TL;DR — Key Takeaways
- A federal judge blocked the Pentagon’s designation of Anthropic as a national security supply-chain risk.
- Judge Rita Lin ruled that the government unlawfully retaliated against Anthropic over its criticism of Pentagon AI policies.
- The dispute centers on Anthropic’s refusal to allow Claude to be used for fully autonomous weapons or mass surveillance of Americans.
A federal judge has blocked the Pentagon’s effort to blacklist Anthropic, handing the AI company a major legal victory in its dispute with the U.S. military over the acceptable uses of AI.
U.S. District Judge Rita Lin ruled that the Department of Defense acted unlawfully when it designated Anthropic a national security supply-chain risk. The designation restricted the company’s access to defense business and prevented Pentagon contractors from using Anthropic technology for their work with the department.
The dispute began early this year, when Anthropic and the Pentagon reached an impasse over how the military could use the Claude AI models. The Defense Department sought access to Claude for all lawful purposes, including sensitive military and intelligence operations. Anthropic refused to permit two uses: fully autonomous weapons and mass surveillance of Americans.
The disagreement escalated after negotiations broke down, prompting the Pentagon to designate Anthropic a national security supply-chain risk in March.
In a 59-page order, Lin found that the government violated Anthropic’s First Amendment rights by retaliating against the company for its public criticism of the Pentagon’s AI policies. She also rejected the national security rationale for the designation, calling the action “illegal and baseless.”
“The government is certainly owed deference on weighty issues of national security,” Lin wrote. However, “the empty invocation of national security is not a blank check to punish and retaliate against government critics.”
Larger Implications
The ruling has implications far beyond the current dispute. AI developers are building models that can potentially support intelligence gathering and other sensitive military operations. The Anthropic case raises a fundamental question: How much control can an AI vendor retain over its technology after selling access to the federal government?
For Anthropic, the stakes include both its AI safety policies and a potentially large source of revenue. Company executives estimated that the Pentagon restrictions could produce billions of dollars in lost business and damage its reputation.
The Pentagon’s action was highly unusual. Anthropic became the first U.S. company publicly classified as a supply-chain risk under a procurement law intended to protect military technology from threats like foreign sabotage. Anthropic challenged that reasoning, contending that there was no factual basis to treat the company as a security threat.
In contrast, Justice Department lawyers said Anthropic’s restrictions could create uncertainty about how Claude could be used during military operations. The government maintained that the dispute resulted from Anthropic’s unwillingness to accept contract terms rather than retaliation over its public position on AI safety.
Yet Judge Lin’s ruling noted that the Pentagon continued to pursue work involving Anthropic after labeling the company a security risk, behavior she found difficult to reconcile with the claim that its technology posed a genuine sabotage threat.
Anthropic welcomed the decision and signaled that it still wants a relationship with the federal government. The company said it remains focused on working with the government to harness AI for U.S. national security.
The ruling, however, does not end the dispute. Anthropic is challenging a separate Pentagon designation in Washington, D.C., based on a different legal authority. Until that litigation is resolved, the company still faces restrictions stemming from the government’s supply-chain risk actions.

