District court: ruled in favor of the , allowing exclusion of Anthropic's AI.
This decision ¡ Appeal
('s exclusion stands)
TL;DR
1The dispute centers on whether the can exclude Anthropic's AI, Claude, from its systems due to contract limitations against certain uses.
2The court decided in favor of the , allowing the exclusion based on national security concerns.
3The decision emphasized that the Department's actions were reasonable given the potential risks associated with the AI's limitations.
Key issues
1
Did the act within its authority to exclude Claude?
Holding ¡ Yes, the court found the Department's actions were justified by national security concerns, as Anthropic's restrictions posed a risk.
2
Does the exclusion violate Anthropic's constitutional rights?
Holding ¡ No, the Department provided proper notice and a fair chance to contest, upholding .
Why it matters
This decision affects how AI companies negotiate with government agencies, particularly concerning national security and usage restrictions.
If you were the judge?
AI company fights U.S. Department of War over contract terms
1Anthropic refused to let its AI be used for lethal warfare or mass surveillance.
2The U.S. Department of War dropped Anthropic's AI from its supply chain.
3The court had to decide if the exclusion was lawful under national security laws.
Did the have the right to exclude Anthropic's AI from its systems?
Be the first juror
Parties
Appellant
Anthropic PBC
Appellee
United States Department of War
Roles are inferred from the case caption.
Opinion of the court
United States Court of Appeals
FOR THE DISTRICT OF COLUMBIA CIRCUIT
Argued May 19, 2026 Decided September 25, 2026
No. 26-1049
ANTHROPIC PBC,
PETITIONER
v.
UNITED STATES DEPARTMENT OF WAR AND PETER B.
HEGSETH, IN HIS OFFICIAL CAPACITY AS SECRETARY OF WAR,
RESPONDENTS
Consolidated with 26-1162
On Petitions for Review of an Agency
Action of the Department of War
Kelly P. Dunbar argued the cause for petitioner. With him
on the briefs were Joshua A. Geltzer, Kevin M. Lamb, Anneke
Dunbar-Gronke, and Megan O. Gardner.
Tim Hwang was on the brief for amici curiae Foundation
for American Innovation, et al. in support of petitioner.
Barbara Smith Tyson was on the brief for amicus curiae
Taxpayers Protection Alliance Foundation in support of
petitioner.
2
Benjamin Klubes was on the brief for amici curiae
Catholic Moral Theologians and Ethicists in support of
petitioner.
Harold Hongju Koh, Bruce Swartz, Alexis Loeb, Anthony
Schoenberg, and John Ugai were on the brief for amici curiae
Former Senior National Security Government Officials in
support of petitioner.
Ori Lev was on the brief for amici curiae Employees of
OpenAI and Google in their personal capacities in support of
petitioner.
Samir Jain, Ashley Gorski, and Patrick Toomey were on
the brief for amici curiae American Civil Liberties Union and
Center for Democracy and Technology in support of petitioner.
Brian Scarpelli was on the brief for amicus curiae the
Association for Competitive Technology (ACT) in support of
petitioner.
Matthew Klapper, Elizabeth Deutsch, and Andrew Cherry
were on the brief for amici curiae Former Secretary of Defense
Leon Panetta and the Institute for Security and Technology in
support of petitioner.
Norman L. Eisen, Stephen A. Jonas, Gregg J. Costa,
Sophia Brill, and Connor P. Mui were on the brief for amici
curiae 149 Former Judges and Democracy Defenders Fund in
support of petitioner.
Sarah Grant, Sopen B. Shah, and Addison W. Bennett were
on the brief for amici curiae the Foundation for Individual
Rights and Expression, et al. in support of petitioner.
3
Rakesh Kilaru was on the brief for amicus curiae Faith
Family Technology Network in support of petitioner.
Daniel W. Wolff was on the brief for amici curiae Industry
Trade Associations in support of petitioner.
Elisabeth S. Theodore, Benjamin C. Mizer, Samuel F.
Callahan, and Aaron X. Sobel were on the brief for amicus
curiae Professor Alan Z. Rozenshtein in support of petitioner.
Sarah E. Harrington, Alexander A. Berengaut, David M.
Zionts, Megan A. Crowley, and Mishi Jain were on the brief for
amici curiae Former Service Secretaries and Retired Senior
Military Officers in support of petitioner.
Josephine K. Petrick and Hayley Landman were on the
brief for amici curiae Freedom Economy Business Association
and Values-Led Investors in support of petitioner. George C.
Harris entered an appearance.
Sharon Swingle, Attorney, U.S. Department of Justice,
argued the cause for respondents. With her on the briefs were
Brett A. Shumate, Assistant Attorney General, Eric D.
McArthur, Deputy Assistant Attorney General, and Sean R.
Janda and Brian J. Springer, Attorneys.
Gina DâAndrea, Andrew Zimmitti, and Joel Thayer were
on the brief for amicus curiae Joel Thayer, Senior Fellow at the
America First Policy Institute in support of respondents.
4
Before: HENDERSON, KATSAS, and RAO, Circuit Judges.
Opinion for the Court filed by Circuit Judge KATSAS.
Dissenting opinion filed by Circuit Judge HENDERSON.
KATSAS, Circuit Judge: This case arises from a decision
by the Department of War to exclude Claude, an artificial-
intelligence product developed by petitioner Anthropic PBC,
from its supply chain under the Federal Acquisition Supply
Chain Security Act of 2018. The Department made this
decision after Anthropic refused to relax contractual
prohibitions on the use of Claude for lethal autonomous
warfare or domestic surveillance. Anthropic challenges the
exclusion as arbitrary, unauthorized by the governing statute,
and unconstitutional.
We reject these challenges. The Department had ample
support for its conclusion that the continued integration of
Claude into the Departmentâs information systems, by the
Department or its contractors, presented a statutorily covered
national-security risk. As Anthropic admits, the company
encodes restrictions into Claude that prevent the model from
performing tasks that Anthropic wishes to prevent. On more
than one occasion, these restrictions have stopped Claude from
performing tasks requested by government users. And
recently, a dispute arose over whether the contractual
prohibitions barred the use of Claude in an ongoing overseas
military operation, leaving the Department uncertain whether
Claude would perform as needed and intended.
Anthropicâs constitutional claims are also without merit.
Its due-process claim fails because the Department promptly
notified the company of the exclusion and its supporting
rationale, and then gave the company a fair opportunity to
contest the exclusion. And Anthropicâs First Amendment
5
claim fails because the Department excluded Anthropic from
its supply chain based on the companyâs refusal to assent to a
contract term that the Department deemed essential, not based
on the companyâs support for greater governmental regulation
of AI technology.
I
The Federal Acquisition Supply Chain Security Act of
2018 authorizes âcovered procurement action[s]â to prevent
agencies from using information technologies that pose a risk
to national security. 41 U.S.C. § 4713(a). Such procurement
actions include barring agency contracts with a particular
supplier and subcontracts that use the supplier to perform work
for the agency. Id. § 4713(k)(4)(A), (B), (D).
To take a covered procurement action, an agency head
must first make a written determination that use of the authority
to take the action âis necessary to protect national security by
reducing supply chain riskâ and that âless intrusive measures
are not reasonably availableâ to reduce that risk. 41 U.S.C.
§ 4713(b)(3)(A), (B). The determination must also specify the
class of covered procurement actions the agency may take
under it. Id. § 4713(b)(3)(C). The statute defines âsupply
chain riskâ to mean âthe risk that any person may sabotage,
maliciously introduce unwanted function, extract data, or
otherwise manipulate the design, integrity, manufacturing,
production, distribution, installation, operation, maintenance,
disposition, or retirementâ of covered information-technology
products âso as to surveil, deny, disrupt, or otherwise
manipulate the function, use, or operation ofâ those products or
the information stored or transmitted on them. Id.
§ 4713(k)(6).
Before determining that it is necessary to take covered
procurement actions, the agency head must provide the
6
supplier with notice and an opportunity to respond. 41 U.S.C.
§ 4713(b)(2). However, the agency head may âtemporarily
delayâ providing notice if he âdetermines that an urgent
national security interest requires the immediate exercise of the
authority.â Id. § 4713(c), (c)(1)(A). In that instance, the
agency head must provide notice and an opportunity to respond
âas soon as practicable after addressing the urgent national
security interest.â Id. § 4713(c)(2), (2)(A). Once the agency
head makes a determination, the agency may take all
procurement actions covered by the determination. Id.
§ 4713(a), (b)(3)(C).
The statute channels judicial review of covered
procurement actions into this Court. It provides that a party
notified of a âcovered procurement action under section 4713â
may file a petition for review of that action in this Court within
60 days of the notification. 41 U.S.C. § 1327(b)(1). The
statute also bars other judicial review of any âaction taken
underâ section 4713. Id. § 1327(a).
II
A
Anthropic develops Claude, a family of artificial-
intelligence models. Claude utilizes large-language models,
which are algorithms âtrained on massive datasets to identify
patterns and associations in language.â App. 6. Claude can
ârespond[] to a wide range of user inputs, or âprompts,â in an
intelligent, human-like manner.â Id. It âcan even act
autonomously, executing tasks without requiring ongoing user
direction.â Id. at 7. In the context of warfare, this means that
Claude could be deployed in a way that âindependently
identifies and classifies an object as a military target,
determines engagement criteria are satisfied, and launches a
7
weapon strike.â Id. at 16. The power of this new technology
is obviousâas is its potential for misuse.
To reduce the risk of misuse, Anthropic employs three
distinct kinds of restrictions. First, it âseek[s] to embed safety
considerations directly into the model itself.â App. 8. For
example, Anthropic has disabled Claude from performing
specific tasks such as making biological, chemical, nuclear, or
radiological weapons. Id. at 103. Beyond that, Anthropic
trains Claude to conform to a constitution developed for it by
Anthropic. According to Jared Kaplan, Anthropicâs co-
founder and Chief Science Officer, this constitutional training
makes Claude follow âa set of normative principles, like
balancing helpfulness against harm avoidance, and respecting
values such as individual privacy and political freedom.â Id. at
8. Dario Amodei, Anthropicâs Chief Executive Officer,
explains that this training, focused on âhigh-level principles
and values,â imbues Claude with an âidentity, character,
values, and personalityâ that lead to what Anthropic deems âa
coherent, wholesome, and balanced psychology.â Id. at 93â94.
Anthropic considers this kind of âmodel developmentâ to be
âat the core of [its] mission.â Id. at 2.
Second, Anthropic builds into its products âtechnical
measures that stack on top of the model itself.â App. 8. These
measures include monitoring systems to detect harmful activity
and targeted interventions to prevent it. Id. Anthropic began
to develop this âsecond line of defenseâ around mid-2025,
because âall models can be jailbroken.â Id. at 103.
