The court did not rule that labs must abandon safeguards. But it validated a reading in which the Pentagon can exclude a supplier when restrictions embedded in the model create uncertainty about its operation in authorized military missions.
A September 25 decision by the District of Columbia Court of Appeals gave the Pentagon an important victory in its dispute with Anthropic. By a 2-1 vote, the court upheld a procurement action that excludes Claude from the military supply chain under the Federal Acquisition Supply Chain Security Act (FASCSA), after the company refused to accept a use clause for “all lawful purposes” without preserving two restrictions: fully autonomous weapons and mass domestic surveillance.
The scope of the decision goes beyond a specific contract because the majority accepted an argument that may become central in future government AI procurements: safeguards embedded by the supplier itself can be treated as operational risk when they prevent or make uncertain the execution of functions the government considers necessary.
At the same time, the ruling does not create a general obligation for companies to supply models without limits nor does it resolve the entire legal dispute between Anthropic and the government.

The line that emerges from the case, therefore, is not simply “safety versus the absence of safety.” The question becomes who ultimately controls the operational restrictions of a model used in military systems and how that control is defined in the contract and in the deployment architecture.
The court treated guardrails as a matter of operational availability
In the D.C. Circuit decision, the majority concluded that there was sufficient basis for the Department of Defense to consider that Claude's restrictions could affect the “functioning, use or operation” of government systems.
The court noted that Anthropic programs behaviors and refusals into successive versions of the model and that these limitations had already blocked tasks requested by government users.
This point shifts the discussion. For Anthropic, the two exceptions represent use limits defined by the supplier. For the Pentagon, when these limits are embedded in the model and can appear within larger applications, they also become a system reliability variable.
The majority accepted this second reading for purposes of FASCSA.

The decision also noted an important technical distinction. Anthropic stated that it cannot access, modify or turn off in real time models already delivered to classified environments. The court, however, understood that the ability to define guardrails and weights in future versions could still alter the behavior available to the Department over time.
This creates a relevant question for frontier AI contracts because these products are not static components. Models receive frequent updates, safety layers can change and new capabilities are released per version.
In a military system, the procurement question is no longer just whether the software works today and comes to include who controls its behavior tomorrow.
The case does not prohibit suppliers from maintaining restrictions
A broader reading of the ruling would be to say that labs now must choose between guardrails and military contracts. The available evidence does not support that conclusion.
In February, OpenAI announced an agreement with the Department of Defense for use in classified environments while maintaining three declared red lines, including mass domestic surveillance and independent control of autonomous weapons.
According to the company, these limitations were implemented through a combination of contractual clauses, cloud-only deployment, maintenance of the safety stack and participation by authorized personnel from OpenAI itself.
This arrangement shows a different path: instead of relying mainly on refusals encoded in the model's behavior, the supplier can try to turn use limits into contractual, architectural and operational controls that the government accepts as compatible with the mission.

That is precisely where the Anthropic case can alter market incentives.
Labs interested in military contracts tend to face more pressure to demonstrate, before signing, how their safety mechanisms behave in classified systems, who has authority to modify them, what happens during a model update and which restrictions are technically imposed by the supplier.
A decision favorable to the Pentagon does not end the legal conflict
The picture remains more fragmented than the term “blacklist” suggests.
In August, a federal judge in California deemed illegal a parallel designation of Anthropic under another legal basis and blocked broader measures, including the attempt to prevent military contractors from maintaining any business relationship with the company.
The decision dealt with a different statutory regime from the one now examined by the D.C. Circuit.
The majority on the appeals court made this distinction explicitly. In its view, the definition of “supply chain risk” used by FASCSA is broader and does not require that the supplier be an adversary or act with malicious intent.
The focus may be on the effect that the supplier's control exerts on the product's operation.
Judge Karen LeCraft Henderson dissented. In a dissenting opinion, she warned that this interpretation gives the government power to demand changes in a supplier's use policies at the risk of classifying it as a supply chain threat.
This disagreement matters because it shows that the problem is not only technical. It involves the boundary between the normal discretion of a public buyer and the use of national security instruments as a mechanism of contractual pressure.
The biggest effect may appear even before new lawsuits
In July 2025, the Department of Defense had awarded Anthropic, Google, OpenAI and xAI prototyping agreements with a ceiling of US$ 200 million to develop frontier AI capabilities in military and enterprise missions.
The official strategy was to broaden the government's experience with multiple suppliers, and not depend on a single lab.
With the dispute, this competition model gains a new layer.
Performance, price and safety will remain important, but military buyers may also assess the supplier's predictability: whether certain functions are blocked unilaterally, whether an update alters already integrated capabilities and whether the government has alternatives when a restriction comes into conflict with a mission.
For labs, the risk is asymmetric.
They remain free to define their own policies and restrictions. But when these restrictions become part of the technical behavior of a product integrated into defense systems, the D.C. Circuit decision gives the Pentagon more room to treat them as a matter of procurement and operational continuity, and not merely as the supplier's ethical preference.
This may change how future contracts are negotiated.
Guardrails are no longer just an internal feature of the model and become an element that must be translated into contractual language: who controls the restriction, when it can be changed, which functions become unavailable and who assumes the risk if the system's behavior changes.
What to watch now
Anthropic said it disagrees with the ruling and is evaluating its options, including seeking review by the full appeals court.
The next legal signal will be whether the company seeks that review or takes the dispute further.
In the market, however, the most important indicator will be contractual.
The next agreements between frontier labs and the government will show whether “lawful use” clauses come to be accompanied by more detailed definitions of guardrails, model updates, control of safety stacks and liability for functional unavailability.
If this happens, the Anthropic case will have produced an effect that goes beyond the exclusion of a supplier: the internal governance of models will come to formally occupy space in military procurement.
In this scenario, the ability to maintain safeguards does not disappear. But it comes to depend increasingly on how these safeguards are negotiated and implemented before the model enters the state's operational chain.



