Pete Hegseth and Trump got a dubious win today: a 2-1 panel of the DC Circuit found that the designation of Anthropic as a supply chain risk was not unlawful. It dismissed Anthropic’s challenge despite (1) a different court having found the exact opposite not that long ago; (2) being predicated on a statutory interpretation of “supply chain risk” that would effectively deem most AI models, and potentially all software, a supply chain risk; (3) having made this designation selectively and punitively; and (4) it resulting in Anthropic being disqualified from selling its model to any government agency, including those without same concern the DC Circuit credited the military with having.
To some extent the difference in the two decisions can be explained by the two different statutes at issue. Hegseth claimed the authority to make “supply chain risk” designations under two separate ones, 10 U.S.C. § 3252, which was at issue in the California challenge, and 41 U.S.C. § 4713, which was at issue in this case. Congress is also partly to blame for this mess, because in writing the statutory definition for “supply chain risk” in the 4713 statute it created more space for dubious interpretations like this one (“Whatever paradigmatic examples individual members of Congress may have had in mind, the statutory definition is not limited to “adversar[ies],” 10 U.S.C. § 3252(d)(4), and instead covers “any person,” which cannot refer only to foreign entities, 41 U.S.C. § 4713(k)(6).”). The statute also constrained how such designations could be challenged, sending them all directly to the DC Circuit, rather than a district court, which is why Anthropic’s challenge of the Hegseth action ended up in two separate cases.
But a bizarre situation has still resulted where one court has said that Anthropic’s First Amendment and due process rights had been violated, and another has now said they weren’t, even though the same action was involved with both. Anthropic argued that the California district court’s earlier decision should have been controlling, but the DC Circuit disagreed:
Anthropic contends that the Northern District’s decision is preclusive as well as persuasive. But because the Department’s designation authority is much broader under section 4713 than it is under section 3252, the issues flagged by Anthropic are not the same in both cases. So, for example, the Northern District’s determination that the section 3252 designation was arbitrary does not control our determination whether the section 4713 designation was arbitrary. Likewise, the Northern District’s determination of exigency under section 3252 does not control our determination of exigency under section 4713. In any event, Congress gave this Court exclusive jurisdiction to review procurement actions taken pursuant to section 4713 designations, see 41 U.S.C. § 1327(b)(1), and it specifically barred other courts from reviewing any other “action taken under” section 4713, see id. § 1327(a). That strict “allocation of jurisdiction” to this Court makes it inappropriate to constrain our review based on the Northern District’s judgment. Restatement (Second) of Judgments § 28 (1982); see Shaw v. State of Cal. Dep’t of Alcoholic Beverage Control, 788 F.2d 600, 607–09 (9th Cir. 1986); Lyons v. Westinghouse Elec. Corp., 222 F.2d 184, 188–89 (2d Cir. 1955) (L. Hand, J.).
Instead, because the DC Circuit read the statutory authority Hegseth drew from differently, apparently given its textual differences, it found Hegseth entitled to take the action that he did. But it is a dubious reading that would have broad implications the court did not address. In short, because Anthropic would still have control over its model, the court found that it could be considered to have the power to “manipulate” it, even after being deployed in government, and that made it a supply chain risk.
The Secretary reasonably concluded that removing Anthropic from the Department’s supply chain was necessary to protect national security by reducing supply chain risk to the Department’s information systems. Specifically, the Secretary credited a joint recommendation from two senior Department officials that Claude might be “subject to manipulation” by Anthropic “in such a manner as to inhibit the DoW’s use thereof.” App. 178. Likewise, he credited Under Secretary Michael’s conclusion that Anthropic might “manipulat[e]” the “design, integrity, and operation” of the Department’s Claude models, potentially causing “critical defense system[s] failing to engage” as intended by the Department. Id. at 182.
The record in this case amply supports the Secretary’s conclusion. To begin, it is undisputed that Anthropic can and does control how Claude responds—or fails to respond—to user prompts. Anthropic’s Chief Science Officer explained how the company “seek[s] to embed safety considerations directly into the model itself.” App. 8. Its CEO explained how such training gives the model an “identity, character, values, and personality” of its own, tethered to a “constitution” developed to impose “high-level principles and values” on Claude itself. Id. at 93–94. And the head of its public-sector business explained: “Model training is the primary mechanism through which Anthropic can influence the behavior of models used by the Department.” Id. at 276. Anthropic disclaims any ability to access or alter a model that has already been delivered to the Department, see id., despite the “technical measures” that it uses to police compliance with usage restrictions by private customers, id. at 8. Nonetheless, extant models reflect Claude’s “[c]onstitutional” training. Id. at 274–75. Moreover, Anthropic may encode additional restrictions each time it delivers any “new version of the model” to Department contractors. Id. at 276. Finally, it is undisputed that such model restrictions are vitally important to Anthropic, which describes them as lying “at the core of [its] mission.” Id. at 2.
The record also indicates that Anthropic’s model training is effective in enforcing usage restrictions and that, as a result, Claude has refused to answer legitimate queries from government users. Anthropic itself explained how early, commercially available versions of Claude frustrated Department and intelligence-community users by refusing prompts to evaluate classified materials. App. 255. Likewise, as Under Secretary Michael explained, the Department learned in 2025 that Claude had refused to process CDC prompts to support research to prevent the spread of infectious diseases. Id. at 212. Anthropic responds that these glitches reflected safety features appropriately built into models sold to private companies and were resolved after Anthropic engineers worked with the relevant government stakeholders. Id. at 255–56, 261–62. Perhaps so, but the point here is not that these model or usage restrictions were arbitrary; instead, it is that Anthropic’s model training does effectively enforce contractual usage restrictions.
