Logo
FrontierNews.ai

Why Anthropic Refused to Remove Claude's Safety Guardrails, and What It Cost the Company

A divided U.S. appeals court has upheld the Pentagon's decision to exclude Anthropic and its Claude AI models from Defense Department contracts, after the company refused to remove safety restrictions on autonomous weapons and mass surveillance. The 2-1 ruling by the U.S. Court of Appeals for the District of Columbia Circuit allows the military to maintain Anthropic's designation as a national-security supply-chain risk, marking a major victory for the Trump administration and Defense Secretary Pete Hegseth.

What Exactly Did Anthropic Refuse to Do?

The dispute centers on a fundamental disagreement about who controls how AI systems are used once they leave the developer's hands. Anthropic built safety restrictions into Claude that prevent the model from being used for certain military applications. The Pentagon demanded that Anthropic make Claude available for "all lawful uses," but the company refused, arguing that the demand was too broad and could require Claude to support operations that violate its safety principles.

Specifically, Anthropic's safeguards limit Claude's use in systems that could independently select and attack targets, conduct mass surveillance without meaningful human oversight, or support civilian espionage. CEO Dario Amodei made clear the company would not remove those guardrails, even when negotiations over a framework agreement worth approximately $200 million collapsed.

The Pentagon's position was straightforward: military agencies must have access to tools needed for national security and cannot accept technical restrictions that may interfere with lawful operations. Defense officials argued that Claude's built-in limitations could unexpectedly interrupt legitimate military operations, making the system unreliable for national-security missions.

How Did the Court Justify the Pentagon's Ban?

Writing for the majority, Judge Gregory Katsas, joined by Judge Neomi Rao, said the Defense Department had ample legal grounds to act under the Federal Acquisition Supply Chain Security Act of 2018, known as FASCSA. The law was originally designed to protect federal procurement systems against infiltration, sabotage, or manipulation by foreign adversaries, but the court interpreted it broadly to cover Anthropic's situation.

The judges accepted the Pentagon's argument that Anthropic's restrictions could prevent Claude from performing functions the department considered lawful and necessary. They also rejected Anthropic's claim that the government retaliated against the company because of its views on AI safety and military ethics. The court concluded that the Pentagon acted because Anthropic would not accept essential contract terms, not because the company had publicly criticized military applications of artificial intelligence.

Judge Karen LeCraft Henderson, the dissenting judge, disagreed sharply. She argued that FASCSA should not be used to classify a company as a supply-chain risk simply because it enforces contractual or ethical limits on its own technology. Henderson warned that the government's interpretation could give federal agencies broad power to exclude technology companies that refuse to accept expansive contract demands.

What Are the Broader Implications for AI Companies and National Security?

The ruling creates a tension between two competing interests. On one side, Anthropic and other AI developers argue they have a responsibility to prevent their products from being used in autonomous warfare or indiscriminate surveillance, even if the government describes those uses as legal. On the other side, the Pentagon says military agencies must have access to tools needed for national security and cannot accept technical restrictions that may interfere with lawful operations.

The decision raises several critical concerns for the broader technology industry:

  • Corporate Autonomy: If companies know that refusing military applications could result in blacklisting from defense contracts, they may become less willing to impose safety restrictions on their own technology.
  • Race to the Bottom: The ruling could encourage a competitive race among AI developers to offer fewer limitations in order to win defense contracts, potentially undermining industry-wide safety standards.
  • Administrative Power: The case raises questions about whether the government's interpretation of FASCSA gives federal agencies excessive power to exclude technology companies based on procurement disputes rather than genuine security threats.
  • First Amendment Concerns: Anthropic argued that the Pentagon's designation violated the company's First Amendment rights by punishing it for publicly advocating for AI safety, though the appeals court rejected this claim.

The appeals court's reasoning creates a distinction between a company's right to express opinions about AI safety and the government's authority to decide which suppliers it will use. Critics argue this distinction is not clear-cut, since the government's action came directly after Anthropic rejected a demand to remove safeguards based on ethical principles.

How Might This Ruling Reshape AI Development?

The decision does not prohibit all commercial use of Claude. It allows the Pentagon to exclude Anthropic from Defense Department contracts and military systems, while other government agencies and private companies may continue to work with the company under existing legal conditions.

However, the ruling stands in tension with a separate decision from a federal court in San Francisco, which previously found that a broader executive-branch attempt to blacklist Anthropic was unlawful. That California decision blocked a general ban imposed by the White House but did not eliminate the Pentagon's authority to exclude Claude from military contracts. The two rulings address different government actions and are based on different legal questions.

Supporters of the Pentagon's position argue that national-security systems cannot depend on models that may refuse tasks or interrupt operations unexpectedly. They contend that the government must be able to assess whether an AI system is reliable and available for lawful missions. Anthropic counters that reliability should include safety and predictable limits, not merely unrestricted compliance.

The case therefore raises fundamental questions about administrative power, government procurement, corporate speech, and the constitutional limits of national-security authority. As AI systems become increasingly central to military and intelligence operations, the tension between corporate safety principles and government control will likely intensify, potentially shaping how future AI companies approach military partnerships.