The federal government’s dispute with Anthropic moved from a negotiation over the permissible use of Claude to litigation over the government’s ability to designate a domestic artificial intelligence company to be a supply chain risk. This designation impacts government contractors who are receiving certification requests.

 

Background

 

The controversy arose after Anthropic resisted removing its restrictions on use of its AI models for mass domestic surveillance and fully autonomous lethal weapons. The government then designated Anthropic as a supply chain risk under two separate authorities: 10 U.S.C. § 3252, a federal statute granting the Department of Defense authority to manage supply chain risks by excluding specific sources or withholding subcontracting consent for sensitive national security and defense systems; and 41 U.S.C. § 4713, part of the Federal Acquisition Supply Chain Security Act framework that grants heads of federal executive agencies the authority to exclude sources or products from federal procurements to mitigate national security risks.  Anthropic challenged these actions in court proceedings, and the early rulings have created a mixed and unsettled compliance environment for government contractors.

 

At present, government contractors are receiving requests from military customers seeking certifications regarding their use of Anthropic products in contract performance. Reporting indicates, for example, that the Air Force Research Laboratory has directed contractors to identify, report, and remove Anthropic products on an accelerated schedule. These requests have generated uncertainty because they appear to apply supply chain risk concepts traditionally associated with foreign adversaries or prohibited technologies to a U.S.-based artificial intelligence company.

 

Recent discussions among government contracts practitioners indicate that contractors are receiving different certification and information requests, with varying scopes and certification language. That lack of consistency has created legitimate questions about what contractors are being asked to certify, what diligence is expected, and whether modified or qualified certification language is appropriate.

 

As the litigation continues, contractors should not assume that the existence of a preliminary injunction resolves the compliance obligations. One designation has been preliminarily enjoined, while the separate FASCSA designation remains the subject of ongoing litigation and has already prompted certification requests directed to contractors and subcontractors.

 

What do the Certification Requests Seek?

 

Although the requests vary, they generally seek information concerning:

 

  • Does the contractor use Anthropic products or services;
  • Whether Anthropic technology is incorporated into products or services provided to the government;
  • Does the contractor maintain business relationships with Anthropic; and
  • Whether Anthropic functionality is embedded within the contractor's software environment or supply chain.

 

Why Are Contractors Concerned?

 

The principal challenge is that the certification requests contain terms that are not clearly defined.  Questions include:

 

  • What is the scope "use" of Anthropic technology reached by the certification?
  • Does indirect use through a software provider constitute use under the certification?
  • Does internal business use matter if the technology is not used during contract performance?
  • Are contractors expected to certify only direct use or also embedded functionality within third-party software?

 

These questions can be difficult to answer because AI capabilities are integrated into commercial products and cloud-based services, making it challenging to identify all potential Anthropic touchpoints within their organizations.

 

The Litigation: Two Proceedings and Two Different Interim Results

 

Anthropic filed two related challenges. 

 

In the Northern District of California, Anthropic challenged the 10 U.S.C. § 3252 designation and related executive directives. In the D.C. Circuit, Anthropic challenged the separate FASCSA designation under 41 U.S.C. § 4713, which has its own judicial review mechanism.

 

In the California case, the district court granted Anthropic a preliminary injunction blocking enforcement of the § 3252 designation and related directives while the case proceeds. The court found that Anthropic was likely to succeed on claims that the government’s actions constituted First Amendment retaliation, violated due process, and were likely contrary to law and arbitrary and capricious under the Administrative Procedure Act. The court also questioned whether the asserted supply chain risk rationale fit the facts, particularly where the dispute centered on Anthropic’s refusal to remove usage restrictions from its AI products.

 

The D.C. Circuit case developed differently. The court denied Anthropic’s emergency request to stay the FASCSA designation at the preliminary stage, while granting expedited review. That ruling did not decide the merits and left contractors in a difficult position: the California injunction provides relief as to one designation and related directives, while the FASCSA designation remains active pending further review.

 

For contractors, the practical takeaway is that litigation has not produced a simple answer; instead, it has created a situation where  agencies are issuing certification requests and contractors are facing difficulty in addressing the requests while courts evaluate the legality of the underlying designations.

