
이미지: AI 생성 — METAL LAB
Summary
- A US federal court ruled that the supply-chain risk designation against Anthropic and the government-wide ban were unlawful.
- The court affirmed the government's right to choose its vendors but held that market-wide retaliation over public criticism is not permitted.
- Anthropic won on its main constitutional and administrative-law claims, but lost on its separation-of-powers claim and on claims against several individual agencies.
Anthropic has won on the merits in its lawsuit against a sweeping blacklist imposed by the US government. Judge Rita Lin of the US District Court for the Northern District of California ruled on August 27 that the Department of Defense's designation of Anthropic as a "national security supply chain risk" — and the accompanying effort to cut off dealings between Anthropic and both federal agencies and defense contractors — violated the First and Fifth Amendments as well as federal administrative law.
The ruling doesn't mean the court forced the Pentagon to accept Anthropic's weapons policy. The opinion states plainly that the Department of Defense remains free to choose whatever AI vendor it wants. What the court drew a line against was something different: using a breakdown in contract negotiations as grounds to push a critical company out of the entire government market.
A preliminary win in March becomes a merits win in August
This ruling is distinct from the preliminary injunction issued on March 26. Back then, the court temporarily blocked enforcement because it found the government's action was likely unlawful and could cause Anthropic irreparable harm. This time, after reviewing the full record submitted by both sides, the court issued a 59-page summary judgment ruling on the merits of the key issues.

What the ruling criticized most sharply was the government's own justification. The Pentagon's administrative record rested almost entirely on a single four-page memo — and even that document was written after two of the three challenged actions had already been taken. The government initially cited the risk that Anthropic could access deployed models through a "backdoor," but during litigation it conceded that Anthropic has no such access.
In the court's view, what remained as the supposed risk unique to Anthropic wasn't technical at all — it was "trust," as the government put it. The Pentagon's record included language suggesting Anthropic had grown increasingly adversarial through the media. Judge Lin found this looked less like a national security risk assessment and more like retaliation against a company for publicly criticizing the government's AI usage policy.
Two red lines at the center of the dispute
The conflict escalated after the Department of Defense pushed for contract terms requiring AI vendors to permit all lawful uses of their technology. Anthropic said it could lift most restrictions, but drew the line at two uses: large-scale domestic surveillance of Americans, and fully autonomous lethal weapons that select and strike targets without human involvement.

In an official statement on February 26, Anthropic acknowledged that military decisions are the Pentagon's to make, not a private company's. At the same time, it argued that current frontier AI isn't reliable enough to safely operate fully autonomous weapons, and that large-scale domestic surveillance is an area where law hasn't caught up with the pace of technology. Rather than demanding the right to choose its own government customers, the company said it was simply identifying two uses for which it couldn't supply its product.
The next day, President Trump directed all federal agencies to stop using Anthropic's technology, and Defense Secretary Pete Hegseth designated Anthropic a supply chain risk. That designation also triggered a secondary boycott, barring companies that contract with the Pentagon from doing commercial business with Anthropic even in matters unrelated to the military. The court found that supply chain laws originally designed to block interference by foreign intelligence services or terrorist organizations could not be stretched to cover this.
The government can switch vendors — but it can't punish them
The most consequential line in the ruling is that "national security" isn't a blank check that justifies anything. The court affirmed the government's freedom to stop using Claude and pick a different AI vendor. But it found that shutting Anthropic out of the entire federal government and the private defense market because the company spoke out publicly amounted to retaliation barred by the First Amendment.
Procedure was also at issue. Anthropic never received notice or a chance to respond before being designated a supply chain risk. The Pentagon kept no specific record showing it had considered less intrusive alternatives, nor did it properly follow the risk-assessment process that the law requires responsible officials to carry out. The court found this violated the Fifth Amendment's due process guarantee and the Administrative Procedure Act.
The ruling vacated the government's actions and issued a permanent injunction. It also denied the government's request for a seven-day stay, noting that the same measures had already been on hold since March and that the government had failed to show it would suffer irreparable harm.
Not a total victory
Anthropic didn't win every claim. The government prevailed on the ultra vires claim that the presidential directive itself violated separation-of-powers principles. Claims against several individual agencies — including the Department of Health and Human Services, the Department of Commerce, the Department of Veterans Affairs, the Securities and Exchange Commission, and NASA — were also rejected because no final agency action could be confirmed.
A separate supply chain case remains pending before the US Court of Appeals for the DC Circuit. This California ruling does not resolve that case. There's speculation the government may appeal to the Ninth Circuit, though no notice of appeal has been confirmed as of the ruling.
In court filings, Anthropic argued that if the sanctions were reinstated, revenue from defense-related customers could fall 50 to 100 percent, and total 2026 revenue could take a hit of billions of dollars. That figure is Anthropic's own litigation estimate, not an independently verified financial result. The up-to-$200 million Department of Defense contract signed in July 2025 was also not a new contract won as a result of this ruling.
Editor's take
The real question in this case was never whether an AI company gets to control the military. The court didn't answer that question — it explicitly affirmed the Pentagon's right to choose a less restrictive model from a different vendor. What the ruling blocked wasn't a buyer's choice. It was the government using its combined purchasing power and regulatory authority all at once to push a critic out of the market entirely.
In an ordinary business relationship, you can just end a deal and find another supplier. Government contracts are different. If a breakdown in negotiations with one department can cascade into a ban across every federal agency — and beyond that, into a ban on the private companies that do business with that department — then the government effectively holds both a giant megaphone and the keys to the door at the same time. That's why the court drew a distinction between a failed contract negotiation and public retaliation.
AI safety standards deserve the same kind of scrutiny. There's no guarantee that every restriction a model company insists on is correct, and private companies shouldn't be substituting their judgment for democratic oversight. But the government, in turn, can't wave away the possibility of technical failure just by writing "all lawful uses" into a broad contract clause. Safety standards only get tested when two parties with different responsibilities are allowed to clash openly.
This ruling doesn't lock in Anthropic's two red lines as official US military AI policy. What it does establish is a standard: an AI company shouldn't be branded a national security threat simply for criticizing government policy. In an era when AI companies and state power are negotiating with each other, what's needed isn't a race to enforce silence and loyalty — it's a process for setting the boundaries of a contract while leaving room for disagreement.



Comments