U.S. District Judge Rita Lin waited until Thursday night to publish the opinion, and then she did not hedge. The Pentagon’s attempt to brand Anthropic a “supply chain risk” was illegal. It was not, in her account, a security judgment that happened to land on a difficult contractor. It was punishmentpunishing the lab for criticizing Defense Department views on military AI.

The order runs 59 pages. In it she wrote that officials wanted “to make a public example” of the company for “arrogance,” and that the move was “not based on any articulable basis to believe that Anthropic would actually sabotage its model.” CEO Dario Amodei had refused unrestricted use for mass surveillance and autonomous armed drones. In February, Trump and Defense Secretary Pete Hegseth labeled the lab a risk; OpenAI signed a Pentagon deal hours later.

Lin’s legal holding is as blunt as her narrative. She said neither the Constitution nor the statute invoked allows “sweeping penalties based principally on Anthropic’s critique.” She had already blocked the designation and a White House order telling agencies to drop Claude. The government is expected to appeal. A narrower D.C. Circuit case on a different procurement statute is still pending. Anthropic welcomed the ruling. The White House did not immediately comment.

A designation with a particular sting

In federal procurement, supply chain risk is not a press-release insult. It is a term of art that can exile a vendor from the most sensitive networks in the government. It is the language used for companies whose equipment might be backdoored, whose ownership might answer to a rival state, whose presence inside a weapons system would be a gift to an adversary. To hang that label on a San Francisco AI lab is to say, in the government’s own dialect, that the model itself might be a weapon turned inward.

Lin’s 59-page order rejects that implication on the facts the Pentagon offered. The officials, she wrote, wanted “to make a public example” of Anthropic for “arrogance.” They did not, in her reading, have “any articulable basis to believe that Anthropic would actually sabotage its model.” The difference between those two sentences is the difference between a security case and a retaliation case. One is about what a vendor might do to a warfighter. The other is about what a vendor said to a Cabinet.

A public example is a political object. It is meant to be seen. It is meant to discipline the next company that is thinking about saying no. Lin treated that motive as a problem, not as a show of resolve.

The no that started the fight

Mass surveillance and autonomous armed drones

The underlying disagreement is not mysterious. Dario Amodei had refused unrestricted use for mass surveillance and autonomous armed drones. Those are not abstract ethics talking points. They are two of the applications the national-security state most wants from a frontier model, and two of the applications a safety-branded lab is least eager to underwrite without limits.

Mass surveillance is a data problem and a civil-liberties problem. A model that can read, sort, and summarize the digital exhaust of a population at military speed is a capability governments will not politely decline. Autonomous armed drones are a control problem. A system that can find, track, and fire without a person in the loop is the scenario every AI-safety white paper eventually reaches, and the scenario every air-power brief would like to normalize.

Amodei’s refusal was a commercial decision dressed as a principled one, or a principled decision with commercial consequences. Either way, it left the Defense Department with a vendor that would sell some of Claude and not all of Claude. The Pentagon has never liked à-la-carte conscience from contractors. Contractors, for their part, have rarely had a product as general as a large language model, which can be a help desk in the morning and a targeting aid at night.

Anthropic has spent its public life claiming that caution is the point of the company — that it exists because its founders left a rival lab and wanted stricter limits on what powerful systems may do. A fight with the Pentagon over unrestricted use is that brand colliding with the largest customer in the world.

February: the label, then the rival

A risk designation and a deal, hours apart

The political sequence, as the order recounts it, was compressed. Trump and Defense Secretary Pete Hegseth labeled the lab a risk in February. OpenAI signed a Pentagon deal hours later.

Hours. Not a quarter. Not a procurement cycle. Hours. The juxtaposition does not prove a quid pro quo, and Lin’s opinion, as described, does not need it to. What the timing does is strip the episode of any claim to being a slow, technical review. A supply chain risk finding that appears in the same news cycle as a competitor’s contract looks like industrial policy with a security badge.

OpenAI and Anthropic have been the paired protagonists of the American model race since the latter was founded by people who once worked at the former. The government is now one of the arenas in which that race is scored. A Pentagon deal is revenue, legitimacy, and a path into classified networks. It is also a statement that Washington has picked a stack. When the label went on Anthropic and the signature went on OpenAI in the same slice of a day, the market heard a choice.

Lin’s job was not to referee the rivalry. It was to decide whether the United States may convert a vendor’s critique of Defense Department views on military AI into exile. Her answer, on Thursday night, was no.

What the Constitution is doing in a procurement fight

Critique as the principal basis

Government contracting is usually a statutory thicket. Vendors sue under the Administrative Procedure Act, under specific procurement codes, under claims that a competition was wired. Lin reached past that thicket. She said neither the Constitution nor the statute invoked allows “sweeping penalties based principally on Anthropic’s critique.”

