Anthropic PBC v. United States Department of War
CourtCourt of Appeals for the D.C. Circuit
Date FiledSeptember 25, 2026
Docket26-1049
StatusPublished
📰 News Coverage: Read the LAWS.com news report on this case
Full Opinion
United States Court of Appeals
FOR THE DISTRICT OF COLUMBIA CIRCUIT
Argued May 19, 2026 Decided September 25, 2026
No. 26-1049
ANTHROPIC PBC,
PETITIONER
v.
UNITED STATES DEPARTMENT OF WAR AND PETER B.
HEGSETH, IN HIS OFFICIAL CAPACITY AS SECRETARY OF WAR,
RESPONDENTS
Consolidated with 26-1162
On Petitions for Review of an Agency
Action of the Department of War
Kelly P. Dunbar argued the cause for petitioner. With him
on the briefs were Joshua A. Geltzer, Kevin M. Lamb, Anneke
Dunbar-Gronke, and Megan O. Gardner.
Tim Hwang was on the brief for amici curiae Foundation
for American Innovation, et al. in support of petitioner.
Barbara Smith Tyson was on the brief for amicus curiae
Taxpayers Protection Alliance Foundation in support of
petitioner.
2
Benjamin Klubes was on the brief for amici curiae
Catholic Moral Theologians and Ethicists in support of
petitioner.
Harold Hongju Koh, Bruce Swartz, Alexis Loeb, Anthony
Schoenberg, and John Ugai were on the brief for amici curiae
Former Senior National Security Government Officials in
support of petitioner.
Ori Lev was on the brief for amici curiae Employees of
OpenAI and Google in their personal capacities in support of
petitioner.
Samir Jain, Ashley Gorski, and Patrick Toomey were on
the brief for amici curiae American Civil Liberties Union and
Center for Democracy and Technology in support of petitioner.
Brian Scarpelli was on the brief for amicus curiae the
Association for Competitive Technology (ACT) in support of
petitioner.
Matthew Klapper, Elizabeth Deutsch, and Andrew Cherry
were on the brief for amici curiae Former Secretary of Defense
Leon Panetta and the Institute for Security and Technology in
support of petitioner.
Norman L. Eisen, Stephen A. Jonas, Gregg J. Costa,
Sophia Brill, and Connor P. Mui were on the brief for amici
curiae 149 Former Judges and Democracy Defenders Fund in
support of petitioner.
Sarah Grant, Sopen B. Shah, and Addison W. Bennett were
on the brief for amici curiae the Foundation for Individual
Rights and Expression, et al. in support of petitioner.
3
Rakesh Kilaru was on the brief for amicus curiae Faith
Family Technology Network in support of petitioner.
Daniel W. Wolff was on the brief for amici curiae Industry
Trade Associations in support of petitioner.
Elisabeth S. Theodore, Benjamin C. Mizer, Samuel F.
Callahan, and Aaron X. Sobel were on the brief for amicus
curiae Professor Alan Z. Rozenshtein in support of petitioner.
Sarah E. Harrington, Alexander A. Berengaut, David M.
Zionts, Megan A. Crowley, and Mishi Jain were on the brief for
amici curiae Former Service Secretaries and Retired Senior
Military Officers in support of petitioner.
Josephine K. Petrick and Hayley Landman were on the
brief for amici curiae Freedom Economy Business Association
and Values-Led Investors in support of petitioner. George C.
Harris entered an appearance.
Sharon Swingle, Attorney, U.S. Department of Justice,
argued the cause for respondents. With her on the briefs were
Brett A. Shumate, Assistant Attorney General, Eric D.
McArthur, Deputy Assistant Attorney General, and Sean R.
Janda and Brian J. Springer, Attorneys.
Gina D’Andrea, Andrew Zimmitti, and Joel Thayer were
on the brief for amicus curiae Joel Thayer, Senior Fellow at the
America First Policy Institute in support of respondents.
4
Before: HENDERSON, KATSAS, and RAO, Circuit Judges.
Opinion for the Court filed by Circuit Judge KATSAS.
Dissenting opinion filed by Circuit Judge HENDERSON.
