What the court found
On August 27, 2026, U.S. District Judge Rita Lin of the Northern District of California ruled that the Pentagon's designation of Anthropic as a "supply chain risk" was unlawful on three independent grounds: it was retaliation for constitutionally protected speech in violation of the First Amendment, it was "arbitrary and capricious" agency action under the Administrative Procedure Act, and it denied Anthropic due process under the Fifth Amendment (TechCrunch). Lin ordered the designation removed. "The empty invocation of national security is not a blank check to punish and retaliate against government critics," she wrote (Nextgov/FCW).
The dispute began earlier this year when Defense Secretary Pete Hegseth and President Trump labeled Anthropic a supply-chain risk and directed every federal agency — not just Defense — to stop contracting with the company. The trigger was Anthropic's refusal to drop two guardrails on Claude: a bar on its use in fully autonomous lethal weapons decisions and a bar on its use for mass surveillance of American citizens. The Pentagon denied it intended any unlawful use and characterized Anthropic's position as an attempt to control how the military uses tools it purchases (TechCrunch).
Anthropic sued in March, raising five counts under the APA and the First and Fifth Amendments (Lawfare). The government had invoked two separate authorities to make the designation stick: 10 U.S.C. § 3252, the Pentagon's own supply-chain exclusion statute, and the Federal Acquisition Supply Chain Security Act's § 4713 (Just Security). Lin's August ruling addresses the § 3252 designation; a narrower fight over the § 4713 designation is still pending before the D.C. Circuit (Fortune) — this case is a major defeat for the administration, not the final word.
The evidence of pretext
What seems to have moved the court most was internal inconsistency in the government's own conduct. Lin pointed to the fact that Hegseth had separately proposed invoking the Defense Production Act to declare Anthropic essential to national security — the opposite of a supply-chain threat — and that the Department of Defense kept pursuing a new contract with the company even after branding it a risk (TechCrunch). Fortune reported Lin concluded the real motive was a desire "to make a public example out of Anthropic for its 'arrogance'" (Fortune). A national security agency cannot simultaneously court a vendor as indispensable and blacklist it as dangerous — that contradiction is what turned a discretionary label into evidence of retaliation.
Steelmanning the Pentagon's case
The government's underlying instinct is not unreasonable. Agencies buying software for sensitive defense systems have a legitimate interest in vendors that won't unilaterally dictate how lawful government functions get performed, and Congress gave the Pentagon supply-chain exclusion authority precisely so it wouldn't have to litigate every procurement decision involving a sensitive vendor. 10 U.S.C. § 3252 lets agency heads exclude sources found to pose a "supply chain risk" — defined as the risk that an adversary may sabotage, maliciously introduce unwanted function into, or otherwise subvert a covered system — and Congress deliberately insulated those calls from bid-protest and federal-court review (Cornell Law). If a vendor really were compromised by a foreign adversary, speed and discretion matter more than due process for the vendor.
But that is precisely the gap between the statute's purpose and its use here. Section 3252 was built to counter adversarial subversion — foreign sabotage, hidden backdoors, compromised components — not a domestic company's public, values-based limits on how its own product may be used. Anthropic's refusal to permit autonomous-kill-decision or mass-surveillance use cases is not sabotage; it is a contractual term any vendor is free to set. Treating a supplier's ethical red line as a national-security defect stretches the statute past its text, and doing so because the company voiced that position in public is textbook viewpoint retaliation. Congress's decision to strip judicial review from ordinary § 3252 determinations only sharpens the problem: without constitutional claims as a backstop, an agency could use this authority to punish any contractor's protected speech with no court ever looking at it. Lin's ruling shows the constitutional floor held — but only because Anthropic had the resources to litigate for nearly six months against exactly the kind of unreviewable, discretionary power Congress built.
Why this matters beyond one company
The government now buys AI at a scale where procurement leverage doubles as content-moderation-by-other-means: an agency that cannot force a vendor's design choices through regulation can still starve it of federal revenue for holding a disfavored position. That precedent would have chilled every AI lab from stating safety commitments publicly, since doing so could become the pretext for a "security" designation. A predictable, viewpoint-neutral supply-chain security process — one that actually targets sabotage risk rather than corporate dissent — is a precondition for a healthy federal AI market, not an obstacle to one. The Pentagon is expected to appeal, and the parallel FASCSA fight continues in the D.C. Circuit, so the underlying question of how far procurement coercion can reach into vendor speech is far from settled.