
A federal judge has ordered the Pentagon to remove its designation of Anthropic as a "supply chain risk," delivering a significant legal setback to the Defense Department in a dispute over how much control technology companies can retain over the military use of their artificial-intelligence systems.
Judge Rita Lin of the Northern District of California found that the Pentagon's action against the AI company "constituted unlawful retaliation in violation of the First Amendment" and that the company "was denied the pre-deprivation process required under the Fifth Amendment."
The ruling matters beyond Anthropic because the dispute turned a disagreement over AI safeguards into a question about how the government can use national-security procurement powers against a domestic technology supplier.
A procurement dispute became a constitutional fight
The conflict began after the AI company refused to remove safeguards that would prevent the military from using its Claude AI model for autonomous weapons and mass surveillance. The company argued that its models were not sufficiently reliable for those purposes.
Defense Secretary Pete Hegseth rejected the idea that a private company should be able to constrain how the US military uses technology it purchases. In February, the Pentagon classified Anthropic as a supply chain risk, preventing the department and its contractors from working with the company's products.
That designation carried unusual weight because it had previously been used only against companies viewed as connected to foreign adversaries. Anthropic sued in March.
Lin rejected the Pentagon's argument that an inability to "trust" Anthropic justified applying the label. She wrote that "The empty invocation of national security is not a blank check to punish and retaliate against government critics," and concluded that the evidence showed officials wanted to make a "public example out of Anthropic for its 'arrogance' in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model."
Why the ruling matters for AI suppliers
The decision separates two issues that had become intertwined: whether the Pentagon wants to procure technology under a vendor's restrictions, and whether disagreement over those restrictions justifies treating that vendor as a security threat.
That distinction could be important as government agencies negotiate access to AI systems whose developers impose their own limits on deployment. The ruling does not resolve the underlying disagreement over military use of Claude, but it removes the Pentagon's supply-chain designation as a tool in that dispute.
Lin also pointed to continued engagement between Anthropic and other parts of the government as evidence against the Pentagon's security rationale. "None of that is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security," she wrote.
The dispute is not fully over
Anthropic welcomed the decision and said it remained focused on working with the government on national-security applications.
The broader legal fight continues. A second Anthropic-lawsuit related to the designation remains before a Washington, DC, court. President Donald Trump also said in June that although he had previously considered the AI company a national-security threat, he no longer held that view.