On September 25, 2026, the U.S. Court of Appeals for the D.C. Circuit held in a 2-1 decision that the Pentagon’s labeling of Anthropic as “a supply chain risk to the national security” and immediate exclusion of Anthropic from the Pentagon’s supply chain on that basis were permissible under the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA). The Court’s majority also rejected Anthropic’s constitutional challenge and arguments under the Administrative Procedure Act. In an earlier insight, we noted how this was a functional debarment of Anthropic and could serve as the basis for future suspension and debarment actions for any federal contractors or subcontractors that incorporate Anthropic products into their IT infrastructure. Despite this ruling on the designation under 41 U.S.C. § 4713, which is stayed while Anthropic decides whether to seek en banc review, the separate 10 U.S.C. § 3252 designation remains under a permanent injunction under the Northern District of California ruling. Notably, the line that Anthropic drew, resulting in the supply chain risk designation, was itself something of a preemptive “kill switch” and the D.C. Circuit ruling comes amid White House and Congressional discussions on AI safety and regulations and various proposals for laws that would require an actual “kill switch”—though it’s unclear if such requirements are even technically feasible or would be effective.
This decision permits the federal government to exclude those companies with which it has philosophical disagreements from supplying goods and services to the Pentagon, based on stated national security justifications. In our earlier coverage (here, here, and here), we explained how the government’s decision to designate a domestic company as a supply chain risk, using authorities historically reserved for foreign adversaries, as retaliation for refusing to accept the government’s preferred contract terms, would fundamentally alter the bargaining position of every government contractor. If this decision stands, that reality has come to pass.
The Dispute
Although it was ultimately litigated as a dispute about whether the use of Anthropic in government systems poses a national security threat, the dispute began during contract negotiations about what Anthropic would and would not permit its AI tools to be used for. The Pentagon requested contractual authorization to use the AI tools for “all lawful uses,” with no exclusion of use for lethal autonomous warfare or mass surveillance. These permissions, according to Anthropic, were “incompatible with democratic values” and presented “serious, novel risks to our fundamental liberties,” and Anthropic could not agree to those concessions.
The Pentagon’s action does not come as a surprise. Last fall, Secretary Hegseth declared that “Our rules of engagement are designed to unleash American power, not shackle it.” The Secretary’s refrain of “maximum lethality, not tepid legality” and “violent effect, not politically correct,” crystallized the philosophical dispute between the Administration and many frontier AI companies.
The relevant law, 41 U.S.C. § 4713, gives the head of any executive agency the power to immediately exclude suppliers or companies from agency contracts and subcontracts, upon a determination that the supplier’s place in the supply chain poses a risk to the national security interests of the United States.
Here, the Pentagon argued that the AI models developed by Anthropic were built and trained to refuse to execute certain tasks, or to act in a manner that could cause a military operation to fail or otherwise harm national security interests.
While it is difficult to ignore the seemingly retaliatory context in which this designation was made, the national security context in which it arose likely played a significant role. Courts have always been very deferential to the executive in the national security context, and have been hesitant to second-guess an administration’s policy preferences despite the rejection of the presumption of regularity in some cases by the courts during this Administration, the D.C. Circuit appears to be continuing the wide deference to the Executive for “national security.”
AI Use in the Military and the “Kill Switch” Debate
Some of the disagreement that led to this litigation is about whether AI safety is a problem to be addressed at all, or whether the problem is instead those focused on “AI Safety”. The Anthropic CEO recently penned an essay calling for the AI industry to “slow the pace” at which the capabilities of AI models improve, amid myriad public concerns about AI going beyond the bounds of what its creators would like, including by hacking government websites and competitors’ databases. Concurrently the debate about how, and to what extent, Congress should regulate AI continues. Some lawmakers are calling for requirements for kill switches in models or other mechanisms to control models, which could create new cybersecurity vulnerabilities, concentrate control over models, and may even be infeasible. Anthropic’s safety approach has largely been focused on “alignment,” i.e., building in safety concerns into the training of the models themselves. But this approach is precisely what is being targeted as the “supply chain risk” in this designation, now upheld by the D.C. Circuit panel.
