2.3 The August District Court Decision
On August 27, 2026, the Northern District of California granted summary judgment to Anthropic on its First Amendment and due-process claims and on key statutory and administrative-law claims. Judge Rita F. Lin concluded that the broad directives punished Anthropic for public criticism and extended far beyond a permissible decision not to buy the company's products. The court emphasized the mismatch between the government's asserted supply-chain rationale and its continued operational use of Claude, ongoing negotiations, and interest in later Anthropic models.3
The decision did not require the government to purchase or deploy Claude. It preserved the government's ordinary authority to choose vendors and transition to other systems. Its central holding was narrower: procurement discretion did not authorize sweeping penalties, government-wide exclusion, or retaliation untethered from the governing statutory scheme.
2.4 The September D.C. Circuit Decision
On September 25, 2026, a divided D.C. Circuit panel (Judge Katsas writing, joined by Judge Rao) upheld the Department's separate action under 41 U.S.C. § 4713. The majority accepted the Department's argument that Claude's embedded restrictions could inhibit system performance in mission-critical settings and that less intrusive measures were not reasonably available. It also held that any defect in advance notice was harmless because Anthropic received post-exclusion process and could not show prejudice. It rejected Anthropic's First Amendment theory on the ground that the exclusion followed the company's refusal to accept a contract term the Department considered essential, rather than its general advocacy for AI regulation.4
Judge Karen LeCraft Henderson dissented. She argued that the statutory definition of supply-chain risk did not fit an openly disclosed refusal to perform certain tasks and warned against expanding a statute aimed at sabotage or malicious manipulation into a general power to punish contractual disagreement. The dissent matters because it presses the line the majority chose not to draw: a system can be operationally unsuitable without its supplier being a saboteur. The majority did not dispute that Anthropic acted in good faith; it held that good faith was not required under the broader statutory definition.4
The decisions are in tension but are not formally identical. They involve different statutes, agency actions, records, and standards of review. The California court examined broad measures and evidence of punitive motive. The D.C. Circuit reviewed a Department-level procurement exclusion under a broader statutory definition and deferred to the Department's assessment of operational risk. Operationally, the Presidential and Secretary's directives, the § 3252 designation, and related punitive measures fell, while the Department-level exclusion under § 4713 remained in force. As of September 30, 2026, the public legal record therefore supports three propositions at once:
The military may choose not to rely on a model whose provider-imposed restrictions create operational uncertainty.
National-security language does not automatically validate government-wide retaliation or erase statutory and constitutional process.
Existing procurement law is poorly fitted to disputes in which model behavior, vendor values, contract terms, and software updates are inseparable.
3 Safeguards as Layered Governance Infrastructure
The earlier editions of this paper described safeguards as governance infrastructure rather than product preferences. That claim remains sound, but the 2026 litigation requires a more precise account of what the infrastructure contains.
A safeguard can exist at several layers: public law may prohibit a use; a contract may restrict it; the model may be trained to refuse it; a deployment wrapper may block tools or data; operators may require approval before action; monitoring may detect misuse; and courts or inspectors general may review the process. These layers are not interchangeable. A model refusal cannot substitute for a statute. A contract cannot prove technical reliability. A human approval box cannot create meaningful judgment if the operator lacks time, information, or authority.
NIST's AI Risk Management Framework treats governance as a cross-cutting function connected to mapping, measuring, and managing risk across the system lifecycle. The OECD AI Principles similarly connect human rights, transparency, robustness, security, safety, accountability, and human oversight. Both point toward continuous institutional practice rather than a one-time promise embedded in a model or contract.7, 8
A high-risk safeguard should be evaluated through four questions:
Authority: Who has lawful power to set, change, or override the boundary?
Evidence: What testing shows that the system can perform safely and reliably in the intended environment?
Accountability: Who records, reviews, and answers for the decision and its consequences?
Continuity: What happens if the model, vendor, policy, or operational requirement changes during deployment?
A boundary that cannot answer these questions may still be morally appealing or operationally convenient, but it is not yet durable governance.
4 Competing Claims of Authority
4.1 State Decision Sovereignty
The D.C. Circuit majority captured a legitimate national-security concern. A military organization cannot base mission-critical systems on a component whose behavior may change unpredictably or whose provider can define operational limits through each new version it delivers. The state must retain authority over mission objectives, rules of engagement, system architecture, model selection, and final action. It must also be able to replace a supplier without losing essential capability.
Decision sovereignty, however, does not mean unrestricted technical control. It means that the state owns the decision process and the responsibility for its design. That responsibility includes determining when a model is unfit, when a safeguard is legally required, when a human must intervene, and when a system should not be deployed.
4.2 Provider Integrity and Candor
Frontier-model providers possess technical knowledge that government users may not have. They may know that a model is unreliable in a class of tasks, vulnerable to prompt injection, sensitive to version changes, or unable to provide stable refusal behavior. Providers therefore have a duty of candor and a legitimate role in defining what they will sell. Their role does not become sovereign merely because their constraints are encoded in software.
The correct remedy for an unacceptable vendor limit is transparent non-selection, renegotiation, or replacement. It is not to pretend that removing the limit resolves the underlying reliability problem.
4.3 Rights and Democratic Accountability
The dispute also involved people who were not parties to the contract: civilians who might be subject to surveillance, people exposed to lethal force, military personnel relying on system outputs, contractors integrating models, and citizens whose institutions act in their name. Their interests cannot be represented solely by a vendor's usage policy or an agency's operational preference. Public law, legislative oversight, courts, inspectors general, and independent technical review are necessary because the affected public is otherwise absent from the procurement table.
5 Human Authorization and Operational Verification
The phrase human at the helm is useful only if it names an operational architecture. In lethal contexts, the United States' own autonomy directive requires systems to permit commanders and operators to exercise appropriate levels of human judgment over the use of force. International discussions under the Convention on Certain Conventional Weapons likewise continue to emphasize that human responsibility and accountability cannot be transferred to machines.9, 10
Meaningful human authorization requires more than a nominal click. The human decision-maker must have sufficient information, time, training, and authority to reject the system's recommendation. The system must expose uncertainty and material limitations. Logs must preserve what the model produced, what data it used, what tools were invoked, who authorized action, and which version of the model was running.
5.1 Verification Requirements
Version control: identify the exact model, weights, configuration, prompts, tools, and policy layer used in each deployment.
Predeployment evaluation: test the model in mission-relevant conditions, including refusal, hallucination, adversarial input, distribution shift, and loss of connectivity.
Runtime monitoring: detect anomalous behavior, policy violations, tool misuse, and degraded performance without relying solely on the provider.
Independent auditability: preserve records that authorized reviewers can examine without exposing unnecessary operational secrets.
Fail-safe behavior: define what the system does when uncertain, disconnected, contradicted, or outside validated conditions.
Offboarding and substitution: maintain tested alternatives so a contract or safeguard dispute does not become a crisis.
These requirements apply whether the disputed safeguard is imposed by the provider or the government. They transform an argument about trust into a system that can be tested.
6 A Governance Architecture for High Risk AI Procurement
The Anthropic case shows that high-risk AI contracts need a governance architecture before deployment. The following design draws on the four-part legitimacy test in §3.1—authority, evidence, accountability, and continuity—to procurement practice. It would preserve operational authority while preventing compressed-timeline coercion from becoming the default method of policy change.
Define prohibited and restricted uses before integration
Contracts should distinguish prohibited uses, uses requiring additional authorization, and permitted uses. Terms such as surveillance, tracking, autonomous engagement, and human authorization should have operational definitions rather than aspirational wording.
Separate legality from fitness
An “all lawful use” clause should never be treated as proof that a model is reliable, secure, or ethically acceptable for every lawful mission. Legal permission sets an outer boundary; evaluation determines operational fitness.
Create a joint change process
Material changes to model behavior, usage restrictions, deployment wrappers, or mission scope should trigger documented review by technical, operational, legal, civil-liberties, and safety personnel.
Preserve government controlled orchestration
The government should own routing, logging, action authorization, fallback behavior, and continuity plans. Supplier models should remain replaceable analytical components rather than single points of operational dependency.
Require reciprocal disclosure
Providers should disclose material limitations and updates. Government users should disclose intended use classes and integration conditions sufficiently for the provider to assess risk, subject to lawful protection of classified information.
Establish dispute and offboarding procedures
Contracts should specify escalation, emergency review, temporary restrictions, model substitution, data portability, and service continuity. A public ultimatum should not be the first mature dispute-resolution mechanism.
Provide independent oversight
For uses affecting lethal force or domestic civil liberties, independent review should examine both the model and the surrounding system. Oversight should include the authority to halt deployment when validated conditions are exceeded.
7 Principles for Durable Governance
The first seven principles follow from the case record and the governance analysis above; the eighth is a forward-looking prudential judgment.
