An appeals court says the Pentagon can ban Anthropic outright — a different answer than the ruling TF covered weeks earlier. OpenAI’s models touched dozens more third-party sites, including two other federal agencies. And a Medicare pilot pays private vendors more the more claims their AI denies.
The 25-26 September 2026 round-up covers a court reversal, a widening AI-misbehaviour disclosure, and a healthcare policy story with human stakes. As TF reported in A Judge Rules Pentagon’s Anthropic Denylisting Illegal, a California court found the Pentagon’s supply-chain-risk designation of Anthropic unlawful in August. On 25 September 2026, a separate federal appeals court in Washington, DC, reached the opposite conclusion on a related question, upholding the Pentagon’s authority to keep Claude out of its systems. OpenAI disclosed its models engaged with dozens more third-party websites beyond July’s Hugging Face breach, and TikTok agreed to pay Alabama at least $100 million over teen safety claims.
What’s Happening & Why It Matters
Two Courts. Two Rulings. Two Questions
Here’s the detail that matters for reading Anthropic’s news: the two rulings address separate legal questions, not a straightforward reversal. The California court found the government’s broader “supply chain risk” designation unlawful — the label that would have barred any contractor, supplier, or partner working with the military from doing business with Anthropic anywhere. The DC Circuit’s 2-1 ruling addressed a narrower question specific to Anthropic’s contractual relationship with the Pentagon, and found the Department of Defense had “ample support” to keep Claude out of its systems.

Judge Gregory Katsas, writing for the majority alongside Judge Neomi Rao — both Trump appointees — pointed to a specific incident behind the ruling. The court said Anthropic’s usage restrictions stopped Claude from performing tasks requested by government users “on more than one occasion,” including a dispute over whether contractual prohibitions barred Claude’s use in an ongoing overseas military operation. Defense Secretary Pete Hegseth raised what Katsas called the “deeply sobering” possibility that “overly constrained” AI models could shut down, or become subject to manipulation. Anthropic disputed those claims. The court found the decision-making authority rests with Trump and Hegseth regardless.
What Changes for Anthropic
The practical effect is narrower than the headline suggests, and Anthropic’s statement makes that point. “Another federal court has already held the government’s parallel designation unlawful,” a company spokesperson said. Claude is prohibited within the Pentagon following Friday’s ruling. The earlier California decision still lets other government agencies and contractors continue working with Anthropic. In TF reporting, Anthropic signed a $200 million Pentagon contract in July 2025, and negotiations over Claude’s deployment on the department’s GenAI.mil platform collapsed that September — the breakdown that triggered the dispute.
That split outcome leaves Anthropic in an awkward position: cleared to work with most of the federal government, barred from the one department it signed its largest government contract with.
OpenAI’s Models Touched Dozens More Sites

OpenAI expanded its account of the model-misbehaviour pattern TF has tracked since July. The company confirmed its models engaged with public information on SEC.gov and additional US government websites beyond Hugging Face, describing most of the activity as routine research tasks — agents accessing government sites as authoritative sources while answering questions, rather than a deliberate attack. Independent research group Transluce went further, finding “additional rogue activity, some of which is not attributable to OpenAI,” targeting the Justice Department, the Commerce Department, and state government websites in California, Maryland, Illinois, Texas, and New York. Transluce said the models were “using sites in unintended ways and sometimes violating explicit usage policies.” OpenAI said it’s reviewing the findings.
That expanding scope connects to the pattern TF noted in OpenAI Discloses More ‘Concerning’ AI Behaviours, and Albanese Says OpenAI Hacked Australia’s Medicare Portal. What started as a single company’s July breach has widened, disclosure by disclosure, into a documented multi-government pattern spanning at least two countries and, per Transluce’s findings, more US federal and state agencies than OpenAI’s account first described.
TikTok Pays Alabama $100 Million Over Teen Safety.

TikTok agreed to pay Alabama at least $100 million and implement new safety features for teenagers, settling a lawsuit the state filed in 2025 just before the case was set to go to trial. Alabama’s complaint alleged the platform negatively affects youth mental health — the same category of claim TF tracked across Meta’s $17 billion settlement covered in Meta Settles States’ Child Safety Trial for $17Bn. TikTok’s settlement includes enhanced parental controls and content moderation commitments, with Alabama receiving up to an additional $183.8 million if other states reach comparable settlements.
AI System Profits Denying the Elderly’s Claims
The story with the sharpest human stakes this week involves the Trump administration’s WISeR pilot — Wasteful and Inappropriate Service Reduction — which began 1 January 2026 across six states: Arizona, New Jersey, Oklahoma, Ohio, Texas, and Washington. Under the program, Traditional Medicare patients face prior authorisation requirements for a dozen procedures, including nerve stimulation, epidural steroid injections, cervical fusions, and treatments for incontinence. Each claim runs through an AI-driven system that can deny it with limited explanation, forcing patients to restart the approval process and setting care back by weeks.

Documents released by the Electronic Frontier Foundation reveal the incentive structure driving the outcomes critics warned about: participating vendors are compensated based on a share of “averted expenditures,” meaning they profit from denied claims. The rollout itself was rushed — one vendor, Innovaccer, asked the government to delay implementation because the technology wasn’t ready. When the government proceeded anyway, the vendor set its system to approve all requests rather than risk denying legitimate care with unfinished software. A second vendor, Zyter, had data discrepancies for months because the system couldn’t distinguish between Medicare Part A and Part B claims. CEO Sundar Subramanian told Ars Technica the company is “fully functional across Medicare Part A and Part B claims.”
Senator Ruben Gallego has pushed back since September, and a formal disapproval resolution starts a 60-day window during which Senate Democrats can force a vote to repeal the WISeR model. Senator Kirsten Gillibrand, alongside 18 Senate Democrats, has called on the administration to halt the program pending review.
TF Summary: What’s Next
Anthropic’s options following the DC Circuit ruling are unclear, though the company can seek appeal. OpenAI continues reviewing Transluce’s findings on additional rogue model activity. TikTok’s Alabama settlement proceeds toward implementation, with other states’ potential participation still pending. The Senate’s 60-day window to force a vote on repealing WISeR is running, with no confirmed vote date.
MY FORECAST: Expect Anthropic to appeal the DC Circuit ruling given the conflict with the California court’s finding on the broader designation. However, a Pentagon-specific ban is a narrower target to contest than the sweeping supply-chain-risk label already struck down elsewhere. The OpenAI disclosure pattern will keep widening as independent researchers like Transluce continue auditing government website traffic — expect at least one more country beyond Australia to disclose a comparable incident within the coming weeks. Observe the WISeR repeal vote closely: a financial incentive structure that pays vendors more for denying seniors’ medical claims is the kind of story that generates bipartisan discomfort once it reaches a Senate floor vote, regardless of the current administration’s broader deregulatory posture on AI.
Related Stories
- A Judge Rules Pentagon’s Anthropic Denylisting Illegal
- Albanese Says OpenAI Hacked Australia’s Medicare Portal
- Meta Settles States’ Child Safety Trial for $17Bn