Finally, the record reveals a recent, serious dispute about the scope of the contractual prohibitions on lethal autonomous warfare and mass domestic surveillance. Under Secretary Michael describes the incident in general but striking terms: [O]ne of Anthropic’s executives questioned the propriety of the potential use of their software for a sensitive military operation abroad despite that use being permitted under the existing Terms of Service. This led to alarm by the DoW and the prime contractor who provides Anthropic software, and raised material doubts as to whether they would cause their software to stop working or cause some other disastrous action that would put our warfighters[’] lives in danger. App. 181. Anthropic does not say much about this incident, except to suggest that it reflected a misunderstanding. Id. at 236–37. But regardless, Anthropic has made clear that it views the contractual prohibition on mass domestic surveillance as urgent to support “democratic values,” id. at 146, and the contractual prohibition on lethal autonomous warfare as urgent to avoid “put[ting] America’s warfighters and civilians at risk” of a catastrophic AI mistake, id. at 147. For its part, the Department has made clear that it views an “any lawful use” authorization to be critical to its “AI-first” strategic plan. Id. at 202, 206. With such diametrically opposed positions and with contractual limitations that are hardly self-defining, the prospect for disputes is apparent.
In sum, the Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary.
The nightmare hypo that the court credited was what if the military had some sensitive plans that depended on Claude’s use, which Anthropic then changed on the fly, which jeopardized the mission. But there are multiple problems with the court’s acceptance of the government’s argument here.
For one, if the court’s statutory interpretation about the power to affect the operation of delivered software were correct, then pretty much any software product, at least those still subject to vendor-supplied updates, could be considered supply chain risks, given that any update could make substantive changes. In any case, it would seem to mean that any AI model would be too risky for the government to use, because there is nothing unusual about Anthropic’s model-control architecture—to the extent Anthropic could still control its model, so could any other AI vendor potentially control theirs. Whether they would or not would depend on the contract restraining them, and the only thing potentially different about Anthropic is that it did not want to be contractually obligated to allow certain functions that Hegseth really wanted—functions that were ethically dubious at best and monstrously dangerous at worst.
But because that contractual reluctance upset Trump and Hegseth, they singled Anthropic out, alone, for negative treatment, turning their pique that “we can’t agree with Anthropic on how the software would need to be designed for us to be able to buy it” into “and because we can’t agree then NO ONE ELSE IN THE GOVERNMENT CAN EVER USE IT.” Per the DC Circuit, such an overbroad measure—after all, not every agency had the same concerns about changeability that the military might, yet Hegseth was deciding for them, too, whether they could use Claude, even when its architecture created no particular risk to them—and clearly punitive measure was perfectly fine because it implicated the implicit “national security” exception to the First Amendment the Founders apparently wrote into it in invisible ink.
To succeed on such a First Amendment retaliation claim, the plaintiff or petitioner must prove that (1) it engaged in protected speech, (2) the government took materially adverse action against it, and (3) the speech caused the materially adverse action. See Houston Cmty. Coll. Sys. v. Wilson, 595 U.S. 468, 477–79 (2022); Aref v. Lynch, 833 F.3d 242, 258 (D.C. Cir. 2016). Anthropic has satisfied the first and second prongs of this test, but not the third. The First Amendment squarely protects Anthropic’s advocacy regarding the safe and appropriate use of AI products. Moreover, the Department’s exclusion of Claude from its supply chain plainly qualifies as a materially adverse action. However, we can discern no causal connection between the two. Instead, the record makes clear that the Department removed Anthropic from its supply chain not because of its advocacy, but because Anthropic refused to agree to a contract term the Department deemed essential to national security.
Because Anthropic wouldn’t do the deal Hegseth wanted to do, he was therefore entitled to declare it too risky for anyone in the government to use, without it being seen as punishing Anthropic for its disinclination.
Anthropic points to various pungent statements in the Secretary’s February 27 social media post. Among other things, the Secretary denounced Anthropic’s “sanctimonious rhetoric,” “virtue-signaling,” and “Silicon Valley ideology.” App. 77. Such rhetoric seldom provides a sound basis for judging the lawfulness of federal executive action. See, e.g., Mullin v. Doe, 146 S. Ct. 2121, 2139 (2026); Trump v. Hawaii, 585 U.S. at 700–02. In any event, for all its flourishes, the Secretary’s social media post squarely addresses Anthropic’s refusal to provide the “all lawful uses” contractual authorization. He described Anthropic’s behavior as a “textbook case of how not to do business” with the Pentagon. App. 77 (emphasis added). He reiterated the Department’s demand for “full, unrestricted access to Anthropic’s models for every lawful purpose in defense of the Republic.” Id. (cleaned up). And he characterized Anthropic’s refusal to provide that access as imposing an unacceptable “veto power over the operational decisions of the United States military.” Id. The nub of this dispute was contractual, and the First Amendment did not require the Department to continue a contractual relationship that it viewed as creating a national-security risk.
Per the DC Circuit panel, the First Amendment takes a backseat to the President and his Secretary’s determination that a technology can ever be used by the government, no matter what.
This case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology. The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force. Both possibilities present obvious national-security concerns. But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution. Accordingly, we deny the petitions for review.
Which cannot possibly be right if the Bill of Rights is to have any meaning in limiting government power, and especially not on a record like this. Yet here we are.