A federal court has ruled that the Pentagon used national-security procurement law as a punishment system. On August 27, U.S. District Judge Rita Lin granted Anthropic summary judgment on its First Amendment, due-process, and Administrative Procedure Act claims. Her 59-page order found that the government had converted a contract dispute into a company-wide blacklist without evidence that Anthropic posed a distinct technical threat.
This revisits Fable 5 Turned Model Access Into an Export-Control API, which examined classifiers, retention, customer gates, and government review around frontier-model access. The new development reaches the opposite direction of control. The government tried to turn Anthropic’s refusal to remove two usage restrictions into a supply-chain designation, a federal purchasing ban, and a boycott by defense contractors. The court’s merits judgment defines where vendor selection ends and retaliatory exclusion begins.
Two clauses became a national-security feud
Anthropic had supplied Claude to U.S. intelligence and defense agencies since 2024. The company held a Top Secret facility clearance, received high-level federal cloud authorizations, and won an agreement worth up to $200 million to integrate AI capabilities across the military. The Pentagon later demanded contract language allowing every lawful use of Claude. Anthropic accepted broad military use while retaining restrictions on lethal autonomous warfare and mass surveillance of Americans.[1]
Those restrictions were contractual. The court found that Anthropic could not remotely alter or disable Claude Gov after deployment, could not see how the Pentagon used the model, and had no technological route to enforce the disputed clauses inside military systems. The government’s administrative record eventually conceded that Anthropic’s model carried the same basic black-box risk as competing AI systems.[1]
The Pentagon remained free to choose another vendor. It had several. Secretary Pete Hegseth said as much during negotiations. The escalation began when the government attached a national-security label to Anthropic itself, ordered federal agencies to stop using its products, and told defense contractors to stop doing business with the company even on work unrelated to the military.[1][2]
The administrative record was four pages thin
The legal collapse began with the evidence. The government’s complete rationale rested on a four-page memorandum written after two of the three challenged actions. The memo initially leaned on a theory that Anthropic retained backdoor access to deployed models. The developed record killed that claim. The company lacked such access, and the government backed away from it.[1]
That left “trust.” Officials argued that Anthropic’s public criticism and “increasingly hostile manner through the press” made the company untrustworthy. The court compared that assertion with the government’s behavior. Days before the blacklist, Hegseth had considered using the Defense Production Act, a move that would treat Anthropic as essential to national security. After the blacklist, officials kept negotiating with the company and described a deal as close. The government also continued discussing sensitive uses for Anthropic’s Mythos model.[1]
Those facts made the sabotage framing look absurd. A government that genuinely believed a vendor might poison military software would not keep pursuing contracts and sensitive collaboration with that vendor. Lin found that officials wanted to make a public example of Anthropic for its “arrogance” in criticizing the administration. Reuters reported the court’s description of the measures as “illegal and baseless.”
The ruling does not grant Anthropic a right to a Pentagon contract. It constrains the route government can use after rejecting one. Agencies can select products, negotiate terms, terminate relationships, and account for genuine security risks. They cannot invent a sabotage case from a policy disagreement, bypass notice and response, then spread the penalty through the contractor economy.
The label was designed for infiltration, not disobedience
The supply-chain statute at issue, 10 U.S.C. § 3252, addresses threats to national-security systems. The court found that Anthropic did not fit the statutory definition of a supply-chain risk. The record contained no basis to believe the company would sabotage Claude, insert malicious code, or allow an adversary to compromise military systems. A disagreement over permitted uses could justify choosing a competitor. It could not support a designation built for infiltration and sabotage.[1]
The contractor order exceeded the statute again. It reached business unrelated to the national-security system supposedly at risk. That secondary boycott threatened Anthropic’s commercial relationships across the defense industrial base. The order describes unrebutted evidence that reinstatement could cut defense-related customer revenue by 50 to 100 percent and reduce 2026 revenue by billions of dollars.[1]
This mechanism matters beyond one AI company. Modern government software arrives through clouds, integrators, resellers, model hosts, consultancies, and subcontractors. A supply-chain label can propagate through every layer without a formal debarment proceeding. Risk teams react before courts do. Customers flee ambiguity. Procurement officers choose the vendor whose name does not require a legal memo. The label can cause most of the damage before anyone tests its factual basis.
Due process exists for this exact reason. The court found a serious risk of erroneous deprivation and no emergency that justified skipping notice and a chance to respond. The preliminary injunction had already been in place for five months without the government identifying a concrete national-security harm. Lin denied a requested seven-day stay and held that vacatur alone would leave the constitutional injury and chilling effect insufficiently addressed.[1]
AI vendors now write policy inside procurement contracts
Anthropic’s restrictions still deserve scrutiny. A private model vendor can shape military capability by deciding which uses its product will support. That power grows when one provider becomes embedded across agencies and contractors. The Pentagon’s frustration came from a real governance problem: a government buyer wanted operational control over a strategic tool, while the vendor claimed responsibility for two failure modes it considered unsafe or unlawful in practice.
The sane response was contractual separation. The Pentagon could walk away, build another stack, demand transparent guarantees from a willing vendor, or pursue legislation governing autonomous weapons and domestic surveillance. The blacklist tried to win the policy dispute by changing Anthropic’s status in the market.
That move also exposed the double role assigned to AI labs. Government treats them as ordinary contractors when negotiating price and terms, strategic infrastructure when demanding access, expert authorities when seeking safety assurances, and disloyal political actors when their safety position becomes inconvenient. Those roles carry incompatible expectations. Procurement law cannot cleanly resolve them, but it can stop officials from laundering retaliation through technical-risk vocabulary.
CNN’s account notes that the designation had previously been used against companies linked to foreign adversaries. Applying it to the first American company because of a public contract dispute expanded a security instrument into domestic economic discipline. The court forced that expansion back into constitutional and statutory boundaries.
Anthropic won this round because the government chose the loudest and weakest control surface. It had procurement discretion, alternative vendors, contract terms, legislation, and ordinary security review available. It reached instead for a label that implied sabotage, spread through contractor relationships, and punished speech. The court’s answer was blunt: national security carries enormous weight, but the words do not become evidence by repetition.