NextFin News - A federal appeals court ruled on Friday that the Pentagon may keep artificial-intelligence firm Anthropic on its national-security blacklist, handing the Trump administration a legal victory that clears the way for the Defense Department to bar the maker of Claude from its supply chain even as the company races toward what could be the largest initial public offering in history.
The U.S. Court of Appeals for the District of Columbia Circuit, in a 2-1 decision, denied Anthropic's petitions for review of the Department of War's determination that the company's products pose a "supply chain risk" under the Federal Acquisition Supply Chain Security Act of 2018. The ruling, decided September 25 in case No. 26-1049, leaves in place a label that has never before been applied to an American company and that blocks the Pentagon and its contractors from using Anthropic's models on defense work.
Circuit Judge Gregory Katsas wrote the opinion for the court; Circuit Judge Karen LeCraft Henderson dissented. The court rejected Anthropic's arguments that the exclusion was arbitrary, unauthorized by statute, and unconstitutional. "We deny the petitions for review. So ordered," the opinion concluded.
The dispute began in February 2026, when the Pentagon pressed Anthropic to remove safety guardrails that prevent its Claude models from being used for lethal autonomous weapons or mass surveillance of Americans. When Anthropic held its ground, Defense Secretary Pete Hegseth designated the company a supply chain risk and barred the department and its contractors from using its products. President Trump separately directed federal agencies to stop using Anthropic's technology.
Anthropic sued in March, arguing the designation was retaliation for its public stance on AI safety. In August, a different court — U.S. District Judge Rita Lin in the Northern District of California — permanently blocked a separate designation made under 10 U.S.C. § 3252, finding the government's actions "constituted unlawful retaliation in violation of the First Amendment" and that Anthropic "was denied the pre-deprivation process required under the Fifth Amendment."
But the D.C. Circuit's ruling turns on a different statute — 41 U.S.C. § 4713 — whose definition of "supply chain risk" is broader than the one Judge Lin applied. The appeals court noted that the two statutory definitions are not interchangeable, and its decision leaves the FASCSA designation in force even as the § 3252 designation remains enjoined. The result is a legal split that gives the Pentagon one working tool while Anthropic fights to keep another broken.
The Court's Reasoning: Contract, Not Speech
The D.C. Circuit's reasoning rests on a narrow but consequential reading of the statute. The court found the Department had "ample support" for concluding that integrating Claude into its information systems presented a statutorily covered national-security risk.
The key factual predicate: Anthropic encodes restrictions into Claude that prevent the model from performing certain tasks. "As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent," Katsas wrote. "On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users."
The court also pointed to a dispute over whether contractual prohibitions barred the use of Claude in an ongoing overseas military operation, "leaving the Department uncertain whether Claude would perform as needed and intended."
On the constitutional claims, the court drew a line between speech and contract. Anthropic's due-process claim failed because the department promptly notified the company of the exclusion and its rationale, then gave it a fair opportunity to contest it. The First Amendment claim failed because the exclusion was based on Anthropic's "refusal to assent to a contract term that the Department deemed essential, not based on the company's support for greater governmental regulation of AI technology."
That distinction — refusal to sign a term versus punishment for speech — is the fulcrum of the decision. It allows the government to exclude a vendor for declining a contract condition without having to prove that the vendor's public advocacy was the motivating factor. For every AI company that has built its brand on safety guardrails, that is the new line in the sand.
The decision also closed a procedural loop. On April 8, the same panel denied Anthropic's emergency stay request while expediting review on the merits, writing that the "equitable balance here cuts in favor of the government." The judges acknowledged Anthropic "will likely suffer some irreparable harm," but weighed that against "judicial management of how, and through whom, the Department of Defense secures vital AI technology during an active military conflict." Five months later, the merits matched the emergency calculus.
The Dissent: A Statutory, Not Constitutional, Fight
Judge Henderson's dissent turned on the statutory definition of "supply chain risk." She argued the question "turns on whether Anthropic falls within the statute's definition," signaling that the majority's reading stretches the term beyond what Congress wrote.
Yet even her dissent closed with deference: "In our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution." That concession matters. It means the disagreement is not over whether the executive branch deserves latitude on national security — both judges agreed it does — but over whether this particular statute reaches this particular conduct.
The split signals where a future Supreme Court battle would be fought. The majority grounded its decision in contract and process; the dissent grounded hers in statutory text. If the case reaches the high court, the statutory question — not the constitutional one — is where the war will be won or lost.
The Financial Stakes: Billions on the Line Ahead of an IPO
The timing is what makes this more than a procurement dispute. On June 1, 2026, Anthropic confidentially submitted a draft registration statement on Form S-1 to the Securities and Exchange Commission for a proposed IPO of its common stock, giving itself "the option to go public after the SEC completes its review." The company has been widely reported to be targeting a listing as early as October 2026.
The valuation at stake is unprecedented. Anthropic raised $30 billion in February at a $380 billion post-money valuation, then closed a $65 billion Series H round on May 28 that lifted its valuation to $965 billion — ahead of OpenAI's most recent reported valuation. Its run-rate revenue crossed $47 billion in May, up from $14 billion as of mid-February, with Claude Code alone generating more than $2.5 billion in annual run-rate revenue.
The blacklist threatens that narrative. In court filings, Anthropic executives warned the designation could cut 2026 revenue by "multiple billions of dollars." CFO Krishna Rao said the company expects an immediate loss of more than $150 million in annual recurring revenue tied to existing and expected Defense Department contracts, and that the public-sector business — projected at more than half a billion dollars in 2026 revenue — could "shrink substantially or disappear altogether."
