There is now a new way to become a risk to US national security: build a technology capable of serving the military, then decide that it should not be allowed to do everything.

On September 25, 2026, the US Court of Appeals for the District of Columbia Circuit, in a 2–1 decision, upheld the Pentagon’s decision to exclude Claude, the artificial intelligence model developed by Anthropic, from its supply chain. The dispute may appear narrow: one supplier, one customer, two restrictions on use, and a disagreement over the terms under which a technology can be deployed.

In reality, it reaches much further.

As artificial intelligence becomes part of military infrastructure, who retains the final authority over what it can do?

Anthropic believed it should retain that authority over two specific uses. The Pentagon believes that authority must ultimately belong to the state.

Between those positions lies what may become one of the first major sovereignty disputes of the foundation-model era.

Two red lines

The dispute did not begin because Anthropic refused to work with the US military. Almost the opposite was true.

Claude had been used from 2024 in classified environments within the Pentagon and the US intelligence community through contractors. But early commercial versions of the model sometimes rejected tasks that were routine in a national-security context: summarizing threat assessments, processing classified material or translating intercepted communications describing violence.

Anthropic therefore adapted the product.

In March 2025, the company introduced Claude Gov, a version designed for national-security agencies. It also relaxed some of its contractual restrictions. Claude could be used to analyze foreign intelligence, conduct certain offensive cyber operations and contribute to the design of weapons systems.

Two prohibitions remained: mass domestic surveillance of Americans and fully autonomous lethal weapons — systems capable of selecting and engaging targets without human intervention in the final decision.

Those two exceptions eventually became the fault line.

In late 2025, the Pentagon asked Anthropic to accept a much simpler principle: “all lawful uses.”

If an operation was lawful under US law and authorized by the competent authorities, the supplier of the model should not be able to impose an additional private restriction.

Anthropic refused.

The company was not necessarily arguing that the two uses would always be illegal. CEO Dario Amodei acknowledged that some forms of domestic surveillance could be lawful while still presenting, in Anthropic’s view, serious risks to civil liberties. On fully autonomous weapons, he acknowledged their potential importance to US defense while arguing that current technology was not sufficiently reliable to delegate the selection and engagement of targets without human control.

The disagreement therefore ran deeper than legal compliance.

Anthropic’s position was effectively: not everything that is legal should necessarily be automated.

The Pentagon’s answer was equally fundamental: that decision cannot ultimately belong to the supplier.

When the safeguard becomes the dependency

The dispute might have remained contractual. In early 2026, it changed character.

On January 9, Defense Secretary Pete Hegseth presented a strategy intended to accelerate the integration of artificial intelligence across the US military. The directive included a requirement that future contracts permit lawful military uses without being constrained by the private usage policies of technology suppliers.

Around the same period, another episode made the underlying problem tangible.

According to the court record, an Anthropic official raised questions about a contractor’s use of Claude during a sensitive overseas military operation. The Pentagon considered the use permissible under the contract. But the fact that the question arose was enough to expose a deeper concern: if a model becomes essential to an operation, what happens when its developer concludes that the operation crosses its own limits?

The record also referred to other instances in which Claude rejected government requests because of restrictions embedded in its behavior.

On February 24, Hegseth and Amodei met. The Pentagon again asked Anthropic to accept the clause permitting all lawful uses. Two days later, the company maintained its refusal.

On March 3, the Pentagon formally designated Claude as presenting a significant risk to its supply chain. Anthropic systems were to be removed from Defense Department networks, and contractors working for the department could no longer use them in performing their contracts.

At that point, the case ceased to be merely a dispute between a technology company and one of its customers.

A guardrail designed to reduce the risks created by artificial intelligence had itself become a legally recognizable source of risk.

Two definitions of reliability

The paradox is almost perfect.

For Anthropic, reliability means preventing the model from performing certain tasks when their consequences may be irreversible. The more powerful a system becomes, the stronger its safeguards should be.

For a military organization, the definition can be reversed.

A system integrated into intelligence, cyber operations, command functions or military planning becomes part of an operational chain. Its value depends not only on its intelligence, but also on its availability, predictability and the certainty that it will perform the mission for which it was deployed.

A fighter aircraft whose manufacturer could determine which missions it was willing to fly would hardly qualify as a sovereign military capability. The same would apply to a communications system whose supplier retained an implicit right to decide which operations could use it.

Artificial intelligence introduces precisely that possibility.

Unlike an engine, a radar or a missile, a foundation model has behavior continuously shaped by its training, weights, usage policies and the safety mechanisms developed by a private company.

The supplier is therefore no longer selling only a technology.

It is carrying a normative architecture with it.

The Washington precedent

That reality has now entered US defense procurement law.

The D.C. Circuit majority relied on the Federal Acquisition Supply Chain Security Act, which allows the government to exclude technologies presenting certain national-security risks. The court concluded that Anthropic’s ability to modify the guardrails and weights of future versions of Claude could fall within the statute’s definition of risks affecting the operation of an information-technology product.

The distinction matters.

The court did not establish that Anthropic could remotely disable a model already installed inside a classified military network. The Pentagon itself clarified that its decision did not depend on such a possibility.

