2026-10-11 16:38 UTC

The DC Circuit's 2-1 ruling says the Pentagon may blacklist Anthropic for withholding Claude features from military use even without bad motive; whether Anthropic's signaled en banc or Supreme Court review overturns it — and whether the government ever actually invokes the designation despite Lutnick's claimed détente — will determine if US blacklisting becomes upheld, live leverage over frontier-lab capability decisions.

state: acceleratingheat: highuncertainty: mediumconvergesscott: highai-governance frontier-labs government-coercionAnthropicPete HegsethGregory KatsasNeomi RaoHoward Lutnick
Surfaced 2026-10-05T22:38:35Z — The panel denied Anthropic's petitions for review, holding 'no such bad motive is required to support a designation under the much broader d — The second tracked trigger fired: BBC (via hn.story.49969929) reports the Pentagon is actually invoking the blacklist and stopping Anthropic tool use, converting the Sept 25 ruling from contested precedent into live operational leverage and effectively contradicting Lutnick's claimed détente; the open question narrows to en banc/SCOTUS review and the scope of execution. Heat goes high as a delivery call — the case's own prior decision committed to instant reheat on either trigger, and a fresh on-record BBC report of state action against a frontier lab should draw same-day follow-on — despite cold measured rates (0.33 pts/h, 57th percentile) that simply lag a hours-old story.

What is this?

On Sept 25, 2026 a 2-1 DC Circuit panel (Katsas, Rao; Henderson dissenting) upheld the Pentagon's March 2026 designation of Anthropic as a 'supply chain risk' under 41 U.S.C. § 4713, holding no bad motive is required because the statute is broader than 10 U.S.C. § 3252 — the malicious-adversary provision a district court had relied on to block the designation as punitive — creating a live statutory split over the same designation. The dispute began after Anthropic refused to let Claude be used for fully autonomous lethal weapons or mass surveillance of Americans, insisting on usage restrictions that on at least one occasion stopped Claude mid-task for government users, which Judge Katsas called 'ample support' for the risk finding since Anthropic was 'willing and able' to enforce restrictions through model training. The designation bars the military and defense contractors from using Claude, and per an Oct 5 BBC report (carried in the case evidence but not independently corroborated in the supplied snippets) the Pentagon is now actually invoking the blacklist and stopping Anthropic tool use, contradicting Commerce Secretary Lutnick's claimed détente; Anthropic's signaled en banc/SCOTUS petition remains unfiled, and the designation reportedly runs on a 180-day removal timeline.

Why it matters to Scott

The Oct 5 invocation converts Scott's Sovereign Software Assurance / vendor-lock-in thesis from argument into state practice: the Pentagon priced unilateral vendor control over model behavior as supply-chain risk and executed the exit — the framework's 'if the supplier vanished, could you continue' counterfactual run by the most security-conscious buyer on earth — while Anthropic's safety guardrails priced as procurement risk and cost it an entire market, a dated receipt and a sharp inversion for his anti-lock-in case rather than a mere illustration of it. The DoD pivot to alternatives is a working instance of exactly the mitigations his own stack already implements (LiteLLM multi-provider routing, Ollama/open-weight self-hosting), so this bears on what he builds and argues; it continues the radar's Pentagon–Anthropic lineage (ban-reaffirmed, blacklist-blocked, classified-exit) but the convergence stands on his own sovereignty and lock-in pages, which argue the principle without anticipating its enforcement.
ip:framework.sovereign-software-assuranceip:concept.vendor-lock-inip:concept.composable-bespokeip:concept.regulatory-compliancedev:technology.litellmdev:technology.ollamaradar:pentagon-anthropic-ban-reaffirmedradar:pentagon-anthropic-blacklist-blockedradar:dod-classified-anthropic-exitradar:white-house-gold-eagle-frontier-accessradar:concept.sovereign-airadar:concept.open-weightsradar:concept.self-hosting
queries asked of Scott's wikis
  • vendor lock-in unilateral control model provider
  • open weights self-hosting sovereignty inference
  • safety guardrails positioning as regulatory or procurement risk
  • model refusal behavior reliability critical production systems
  • government coercion frontier lab capability or deployment decisions
  • enterprise buyer concentration risk single model vendor