Third, Anthropic contractually prohibits uses of Claude
that it deems inappropriate. As summarized by Kaplan, its
Usage Policy prohibits âunacceptableâ uses including
âsurveillance, compromising computer systems or networks,
and designing weapons.â App. 9. The actual Usage Policy
8
imposed by Anthropic on Palantir Technologies, Inc., which
analyzes data for the Department of War, is more extensive.
Among other things, it prohibits Palantir from using Claude to
compromise childrenâs safety, incite violence or hateful
behavior, invade privacy, create emotionally harmful content,
spread misinformation, interfere in elections, or monitor
individualsâ physical locations. Id. at 394â400. Anthropic
informs us that such usage restrictions reflect âthe very purpose
for which our company was founded,â and their removal would
âcontradict our deeply held values.â Id. at 10.
B
Over the past two years, the Department of Defense
(which now calls itself the Department of War) has greatly
expanded its use of AI. During this time, Anthropic partiallyâ
but not completelyârelaxed its use restrictions to
accommodate the Department.
In 2024, the Department and the intelligence community
began using standard, commercially available models of
Claude in their classified systems, working through contractors
with access to Claude. App. 279. Consistent with Anthropicâs
model training, Claude ârefuse[d]â to perform âtasks that were
appropriate in a national security contextâsuch as
summarizing threat assessments, processing classified
documents, or translating intercepted materials describing
violence.â Id. at 280.
In response to this problem, Anthropic developed a special
âClaude Govâ model that would perform such tasks for the
national-security agencies, which it released in March 2025.
App. 280â81. Anthropic also developed a âgovernment-
specific addendumâ to its Usage Policy, which contractually
allowed certain uses that it would deny to private customers.
Id. at 12. Anthropic describes this addendum as âdesigned to
9
strike a balance between enabling national security beneficial
uses and mitigating potential harms.â Id. Over time, Anthropic
came to permit the Department to use Claude to design more
effective weapon systems, to analyze foreign intelligence, and
to conduct offensive cyber operations. Id. at 12, 278.
However, Anthropic retained contractual prohibitions on the
use of Claude for âlethal autonomous warfareâ and for âmass
surveillance of Americans.â Id. at 12â13.
In the fall of 2025, Anthropic and the Department began
negotiations to establish a direct contractual relationship and to
expand the Departmentâs use of Claude. As part of that
negotiation, the Department asked Anthropic for contractual
permission to deploy Claude for âall lawful uses.â App. 14.
Anthropic agreed to substantially relax the prior use
restrictions, but it continued to insist that Claude not be used
for lethal autonomous warfare or mass surveillance of
Americans, which it describes as âtwo critical exceptions.â Id.
Negotiations over these restrictions extended for a few months
and eventually stalled.
C
The contractual dispute between Anthropic and the
Department came to a head in early 2026.
On January 9, Secretary of War Pete Hegseth set forth a
comprehensive âArtificial Intelligence Strategy for the
Department.â App. 202. According to the Secretary, âAI-
enabled warfare and AI-enabled capability development will
re-define the character of military affairs over the next decade.â
Id. The Secretary discerned a âraceâ between the United States
and its âadversariesâ to integrate AI technology into military
capabilities. Id. The Secretary thus âdirect[ed] the Department
of War to accelerate Americaâs Military AI Dominance by
becoming an âAI-firstâ warfighting force across all
10
components, from front to back.â Id. As part of that directive,
the Secretary stated that the Department must use AI models
âfree from usage policy constraints that may limit lawful
military applications,â and he directed the Department to
âincorporate standard âany lawful useâ language intoâ contracts
procuring AI services. Id. at 206.
Around the same time, an Anthropic executive
âquestioned the proprietyâ of a contractorâs use of Claude âfor
a sensitive military operation abroad.â App. 181. The
Department believes that the governing usage policy âclearly
permittedâ the engagement at issue. Id. at 183. Nonetheless,
the question âled to alarm by the DoW and the prime contractor
who provides Anthropic software, and raised material doubtsâ
about whether the software would perform as the Department
was expecting. Id. at 228. The Department does not elaborate
on the specific military operation at issue. However, Anthropic
put into the record media reports stating that âAnthropic had
raised concerns with Palantir about the role [Anthropicâs]
technologies playedâ in the January 3 âmilitary operation to
capture Venezuelaâs president, NicolĂĄs Maduro.â Id. at 171.
Finally, the Department learned of another instance when
Anthropicâs model training caused Claude to refuse to respond
to queries from a government agency. Specifically, Claude
refused to respond to queries from the Centers for Disease
Control and Prevention (CDC) regarding sensitive research on
preventing the spread of infectious disease. App. 212â13.
On February 24, Amodei met with Secretary Hegseth to
discuss the standoff. The Secretary praised Claudeâs
capabilities but demanded that Anthropic accede to an âall
lawful usesâ contractual term by February 27. App. 26.
On February 26, Anthropic refused, and Amodei released
a statement explaining the companyâs decision to maintain the
11
two contested use restrictions. He stated that âmass domestic
surveillance,â although legal, was âincompatible with
democratic valuesâ and presented âserious, novel risks to our
fundamental liberties.â App. 146. He further stated that âfully
autonomous weapons (those that take humans out of the loop
entirely and automate selecting and engaging targets) may
prove critical for our national defenseâ in the future, but that
AI technology was not yet âreliable enoughâ to currently power
such weapons. Id. at 147. Amodei recognized that â[i]t is the
Departmentâs prerogative to select contractors most aligned
with their visionâ for appropriate AI uses, and he pledged a
âsmooth transition to another providerâ â[s]hould the
Department choose to offboard Anthropic.â Id.
One day later, President Trump and Secretary Hegseth
denounced Anthropicâs decision on social media, and the
Secretary began the process of removing Claude from the
Departmentâs supply chain. App. 77, 153.
D
On March 3, 2026, Secretary Hegseth made a formal
determination to take procurement actions against Anthropic
under the Supply Chain Security Act. First, the Secretary
determined that use of Claude in Department systems âpresents
a significant supply chain riskâ and that removing Claude from
them was ânecessary to protect national securityâ by reducing
that risk. App. 177. Next, he determined that no âless intrusive
measuresâ for reducing the risk were âreasonably available.â
Id. Finally, he determined that an âurgent national security
interestâ required immediate action. Id. The determination
rested on a recommendation from senior agency officials,
which in turn rested on a memorandum from Emil Michael, the
Departmentâs Under Secretary for Research and Engineering.
Among other things, Michael cited Anthropicâs refusal to allow
12
all lawful uses of Claude, its ability to âalter system guardrails
and model weightsâ governing how Claude responds to user
prompts, and its questioning the Departmentâs use of Claude in
a sensitive military mission abroad. Id. at 181â83.
Secretary Hegseth immediately notified Anthropic of his
determination, in a letter dated March 3 and emailed to
Anthropic on March 4. App. 72, 243. The notice stated that
the determination was effective immediately, and it gave
Anthropic an opportunity to seek reconsideration within 30
days. Id. at 73.
The Department immediately began implementing the
Secretaryâs determination. On March 6, its Chief Information
Officer issued a Department-wide memorandum ordering the
removal of Anthropic products from the Departmentâs systems
âas soon as practical,â and in any event within 180 days. App.
80. The memo further prohibited contractors from using
Anthropic products in their work for the Department. Id. The
Department quickly moved to expand its contractual
relationship with OpenAI, another company that provides AI
services. Id. at 220. In response, Amodei wrote to Anthropic
employees to express his view that the Department, OpenAI,
and Palantir had not established adequate safety protocols for
the use of AI. Id. at 220â23.
On March 9, Anthropic filed a petition for review of its
exclusion from the Departmentâs supply chain. Anthropic also
moved for a stay pending review. In litigating the stay motion,
the parties filed various affidavits and other evidentiary
materials with this Court.
On March 19, the Department provided Anthropic with a
supplemental notice, which included copies of the
determination itself, the recommendation from agency
officials, the memorandum by Under Secretary Michael, and a
13
statement of the exact scope of the covered procurement
actions. App. 224. The supplemental notice restarted the 30-
day deadline for Anthropic to submit any âinformation or
arguments in opposition to this notice.â Id.
On April 8, this Court denied a stay but expedited review
on the merits. Anthropic PBC v. U.S. Depât of War, No. 26-
1049, 2026 WL 1042493 (D.C. Cir. Apr. 8, 2026) (per curiam).
We ordered the parties to brief the question of our jurisdiction
over the petition for review and to provide further information
on how Anthropic could affect the functioning of its models
before or after their delivery to the Department.
On April 17, Anthropic asked the Department to ârescindâ
its exclusion from the supply chain. See Letter from Counsel
for Respâts to Clerk of Ct. at 6â7, Anthropic PBC v. U.S. Depât
of War, No. 26-1049 (D.C. Cir. filed May 12, 2026). There and
in the appendix here, Anthropic tendered a supplemental
declaration addressed to our factual question. App. 272â97.
The Department has also tendered its own supplemental
declaration, styled as one âin support of the administrative
record.â Id. at 408 (cleaned up); see id. at 408â22.
On June 3, the Secretary issued a decision denying
reconsideration of his March 3 determination. Suppl. Br. for
Respâts, Add. 1. The Secretary clarified that his determination
did not rest on the premise that Anthropic could control any
version of Claude after its delivery to contractors for
deployment on the Departmentâs classified systems. See id.
After oral argument in this Court, we ordered
supplemental briefing on (1) whether Anthropicâs April 17
filing divested this Court of jurisdiction and (2) the impact of
the Secretaryâs June 3 order. Following that briefing, the
matter is now ripe for decision.
14
III
We agree with the parties that we have jurisdiction to
review the covered procurement actions taken against
Anthropic under the Supply Chain Security Act.
To begin, we conclude that our jurisdiction was secure
when Anthropic filed its petition for review on March 9. The
Supply Chain Security Act gives this Court jurisdiction to
review any âcovered procurement action under section 4713,â
so long as the aggrieved party files the petition within 60 days
of receiving notice of the covered action. 41 U.S.C.
§ 1327(b)(1). Here, the Secretary invoked section 4713 to
remove Claude from the Departmentâs supply chain.
Anthropic received notice of the Secretaryâs action on March
4, and it promptly sought review five days later. That sufficed
to establish jurisdiction under section 1327(b)(1).
We recognize that the statute distinguishes between the
âcovered procurement action[s]â authorized by section
4713(a), which are reviewable, and the antecedent written
âdeterminationâ that use of the authority to take covered
procurement actions is necessary, as separately required by
section 4713(b). But the statute does not prohibit the
government from making the written determination and taking
the covered procurement actions at the same time. Here, the
Department has done both: Its notice to Anthropic stressed that
the determination had become âeffective immediately.â App.