"Across Anthropic's entire business, and adjusting for how likely any given customer is to take a maximal reading, the government's actions could reduce Anthropic's 2026 revenue by multiple billions of dollars," Rao said in the filing.
More than 100 enterprise customers reached out to Anthropic about the designation, according to the filing. The company argued the label impugns its integrity and reputation "as a trusted partner," with a "real but incalculable effect on sales to non-governmental customers." For a company about to ask public investors to underwrite a near-trillion-dollar valuation, that reputational overhang is the part of the ruling that cannot be quantified in a spreadsheet.
The Second-Order Effect: Who Wins When One AI Champion Is Grounded
The immediate loser is Anthropic. The second-order winners are its rivals. Hours after the Pentagon moved to blacklist Anthropic in February, OpenAI announced a deal to deploy its models across the Defense Department's networks. In May, the Pentagon said it had reached agreements with seven AI companies — SpaceX, OpenAI, Google, NVIDIA, Reflection, Microsoft and Amazon Web Services — to integrate their capabilities into the classified Impact Level 6 and 7 environments. Anthropic was the only frontier-model developer conspicuously absent.
The strategic consequence is larger than any single contract. Defense AI procurement is sticky: once a model is embedded in classified workflows, switching costs are high. A competitor locked out during the embedding phase may never get back in, regardless of how its models perform on benchmarks. The blacklist does not just redirect this year's revenue; it redirects the reference architecture that defense contractors will build on for years.
That dynamic also reshapes the IPO calculus. Public-market investors price frontier AI on growth trajectory and total addressable market. A company excluded from the defense vertical — one of the few government-backed growth engines in AI — must convince investors that commercial demand alone can justify a near-trillion-dollar valuation. OpenAI, by contrast, enters its own eventual listing with a government footprint already in place.
Cyclical Setback or Structural Shift?
This is structural, not cyclical. A cyclical setback would be a contract delay, a budget cut, a procurement pause that reverses when the political wind shifts. What happened here is different: the government established a legal precedent that a vendor's refusal to relax safety guardrails can itself constitute a supply chain risk. That precedent survives the change of any single contract officer.
The mechanism is durable because it runs through contract law, not discretion. The court did not rule that Anthropic's guardrails are wrong; it ruled that the department may treat a vendor's refusal to assent to a contract term as a national-security risk. That is a rule other agencies can copy. The White House directive barring federal use of Anthropic's technology, and the parallel designation struck down in California, show how quickly the tool can multiply.
The one caveat: the precedent is bounded by process. The court emphasized that Anthropic received prompt notice and a fair opportunity to contest the exclusion. A future designation issued without that process would face a different due-process question. But within those guardrails, the executive branch now has a tested pathway to exclude vendors whose terms it dislikes.
The Counter-Thesis
The strongest argument against this reading is that it effectively nullifies the First Amendment protection the California court found. Judge Lin, in the Northern District of California, held that the designation "constituted unlawful retaliation in violation of the First Amendment." Two federal courts looking at the same conduct reached opposite constitutional conclusions. If the Supreme Court takes the case, Anthropic's best path is not the contract theory that failed in Washington — it is the retaliation theory that succeeded in San Francisco.
The counter-thesis has teeth because the timeline is awkward for the government. Anthropic had advocated for AI safety restrictions since its founding, and the designation came only after it refused to relax those restrictions for the Pentagon. A court that sees the contract term as a pretext will see the speech as the cause.
But the D.C. Circuit insulated itself from that attack by refusing to inquire into motive. It treated the exclusion as a contract consequence, not a speech penalty. That is a hard frame to crack on appeal — unless the Supreme Court is willing to look behind the contract language to the sequence of events.
The falsifying signal is specific: if the Supreme Court grants certiorari and reverses on the First Amendment retaliation theory, the structural reading above is wrong. Watch for a cert petition within the 90-day window after the September 25 judgment, and for signals from the justices on government-vendor speech rights. A reversal would restore the California rule nationwide and make guardrail-based exclusions far harder to defend.
What Comes Next
The short-term impact is concentrated on Anthropic: a company heading into an IPO with a government channel closed, a rival embedded in its place, and a valuation that now has to be justified without defense revenue. The medium-term impact spreads to every AI vendor that writes safety terms into its contracts: the government has a court-tested tool to respond.
The long-term question is whether this becomes the template for a broader realignment of the AI supply chain. If other agencies adopt the FASCSA pathway, the defense AI market could consolidate around vendors willing to sign unrestricted-use terms — OpenAI, Microsoft, Google, and the defense-native contractors already inside classified networks. Anthropic would be the cautionary case.
Base case: the designation stands, Anthropic lists at a discounted valuation, and the defense AI market consolidates around vendors with unrestricted contract terms. Upside case for Anthropic: the Supreme Court takes the case and reverses on retaliation grounds, restoring its government access and vindicating the guardrail model. Downside case: the FASCSA tool spreads beyond defense, other agencies issue parallel exclusions, and the revenue hit compounds ahead of the IPO.
What to watch: the cert petition window; any request for rehearing en banc at the D.C. Circuit; Anthropic's public S-1 filing and its treatment of the designation as a risk factor; and whether other agencies invoke FASCSA against other vendors.
The court did not decide whether Anthropic's guardrails were right. It decided that a company can be excluded for refusing to take them off — and that distinction will shape the AI industry long after this case is over.
Explore more exclusive insights at nextfin.ai.