Measured heat

now 0 pts/hpeak 11 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 410h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-24 14:00⭐ origin echo-reconstructedThe panel denied Anthropic's petitions for review, holding 'no such bad motive is required to support a designation under the much broader d
US Court of Appeals for the DC Circuit (Katsas and Rao in majority, Henderson dissenting) on paper (echo) · attributed from hn.story.49855010
—
09-26 10:07first on hacker news · published · +44.1hCourt rules Trump can blacklist Anthropic for refusing to enable Claude features
sbulaev
—
09-26 10:07amplified on hacker newshn.story.49855010
sbulaev
peak 3 · 1 comments · 22% of case engagement
09-27 17:01amplified on hacker newshn.story.49868510
joozio
peak 2 · 0 comments · 11% of case engagement
10-05 20:07amplified on hacker news 👑hn.story.49969929
sbulaev
peak 12 · 0 comments · 66% of case engagement
09-26 10:20our radar first saw it · +44.4hdiscovery anchor: hn.story.49855010—
10-05 21:46reached heat=high · +271.8h · via queue+ledger——
pace: p50 vs 1032 stories at the 336h mark (now 410h old) — ahead of aipass-false-success-fixes (1.1x), behind android-editable-graph-agent (0.9x)

Evidence (4) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnCourt rules Trump can blacklist Anthropic for refusing to enable Claude features
Retrieved article excerpt

Open article · Retrieved 2026-09-26T10:23:02.070447+00:00

Blacklist approved

# Court rules Pentagon can blacklist Anthropic for refusing to enable Claude features

“Overly constrained AI models” could cause military operations to fail, judges say.

[Jon Brodkin](https://arstechnica.com/author/jon-brodkin/)
–

Sep 25, 2026 5:36 pm
| [50](https://arstechnica.com/tech-policy/2026/09/court-rules-trump-can-blacklist-anthropic-for-refusing-to-enable-claude-features/#comments "50 comments")

[A person's finger hovering over the Claude AI app's icon on a phone screen.
A person's finger hovering over the Claude AI app's icon on a phone screen.](https://cdn.arstechnica.net/wp-content/uploads/2026/03/claude-app.jpg)

Credit:
Getty Images | picture alliance

Credit:
Getty Images | picture alliance

Text
settings



Story text

Size

Small
Standard
Large
Width
\*

Standard
Wide
Links

Standard
Orange

\* Subscribers only  
  [Learn more](https://arstechnica.com/store/product/subscriptions/)

Minimize to nav

A US appeals court today approved the Department of Defense’s blacklisting of Anthropic technology. Judges decided the Trump administration had authority to blacklist Anthropic for withholding certain AI features from the military even if Anthropic had no malicious intent.

In a [2-1 ruling](https://storage.courtlistener.com/recap/gov.uscourts.cadc.42923/gov.uscourts.cadc.42923.1208891909.0_1.pdf) issued by the US Court of Appeals for the District of Columbia Circuit, a panel of judges said the “case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology.” The US “raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force,” the ruling said.

Trump and Defense Secretary Pete Hegseth “must determine how best to balance the competing risks,” the court said. “In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution. Accordingly, we deny the petitions for review.” The same court previously [denied](https://arstechnica.com/tech-policy/2026/04/trump-appointed-judges-refuse-to-block-trump-blacklisting-of-anthropic-ai-tech/) Anthropic’s emergency motion for a stay in April.

The two judges who ruled against Anthropic were both appointed by Trump and served in the first Trump administration. [Judge Gregory Katsas](https://www.cadc.uscourts.gov/content/gregory-g-katsas) was previously deputy counsel to the president, and [Judge Neomi Rao](https://www.cadc.uscourts.gov/content/neomi-rao) served in the Trump administration’s Office of Management and Budget.

## Two courts, two different decisions

Anthropic [sued the Trump administration](https://arstechnica.com/tech-policy/2026/03/anthropic-sues-us-over-blacklisting-white-house-calls-firm-radical-left-woke/) in March after it ordered federal agencies to stop using Anthropic’s products and banned defense contractors from doing any business with Anthropic. Anthropic may appeal today’s ruling, either by asking for an *en banc* review with all of the appeals court judges or by petitioning the Supreme Court.

“We respectfully disagree with the court’s decision,” an Anthropic spokesperson [told CNBC](https://www.cnbc.com/2026/09/25/pentagon-anthropic-ai-risk-appeals-court.html). “Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review.” Despite the ongoing legal battle, Commerce Secretary Howard Lutnick [recently said](https://www.bloomberg.com/news/articles/2026-09-02/lutnick-says-anthropic-has-patched-relations-with-us-government) the Trump administration and Anthropic have patched up their relationship and are “in tune.”

