A federal judge has permanently voided the Pentagon’s designation of Anthropic as a national-security “supply chain risk,” finding that the government used a security procurement authority to retaliate against the maker of Claude over its restrictions on domestic surveillance and autonomous weapons. The immediate consequence is that federal agencies and contractors can no longer rely on that designation or the related blacklisting directives to exclude Anthropic.

Computerworld first reported the decision, issued late on Thursday, August 27, by U.S. District Judge Rita F. Lin in San Francisco. Lin granted Anthropic major portions of its summary-judgment motion and held that the administration violated the company’s First Amendment rights, denied it the pre-deprivation process required by the Fifth Amendment, and acted arbitrarily and capriciously under the Administrative Procedure Act.

This is not a ruling that forces the Defense Department to buy Claude, renew a contract, or reverse its move toward other AI suppliers. It is a ruling that says the government cannot turn a procurement-security designation into a punishment for a vendor’s public policy position.

Legal technology scene with a gavel, privacy-marked documents, AI interface, servers, and government buildings.The ruling turns on what a supply-chain risk actually means​

The Pentagon’s label carried unusually broad consequences. A supply-chain-risk designation is intended to protect national-security systems from vendors or components that an adversary could use to sabotage, subvert, or introduce malicious functionality into technology used by the government. In normal terms, it is an anti-tampering and anti-infiltration tool.

The court’s record showed that the government tried to apply that authority to Anthropic after negotiations broke down over restrictions on how the military could use Claude. Anthropic had objected to use of its models for mass surveillance of Americans and for fully autonomous weapons. The Pentagon argued that those constraints made the company an unacceptable risk.

Lin rejected the basic premise. Her March preliminary-injunction ruling had already found that the relevant statute, 10 U.S.C. § 3252, addresses the risk of an adversary sabotaging or subverting a covered system. In that earlier decision, she wrote that public restrictions and negotiating positions do not resemble covert sabotage, malicious code insertion, or an attempt to compromise an IT system.

The final ruling goes further. Reuters reported that Lin found no material dispute that Defense Secretary Pete Hegseth’s designation violated the governing statute and was arbitrary and capricious. The court did not decide that every AI vendor restriction is reasonable or that the Pentagon must accept Anthropic’s terms. It found that the government’s chosen legal mechanism did not fit the alleged problem.

For enterprise IT leaders, that distinction is more than legal terminology. A genuine software supply-chain finding should identify a technical or operational risk: malicious updates, compromised build infrastructure, hidden remote access, coercive foreign control, or a credible path to subversion. A supplier’s refusal to license a model for a requested purpose belongs in contracting, policy, and vendor-management processes. Conflating the categories weakens both.

The court found retaliation, not a disputed security assessment​

The most consequential part of Lin’s decision is the constitutional finding. According to the Associated Press, the judge concluded that the government’s actions were based on a desire to make an example of Anthropic for criticizing the administration’s position, rather than on an articulable basis to believe Anthropic would sabotage its model.

That finding matters because courts generally give the executive branch wide latitude on national-security assessments. The administration argued that large AI models are opaque and difficult to evaluate in the way the government might assess physical hardware. That is not a frivolous operational concern: foundation models do create difficult questions around provenance, model updates, data handling, privileged access, and whether a vendor can reliably explain model behavior.

But uncertainty about AI is not itself evidence that a particular provider will compromise a government system. The court found that the record did not support the government’s claimed inference from Anthropic’s contract position to sabotage risk. The technical question of how to secure a model was effectively displaced by a political question over what the model could be used to do.

Lin’s opinion therefore offers a warning that reaches beyond Anthropic. National-security language does not remove the need for a factual record, statutory authority, and process. Agencies can impose security restrictions, but they must establish a connection between the supplier and the risk the law authorizes them to address.

The ruling also narrows a potentially dangerous precedent for software firms. If an agency could blacklist a domestic vendor as a supply-chain threat merely because the vendor objected to an end use, companies selling cybersecurity products, cloud services, developer tools, endpoint-management platforms, and AI systems would have a powerful incentive to avoid publicly challenging government demands. That would make contractual guardrails less meaningful precisely where the technology can be deployed at scale.


The designation had already been frozen, so the operational change is limited​

The final ruling is legally significant, but it does not mean government IT departments will suddenly reinstall Claude or unwind every contingency plan created this spring. Lin had temporarily blocked enforcement of the designation in March while the case proceeded, meaning the blacklist had been halted before it could fully take effect.

That timing is important. Contractors and agencies may still have moved workloads, revised procurement plans, restricted access to Claude, or selected alternatives to avoid legal and political uncertainty. Those business decisions are not automatically undone by the court order.

Bloomberg, as carried by The Business Times, reported that a government lawyer said in late July that the Pentagon had continued winding down its Anthropic use and aimed to complete the process by September 30. That reported timetable should not be mistaken for a court mandate. It reflects a potential procurement choice, and Lin specifically said the Pentagon remains free to transition to other AI providers so long as it acts consistently with applicable laws and regulations.

The practical outcome is therefore narrower than headlines about a “ban lifted” suggest:

  • Federal agencies and contractors should no longer treat Anthropic as formally disqualified by the vacated supply-chain-risk designation.
  • The Defense Department can still choose not to use Claude, decline renewals, or select another provider through ordinary procurement channels.
  • Organizations that removed Claude solely because of the government’s designation should review the legal and procurement basis for that decision, rather than assuming the original exclusion remains in force.
  • Organizations that continue to use Anthropic tools still need their own risk assessments covering data classification, model access, tenant isolation, logging, retention, export controls, and contractual use restrictions.

For systems administrators, the central task is not to reverse a vendor decision overnight. It is to separate policy-driven emergency controls from controls justified by a documented technical risk. A block on a sanctioned or compromised supplier belongs in endpoint, identity, network, and software-allowlisting systems. A temporary vendor freeze caused by an unsettled government directive should have a different owner, a different review date, and a documented exit condition.

The case leaves one separate dispute unresolved​

Anthropic’s win in Northern California does not close every case tied to its clash with the Pentagon. The Associated Press reported that Anthropic has a separate, narrower challenge pending in the federal appeals court in Washington, D.C., involving a different rule the Pentagon used in seeking to characterize the company as a supply-chain risk.

That pending matter is the main reason contractors should resist declaring the entire conflict over. The August 27 ruling disposes of the challenged designation and related actions in Lin’s case, but the broader relationship between Anthropic and the military remains unsettled. An appeal by the government is also possible.

Still, the decisive fact from this ruling is already clear: the government lost after attempting to use a statutory supply-chain-security tool against a domestic AI vendor whose alleged offense was refusing unrestricted military use of its product. The court found the designation unlawful on statutory, administrative-law, due-process, and First Amendment grounds.

For federal contractors and the IT teams supporting them, the immediate action is to update vendor-risk registers and procurement notes. Anthropic is no longer carrying a valid Pentagon supply-chain-risk designation under this ruling; whether an organization uses Claude next is again a normal security, compliance, and contracting decision—not compliance with a voided blacklist.