U.S. Appeals Court Upholds Pentagon’s Blacklisting of Anthropic as a Supply‑Chain Risk
What Happened — The D.C. Circuit Court ruled 2‑1 that the Department of Defense was within its authority to remove Anthropic, the creator of Claude AI models, from the federal supply chain under the Federal Acquisition Supply Chain Security Act. The decision follows a conflicting ruling from a California federal judge that had favored Anthropic.
Why It Matters for Trust & Control Assurance
- The ruling treats AI model restrictions as a supply‑chain risk, highlighting the need for continuous third‑party risk assessment and documented governance of AI services used by government contracts.
- Organizations must be able to demonstrate that they evaluate vendor‑provided AI controls, maintain evidence of risk‑based decisions, and have an auditable trail for procurement reviews.
- This scenario maps directly to Verisq’s Third‑Party Risk Management capability, which provides continuous monitoring and evidence collection for supplier risk‑based decisions.
Who Is Affected
- Federal agencies and defense contractors that source AI models or services.
- AI vendors supplying models to government customers.
Recommended Actions
- Review your AI vendor contracts against the Federal Acquisition Supply Chain Security Act requirements and document any risk‑mitigation controls.
- Deploy continuous monitoring of third‑party AI services to capture governance evidence (e.g., model guardrails, usage restrictions) for audit readiness.
Technical Notes – The court’s decision hinges on the interpretation that “outward malicious intent” is not required for a supplier to be deemed a supply‑chain risk when the design or operation of its product can be manipulated. This legal precedent expands the scope of supply‑chain risk assessments to include AI model governance and usage policies. Source: DataBreachToday