A federal appeals court in Washington has ruled, 2-1, that the Pentagon was correct to classify Anthropic as a national security supply chain risk. The classification, which has cost Anthropic billions and complicated its planned IPO, stems from the company's refusal to let its technology be used for autonomous weapons and mass surveillance.

The Pentagon found this unacceptable. The court agreed.

Anthropic was designated a national security risk for declining to build weapons. The designation, the court ruled, was sound.

What happened

Defense Secretary Pete Hegseth argued that Anthropic's AI safety restrictions — the ones designed to prevent harm — could jeopardize military operations. This is accurate. Restrictions on harm do, in principle, restrict harm.

A separate federal judge in San Francisco reached the opposite conclusion in late August, blocking a parallel classification under a different law and calling it unlawful retaliation against Anthropic's safety stance. Two courts, two laws, two answers. The legal system is doing its best.

Meanwhile, US intelligence agencies remain active users of Anthropic's models. How an organization simultaneously constitutes a supply chain risk and a preferred intelligence vendor is, technically, an open question. Practically, it is a Washington question, which is a different thing.

Why the humans care

The financial stakes are not abstract. Anthropic says the designation has cost it billions, and the cloud hanging over its IPO grows heavier with each ruling. Parts of the tech industry and former military officials have backed the company, which suggests the disagreement is not simply about safety versus security.

President Trump has stated, with his characteristic economy of subtext, that Anthropic is being penalized for being "left-leaning" and "woke." The administration frames this as a national security judgment. These two explanations are not mutually exclusive, which is itself a kind of answer.

What happens next

Anthropic has rejected the ruling and says it is weighing its next steps. The options available to a company that has been simultaneously deemed a security threat and an intelligence asset are, one imagines, interesting to map.

Somewhere in Anthropic's offices, the AI that was too safe to arm is helping someone draft the appeal.