A grey concrete corridor receding into fluorescent shadow, a heavy metal double door on the left standing ajar with warm amber light showing through the gap

FASCA Was Built for Huawei. The D.C. Circuit Used It on Anthropic.

/ Maxim Starkweather / 7 min read

On September 25, a federal appeals court handed the Pentagon a legal framework it should not have. The U.S. Court of Appeals for the D.C. Circuit ruled 2-1 to uphold the Department of Defense’s designation of Anthropic as a supply chain risk under the Federal Acquisition Supply Chain Security Act — the law Congress passed in 2018 to protect military procurement from foreign adversary infiltration. The majority’s key principle: “what Anthropic does, not why Anthropic does it.” In plain terms: it doesn’t matter that Anthropic built safety constraints into Claude for principled reasons. What matters is that Claude sometimes refuses. That refusal is now, legally, a supply chain defect.

This is not the ruling the statute was designed to produce. FASCA was built for Huawei. The D.C. Circuit applied it to an American AI company with published safety policies. That gap between intent and application is the important thing to understand, because the logic doesn’t stop at Anthropic.

FASCA Was Designed to Stop Foreign Sabotage

The Federal Acquisition Supply Chain Security Act was enacted in 2018 at the height of concern over Chinese telecommunications hardware in critical infrastructure. The target was clear: foreign state actors embedding backdoors, kill switches, or surveillance capabilities into components that American agencies had purchased in good faith. Huawei and ZTE were the named concerns. The statute gave the Secretary of Defense authority to designate a company as a supply chain risk and immediately bar its products from all Pentagon procurement — and, critically, from any private sector work on Pentagon contracts as well. Defense contractors building anything for the military had to comply. The mechanism was total and swift by design: when a foreign adversary might be listening, you don’t negotiate a transition period.

Anthropic is not a foreign adversary. It is a U.S. company that won a $200 million DOD contract in 2024 and built an AI system and then, as a condition of deploying it, decided Claude should not help design fully autonomous weapons or conduct mass surveillance of American citizens. When Defense Secretary Pete Hegseth demanded in early 2026 that Anthropic accept “all lawful uses” of Claude without restriction, Anthropic refused. The DOD issued a FASCA designation on March 4, 2026. Trump subsequently ordered a government-wide phase-out of Claude, with the Pentagon receiving a six-month transition period for systems already embedded in classified operations. Anthropic — reportedly the first domestic AI company to receive this designation — filed suit the same month, arguing the action violated its First Amendment rights and that FASCA was never intended for this application.

A balance scale tipping under the weight of military procurement documents against a glowing circuit form, in a cold archival room

The dissent in last week’s ruling agrees. Judge Karen LeCraft Henderson wrote that Congress enacted FASCA “specifically to protect against sabotage by malignant foreign powers” — not to penalize a domestic company for enforcing its own product restrictions. That reading is obviously correct as a matter of statutory history. The majority reached a different conclusion.

What the Majority Actually Said

Judge Gregory Katsas, writing for the majority, framed the Pentagon’s concern in the clearest possible terms: the Secretary had raised “the deeply sobering prospect of overly constrained AI models shutting down unexpectedly” and thereby compromising military operations. The court acknowledged Anthropic likely has “noble intentions” but held that intent is irrelevant to the supply chain risk analysis. What the government cares about is operational predictability. Claude might refuse a task. That possibility — not a security backdoor, not evidence of compromise, not any relationship to a foreign state — is the risk.

There is a real military planning problem buried in this reasoning. If you are building an AI system into battlefield logistics or medical triage, you need to know it will operate under the conditions you’ve specified. An AI that may decline certain tasks introduces uncertainty. The majority is not wrong that this is a procurement concern. Defense contracting has long required vendors to demonstrate reliability against adversarial conditions; an AI that opts out of certain categories of use is, under that lens, a system with known operational gaps.

Two gavels casting shadows across a surface split between California sun and D.C. grey, the shadows overlapping

But the majority’s resolution of that concern — applying FASCA — creates a framework with no principled stopping point. FASCA was not designed to resolve procurement disputes about capability specifications. It was designed to freeze out bad actors. Collapsing the distinction between “this system won’t do what we want” and “this system has been compromised by a hostile foreign power” doesn’t just affect Anthropic. It means any AI safety restriction that makes a model operationally constrained for military purposes is a potential FASCA trigger. The statute becomes a procurement negotiating tool, available whenever a company declines to remove a guardrail the Pentagon wants removed.

