A federal judge in California has vacated the Pentagon’s designation of Anthropic as a national-security supply-chain risk, ruling that the government unlawfully punished the AI company over its public stance on limits for military use of its Claude models.
U.S. District Judge Rita F. Lin issued the 59-page decision on August 27, granting Anthropic summary judgment on key constitutional and administrative-law claims. The court found that the challenged actions amounted to unlawful retaliation in violation of the First Amendment, and that Anthropic was denied the pre-deprivation process required by the Fifth Amendment. Lin also concluded that the Pentagon’s directive and supply-chain designation exceeded statutory authority, were contrary to law, and were arbitrary and capricious.
What the ruling changes
The decision requires the Defense Department to unwind the designation and associated guidance, directives, communications, and restrictions. That is a significant immediate outcome for Anthropic and for defense contractors that had faced restrictions on using the company’s technology in Defense Department work. But the ruling does not compel the Pentagon to purchase Claude, retain Anthropic as a supplier, or award the company any future contract. The department remains free to choose other AI providers or to end a relationship with Anthropic through lawful means.
The conflict grew out of negotiations over the military’s use of Claude earlier this year. The Defense Department sought access for “all lawful” uses, while Anthropic sought to preserve two stated limitations: no mass surveillance of Americans and no use in fully autonomous weapons. Anthropic maintained that it wanted to support national-security work while keeping those boundaries in place. The company filed its California lawsuit in March after the Pentagon designated it a supply-chain risk and imposed restrictions on its commercial relationships with military contractors.
The court’s constitutional and statutory findings
Lin’s ruling drew a sharp distinction between a valid national-security action and the government’s treatment of Anthropic in this case. The court found that Anthropic’s statements about AI safety and the restrictions it sought were protected speech on a matter of public concern. It concluded that the government would not have taken the challenged action absent a desire to make an example of the company for its position in the dispute.
The order also addressed the procedural basis for the designation. Supply-chain authorities are designed to address threats such as sabotage or subversion, and the court found no adequate showing that Anthropic’s contracting position fit that purpose. The ruling said the government’s broad invocation of national security did not eliminate its constitutional due-process obligations toward a domestic company with a substantial federal contracting business, particularly where no exigent circumstances had been demonstrated.
Implications for AI procurement
For government technology buyers and AI vendors, the practical importance of the decision is narrower than a general endorsement of any company’s model-use policy. It does not establish that a provider can dictate every condition of a federal contract, nor does it prevent the Pentagon from evaluating risks in AI systems or choosing not to procure a particular model. Instead, it limits the government’s ability to use a supply-chain-risk designation as a means of penalizing a supplier for protected speech or sidestepping the procedural and statutory constraints that govern such actions.
The case also shows why model-use terms are becoming a central procurement issue as foundation-model providers move deeper into sensitive government work. AI companies may be willing to support defense, intelligence, and other public-sector missions while retaining restrictions on specific categories of deployment. Government agencies, meanwhile, may seek broader operational discretion and continuity of access. The court’s decision indicates that a disagreement over those terms cannot simply be recast as a supply-chain threat without a legally sufficient basis.
The immediate procurement effect is the removal of the blacklist and its associated restrictions, restoring Anthropic’s ability to compete and work through the defense contracting ecosystem on the same legal footing it had before the challenged actions. The ruling also provides protection against renewed implementation of the retaliatory measures addressed in the case. It does not resolve every dispute between Anthropic and the federal government, however: a separate related matter involving a distinct designation remains pending in Washington, D.C.
What happens next
Anthropic said it welcomed the ruling and remained focused on working productively with the government on national-security applications of AI. The Pentagon’s next move was not established by the decision itself. While the government can seek further review, the court denied its request to administratively stay the permanent injunction, noting that the challenged actions had already been under a preliminary injunction for more than five months.
For the broader AI sector, the ruling is a consequential reminder that government adoption of powerful foundation models will be shaped not only by model capability and security testing, but also by contract terms, constitutional limits, and the legal process used when agencies seek to exclude a supplier. The court did not decide whether Anthropic’s two disputed restrictions are the right policy for military AI. It decided that the Pentagon could not impose the challenged punishment in the way it did.