KATSAS, Circuit Judge: This case arises from a decision
by the Department of War to exclude Claude, an artificial-
intelligence product developed by petitioner Anthropic PBC,
from its supply chain under the Federal Acquisition Supply
Chain Security Act of 2018. The Department made this
decision after Anthropic refused to relax contractual
prohibitions on the use of Claude for lethal autonomous
warfare or domestic surveillance. Anthropic challenges the
exclusion as arbitrary, unauthorized by the governing statute,
and unconstitutional.
We reject these challenges. The Department had ample
support for its conclusion that the continued integration of
Claude into the Department’s information systems, by the
Department or its contractors, presented a statutorily covered
national-security risk. As Anthropic admits, the company
encodes restrictions into Claude that prevent the model from
performing tasks that Anthropic wishes to prevent. On more
than one occasion, these restrictions have stopped Claude from
performing tasks requested by government users. And
recently, a dispute arose over whether the contractual
prohibitions barred the use of Claude in an ongoing overseas
military operation, leaving the Department uncertain whether
Claude would perform as needed and intended.
Anthropic’s constitutional claims are also without merit.
Its due-process claim fails because the Department promptly
notified the company of the exclusion and its supporting
rationale, and then gave the company a fair opportunity to
contest the exclusion. And Anthropic’s First Amendment
5
claim fails because the Department excluded Anthropic from
its supply chain based on the company’s refusal to assent to a
contract term that the Department deemed essential, not based
on the company’s support for greater governmental regulation
of AI technology.
I
The Federal Acquisition Supply Chain Security Act of
2018 authorizes “covered procurement action[s]” to prevent
agencies from using information technologies that pose a risk
to national security. 41 U.S.C. § 4713(a). Such procurement
actions include barring agency contracts with a particular
supplier and subcontracts that use the supplier to perform work
for the agency. Id. § 4713(k)(4)(A), (B), (D).
To take a covered procurement action, an agency head
must first make a written determination that use of the authority
to take the action “is necessary to protect national security by
reducing supply chain risk” and that “less intrusive measures
are not reasonably available” to reduce that risk. 41 U.S.C.
§ 4713(b)(3)(A), (B). The determination must also specify the
class of covered procurement actions the agency may take
under it. Id. § 4713(b)(3)(C). The statute defines “supply
chain risk” to mean “the risk that any person may sabotage,
maliciously introduce unwanted function, extract data, or
otherwise manipulate the design, integrity, manufacturing,
production, distribution, installation, operation, maintenance,
disposition, or retirement” of covered information-technology
products “so as to surveil, deny, disrupt, or otherwise
manipulate the function, use, or operation of” those products or
the information stored or transmitted on them. Id.
§ 4713(k)(6).
Before determining that it is necessary to take covered
procurement actions, the agency head must provide the
6
supplier with notice and an opportunity to respond. 41 U.S.C.
§ 4713(b)(2). However, the agency head may “temporarily
delay” providing notice if he “determines that an urgent
national security interest requires the immediate exercise of the
authority.” Id. § 4713(c), (c)(1)(A). In that instance, the
agency head must provide notice and an opportunity to respond
“as soon as practicable after addressing the urgent national
security interest.” Id. § 4713(c)(2), (2)(A). Once the agency
head makes a determination, the agency may take all
procurement actions covered by the determination. Id.
§ 4713(a), (b)(3)(C).
The statute channels judicial review of covered
procurement actions into this Court. It provides that a party
notified of a “covered procurement action under section 4713”
may file a petition for review of that action in this Court within
60 days of the notification. 41 U.S.C. § 1327(b)(1). The
statute also bars other judicial review of any “action taken
under” section 4713. Id. § 1327(a).
II
A
Anthropic develops Claude, a family of artificial-
intelligence models. Claude utilizes large-language models,
which are algorithms “trained on massive datasets to identify
patterns and associations in language.” App. 6. Claude can
“respond[] to a wide range of user inputs, or ‘prompts,’ in an
intelligent, human-like manner.” Id. It “can even act
autonomously, executing tasks without requiring ongoing user
direction.” Id. at 7. In the context of warfare, this means that
Claude could be deployed in a way that “independently
identifies and classifies an object as a military target,
determines engagement criteria are satisfied, and launches a
7
weapon strike.” Id. at 16. The power of this new technology
is obvious—as is its potential for misuse.
