Home › Intelligence › Brief
BREACH BRIEF 🟠 High ThreatIntel

U.S. Appeals Court Upholds Pentagon Blacklisting of Anthropic as Supply‑Chain Risk

The D.C. Circuit affirmed the DoD’s authority to blacklist Anthropic under the Federal Acquisition Supply Chain Security Act, treating AI model restrictions as a supply‑chain risk. This underscores the need for continuous third‑party risk monitoring and auditable governance for AI services used by federal contracts.

Verisq™ Intelligence · 📅 September 26, 2026 · 📰 databreachtoday.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
databreachtoday.com

U.S. Appeals Court Upholds Pentagon’s Blacklisting of Anthropic as a Supply‑Chain Risk

What Happened — The D.C. Circuit Court ruled 2‑1 that the Department of Defense was within its authority to remove Anthropic, the creator of Claude AI models, from the federal supply chain under the Federal Acquisition Supply Chain Security Act. The decision follows a conflicting ruling from a California federal judge that had favored Anthropic.

Why It Matters for Trust & Control Assurance

  • The ruling treats AI model restrictions as a supply‑chain risk, highlighting the need for continuous third‑party risk assessment and documented governance of AI services used by government contracts.
  • Organizations must be able to demonstrate that they evaluate vendor‑provided AI controls, maintain evidence of risk‑based decisions, and have an auditable trail for procurement reviews.
  • This scenario maps directly to Verisq’s Third‑Party Risk Management capability, which provides continuous monitoring and evidence collection for supplier risk‑based decisions.

Who Is Affected

  • Federal agencies and defense contractors that source AI models or services.
  • AI vendors supplying models to government customers.

Recommended Actions

  1. Review your AI vendor contracts against the Federal Acquisition Supply Chain Security Act requirements and document any risk‑mitigation controls.
  2. Deploy continuous monitoring of third‑party AI services to capture governance evidence (e.g., model guardrails, usage restrictions) for audit readiness.

Technical Notes – The court’s decision hinges on the interpretation that “outward malicious intent” is not required for a supplier to be deemed a supply‑chain risk when the design or operation of its product can be manipulated. This legal precedent expands the scope of supply‑chain risk assessments to include AI model governance and usage policies. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/us-appeals-court-backs-pentagon-blacklisting-anthropic-a-32941 ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →