A federal judge ruled Thursday that the Pentagon’s designation of artificial intelligence company Anthropic as a supply chain risk was unlawful, handing the startup a major legal victory in its monthslong battle with the Trump administration over the military use of AI.
U.S. District Judge Rita Lin, a Biden appointee in the Northern District of California, found that the Department of Defense violated the First Amendment by punishing Anthropic for publicly criticizing the Pentagon’s position on AI use. The designation, issued by Defense Secretary Pete Hegseth in February, marked the first time an American company had been publicly labeled a supply chain risk under an obscure procurement statute aimed at protecting military systems from foreign sabotage.
“The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote in a 59-page decision. She described the Pentagon’s actions as “illegal and baseless” and said the broad measures imposed on Anthropic were “arbitrary and capricious.”
The ruling makes permanent a temporary suspension of sanctions that Lin ordered in March and takes effect immediately. The government may appeal.
How the dispute began
The conflict started this past winter, when Hegseth moved to renegotiate all AI labs’ contracts with the military to allow the Pentagon to use AI for “any lawful use,” which would significantly expand the agency’s authority. Most AI companies signed onto the new terms. Anthropic refused.
Anthropic set two red lines. The company would not allow its Claude AI models to be used for mass surveillance of Americans or for lethal autonomous weapons, systems with the power to kill targets without human oversight. Anthropic has said its models are not reliable enough to be safely used in autonomous weapons and that it opposes domestic surveillance as a violation of rights. The Pentagon countered that private companies should not be able to constrain military action.
Talks escalated and then collapsed. Less than 24 hours before a final ultimatum from the Trump administration, Anthropic CEO Dario Amodei issued a statement that the company would not change its stance, writing that Anthropic had “never raised objections to particular military operations nor attempted to limit use of our technology in an ad hoc manner” but that in a “narrow set of cases, we believe AI can undermine, rather than defend, democratic values.”
After Anthropic’s refusal, Trump lashed out at the company in a February social media post, calling it “a radical left, woke company” and “out-of-control.” The White House argued the military was beholden to the U.S. Constitution, “not any woke AI company’s terms of service.” The Pentagon then designated Anthropic a supply chain risk, a classification typically reserved for companies based in countries that pose a threat to the United States. The designation barred defense contractors from using Anthropic’s technology in their work with the agency, and the Pentagon moved to replace Anthropic’s influence by signing deals with seven other AI labs, including Google, Microsoft, OpenAI, and SpaceX.
The legal fight
Anthropic sued the Trump administration in March in San Francisco, alleging the government violated its right to free speech under the First Amendment by retaliating against its views on AI safety. The company also said it was not given a chance to dispute the designation, in violation of its Fifth Amendment right to due process. The lawsuit called the government’s actions both “unprecedented and unlawful,” unsupported by facts and inconsistent with the military’s past praise of Claude.
The Justice Department countered that Anthropic’s refusal to lift its restrictions could cause uncertainty in the Pentagon over how it could use Claude and risk disabling military systems during operations. The government said the designation stemmed from Anthropic’s refusal to accept contractual terms, not its views on AI safety. Lin rejected that argument. She wrote that while the government is owed deference on matters of national security, its actions were not founded on any “articulable basis,” and that neither the Constitution nor the federal statute invoked allowed officials to impose sweeping penalties based principally on Anthropic’s critique of the administration’s views.
In an earlier round of the lawsuit, Lin said the government was trying to “cripple” the company and “chill public debate” over military use of AI. “This appears to be classic First Amendment retaliation,” she wrote at the time. On Thursday, she barred the federal agencies named in the lawsuit from enforcing Trump’s order to stop using Anthropic’s tools and overturned Hegseth’s designation.
Anthropic welcomed the ruling. “We welcome the court’s ruling that this supply chain risk designation was unlawful,” a spokesperson said. “We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.”
The victory is not total. The Pentagon relied on two distinct designations to justify its supply chain risk action, which had to be litigated in two separate courts. Anthropic has a second lawsuit pending in Washington, D.C., over a separate supply chain risk designation that could lead to its exclusion from civilian government contracts. Until that case is resolved, Anthropic still technically remains a supply chain risk. The suits would not require the Pentagon to restart its work with the company even if Anthropic prevails in both venues, but the rulings could clear the way for the company to reestablish ties that had been cut off, reopening business opportunities at a moment when Anthropic is marching toward what is expected to be a near-record IPO.