To reduce the risk of misuse, Anthropic employs three
distinct kinds of restrictions. First, it “seek[s] to embed safety
considerations directly into the model itself.” App. 8. For
example, Anthropic has disabled Claude from performing
specific tasks such as making biological, chemical, nuclear, or
radiological weapons. Id. at 103. Beyond that, Anthropic
trains Claude to conform to a constitution developed for it by
Anthropic. According to Jared Kaplan, Anthropic’s co-
founder and Chief Science Officer, this constitutional training
makes Claude follow “a set of normative principles, like
balancing helpfulness against harm avoidance, and respecting
values such as individual privacy and political freedom.” Id. at
8. Dario Amodei, Anthropic’s Chief Executive Officer,
explains that this training, focused on “high-level principles
and values,” imbues Claude with an “identity, character,
values, and personality” that lead to what Anthropic deems “a
coherent, wholesome, and balanced psychology.” Id. at 93–94.
Anthropic considers this kind of “model development” to be
“at the core of [its] mission.” Id. at 2.
Second, Anthropic builds into its products “technical
measures that stack on top of the model itself.” App. 8. These
measures include monitoring systems to detect harmful activity
and targeted interventions to prevent it. Id. Anthropic began
to develop this “second line of defense” around mid-2025,
because “all models can be jailbroken.” Id. at 103.
Third, Anthropic contractually prohibits uses of Claude
that it deems inappropriate. As summarized by Kaplan, its
Usage Policy prohibits “unacceptable” uses including
“surveillance, compromising computer systems or networks,
and designing weapons.” App. 9. The actual Usage Policy
8
imposed by Anthropic on Palantir Technologies, Inc., which
analyzes data for the Department of War, is more extensive.
Among other things, it prohibits Palantir from using Claude to
compromise children’s safety, incite violence or hateful
behavior, invade privacy, create emotionally harmful content,
spread misinformation, interfere in elections, or monitor
individuals’ physical locations. Id. at 394–400. Anthropic
informs us that such usage restrictions reflect “the very purpose
for which our company was founded,” and their removal would
“contradict our deeply held values.” Id. at 10.
B
Over the past two years, the Department of Defense
(which now calls itself the Department of War) has greatly
expanded its use of AI. During this time, Anthropic partially—
but not completely—relaxed its use restrictions to
accommodate the Department.
In 2024, the Department and the intelligence community
began using standard, commercially available models of
Claude in their classified systems, working through contractors
with access to Claude. App. 279. Consistent with Anthropic’s
model training, Claude “refuse[d]” to perform “tasks that were
appropriate in a national security context—such as
summarizing threat assessments, processing classified
documents, or translating intercepted materials describing
violence.” Id. at 280.
In response to this problem, Anthropic developed a special
“Claude Gov” model that would perform such tasks for the
national-security agencies, which it released in March 2025.
App. 280–81. Anthropic also developed a “government-
specific addendum” to its Usage Policy, which contractually
allowed certain uses that it would deny to private customers.
Id. at 12. Anthropic describes this addendum as “designed to
9
strike a balance between enabling national security beneficial
uses and mitigating potential harms.” Id. Over time, Anthropic
came to permit the Department to use Claude to design more
effective weapon systems, to analyze foreign intelligence, and
to conduct offensive cyber operations. Id. at 12, 278.
However, Anthropic retained contractual prohibitions on the
use of Claude for “lethal autonomous warfare” and for “mass
surveillance of Americans.” Id. at 12–13.
In the fall of 2025, Anthropic and the Department began
negotiations to establish a direct contractual relationship and to
expand the Department’s use of Claude. As part of that
negotiation, the Department asked Anthropic for contractual
permission to deploy Claude for “all lawful uses.” App. 14.
Anthropic agreed to substantially relax the prior use
restrictions, but it continued to insist that Claude not be used
for lethal autonomous warfare or mass surveillance of
Americans, which it describes as “two critical exceptions.” Id.
Negotiations over these restrictions extended for a few months
and eventually stalled.
C
The contractual dispute between Anthropic and the
Department came to a head in early 2026.
On January 9, Secretary of War Pete Hegseth set forth a
comprehensive “Artificial Intelligence Strategy for the
Department.” App. 202. According to the Secretary, “AI-
enabled warfare and AI-enabled capability development will
re-define the character of military affairs over the next decade.”
