Skip to content
← Back to Insights

Court Upholds Anthropic Exclusion: Making Safety Restrictions Predictable

AI Anthropic AI Safety Product Design News

TL;DR

A US appeals court backs excluding Claude from the defense supply chain in a 2-1 decision. The ruling addresses purchasing authority, not whether removing safeguards improves reliability. Product teams still need to distinguish intended refusals from mistakenly blocked tasks.

Court Upholds Anthropic Exclusion: Making Safety Restrictions Predictable

Anthropic has lost its challenge to exclusion from the defense supply chain: the US Court of Appeals for the District of Columbia Circuit backed the government in a 2-1 decision. An unresolved technical question remains: can removing a model’s usage restrictions reduce interruptions without increasing harmful outputs? The court decided whether the government acted within its authority, not how the two designs perform on identical tasks.Decision Reuters report

The decision is dated 2026-09-25, without a publication time. This Reuters version appeared at 12:08 EDT that day, or 00:08 on September 26 in Taipei. This article uses the Taipei date of September 26 and a reporting cutoff of 20:25. It covers a substantive previous-day decision still inside the 48-hour window; a report crossing midnight does not change the decision’s date.Decision date Publication time

The dispute arose from Anthropic’s refusal to remove Claude’s restrictions on lethal autonomous weapons and mass domestic surveillance. The majority accepted the department’s assessment that embedded restrictions and contractual disagreement could prevent military tasks from proceeding as expected. The dissent argued that openly and honestly enforcing usage restrictions should not qualify as the statutory supply-chain manipulation risk.Competing positions

The opinion also distinguishes two mechanisms. Anthropic denies it can access or modify a model after delivery to classified systems. Safety training nevertheless shapes the delivered version’s behavior, and subsequent versions can introduce new restrictions. That is different from a supplier being able to remotely switch off an already deployed model at any time.Delivery and training

The record includes Claude having refused US CDC prompts supporting infectious-disease prevention research. Anthropic said its engineers resolved the relevant problems with government users. This supports both the existence of refusals affecting legitimate work and the possibility of correcting them. It does not establish an overall false-refusal rate.Example and company response

Make refusal conditions part of the product promise

I favor retaining explicit usage boundaries while asking suppliers to explain how their models implement them. When a task falls outside the service’s scope, an early refusal lets the customer make other arrangements. When an accepted task stops halfway because the model misclassifies it, the customer faces an unpredictable interruption. Both situations might display the same refusal message, but they call for different product responses.

Extending the CDC example hypothetically, suppose a researcher submits an authorized disease-prevention document and the model stops organizing it because it misjudges its purpose. An appropriate correction should restore that task while checking that previously prohibited uses have not become possible. Counting only fewer refusals would mix correcting mistakes with weakening protections. Emphasizing firm refusals alone would not establish whether users can complete legitimate work.

This adds a practical responsibility to version delivery. Alongside capability improvements, suppliers should explain whether previously supported work has changed. If users cannot distinguish insufficient capability from a service boundary or a mistaken block, another disclaimer will not reduce retries. I favor actionable refusal explanations and testing confirmed false-refusal cases in subsequent versions. These are product recommendations, not requirements imposed by the court or newly announced Anthropic features.

The ruling maintains exclusion from the defense supply chain. A California court reached a different decision about a parallel measure under another law, so this result must not be described as a blanket prohibition on private use of Claude. Anthropic is considering further judicial review.Scope Parallel litigation This judgment supports the access restriction. Determining which safety design is more reliable still requires reporting both legitimate tasks blocked by mistake and prohibited uses allowed through.

The cover reuses this site’s earlier Anthropic–Pentagon illustration, not a photograph of this court proceeding. Downloading a news image failed because hostname resolution was unavailable.

Sources:

Get the latest insights

Join the newsletter to receive my latest articles on GenAI, AI Agents, and architecture.

No spam. Unsubscribe anytime.