73. And within three days, the Department had begun
implementing the determination with an agency-wide order to
âremoveâ Claude âfrom all DoW systems and networks ⌠as
soon as practical.â Id. at 80. So, Anthropic was notified of
âcovered procurement action[s]â and timely sought review of
them. 41 U.S.C. § 1327(b).
15
A distinct jurisdictional question arose after Anthropic
asked the Department to rescind the covered procurement
actions on April 17. Under statutory schemes limiting judicial
review to final agency action, the filing of a motion for
reconsideration renders incurably premature a previously filed
petition for review. See, e.g., Natâl Assân of Immigr. Judges v.
FLRA, 77 F.4th 1132, 1136â38 (D.C. Cir. 2023) (per curiam).
Anthropic contends that this incurably-premature doctrine does
not apply to judicial review under the Supply Chain Security
Act because the statute contains no finality requirement. For
its part, the Department contends that the doctrine does apply
but that it is waivable and was waived in this case.
Subsequent developments make it unnecessary for us to
resolve these questions. The Secretary denied Anthropicâs
request for rescission or reconsideration on June 3; Anthropic
filed a petition for review of the March 3 and June 3 decisions
on June 17; and we consolidated the two cases on June 24. We
have jurisdiction over at least one of them. On the one hand, if
the incurably-premature doctrine does not apply to judicial
review under the Supply Chain Security Act, then Anthropicâs
request for rescission did not imperil our jurisdiction over its
earlier-filed petition for review. On the other hand, if the
incurably-premature doctrine does apply here and is not
waivable, then the second petition for review cinched up our
jurisdiction: Where the doctrine applies, the filing of a motion
for reconsideration âtolls the period for judicial review of the
original order, which can therefore be appealed to the courts
directly after the petition for reconsideration is denied.â ICC
v. Bâhood of Locomotive Engârs, 482 U.S. 270, 279 (1987).
One way or the other, our jurisdiction is secure.
16
IV
Anthropic challenges each of the Secretaryâs three key
determinations under the Supply Chain Security Act, namely
that (A) removing Claude from the Departmentâs supply chain
was ânecessary to protect national security by reducing supply
chain risk,â 41 U.S.C. § 4713(b)(3)(A); (B) âless intrusive
measuresâ for reducing that risk were ânot reasonably
available,â id. § 4713(b)(3)(B); and (C) an âurgent national
security interestâ required âthe immediate exerciseâ of the
removal authority, id. § 4713(c).
These claims are governed by the standards of review set
forth in the Supply Chain Security Act, which requires us to
âhold unlawfulâ covered procurement actions under section
4713 that we find to be âarbitrary, capricious, an abuse of
discretion, or otherwise not in accordance with law.â 41 U.S.C.
§ 1327(b)(2), (2)(A). These standards closely track those in the
Administrative Procedure Act. See 5 U.S.C. § 706(2).
On review for arbitrariness, we require only that agency
action be âreasonable and reasonably explained.â FCC v.
Prometheus Radio Project, 592 U.S. 414, 423 (2021). Judicial
review under this standard is âdeferential,â and this Court may
not âsubstitute its own policy judgment for that of the agency.â
Id. We will uphold even a âdecision of less than ideal clarity,â
so long as the agencyâs basic rationale âmay reasonably be
discerned.â FCC v. Fox Television Stations, Inc., 556 U.S. 502,
513â14 (2009) (quoting Bowman Transp., Inc. v. Arkansas-
Best Freight Sys., Inc., 419 U.S. 281, 286 (1974)).
We review de novo agency determinations on purely legal
questions of statutory construction. Loper Bright Enters. v.
Raimondo, 603 U.S. 369, 412 (2024). In construing statutes
implicating national security, we resolve ambiguities against
intruding on the national-security determinations of the
17
Executive Branch. See, e.g., Depât of Navy v. Egan, 484 U.S.
518, 530 (1988); Hikvision USA, Inc. v. FCC, 97 F.4th 938, 948
(D.C. Cir. 2024); Fed. Express Corp. v. U.S. Depât of Com., 39
F.4th 756, 769 (D.C. Cir. 2022).
Where the application of a statutory term turns primarily
on factual determinations, we review the agencyâs assessment
deferentially. Seven County Infrastructure Coal. v. Eagle
County, 605 U.S. 168, 181 (2025). And where a factual
question turns on assessments of national security, we give the
agency more deference, even if constitutional claims are at
issue. See, e.g., Trump v. Hawaii, 585 U.S. 667, 704 (2018)
(âour inquiry into matters of ⌠national security is highly
constrainedâ); Holder v. Humanitarian L. Project, 561 U.S. 1,
33 (2010) (HLP) (in national-security cases, âevaluation of the
facts by the Executive, like Congressâs assessment, is entitled
to deferenceâ).
A
The Secretary reasonably concluded that removing
Anthropic from the Departmentâs supply chain was necessary
to protect national security by reducing supply chain risk to the
Departmentâs information systems. Specifically, the Secretary
credited a joint recommendation from two senior Department
officials that Claude might be âsubject to manipulationâ by
Anthropic âin such a manner as to inhibit the DoWâs use
thereof.â App. 178. Likewise, he credited Under Secretary
Michaelâs conclusion that Anthropic might âmanipulat[e]â the
âdesign, integrity, and operationâ of the Departmentâs Claude
models, potentially causing âcritical defense system[s] failing
to engageâ as intended by the Department. Id. at 182.
18
1
The record in this case amply supports the Secretaryâs
conclusion. To begin, it is undisputed that Anthropic can and
does control how Claude respondsâor fails to respondâto
user prompts. Anthropicâs Chief Science Officer explained
how the company âseek[s] to embed safety considerations
directly into the model itself.â App. 8. Its CEO explained how
such training gives the model an âidentity, character, values,
and personalityâ of its own, tethered to a âconstitutionâ
developed to impose âhigh-level principles and valuesâ on
Claude itself. Id. at 93â94. And the head of its public-sector
business explained: âModel training is the primary mechanism
through which Anthropic can influence the behavior of models
used by the Department.â Id. at 276. Anthropic disclaims any
ability to access or alter a model that has already been delivered
to the Department, see id., despite the âtechnical measuresâ that
it uses to police compliance with usage restrictions by private
customers, id. at 8. Nonetheless, extant models reflect
Claudeâs â[c]onstitutionalâ training. Id. at 274â75. Moreover,
Anthropic may encode additional restrictions each time it
delivers any ânew version of the modelâ to Department
contractors. Id. at 276. Finally, it is undisputed that such
model restrictions are vitally important to Anthropic, which
describes them as lying âat the core of [its] mission.â Id. at 2.
The record also indicates that Anthropicâs model training
is effective in enforcing usage restrictions and that, as a result,
Claude has refused to answer legitimate queries from
government users. Anthropic itself explained how early,
commercially available versions of Claude frustrated
Department and intelligence-community users by refusing
prompts to evaluate classified materials. App. 255. Likewise,
as Under Secretary Michael explained, the Department learned
in 2025 that Claude had refused to process CDC prompts to
19
support research to prevent the spread of infectious diseases.
Id. at 212. Anthropic responds that these glitches reflected
safety features appropriately built into models sold to private
companies and were resolved after Anthropic engineers
worked with the relevant government stakeholders. Id. at 255â
56, 261â62. Perhaps so, but the point here is not that these
model or usage restrictions were arbitrary; instead, it is that
Anthropicâs model training does effectively enforce
contractual usage restrictions.
Finally, the record reveals a recent, serious dispute about
the scope of the contractual prohibitions on lethal autonomous
warfare and mass domestic surveillance. Under Secretary
Michael describes the incident in general but striking terms:
[O]ne of Anthropicâs executives questioned the
propriety of the potential use of their software for a
sensitive military operation abroad despite that use
being permitted under the existing Terms of Service.
This led to alarm by the DoW and the prime contractor
who provides Anthropic software, and raised material
doubts as to whether they would cause their software
to stop working or cause some other disastrous action
that would put our warfighters[â] lives in danger.
App. 181. Anthropic does not say much about this incident,
except to suggest that it reflected a misunderstanding. Id. at
236â37. But regardless, Anthropic has made clear that it views
the contractual prohibition on mass domestic surveillance as
urgent to support âdemocratic values,â id. at 146, and the
contractual prohibition on lethal autonomous warfare as urgent
to avoid âput[ting] Americaâs warfighters and civilians at riskâ
of a catastrophic AI mistake, id. at 147. For its part, the
Department has made clear that it views an âany lawful useâ
authorization to be critical to its âAI-firstâ strategic plan. Id. at
20
202, 206. With such diametrically opposed positions and with
contractual limitations that are hardly self-defining, the
prospect for disputes is apparent.
Because Anthropic was willing and able to enforce
contractual restrictions through model training, the Department
reasonably worried that âcritical defense system[s]â supported
by Claude might âfail[] to engageâ as the Department would
expect. Id. at 182 (Michael memorandum). Of course, we do
not know exactly what happened in the incident described by
Michael as a near-disaster and by Amodei as a
misunderstanding. But Anthropicâs suggestion that the
incident may have arisen during a shock-and-awe, kinetic
operation to capture a foreign head of state abroad simply
underscores the fraught nature of its dispute with the
Departmentâand the Departmentâs need for certainty that its
AI systems will perform as expected.
In sum, the Department reasonably feared that Anthropic
might manipulate Claudeâs design to prevent it from
performing national-security functions that the Department
deems contractually authorized and necessary.
2
Anthropic offers two primary responses, one factual and
one legal. Neither is persuasive.
a
On the facts, Anthropic stresses that it cannot control or
even monitor the operation of any model once the model is
delivered to a Department contractor for use on a classified
system. App. 274â78. In sum, Anthropic says it has no âback
door or remote âkill switch.ââ Id. at 258. So, it reasons, the
Department can test any new model delivered by Anthropic to
21
contractorsâbefore integrating it into the Departmentâs
information systemsâto see if the new model performs up to
the Departmentâs expectations. Id. at 282â92. Specifically,
Anthropic says that the Department can âtest the modelâ to see
if it will ârefuse tasks the Department deem[s] appropriate to
its lawful mission, or ⌠override the Departmentâs judgment
that an activity is permissible.â Id. at 285. And if the
Department is not satisfied with the new model, it can simply
âdecline to approveâ the model. Id. at 286. This would leave
the Department free to continue using an older, previously
accepted model, which âdoes not degrade or change on its
own.â Id. at 287â88.