Id. The Secretary discerned a “race” between the United States
and its “adversaries” to integrate AI technology into military
capabilities. Id. The Secretary thus “direct[ed] the Department
of War to accelerate America’s Military AI Dominance by
becoming an ‘AI-first’ warfighting force across all
10
components, from front to back.” Id. As part of that directive,
the Secretary stated that the Department must use AI models
“free from usage policy constraints that may limit lawful
military applications,” and he directed the Department to
“incorporate standard ‘any lawful use’ language into” contracts
procuring AI services. Id. at 206.
Around the same time, an Anthropic executive
“questioned the propriety” of a contractor’s use of Claude “for
a sensitive military operation abroad.” App. 181. The
Department believes that the governing usage policy “clearly
permitted” the engagement at issue. Id. at 183. Nonetheless,
the question “led to alarm by the DoW and the prime contractor
who provides Anthropic software, and raised material doubts”
about whether the software would perform as the Department
was expecting. Id. at 228. The Department does not elaborate
on the specific military operation at issue. However, Anthropic
put into the record media reports stating that “Anthropic had
raised concerns with Palantir about the role [Anthropic’s]
technologies played” in the January 3 “military operation to
capture Venezuela’s president, Nicolás Maduro.” Id. at 171.
Finally, the Department learned of another instance when
Anthropic’s model training caused Claude to refuse to respond
to queries from a government agency. Specifically, Claude
refused to respond to queries from the Centers for Disease
Control and Prevention (CDC) regarding sensitive research on
preventing the spread of infectious disease. App. 212–13.
On February 24, Amodei met with Secretary Hegseth to
discuss the standoff. The Secretary praised Claude’s
capabilities but demanded that Anthropic accede to an “all
lawful uses” contractual term by February 27. App. 26.
On February 26, Anthropic refused, and Amodei released
a statement explaining the company’s decision to maintain the
11
two contested use restrictions. He stated that “mass domestic
surveillance,” although legal, was “incompatible with
democratic values” and presented “serious, novel risks to our
fundamental liberties.” App. 146. He further stated that “fully
autonomous weapons (those that take humans out of the loop
entirely and automate selecting and engaging targets) may
prove critical for our national defense” in the future, but that
AI technology was not yet “reliable enough” to currently power
such weapons. Id. at 147. Amodei recognized that “[i]t is the
Department’s prerogative to select contractors most aligned
with their vision” for appropriate AI uses, and he pledged a
“smooth transition to another provider” “[s]hould the
Department choose to offboard Anthropic.” Id.
One day later, President Trump and Secretary Hegseth
denounced Anthropic’s decision on social media, and the
Secretary began the process of removing Claude from the
Department’s supply chain. App. 77, 153.
D
On March 3, 2026, Secretary Hegseth made a formal
determination to take procurement actions against Anthropic
under the Supply Chain Security Act. First, the Secretary
determined that use of Claude in Department systems “presents
a significant supply chain risk” and that removing Claude from
them was “necessary to protect national security” by reducing
that risk. App. 177. Next, he determined that no “less intrusive
measures” for reducing the risk were “reasonably available.”
Id. Finally, he determined that an “urgent national security
interest” required immediate action. Id. The determination
rested on a recommendation from senior agency officials,
which in turn rested on a memorandum from Emil Michael, the
Department’s Under Secretary for Research and Engineering.
Among other things, Michael cited Anthropic’s refusal to allow
12
all lawful uses of Claude, its ability to “alter system guardrails
and model weights” governing how Claude responds to user
prompts, and its questioning the Department’s use of Claude in
a sensitive military mission abroad. Id. at 181–83.
Secretary Hegseth immediately notified Anthropic of his
determination, in a letter dated March 3 and emailed to
Anthropic on March 4. App. 72, 243. The notice stated that
the determination was effective immediately, and it gave
Anthropic an opportunity to seek reconsideration within 30
days. Id. at 73.
The Department immediately began implementing the
Secretary’s determination. On March 6, its Chief Information
Officer issued a Department-wide memorandum ordering the
removal of Anthropic products from the Department’s systems
“as soon as practical,” and in any event within 180 days. App.
80. The memo further prohibited contractors from using
Anthropic products in their work for the Department. Id. The
Department quickly moved to expand its contractual
relationship with OpenAI, another company that provides AI
services. Id. at 220. In response, Amodei wrote to Anthropic
employees to express his view that the Department, OpenAI,
and Palantir had not established adequate safety protocols for
the use of AI. Id. at 220–23.
