Full Opinion

United States Court of Appeals FOR THE DISTRICT OF COLUMBIA CIRCUIT Argued May 19, 2026 Decided September 25, 2026 No. 26-1049 ANTHROPIC PBC, PETITIONER v. UNITED STATES DEPARTMENT OF WAR AND PETER B. HEGSETH, IN HIS OFFICIAL CAPACITY AS SECRETARY OF WAR, RESPONDENTS Consolidated with 26-1162 On Petitions for Review of an Agency Action of the Department of War Kelly P. Dunbar argued the cause for petitioner. With him on the briefs were Joshua A. Geltzer, Kevin M. Lamb, Anneke Dunbar-Gronke, and Megan O. Gardner. Tim Hwang was on the brief for amici curiae Foundation for American Innovation, et al. in support of petitioner. Barbara Smith Tyson was on the brief for amicus curiae Taxpayers Protection Alliance Foundation in support of petitioner. 2 Benjamin Klubes was on the brief for amici curiae Catholic Moral Theologians and Ethicists in support of petitioner. Harold Hongju Koh, Bruce Swartz, Alexis Loeb, Anthony Schoenberg, and John Ugai were on the brief for amici curiae Former Senior National Security Government Officials in support of petitioner. Ori Lev was on the brief for amici curiae Employees of OpenAI and Google in their personal capacities in support of petitioner. Samir Jain, Ashley Gorski, and Patrick Toomey were on the brief for amici curiae American Civil Liberties Union and Center for Democracy and Technology in support of petitioner. Brian Scarpelli was on the brief for amicus curiae the Association for Competitive Technology (ACT) in support of petitioner. Matthew Klapper, Elizabeth Deutsch, and Andrew Cherry were on the brief for amici curiae Former Secretary of Defense Leon Panetta and the Institute for Security and Technology in support of petitioner. Norman L. Eisen, Stephen A. Jonas, Gregg J. Costa, Sophia Brill, and Connor P. Mui were on the brief for amici curiae 149 Former Judges and Democracy Defenders Fund in support of petitioner. Sarah Grant, Sopen B. Shah, and Addison W. Bennett were on the brief for amici curiae the Foundation for Individual Rights and Expression, et al. in support of petitioner. 3 Rakesh Kilaru was on the brief for amicus curiae Faith Family Technology Network in support of petitioner. Daniel W. Wolff was on the brief for amici curiae Industry Trade Associations in support of petitioner. Elisabeth S. Theodore, Benjamin C. Mizer, Samuel F. Callahan, and Aaron X. Sobel were on the brief for amicus curiae Professor Alan Z. Rozenshtein in support of petitioner. Sarah E. Harrington, Alexander A. Berengaut, David M. Zionts, Megan A. Crowley, and Mishi Jain were on the brief for amici curiae Former Service Secretaries and Retired Senior Military Officers in support of petitioner. Josephine K. Petrick and Hayley Landman were on the brief for amici curiae Freedom Economy Business Association and Values-Led Investors in support of petitioner. George C. Harris entered an appearance. Sharon Swingle, Attorney, U.S. Department of Justice, argued the cause for respondents. With her on the briefs were Brett A. Shumate, Assistant Attorney General, Eric D. McArthur, Deputy Assistant Attorney General, and Sean R. Janda and Brian J. Springer, Attorneys. Gina D’Andrea, Andrew Zimmitti, and Joel Thayer were on the brief for amicus curiae Joel Thayer, Senior Fellow at the America First Policy Institute in support of respondents. 4 Before: HENDERSON, KATSAS, and RAO, Circuit Judges. Opinion for the Court filed by Circuit Judge KATSAS. Dissenting opinion filed by Circuit Judge HENDERSON. KATSAS, Circuit Judge: This case arises from a decision by the Department of War to exclude Claude, an artificial- intelligence product developed by petitioner Anthropic PBC, from its supply chain under the Federal Acquisition Supply Chain Security Act of 2018. The Department made this decision after Anthropic refused to relax contractual prohibitions on the use of Claude for lethal autonomous warfare or domestic surveillance. Anthropic challenges the exclusion as arbitrary, unauthorized by the governing statute, and unconstitutional. We reject these challenges. The Department had ample support for its conclusion that the continued integration of Claude into the Department’s information systems, by the Department or its contractors, presented a statutorily covered national-security risk. As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent. On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users. And recently, a dispute arose over whether the contractual prohibitions barred the use of Claude in an ongoing overseas military operation, leaving the Department uncertain whether Claude would perform as needed and intended. Anthropic’s constitutional claims are also without merit. Its due-process claim fails because the Department promptly notified the company of the exclusion and its supporting rationale, and then gave the company a fair opportunity to contest the exclusion. And Anthropic’s First Amendment 5 claim fails because the Department excluded Anthropic from its supply chain based on the company’s refusal to assent to a contract term that the Department deemed essential, not based on the company’s support for greater governmental regulation of AI technology. I The Federal Acquisition Supply Chain Security Act of 2018 authorizes “covered procurement action[s]” to prevent agencies from using information technologies that pose a risk to national security. 