A US appeals court today approved the Trump administration’s blacklisting of Anthropic technology. Judges decided the US had authority to blacklist Anthropic for withholding certain AI features even if Anthropic had no malicious intent.
In a 2-1 ruling issued by the US Court of Appeals for the District of Columbia Circuit, a panel of judges said the “case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology.” The US “raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force,” the ruling said.
Trump and Defense Secretary Pete Hegseth “must determine how best to balance the competing risks,” the court said. “In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution. Accordingly, we deny the petitions for review.” The same court previously denied Anthropic’s emergency motion for a stay in April.
The two judges who ruled against Anthropic were both appointed by Trump and served in the first Trump administration. Judge Gregory Katsas was previously deputy counsel to the president, and Judge Neomi Rao served in the Trump administration’s Office of Management and Budget.
Two courts, two different decisions
Anthropic sued the Trump administration in March after Trump and Hegseth ordered federal agencies to stop using Anthropic’s products and banned defense contractors from doing any business with Anthropic. Anthropic may appeal today’s ruling, either by asking for an en banc review with all of the appeals court judges or by petitioning the Supreme Court.
“We respectfully disagree with the court’s decision,” an Anthropic spokesperson told CNBC. “Another federal court has already held the government’s parallel designation unlawful. We remain confident in our position and are considering all options, including further review.” Despite the ongoing legal battle, Commerce Secretary Howard Lutnick recently said the Trump administration and Anthropic have patched up their relationship and are “in tune.”
Two courts have been reviewing the US blacklisting of Anthropic. A judge in US District Court for the Northern District of California ruled last month that the action was illegal because Anthropic does not meet the definition of a supply-chain risk, which is limited to “the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert… a covered system.”
Today’s ruling from the DC Circuit did not dispute the district court’s primary finding. But it said the district court was tasked with reviewing whether the decision was allowed under one law while the appeals court has exclusive jurisdiction to review the decision under a different, more permissive grant of authority.
The district court decision found a violation of 10 U.S.C. § 3252, in which supply chain risks are limited to malicious actions by adversaries. The appeals court reviewed the blacklisting under 41 U.S.C. § 4713, which doesn’t have the same restrictions. Notably, Congress gave the DC Circuit appeals court exclusive jurisdiction to review procurement actions taken under Section 4713 designations.
Bad motive not required
Today’s ruling said:
We have no quarrel with the Northern District’s conclusion that use of the critical noun adversary, combined with the sinister connotation fairly pervading the string of sabotage, maliciously introduce, and otherwise subvert, indicate that bad motive is required to support a designation under section 3252. Likewise, we have no quarrel with the Northern District’s conclusion that Anthropic has acted with no such bad motive in its dealings with the Department. But as explained at length above, no such bad motive is required to support a designation under the much broader definition set forth in section 4713.
The US designated Anthropic as a supply chain risk under both 3252 and 4713. The latter statute defines “supply chain risk” as “the risk that any person may sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement” of covered technology products “so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of” those products or the information stored or transmitted on them, the court said.
The use of “any person” shows that the definition is not limited to adversaries or foreign entities, the court said. The court also pointed to the word “deny,” which it said applies to Anthropic preventing the US from using certain Claude features.
“In sum, we conclude that the Secretary’s concern about Anthropic disabling Claude from performing lawful actions requested by the Department qualifies as a ‘supply chain risk’ within the meaning of section 4713,” the court majority said. It also said “the Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary.”
Judge’s dissent
The dissenting vote was cast by Judge Karen Henderson, a George H.W. Bush appointee. Henderson disputed the majority’s reading of the definition in 4713, saying that when “viewed in their statutory context, the verbs at issue are all directed at deliberately impeding or eavesdropping on the ‘function, use, or operation’ of a covered article that has entered the federal supply chain.”
Congress “enacted the statute in response to calls from the US intelligence community for legislation to meet the threat of ‘[h]ostile nation state and other bad actors’ infiltrating the federal government’s information and technology systems through its supply chains,” Henderson wrote. She said the definition should not be interpreted to cover “a contractor’s honest and upfront enforcement of restrictions on a covered article’s use disfavored by the government.”
Anthropic alleged, and the district court judge in California agreed, that the Trump administration illegally retaliated against the company after it refused to drop restrictions on the use of its products for lethal autonomous warfare and mass surveillance of Americans.
The appeals court said that Anthropic “encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent. On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users. And recently, a dispute arose over whether the contractual prohibitions barred the use of Claude in an ongoing overseas military operation, leaving the Department uncertain whether Claude would perform as needed and intended.”
The case in the Northern District of California was presided over by Judge Rita Lin, a Biden appointee. Lin determined that the blacklisting violated the First Amendment. “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.