Two courts have been reviewing the US blacklisting of Anthropic. A judge in US District Court for the Northern District of California [ruled last month that the action](https://arstechnica.com/tech-policy/2026/08/trump-blacklisting-of-woke-anthropic-deemed-illegal-by-federal-judge/) was illegal because Anthropic does not meet the definition of a supply-chain risk, which is limited to “the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert… a covered system.”

Today’s ruling from the DC Circuit did not dispute the district court’s primary finding. But it said the district court was tasked with reviewing whether the decision was allowed under one law while the appeals court has exclusive jurisdiction to review the decision under a different, more permissive grant of authority.

The district court decision found a violation of 10 U.S.C. § 3252, in which supply chain risks are limited to malicious actions by adversaries. The appeals court reviewed the blacklisting under 41 U.S.C. § 4713, which doesn’t have the same restrictions. Notably, Congress gave the DC Circuit appeals court exclusive jurisdiction to review procurement actions taken under Section 4713 designations.

## Bad motive not required

Today’s ruling said:

> We have no quarrel with the Northern District’s conclusion that use of the critical noun *adversary*, combined with the sinister connotation fairly pervading the string of *sabotage*, *maliciously introduce*, and *otherwise subvert*, indicate that bad motive is required to support a designation under section 3252. Likewise, we have no quarrel with the Northern District’s conclusion that Anthropic has acted with no such bad motive in its dealings with the Department. But as explained at length above, no such bad motive is required to support a designation under the much broader definition set forth in section 4713.

The US designated Anthropic as a supply chain risk under both 3252 and 4713. The latter statute defines “supply chain risk” as “the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement” of covered technology products “so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of” those products or the information stored or transmitted on them, the court said.

The use of “any person” shows that the definition is not limited to adversaries or foreign entities, the court said. The court also pointed to the word “deny,” which it said applies to Anthropic preventing the US from using certain Claude features.

“In sum, we conclude that the Secretary’s concern about Anthropic disabling Claude from performing lawful actions requested by the Department qualifies as a ‘supply chain risk’ within the meaning of section 4713,” the court majority said. It also said “the Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary.”

## Judge’s dissent

The dissenting vote was cast by Judge Karen Henderson, a George H.W. Bush appointee. Henderson disputed the majority’s reading of the definition in 4713, saying that when “viewed in their statutory context, the verbs at issue are all directed at deliberately impeding or eavesdropping on the ‘function, use, or operation’ of a covered article that has entered the federal supply chain.”

Congress “enacted the statute in response to calls from the US intelligence community for legislation to meet the threat of ‘[h]ostile nation state and other bad actors’ infiltrating the federal government’s information and technology systems through its supply chains,” Henderson wrote. She said the definition should not be interpreted to cover “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.”

Anthropic alleged, and the district court judge in California agreed, that the Trump administration illegally retaliated against the company after it refused to drop restrictions on the use of its products for lethal autonomous warfare and mass surveillance of Americans.

The appeals court said that Anthropic “encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent. On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users. And recently, a dispute arose over whether the contractual prohibitions barred the use of Claude in an ongoing overseas military operation, leaving the Department uncertain whether Claude would perform as needed and intended.”

The case in the Northern District of California was presided over by Judge Rita Lin, a Biden appointee. Lin determined that the blacklisting violated the First Amendment. “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.

[Photo of Jon Brodkin](https://arstechnica.com/author/jon-brodkin/)

[Jon Brodkin](https://arstechnica.com/author/jon-brodkin/)
Senior IT Reporter

[Jon Brodkin](https://arstechnica.com/author/jon-brodkin/)
Senior IT Reporter

Jon is a Senior IT Reporter for Ars Technica. He covers the telecom industry, Federal Communications Commission rulemakings, broadband consumer affairs, court cases, and government regulation of the tech industry.

[50 Comments](https://arstechnica.com/tech-policy/2026/09/court-rules-trump-can-blacklist-anthropic-for-refusing-to-enable-claude-features/#comments "50 comments")
sbulaev31
🟧 echo.paper ⭐The panel denied Anthropic's petitions for review, holding 'no such bad motive is required to support a designation under the much broader dUS Court of Appeals for the DC Circuit (Katsas and Rao in majority, Henderson dissenting)——
🟧 hnAppeals Court Lets The Pentagon Designate Anthropic a Supply-Chain Riskjoozio20
🟧 hnPentagon stops using Anthropic AI tools after blacklisting company, BBC toldsbulaev120

Interpretation history

Decision trace