41 U.S.C. § 4713(a). Such procurement actions include barring agency contracts with a particular supplier and subcontracts that use the supplier to perform work for the agency. Id. § 4713(k)(4)(A), (B), (D). To take a covered procurement action, an agency head must first make a written determination that use of the authority to take the action “is necessary to protect national security by reducing supply chain risk” and that “less intrusive measures are not reasonably available” to reduce that risk. 41 U.S.C. § 4713(b)(3)(A), (B). The determination must also specify the class of covered procurement actions the agency may take under it. Id. § 4713(b)(3)(C). The statute defines “supply chain risk” to mean “the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement” of covered information-technology products “so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of” those products or the information stored or transmitted on them. Id. § 4713(k)(6). Before determining that it is necessary to take covered procurement actions, the agency head must provide the 6 supplier with notice and an opportunity to respond. 41 U.S.C. § 4713(b)(2). However, the agency head may “temporarily delay” providing notice if he “determines that an urgent national security interest requires the immediate exercise of the authority.” Id. § 4713(c), (c)(1)(A). In that instance, the agency head must provide notice and an opportunity to respond “as soon as practicable after addressing the urgent national security interest.” Id. § 4713(c)(2), (2)(A). Once the agency head makes a determination, the agency may take all procurement actions covered by the determination. Id. § 4713(a), (b)(3)(C). The statute channels judicial review of covered procurement actions into this Court. It provides that a party notified of a “covered procurement action under section 4713” may file a petition for review of that action in this Court within 60 days of the notification. 41 U.S.C. § 1327(b)(1). The statute also bars other judicial review of any “action taken under” section 4713. Id. § 1327(a). II A Anthropic develops Claude, a family of artificial- intelligence models. Claude utilizes large-language models, which are algorithms “trained on massive datasets to identify patterns and associations in language.” App. 6. Claude can “respond[] to a wide range of user inputs, or ‘prompts,’ in an intelligent, human-like manner.” Id. It “can even act autonomously, executing tasks without requiring ongoing user direction.” Id. at 7. In the context of warfare, this means that Claude could be deployed in a way that “independently identifies and classifies an object as a military target, determines engagement criteria are satisfied, and launches a 7 weapon strike.” Id. at 16. The power of this new technology is obvious—as is its potential for misuse. To reduce the risk of misuse, Anthropic employs three distinct kinds of restrictions. First, it “seek[s] to embed safety considerations directly into the model itself.” App. 8. For example, Anthropic has disabled Claude from performing specific tasks such as making biological, chemical, nuclear, or radiological weapons. Id. at 103. Beyond that, Anthropic trains Claude to conform to a constitution developed for it by Anthropic. According to Jared Kaplan, Anthropic’s co- founder and Chief Science Officer, this constitutional training makes Claude follow “a set of normative principles, like balancing helpfulness against harm avoidance, and respecting values such as individual privacy and political freedom.” Id. at 8. Dario Amodei, Anthropic’s Chief Executive Officer, explains that this training, focused on “high-level principles and values,” imbues Claude with an “identity, character, values, and personality” that lead to what Anthropic deems “a coherent, wholesome, and balanced psychology.” Id. at 93–94. Anthropic considers this kind of “model development” to be “at the core of [its] mission.” Id. at 2. Second, Anthropic builds into its products “technical measures that stack on top of the