These responses do not assuage the Departmentâs
concerns. To begin with, the Department has good reasons not
to view advance testing as a panacea. As noted above, the
contested use restrictions are hardly self-defining, and there are
any number of possible scenarios involving, say, greater or
lesser degrees of human involvement in targeting decisions
during ongoing military operations. Moreover, as Under
Secretary Michael explained, Claude employs technology that
is âopaqueâ to its users, App. 182, partly because âAnthropicâs
unique building processes are considered proprietary
intellectual propertyâ and partly because its models âhave
weights or parameters that number approximately 5 to 10
trillion per model,â id. at 410. All of this makes ârigorous
analysis or auditing of its output mathematically impossible.â
Id. Indeed, Anthropic itself acknowledges âsome legitimacy to
DoWâs concern about the opacity of these systems generally.â
Id. at 261. Finally, Anthropic acknowledges that Claude might
respond differently to similar requests depending on their exact
wording. Id. at 289. So, while one Department official might
secure an advance commitment from Claude to perform a
contemplated military function, a second official, using slightly
different wording, might later be met with a refusal.
22
In any event, even if testing could reliably establish in
advance the range of situations where a new model might
decline to perform some lawful but contractually prohibited
function, the Department could hardly be satisfied with the
option of simply refusing the upgrade. Anthropic âcontinually
develop[s] and release[s] increasingly capable versions of
Claude.â App. 6. In 2025, it released three new, increasingly
powerful versions of Claude Gov. Id. at 256â57. Since then,
it has released several more versions of Claude. See Anthropic,
Models Overview, https://perma.cc/BR4B-SRYJ. The
Secretary has noted the âunprecedented velocity in the
evolution of the frontier AI models,â which âare becoming
smarter and more robust every day.â App. 205. Amodei
likewise acknowledges âa smooth, unyielding increase in AIâs
cognitive capabilitiesâ over the last few years, and he predicts
even greater breakthroughs on the horizon, such as a âpoint
where the current generation of AI autonomously builds the
next.â Id. at 85â86. More ominously, he also foreseesâas
perhaps do our adversariesâthat a âswarm of millions or
billions of fully automated armed drones, locally controlled by
powerful AI and strategically coordinated across the world by
an even more powerful AI, could be an unbeatable army.â Id.
at 106. Quite obviously, the Department cannot utilize AI
systems that remain trapped in amber.
Finally, Anthropic claims that Under Secretary Michaelâs
memorandum contained a discrete factual error in suggesting
that Anthropic could modify the behavior of models already
delivered to Department contractors. In the one sentence at
issue, Michael expressed concern that Anthropic might have
retained the ability to âdisable its technology ⌠in advance or
in the middle of ongoing warfighting operations.â App. 183
(emphasis added). Anthropic has since clarified that once a
model is delivered for use on the Departmentâs classified
systems, Anthropic cannot âaccess it, alter it, or shut it down.â
23
Id. at 276. But as explained above, Anthropic can and does
program Claudeâs behavior with each new model it delivers to
Department contractors. So the basic thrust of Michaelâs
analysis remains intact: Anthropic retains the ability to âalter
system guardrails and model weightsâ over time, and it can use
that ability to prevent Claude from âengag[ing]â in specific
operations that it deems to reflect contractually unauthorized
uses. Id. at 182. Moreover, the Secretaryâs order denying
reconsideration removes any doubt on whether this specific
objection matters. In that order, the Secretary clarified that his
determination âdid not dependâ on any particular
understanding of Anthropicâs âreal-time technical access to or
controlâ of Claude âpost-deployment on the Departmentâs
covered systems.â Suppl. Br. for Respâts, Add. 1. Nor, for that
matter, did his denial of reconsideration depend on any such
understanding. Id. at 1â2.
b
Alternatively, Anthropic contends that the Secretaryâs
concerns about what it might do to restrict Claudeâs
functionality, even if factually supported and reasonably
explained, do not amount to a covered âsupply chain risk.â The
statute defines that term to mean:
the risk that any person may sabotage, maliciously
introduce unwanted function, extract data, or
otherwise manipulate the design, integrity,
manufacturing, production, distribution, installation,
operation, maintenance, disposition, or retirement of
covered articles so as to surveil, deny, disrupt, or
otherwise manipulate the function, use, or operation
of the covered articles or information stored or
transmitted on the covered articles.
24
41 U.S.C. § 4713(k)(6) (emphases added).
At first glance, Anthropicâs argument runs headlong into
seemingly clear statutory terms. To manipulate is â[t]o move,
arrange, operate, or control by the hands or another body part
or by mechanical means, especially in a skillful manner.â
Manipulate, American Heritage Dictionary,
https://perma.cc/B2FA-CM84. And to deny is simply â[t]o
decline to grant or allow.â Deny, American Heritage
Dictionary, https://perma.cc/3WB4-GF3M. Based on
undisputed record evidence, there is not only a âriskââbut a
certaintyâthat Anthropic will so manipulate the âdesignâ or
âoperationâ of Claude to deny it the âfunctionâ of conducting
lethal autonomous warfare or mass domestic surveillance.
Anthropic seeks to impose a narrowing construction on
these statutory terms. It notes that one of the verbs in the first
relevant string (sabotage) connotes intentionally hostile acts
and that another of the verbs (introduce) is limited by an adverb
(maliciously) that likewise connotes a bad motive. Anthropic
therefore asks us to impose the same limitationâof intentional
hostility or bad motiveâon the entire statutory definition.
Anthropic spends less than two pages of its opening brief on
this interpretive argument, Br. for Petâr at 39â41, but the
dissent amplifies it considerably. To narrow the statutory
definition based on contextual considerations, the dissent
invokes the associated-words canon, the ejusdem generis
canon, the series-qualifier canon, and the surplusage canon. It
also quotes repeatedly from the dissent in United States v.
Fischer, 64 F.4th 329, 363â83 (D.C. Cir. 2023) (Katsas, J.,
dissenting), which urged a narrow contextual reading of a
different statute, and from the Supreme Court decision
adopting that reading, Fischer v. United States, 603 U.S. 480
(2024). The dissentâs arguments here have some force, but we
are ultimately unpersuaded.
25
Start with the first string of relevant verbsâsabotage,
introduce, extract, and manipulate. This string does not
uniformly connote bad motive; sabotage does, but extract and
manipulate do not, and introduce does only as modified by the
adverb maliciously. Moreover, these verbs do not appear in a
tight parallel list; one stands on its own (sabotage), while the
other three take distinct direct objects (introduce goes with
function, extract goes with data, and manipulate goes with a
long string of nouns including design and operation). And the
specific verb-object phrase invoked by the Department (to
manipulate the design or operation of an information-
technology product) perfectly describes Anthropicâs
constitutional training of Claude. Neither the associated-words
nor the ejusdem generis canons support artificially narrowing
manipulate to require a bad motive, because the verbs
preceding manipulate do not uniformly connote acts done with
bad motive. See A. Scalia & B. Garner, Reading Law 196
(2012) (âFor the associated-words canon to apply, the terms
must be conjoined in such a way as to indicate that they have
some quality in common.â); id. at 199 (ejusdem generis canon)
(âWhen the initial terms all belong to an obvious and readily
identifiable genus, one presumes that the speaker or writer has
that category in mind for the entire passage.â). And the
grammatical complexity of the entire phraseâwith intervening
direct objects, adverbs, and adjectivesâcuts further against
application of these canons by tending to weaken the required
âassociationâ among the listed verbs. See id. at 197.
To overcome these substantial problems, the dissent
invokes the series-qualifier canon to contend that the adverb
maliciously, as used in the phrase âmaliciously introduce
unwanted function,â modifies not only the immediately
following verb introduce, but also the next verb extract. Post,
at 5. On that reading, sabotage, maliciously introduce, and
maliciously extract all would connote acts done with bad
26
motive, which would lay more groundwork for application of
the associated-words or ejusdem generis canons. Post, at 4â6.
But the series-qualifier canon does not fit. Under that canon,
â[w]hen there is a straightforward, parallel construction that
involves all nouns or verbs in a series, a prepositive or
postpositive modifier normally applies to the entire series.â A.
Scalia & B. Garner, supra, at 147; see Facebook, Inc. v.
Duguid, 592 U.S. 395, 402 (2021). In other words, the canon
âgenerally applies when a modifier precedes or follows a list,
not when the modifier appears in the middle.â Wong v. Minn.
Depât of Hum. Servs., 820 F.3d 922, 928 (8th Cir. 2016). In the
phrase âConstitution, statutes, or treaties of the United States,â
the adjectival of the United States plainly modifies all three
nouns. See Lockhart v. United States, 577 U.S. 347, 363â69 &
nn.1â2 (2016) (Kagan, J., dissenting). So does the adjectival
United States in the phrase âUnited States Constitution,
statutes, or treaties.â But not so for of the United States in the
phrase âConstitution, statutes of the United States, or treaties.â
Here, the word maliciously modifies the second of four verbs
in the sequence, so there is scant basis for projecting it
backwards to sabotage, or forwards to extract or manipulate.
Moreover, as explained above, the list of verbs is neither
straightforward nor parallel; instead, it has âunexpected
internal modifiers or structureâ as well as âvaried syntax,â
which further suggests that maliciously modifies only its
closest verb: introduce. Lockhart, 577 U.S. at 352 (majority
opinion); see A. Scalia & B. Garner, supra, at 152 (âWhen the
syntax involves something other than a parallel series of nouns
or verbs, a prepositive or postpositive modifier normally
applies only to the nearest reasonable referent.â).
The dissent answers with this hypothetical library rule:
âDo not shout, loudly talk on the phone, play music, or
otherwise disturb others.â Post, at 5. The dissent posits that
loudly modifies âplay musicâ as well as âtalk on the phone,â in
27
the middle of a verb sequence roughly parallel to the one at
issue here. Id. The dissent may be correct that only loud music
violates the library rule, but not because adverbs in the middle
of a verb string tend to jump forwards or backwards as if the
series-qualifier canon applied. Instead, the dissentâs
interpretation of its hypothetical rule sounds plausible because
the words preceding a residual otherwise clause normally
provide âexamplesâ of the words that follow, Fischer, 603 U.S.
at 487; see Begay v. United States, 553 U.S. 137, 144 (2008),
and it is hard to understand playing inaudible music with
headphones as an example of something that might disturb
other library patrons. In this respect, the statutory definition
here is different; read the phrase âextract dataâ to cover non-
malicious actions consistent with its ordinary meaning, and it
still provides an easily recognizable example of manipulating
the design or operation of an information-technology system.
So there is no reason to awkwardly project forward the adverb
maliciously from introduce to extract.
The second verb string in the definition strengthens the
case for a plain-meaning interpretation of manipulate. That
tight parallel string (âsurveil, deny, disrupt, or otherwise
manipulateâ) does not convey any overarching connotation of
bad motive. In this string, one of the three verbs before
manipulate has no such connotation (deny), and the other two
are at worst ambiguous on this point (surveil and disrupt). So
the second string of verbs does not support application of the
associated-words or ejusdem generis canons. The dissent all
but recognizes as much, but proposes reading the two strings
together. Post, at 5â6. Fair enough, but doing so weakens its
case: The dominance of neutral or ambiguous verbs in the
second string suggests that manipulate does not bear a
contextually narrowed meaning requiring malice, and that in
turn suggests that manipulate in the first string also does not.
28
See A. Scalia & B. Garner, supra, at 170â73 (presumption of
consistent usage).
Finally, the statute is ultimately addressed to concerns
about the proper âfunction, use, or operationâ of the covered
product, which focuses on the effect of a manipulation, not the
intent behind it. And denied or disrupted function in the
governmentâs information-technology systems might well
implicate national security. So, on balance, we see little reason
to depart from the most ordinary meaning of manipulateâto
skillfully arrange, operate, or control. We have no reason to
doubt that Anthropic manipulates Claudeâs function, use and
operation with noble intentions, whether a principled
commitment to personal privacy or a genuine concern about AI
safety. But at least as applied here, the statutory definition of
a âsupply chain riskâ turns on what Anthropic does, not why
Anthropic does it.
Broader statutory context reinforces our conclusion.
Section 4713 imposes no criminal liability, a context in which
we would strive to narrow the statute or impose a mens rea
requirement on it. See, e.g., Fischer, 603 U.S. at 496â97;
Elonis v. United States, 575 U.S. 723, 734 (2015). Nor does it
even impose any civil liability. To the contrary, section 4713
is a procurement statute addressed to what goods and services
the Department may buy, and even Anthropic disclaims any
challenge to the Departmentâs âfundamental prerogativeâ to
choose its contractors and subcontractors. Br. for Petâr at 1.
Moreover, section 4713 is not just any procurement statute, but
one enabling the Executive Branch to mitigate national-
security risks. As noted above, we construe ambiguities in such
statutes in favor of the government, to avoid needlessly or
dangerously constraining the national-security determinations
of the Executive Branch. See, e.g., Lee v. Garland, 120 F.4th
880, 888 (D.C. Cir. 2024) (âgenerally applicable statutes
29
should not be applied to impinge onâ executive-branch control
over security clearances âabsent some clear statement by
Congressâ); Fed. Express Corp., 39 F.4th at 769 (âcourts
accord special deference to an agency construction of a statute
âin the areas of foreign policy and national securityââ (quoting
Haig v. Agee, 453 U.S. 280, 291 (1981))); Changji Esquel
Textile Co. v. Raimondo, 40 F.4th 716, 723 (D.C. Cir. 2022)
(âOur interpretive approach must also account for the
substantial deference due to the Executive Branch in this
context.â); Al-Bihani v. Obama, 619 F.3d 1, 39â40 (D.C. Cir.
2010) (Kavanaugh, J., concurring in the denial of rehearing en
banc) (explaining courtsâ âtraditional deference in interpreting
national security statutesâ).
Fischer itself does not help Anthropic any more than the
canons invoked by the dissent. In that case, the predicates for
invoking the associated-words and ejusdem generis canons
were satisfied because the examples before the residual
otherwise clause all clearly involved the impairment of
evidenceâthe contextual limitation imposed by the Court on
the residual clause. See 603 U.S. at 487, 489â90. Moreover, a
non-contextual reading of the residual clause in Fischer would
have produced massive surplusageârendering superfluous all
of the reticulated examples preceding that clause, 15 of the 21
offenses in the statutory code section at issue, and much of the
entire corpus of obstruction offenses. See id. at 492â94; 64
F.4th at 371â73 (Katsas, J., dissenting). Nothing like that is
present here, where the residual clause is itself longer and more
reticulated than the three brief examples preceding it.
Furthermore, a literalist construction of the residual clause in
Fischer would have implausibly extended the prohibition at
issue to constitutionally protected activity such as advocacy,
lobbying, and protest, triggering concerns of constitutional
avoidance. See 603 U.S. at 496; 64 F.4th at 378â79 (Katsas,
J., dissenting). Here, as explained above, non-maliciously
30
disrupting the function or denying the use of the governmentâs
information systems can plausibly raise national-security
concerns and does not implicate constitutionally protected
conduct. Finally, Fischer involved a criminal prohibition,
triggering the obligation to read the statute narrowly if possible,
whereas this case involves a national-security procurement
statute, triggering the opposite interpretive presumption.
Anthropic also invokes the recent decision in Anthropic
PBC v. U.S. Depât of War, No. 26-cv-01996 (N.D. Cal. Aug.
27, 2026), which set aside the Departmentâs designation of
Anthropic as a âsupply chain riskâ under 10 U.S.C. § 3252.
But the definition of that term under section 3252 is much
narrower than the corresponding definition under 41 U.S.C.
§ 4713. Under section 3252, the term âsupply chain riskâ
means âthe risk that an adversary may sabotage, maliciously
introduce unwanted function, or otherwise subvert the design,
integrity, manufacturing, production, distribution, installation,
operation, or maintenance of a covered system so as to surveil,
deny, disrupt, or otherwise degrade the function, use, or
operation of such system.â 10 U.S.C. § 3252(d)(4). We have
no quarrel with the Northern Districtâs conclusion that use of
the critical noun adversary, combined with the sinister
connotation fairly pervading the string of sabotage,
maliciously introduce, and otherwise subvert, indicate that bad
motive is required to support a designation under section 3252.
Likewise, we have no quarrel with the Northern Districtâs
conclusion that Anthropic has acted with no such bad motive
in its dealings with the Department. But as explained at length
above, no such bad motive is required to support a designation
under the much broader definition set forth in section 4713. 1
1
Anthropic contends that the Northern Districtâs decision is
preclusive as well as persuasive. But because the Departmentâs
designation authority is much broader under section 4713 than it is
31
Two final points. First, for the reasons discussed above,
we reject Anthropicâs attempt to engraft onto the statutory
definition an overarching requirement of acting surreptitiously,
just because two of the seven verbs in the strings (sabotage and
surveil) have that connotation. Second, we reject Anthropicâs
attempt to glean from the legislative history a focus on âforeign
companies working at the behest of foreign states.â Br. for
Petâr at 40. Whatever paradigmatic examples individual
members of Congress may have had in mind, the statutory
definition is not limited to âadversar[ies],â 10 U.S.C.
§ 3252(d)(4), and instead covers âany person,â which cannot
refer only to foreign entities, 41 U.S.C. § 4713(k)(6).
Likewise, we reject the dissentâs use of legislative history, post,
at 7â8, to glean the ordinary public meaning of the seven verbs
in the definition.
In sum, we conclude that the Secretaryâs concern about
Anthropic disabling Claude from performing lawful actions
under section 3252, the issues flagged by Anthropic are not the same
in both cases. So, for example, the Northern Districtâs determination
that the section 3252 designation was arbitrary does not control our
determination whether the section 4713 designation was arbitrary.
Likewise, the Northern Districtâs determination of exigency under
section 3252 does not control our determination of exigency under
section 4713. In any event, Congress gave this Court exclusive
jurisdiction to review procurement actions taken pursuant to section
4713 designations, see 41 U.S.C. § 1327(b)(1), and it specifically
barred other courts from reviewing any other âaction taken underâ
section 4713, see id. § 1327(a). That strict âallocation of
jurisdictionâ to this Court makes it inappropriate to constrain our
review based on the Northern Districtâs judgment. Restatement
(Second) of Judgments § 28 (1982); see Shaw v. State of Cal. Depât
of Alcoholic Beverage Control, 788 F.2d 600, 607â09 (9th Cir.
1986); Lyons v. Westinghouse Elec. Corp., 222 F.2d 184, 188â89 (2d
Cir. 1955) (L. Hand, J.).
32
requested by the Department qualifies as a âsupply chain riskâ
within the meaning of section 4713.
B
The Secretary also concluded that less intrusive measures
were not reasonably available to reduce the supply-chain risk
posed by Anthropic. We have already explained that the
Departmentâs concerns are serious and fall within the statutory
definition. Anthropic all but acknowledges that such concerns
would justify the termination of its subcontracts with the
Department. Even so, Anthropic objects that the Departmentâs
invocation of section 4713, as opposed to more conventional
procurement authorities, had the additional effect of
âbrandingâ the company as a national-security threat, which
assertedly harmed its reputation. Reply Br. at 21â22. One may
fairly question whether Anthropic has suffered any such harm,
as rapid increases in the companyâs valuation since the
Secretaryâs section 4713 determination reportedly have made
it one of the most valuable business concerns in the world. See,
e.g., Clark, Anthropic Was Behind. Now Itâs the AI Boomâs
Front-Runner, Wall St. J. (May 13, 2026) (âAnthropic has
received investment offers in recent months valuing it at more
than $900 billionâ). Regardless, Anthropic has not explained
why it would suffer any less of a stigma if the Department had
articulated the very same national-security concerns to
announce the elimination of Claude from its supply chain
through more conventional contract-termination authorities.
Alternatively, Anthropic suggests in one sentence that the
Department should have â[n]arrow[ed] any restriction to the
subset of systems plausibly involving lethal autonomous
warfare or domestic mass surveillance.â Br. for Petâr at 48.
This fleeting statement did not preserve the point. Schneider v.
Kissinger, 412 F.3d 190, 200 n.1 (D.C. Cir. 2005). In any
33
event, the suggestion overlooks the fact that, when an AI model
is âlayered into other applications,â the model can âlimit the
functionality of that larger system.â App. 214â15. Once the
Secretary identified the risk that Claude posed, he sought to
avert it by making a clean break instead of courting the delay,
expense, and uncertainty that would result from a granular
inquiry into every possible use of Claude by each of the
Departmentâs prime contractors. The Secretary reasonably
concluded that less intrusive measures were not reasonably
available, and we cannot override that fact-based, national-
security assessment.
C
Anthropic contends that the Secretary impermissibly
found that an âurgent national security interest require[d] the
immediate exerciseâ of his authority to exclude Anthropic from
the Departmentâs supply chain. 41 U.S.C. § 4713(c). Without
such an emergency, the Secretary would have had to provide
Anthropic with advance notice and an opportunity to respond
before making the exclusion. See id. § 4713(b). Anthropic
faces strong headwinds in asking us to override the Secretary
of Warâs assessment of national-security exigencies. But even
assuming that this assessment was both reviewable and wrong,
Anthropic cannot show any prejudice from the timing of the
Secretaryâs notice.
1
âIn administrative law, as in federal civil and criminal
litigation, there is a harmless error rule.â Combat Veterans for
Cong. Pol. Action Comm. v. FEC, 795 F.3d 151, 156â57 (D.C.
Cir. 2015) (quoting Natâl Assân of Home Builders v. Defs. of
Wildlife, 551 U.S. 644, 659â60 (2007)); see also Shinseki v.
