On September 25, 2026, a divided panel of the U.S. Court of Appeals for the D.C. Circuit upheld the Pentagon's designation of Anthropic as a national security supply chain risk, ruling 2-1 that the Department "had ample support for its conclusion that the continued integration of Claude into the Department's information systems...presented a statutorily covered national-security risk". Read on its own, that looks like the government's institutions finally settling the year's biggest fight over an AI vendor's place inside American defense infrastructure. A label was challenged, a court agreed with it, the matter is closed.
The designation itself was not new in September. The Department of Defense had formally informed Anthropic in a statement on March 5, 2026 that the company and its products were "deemed a supply chain risk, effective immediately". That status followed a February 27, 2026 national security AI directive under which the General Services Administration removed Anthropic from the federal Multiple Award Schedule, the government's central procurement platform. MAS schedules accounted for over $52.5 billion in sales in fiscal 2025. The label was not a vague invocation of "national security" either: by Anthropic's own account in its court petition, the Department of War's notice specifically invoked 41 U.S.C. Section 4713, the Federal Acquisition Supply Chain Security Act of 2018, to exclude Anthropic's products from covered procurements, while Secretary Hegseth separately invoked a distinct designation authority under 41 U.S.C. Section 3252, the same statutory toolkit built to police foreign sabotage of federal supply chains.

It is worth slowing down on the "case closed" read. Eighteen months before the ruling, in July 2025, the Pentagon had awarded Anthropic a two-year prototype agreement with a $200 million ceiling, the kind of contract a company points to as proof the government trusts its product enough to build on it. The marketplace Anthropic was frozen out of in February 2026 processed more than 260 times that ceiling in a single fiscal year. The same company the Pentagon later called a supply chain risk is the company the Pentagon had, months earlier, been paying to wire its AI deeper into military systems.
The dependency underneath the label
The risk a "supply chain" designation describes is rarely about the product on the surface. It is about what feeds it, and who controls the feeding. The following month, in April 2026, Amazon committed $5 billion to Anthropic immediately with up to $20 billion more to come, while Anthropic committed to spend more than $100 billion on AWS technologies over the following decade: more than four times what it received, funneled back into a single hyperscaler's cloud and chip infrastructure. The government's own account of the risk was not that Claude answers questions badly, but that the company's dependencies were the exposure. Deepening the largest of those dependencies weeks after being told exactly that is the part of the story the September ruling does not resolve.

What the label actually cost
The stakes were not abstract to the company on the receiving end. Anthropic's own chief financial officer, Krishna Rao, told a federal court under oath in March 2026 that the government's actions could reduce the company's 2026 revenue "by multiple billions of dollars". That is a sworn estimate from the company itself, not a critic's guess, and it sits awkwardly next to a company simultaneously committing $100 billion of future spending to its largest cloud partner. Anthropic's finance chief was describing an existential threat to revenue in the same season its board was signing the decade's largest compute contract.
Two courts, one policy, opposite verdicts
The September ruling was not the only word on the underlying policy. A month earlier, in August 2026, a federal judge in California, Rita Lin, ruled that the same designation authority had been used to unlawfully retaliate against Anthropic for its public criticism of the government, writing that "the empty invocation of national security is not a blank check to punish and retaliate against government critics". Two federal courts examined the same designation authority within a month of each other and reached opposite readings of it. One found the government had "ample support" for a genuine security conclusion. The other found the same authority wielded as retaliation against a critic.
The honest objection
The strongest case for the Pentagon's position is that a defense department is not required to prove a smoking gun before protecting the systems Claude is wired into; a 2-1 appellate panel, applying the deferential standard courts owe national security judgments, found the Department had "ample support" for its conclusion. Courts do not lightly override that kind of institutional judgment, and they did not here.
That case is real, but it does not erase Judge Lin's finding a month earlier, in August 2026, that the same designation authority had been wielded as retaliation against a critic. The two rulings answer different legal questions: whether the designation was supported on the merits, and whether it was applied for retaliatory reasons. A designation can clear the first bar and still have failed the second in another court's eyes. Both things can be true of the same policy, decided a month apart, which is precisely why "the courts settled it" is the wrong takeaway from either ruling alone.
What India is building on the same fault line
The mechanism the D.C. Circuit just upheld, that a government can treat a vendor's concentrated compute dependency as a national security exposure in its own right, is not a uniquely American concern. India's national common AI compute capacity crossed 34,333 GPUs as of May 30, 2025 under the IndiaAI Mission, and by February 2026 officials were expanding an existing base of 38,000 GPUs toward a target of more than 58,000, a roughly 70 percent increase in nine months.

That buildout runs through a small number of empanelled private compute partners, and the government's own description of the hardware is direct: more than 38,000 GPUs onboarded through the AI compute portal are provided to Indian start-ups and academia at a subsidised rate, and "GPUs are highly advanced equipment and are primarily manufactured in one country". That is the same structural fact underlying the U.S. dispute: a fast-growing AI ecosystem resting on a narrow, geographically concentrated hardware base, with a handful of intermediary partners standing between the buyer and the supply. In at least one case that overlap is not just structural but corporate: SHI India, an AWS Partner Network partner empanelled under the IndiaAI Mission, announced in April 2026 that it was provisioning Amazon Web Services' own AI services, including Amazon SageMaker, to Indian organizations training models under the mission, the same hyperscaler that was, that same month, tying Anthropic's own U.S. compute to a decade-long AWS commitment. India is not Anthropic and the IndiaAI Mission is not a defense integration. But the American case has now tested two ideas in court: that concentrated compute dependency is itself a security exposure, and that whoever controls that designation authority can use it as either a safeguard or a weapon. Both apply just as easily to any government racing to build sovereign compute on somebody else's hardware. It is a lens worth having before the dependency is too large to unwind, not a verdict on India's program.
The Signal
Nothing about September 25 actually settled the argument over what Anthropic is to the U.S. government: a trusted contractor, a risk worth a blacklist, or both at once, depending on which court and which week you ask. What the ruling did settle is that the supply chain risk designation itself survives judicial review even after a different court called its use retaliatory, which makes it a durable tool for whoever holds the pen next. Anthropic's own answer, visible in its balance sheet rather than its court filings, was to bind itself more tightly to the single hyperscaler now underwriting its growth. Watch what the company does with its next major compute contract, not what it argues in its next brief. A company that believes the exposure is behind it does not need to hedge it. One that keeps concentrating it is telling you, with money instead of words, that the label was closer to the truth than the press release admitted.
Reporting basis: the D.C. Circuit's September 2026 ruling is per Breaking Defense's reporting; the Pentagon's March 2026 designation statement is per Fortune's reporting, quoting the Department directly. Anthropic's July 2025 prototype agreement and its April 2026 compute commitment with Amazon are both per Anthropic's own announcements. Judge Rita Lin's August 2026 ruling is per TechCrunch's reporting of the decision. Krishna Rao's revenue estimate is from his own sworn declaration in N.D. Cal. case No. 3:26-cv-01996, hosted by CourtListener's RECAP archive, and is a single-source figure from the company itself, not an independently verified number. The GSA Schedule sales figure and the February 2026 directive are per the General Services Administration's own release. India's compute capacity figures are per three separate press releases from the Ministry of Electronics and Information Technology, via the Press Information Bureau. The SHI India provisioning of AWS services under the IndiaAI Mission is per Amazon Web Services' own press release. The marketplace-to-contract ratio and the nine-month compute growth rate are The Signal's calculations from those figures.