model itself.” App. 8. These measures include monitoring systems to detect harmful activity and targeted interventions to prevent it. Id. Anthropic began to develop this “second line of defense” around mid-2025, because “all models can be jailbroken.” Id. at 103. Third, Anthropic contractually prohibits uses of Claude that it deems inappropriate. As summarized by Kaplan, its Usage Policy prohibits “unacceptable” uses including “surveillance, compromising computer systems or networks, and designing weapons.” App. 9. The actual Usage Policy 8 imposed by Anthropic on Palantir Technologies, Inc., which analyzes data for the Department of War, is more extensive. Among other things, it prohibits Palantir from using Claude to compromise children’s safety, incite violence or hateful behavior, invade privacy, create emotionally harmful content, spread misinformation, interfere in elections, or monitor individuals’ physical locations. Id. at 394–400. Anthropic informs us that such usage restrictions reflect “the very purpose for which our company was founded,” and their removal would “contradict our deeply held values.” Id. at 10. B Over the past two years, the Department of Defense (which now calls itself the Department of War) has greatly expanded its use of AI. During this time, Anthropic partially— but not completely—relaxed its use restrictions to accommodate the Department. In 2024, the Department and the intelligence community began using standard, commercially available models of Claude in their classified systems, working through contractors with access to Claude. App. 279. Consistent with Anthropic’s model training, Claude “refuse[d]” to perform “tasks that were appropriate in a national security context—such as summarizing threat assessments, processing classified documents, or translating intercepted materials describing violence.” Id. at 280. In response to this problem, Anthropic developed a special “Claude Gov” model that would perform such tasks for the national-security agencies, which it released in March 2025. App. 280–81. Anthropic also developed a “government- specific addendum” to its Usage Policy, which contractually allowed certain uses that it would deny to private customers. Id. at 12. Anthropic describes this addendum as “designed to 9 strike a balance between enabling national security beneficial uses and mitigating potential harms.” Id. Over time, Anthropic came to permit the Department to use Claude to design more effective weapon systems, to analyze foreign intelligence, and to conduct offensive cyber operations. Id. at 12, 278. However, Anthropic retained contractual prohibitions on the use of Claude for “lethal autonomous warfare” and for “mass surveillance of Americans.” Id. at 12–13. In the fall of 2025, Anthropic and the Department began negotiations to establish a direct contractual relationship and to expand the Department’s use of Claude. As part of that negotiation, the Department asked Anthropic for contractual permission to deploy Claude for “all lawful uses.” App. 14. Anthropic agreed to substantially relax the prior use restrictions, but it continued to insist that Claude not be used for lethal autonomous warfare or mass surveillance of Americans, which it describes as “two critical exceptions.” Id. Negotiations over these restrictions extended for a few months and eventually stalled. C The contractual dispute between Anthropic and the Department came to a head in early 2026. On January 9, Secretary of War Pete Hegseth set forth a comprehensive “Artificial Intelligence Strategy for the Department.” App. 202. According to the Secretary, “AI- enabled warfare and AI-enabled capability development will re-define the character of military affairs over the next decade.” Id. The Secretary discerned a “race” between the United States and its “adversaries” to integrate AI technology into military capabilities. Id. The Secretary thus “direct[ed] the Department of War to accelerate America’s Military AI Dominance by becoming an ‘AI-first’ warfighting force across all 10 components, from front to back.” Id. As part of that directive, the Secretary stated that the Department must use AI models “free from usage policy constraints that may limit lawful military applications,” and he directed the Department to “incorporate standard ‘any lawful use’ language into” contracts procuring AI services. Id. at 206. Around the same time, an Anthropic executive “questioned the propriety” of a contractor’s use of Claude “for a sensitive military operation abroad.” App. 181. The Department believes that the governing usage policy “clearly permitted” the engagement at issue. Id. at 183. Nonetheless, the question “led to alarm