Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
AI Vendor Becomes Supply-Chain Risk: The Anthropic CaseSupply Chain Risk Management
5 min readFor Supply Chain Risk Managers

AI Vendor Becomes Supply-Chain Risk: The Anthropic Case

What Happened

The D.C. Circuit Court of Appeals upheld the Department of Defense's designation of Anthropic as a supply-chain risk in September 2026. This designation, effective since March, bars DOD employees and contractors from using Anthropic's AI products for defense purposes.

The issue began in February when the DOD demanded Anthropic modify its contract to allow "all lawful use" of its AI tools, removing restrictions on domestic mass surveillance and autonomous weapons. Anthropic refused by the Feb. 27 deadline, prompting Defense Secretary Pete Hegseth to direct the supply-chain risk designation, which became official on March 3.

Anthropic challenged the designation on two statutory grounds. While a Northern District of California court ruled in Anthropic's favor on one justification in August, the D.C. Circuit panel sided with the DOD on the second statutory basis. Judge Karen LeCraft Henderson dissented.

Timeline

Feb. 24: DOD issues ultimatum for Anthropic to permit all lawful uses of its AI by Feb. 27

Feb. 27: Anthropic refuses; Hegseth announces intent to designate company as a supply-chain risk

March 3: DOD formally designates Anthropic as a supply-chain risk

August: Northern District of California rules in Anthropic's favor on one statutory justification

September 28: D.C. Circuit Court of Appeals upholds DOD designation under separate statutory authority

Which Controls Failed or Were Missing

This isn't a typical security incident with technical failures. It's a contractual and compliance issue that highlights gaps in how your team validates vendor alignment with mission requirements before dependencies are established.

Vendor risk assessment (SR-5 from NIST SP 800-53): If you're a DIB contractor using Anthropic's tools, you likely assessed technical security controls but didn't consider policy conflicts with your customer. Supply-chain risk assessments under SR-5 require identifying threats throughout the system life cycle, including "counterfeiting, tampering, and malicious software insertion." While the control doesn't explicitly mention vendor policy misalignment, SR-5(a) requires documenting supply-chain risk and mitigation strategies. A vendor refusing to modify acceptable use terms in response to customer requirements is a supply-chain threat you should have documented.

Acquisition strategy controls (SA family): NIST SP 800-53 SA-9, External Information System Services, requires defining and documenting security controls for external providers. If you're using a commercial AI service, verify that the provider's policies don't conflict with your obligations under DFARS 252.204-7012 or your CMMC Level 2 certification. The control baseline calls for a defined process to monitor compliance and control changes. When the DOD attempted to modify contract terms and Anthropic refused, it should have triggered your own risk response.

Continuous monitoring (CA-7): You're required to monitor your information systems continuously, including supply-chain elements. If your team uses Claude for drafting technical documentation or analyzing sensor data, and that vendor becomes a designated supply-chain risk, your continuous monitoring program should flag that change and force a risk decision. Most teams monitor CVEs and patch status but don't track regulatory or policy-based vendor risk.

What the Relevant Standard Requires

DFARS 252.204-7012 requires you to "provide adequate security" for covered defense information in your systems. Clause (b) mandates implementing NIST SP 800-171 security requirements. Using a third-party AI service introduces an external system into your data flow. NIST SP 800-171 requirement 3.13.11 states: "Employ cryptographic mechanisms to protect the confidentiality of remote access sessions." Sending covered defense information to an AI vendor's API establishes a remote access session to an external system.

The deeper obligation is in 32 CFR Part 170, the CMMC regulation. Section 170.21(b)(3) requires assessing supply-chain risk as part of your cybersecurity program. The rule doesn't narrowly define "supply-chain risk" as malware or hardware tampering; it includes any supply chain element that could compromise your ability to protect CUI or fulfill contract requirements.

Once the DOD designates a company as a supply-chain risk under 10 U.S.C. § 4871 or 10 U.S.C. § 3252, you're on notice. Continuing to use that vendor's products exposes you to audit findings during your CMMC assessment. Your C3PAO will ask whether you've assessed third-party services for supply-chain risk and documented mitigation strategies for identified risks. "We didn't know Anthropic was designated" won't suffice.

FedRAMP Moderate baseline control SR-2, Supply Chain Risk Management Plan, requires cloud service providers to develop a plan that includes supplier reviews and a process for identifying and mitigating risks. If you're a CSP serving defense customers, you can't sub-process CUI through a vendor flagged by the DOD.

Lessons and Action Items for Your Team

Maintain a vendor risk register that tracks policy and regulatory status, not just security posture. Include a field for "customer acceptable use alignment" and flag vendors whose terms restrict government or defense applications. Update it quarterly and whenever a major contract modification occurs.

Build contract language requiring vendors to notify you within 48 hours of any supply-chain risk designation by a federal agency. Most SaaS agreements don't include this. Add it as a flow-down requirement in your next renewal cycle. If your vendor refuses, that's a red flag.

Map your AI and cloud service dependencies to the data classifications they touch. Create a matrix showing which vendors process CUI, which handle FCI, and which are isolated to unclassified internal tools. When a vendor gets flagged, you'll know immediately whether you have a compliance problem or just an operational inconvenience.

Don't assume a vendor's current acceptable use policy will remain stable. Anthropic's conflict with the DOD started because the department wanted to remove restrictions. If you're designing systems around a vendor's ethical AI commitments, document what happens if those commitments change. Your risk register should include a "policy volatility" score.

Review your CMMC System Security Plan and update the supply-chain risk section. If you're preparing for a Level 2 assessment, your SSP needs to show how you identify, assess, and respond to supply-chain threats. A documented process that includes monitoring federal supply-chain risk designations demonstrates maturity. A blank section or generic boilerplate will draw findings.

If you're using Anthropic now, you have three options: stop using it for any DOD work, document a risk acceptance with a migration plan and timeline, or get explicit written guidance from your contracting officer that your specific use case is exempt. Option three is unlikely unless you're working with unclassified data with no CUI involved.

The broader lesson: supply-chain risk isn't just about hardware backdoors or compromised software builds. It includes any vendor dependency that conflicts with your customer's mission requirements or regulatory posture. Your compliance program needs to account for that.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like