On March 9, Anthropic filed a petition for review of its
exclusion from the Department’s supply chain. Anthropic also
moved for a stay pending review. In litigating the stay motion,
the parties filed various affidavits and other evidentiary
materials with this Court.
On March 19, the Department provided Anthropic with a
supplemental notice, which included copies of the
determination itself, the recommendation from agency
officials, the memorandum by Under Secretary Michael, and a
13
statement of the exact scope of the covered procurement
actions. App. 224. The supplemental notice restarted the 30-
day deadline for Anthropic to submit any “information or
arguments in opposition to this notice.” Id.
On April 8, this Court denied a stay but expedited review
on the merits. Anthropic PBC v. U.S. Dep’t of War, No. 26-
1049, 2026 WL 1042493 (D.C. Cir. Apr. 8, 2026) (per curiam).
We ordered the parties to brief the question of our jurisdiction
over the petition for review and to provide further information
on how Anthropic could affect the functioning of its models
before or after their delivery to the Department.
On April 17, Anthropic asked the Department to “rescind”
its exclusion from the supply chain. See Letter from Counsel
for Resp’ts to Clerk of Ct. at 6–7, Anthropic PBC v. U.S. Dep’t
of War, No. 26-1049 (D.C. Cir. filed May 12, 2026). There and
in the appendix here, Anthropic tendered a supplemental
declaration addressed to our factual question. App. 272–97.
The Department has also tendered its own supplemental
declaration, styled as one “in support of the administrative
record.” Id. at 408 (cleaned up); see id. at 408–22.
On June 3, the Secretary issued a decision denying
reconsideration of his March 3 determination. Suppl. Br. for
Resp’ts, Add. 1. The Secretary clarified that his determination
did not rest on the premise that Anthropic could control any
version of Claude after its delivery to contractors for
deployment on the Department’s classified systems. See id.
After oral argument in this Court, we ordered
supplemental briefing on (1) whether Anthropic’s April 17
filing divested this Court of jurisdiction and (2) the impact of
the Secretary’s June 3 order. Following that briefing, the
matter is now ripe for decision.
14
III
We agree with the parties that we have jurisdiction to
review the covered procurement actions taken against
Anthropic under the Supply Chain Security Act.
To begin, we conclude that our jurisdiction was secure
when Anthropic filed its petition for review on March 9. The
Supply Chain Security Act gives this Court jurisdiction to
review any “covered procurement action under section 4713,”
so long as the aggrieved party files the petition within 60 days
of receiving notice of the covered action. 41 U.S.C.
§ 1327(b)(1). Here, the Secretary invoked section 4713 to
remove Claude from the Department’s supply chain.
Anthropic received notice of the Secretary’s action on March
4, and it promptly sought review five days later. That sufficed
to establish jurisdiction under section 1327(b)(1).
We recognize that the statute distinguishes between the
“covered procurement action[s]” authorized by section
4713(a), which are reviewable, and the antecedent written
“determination” that use of the authority to take covered
procurement actions is necessary, as separately required by
section 4713(b). But the statute does not prohibit the
government from making the written determination and taking
the covered procurement actions at the same time. Here, the
Department has done both: Its notice to Anthropic stressed that
the determination had become “effective immediately.” App.
73. And within three days, the Department had begun
implementing the determination with an agency-wide order to
“remove” Claude “from all DoW systems and networks … as
soon as practical.” Id. at 80. So, Anthropic was notified of
“covered procurement action[s]” and timely sought review of
them. 41 U.S.C. § 1327(b).
15
A distinct jurisdictional question arose after Anthropic
asked the Department to rescind the covered procurement
actions on April 17. Under statutory schemes limiting judicial
review to final agency action, the filing of a motion for
reconsideration renders incurably premature a previously filed
petition for review. See, e.g., Nat’l Ass’n of Immigr. Judges v.
FLRA, 77 F.4th 1132, 1136–38 (D.C. Cir. 2023) (per curiam).
Anthropic contends that this incurably-premature doctrine does
not apply to judicial review under the Supply Chain Security
Act because the statute contains no finality requirement. For
its part, the Department contends that the doctrine does apply
but that it is waivable and was waived in this case.