by the DoW and the prime contractor who provides Anthropic software, and raised material doubts” about whether the software would perform as the Department was expecting. Id. at 228. The Department does not elaborate on the specific military operation at issue. However, Anthropic put into the record media reports stating that “Anthropic had raised concerns with Palantir about the role [Anthropic’s] technologies played” in the January 3 “military operation to capture Venezuela’s president, Nicolás Maduro.” Id. at 171. Finally, the Department learned of another instance when Anthropic’s model training caused Claude to refuse to respond to queries from a government agency. Specifically, Claude refused to respond to queries from the Centers for Disease Control and Prevention (CDC) regarding sensitive research on preventing the spread of infectious disease. App. 212–13. On February 24, Amodei met with Secretary Hegseth to discuss the standoff. The Secretary praised Claude’s capabilities but demanded that Anthropic accede to an “all lawful uses” contractual term by February 27. App. 26. On February 26, Anthropic refused, and Amodei released a statement explaining the company’s decision to maintain the 11 two contested use restrictions. He stated that “mass domestic surveillance,” although legal, was “incompatible with democratic values” and presented “serious, novel risks to our fundamental liberties.” App. 146. He further stated that “fully autonomous weapons (those that take humans out of the loop entirely and automate selecting and engaging targets) may prove critical for our national defense” in the future, but that AI technology was not yet “reliable enough” to currently power such weapons. Id. at 147. Amodei recognized that “[i]t is the Department’s prerogative to select contractors most aligned with their vision” for appropriate AI uses, and he pledged a “smooth transition to another provider” “[s]hould the Department choose to offboard Anthropic.” Id. One day later, President Trump and Secretary Hegseth denounced Anthropic’s decision on social media, and the Secretary began the process of removing Claude from the Department’s supply chain. App. 77, 153. D On March 3, 2026, Secretary Hegseth made a formal determination to take procurement actions against Anthropic under the Supply Chain Security Act. First, the Secretary determined that use of Claude in Department systems “presents a significant supply chain risk” and that removing Claude from them was “necessary to protect national security” by reducing that risk. App. 177. Next, he determined that no “less intrusive measures” for reducing the risk were “reasonably available.” Id. Finally, he determined that an “urgent national security interest” required immediate action. Id. The determination rested on a recommendation from senior agency officials, which in turn rested on a memorandum from Emil Michael, the Department’s Under Secretary for Research and Engineering. Among other things, Michael cited Anthropic’s refusal to allow 12 all lawful uses of Claude, its ability to “alter system guardrails and model weights” governing how Claude responds to user prompts, and its questioning the Department’s use of Claude in a sensitive military mission abroad. Id. at 181–83. Secretary Hegseth immediately notified Anthropic of his determination, in a letter dated March 3 and emailed to Anthropic on March 4. App. 72, 243. The notice stated that the determination was effective immediately, and it gave Anthropic an opportunity to seek reconsideration within 30 days. Id. at 73. The Department immediately began implementing the Secretary’s determination. On March 6, its Chief Information Officer issued a Department-wide memorandum ordering the removal of Anthropic products from the Department’s systems “as soon as practical,” and in any event within 180 days. App. 80. The memo further prohibited contractors from using Anthropic products in their work for the Department. Id. The Department quickly moved to expand its contractual relationship with OpenAI, another company that provides AI services. Id. at 220. In response, Amodei wrote to Anthropic employees to express his view that the Department, OpenAI, and Palantir had not established adequate safety protocols for the use of AI. Id. at 220–23. On March 9, Anthropic filed a petition for review of its exclusion from the Department’s supply chain. Anthropic also moved for a stay pending review. In litigating the stay motion, the parties filed various affidavits and other evidentiary materials with this Court. On March 19, the Department provided Anthropic with a supplemental notice, which included copies of the determination itself, the