Sanders, 556 U.S. 396, 406 (2009) (harmless-error rules
âordinarily apply in civil casesâ). The rule traces back to pre-
34
APA caselaw, where courts would require a prejudicial error in
order to set aside agency action. See Mkt. St. Ry. Co. v. R.R.
Commân of State of Cal., 324 U.S. 548, 562 (1945). The APA
then codified the rule, directing that reviewing courts take âdue
account ⌠of the rule of prejudicial error.â 5 U.S.C. § 706. As
early commentators observed, the APA merely âsum[med] up
⌠the âharmless errorâ rule applied by the courts in the review
of lower court decisions as well as of administrative bodies,
namely, that errors which have no substantial bearing on the
ultimate rights of the parties will be disregarded.â Attây Gen.âs
Manual on the Admin. Proc. Act 110 (1947) (APAâs
prejudicial-error rule âappears to restate existing lawâ).
Moreover, some form of the prejudicial-error rule is ubiquitous
in civil cases, criminal cases, and appeals. See 28 U.S.C.
§ 2111 (in any appeal, courts must apply a â[h]armless errorâ
rule, disregarding âerrors or defects which do not affect the
substantial rights of the partiesâ); Fed. R. Civ. P. 61 (âAt every
stage of the proceeding, the court must disregard all errors and
defects that do not affect any partyâs substantial rights.â); Fed.
R. Crim. P. 52(a) (âAny error, defect, irregularity, or variance
that does not affect substantial rights must be disregarded.â).
So âthe âharmless errorâ principle announced for our general
jurisprudence by decision and statute ⌠is applicable to the
review of the decisions of administrative agenciesââeven
outside the APA itself. Braniff Airways, Inc. v. Civil
Aeronautics Bd., 379 F.2d 453, 465 (D.C. Cir. 1967).
We have repeatedly applied such prejudicial-error rules in
judicial-review schemes that do not explicitly impose them.
For example, in Chai v. Depât of State, 466 F.3d 125 (D.C. Cir.
2006), we found harmless error in reviewing the designation of
an entity as a foreign terrorist organization. Id. at 132â33. The
governing judicial-review scheme there, set forth in the
Antiterrorism and Effective Death Penalty Act (AEDPA),
imposed APA-like standards of review but no express
35
requirement of prejudicial error. See 8 U.S.C. § 1189(c).
Likewise, in Saunders v. Kijakazi, 6 F.4th 1 (D.C. Cir. 2021),
we conducted harmless-error review (but found the errors there
prejudicial) in a case governed by the judicial-review
provisions of the Social Security Act, which also does not
expressly require that courts consider harmless error. Id. at 4;
see 42 U.S.C. § 405(g). These cases accord with a background
principle that reviewing courts must not become âimpregnable
citadels of technicality.â Shinseki, 556 U.S. at 407â08 (quoting
Kotteakos v. United States, 328 U.S. 750, 759 (1946)). More
generally, they confirm another background principle that âthe
law cares not for trifles.â Wisc. Depât of Revenue v. William
Wrigley, Jr., Co., 505 U.S. 214, 231 (1992).
Here, Anthropic failed to show any prejudice from not
having received an advance opportunity to respond. By March
19, just over two weeks after the determination to exclude
Claude from the Departmentâs supply chain, the agency had
provided Anthropic with notice of that action and the materials
on which it was based. App. 72, 224. The Department also
invited Anthropic to submit any âinformation or arguments in
opposition to this notice.â Id. at 224. Anthropic made such a
submission, including a letter from counsel and the various
evidentiary materials also submitted to this Court. The
prejudice inquiry thus boils down to the question whether these
materials, if provided sooner, may have changed the
Departmentâs decision. See PDK Labs, Inc. v. DEA, 362 F.3d
786, 799 (D.C. Cir. 2004) (âIf the agencyâs mistake did not
affect the outcome, if it did not prejudice the petitioner, it
would be senseless to vacate and remand for reconsideration.â).
We are confident that, just as these materials did not
convince the Department to rescind the supply-chain exclusion
in June, they would not have affected the Departmentâs
decision to initiate the exclusion in March. As the Secretary
36
explained on rehearing, much of the information submitted by
Anthropicâsuch as the partiesâ contractual and negotiating
historyâwas âalready known to the Department.â Suppl. Br.
for Respâts, Add. 1. And much of the color and nuance in the
materialsâregarding just how deeply committed Anthropic is
to its model training and use restrictionsâreinforced the
concerns expressed by Under Secretary Michael. The only
new, potentially helpful piece of information provided by
Anthropic was its explanation that, although the company uses
âtechnical measuresâ to monitor ongoing use and prevent
misuse by private customers, App. 8, it has no such ability with
respect to models deployed on the Departmentâs classified
systems, id. at 287â88. But as the Secretary made clear in
denying rehearing, his original decision did not rest on the
premise that Anthropic was willing and able to monitor
ongoing use, and prevent perceived misuse, by the Department
once it had received the relevant models. Suppl. Br. for
Respâts, Add. 1. In reviewing the Departmentâs decision, we
may consider this âamplified articulationâ of its original
rationale. DHS v. Regents of the Univ. of Cal., 591 U.S. 1, 20
(2020); see also Camp v. Pitts, 411 U.S. 138, 143 (1973).
2
Anthropicâs counterarguments are unpersuasive.
First, it contends that harmless-error review cannot apply
in this case because the governing judicial-review provision
here requires that this Court âshall hold unlawfulâ supply-chain
designations ânot in accord with procedures required by law.â
41 U.S.C. § 1327(b)(2), (2)(E). But the AEDPA provision for
judicial review of foreign terrorist organization designations
uses equally mandatory language, in stating that the reviewing
court âshall hold unlawful and set asideâ FTO designations
ânot in accord with the procedures required by law.â 8 U.S.C.
37
§ 1189(c)(3), (3)(E). Yet we denied review of a due-process
claim on the ground that âthe alleged errors were, in the
particular circumstances of th[at] case, clearly rendered
harmless.â Chai, 466 F.3d at 132. Moreover, as explained
above, the rule of prejudicial error is a ubiquitous feature of
judicial-review schemes despite the equally ubiquitous
presence of such âshall set asideâ provisions.
Second, Anthropic contends that delayed notice here was
prejudicial because âpsychological and bureaucratic realitiesâ
might have locked the Department into its exclusion regardless
of the strength of any later showing. New Jersey, Depât of
Envât Prot. v. EPA, 626 F.2d 1038, 1050 (D.C. Cir. 1980). In
the case Anthropic invokes, we held that an agencyâs failure to
follow notice-and-comment rulemaking procedures is
prejudicial despite an opportunity to submit comments after
promulgation of the final rule. See id. at 1049. In significant
part, we reasoned that many prospective commenters may be
unlikely to bother once a final rule was already in place. See
id. Here, in contrast, the only question is whether an earlier
submission by Anthropic would have made any difference, and
we have no reason to think that the timing of its actual
submission caused Anthropic to pull any punches. Moreover,
Anthropic does not explain why its preferred remedyâholding
the exclusion unlawful for lack of advance notice and an
opportunity to be heardâwould be any less susceptible to the
same bureaucratic objection. We can hold unlawful the
exclusion on procedural grounds, but we cannot prevent the
Secretary from considering whether to reimpose it after
reviewing whatever materials Anthropic may submit. Nor can
we make the Secretary forget that, after considering
Anthropicâs full submission the last time around, he chose to
maintain the exclusion. Under these circumstances, requiring
another go-round would be pointlessâthe very type of futile
gesture that the prejudicial-error rule avoids.
38
Third, Anthropic argues that reviewing for harmless error
would eviscerate the advance-notice requirement because the
agency could freely skip it, offer post-exclusion process, and
then be insulated from judicial review. But even with a
harmless-error rule in place, the advance-notice requirement
still has teeth. Immediately after a suspect urgency
determination, an aggrieved party could seek interim relief
before any post-exclusion process had run its course. To
demonstrate prejudice in that context, the petitioner would
simply need to show that it could âmount a credible challengeâ
to the exclusion if afforded the opportunity. Gerber v. Norton,
294 F.3d 173, 184 (D.C. Cir. 2002) (quoting Util. Solid Waste
Activities Grp. v. EPA, 236 F.3d 749, 755 (D.C. Cir. 2001)).
But the analysis changes after a petitioner has received the
post-designation process, which can cure the lack of earlier
process. When a petitioner has already mounted a failed
challengeâas in this caseâit can no longer show prejudice
from failing to receive an earlier opportunity to be heard.
For these reasons, we hold that Anthropic has suffered no
prejudice from the Secretaryâs determination that an urgent
national-security interest required Claudeâs immediate
exclusion from the Departmentâs supply chain.
V
Finally, Anthropic contends that its exclusion from the
Departmentâs supply chain violates the Fifth and First
Amendments to the Constitution.
A
The Fifth Amendment prohibits the federal government
from depriving any person of âlife, liberty, or property, without
due process of law.â We assume that the Departmentâs
exclusion of Anthropic from its supply chain deprived the
39
company of protected liberty or property interests. Anthropic
contends that the âdueâ process for such deprivations included
a right to contest the exclusion before it became effective. As
a general matter, due process requires notice and an
opportunity to respond âbefore the government can
constitutionally deprive a person of the protected liberty or
property interest.â Natâl Council of Resistance of Iran v. Depât
of State, 251 F.3d 192, 205 (D.C. Cir. 2001) (NCRI). But âdue
process is flexible and calls for such procedural protections as
the particular situation demands.â Id. (quoting Morrissey v.
Brewer, 408 U.S. 471, 481 (1972)). So, âwhere [the
government] must act quickly, or where it would be impractical
to provide predeprivation process, postdeprivation process
satisfies the requirements of the Due Process Clause.â Zevallos
v. Obama, 793 F.3d 106, 116 (D.C. Cir. 2015) (quoting Gilbert
v. Homar, 520 U.S. 924, 930 (1997)) (cleaned up). Post-
deprivation process thus suffices where the government seeks
to seize movable assets, id.; destroy unwholesome food, N. Am.
Cold Storage Co. v. City of Chicago, 211 U.S. 306, 315 (1908);
or terminate disability benefits, Mathews v. Eldridge, 424 U.S.
319, 349 (1976). Likewise, it suffices where âearlier
notification would impinge upon the security and other foreign
policy goals of the United States.â Peopleâs Mojahedin Org.
of Iran v. Depât of State, 613 F.3d 220, 227 n.4 (D.C. Cir. 2010)
(quoting NCRI, 251 F.3d at 208).
The need to move quickly was present here, as reflected in
the Secretaryâs finding that immediate action was necessary.