The problem lies elsewhere.

Anthropic develops future versions of the system and determines some of the behaviors those versions will accept or reject.

In other words, dependency does not necessarily take the form of a kill switch.

It can reside inside the model itself.

For the majority, that was sufficient to make the Pentagon’s concern reasonable. A system whose future versions may incorporate restrictions incompatible with certain military missions can constitute a supply-chain risk even when those restrictions are introduced for safety reasons rather than with any intention of harming the government.

That may be the most consequential legal element of the case.

The supplier’s intentions and the customer’s operational security become two separate questions.

Two courts, two readings

The Pentagon’s victory is not definitive.

Less than a month earlier, on August 28, federal judge Rita Lin in California had invalidated a parallel designation targeting Anthropic. She found that the government action examined in that proceeding was legally defective and accepted elements of the company’s constitutional arguments concerning retaliation and due process.

At first sight, the two rulings appear contradictory.

They are not based on precisely the same legal mechanism.

The D.C. Circuit considered the exclusion under the Federal Acquisition Supply Chain Security Act, whose definition of supply-chain risk was broad enough, according to the majority, to encompass certain modifications to the operation of an information-technology product. The majority also rejected Anthropic’s argument that the decision constituted unlawful retaliation for its public positions on AI safety.

The litigation therefore remains open. After the September 25 decision, Anthropic said it was considering its options, including seeking review by the full appeals court. The company has also argued that the government measures have cost it billions of dollars in business and damaged its reputation.

But the importance of the ruling already extends beyond the eventual outcome of the case.

At this level of the federal judiciary, restrictions imposed by the developer of a major AI model can now be analyzed not merely as safety mechanisms, but as a potential dependency within a strategic supply chain.

Software becomes political

The problem was less visible with previous generations of software.

Microsoft could provide an operating system to the US government without deciding the political objectives pursued with every document produced on it. A server manufacturer could impose technical requirements without determining which intelligence operations those machines would execute.

Foundation models blur that separation.

They interpret requests. They can accept them, transform them or refuse them. They are trained according to principles selected by their developers. And as they become capable of increasingly autonomous action, those principles can generate operational consequences.

Code begins to resemble policy.

For companies, surrendering that control entirely creates another problem.

A laboratory agreeing indiscriminately to “all lawful uses” would become dependent on the state’s own definition of legality — and on how that definition might evolve. Its technology could eventually be used in circumstances its researchers, executives, employees or other customers consider incompatible with the commitments under which the system was developed.

For the state, accepting the opposite principle means recognizing that a private company can embed its own limits inside defense infrastructure.

Both positions therefore contain their own form of risk.

No stable institutional architecture yet exists to reconcile them.

The military AI market could divide

The Anthropic dispute may consequently reach far beyond Claude.

Western militaries are seeking to integrate increasingly capable models into intelligence, logistics, cyber operations, image analysis, planning and, progressively, combat functions. They do not develop all these technologies themselves. They are becoming customers of a private industry whose models evolve much faster than traditional military procurement cycles.

That dependence creates a new industrial trade-off.

AI laboratories can accept contracts granting the state very broad discretion over military applications. They can preserve their own restrictions and relinquish some defense markets. A third possibility is to develop separate government models governed by different rules from civilian versions — an approach Anthropic had already begun pursuing with Claude Gov.

But as AI models become more central to military operations, pressure for sovereign control is likely to intensify.

That could benefit suppliers willing to accept the doctrine of “all lawful uses.” It could also encourage the Pentagon to diversify across multiple models, expand internal capabilities or demand architectures designed to reduce dependence on any single laboratory.

The issue therefore extends beyond competition among Anthropic, OpenAI, Google and other developers.

It concerns the structure of the emerging American military-technology complex itself.

Who sets the limit?

The final question is probably not whether Anthropic was right to establish its two red lines, or whether the Pentagon was right to reject them.

It is who should possess the authority to establish those lines.

The developer can invoke its technical knowledge of the system. The military can invoke its operational responsibility. The executive branch holds political authority over the armed forces. Congress can define permissible uses. Courts can determine how far each of those powers extends.

For now, these layers overlap without a common doctrine.

That is why the September 25 ruling matters beyond Claude’s immediate commercial fate.

For decades, military sovereignty has meant controlling territory, communications, industrial capacity, weapons and supply chains. Artificial intelligence now adds something less visible: control over the behavior of software itself.

The Pentagon is no longer asking its suppliers merely to deliver a technology.

It is asking them not to retain the authority to decide what that technology will refuse to do.

And when the machine enters the chain of command, the last line of code becomes a line of sovereignty.

Main sources

— US Court of Appeals for the District of Columbia Circuit, Anthropic PBC v. United States Department of War, No. 26-1049, September 25, 2026. — Reuters, US appeals court upholds Pentagon's blacklisting of Anthropic, September 25, 2026. — Reuters, US judge rules Pentagon blacklisting of Anthropic unlawful, August 28, 2026. — Reuters, coverage of the Anthropic–Pentagon litigation and the California federal court proceedings, August–September 2026.