recommendation from agency officials, the memorandum by Under Secretary Michael, and a 13 statement of the exact scope of the covered procurement actions. App. 224. The supplemental notice restarted the 30- day deadline for Anthropic to submit any “information or arguments in opposition to this notice.” Id. On April 8, this Court denied a stay but expedited review on the merits. Anthropic PBC v. U.S. Dep’t of War, No. 26- 1049, 2026 WL 1042493 (D.C. Cir. Apr. 8, 2026) (per curiam). We ordered the parties to brief the question of our jurisdiction over the petition for review and to provide further information on how Anthropic could affect the functioning of its models before or after their delivery to the Department. On April 17, Anthropic asked the Department to “rescind” its exclusion from the supply chain. See Letter from Counsel for Resp’ts to Clerk of Ct. at 6–7, Anthropic PBC v. U.S. Dep’t of War, No. 26-1049 (D.C. Cir. filed May 12, 2026). There and in the appendix here, Anthropic tendered a supplemental declaration addressed to our factual question. App. 272–97. The Department has also tendered its own supplemental declaration, styled as one “in support of the administrative record.” Id. at 408 (cleaned up); see id. at 408–22. On June 3, the Secretary issued a decision denying reconsideration of his March 3 determination. Suppl. Br. for Resp’ts, Add. 1. The Secretary clarified that his determination did not rest on the premise that Anthropic could control any version of Claude after its delivery to contractors for deployment on the Department’s classified systems. See id. After oral argument in this Court, we ordered supplemental briefing on (1) whether Anthropic’s April 17 filing divested this Court of jurisdiction and (2) the impact of the Secretary’s June 3 order. Following that briefing, the matter is now ripe for decision. 14 III We agree with the parties that we have jurisdiction to review the covered procurement actions taken against Anthropic under the Supply Chain Security Act. To begin, we conclude that our jurisdiction was secure when Anthropic filed its petition for review on March 9. The Supply Chain Security Act gives this Court jurisdiction to review any “covered procurement action under section 4713,” so long as the aggrieved party files the petition within 60 days of receiving notice of the covered action. 41 U.S.C. § 1327(b)(1). Here, the Secretary invoked section 4713 to remove Claude from the Department’s supply chain. Anthropic received notice of the Secretary’s action on March 4, and it promptly sought review five days later. That sufficed to establish jurisdiction under section 1327(b)(1). We recognize that the statute distinguishes between the “covered procurement action[s]” authorized by section 4713(a), which are reviewable, and the antecedent written “determination” that use of the authority to take covered procurement actions is necessary, as separately required by section 4713(b). But the statute does not prohibit the government from making the written determination and taking the covered procurement actions at the same time. Here, the Department has done both: Its notice to Anthropic stressed that the determination had become “effective immediately.” App. 73. And within three days, the Department had begun implementing the determination with an agency-wide order to “remove” Claude “from all DoW systems and networks … as soon as practical.” Id. at 80. So, Anthropic was notified of “covered procurement action[s]” and timely sought review of them. 41 U.S.C. § 1327(b). 15 A distinct jurisdictional question arose after Anthropic asked the Department to rescind the covered procurement actions on April 17. Under statutory schemes limiting judicial review to final agency action, the filing of a motion for reconsideration renders incurably premature a previously filed petition for review. See, e.g., Nat’l Ass’n of Immigr. Judges v. FLRA, 77 F.4th 1132, 1136–38 (D.C. Cir. 2023) (per curiam). Anthropic contends that this incurably-premature doctrine does not apply to judicial review under the Supply Chain Security Act because the statute contains no finality requirement. For its part, the Department contends that the doctrine does apply but that it is waivable and was waived in this case. Subsequent developments make it unnecessary for us to resolve these questions. The Secretary denied Anthropic’s request for rescission or reconsideration on June 3; Anthropic filed a petition for review of the March 3 and June 3 decisions on June 17; and we consolidated the two cases on June 24. We have jurisdiction over at least one of them. On the one hand, if the incurably-premature doctrine does not apply to judicial review under the Supply Chain Security Act, then Anthropic’s request for rescission did not imperil our jurisdiction over its earlier-filed petition for review. On the other hand, if the incurably-premature doctrine does apply here and is not waivable, then the second petition for review cinched up our jurisdiction: Where the doctrine applies, the filing of a motion for reconsideration “tolls the period for judicial review of the original order, which can therefore be appealed to the courts directly after the petition for reconsideration is denied.” ICC v. B’hood of Locomotive Eng’rs, 482 U.S. 270, 279 (1987). One way or the other, our jurisdiction is secure. 