A 59-page federal ruling issued Thursday struck down the Pentagon’s effort to brand Anthropic a national-security supply-chain risk, rejecting a measure that could have excluded the company’s Claude artificial-intelligence models from military systems and disrupted their use by defense contractors. U.S. District Judge Rita F. Lin concluded that the designation and related directives violated the First Amendment, denied the company due process and exceeded the procurement authority Congress provided for protecting sensitive military technology.
The decision is the clearest judicial boundary yet on how the Defense Department may respond when an AI supplier refuses particular military uses of its models. Anthropic had maintained two restrictions: no use for fully autonomous lethal weapons and no mass domestic surveillance. The Pentagon argued that operational decisions must remain with the government and that a vendor’s ability to change contractual terms could create uncertainty during military operations.
Lin did not decide which side had the better policy for battlefield AI. Her court order emphasized that the department remains free to stop buying Claude or select a vendor willing to authorize every lawful use. The legal failure arose when officials went further, invoking a supply-chain statute to impose broad penalties that the court found were tied principally to Anthropic’s public criticism rather than a technical vulnerability.
A dispute over two military uses
Defense and intelligence agencies began using Claude in 2024, according to the administrative record summarized by the court. By March 2025, national-security users had access to specialized Claude Gov models through partner platforms. Anthropic says those systems supported intelligence analysis, modeling and simulation, operational planning and cyber operations—missions it continued to describe as legitimate defense applications even while contesting the blacklist.
The break came during negotiations over broader use. Anthropic’s position was that current general-purpose models were not sufficiently reliable for fully autonomous lethal systems and that mass surveillance of Americans raised distinct civil-liberties concerns. Its March statement said those limits governed high-level use cases, not battlefield decisions, and offered continued support during any transition. That account is from an interested party, but the two restrictions themselves were not disputed in the litigation.
The government took the opposite institutional view: elected leaders and military commanders, not private technology executives, must determine which lawful capabilities are available. In filings described by Reuters, the Justice Department argued that Anthropic’s refusal to accept unrestricted terms could complicate the Pentagon’s use of Claude and risk disruption in operations. Officials said the designation responded to a contractual impasse rather than the company’s speech about AI safety.
The blacklist reached beyond a vendor change
On February 27, President Donald Trump directed federal agencies to stop using Anthropic technology, allowing a six-month phaseout for agencies already dependent on it. Defense Secretary Pete Hegseth then announced that Anthropic would be designated a supply-chain risk and said military contractors, suppliers and partners could not conduct commercial activity with the company. A formal designation followed in early March.
That was a much larger step than declining to renew a contract. The measure threatened relationships between Anthropic and companies that integrate Claude into broader products used by the government. Microsoft, which filed in support of Anthropic, said the abrupt restriction could disrupt services and impose costly replacement work. Its intervention reflected Microsoft’s commercial stake, but it also illustrated the dependencies created when the same foundation model appears inside many layers of a defense technology stack. Reuters reported that researchers from competing AI companies also urged the court to block the action.
The designation was unprecedented in a crucial respect: it was the first publicly reported use of the military supply-chain authority against a U.S. company. Anthropic said it faced billions of dollars in lost business and broader reputational harm. The Pentagon could still migrate from Claude, but a supply-chain label implied that the product presented a security danger rather than a disagreement over acceptable uses.
Why the supply-chain law did not fit
The governing statute, 10 U.S.C. § 3252, is designed to protect national-security systems from adversarial sabotage, malicious functions and other forms of technical subversion. It permits exclusion of a source from certain covered procurements only when the action is necessary to reduce such risk and less intrusive measures are not reasonably available. The Defense Federal Acquisition Regulation Supplement applies that authority to information technology incorporated into covered military systems.
Lin found that the administrative record did not establish the kind of risk the law describes. Officials initially considered whether Anthropic retained a technical “backdoor” into deployed models. The court said the undisputed evidence showed it did not, and the government conceded that Claude was no more vulnerable on that point than other closed, or “black box,” AI systems. The remaining rationale focused on whether Anthropic could be trusted after criticizing the department.
The ruling held that this rationale could not support the statutory designation. It also found the government had not identified a supply-chain threat linked to an adversary, had not adequately considered less restrictive options and had imposed consequences broader than the procurement actions Congress authorized. The Pentagon’s implementation guidance treats Section 3252 as a risk-management mechanism for covered systems, reinforcing the distinction between protecting a technical supply chain and punishing a supplier dispute.
Constitutional findings sharpen the limit
The court separately ruled that the government retaliated against Anthropic for protected speech. Lin pointed to official statements criticizing the company’s public posture and to the administrative record’s reliance on Anthropic’s “increasingly hostile manner through the press.” She concluded that the Constitution did not allow the government to attach sweeping penalties principally because a contractor publicly challenged the administration’s AI policy.
Anthropic also prevailed on its Fifth Amendment claim. The designation damaged the company’s reputation while altering its ability to pursue government business, yet officials did not provide meaningful notice and an opportunity to contest the label before it took effect. Lin found that the company was entitled to pre-deprivation process even in a national-security setting. The opinion additionally held that most federal agencies violated administrative law when they terminated relationships without the notice required for withdrawal of a license-like benefit.
The ruling was not a complete victory. The court rejected Anthropic’s separation-of-powers theory and ruled for agencies that had taken no relevant final action or only interim measures. It also did not order the military to keep using Claude. An earlier preliminary injunction had already restored the pre-blacklist position while leaving the Pentagon free to transition to other models through lawful contracting procedures; the government appealed that order, and related litigation remains pending.
What changes for military AI procurement
The immediate result is continuity, not a mandate. The Pentagon can evaluate model performance, reliability, security and contract terms, then choose another supplier if Claude does not meet its requirements. What it cannot do, under this ruling, is convert a policy disagreement into a supply-chain finding without evidence that matches the statute or use procurement power to retaliate against criticism. The Pentagon had not commented on the decision when Reuters published its report, leaving open whether it will appeal the summary-judgment ruling.
For defense planners, the case exposes a structural vulnerability in adopting commercial AI. Model providers can update safety policies, access terms and technical interfaces more quickly than traditional weapons contractors. The government therefore needs redundancy, transition plans and clear clauses addressing continuity of service. Those are ordinary acquisition and operational-resilience tools; the ruling suggests they cannot be replaced by a national-security designation untethered from a technical supply-chain threat.
For AI companies, the decision does not create a general right to dictate military doctrine. Suppliers remain responsible for deciding what they will sell, while the Pentagon decides what it will buy. The durable lesson is procedural: disputes over lethal autonomy, surveillance and model control must be resolved through transparent contracting, statutory authorities that fit the risk and reviewable evidence. As military AI moves from experiments into operational systems, those boundaries will matter as much as benchmark performance.