A federal appeals court ruled on September 25, 2026, upholding the Pentagon's earlier designation of Anthropic — the San Francisco-based AI company behind the Claude family of large language models — as a supply chain risk, according to reporting published by CNBC and flagged late Friday on Hacker News. The decision affirms a Defense Department determination that had been contested by Anthropic, which argued the designation was procedurally flawed and factually unsupported.
The ruling does not accuse Anthropic of espionage or deliberate misconduct. Rather, the court found that the Pentagon acted within its statutory authority under supply chain risk management provisions when it flagged the company based on factors including its investment structure, its reliance on foreign-sourced hardware and cloud infrastructure, and the potential for adversarial access to model weights or training pipelines. Anthropic had raised roughly $7.7 billion in outside investment as of mid-2026, with significant stakes held by Amazon and Saudi Arabia's sovereign wealth-linked entities — both relationships the DoD apparently cited in its review.
The practical effect of the designation is that federal agencies and their contractors face additional restrictions or review requirements when procuring or deploying Anthropic's models in sensitive contexts. It does not constitute a ban, but it creates a compliance burden comparable to what companies on the Entity List experience in commercial export contexts.
Anthropic issued a statement calling the ruling "deeply mistaken" and said it was evaluating further legal options, including a potential appeal to the full circuit or a petition for certiorari to the Supreme Court. The company did not specify a timeline.
What is less visible in mainstream coverage of this story is the structural reason supply chain designation matters beyond any single vendor: federal supply chain risk management frameworks, particularly those codified under Section 1654 of the FY2019 NDAA, give the DoD and DHS broad discretionary authority to act on AI and software providers without the same transparency requirements that govern hardware-focused actions like those targeting Huawei or SMIC. There is no public scoring rubric, no mandatory disclosure of the specific evidence used, and no guaranteed pathway for a designated company to review the classified portions of the case against it. That opacity means enterprises and institutions that have built operational dependencies on a given AI platform can find themselves holding a stranded asset — procurement contracts voided, integrations suspended, and compliance exposure created — with little advance warning. For organizations in critical infrastructure sectors that have begun embedding AI APIs into operational workflows, this ruling is a concrete reminder that those dependencies carry a category of regulatory risk that traditional vendor due-diligence processes were not designed to surface. Our AI vendor risk overview covers how to evaluate these exposure points before they become compliance events.
The case is expected to draw amicus attention from other major AI developers, several of which are also partially capitalized by foreign sovereign or quasi-sovereign investment vehicles. Legal analysts cited by CNBC noted the ruling could accelerate pressure on Congress to clarify the evidentiary standards the DoD must meet before issuing supply chain risk designations for software and model-based services — a category the original 2019 legislation did not anticipate with any precision.