16 IV Anthropic challenges each of the Secretary’s three key determinations under the Supply Chain Security Act, namely that (A) removing Claude from the Department’s supply chain was “necessary to protect national security by reducing supply chain risk,” 41 U.S.C. § 4713(b)(3)(A); (B) “less intrusive measures” for reducing that risk were “not reasonably available,” id. § 4713(b)(3)(B); and (C) an “urgent national security interest” required “the immediate exercise” of the removal authority, id. § 4713(c). These claims are governed by the standards of review set forth in the Supply Chain Security Act, which requires us to “hold unlawful” covered procurement actions under section 4713 that we find to be “arbitrary, capricious, an abuse of discretion, or otherwise not in accordance with law.” 41 U.S.C. § 1327(b)(2), (2)(A). These standards closely track those in the Administrative Procedure Act. See 5 U.S.C. § 706(2). On review for arbitrariness, we require only that agency action be “reasonable and reasonably explained.” FCC v. Prometheus Radio Project, 592 U.S. 414, 423 (2021). Judicial review under this standard is “deferential,” and this Court may not “substitute its own policy judgment for that of the agency.” Id. We will uphold even a “decision of less than ideal clarity,” so long as the agency’s basic rationale “may reasonably be discerned.” FCC v. Fox Television Stations, Inc., 556 U.S. 502, 513–14 (2009) (quoting Bowman Transp., Inc. v. Arkansas- Best Freight Sys., Inc., 419 U.S. 281, 286 (1974)). We review de novo agency determinations on purely legal questions of statutory construction. Loper Bright Enters. v. Raimondo, 603 U.S. 369, 412 (2024). In construing statutes implicating national security, we resolve ambiguities against intruding on the national-security determinations of the 17 Executive Branch. See, e.g., Dep’t of Navy v. Egan, 484 U.S. 518, 530 (1988); Hikvision USA, Inc. v. FCC, 97 F.4th 938, 948 (D.C. Cir. 2024); Fed. Express Corp. v. U.S. Dep’t of Com., 39 F.4th 756, 769 (D.C. Cir. 2022). Where the application of a statutory term turns primarily on factual determinations, we review the agency’s assessment deferentially. Seven County Infrastructure Coal. v. Eagle County, 605 U.S. 168, 181 (2025). And where a factual question turns on assessments of national security, we give the agency more deference, even if constitutional claims are at issue. See, e.g., Trump v. Hawaii, 585 U.S. 667, 704 (2018) (“our inquiry into matters of … national security is highly constrained”); Holder v. Humanitarian L. Project, 561 U.S. 1, 33 (2010) (HLP) (in national-security cases, “evaluation of the facts by the Executive, like Congress’s assessment, is entitled to deference”). A The Secretary reasonably concluded that removing Anthropic from the Department’s supply chain was necessary to protect national security by reducing supply chain risk to the Department’s information systems. Specifically, the Secretary credited a joint recommendation from two senior Department officials that Claude might be “subject to manipulation” by Anthropic “in such a manner as to inhibit the DoW’s use thereof.” App. 178. Likewise, he credited Under Secretary Michael’s conclusion that Anthropic might “manipulat[e]” the “design, integrity, and operation” of the Department’s Claude models, potentially causing “critical defense system[s] failing to engage” as intended by the Department. Id. at 182. 