A federal judge has ruled that the Pentagon illegally blacklisted Anthropic as a national security threat. Part of the Pentagon’s case rested on capabilities Claude does not have. US District Judge Rita Lin found that the Pentagon retaliated against Anthropic for public criticism. It also denied the company due process and applied an unlawful supply-chain risk designation.
The Anthropic blacklist traces back to February. The company had declined Pentagon requests to strip out safeguards that block autonomous weapons targeting and mass surveillance uses of Claude. Defense Secretary Pete Hegseth called Claude’s abilities “exquisite.” He gave Anthropic three days to comply and threatened to invoke the Defense Production Act if it refused.
How the Anthropic blacklist began
The Pentagon’s national security assessment claimed Anthropic could remotely alter, disable, or corrupt Claude models already deployed inside government systems. Judge Lin rejected that claim as “entirely unfounded.” Anthropic has no way to access or modify static models once the Pentagon integrates them into its own infrastructure, she noted.
Lin also found no record of prior supply-chain concerns about Anthropic in the government’s own files. She concluded that “the Pentagon assembled its case after the fact” to support a decision it had already made. She pointed to a telling inconsistency, too. After issuing the blacklist, the Under Secretary of Defense kept negotiating contracts with Anthropic, writing at one point, “I think we are very close here.”
Public statements from the administration reinforced the retaliation finding. President Trump described Anthropic as a “RADICAL LEFT, WOKE COMPANY,” and internal Pentagon memos complained about the company’s “increasingly hostile manner through the press.” Lin wrote that “an IT vendor does not become a potential adversary of the United States whenever it asks probing questions.” She warned against blacklisting companies simply for being “too arrogant or difficult to trust.”
Fallout beyond the Pentagon
Hegseth’s directive did not stop at the Pentagon’s own contracts. It discouraged every Pentagon contractor from working with Anthropic at all, a move that drew concerns from more than 100 enterprise customers. Anthropic has estimated the fallout could cost it billions of dollars in lost revenue if the designation had stood.
The dispute started after Anthropic held firm on usage rules it applies to every government customer, not just the Pentagon. Those rules bar Claude from powering autonomous weapons targeting or bulk surveillance of Americans. Anthropic has kept those restrictions in place since it began selling to federal agencies.
The ruling does not strip the Pentagon of its purchasing authority. Judge Lin affirmed that the agency can still end its Anthropic contracts through ordinary procurement channels. What it cannot do, according to the ruling, is use a national security label as cover for punishing a vendor that pushed back in public. For other AI vendors selling into the federal government, the case sets a concrete boundary. A customer can walk away from a contract, but it cannot invent a security threat to punish a company for saying no.