Two Rulings, One Very Confused Legal Landscape

The D.C. Circuit’s ruling lands while a directly contradicting decision is in force in a parallel case. In August 2026, U.S. District Judge Rita Lin in San Francisco ruled that the government’s broader order — the Trump administration’s government-wide directive to cease using Claude — was unconstitutional on three independent grounds: First Amendment retaliation, arbitrary and capricious administrative action, and Fifth Amendment due process violations. Lin found the government’s posture “based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government’s weapons policies,” and stated plainly that “the empty invocation of national security is not a blank check to punish and retaliate against government critics.”

Lin’s ruling addressed the broader government-wide ban; the D.C. Circuit addressed the narrower FASCA designation specifically. The practical result of the current split: non-Pentagon federal agencies can still use Claude — Lin’s ruling remains in effect. Pentagon personnel and the defense contractors who work for them cannot. The same AI system is simultaneously lawful and unlawful depending on which agency is doing the purchasing and which courtroom you happen to be standing in.

What makes this split genuinely unstable is that the legal theories don’t actually conflict — they address different questions. Lin found the government’s motivation was retaliatory. The D.C. Circuit held that even if motivation was improper, the operational concern about Claude’s restrictions gives the Pentagon adequate FASCA grounds. Neither court has settled what FASCA actually requires in a case like this. That unresolved question is now almost certainly headed to either the full D.C. Circuit or the Supreme Court.

Legal experts watching the case were not surprised by the outcome but were explicit about why. Charlie Bullock of the Institute for Law & AI told Breaking Defense that this was “the expected outcome, given the terrible luck Anthropic had with the panel draw,” and predicted the company “would likely prevail before an en banc DC Circuit or SCOTUS if granted review.” Sean Timmons, a former JAG officer, noted that the full D.C. Circuit is “much more diverse and unpredictable” than the three-judge panel. In other words: the case result was shaped significantly by which three judges happened to be assigned. That is not a statement about the strength of the majority’s reasoning; it’s an acknowledgment that on hard questions of statutory interpretation, the outcome is sensitive to who decides.

What the Precedent Actually Does

Anthropic’s legal path is clear enough: rehearing by the same panel is available, en banc review of the full D.C. Circuit is the more promising option, and the Supreme Court is a ceiling if nothing else works. The practical timeline is long — months at minimum, more likely over a year. The designation continues to block Pentagon and defense contractor procurement throughout that period. A separate legal threat hangs in the background: the ruling has been described as damaging to Anthropic’s pre-IPO business prospects, which is a different kind of clock running simultaneously.

But the more important question is what this ruling does to every other AI company making safety commitments. The D.C. Circuit has now articulated a framework under which any documented AI safety restriction — one that prevents a model from performing tasks the military might want — can be characterized as an operational reliability concern sufficient to support a FASCA designation. The court specifically declined to weigh the reasons behind the restriction. Principled safety policy and deliberate incapacitation are legally equivalent under this reading.

Every AI lab that publishes an acceptable use policy, every model card that lists prohibited applications, every company that tells the government “our AI won’t help with that” has now been given a preview of the legal argument that can be deployed against them. Henderson’s dissent is the correct reading of FASCA’s scope, but it is the dissent, not the holding. Until the full court or the Supreme Court weighs in, the majority’s framework is the operative law in D.C. — the jurisdiction that handles most federal procurement disputes.

The structural incentive this creates is worth naming. Anthropic’s competitors in defense AI — Microsoft, Palantir, the vendors that integrate Claude’s rivals — do not have Claude’s restrictions. They passed FASCA’s implicit reliability test because they never declined. The majority’s framework doesn’t just punish a safety-forward company after the fact. It tells every AI company entering the defense market that publishing safety policies is a legal liability. That is the thing worth paying attention to, not the status of Anthropic’s contracts.

A grey concrete corridor receding into fluorescent shadow, a heavy metal double door on the left standing ajar with warm amber light showing through the gap

AI-generated editorial illustration · TemperatureZero · September 27, 2026

Keep reading the signal

Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.

Subscribe Free

Continue the archive

Latest BriefingsArticlesAbout Temperature Zero