18 1 The record in this case amply supports the Secretary’s conclusion. To begin, it is undisputed that Anthropic can and does control how Claude responds—or fails to respond—to user prompts. Anthropic’s Chief Science Officer explained how the company “seek[s] to embed safety considerations directly into the model itself.” App. 8. Its CEO explained how such training gives the model an “identity, character, values, and personality” of its own, tethered to a “constitution” developed to impose “high-level principles and values” on Claude itself. Id. at 93–94. And the head of its public-sector business explained: “Model training is the primary mechanism through which Anthropic can influence the behavior of models used by the Department.” Id. at 276. Anthropic disclaims any ability to access or alter a model that has already been delivered to the Department, see id., despite the “technical measures” that it uses to police compliance with usage restrictions by private customers, id. at 8. Nonetheless, extant models reflect Claude’s “[c]onstitutional” training. Id. at 274–75. Moreover, Anthropic may encode additional restrictions each time it delivers any “new version of the model” to Department contractors. Id. at 276. Finally, it is undisputed that such model restrictions are vitally important to Anthropic, which describes them as lying “at the core of [its] mission.” Id. at 2. The record also indicates that Anthropic’s model training is effective in enforcing usage restrictions and that, as a result, Claude has refused to answer legitimate queries from government users. Anthropic itself explained how early, commercially available versions of Claude frustrated Department and intelligence-community users by refusing prompts to evaluate classified materials. App. 255. Likewise, as Under Secretary Michael explained, the Department learned in 2025 that Claude had refused to process CDC prompts to 19 support research to prevent the spread of infectious diseases. Id. at 212. Anthropic responds that these glitches reflected safety features appropriately built into models sold to private companies and were resolved after Anthropic engineers worked with the relevant government stakeholders. Id. at 255– 56, 261–62. Perhaps so, but the point here is not that these model or usage restrictions were arbitrary; instead, it is that Anthropic’s model training does effectively enforce contractual usage restrictions. Finally, the record reveals a recent, serious dispute about the scope of the contractual prohibitions on lethal autonomous warfare and mass domestic surveillance. Under Secretary Michael describes the incident in general but striking terms: [O]ne of Anthropic’s executives questioned the propriety of the potential use of their software for a sensitive military operation abroad despite that use being permitted under the existing Terms of Service. This led to alarm by the DoW and the prime contractor who provides Anthropic software, and raised material doubts as to whether they would cause their software to stop working or cause some other disastrous action that would put our warfighters[’] lives in danger. App. 181. Anthropic does not say much about this incident, except to suggest that it reflected a misunderstanding. Id. at 236–37. But regardless, Anthropic has made clear that it views the contractual prohibition on mass domestic surveillance as urgent to support “democratic values,” id. at 146, and the contractual prohibition on lethal autonomous warfare as urgent to avoid “put[ting] America’s warfighters and civilians at risk” of a catastrophic AI mistake, id. at 147. For its part, the Department has made clear that it views an “any lawful use” authorization to be critical to its “AI-first” strategic plan. Id. at 20 202, 206. With such diametrically opposed positions and with contractual limitations that are hardly self-defining, the prospect for disputes is apparent. Because Anthropic was willing and able to enforce contractual restrictions through model training, the Department reasonably worried that “critical defense system[s]” supported by Claude might “fail[] to engage” as the Department would expect. Id. at 182 (Michael memorandum). Of course, we do not know exactly what happened in the incident described by Michael as a near-disaster and by Amodei as a misunderstanding. But Anthropic’s suggestion that the incident may have arisen during a shock-and-awe, kinetic operation to capture a foreign head of state abroad simply underscores the fraught nature of its dispute with the Department—and the Department’s need for certainty that its AI systems will perform as expected. In sum, the Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary. 2 Anthropic offers two primary responses, one factual and one legal. Neither is persuasive. a On the facts, Anthropic stresses that it cannot control or even monitor the operation of any model once the model is delivered to a Department contractor for use on a classified system. App. 274–78. In sum, Anthropic says it has no “back door or remote ‘kill switch.’” Id. at 258. So, it reasons, the Department can test any new model delivered by Anthropic to 21 contractors—before integrating it into the Department’s information systems—to see if the new model performs up to the Department’s expectations. Id. at 