A federal judge in California has handed Anthropic an early court victory in its fight with the Trump administration over a national security label that threatened the AI company’s federal business.
U.S. District Judge Rita Lin ruled on Thursday evening that Defense Secretary Pete Hegseth’s designation of Anthropic as a supply chain risk was illegal. The ruling said the move amounted to “unlawful retaliation” under the First Amendment, was “arbitrary and capricious,” and denied Anthropic due process required by the Fifth Amendment.
Why Anthropic challenged the supply chain risk label
The conflict began earlier this year, when Hegseth and President Donald Trump labeled Anthropic a supply-chain risk and ordered all federal agencies, including agencies outside defense, to stop working with the maker of Claude.
The dispute centered on Anthropic’s limits around how its AI models could be used. The company had set hard lines on certain safety guardrails that would allow the Pentagon to use its models for fully autonomous weapons and mass surveillance of American citizens.
The Pentagon denied that it intended to use Anthropic models for anything other than lawful purposes. It also alleged that Anthropic could try to control military use of models the government had bought and paid for.
That disagreement turned a policy dispute over AI safety into a broader fight over federal contracting, national security claims, and whether a company can be penalized for criticizing or resisting government demands.
What the judge found
Lin’s ruling focused on the government’s stated reasons for the supply chain risk designation and the evidence surrounding it. She wrote that the government’s “words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government.”
The ruling also pointed to contradictions in the government’s own conduct. One example was Hegseth’s proposition to apply the Defense Production Act to Anthropic. Lin noted that such a step would treat the company as essential to national security, not as a threat to it.
She also pointed to the Department of Defense continuing to pursue a contract with Anthropic and to the government collaborating with the company’s new model, Mythos, for cybersecurity. Those actions cut against the broad claim that Anthropic posed a supply chain risk severe enough to justify cutting off federal work across agencies.
Another key point was technical control. Lin said it was clear that Anthropic “undisputedly lacks” any backdoor access to its technology after handing it over to the DOD.
National security arguments met a constitutional limit
The ruling did not say the government must choose Anthropic as an AI vendor. Lin explicitly recognized that the military can select the AI provider it wants.
But the decision drew a line between vendor choice and punitive government action. Lin wrote, “Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.” She added, “The empty invocation of national security is not a blank check to punish and retaliate against government critics.”
That distinction matters because the label reached beyond ordinary procurement discretion. According to the source article, the order applied to all federal agencies, even those outside defense. In practical terms, a supply chain risk designation can affect whether a company can work with the government at all, not only whether it wins a single defense contract.
Lin’s reasoning treated the government’s stated national security rationale as insufficient where the evidence showed retaliation, inconsistency, and lack of due process.
What Anthropic said after the ruling
An Anthropic spokesperson welcomed the decision in a statement shared with TechCrunch.
“We welcome the court’s ruling that this supply chain risk designation was unlawful,” an Anthropic spokesperson said. “We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.”
The company’s response kept the focus on future government work rather than on escalating the conflict. That is notable because the underlying dispute remains connected to one of the hardest questions in AI policy: how far an AI company can go in setting limits on military and government use of its models.
The legal fight is not over
Anthropic filed two complaints against the DOD in March, one in California and one in Washington, D.C. The California case produced this ruling, but the D.C. suit is still ongoing.
TechCrunch reported that it reached out to the DOD for comment. The source article did not include a response from the DOD.
For now, the ruling gives Anthropic its first court win over the supply chain risk label. It also sends a clear message about the limits of using national security language against a government contractor when the record points to retaliation rather than a genuine supply chain threat.