Two Courts, One Company, Two Answers

On August 27, a federal judge in San Francisco vacated one Pentagon designation of Anthropic, calling the government's measures unlawful retaliation for the company's stance on AI safety. Four weeks later, on September 25, a federal appeals court in Washington upheld a second, separate designation of the same company over the same underlying dispute.

Both rulings now stand at the same time. Congress routes the two statutes behind them to different courts, which is the only reason a company can lose and win on what looks like one fight. The result that carries weight for every AI vendor selling to government is the loss, because of how the majority got there.

What Anthropic Actually Refused

The Department of War wanted a contract clause covering any lawful use of Claude. Anthropic agreed to drop most of its usage limits during the negotiation but kept two: no use in autonomous weapons and no mass surveillance of Americans. Secretary Pete Hegseth gave Dario Amodei a deadline in late February. Anthropic refused publicly on February 26, and the Department issued a formal supply chain risk determination against Claude on March 3 under 41 U.S.C. Section 4713, the Federal Acquisition Supply Chain Security Act.

The order gave the Department 180 days to remove Anthropic products from its systems, a window that closed in early September. Anthropic's petitions to the D.C. Circuit argued the determination was arbitrary, unauthorized by statute, a due process violation and retaliation for protected speech. The panel rejected all four claims on September 25 by a 2 to 1 vote.

The Line the Case Turned On

The statute defines a supply chain risk as anything that lets a party sabotage, extract data from, or otherwise manipulate a covered product. Anthropic's defense rested on the word manipulate meaning something covert or hostile. The majority read it as ordinary control, and then pointed to Anthropic's own public statements as proof: its chief science officer has described embedding safety considerations directly into the model, and its public sector lead has called training the primary way the company shapes what Claude will and will not do.

Judge Gregory Katsas wrote for the majority that the statute turns on what Anthropic does, not why. He credited the Department's argument that overly constrained models could shut down unexpectedly during a real operation. Judge Karen LeCraft Henderson dissented, comparing the reading to a library rule against loud talk, music or otherwise disturbing others: read the wrong way, the rule would ban a whisper. Under her reading, a company that openly enforces usage limits it disclosed in advance is not manipulating anything.

Two Statutes, Two Courts, Two Results

The confusion in this case is structural. The Department used two different legal powers against Anthropic in the same dispute, and each one is reviewed by a different court under a different standard.

QuestionSection 3252 designationSection 4713 designation
Court with jurisdictionFederal district court, San FranciscoD.C. Circuit only
Result so farVacated, August 27, 2026Upheld, September 25, 2026
Does intent matterYes, both courts agreeNo, says the majority
VoteSingle judge order2 to 1, three-judge panel
What it coversGovernment-wide directivesDepartment of War contracts only

What Every Government-Facing AI Vendor Should Take From This

Reuters reported that Anthropic called the loss billions of dollars in lost business ahead of a planned public listing and said it respectfully disagrees while it weighs a full-court rehearing. The commercial stakes are real, but the legal reasoning matters more than the scoreboard for any company that has not yet been sued.

The part of the ruling that travels is this: Anthropic lost in part because it had clearly and publicly explained how it trains safety behavior into its models. That explanation, offered to build trust with buyers and regulators, became the evidence the majority used to find manipulation. A vendor negotiating AI use terms with a government buyer now has to treat its own safety-engineering explanations as a legal exposure question before a dispute ever starts, not only as a trust-building exercise for procurement officers and the public.