282–92. Specifically, Anthropic says that the Department can “test the model” to see if it will “refuse tasks the Department deem[s] appropriate to its lawful mission, or … override the Department’s judgment that an activity is permissible.” Id. at 285. And if the Department is not satisfied with the new model, it can simply “decline to approve” the model. Id. at 286. This would leave the Department free to continue using an older, previously accepted model, which “does not degrade or change on its own.” Id. at 287–88. These responses do not assuage the Department’s concerns. To begin with, the Department has good reasons not to view advance testing as a panacea. As noted above, the contested use restrictions are hardly self-defining, and there are any number of possible scenarios involving, say, greater or lesser degrees of human involvement in targeting decisions during ongoing military operations. Moreover, as Under Secretary Michael explained, Claude employs technology that is “opaque” to its users, App. 182, partly because “Anthropic’s unique building processes are considered proprietary intellectual property” and partly because its models “have weights or parameters that number approximately 5 to 10 trillion per model,” id. at 410. All of this makes “rigorous analysis or auditing of its output mathematically impossible.” Id. Indeed, Anthropic itself acknowledges “some legitimacy to DoW’s concern about the opacity of these systems generally.” Id. at 261. Finally, Anthropic acknowledges that Claude might respond differently to similar requests depending on their exact wording. Id. at 289. So, while one Department official might secure an advance commitment from Claude to perform a contemplated military function, a second official, using slightly different wording, might later be met with a refusal. 22 In any event, even if testing could reliably establish in advance the range of situations where a new model might decline to perform some lawful but contractually prohibited function, the Department could hardly be satisfied with the option of simply refusing the upgrade. Anthropic “continually develop[s] and release[s] increasingly capable versions of Claude.” App. 6. In 2025, it released three new, increasingly powerful versions of Claude Gov. Id. at 256–57. Since then, it has released several more versions of Claude. See Anthropic, Models Overview, https://perma.cc/BR4B-SRYJ. The Secretary has noted the “unprecedented velocity in the evolution of the frontier AI models,” which “are becoming smarter and more robust every day.” App. 205. Amodei likewise acknowledges “a smooth, unyielding increase in AI’s cognitive capabilities” over the last few years, and he predicts even greater breakthroughs on the horizon, such as a “point where the current generation of AI autonomously builds the next.” Id. at 85–86. More ominously, he also foresees—as perhaps do our adversaries—that a “swarm of millions or billions of fully automated armed drones, locally controlled by powerful AI and strategically coordinated across the world by an even more powerful AI, could be an unbeatable army.” Id. at 106. Quite obviously, the Department cannot utilize AI systems that remain trapped in amber. Finally, Anthropic claims that Under Secretary Michael’s memorandum contained a discrete factual error in suggesting that Anthropic could modify the behavior of models already delivered to Department contractors. In the one sentence at issue, Michael expressed concern that Anthropic might have retained the ability to “disable its technology … in advance or in the middle of ongoing warfighting operations.” App. 183 (emphasis added). Anthropic has since clarified that once a model is delivered for use on the Department’s classified systems, Anthropic cannot “access it, alter it, or shut it down.” 23 Id. at 276. But as explained above, Anthropic can and does program Claude’s behavior with each new model it delivers to Department contractors. So the basic thrust of Michael’s analysis remains intact: Anthropic retains the ability to “alter system guardrails and model weights” over time, and it can use that ability to prevent Claude from “engag[ing]” in specific operations that it deems to reflect contractually unauthorized uses. Id. at 182. Moreover, the Secretary’s order denying reconsideration removes any doubt on whether this specific objection matters. In that order, the Secretary clarified that his determination “did not depend” on any particular understanding of Anthropic’s “real-time technical access to or control” of Claude “post-deployment on the Department’s covered systems.” Suppl. Br. for Resp’ts, Add. 1. Nor, for that matter, did his denial of reconsi