutional and APA claims.
Open the record ↗ (opens in a new tab)




Comments