Appeals court upholds Pentagon's Anthropic blacklist on a 2-1 vote

Share
Appeals court upholds Pentagon's Anthropic blacklist on a 2-1 vote

Anthropic lost the appeal it needed most on Friday. The same day, the price tag on the government's other AI gatekeeping job leaked — and it dwarfs anything Congress has budgeted.

A federal appeals court in Washington upheld the Pentagon's blacklisting of Anthropic in a 2-1 decision on Friday, rejecting the company's argument that the designation was arbitrary, unauthorized and unconstitutional. Circuit Judges Gregory Katsas and Neomi Rao found the Defense Department "had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk," with Judge Karen LeCraft Henderson dissenting. The designation, imposed in March after negotiations over how the military could use Claude collapsed, keeps the armed services from using Anthropic's models and blocks defense contractors from using them in Pentagon work. Anthropic said it "respectfully disagrees" and is considering further review — an en banc petition or the Supreme Court — pointing out that a federal judge in San Francisco already struck down a parallel designation under different law. Reuters reports the company says the blacklist has cost it billions of dollars in lost business and damaged its reputation heading into a highly anticipated IPO.

Read the two rulings together and the picture is stranger than a simple loss. San Francisco was about retaliation: Judge Rita Lin found the administration punished Anthropic for its public position on AI safety, which is a First Amendment problem. Friday's D.C. Circuit opinion is about procurement authority — whether the department had statutory room to call the integration of a contractor's model a supply-chain risk at all. Both can be true at once, which is the awkward part: the same blacklist can be unlawful as punishment and defensible as purchasing policy. What the appeals court did not say is that Claude is dangerous. It said the department had support for saying so — the deferential standard courts apply to agencies, and exactly the reasoning that keeps a designation alive long after the news cycle around it moves on. We covered the first ruling when it landed — Judge strikes down Pentagon's blacklist of Anthropic.


The NSA has told lawmakers it is spending billions of dollars this year testing and evaluating frontier AI models, NOTUS reports, citing two people familiar with classified intelligence estimates. No public budget document confirms the figure, the exact amount is unclear, and the Pentagon declined to discuss how the agency allocates resources for AI. The work sits with the NSA's Artificial Intelligence Security Center, which began stress-testing frontier models for national-security vulnerabilities after a run of incidents involving AI agents. For scale: the Congressional Budget Office priced a bipartisan civilian AI oversight bill at roughly $20 million a year, and a separate House reporting bill at $36 million over five years. The two cost drivers, per that reporting, are compute — running adversarial tests against systems that already consume enormous processing power — and people, where government pay cannot compete with packages reported in the hundreds of millions at frontier labs.

That ratio is the story. The national security apparatus is already spending, by these estimates, something two orders of magnitude larger than what Congress has penciled in for civilian AI oversight, and none of it is a line item anyone outside a classified briefing can audit. Lawmakers are reportedly reading the gap as evidence that comprehensive federal AI regulation would cost tens of billions a year, which is pushing the conversation toward a developer-assessment model: tax the labs to fund the audits of the labs. Anthropic and OpenAI have both signaled openness to more federal oversight without agreeing to pay for it, while Google, OpenAI and Anthropic have separately been negotiating their own industry standards body. The report also rests on anonymous sourcing and has been syndicated without independent confirmation, which is worth holding onto — but the direction of the number is not in dispute. We tracked the agency's own reorganisation around this work earlier this month — NSA splits itself into five mission centers — one just for AI.

What to watch: whether Anthropic petitions the D.C. Circuit for en banc review before its S-1 lands, and whether a blacklist a court has now partly blessed shows up in the risk factors of a company preparing to ask public markets for a trillion-dollar valuation.

Should a court be able to call a vendor a national security risk without ever saying its model is dangerous — and should the labs pay for the audits they are now welcoming? Tell us in the comments.

Sources: CNBC · Reuters · Politico · Reason · The Washington Sun (NOTUS) · Techmeme