mrkeyoor.com_
Sat 26 Sept 03:40 UTC
AI6 min read

Court Treats Claude's Safety Refusals as a Supply-Chain Risk

A US appeals court says Anthropic's built-in limits can count as a federal supply-chain risk. The ruling turns model behavior into a procurement issue.

An AI model refusing a task can now count as a federal supply-chain failure. That is the consequence developers should take from a US appeals court's decision upholding the Pentagon's exclusion of Anthropic, rather than the simpler headline that the company lost a government contract dispute. The court accepted that safety behavior built into future versions of Claude could make the system unavailable for work the military expected it to perform, even though Anthropic could not remotely alter the copies already running inside classified networks.

In a 2-1 decision issued September 25, the US Court of Appeals for the District of Columbia Circuit denied Anthropic's challenges to the designation. Judges Gregory Katsas and Neomi Rao formed the majority; Judge Karen LeCraft Henderson dissented. CNBC reported the result as the latest turn in a dispute over two limits Anthropic would not remove: using Claude for fully autonomous lethal operations or mass domestic surveillance.

How a refusal became a supply-chain problem

The Federal Acquisition Supply Chain Security Act lets an agency exclude technology that creates a national-security risk. Its definition covers a person who may manipulate a product's design or operation in a way that denies or disrupts its function. The majority read those verbs literally. It found that malicious intent was unnecessary, because Anthropic deliberately trains and configures Claude to reject uses the company prohibits. On that reading, a safeguard can fit the statute when it prevents a government system from doing an authorized job.

That conclusion rested on more than a policy page. The 51-page opinion says standard Claude models had refused national-security tasks such as summarizing threat assessments and processing documents that described violence. Anthropic responded by releasing Claude Gov in March 2025, with behavior adapted for government work. The record also describes a refusal to answer Centers for Disease Control and Prevention questions about research intended to stop infectious disease, plus a disagreement over whether Claude could be used in an overseas military operation. The operation itself remains unspecified in the court's account.

Anthropic had already relaxed many limits. According to the opinion, the government-specific terms allowed Claude to assist with foreign-intelligence analysis, offensive cyber operations and the design of more effective weapon systems. The company held its line on fully autonomous lethal use and mass surveillance of people in the United States. In Anthropic's February statement, CEO Dario Amodei argued that present models were too unreliable to select and engage targets without a human in the loop, while AI could assemble scattered personal data into surveillance at a scale existing law had not anticipated.

Anthropic told the court it could not access, change or shut down a model after delivery into a classified system. The government therefore was not facing a remote kill switch. The majority still found a risk in the release cycle: Anthropic controls the training and guardrails of each new model it delivers, and those models can respond differently to prompts with slightly different wording. Advance testing could not guarantee that the next version would accept every task the department considered lawful.

For developers, that turns a familiar integration problem into a procurement question. A hosted model's refusal boundary can move with a new release. A self-hosted copy freezes one build but also freezes its capabilities. The court treated continued access to newer models as operationally important, so the government's inability to predict their behavior counted against Anthropic. Model versioning and refusal tests now sit beside fallback planning in this corner of federal purchasing.

The order is narrower than a general Claude ban

The March 3 determination ordered Claude removed from department systems as soon as practical, with 180 days as the outside deadline, and barred contractors from using Anthropic products for work performed under department contracts. It does not block individuals or ordinary companies from using Claude. Anthropic's customer guidance after the designation said military contractors could continue using Claude for work unrelated to those contracts. The appeals ruling did not expand that reach.

Two legal tracks have made the dispute look contradictory. A federal judge in California struck down a separate designation in August, finding that the government had punished Anthropic for its criticism and lacked a basis to say the company would sabotage its model. The Associated Press reported that ruling came under a different authority. The D.C. Circuit said the procurement statute before it used a broader definition and gave that appeals court exclusive jurisdiction over actions taken under it. One court victory therefore did not decide the other case.

Anthropic also lost its First Amendment argument in the D.C. Circuit. The majority agreed that the company's advocacy for AI safeguards was protected speech and that exclusion was an adverse action. It rejected the claimed connection between them, finding that the department acted after Anthropic refused the all lawful uses contract term, rather than because Amodei had publicly supported tighter AI rules. That distinction allowed the court to treat the fight as a failed negotiation over product requirements.

Judge Henderson's dissent saw the statute differently. She read its references to sabotage, malicious insertion and surveillance as language aimed at hostile or deceptive interference, not a supplier openly enforcing agreed restrictions. Congress passed the law after warnings about foreign states and other bad actors compromising government technology, she wrote. Applying it to a domestic vendor's disclosed use policy gives agencies a way to attach a national-security label when a contractor will not change product behavior.

The holding is tied to unusual military facts, even if its logic reaches beyond Anthropic. The majority did not rule that every model refusal is a supply-chain defect, nor did it give commercial buyers a general power to override a provider's safety rules. It decided that this department could invoke this statute after documented refusals and a live contract impasse involving military operations. Teams assessing the ruling should keep those limits attached to it.

AI contracts now have to describe behavior, not just access

Enterprise AI agreements often specify which model a customer receives and where data is processed. Some also promise an outage repair time. This case shows why those terms may be incomplete when the product's behavior is partly defined by training and policy. Two copies can be online and authenticated while giving different answers to the same operational request. The court's record traces exactly that progression: commercial Claude refused some government tasks, Claude Gov permitted more of them, and Anthropic retained two final restrictions.

A buyer integrating a model into a sensitive workflow now has reason to test refusal behavior before each upgrade and record which prompts are required for the system's job. The opinion describes similar prompts producing different answers and rejects advance testing as a complete solution. Contracts can state what happens when a model declines an allowed request and whether a pinned version remains supported. They can name who approves a switch to another provider. A human route for disputed cases matters too. These measures would not settle the policy question, but they would reveal a mismatch before it reaches an active operation.

Providers still have to encode a broad promise to support every lawful use into model behavior and system prompts. Legality and reliability are separate tests. Anthropic's position was that some conduct may be legal yet unsafe for current models. The department's position, accepted by the majority, was that a private supplier could not retain a technical veto over military decisions. The contract failed because neither side would yield on who controlled that boundary.

Anthropic said it was considering further review, which could mean asking the full D.C. Circuit to rehear the case or petitioning the Supreme Court. The separate California judgment has its own path. The department's 180-day outside window for removing Claude has passed, so evidence of what replaced it in affected systems will matter more than another transition promise. The most revealing document will be the next AI contract: whether it defines measurable refusal and failover behavior, or relies again on a demand for all lawful uses. That wording will show whether this decision remains a narrow military procurement fight or becomes a template for buying models whose policies arrive inside the product.

We reviewed this

  1. Speech — our honest review
  2. actors — our honest review

Sources

  1. Anthropic PBC v. United States Department of War (D.C. Circuit opinion)
  2. U.S. appeals court upholds designation of Anthropic as supply chain risk
  3. Statement from Dario Amodei on our discussions with the Department of War
  4. Statement on the comments from Secretary of War Pete Hegseth
  5. Judge says Pentagon's measures against Anthropic were 'illegal and baseless'
  6. US appeals court upholds Pentagon's supply chain risk label on Anthropic