
A U.S. federal judge has overturned the Pentagon’s designation of Anthropic as a national-security supply-chain risk, finding that the government’s broad measures were unlawful and unsupported by a genuine sabotage concern.
U.S. District Judge Rita Lin’s 59-page ruling is the final merits decision in the San Francisco case, following the preliminary injunction she issued in March. The court ordered the Pentagon to vacate the designation and rescind the directives built around it. The government is expected to challenge the ruling.
The dispute was about control, not a technical breach
The conflict began after negotiations over military use of Claude broke down. Anthropic maintained restrictions intended to prevent its models from being used for mass surveillance or fully autonomous weapons, while the Pentagon argued that it should be able to use an AI system for any lawful purpose.
That disagreement escalated far beyond a normal vendor decision. Anthropic was branded a supply-chain risk, federal agencies were directed away from its products, and military contractors faced restrictions on doing business with the company. The designation carried the language and commercial consequences of a security finding even though the dispute centered on policy and contract terms.
A government buyer can walk away—but it cannot retaliate
The court did not say the Pentagon must buy Claude or accept Anthropic’s conditions. Government agencies remain free to choose other suppliers and to transition away from a vendor whose product or contract does not meet their operational needs.
The boundary is what happens next. Lin found that officials used sweeping penalties to make an example of Anthropic for criticizing the government’s approach to AI use, rather than identifying an articulable reason to believe the company would sabotage its model. In other words, procurement discretion did not create a blank check to punish protected expression.
That distinction matters because public procurement is unusually powerful in frontier AI. A federal customer can influence revenue, infrastructure partnerships, investor confidence, and whether contractors are willing to integrate a model. When those tools are used beyond the decision to buy—or not buy—they can shape the safety policies of an entire industry.
The ruling gives AI safety limits legal weight
AI developers regularly describe safety commitments as internal policies. This case shows that those policies can become hard commercial boundaries when a customer wants capabilities the developer will not provide. It also shows the pressure a company may face when the customer is the government and national security is invoked.
The ruling does not settle where every safety boundary should sit. Nor does it give private AI companies authority over military policy. It establishes a narrower but important principle: refusing a deployment and publicly defending that refusal are not, by themselves, evidence that a domestic technology supplier is a security threat.
What changes for technology companies
For companies selling AI into government, the lesson is to make usage policies operationally precise. Safety limits need clear definitions, contract language, escalation paths, technical enforcement, and records showing why a restriction exists. Vague principles are difficult to defend when they collide with a mission-critical deployment.
Government buyers also need a cleaner separation between vendor suitability and retaliation. A supplier may be the wrong fit for a program without being an adversary. Preserving that distinction protects procurement credibility and gives the market a more honest signal about whether a decision reflects capability, contract terms, or verified security risk.
Our earlier coverage of the preliminary injunction examined the court’s first intervention. The final ruling now turns that provisional warning into a concrete limit: national-security authority remains broad, but it still requires evidence and lawful purpose.