US Edition
Your source for latest news
OpinionNational Security Law

The Pentagon's Anthropic blacklist was never really about supply chains

A federal judge's 59-page order didn't just clear one AI company of a "supply chain risk" label — it laid out, in the government's own contradictory conduct, a case study in how national-security statutes can be turned into tools of political retaliation.

PW
By PressTemps Washington DeskPublished Today, 09:22 ET · 6 min read
The Pentagon's Anthropic blacklist was never really about supply chains
An aerial view of the Pentagon, headquarters of the U.S. Department of Defense. Photo by Touch Of Light, CC BY-SA 4.0, via Wikimedia Commons.
What to know
A federal judge in the Northern District of California ruled that the Pentagon's designation of Anthropic as a "supply chain risk to national security" was unlawful retaliation violating the First Amendment and denied due process under the Fifth Amendment.
The designation followed Anthropic's refusal to lift its own bans on using Claude models for fully autonomous weapons and mass surveillance of Americans, after which Defense Secretary Pete Hegseth applied a label historically reserved for firms tied to foreign adversaries.
The court found the government's own conduct — continuing to pursue a contract with Anthropic and proposing Defense Production Act protection for the company even while calling it a security risk — contradicted its stated rationale.
A second, related Anthropic lawsuit remains pending in a Washington, D.C. appeals court, and the government is expected to challenge this ruling as well.

A federal judge in San Francisco ruled this week that the Pentagon broke the law when it declared the AI company Anthropic a "supply chain risk to national security" — a designation historically reserved for firms suspected of ties to foreign adversaries, applied for the first time against an American company. In a 59-page order in Anthropic PBC v. U.S. Department of War, U.S. District Judge Rita Lin found that Defense Secretary Pete Hegseth's action against the Claude maker amounted to unlawful retaliation under the First Amendment and denied the company due process under the Fifth. The ruling does not just settle a contract dispute. It documents, in granular and largely undisputed factual findings, how easily a vague national-security label can be turned into a political cudgel.

"The empty invocation of national security is not a blank check to punish and retaliate against government critics," Lin wrote, adding that "the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless." The dispute traces back to February, when Anthropic refused a Pentagon demand to drop two of its own usage policies — a ban on using its Claude models for fully autonomous weapons and for mass surveillance of Americans. Hegseth responded by directing the designation, and President Trump ordered federal agencies to stop using Anthropic's products entirely, with a six-month phase-out for the Defense Department.

A label meant for adversaries, used on a domestic vendor

The "supply chain risk" determination Hegseth invoked draws on 10 U.S.C. § 3252 and the Federal Acquisition Supply Chain Security Act, codified at 41 U.S.C. § 4713 — authorities built to let agencies exclude vendors linked to hostile states from sensitive procurement, not to police a company's public disagreements with a cabinet secretary. Once applied, the label barred any part of the Pentagon, including its contractors, from using Anthropic's products, a step with real financial stakes: Anthropic has separately pursued and discussed federal contracts, including cybersecurity work tied to its newer models, and rival AI vendors stood to gain directly from any exclusion.

Sen. Chris Coons, the ranking Democrat on the Senate Appropriations defense subcommittee, warned in February — months before the ruling — that the designation would not survive judicial review but would do damage regardless. "When this administration takes a page out of Xi Jinping's playbook and tells our leading companies to embrace the party line or lose its contracts, we send a signal to American businesses that working with our government is a dangerous gamble," Coons said in a statement at the time. "The decision to label Anthropic a supply chain risk will likely be thrown out in court, but the consequences will be lasting."

The government's own conduct undercut its case

What makes Judge Lin's opinion notable is not that she deferred to Anthropic's telling of events; it is that the government's own actions contradicted its stated rationale. Even while Hegseth was branding Anthropic a saboteur risk, the Pentagon continued pursuing a contract with the company and worked with its newer model on cybersecurity matters, and Hegseth separately proposed invoking the Defense Production Act to treat Anthropic as essential to national security — the opposite of a threat to it. Lin also found the government's own evidence showed Anthropic "undisputedly lacks" any backdoor into the software it hands over to the Pentagon, undermining the sabotage theory outright.

"Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless." — U.S. District Judge Rita Lin

Lin concluded the record showed the designation was driven by "a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government," reported by TechCrunch and CNN, both of which reviewed the order. That finding — that a national-security determination was substantially a punishment for protected speech and policy positions rather than a genuine security judgment — is what separates this case from an ordinary contracting dispute over which vendor the military prefers. Agencies win those disputes on rational-basis review all the time. What sank the government here was that its own paper trail showed the stated basis was pretextual.

Why a single contract fight is a governance test

An Anthropic spokesperson said the company "welcome[d] the court's ruling that this supply chain risk designation was unlawful" while stressing it wants to keep "working productively with the government to harness AI for our national security." That measured response reflects the case's real stakes for the company: a second, related lawsuit is still pending before a federal appeals court in Washington, and the government is widely expected to challenge Thursday's ruling as well, meaning the underlying fight over how much control a vendor can retain over its own AI's use in military systems remains unresolved.

But the more durable significance runs past Anthropic. The Information Technology Industry Council, a trade group representing major tech contractors, called the ruling clarifying for the entire sector. "Yesterday's ruling removes uncertainty for businesses across industry seeking to partner with the U.S. government," ITI president Jason Oxman said in a statement reported by Nextgov/FCW. That reaction is telling: the companies most exposed here were never just AI labs weighing safety guardrails. They were any federal contractor that might, on some future issue, decline a demand from an agency head and wonder whether "supply chain risk," or some similarly elastic label, could be turned against them next, without the pre-deprivation hearing the Constitution is supposed to guarantee before the government inflicts that kind of commercial harm.

None of this resolves the genuine policy question underneath the lawsuit: how much authority the Pentagon should have to direct how a contractor's AI models get used in weapons systems and surveillance programs it pays for. Defense Under Secretary Emil Michael has argued, separately, that the department will "never again" let itself be dependent on a single AI vendor — a defensible acquisition goal on its own terms, and one that does not require branding a supplier a saboteur to pursue. Reasonable people can disagree about whether an AI company should get to set binding limits on how the military uses a tool it has purchased. That is a legitimate fight to have, through contract terms, procurement rules or legislation. It is a different thing entirely to lose that argument on the merits and then reach for a statute meant for adversary-linked suppliers to punish the company for having made it publicly.

Judge Lin's order draws a sharp line between a legitimate contracting judgment and a punitive designation dressed up as one. Courts do not usually get to see the internal contradictions this clearly; here, the government's simultaneous courtship and blacklisting of the same company put them on the record, and its own request to invoke the Defense Production Act on Anthropic's behalf undercut its own case before Anthropic's lawyers had to. The next agency tempted to reach for a national-security label as a shortcut around a company's protected speech now has a detailed judicial road map of exactly what not to do — and a reminder that "national security," invoked without evidence to back it, is not on its own a legal argument.

More on this story

All Opinion