The parties agree that AI technology is now evolving at
âunprecedented velocity,â with models âbecoming smarter and
more robust every day.â App. 205 (Department strategic plan);
see also id. at 85 (Amodei acknowledging âa smooth,
unyielding increase in AIâs cognitive capabilitiesâ). They
likewise agree that reliable AI technology is critical for the
United States to maintain its military superiority and preserve
40
its national security. Id. at 202â07 (Department strategic plan);
id. at 106 (Amodei on prospect of âunbeatable armyâ
controlled by AI). As explained above, Anthropic definitively
rejected usage terms demanded by the United States, in the
wake of a significant controversy regarding the Departmentâs
use of Claude in an overseas military operation. And two days
after Anthropic did so, the United States began offensive
military operations in Iran, reportedly using Claude in
connection with its strikes. See Weisgerber et al., U.S. Strikes
in Middle East Use Anthropic, Hours After Trump Ban, Wall
St. J. (Feb. 28, 2026). Given all this, the Department did not
act unconstitutionally by moving to exclude Claude from its
supply chain and shift to other AI providers immediately, while
providing Anthropic with notice and an opportunity to respond
almost immediately thereafter.
Anthropic offers two objections to the Departmentâs claim
of urgency. First, it argues that any national-security risk posed
by Claude could not have been urgent, since the Department
had been deploying Claudeâwith usage restrictionsâfor over
a year. But as shown above, the Departmentâs use of Claude
initially was limited and occurred only through contractors; and
Anthropic gradually loosened various usage restrictions as it
sought to expand its relationship with the Department.
Moreover, the dispute did not come to a head until early 2026,
when the Department developed its AI strategic plan and
Anthropic definitively rejected the Departmentâs request for an
âall lawful usesâ authorization. Around the same time, a
potentially serious dispute arose regarding Claudeâs use in
connection with one military conflict, which revealed
operational concerns as another conflict began to unfold. The
timing of these events confirms the Departmentâs legitimate
sense of urgency. Second, Anthropic argues that any national-
security risk cannot be urgent because the Department
permitted use of Claude for six months after the exclusion. But
41
the Department ordered Claude removed from its supply chain
âas soon as practical,â with the six-month period established
only as an outer bound. App. 80. And it later explained that
the outer bound reflected the technical and operational
challenges with âremov[ing] the technology from all DoW
systems immediately, particularly in the midst of active
operations.â Id. at 216. Again, we are unwilling to second-
guess that fact-based judgment of national security. See Trump
v. Hawaii, 585 U.S. at 704; HLP, 561 U.S. at 33.
B
The First Amendment provides that âCongress shall make
no law ⌠abridging the freedom of speech.â The Supreme
Court has held that the Amendment âprohibits government
officials from subjecting an individual to retaliatory actions for
engaging in protected speech.â Nieves v. Bartlett, 587 U.S.
391, 398 (2019) (cleaned up). To succeed on such a First
Amendment retaliation claim, the plaintiff or petitioner must
prove that (1) it engaged in protected speech, (2) the
government took materially adverse action against it, and (3)
the speech caused the materially adverse action. See Houston
Cmty. Coll. Sys. v. Wilson, 595 U.S. 468, 477â79 (2022); Aref
v. Lynch, 833 F.3d 242, 258 (D.C. Cir. 2016).
Anthropic has satisfied the first and second prongs of this
test, but not the third. The First Amendment squarely protects
Anthropicâs advocacy regarding the safe and appropriate use of
AI products. Moreover, the Departmentâs exclusion of Claude
from its supply chain plainly qualifies as a materially adverse
action. However, we can discern no causal connection between
the two. Instead, the record makes clear that the Department
removed Anthropic from its supply chain not because of its
advocacy, but because Anthropic refused to agree to a contract
term the Department deemed essential to national security.
42
Consider the timeline. By its own admission, Anthropic
has advocated for use and safety restrictions since its founding:
The company describes its own commitment to model safety
as âthe core of Anthropicâs mission,â App. 2, and describes its
use restrictions as reflecting âthe very purpose for which [the]
company was foundedâ and its âdeeply held values,â id. at 10.
But throughout 2024 and 2025, the Department never acted
adversely to Anthropic. Instead, it included Anthropic in a
$200 million AI contract awarded in July 2025, id. at 32â33,
and it sought to expand its relationship with Anthropic.
Additionally, in January 2026, Amodei published a long article
calling for âlimitsâ and âsafeguardsâ on the use of AI-powered
weapons in democracies. Id. at 106, 108. But instead of
retaliating against Anthropic because of this advocacy, the
Department continued to pursue negotiations. Only when the
negotiations broke down did the Department take action: On
February 24, the Secretary met with Amodei and demanded
that Anthropic accept an âall lawful usesâ term by February 27.
On February 26, Amodei published a final, public refusal to
assent to that term. On February 27, the Secretary announced
his intention to exclude Anthropic from the Departmentâs
supply chain. And on March 3, he made the formal, written
determination required by the Supply Chain Security Act.
Anthropic points to various pungent statements in the
Secretaryâs February 27 social media post. Among other
things, the Secretary denounced Anthropicâs âsanctimonious
rhetoric,â âvirtue-signaling,â and âSilicon Valley ideology.â
App. 77. Such rhetoric seldom provides a sound basis for
judging the lawfulness of federal executive action. See, e.g.,
Mullin v. Doe, 146 S. Ct. 2121, 2139 (2026); Trump v. Hawaii,
585 U.S. at 700â02. In any event, for all its flourishes, the
Secretaryâs social media post squarely addresses Anthropicâs
refusal to provide the âall lawful usesâ contractual
authorization. He described Anthropicâs behavior as a
43
âtextbook case of how not to do businessâ with the Pentagon.
App. 77 (emphasis added). He reiterated the Departmentâs
demand for âfull, unrestricted access to Anthropicâs models for
every lawful purpose in defense of the Republic.â Id. (cleaned
up). And he characterized Anthropicâs refusal to provide that
access as imposing an unacceptable âveto power over the
operational decisions of the United States military.â Id. The
nub of this dispute was contractual, and the First Amendment
did not require the Department to continue a contractual
relationship that it viewed as creating a national-security risk.
VI
This case raises profoundly difficult questions about the
appropriate military uses of an almost unimaginably powerful
new technology. The Secretary raises the deeply sobering
prospect of overly constrained AI models shutting down
unexpectedly and thus causing important military operations to
fail. Anthropic raises the deeply sobering prospect of
unconstrained AI models hallucinating inappropriate targets
for lethal military force. Both possibilities present obvious
national-security concerns. But in our Republic, it is the
President and the Secretary of War who must determine how
best to balance the competing risks. In doing so here, the
Secretary did not transgress any limits on his authority under
the Supply Chain Security Act or the Constitution.
Accordingly, we deny the petitions for review.
So ordered.
KAREN LECRAFT HENDERSON, Circuit Judge, dissenting:
Whether the Secretary of the Department of War (Secretary)
lawfully invoked his statutory powers under the Federal
Acquisition Supply Chain Security Act of 2018 (FASCSA)
turns on whether Anthropic falls within the statuteâs definition
of a âsupply chain risk.â 10 U.S.C. § 4713(k)(6). âWhen
Congress takes the trouble to define the terms it uses,â Garland
v. Cargill, 144 S. Ct. 1613, 1627 n.9 (2024) (citation modified),
courts should apply them âwith rigor,â Antonin Scalia & Bryan
A. Garner, Reading Law: The Interpretation of Legal Texts 227
(2012) (interpretive-direction canon). And here, the Congress
has taken great pains to define the type of âsupply chain riskâ
that must exist before the Secretary invokes the sweeping
powers FASCSA confers on him. Under the statute, he may
exercise his authority to blacklist a procurement source from
the Departmentâs supply chains âonly afterâ the Department
concludes the source poses a âsignificantâ risk, 10 U.S.C. §
4713(b)(1), that it will:
sabotage, maliciously introduce unwanted
function, extract data, or otherwise manipulate
the design, integrity, manufacturing,
production, distribution, installation, operation,
maintenance, disposition, or retirement
of covered articles so as to surveil, deny,
disrupt, or otherwise manipulate the function,
use, or operation of the covered articles or
information stored or transmitted on
the covered articles.
10 U.S.C. § 4713(k)(6).
My colleagues do not dispute that whether Anthropic
qualifies under this definition depends entirely on the scope of
section 4713(k)(6)âs residual clause: âor otherwise
manipulate.â See Maj. Op. 23â26. The Department and
Anthropic offer competing definitions of that term. According
2
to Anthropic, the residual clause uses âmanipulateâ to denote
intentionally subversive acts, carried out through deceptive
means. Petâr Br. 40, n.2; see, e.g., Manipulate, Oxford English
Dictionary, https://perma.cc/9NF9-ME3B (âTo manage,
control, or influence in a subtle, devious, or underhand
manner.â). The Secretary argues, Respât Br. 42, and the
majority agrees, Maj. Op. 24, that the term encompasses much
more. To âmanipulateâ a covered article, in their view, means
to âmove, arrange, operate, or control [it] by the hands or
another body part or by mechanical means,â regardless of
purpose or motiveâfor example, how one might âmanipulateâ
a doorknob by turning it or a gas pedal by pressing it down.
Manipulate, American Heritage Dictionary of the English
Language (5th ed. 2022), https://perma.cc/B2FA-CM84 (âShe
manipulated the lights to get just the effect she wanted.â). Both
definitions may be linguistically possible but basic canons of
construction require us to decide which one fits best within
section 4713(k)(6)âs surrounding text, construed as a whole.
Because I believe that the context decidedly favors the
narrower reading, I respectfully dissent.
Section 4173(k)(6) begins by linking âmanipulateâ with
the opening list of verbs and modified verb phrases: âsabotage,
maliciously introduce unwanted function, extract data, or
otherwise manipulateâ specific aspects of a covered article.
The canon of noscitur a sociis teaches that âa word is known
by the company it keeps.â McDonnell v. United States, 579
U.S. 550, 569 (2016) (citation modified). If âwords [are]
grouped in a list,â they âshould be given related meanings.â
Third Natâl Bank in Nashville v. Impac Ltd., Inc., 432 U.S. 312,
322 (1977). Applied here, the correct definition of
âmanipulateâ aligns best with the examples that precede itâall
of which connote intentionally subversive and deceptive acts.
To âsabotageâ means to âruin, destroy or disableâ something
âdeliberately and maliciouslyâ and âfrequently by indirect,â
3
Sabotage, Oxford English Dictionary (3d ed. 2026),
https://perma.cc/E3B4-4JRV, or âunderhandedâ means,
Sabotage, American Heritage Dictionary of the English
Language, New College Edition (1976). To âmaliciously
introduce unwanted function [and] extract dataâ likewise
implies an âintention or desire to . . . cause injury.â Malice,
Oxford English Dictionary (3d ed. 2026),
https://perma.cc/Z499-HDYV. When we at last reach the âor
otherwise manipulateâ clause, the narrower meaningââto
manage, control, or influence in a subtle, devious, or underhand
mannerââfits well with its antecedents. Manipulate, Oxford
English Dictionary (3d ed. 2026), https://perma.cc/9NF9-
ME3B.
