The Volokh Conspiracy
Mostly law professors | Sometimes contrarian | Often libertarian | Always independent
Anthropic's Claims Over Its "Supply Chain Risk" Exclusion by Department of War Rejected
Some excerpts from today's long majority opinion by Judge Gregory Katsas, joined by Judge Neomi Rao, in today's D.C. Circuit decision in Anthropic PBC v. U.S. Department of War:
This case arises from a decision by the Department of War to exclude Claude, an artificial-intelligence product developed by petitioner Anthropic PBC, from its supply chain under the Federal Acquisition Supply Chain Security Act of 2018. The Department made this decision after Anthropic refused to relax contractual prohibitions on the use of Claude for lethal autonomous warfare or domestic surveillance. Anthropic challenges the exclusion as arbitrary, unauthorized by the governing statute, and unconstitutional.
We reject these challenges. The Department had ample support for its conclusion that the continued integration of Claude into the Department's information systems, by the Department or its contractors, presented a statutorily covered national-security risk. As Anthropic admits, the company encodes restrictions into Claude that prevent the model from performing tasks that Anthropic wishes to prevent. On more than one occasion, these restrictions have stopped Claude from performing tasks requested by government users. And recently, a dispute arose over whether the contractual prohibitions barred the use of Claude in an ongoing overseas military operation, leaving the Department uncertain whether Claude would perform as needed and intended.
Anthropic's constitutional claims are also without merit. Its due-process claim fails because the Department promptly notified the company of the exclusion and its supporting rationale, and then gave the company a fair opportunity to contest the exclusion. And Anthropic's First Amendment claim fails because the Department excluded Anthropic from its supply chain based on the company's refusal to assent to a contract term that the Department deemed essential, not based on the company's support for greater governmental regulation of AI technology….
This case raises profoundly difficult questions about the appropriate military uses of an almost unimaginably powerful new technology. The Secretary raises the deeply sobering prospect of overly constrained AI models shutting down unexpectedly and thus causing important military operations to fail. Anthropic raises the deeply sobering prospect of unconstrained AI models hallucinating inappropriate targets for lethal military force. Both possibilities present obvious national-security concerns. But in our Republic, it is the President and the Secretary of War who must determine how best to balance the competing risks. In doing so here, the Secretary did not transgress any limits on his authority under the Supply Chain Security Act or the Constitution. Accordingly, we deny the petitions for review.
Judge Karen LeCraft Henderson dissented on statutory grounds:
Whether the Secretary of the Department of War (Secretary) lawfully invoked his statutory powers under the Federal Acquisition Supply Chain Security Act of 2018 (FASCSA) turns on whether Anthropic falls within the statute's definition of a "supply chain risk." "When Congress takes the trouble to define the terms it uses," courts should apply them "with rigor." And here, the Congress has taken great pains to define the type of "supply chain risk" that must exist before the Secretary invokes the sweeping powers FASCSA confers on him. Under the statute, he may exercise his authority to blacklist a procurement source from the Department's supply chains "only after" the Department concludes the source poses a "significant" risk that it will:
sabotage, maliciously introduce unwanted function, extract data, or otherwise manipulate the design, integrity, manufacturing, production, distribution, installation, operation, maintenance, disposition, or retirement of covered articles so as to surveil, deny, disrupt, or otherwise manipulate the function, use, or operation of the covered articles or information stored or transmitted on the covered articles.
My colleagues do not dispute that whether Anthropic qualifies under this definition depends entirely on the scope of section 4713(k)(6)'s residual clause: "or otherwise manipulate." The Department and Anthropic offer competing definitions of that term. According to Anthropic, the residual clause uses "manipulate" to denote intentionally subversive acts, carried out through deceptive means.
The Secretary argues, and the majority agrees, that the term encompasses much more. To "manipulate" a covered article, in their view, means to "move, arrange, operate, or control [it] by the hands or another body part or by mechanical means," regardless of purpose or motive—for example, how one might "manipulate" a doorknob by turning it or a gas pedal by pressing it down. Both definitions may be linguistically possible but basic canons of construction require us to decide which one fits best within section 4713(k)(6)'s surrounding text, construed as a whole. Because I believe that the context decidedly favors the narrower reading, I respectfully dissent….
I cannot agree that this is the scenario the Congress had in mind when it enacted FASCSA. It enacted the statute in response to calls from the U.S. intelligence community for legislation to meet the threat of "[h]ostile nation state and other bad actors" infiltrating the federal government's information and technology systems through its supply chains. For years, national security agencies had warned that companies "beholden to foreign governments" and other malicious actors were introducing compromised products into "[m]any of the technologies the Federal Government relie[d] on for vital, daily functions." In their published reports, the agencies described numerous covert security breaches carried out by nefarious actors—and in terms that closely track section 4713(k)(6)'s key terms.
Such historical evidence showing how a statute's terms were used pre-enactment sheds light on what sense those words are meant to carry when the Congress writes them into law. That history supports Anthropic's reading. And it refutes the view that "manipulat[ion]" of a covered article encompasses anything like the conduct that, under today's holding, gives rise to a supply chain risk—that is, a contractor's honest and upfront enforcement of restrictions on a covered article's use disfavored by the government.
The majority responds in turn as to the statutory argument; a short excerpt:
Two final points. First, for the reasons discussed above, we reject Anthropic's attempt to engraft onto the statutory definition an overarching requirement of acting surreptitiously, just because two of the seven verbs in the strings (sabotage and surveil) have that connotation. Second, we reject Anthropic's attempt to glean from the legislative history a focus on "foreign companies working at the behest of foreign states." Whatever paradigmatic examples individual members of Congress may have had in mind, the statutory definition is not limited to "adversar[ies]" and instead covers "any person," which cannot refer only to foreign entities….
In sum, we conclude that the Secretary's concern about Anthropic disabling Claude from performing lawful actions requested by the Department qualifies as a "supply chain risk" within the meaning of section 4713.
There's a lot more, both on the statutory and constitutional questions, in the full opinions. I hope to have more on some of these issues later, but in the meantime I thought I'd pass along what struck me as key excerpts.
Sharon Swingle, Brett A. Shumate, Eric D. McArthur, Sean R. Janda, and Brian J. Springer represent the government.