> For one, if the court’s statutory interpretation about the power to affect the operation of delivered software were correct, then pretty much any software product, at least those still subject to vendor-supplied updates, could be considered supply chain risks, given that any update could make substantive changes. In any case, it would seem to mean that any AI model would be too risky for the government to use, because there is nothing unusual about Anthropic’s model-control architecture—to the extent Anthropic could still control its model, so could any other AI vendor potentially control theirs. Whether they would or not would depend on the contract restraining them, and the only thing potentially different about Anthropic is that it did not want to be contractually obligated to allow certain functions that Hegseth really wanted—functions that were ethically dubious at best and monstrously dangerous at worst.
> But because that contractual reluctance upset Trump and Hegseth, they singled Anthropic out, alone, for negative treatment, turning their pique that “we can’t agree with Anthropic on how the software would need to be designed for us to be able to buy it” into “and because we can’t agree then NO ONE ELSE IN THE GOVERNMENT CAN EVER USE IT.” Per the DC Circuit, such an overbroad measure—after all, not every agency had the same concerns about changeability that the military might, yet Hegseth was deciding for them, too, whether they could use Claude, even when its architecture created no particular risk to them—and clearly punitive measure was perfectly fine because it implicated the implicit “national security” exception to the First Amendment the Founders apparently wrote into it in invisible ink.
[1] https://www.law.cornell.edu/uscode/text/10/3252
[2] https://www.techdirt.com/2026/09/25/dc-circuit-oks-hegseths-...