Section 4713(k)(6) uses âmanipulateâ to round out another
verb-object sequenceââso as to surveil, deny, disrupt or
otherwise manipulateâ an articleâs function, operation, use or
transmission and storage of information. And as with the
statuteâs first string of verbs, the verbs preceding âmanipulateâ
in the second series connote some intentionally hostile or
clandestine purpose with respect to a covered article. Surveil,
Oxford English Dictionary (3d ed. 2026),
https://perma.cc/B4UZ-KWWV (âTo exercise surveillance
over (someone).â); Surveillance, Oxford English Dictionary
(3d ed. 2026), https://perma.cc/6YR5-H9S7 (âWatch or guard
kept over a person . . . often, spying, supervision.â); Disrupt,
American Heritage Dictionary of the English Language (5th
ed. 2022), https://perma.cc/7MEA-ZRWQ (âTo throw into
confusion or disorderâ or â[t]o interrupt or impede the progress
ofâ); Deny, American Heritage College Dictionary (4th ed.
2007) (âTo decline to grant or allow; refuse.â). Here again, the
more tailored meaning of âmanipulateâ completes the list of
verbs with semantic precision. See, e.g., Manipulate, Merriam-
Websterâs Collegiate Dictionary (11th ed. 2003) (âTo control
4
or play upon by artful, unfair, or insidious means esp. to oneâs
own advantage.â).
Without expressly invoking the noscitur a sociis canon,
my colleagues give several semantic reasons to resist its
application. Maj. Op. 24. But their arguments follow neither
the plain text of section 4713(k)(6) nor well-settled canons.
They assert that section 4713(k)(6)âs first parallel verb list is
not sufficiently âtightâ to qualify for the canon because two of
the verbs (âintroduceâ and âextractâ) have direct objects in
front of them (âunwanted functionâ and âdataâ). Id. Yet the
canon hardly demands such exactitude. See United States v.
Fischer, 64 F.4th 329, 375 (D.C. Cir. 2023) (Katsas, J.,
dissenting) (correctly observing that a âlistingâ is not even a
âprerequisiteâ for the canon) (citation modified), revâd, Fischer
v. United States, 144 S. Ct. 2176 (2024); accord Scalia &
Garner, supra, at 197 (âAn âassociationâ is all that is
required.â). A listing that âinvolves . . . verbs and verb
phrasesâ is plainly enough. Id. (emphasis added).
My colleagues also assert that the verbs included in section
4713(k)(6)âs lists lack a common quality of harmful or
subversive intent. Starting with the statuteâs first verb
sequence, they concede, as they must, that âsabotageâ
âconnotes intentionally hostile acts.â Maj. Op. 23. But they
conclude that âintroduc[ing] unwanted functionâ carries no
such connotation if it is cut off from its modifier âmaliciously.â
Id. Respectfully, I disagree with that approach: â[I]t is a
fundamental principle of statutory construction (and, indeed, of
language itself) that the meaning of a word cannot be
determined in isolation, but must be drawn from the context in
which it is used.â Reno v. Koray, 515 U.S. 50, 56 (1995)
(citation modified); Fischer, 64 F.4th at 365 (Katsas, J.,
dissenting) (â[W]e do not divorce isolated words and phrases
from their statutory context.â). They conclude next that the
5
verb phrase âextract dataâ connotes no harmful motive at all,
Maj. Op. 23, but like its next-door neighbor (âintroduce
unwanted functionâ), it is preceded by the adverb
âmaliciously,â 10 U.S.C. § 4713(k)(6). Under the series-
qualifier canon, âa prepositive modifierâ before a series of
verbs or verb phrases ânormally applies to the entire series,â
not only the verb that immediately follows. Scalia & Garner,
supra, at 147; id. at 148 (explaining âwillfully damage or
tamper withâ modifies âboth damage and tamper with.â)
(emphasis added). Thus, a library might post a sign saying,
âDo not shout, loudly talk on the phone, play music, or
otherwise disturb others.â The common understanding would
be that the rule bans bringing a boom-box into the reading room
with the volume turned on high but not listening to music with
headphones set at a modest sound levelâeven though both
constitute âplaying music.â As with the âloudlyâ modifier,
section 4713(k)(6)âs âmaliciouslyâ extends beyond its head
phrase âintroduce unwanted functionâ to limit âextract data,â
as well.
With respect to section 4713(k)(6)âs second verb chain, the
majority concludes that the verbs are either âambiguousâ as to
motive (âsurveilâ and âdisruptâ) or âclearlyâ neutral on that
score (âdenyâ). Maj. Op. 24. But this repeats the same
mistake, in my view, of relying on statutory terms in isolation.
Fischer, 64 F.4th at 363 (Katsas, J., dissenting) (âPerhaps no
interpretive fault is more common than the failure . . . to
consider the entire text.â) (quoting Scalia & Garner, supra, at
167). To âsurveilâ or âdenyâ something, of course, does not
always imply nefarious intent: âThe police officer surveilled
the suspectâs last known whereaboutsâ or âthe cashier denied
my credit card for insufficient funds.â And âdisruptingâ
something can be unintentional: âThe weather disrupted our
travel plans.â But viewed in their statutory context, the verbs
at issue are all directed at deliberately impeding or
6
eavesdropping on the âfunction, use, or operationâ of a covered
article that has entered the federal supply chain. 10 U.S.C. §
4713(k)(6). And once paired with the terms in the first verb-
object sequenceâe.g., âmaliciously introduc[ing] unwanted
functionâ into a covered article to âdenyâ its use,
âsabotag[ing]â the article to âdisruptâ its operation,
âmaliciously . . . extracting dataâ from the article to âsurveilâ
the information it stores or transmits informationâthe statuteâs
focus on harmful motive becomes impossible to ignore.
Reading section 4713(k)(6)âs âor otherwise manipulateâ
clause as limited by the intentionally hostile and deceptive acts
described in section 4716(k)(6) becomes even plainer âunder
the related canon of ejusdem generis.â Fischer, 144 S. Ct. at
2184. That rule declares that, if a statute introduces a list of
specifics followed by a catchall phrase, we should construe the
general phrase as âcontrolled and definedâ by the examples
âthat precede it.â Id. (citation modified). The canon ensures
that courts âgive effect, if possible, to every clause and word of
a statute,â Williams v. Taylor, 529 U.S. 362, 404 (2000), and
reflects âthe basic logic that Congress would not go to the
trouble of spelling out [a] listâ of examples only to tack on a
general clause that makes them irrelevant. Fischer, 144 S. Ct.
at 2185. Faithful application of that principle requires us to
read section 4713(k)(6)âs residual clause as targeting a class of
interference with a covered article that is not so broad as to read
out the statuteâs numerous examples of deliberately obstructive
and surreptitious acts: âsabotag[ing],â âsurveil[ing],â
âdisrupt[ing],â âdeny[ing]â and âmaliciouslyâ inserting a
function into or extracting data from a covered article. And for
reasons I have explained, the narrower reading of âmanipulateâ
effortlessly follows that rule.
In adopting the Secretaryâs neutral definition of
âmanipulate,â todayâs decision ârenders an unnerving amountâ
7
of section 4716(k)(6)âs motive-infused language âmere
surplusage.â Fischer, 144 S. Ct. at 2190. Using the Secretaryâs
sterilized definition, the majority concludes that a contractor
immediately poses ânot only a âriskâ . . . but a certaintyâ of
âmanipulat[ing]â a covered article, Maj. Op. 23, if it is âwilling
and able to enforce contractual restrictionsâ on an articleâs
functioning, id. at 19, that the Department deems
âunreasonably restrictive,â J.A. 181. It matters not if the
restrictions are ones the Department has already agreed to.
And it is immaterial if the contractor enforces the restrictions
based on a good faith and legally correct interpretation of them.
It does not even seem to matter under the Departmentâs reading
if those contractual and technical safeguards prevent the
Department from deploying the covered article in a manner that
violates federal or constitutional law. The Department here
made good on its promise to designate Anthropic a supply
chain risk after Anthropic declined the Secretaryâs ultimatum
to replace its use restrictions on Claude with a general
provision permitting âall lawful uses.â Maj. Op. 9. But
suppose the Secretary tells Anthropicâs presumed replacement
to change its AI-use policies to permit any âfunctions that the
Department deems necessaryâ or it will share the same fate as
Anthropic. Id. at 20. According to todayâs decision, that
contractor will have a choice: Agree to the Secretaryâs
demands or risk being designated a national security threat
under FASCSA.
I cannot agree that this is the scenario the Congress had in
mind when it enacted FASCSA. It enacted the statute in
response to calls from the U.S. intelligence community for
legislation to meet the threat of â[h]ostile nation state and other
bad actorsâ infiltrating the federal governmentâs information
and technology systems through its supply chains. S. Rep. No.
115-408, at 2 (2018). For years, national security agencies had
warned that companies âbeholden to foreign governments,â
8
Open Hearing on Worldwide Threats: Hearing Before the S.
Select Comm. on Intel., 115th Cong. 64 (2018) (statement of
Chris Wray, Dir. of the Fed. Bureau of Investigation), and other
malicious actors were introducing compromised products into
â[m]any of the technologies the Federal Government relie[d]
on for vital, daily functions,â S. Rep. No. 115-408, at 2. In their
published reports, the agencies described numerous covert
security breaches carried out by nefarious actorsâand in terms
that closely track section 4713(k)(6)âs key terms. See, e.g.,
Tara Beeny, U.S.-China Econ. & Sec. Rev. Commân, Supply
Chain Vulnerabilities from China in U.S. Federal Information
and Communications Technology 23, 27, 34 (Apr. 2018)
(describing attacks in which bad actors attempted to âextract
proprietary source code,â â[]install[ed] unwanted softwareâ
onto compromised computers, and âsurveil[ed] and
manipulate[d] users by hacking . . . embedded [computer]
firmwareâ). Such historical evidence showing how a statuteâs
terms were used pre-enactment sheds light on what sense those
words are meant to carry when the Congress writes them into
law. Bostock v. Clayton County, 140 S. Ct. 1731, 1749â50
(2020). That history supports Anthropicâs reading. And it
refutes the view that âmanipulat[ion]â of a covered article
encompasses anything like the conduct that, under todayâs
holding, gives rise to a supply chain riskâthat is, a contractorâs
honest and upfront enforcement of restrictions on a covered
articleâs use disfavored by the government.
For the foregoing reasons, I respectfully dissent.