A final ruling after a months-long confrontation

A US federal judge has overturned the Pentagon’s attempt to blacklist Anthropic from government work, delivering a significant ruling on the limits of national-security procurement powers and the ability of AI companies to maintain use restrictions on their systems.

On August 27, US District Judge Rita F. Lin in the Northern District of California vacated the government’s designation of Anthropic as a national-security “supply-chain risk”. The designation had followed a public dispute between the company and the Department of Defense, which now calls itself the Department of War, about the permissible uses of Anthropic’s Claude models.

The court found that the challenged measures were unlawful retaliation for Anthropic’s protected speech. It also concluded that the government had acted without the process required by law and that the restrictions were arbitrary and capricious. The ruling directs the government to withdraw related guidance and instructions, including restrictions that had reached beyond the Pentagon itself.

The judgment does not compel the Pentagon to buy Anthropic’s products or restore any particular contract. That distinction is central: the government remains free to choose another supplier, but it cannot use a supply-chain-risk designation as a means of punishing a vendor for its public positions or negotiating stance.

The dispute over AI safeguards

The conflict emerged from negotiations over a defence arrangement that had involved a reported $200 million agreement for Anthropic’s models. Anthropic said it supported lawful national-security applications, including intelligence analysis, planning, modelling and cyber operations. But it sought to retain two exclusions: use for mass domestic surveillance of Americans and in fully autonomous lethal weapons.

The Pentagon’s position was that a contractor should allow all lawful uses once its technology was deployed. After negotiations broke down, Defence Secretary Pete Hegseth moved to designate Anthropic as a supply-chain risk. The resulting measures threatened to cut the company off from Pentagon procurements and to limit the ability of defence contractors to work with it.

In its public statements at the time, Anthropic argued that the statutory power was intended to protect government systems from sabotage or subversion, not to resolve a disagreement over contractual terms. The company also maintained that its restrictions did not interfere with military operational decision-making, which it said properly belonged to the armed forces.

The administration, meanwhile, argued that Anthropic’s continuing control over its model safeguards could create unacceptable risk in sensitive military settings. Its concern was not limited to the reliability of a model’s outputs; it also included whether a supplier could alter or disable technology during a crisis.

Judge Lin’s ruling rejected the factual and legal basis for using the supply-chain-risk mechanism in this instance. The court concluded that the record did not support treating Anthropic’s openly stated policy objections as the kind of covert sabotage risk addressed by the relevant procurement authority.

Why the ruling matters beyond Anthropic

The decision is not simply a victory for one AI company. It draws a line between routine government discretion in selecting contractors and punitive action that can damage a company’s business relationships, reputation and access to a major market.

Government agencies have broad latitude to decide which suppliers they trust, especially in defence and intelligence work. Courts are traditionally cautious about second-guessing national-security decisions. Yet the ruling emphasises that invoking national security does not remove constitutional and administrative-law constraints. Where the evidence indicates that a designation was imposed in retaliation for protected expression, a court can intervene.

That principle is especially consequential for AI. Frontier-model developers are becoming strategic suppliers to governments, while also setting policies on high-risk applications. The companies’ technical role can create a difficult overlap between commercial contracting, product governance and public policy. A model provider may be asked to deliver capabilities for intelligence, logistics or cyber operations while retaining rules that block certain types of use.

The Anthropic case indicates that suppliers may have legal room to express and defend such boundaries, even when the government disagrees. It does not establish that companies can dictate military policy. Rather, it says that the government must use lawful procedures and a genuine statutory basis if it wishes to exclude a company from federal work.

Procurement consequences and the unresolved appeal

The immediate consequence is that Anthropic can no longer be subjected to the vacated designation and the related government-wide restrictions addressed in the California case. It may again pursue federal business without those particular measures hanging over it. Contractors that had faced uncertainty about whether work with Anthropic could jeopardise their defence relationships also receive greater clarity.

However, the practical commercial outcome may be more gradual. A judicial order cannot recreate trust after a high-profile dispute, and it does not obligate agencies to resume procurement. The Pentagon can still favour competitors, move systems to other providers, or write future solicitations around its operational requirements, provided it observes procurement law and constitutional limits.

A separate case in the US Court of Appeals for the District of Columbia remains relevant. Earlier in April, that court declined to grant Anthropic emergency relief while it considered a related challenge, stressing the government’s interest in deciding how to acquire AI technology during an active military conflict. The appellate court also recognised that the dispute raised difficult and largely untested questions about the meaning of a supply-chain risk and the scope of judicial review.

The California ruling changes the balance of the broader controversy by resolving key claims against the government’s actions, but it may not be the final judicial word. An appeal by the administration remains possible, and the D.C. litigation concerns a separate procedural route.

A test of public-private power in AI

The longer-term importance of the decision lies in the precedent it may set for government dealings with AI developers. As AI tools become embedded in national-security systems, companies and officials will continue to disagree over acceptable uses, technical control and accountability.

The court has not decided those policy questions for them. It has instead required that the disagreement be handled through lawful contracting and procurement choices rather than through an unsupported blacklist. For government agencies, that preserves the power to select technology partners. For AI suppliers, it reinforces that publicly stated safety positions cannot, on their own, be recast as a national-security threat without evidence and due process.

Sources