Key takeaways
- A federal judge ruled Thursday that the Trump administration's supply chain risk designation of Anthropic was unconstitutional retaliation for the company's safety guardrails on autonomous weapons and surveillance.
- Judge Lin found the ban violated the First Amendment, denied Anthropic due process, and contradicted the government's own pursuit of contracts and collaboration with the company on cybersecurity projects.
- The Department of Defense continued actively seeking partnerships with Anthropic and working with its Mythos model for cybersecurity even while the formal supply chain ban remained in place.
A federal judge in California has struck down the Trump administration’s designation of Anthropic as a supply chain risk, marking the first significant legal victory for the AI company in its conflict with the Pentagon over safety standards for advanced models.
U.S. District Judge Rita Lin issued the ruling Thursday evening, concluding that Defense Secretary Pete Hegseth’s decision to label Anthropic as a national security threat violated constitutional protections. Lin characterized the government’s action as “unlawful retaliation” in violation of the First Amendment and found that Anthropic was denied due process protections required under the Fifth Amendment. The judge also determined that the designation was “arbitrary and capricious,” a legal standard indicating that the government had acted without rational basis or factual support for its conclusions.
How the Conflict Began
The Trump administration, through Defense Secretary Pete Hegseth and President Donald Trump, had designated Anthropic as a supply chain risk earlier this year. The label came with an explicit directive: all federal agencies, including those outside the Department of Defense, were ordered to cease all business relationships with the company immediately. This sweeping action placed Anthropic in a category typically reserved for vendors believed to pose direct threats to national security or infrastructure.
The underlying disagreement centered on a fundamental question about who controls the deployment of AI systems purchased by the U.S. government. Anthropic had established firm safety guardrails governing how its models could be used, refusing to enable certain applications. The Pentagon viewed these restrictions as an overreach by the private company into military decision-making and strategic autonomy.
The Core Dispute Over AI Weaponization and Surveillance
Anthropic’s Safety Requirements
Anthropic had drawn specific lines regarding military applications of its Claude models. The company declined to permit the Pentagon to deploy its technology for fully autonomous weapons systems—allowing machines to select and engage targets without human intervention—or for mass surveillance operations targeting American citizens. These were not hypothetical concerns; they represented concrete use cases that the Pentagon had, at least discussed or considered.
The Pentagon’s Counterargument
Military officials pushed back against Anthropic’s restrictions, arguing that the company was overstepping its authority once the U.S. government had purchased its models. The Pentagon insisted that it had no intention of using Anthropic’s technology for any unlawful purposes, noting that federal law and presidential executive orders already constrain how the military can deploy AI. From the Pentagon’s perspective, allowing a private company to impose additional restrictions on purchased technology amounted to Anthropic asserting control over how the military conducted its operations.
The National Security Framing
The government cast the dispute as a matter of national security, arguing that Anthropic posed a risk to the defense industrial base precisely because it claimed the ability to restrict how its tools were used by the military. This framing implied that Anthropic’s insistence on safety guardrails itself constituted a threat—a turnabout that would later become central to the court’s reasoning.

The Contradictions That Undermined the Ban
Defense Production Act Paradox
Judge Lin’s decision zeroed in on a critical inconsistency within the government’s own policies. While designating Anthropic as a supply chain risk, Hegseth had separately proposed invoking the Defense Production Act against the company. Under that law, invoking it against a company is meant to classify that entity as essential to national security—the opposite of the rationale for a supply chain risk designation. If Anthropic was essential to national security, as the DPA invocation would suggest, how could it simultaneously be a threat warranting a complete ban on federal business?
Ongoing Pentagon Contracts and Collaboration
The government’s actions revealed further contradictions. Even as the supply chain risk ban was in place, the Department of Defense continued actively pursuing contracts with Anthropic. The government was also collaborating with the company on development and testing of Mythos, Anthropic’s newer model, specifically for cybersecurity applications. These parallel efforts to work with Anthropic on strategically important projects undermined any credible argument that the company posed an unacceptable security risk.
The Retaliation Conclusion
Examining the totality of the government’s “words and deeds,” Lin concluded that the supply chain risk designation was motivated not by genuine national security concerns but by a desire to make “a public example out of Anthropic for its ‘arrogance’ in criticizing the government.” The company had publicly articulated its safety concerns and refused to bend to Pentagon pressure—positions that, the court found, the administration sought to punish through regulatory designation.
Constitutional Violations
Lin identified multiple constitutional problems with the government’s action. First, she found a First Amendment violation: Anthropic’s public stance on AI safety and its criticism of the Pentagon’s intended uses of its models constituted protected speech, and the supply chain designation appeared to retaliate against the company for that expression. Second, the company was deprived of Fifth Amendment due process protections, receiving no meaningful opportunity to be heard or to challenge the designation through established legal procedures before the ban was imposed.
The ruling on arbitrary and capricious action was grounded in the record itself. Anthropic had presented undisputed evidence that once its technology was delivered to the DOD, the company retained no backdoor access or ability to monitor or control its use. The government’s central security rationale—that Anthropic could somehow subvert or interfere with military use of the models—had no factual foundation.
In her written decision, Lin stated: “Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless. The empty invocation of national security is not a blank check to punish and retaliate against government critics.”
Anthropic’s Path Forward
Anthropic issued a measured response to the ruling. An official spokesperson said the company welcomed “the court’s ruling that this supply chain risk designation was unlawful.” Rather than taking a victory lap, Anthropic signaled a pragmatic interest in repairing its relationship with the government, stating it remains “focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.”
The statement reflected the reality that Anthropic, despite winning this round, operates within an ecosystem where Pentagon dollars and partnerships are significant and strategically important. The company also faces a political administration that has shown willingness to use regulatory power against companies it views as obstacles.
The Litigation Continues
Thursday’s ruling resolves the California case, but it is not the end of Anthropic’s legal battles with the government. In March, the company filed two separate lawsuits challenging the supply chain designation—one in federal court in California, where it prevailed, and another in Washington, D.C. The D.C. case remains pending, meaning additional courts may yet examine different legal theories or factual aspects of the government’s actions against Anthropic.
The California ruling provides a blueprint and precedent for the D.C. litigation, though outcomes in different jurisdictions and before different judges are never assured. What remains clear is that the courts are willing to scrutinize executive branch actions against AI companies, even when national security is invoked as justification.
Frequently Asked Questions
What did the Trump administration order when it designated Anthropic as a supply chain risk?
The administration ordered all federal agencies, both inside and outside the Department of Defense, to stop all business relationships with Anthropic immediately.
What specific military applications did Anthropic refuse to enable?
Anthropic declined to allow the Pentagon to use its models for fully autonomous weapons systems that could select and engage targets without human intervention, or for mass surveillance targeting American citizens.
What contradiction did Judge Lin find most problematic in the government's position?
While banning Anthropic as a security threat, Defense Secretary Hegseth proposed invoking the Defense Production Act against it, which classifies companies as essential to national security—the opposite of the ban's stated rationale.