A federal judge in San Francisco has struck down the Pentagon's blacklisting of Anthropic, ruling that the Defense Department designated the AI company a "supply chain risk" in retaliation for its public speech — a violation of the First Amendment, according to CNBC. U.S. District Judge Rita Lin ordered the designation removed in a ruling issued Thursday evening.
Lin found that the Department of Defense designated Anthropic a supply chain risk "based on a desire to make a public example" of the company. While acknowledging that the government is owed deference on matters of national security, she wrote that its actions were not founded on any "articulable basis." For more context on this story, see our ongoing AI trends.
"Defendants claim that because of Anthropic's 'increasingly hostile manner through the press' and its criticism of the Department of War's views on AI use, Defendants 'cannot trust Anthropic to ensure the integrity of its models,'" Lin wrote in her order. "Neither the Constitution nor the federal statute invoked by Defendants allows them to impose sweeping penalties based principally on Anthropic's critique of the Administration's views."
How the dispute began
The blacklisting dates to March, when the Defense Department formally designated Anthropic a supply chain risk — a label implying the company threatened U.S. national security — after negotiations over how the military could use its Claude AI models spiraled out of control, CNBC reported.
At the heart of the collapse were two irreconcilable demands. Anthropic sought binding assurances that its technology would never be used for fully autonomous weapons or domestic mass surveillance. The Pentagon, for its part, insisted on unfettered access to Claude across all lawful purposes. Talks escalated and then fell apart, and Anthropic became the first American company to be publicly named a supply chain risk. The designation barred defense contractors from using Anthropic's technology in their work with the agency.
Anthropic sued the Trump administration in both San Francisco and Washington, D.C., in an effort to reverse its blacklisting. Because the Defense Department relied on two distinct legal designations, the cases had to be litigated in two separate courts.
A partial victory, with the second fight ongoing
Lin's ruling is a major win for Anthropic, but it is not the end of the road. The company's litigation in Washington, D.C. — over a separate supply chain risk designation that could lead to its exclusion from civilian government contracts — remains pending, as The Guardian noted in its coverage. Until that case is resolved, Anthropic technically remains a designated supply chain risk.
Anthropic welcomed the decision. "We welcome the court's ruling that this supply chain risk designation was unlawful," a company spokesperson told CNBC. "We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology."
The ruling also clears a significant hurdle for Anthropic's business trajectory. The company is widely reported to be marching toward what is expected to be a near-record IPO, and while it has shown no visible slowdown since the blacklisting, restoring its standing with the Pentagon could reopen defense business opportunities that were cut off when contractors became barred from using its models. Anthropic has said its lawsuits aim to return the business to the status quo that existed before the designation — though the suits do not, on their own, require the Pentagon to resume working with the company.
Why the ruling matters beyond Anthropic
The decision is being read as a landmark test of how far the government can go in punishing AI companies for their public positions. Judge Lin's order rejects the core theory underpinning the blacklist: that an AI lab's refusal to drop safety restrictions on its models — or its criticism of administration policy — can itself be treated as evidence of disloyalty or unreliability.
That principle has implications for every frontier lab negotiating with Washington. Several major AI companies have spent 2026 navigating a White House framework review process that conditions federal favor on model access and security arrangements, and Anthropic's case was widely viewed as the stress test of how much leverage the government could bring to bear on a lab that refuses to cooperate on the government's terms.
For now, at least in the Defense Department's case, a federal judge has answered: not this much. Reuters characterized the ruling as the latest turn in the Claude maker's high-stakes fight with the military over AI safety on the battlefield — a fight that now moves to the D.C. courthouse for its second act.
For more on the policy fight over frontier AI, see our coverage of the White House AI framework review and the government's escalating scrutiny of Chinese models.
What a supply chain risk designation actually does
The label at the center of the case is one of the most severe tools available to the Defense Department. A supply chain risk designation signals that a company is presumed to threaten U.S. national security, and in Anthropic's case it effectively walled the company off from the defense industrial base: defense contractors were barred from using Anthropic's technology in their work for the agency. For an AI lab whose models compete for sensitive government and government-adjacent workloads, the designation functioned as an exclusion order without a trial.
Anthropic's designation was also historically notable. As CNBC's account of the litigation notes, the company was the first American firm to be publicly named a supply chain risk — an escalation that turned a contract negotiation into a constitutional test case.
The speech question at the center of the ruling
Judge Lin's order is built on a retaliation theory: the government crossed the line from evaluating a vendor's reliability into punishing the vendor for what it said in public. Her order quoted the government's own justification — that Anthropic's "increasingly hostile manner through the press" and its criticism of the Department of War's positions meant officials "cannot trust Anthropic to ensure the integrity of its models" — and rejected it as a basis for the designation.
The ruling leaves the government's national security deference intact but bounded. Lin wrote that the actions were not founded on any "articulable basis," and that neither the Constitution nor the federal statute invoked by the Defense Department permits "sweeping penalties based principally on Anthropic's critique of the Administration's views." In plain terms: national security is not a blank check to blacklist a company for its editorial line.
One limit on the victory is worth stating clearly. Anthropic's lawsuits seek to undo the penalty, not to compel new business. As the company has said, the suits would not require the Pentagon to restart its work with the company — they aim to return Anthropic to the status quo before the designation, leaving any renewed defense relationship to a future negotiation that both sides would have to choose.
What comes next
The second front of the litigation now takes center stage. Anthropic's case in Washington, D.C. challenges a separate supply chain risk designation — one that could lead to its exclusion from civilian as well as defense government contracts — and remains pending, The Guardian reported. Until that case is resolved, Anthropic technically remains a designated supply chain risk.
The stakes extend well past one company. Frontier labs are negotiating with Washington in real time over model access, security arrangements, and the terms of public sector deployment, and Anthropic's case was widely viewed as a stress test of how much leverage the government could exert over a lab that publicly resists those terms. A federal judge has now answered that question for the Defense Department's designation. The D.C. court will say whether the answer holds across the government.
---
Stay Ahead of AIGet the latest AI news, analysis, and breakthroughs — all in one place.
Read more AI news →