Subsequent developments make it unnecessary for us to
resolve these questions. The Secretary denied Anthropic’s
request for rescission or reconsideration on June 3; Anthropic
filed a petition for review of the March 3 and June 3 decisions
on June 17; and we consolidated the two cases on June 24. We
have jurisdiction over at least one of them. On the one hand, if
the incurably-premature doctrine does not apply to judicial
review under the Supply Chain Security Act, then Anthropic’s
request for rescission did not imperil our jurisdiction over its
earlier-filed petition for review. On the other hand, if the
incurably-premature doctrine does apply here and is not
waivable, then the second petition for review cinched up our
jurisdiction: Where the doctrine applies, the filing of a motion
for reconsideration “tolls the period for judicial review of the
original order, which can therefore be appealed to the courts
directly after the petition for reconsideration is denied.” ICC
v. B’hood of Locomotive Eng’rs, 482 U.S. 270, 279 (1987).
One way or the other, our jurisdiction is secure.
16
IV
Anthropic challenges each of the Secretary’s three key
determinations under the Supply Chain Security Act, namely
that (A) removing Claude from the Department’s supply chain
was “necessary to protect national security by reducing supply
chain risk,” 41 U.S.C. § 4713(b)(3)(A); (B) “less intrusive
measures” for reducing that risk were “not reasonably
available,” id. § 4713(b)(3)(B); and (C) an “urgent national
security interest” required “the immediate exercise” of the
removal authority, id. § 4713(c).
These claims are governed by the standards of review set
forth in the Supply Chain Security Act, which requires us to
“hold unlawful” covered procurement actions under section
4713 that we find to be “arbitrary, capricious, an abuse of
discretion, or otherwise not in accordance with law.” 41 U.S.C.
§ 1327(b)(2), (2)(A). These standards closely track those in the
Administrative Procedure Act. See 5 U.S.C. § 706(2).
On review for arbitrariness, we require only that agency
action be “reasonable and reasonably explained.” FCC v.
Prometheus Radio Project, 592 U.S. 414, 423 (2021). Judicial
review under this standard is “deferential,” and this Court may
not “substitute its own policy judgment for that of the agency.”
Id. We will uphold even a “decision of less than ideal clarity,”
so long as the agency’s basic rationale “may reasonably be
discerned.” FCC v. Fox Television Stations, Inc., 556 U.S. 502,
513–14 (2009) (quoting Bowman Transp., Inc. v. Arkansas-
Best Freight Sys., Inc., 419 U.S. 281, 286 (1974)).
We review de novo agency determinations on purely legal
questions of statutory construction. Loper Bright Enters. v.
Raimondo, 603 U.S. 369, 412 (2024). In construing statutes
implicating national security, we resolve ambiguities against
intruding on the national-security determinations of the
17
Executive Branch. See, e.g., Dep’t of Navy v. Egan, 484 U.S.
518, 530 (1988); Hikvision USA, Inc. v. FCC, 97 F.4th 938, 948
(D.C. Cir. 2024); Fed. Express Corp. v. U.S. Dep’t of Com., 39
F.4th 756, 769 (D.C. Cir. 2022).
Where the application of a statutory term turns primarily
on factual determinations, we review the agency’s assessment
deferentially. Seven County Infrastructure Coal. v. Eagle
County, 605 U.S. 168, 181 (2025). And where a factual
question turns on assessments of national security, we give the
agency more deference, even if constitutional claims are at
issue. See, e.g., Trump v. Hawaii, 585 U.S. 667, 704 (2018)
(“our inquiry into matters of … national security is highly
constrained”); Holder v. Humanitarian L. Project, 561 U.S. 1,
33 (2010) (HLP) (in national-security cases, “evaluation of the
facts by the Executive, like Congress’s assessment, is entitled
to deference”).
A
The Secretary reasonably concluded that removing
Anthropic from the Department’s supply chain was necessary
to protect national security by reducing supply chain risk to the
Department’s information systems. Specifically, the Secretary
credited a joint recommendation from two senior Department
officials that Claude might be “subject to manipulation” by
Anthropic “in such a manner as to inhibit the DoW’s use
thereof.” App. 178. Likewise, he credited Under Secretary
Michael’s conclusion that Anthropic might “manipulat[e]” the
“design, integrity, and operation” of the Department’s Claude
models, potentially causing “critical defense system[s] failing
to engage” as intended by the Department. Id. at 182.