 

Key Risks for Contractors Responding During Active Litigation

 

False Certification Risk

 

The most immediate risk is providing a certification that later proves inaccurate. AI functionality may be embedded in products supplied by cloud providers, software vendors, or subcontractors. A contractor that certifies it does not use Anthropic technology without sufficient investigation could later discover that it incorrectly certified.

 

Contractual Risk

 

Certification statements may become part of the contractual record. Depending on the circumstances, inaccurate representations could create disputes concerning compliance obligations, eligibility determinations, or contract administration matters.

 

Supply Chain Visibility Challenges

 

Many contractors have limited visibility into the AI technologies used by lower-tier suppliers and software vendors. As AI functionality becomes increasingly embedded within commercial products, identifying all relevant dependencies may be difficult.

 

Continuing Compliance Risks

 

Even where a certification is accurate when signed, subsequent software updates, new integrations, or changing vendor relationships may affect the accuracy of prior representations.

 

Litigation May Cause Change 

 

Because the legal status of the designations may change as the cases proceed, contractors should avoid treating early certification requests as one-time events. Certification language, agency direction, and prime contractor flow downs may need to be revisited as courts issue further rulings or agencies modify implementation guidance.

 

The FedRAMP Compliance Contradiction


Adding to the confusion is the divergence between civilian agency authorization and defense restrictions. In July 2026, Anthropic successfully achieved FedRAMP High authorization for its Claude Code and Claude Cowork platforms within specific government cloud environments. Consequently, while civilian executive agencies are legally permitted—and in some cases actively encouraged—to deploy these FedRAMP-compliant Anthropic tools, defense contractors and military subcontractors face pressure to purge the exact same technology from their environments. This regulatory disconnect means that a contractor supporting both civilian and defense programs may find themselves contractually required to utilize Claude on one project while simultaneously certifying its total exclusion from another.

 

Contractor Response Considerations

 

Contractors receiving Anthropic certification requests should consider the following steps:

 

1. Conduct an Internal Assessment

 

Before responding, contractors should identify:

 

  • Direct Anthropic products or services;
  • AI-enabled software used in contract performance;
  • Cloud environments supporting contract performance;
  • Relevant subcontractor and supplier technologies;
  • Internal business systems that may be implicated by the certification; and
  • Determine if any shared cloud environments or software tools cross over between civilian agency projects (where Anthropic may be FedRAMP-approved) and defense projects (where it is restricted).

 

2. Seek Clarification of Ambiguous Terms

 

Contractors can consider requesting clarification when certifications contain undefined terms such as:

 

  • "use";
  • "relationship";
  • "involvement";
  • "integration"; or
  • "Anthropic technology."

 

3. Document Due Diligence

 

Contractors should document:

 

  • Internal reviews;
  • Supplier inquiries;
  • Technology assessments;
  • Management decisions; and
  • Legal analyses supporting the certification.

 

A well-documented diligence process may become important if questions arise later.

4. Consider Whether there is a Need to Revise Certification Language

 

Contractors appear to be seeking modifications that more accurately reflect the results of their diligence efforts.

 

Examples include:

 

  • Adding knowledge qualifiers;
  • Limiting representations to contract performance;
  • Clarifying that certifications are based on currently available information;
  • Distinguishing direct from indirect use; and
  • Providing factual disclosures where some use exists.

 

Looking Ahead

 

The Anthropic product prohibition and related certification activity reflect a challenging situation for government acquisition officials and contractors alike. Existing procurement regulations were not designed with modern AI systems in mind, and recent commentary within the government contracts community has emphasized that traditional supply chain compliance frameworks may be difficult to apply to embedded AI tools and commercial software ecosystems.

 

Until agencies provide more consistent guidance or courts resolve the pending disputes, contractors should approach Anthropic certification requests with the same discipline applied to cybersecurity, supply chain, and sourcing representations: read each request carefully, define the scope of the certification, conduct and document reasonable diligence, seek clarification where necessary, and avoid absolute statements that exceed the facts known at the time of certification.

 

If you have any questions about the issues raised in this alert, please contact the authors or the Womble Bond Dickinson attorney with whom you work. Learn more about Womble’s Government Contracting team and the firm’s AI team.