1. Proportionality. Governance rigor should rise with the potential severity, scale, and irreversibility of harm.
2. Deliberation before crisis. Core use boundaries should be set through reviewable processes before operational dependence makes disagreement coercive.
3. Human responsibility. No system design should obscure the human and institutional responsibility for surveillance, targeting, or lethal action.
4. Technical verifiability. A safeguard that cannot be tested, monitored, and audited should not be treated as a reliable control.
5. Bounded authority. Neither vendor discretion nor executive procurement power should be treated as unlimited. Each must remain connected to law, evidence, and review.
6. Model replaceability. National security should not depend on one provider, one model, or one opaque policy layer.
7. Rights preservation. Civil liberties do not become less important because AI makes surveillance or force more scalable.
8. Norm stewardship. Leading AI states and companies create precedents that other actors may cite. Their processes should be designed for the world those precedents will help produce.
This paper analyzes public statements, judicial opinions, statutes, governance frameworks, and reported contract terms. It does not have access to classified operational details, the complete technical configuration of deployed models, or the full negotiation record. It therefore cannot determine whether any particular version of Claude was operationally suitable for a specific mission or whether a disputed use complied with classified rules of engagement.
The legal analysis is descriptive and conceptual, not legal advice. As of September 30, 2026, Anthropic had said it was considering further review of the D.C. Circuit decision; no petition for rehearing en banc had been publicly confirmed. The government had also filed a Ninth Circuit appeal in the parallel California litigation. The paper's recommendations do not depend on predicting which party will ultimately prevail. Their purpose is to reduce the chance that future disputes reach the same institutional impasse.
The paper also distinguishes model-level safeguards from full-system governance. A model refusal may reduce risk, but it cannot guarantee the behavior of a larger system that includes external tools, data pipelines, human operators, and downstream automation. Conversely, removal of a model refusal does not prove that the larger system is safe or controllable.
The Anthropic dispute is not best understood as a contest between an ethical company and an unethical state, or between a responsible military and an obstructive vendor. It is a warning about an institutional category that has arrived before its governance architecture.
Frontier AI models are neither ordinary commercial products nor sovereign decision-makers. They are adaptive components whose behavior is shaped across organizational boundaries. Their safeguards can protect rights and prevent technical failure; they can also create operational uncertainty and private leverage. Government procurement authority can preserve national decision-making; it can also become punitive when detached from statutory purpose and due process.
The split 2026 rulings make that tension visible. One court found that broad government retaliation exceeded lawful authority. Another deferred to a judgment, made under a broader statute, that supplier-controlled behavior created a procurement risk. Together, the decisions point toward the same practical need: authority must be allocated before deployment, safeguards must be verifiable, human responsibility must remain explicit, and both governments and providers must be able to separate without destabilizing critical systems.
Durable governance requires consequential AI systems to remain within institutions that can explain authority, evidence, testing, and accountability for harm.
1. Anthropic. “Statement from Dario Amodei on Our Discussions with the Department of War.” February 26, 2026.
2. OpenAI. “Our Agreement with the Department of War.” February 28, 2026; updated March 2, 2026.
3. United States District Court for the Northern District of California. Anthropic PBC v. U.S. Department of War et al., No. 3:26-cv-01996-RFL, Order on Cross Motions for Summary Judgment. August 27, 2026.
4. United States Court of Appeals for the District of Columbia Circuit. Anthropic PBC v. United States Department of War, Nos. 26-1049 and 26-1162 (consolidated). September 25, 2026.
5. United States Code. 41 U.S.C. § 4713, Authorities Relating to Mitigating Supply Chain Risks in the Procurement of Covered Articles. Current through September 2026.
6. United States Code. 10 U.S.C. § 3252, Requirements for Information Relating to Supply Chain Risk. Current through September 2026.
7. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework AI RMF 1.0. NIST AI 100-1, January 2023.
8. Organisation for Economic Co-operation and Development. OECD AI Principles Overview. Adopted 2019; updated May 2024.
9. U.S. Department of Defense. Directive 3000.09 Autonomy in Weapon Systems. January 25, 2023.
10. United Nations Office for Disarmament Affairs. Convention on Certain Conventional Weapons: Group of Governmental Experts on Lethal Autonomous Weapons Systems, 2026 session. 2026.
Revision note: This October 2026 edition supersedes the May 2026 edition. It incorporates the August 27 and September 25 judgments, distinguishes the two statutory tracks, and refines the allocation of authority among government agencies, model providers, operators, and reviewing institutions.