18
1
The record in this case amply supports the Secretary’s
conclusion. To begin, it is undisputed that Anthropic can and
does control how Claude responds—or fails to respond—to
user prompts. Anthropic’s Chief Science Officer explained
how the company “seek[s] to embed safety considerations
directly into the model itself.” App. 8. Its CEO explained how
such training gives the model an “identity, character, values,
and personality” of its own, tethered to a “constitution”
developed to impose “high-level principles and values” on
Claude itself. Id. at 93–94. And the head of its public-sector
business explained: “Model training is the primary mechanism
through which Anthropic can influence the behavior of models
used by the Department.” Id. at 276. Anthropic disclaims any
ability to access or alter a model that has already been delivered
to the Department, see id., despite the “technical measures” that
it uses to police compliance with usage restrictions by private
customers, id. at 8. Nonetheless, extant models reflect
Claude’s “[c]onstitutional” training. Id. at 274–75. Moreover,
Anthropic may encode additional restrictions each time it
delivers any “new version of the model” to Department
contractors. Id. at 276. Finally, it is undisputed that such
model restrictions are vitally important to Anthropic, which
describes them as lying “at the core of [its] mission.” Id. at 2.
The record also indicates that Anthropic’s model training
is effective in enforcing usage restrictions and that, as a result,
Claude has refused to answer legitimate queries from
government users. Anthropic itself explained how early,
commercially available versions of Claude frustrated
Department and intelligence-community users by refusing
prompts to evaluate classified materials. App. 255. Likewise,
as Under Secretary Michael explained, the Department learned
in 2025 that Claude had refused to process CDC prompts to
19
support research to prevent the spread of infectious diseases.
Id. at 212. Anthropic responds that these glitches reflected
safety features appropriately built into models sold to private
companies and were resolved after Anthropic engineers
worked with the relevant government stakeholders. Id. at 255–
56, 261–62. Perhaps so, but the point here is not that these
model or usage restrictions were arbitrary; instead, it is that
Anthropic’s model training does effectively enforce
contractual usage restrictions.
Finally, the record reveals a recent, serious dispute about
the scope of the contractual prohibitions on lethal autonomous
warfare and mass domestic surveillance. Under Secretary
Michael describes the incident in general but striking terms:
[O]ne of Anthropic’s executives questioned the
propriety of the potential use of their software for a
sensitive military operation abroad despite that use
being permitted under the existing Terms of Service.
This led to alarm by the DoW and the prime contractor
who provides Anthropic software, and raised material
doubts as to whether they would cause their software
to stop working or cause some other disastrous action
that would put our warfighters[’] lives in danger.
App. 181. Anthropic does not say much about this incident,
except to suggest that it reflected a misunderstanding. Id. at
236–37. But regardless, Anthropic has made clear that it views
the contractual prohibition on mass domestic surveillance as
urgent to support “democratic values,” id. at 146, and the
contractual prohibition on lethal autonomous warfare as urgent
to avoid “put[ting] America’s warfighters and civilians at risk”
of a catastrophic AI mistake, id. at 147. For its part, the
Department has made clear that it views an “any lawful use”
authorization to be critical to its “AI-first” strategic plan. Id. at
20
202, 206. With such diametrically opposed positions and with
contractual limitations that are hardly self-defining, the
prospect for disputes is apparent.
Because Anthropic was willing and able to enforce
contractual restrictions through model training, the Department
reasonably worried that “critical defense system[s]” supported
by Claude might “fail[] to engage” as the Department would
expect. Id. at 182 (Michael memorandum). Of course, we do
not know exactly what happened in the incident described by
Michael as a near-disaster and by Amodei as a
misunderstanding. But Anthropic’s suggestion that the
incident may have arisen during a shock-and-awe, kinetic
operation to capture a foreign head of state abroad simply
underscores the fraught nature of its dispute with the
Department—and the Department’s need for certainty that its
AI systems will perform as expected.
In sum, the Department reasonably feared that Anthropic
might manipulate Claude’s design to prevent it from
performing national-security functions that the Department
deems contractually authorized and necessary.
