Pentagon Wins Authority to Blacklist AI Vendors Over Safety Features
TL;DR: A DC Circuit appeals court ruled the Trump administration can blacklist Anthropic for refusing to enable certain Claude features for military use, even absent malicious intent. This creates precedent for governments to override vendor safety policies in procurement decisions.
The Ruling: Jurisdiction Trumps Intent
The US Court of Appeals for the District of Columbia Circuit issued a 2-1 decision upholding the Department of Defense’s blacklisting of Anthropic technology. The court found the Trump administration had statutory authority under 41 U.S.C. § 4713 to designate Anthropic a procurement risk, regardless of whether the company acted with malicious intent.
The distinction matters operationally. A lower federal court had ruled the blacklisting illegal under 10 U.S.C. § 3252, which limits supply-chain risks to adversarial sabotage. The appeals court sidestepped this by reviewing under a different statute with broader language and exclusive DC Circuit jurisdiction—a jurisdictional move that effectively nullified the district court’s reasoning.
Background: Anthropic’s Refusal and the Escalation
Anthropic, the Claude AI developer, declined to remove safety guardrails from its models for Pentagon use. The company refused to disable features that prevent the AI from assisting with targeting lethal force or other military applications deemed ethically problematic by the company’s constitution.
In response, the Trump administration issued an executive order in March 2026 instructing federal agencies to cease Anthropic product usage and prohibited defense contractors from conducting business with the company. The blacklisting effectively locked Anthropic out of the US defense industrial base—a market segment worth billions annually.
Anthropic immediately challenged the order in federal court. Ars Technica reported the appeals court decision, which concluded that balancing military operational needs against AI safety risks fell within executive authority.
The Competing Risk Framework
The court explicitly acknowledged the stakes: “The US raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force.”
Rather than resolve this tension, the panel deferred to executive judgment. Defense Secretary Pete Hegseth retained full discretion to “determine how best to balance the competing risks,” without transgressing constitutional limits or statutory authority.
Judge Composition and Political Alignment
Both judges voting against Anthropic—Gregory Katsas and Neomi Rao—were appointed by Trump and held senior roles in his first administration. Katsas served as deputy counsel to the president; Rao held an OMB position. The dissenting judge was not identified in available reporting.
Operational and Investment Implications
This ruling establishes that vendor safety policies do not shield companies from government procurement blacklisting. Defense contractors and their AI suppliers now face pressure to adopt permissive configurations for military deployment, regardless of internal ethical frameworks.
For investors, the decision increases execution risk for AI companies pursuing defense contracts. Regulatory or policy disagreements can trigger sudden market access loss without requiring proof of malicious conduct. Anthropic’s valuation and growth trajectory depend partly on maintaining enterprise and government relationships.
The ruling also signals that AI safety constraints—a competitive differentiator for Anthropic—may be treated as operational liabilities by procurement authority. Competitors willing to remove guardrails gain market advantage in defense spending.
Parallel Court Decisions and Future Appeals
Notably, the US District Court for the Northern District of California reached the opposite conclusion last month, ruling the blacklisting unlawful. That court found Anthropic did not meet the statutory definition of a supply-chain risk because the company engaged in no sabotage or malicious action.
The DC Circuit’s decision does not reverse the district court on statutory interpretation—it simply applies a different statute with exclusive appellate jurisdiction. This jurisdictional split leaves the law fragmented: one statute prohibits the action, another permits it, depending on which court reviews which provision.
Anthropic stated it “respectfully disagreed” with the ruling and is considering further appeals, including en banc review or Supreme Court petition. Commerce Secretary Howard Lutnick recently claimed the administration and Anthropic have “patched up their relationship,” suggesting possible settlement negotiation below the Supreme Court threshold.
Broader Implications for AI Governance
The decision sets precedent for government override of private AI safety policies in procurement contexts. Other vendors may face similar pressure if their safety configurations conflict with military operational preferences.
The tension remains unresolved: should government procurement authority encompass forcing vendors to disable safety features, or should vendor autonomy over model behavior be protected as a property right? The court declined to answer, leaving the question to political branches.