A federal judge on Thursday vacated the Pentagon's designation of Anthropic as a national security supply-chain risk, ruling that the February 27 decision by defense secretary Pete Hegseth was unconstitutional retaliation against the AI lab. U.S. District Judge Rita Lin, sitting in San Francisco, issued a 59-page ruling that also lifted sanctions imposed by nine agencies, including the Pentagon, the Treasury Department, the State Department, and the Department of Homeland Security. The order restores Anthropic's eligibility for federal contracts across those agencies and removes a punitive measure that had barred defense contractors from doing business with the company.
The blacklist grew out of a collapsed $200 million deal for the U.S. military to use Claude models. Anthropic wanted contractual limits ruling out fully autonomous lethal weapons and domestic mass surveillance; Hegseth insisted the contract allow "all lawful use" and rejected any curbs. When negotiations broke down in February, the Department of Defense labeled Anthropic a supply-chain risk, making it the first American AI company publicly given that designation.
Lin found the measures "arbitrary, capricious, an abuse of discretion, and otherwise not in accordance with law," and concluded the Pentagon had violated Anthropic's First Amendment rights by punishing the company for publicly criticizing the administration's views on AI use.
“Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.”— Rita Lin, U.S. District Judge
Key facts
- 01U.S. District Judge Rita Lin vacated the February 27 decision by defense secretary Pete Hegseth designating Anthropic a supply-chain risk.
- 02The 59-page ruling lifted sanctions imposed by nine agencies, including the Pentagon, Treasury, State, and Homeland Security.
- 03The dispute stems from a collapsed $200 million deal to use Claude models for military applications.
- 04A parallel case at the US Court of Appeals for the District of Columbia remains ongoing, leaving Anthropic technically still designated a supply-chain risk.
- 05Lin cited ongoing government discussions with Anthropic about its new model, Mythos, as evidence undermining the national security rationale.
The judge pointed to a specific tension in the government's own conduct. Even while designating Anthropic a saboteur risk, federal agencies were simultaneously in talks with the company about deploying its forthcoming model, Mythos, in sensitive contexts. "None of that is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security," Lin wrote.
The ruling is narrow in one important respect: Lin affirmed that the Pentagon is under no obligation to use Claude and remains free to pick a different vendor. What the court struck down was the sweeping penalty regime — the blacklist itself, and its extension to contractors and suppliers — not the underlying procurement choice.
Anthropic filed two lawsuits in response to the designation, one in federal district court in California and one at the US Court of Appeals for the District of Columbia. The DC case, which addresses a separate legal basis the Pentagon used to justify the supply-chain designation, is still pending. Until it resolves, Anthropic technically remains a supply-chain risk despite Lin's order.
“We welcome the court's ruling that this supply-chain risk designation was unlawful. We remain focused on working productively with the government to harness AI for our national security.”— Danielle Cohen, Anthropic spokesperson
The origins of the rift trace to reports that the U.S. used Claude in the operation to capture Venezuelan president Nicolás Maduro. After the operation, a Palantir employee relayed concerns from an Anthropic staffer to U.S. officials about how the models had been used — friction that helped push subsequent contract talks toward collapse. The Pentagon argued at the time that giving Anthropic access to classified systems would "introduce unacceptable risk" because the company could theoretically disable or alter its own technology in wartime.
A Pentagon appeal is expected. The Department of Defense has not yet publicly responded to the ruling beyond prior statements defending the designation. Anthropic's models remain subject to the Trump administration's AI oversight framework, a separate regime that applies to frontier systems based on their capabilities rather than any national security allegation against the vendor.
The commercial stakes are substantial. Anthropic is moving toward what is expected to be a near-record IPO, and the blacklist had cut off a lane of federal and defense-contractor business at exactly the wrong moment. Reopening that channel — even partially, pending the DC case — restores optionality for a company whose top models are considered among the strongest in the world and whose government revenue trajectory matters to public-market investors.
The decision also draws a line other AI vendors will notice. Frontier labs negotiating with the Department of Defense now have a precedent that public disagreement with the government over model-use terms cannot, by itself, be grounds for a supply-chain risk designation. That shifts leverage back toward the vendor on questions like autonomous weapons and surveillance carve-outs, which had been points of active dispute across the industry. Whether the DC court reaches the same conclusion — and whether the Pentagon's appeal narrows the ruling — will determine how durable that shift proves.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