2
Anthropic offers two primary responses, one factual and
one legal. Neither is persuasive.
a
On the facts, Anthropic stresses that it cannot control or
even monitor the operation of any model once the model is
delivered to a Department contractor for use on a classified
system. App. 274–78. In sum, Anthropic says it has no “back
door or remote ‘kill switch.’” Id. at 258. So, it reasons, the
Department can test any new model delivered by Anthropic to
21
contractors—before integrating it into the Department’s
information systems—to see if the new model performs up to
the Department’s expectations. Id. at 282–92. Specifically,
Anthropic says that the Department can “test the model” to see
if it will “refuse tasks the Department deem[s] appropriate to
its lawful mission, or … override the Department’s judgment
that an activity is permissible.” Id. at 285. And if the
Department is not satisfied with the new model, it can simply
“decline to approve” the model. Id. at 286. This would leave
the Department free to continue using an older, previously
accepted model, which “does not degrade or change on its
own.” Id. at 287–88.
These responses do not assuage the Department’s
concerns. To begin with, the Department has good reasons not
to view advance testing as a panacea. As noted above, the
contested use restrictions are hardly self-defining, and there are
any number of possible scenarios involving, say, greater or
lesser degrees of human involvement in targeting decisions
during ongoing military operations. Moreover, as Under
Secretary Michael explained, Claude employs technology that
is “opaque” to its users, App. 182, partly because “Anthropic’s
unique building processes are considered proprietary
intellectual property” and partly because its models “have
weights or parameters that number approximately 5 to 10
trillion per model,” id. at 410. All of this makes “rigorous
analysis or auditing of its output mathematically impossible.”
Id. Indeed, Anthropic itself acknowledges “some legitimacy to
DoW’s concern about the opacity of these systems generally.”
Id. at 261. Finally, Anthropic acknowledges that Claude might
respond differently to similar requests depending on their exact
wording. Id. at 289. So, while one Department official might
secure an advance commitment from Claude to perform a
contemplated military function, a second official, using slightly
different wording, might later be met with a refusal.
22
In any event, even if testing could reliably establish in
advance the range of situations where a new model might
decline to perform some lawful but contractually prohibited
function, the Department could hardly be satisfied with the
option of simply refusing the upgrade. Anthropic “continually
develop[s] and release[s] increasingly capable versions of
Claude.” App. 6. In 2025, it released three new, increasingly
powerful versions of Claude Gov. Id. at 256–57. Since then,
it has released several more versions of Claude. See Anthropic,
Models Overview, https://perma.cc/BR4B-SRYJ. The
Secretary has noted the “unprecedented velocity in the
evolution of the frontier AI models,” which “are becoming
smarter and more robust every day.” App. 205. Amodei
likewise acknowledges “a smooth, unyielding increase in AI’s
cognitive capabilities” over the last few years, and he predicts
even greater breakthroughs on the horizon, such as a “point
where the current generation of AI autonomously builds the
next.” Id. at 85–86. More ominously, he also foresees—as
perhaps do our adversaries—that a “swarm of millions or
billions of fully automated armed drones, locally controlled by
powerful AI and strategically coordinated across the world by
an even more powerful AI, could be an unbeatable army.” Id.
at 106. Quite obviously, the Department cannot utilize AI
systems that remain trapped in amber.
Finally, Anthropic claims that Under Secretary Michael’s
memorandum contained a discrete factual error in suggesting
that Anthropic could modify the behavior of models already
delivered to Department contractors. In the one sentence at
issue, Michael expressed concern that Anthropic might have
retained the ability to “disable its technology … in advance or
in the middle of ongoing warfighting operations.” App. 183
(emphasis added). Anthropic has since clarified that once a
model is delivered for use on the Department’s classified
systems, Anthropic cannot “access it, alter it, or shut it down.”
23
Id. at 276. But as explained above, Anthropic can and does
program Claude’s behavior with each new model it delivers to
Department contractors. So the basic thrust of Michael’s
analysis remains intact: Anthropic retains the ability to “alter
system guardrails and model weights” over time, and it can use
that ability to prevent Claude from “engag[ing]” in specific
operations that it deems to reflect contractually unauthorized
uses. Id. at 182. Moreover, the Secretary’s order denying
reconsideration removes any doubt on whether this specific
objection matters. In that order, the Secretary clarified that his
determination “did not depend” on any particular
understanding of Anthropic’s “real-time technical access to or
control” of Claude “post-deployment on the Department’s
covered systems.” Suppl. Br. for Resp’ts, Add. 1. Nor, for that
matter, did his denial of reconsi