The constitutional half of that sentence is the First Amendment, applied to a company that spoke and then lost the ability to sell. American law has a long, if uneven, tradition of treating government retaliation for speech as its own wrong. The government may choose not to buy. It may write requirements. It may, in true security cases, freeze out a vendor whose product is dangerous. What it may not do, if Lin is right, is use the most severe procurement stigma on the books because the vendor argued with it.

Principally is doing careful work in the quoted holding. Lin did not write that the Pentagon is forbidden to consider security. She wrote that it may not impose sweeping penalties when the principal reason is the critique. Motive, in retaliation cases, is the whole case. That is why the phrases “public example” and “arrogance” matter. They are not color. They are evidence of why the label was applied.

The statutory half will matter on appeal, because statutes are easier for an appellate court to narrow than the Constitution is. A narrower D.C. Circuit case on a different procurement statute is still pending. The government now has two paths: attack Lin’s constitutional reasoning in her circuit, and keep a separate, smaller fight alive in Washington on different text.

An injunction that was already in place

Thursday’s opinion was not the first time Lin put her hand up. She had already blocked the designation and a White House order telling agencies to drop Claude. The new ruling goes further. It does not only pause the machinery. It voids the legal theory that the machinery was using.

The White House order is worth sitting with. It did not merely tell the Defense Department to look elsewhere. It told agencies — the plural, civilian as well as military — to drop Claude. That is how a Pentagon dispute becomes a government-wide exile. A model that cannot be used at Defense is a lost contract. A model that cannot be used across the executive branch is a lost market, and a signal to every prime contractor that Claude is radioactive.

Blocking that order was already a serious judicial intervention in the management of the executive branch. Calling the underlying designation illegal, after 59 pages, is a judgment on the merits. It says the government did not merely move too fast. It moved for a reason the law does not allow.

Appeals, and the case that is not over

The government is expected to appeal. That sentence is almost a formality in a case that pits a district judge against the President, the Defense Secretary, and a national-security designation. The Justice Department does not leave supply chain risk opinions sitting on a San Francisco docket if it can help it.

Appeals take time. They also freeze uncertainty in place. Agencies that were told to drop Claude, then told they may not be told to drop Claude, will now wait to see whether a circuit panel agrees with Lin that critique cannot be the principal basis for sweeping penalties. Vendors will wait to see whether conscience clauses in AI contracts are legal positions or career-ending ones.

Meanwhile, a narrower D.C. Circuit case on a different procurement statute is still pending. The split geography is typical of modern government-contract fights. Plaintiffs file where the company lives and where the agencies live. Different statutes produce different records. A win in the Northern District of California does not automatically dissolve a case in Washington. Anthropic has a victory. It does not yet have a clean map.

What the ruling does not decide

Lin did not decide whether the Pentagon should buy Claude. She did not decide whether mass surveillance and autonomous armed drones are wise uses of foundation models. She did not decide whether OpenAI’s February deal was better, cheaper, or more compliant. She decided that the particular tool the government reached for — a “supply chain risk” brand, aimed at a lab that had criticized Defense Department views on military AI — was not a tool the Constitution or the statute invoked would let them use principally as punishment for speech.

That is a large holding and a limited one. Large, because it tells the executive branch that AI policy arguments are still speech. Limited, because a more careful record, a different statute, or a genuine sabotage concern could look different. Lin herself underscored the gap: there was “not based on any articulable basis to believe that Anthropic would actually sabotage its model.” The next designation, if there is one, will come with more paper.

A welcome, and a silence

Anthropic welcomed the ruling. Of course it did. The company has spent the year being described in official language as a hazard to the arsenal. A federal judge has now described that language as a public example built on arrogance, not on sabotage. For a lab whose business depends on being trusted with other people’s data and other people’s workflows, the difference is existential.

The White House did not immediately comment. That silence matches the hour. Thursday-night opinions are written to be read on Friday. The political response, if it comes, will come with the appeal. Trump and Hegseth have already named their position. They labeled the lab a risk in February. Lin has named hers. The circuit courts will be asked to choose.

Until then, the practical situation is the one Lin had already created and has now fortified: the designation is blocked, the order to drop Claude is blocked, and the theory that a contractor may be made an example for talking back has been declared illegal. The Pentagon may still prefer another model. It may still write requirements that Anthropic will not meet. It may still sign the next deal with OpenAI. What it may not do, if this 59-page reading stands, is dress a speech dispute up as a supply-chain emergency and dare the judiciary to blink.

Military AI will not wait for the caption to end. The uses Amodei refused — unrestricted mass surveillance, autonomous armed drones — remain the uses governments want. The critique that Lin says cannot be the basis for sweeping penalties remains the critique a safety lab has to make if it wants to keep the word safety. Thursday night did not reconcile those facts. It only said that the government has to argue them in the open, with an articulable basis, and not as a lesson in humility for a company it found too proud to obey.