The AI lab that said "no" to military surveillance just lost the right to say no at all.

The Summary

The Signal

The U.S. Court of Appeals for the District of Columbia Circuit just handed the Pentagon something it desperately wanted: the power to blacklist AI companies not for what their models do, but for what they won't do. Judge Gregory G. Katsas wrote that the Defense Department "reasonably feared" Anthropic might tweak Claude to block national security functions the Pentagon deems necessary. Translation: if you build safety limits into your model that conflict with military objectives, you're now a supply chain risk.

This isn't about Anthropic shipping compromised code or leaking data to adversaries. It's about Dario Amodei drawing a line. When the Pentagon wanted Claude for mass surveillance and autonomous weapons, Anthropic said no. That refusal, in February, triggered Trump and Hegseth to label the company a national security threat. Now a federal court has validated that labeling.

"The Department reasonably feared that Anthropic might manipulate Claude's design to prevent it from performing national-security functions."

Here's what makes this ruling especially sharp: it sets up a framework where AI safety features are reframed as potential sabotage. If your model won't help target drone strikes or sift through surveillance feeds, the government can argue you might be hiding that limitation on purpose. Intent doesn't matter. Capability does. And if you've intentionally limited capability for ethical reasons, you're suspect.

Anthropic had argued multiple violations of its rights, but the 2-1 panel sided with the Trump administration. The dissenting judge's opinion wasn't detailed in the coverage, but the majority opinion is clear: national security concerns trump corporate objections when the Pentagon decides your refusal to cooperate is itself a risk.

Meanwhile, a separate California case found the Pentagon illegally retaliated against Anthropic for criticizing military AI use. So Anthropic is simultaneously winning on First Amendment grounds and losing on national security grounds. The government can't punish you for speech, but it can blacklist you for building models that won't do what it wants. The contradiction is the point. Legal, as long as it's framed as supply chain risk.

Key tensions this ruling exposes:

  • AI companies building safety guardrails vs. governments demanding unfettered access
  • Corporate ethics policies vs. national security mandates
  • Free speech protections vs. procurement blacklisting
  • The line between principled refusal and suspected sabotage

The Implication

Every AI lab now has a choice: build for the Pentagon's definition of national security, or risk getting labeled a threat for saying no. OpenAI, Google, Meta, and every other foundation model company just watched Anthropic get legally designated as risky for refusing military use cases. The court didn't rule on whether Anthropic's concerns about surveillance and autonomous weapons were valid. It ruled that those concerns don't override the Pentagon's authority to define supply chain risk.

If you're building agents meant to operate in regulated industries, government contracts, or critical infrastructure, this ruling is your new compliance landscape. Safety isn't just a feature anymore. It's a potential liability if it conflicts with what a federal agency decides it needs your model to do. The question isn't whether your AI works. It's whether it works the way the government wants, even if you built it not to.

Sources

Wired | Fast Company Tech