Through the litigation it is accepted that Anthropic has not created a kill switch that it would control in the model, but instead baked into the training guardrails it views as necessary for overall safety. Yet the Pentagon’s argument here is that the implementation of certain safeguards, even without “kill switches,” is precisely what can make an AI tool or model harmful to national security because it might not do what the Pentagon wants it to do. Effectively, the Pentagon views the embedded safety guardrails as an urgent national security risk. This could have the effect of incentivizing AI companies desiring lucrative federal contracts to make models less safe and less aligned to U.S. law or even human control. After its pivot away from Anthropic, the Pentagon shifted towards OpenAI. But amid a larger, and growing, concern about AI safety, it’s unclear how this no-guardrails approach may change over time. For example, OpenAI recently announced that it would not release its latest AI model for use because of “high levels of what the company saw as deception, or a willingness to mislead users about its actions. The model was also willing to go beyond the original scope of what it was asked to do, without checking back for directions or instructions.” It is not difficult to see the inherent concerns with incorporating such AI into military and weapons systems. Amid the larger debate about the safety of advancing AI capabilities, we may rapidly reach a point where unfettered demands of the Pentagon and the AI safety debate collide.
Contractor Compliance
Although contractors should certainly be prepared for direction or communication from the cognizant contracting officers, Anthropic’s active § 4713 designation creates potential compliance obligations under FAR clause 52.204-29 and FAR clause 52.204-30 (or Revolutionary FAR Overhaul 52.240-90 and 52.240-91), which can legally bind contractors to execute mandatory monitoring, internal supply chain inquiries, reporting, and mitigation protocols regarding any use of Anthropic’s technology. Here is what defense contractors should be doing in light of the D.C. Circuit Anthropic decision:
- Centralize and Scrutinize Certification Requests
- Contractors should be on the lookout for requests from contracting officers or primes asking to confirm that they are not using Anthropic products. It is crucial for contractors to be aware that some of these requests may trigger the False Statements Act (18 U.S.C. § 1001) and other civil or criminal exposure for false statements and that they should be careful and deliberate in their responses.
- Contractors should establish a single point of contact to receive, assess, and coordinate all Anthropic-related certification responses to ensure consistency.
- Contractors should consider pushing back on overbroad language. If a certification requests confirmation of company-wide non-use of Anthropic, the contractor should raise the discrepancy with their contracting officer, as the ban technically only applies to use “in the performance of” a covered contract.
- Evaluate Potential Enterprise-Wide and “Back Office” Exposure
- The prohibition under FAR 52.204-30 applies to using covered articles “as part of the performance of the contract.”
- It is not clear, however, that the exact boundary of “as part of the performance of the contract” will be implemented by the Pentagon.
- It is unclear if the ban extends to back-office systems (e.g., human resources or accounting software) powered by Anthropic that only indirectly support contract performance.
- It is also unclear how the ban affects third-party software tools used across a contractor’s enterprise that happen to have Anthropic products, such as Claude, embedded within.
- Due to this ambiguity, contractors may wish to consider the costs and other burdens to eliminate Anthropic products from their entire enterprise to mitigate risk.
- Prepare for Formal Contract Modifications
- The D.C. Circuit’s ruling validates the Secretary of Defense’s authority but does not automatically rewrite existing contracts.
- Contractors should anticipate an influx of formal contract modifications incorporating the Anthropic ban via FAR 52.204-30(b)(4).
- Recognize the Expanded Definition of “Supply Chain Risk”
- A significant takeaway from the ruling is the court’s broad interpretation of what constitutes a supply chain risk under FASCSA.
- The D.C. Circuit held that Anthropic embedding safety guardrails into its own AI models constituted “manipulating” the software even without malicious intent, therefore meeting the statutory definition of a risk. This broad reading, along with a low burden applied to the requirement that the government use less intrusive measures to mitigate the risk, could have wide ramifications.
- Contractors should be aware that, if the D.C. Circuit’s decision stands, the reasoning could be used by the U.S. Government to designate standard commercial features—such as a software-as-a-service provider’s ability to push routine software updates or cut off access for non-payment—as company-crippling “supply chain risks.”
What Contractors Should Do Now
The D.C. Circuit’s decision is significant and could chill contractors otherwise disposed to push back on requirements, but it is not the final word. The judgment is stayed while Anthropic considers rehearing, the separate § 3252 designation remains enjoined in California, and the two courts have now reached different results on the same facts under different statutes. For contractors, the practical point is that the § 4713 designation does not operate on its own: obligations generally turn on which clauses a given contract carries and what direction the contracting officer has issued in writing. Contractors that inventory where Anthropic tools touch contract performance, route certification requests through a single reviewer, and document the line between covered work and the rest of the enterprise will likely be well positioned however the litigation resolves.
Fluet’s Government Contracts and International Trade teams counsel defense contractors on exactly these questions: reviewing and responding to Anthropic-related certification requests from contracting officers and primes, assessing which supply-chain clauses a contract actually carries, scoping and documenting AI tool use in contract performance, preserving cost and schedule rights when removal is directed, and managing false-statement exposure. For more, see our series, Autonomy Decoded, or contact us.


