Two Courts, One Company, Two Answers
On August 27, a federal judge in San Francisco vacated one Pentagon designation of Anthropic, calling the government's measures unlawful retaliation for the company's stance on AI safety. Four weeks later, on September 25, a federal appeals court in Washington upheld a second, separate designation of the same company over the same underlying dispute.
Both rulings now stand at the same time. Congress routes the two statutes behind them to different courts, which is the only reason a company can lose and win on what looks like one fight. The result that carries weight for every AI vendor selling to government is the loss, because of how the majority got there.
What Anthropic Actually Refused
The Department of War wanted a contract clause covering any lawful use of Claude. Anthropic agreed to drop most of its usage limits during the negotiation but kept two: no use in autonomous weapons and no mass surveillance of Americans. Secretary Pete Hegseth gave Dario Amodei a deadline in late February. Anthropic refused publicly on February 26, and the Department issued a formal supply chain risk determination against Claude on March 3 under 41 U.S.C. Section 4713, the Federal Acquisition Supply Chain Security Act.
The order gave the Department 180 days to remove Anthropic products from its systems, a window that closed in early September. Anthropic's petitions to the D.C. Circuit argued the determination was arbitrary, unauthorized by statute, a due process violation and retaliation for protected speech. The panel rejected all four claims on September 25 by a 2 to 1 vote.
The Line the Case Turned On
The statute defines a supply chain risk as anything that lets a party sabotage, extract data from, or otherwise manipulate a covered product. Anthropic's defense rested on the word manipulate meaning something covert or hostile. The majority read it as ordinary control, and then pointed to Anthropic's own public statements as proof: its chief science officer has described embedding safety considerations directly into the model, and its public sector lead has called training the primary way the company shapes what Claude will and will not do.
Judge Gregory Katsas wrote for the majority that the statute turns on what Anthropic does, not why. He credited the Department's argument that overly constrained models could shut down unexpectedly during a real operation. Judge Karen LeCraft Henderson dissented, comparing the reading to a library rule against loud talk, music or otherwise disturbing others: read the wrong way, the rule would ban a whisper. Under her reading, a company that openly enforces usage limits it disclosed in advance is not manipulating anything.
Two Statutes, Two Courts, Two Results
The confusion in this case is structural. The Department used two different legal powers against Anthropic in the same dispute, and each one is reviewed by a different court under a different standard.
| Question | Section 3252 designation | Section 4713 designation |
|---|---|---|
| Court with jurisdiction | Federal district court, San Francisco | D.C. Circuit only |
| Result so far | Vacated, August 27, 2026 | Upheld, September 25, 2026 |
| Does intent matter | Yes, both courts agree | No, says the majority |
| Vote | Single judge order | 2 to 1, three-judge panel |
| What it covers | Government-wide directives | Department of War contracts only |
What Every Government-Facing AI Vendor Should Take From This
Reuters reported that Anthropic called the loss billions of dollars in lost business ahead of a planned public listing and said it respectfully disagrees while it weighs a full-court rehearing. The commercial stakes are real, but the legal reasoning matters more than the scoreboard for any company that has not yet been sued.
The part of the ruling that travels is this: Anthropic lost in part because it had clearly and publicly explained how it trains safety behavior into its models. That explanation, offered to build trust with buyers and regulators, became the evidence the majority used to find manipulation. A vendor negotiating AI use terms with a government buyer now has to treat its own safety-engineering explanations as a legal exposure question before a dispute ever starts, not only as a trust-building exercise for procurement officers and the public.
Read next: A Security Badge Told The Pentagon Nothing About What Grok Would Generate | A Safety Essay Became Evidence in an Antitrust Suit



