
Last night, U.S. District Judge Rita Lin permanently barred the Trump administration from enforcing the “supply chain risk” designation placed on Anthropic in February. This designation was applied after Anthropic refused to grant the Pentagon unrestricted use of Claude. (Their two red lines: no fully autonomous weapons, and no mass surveillance of Americans.) It barred Anthropic not just from working with the federal government but also from working with defense contractors. The restriction applied even to unrelated work — if a company happened to do business with the government then it couldn’t also do business with Anthropic. (StopWatch most recently covered the ensuing lawsuits in May.)
Lin’s 59-page order finds that the administration retaliated against the company for constitutionally protected speech, denied it due process, and violated the Administrative Procedure Act. It also finds that Anthropic never met the statutory definition of a “supply chain risk.”
This designation, previously reserved for companies tied to foreign adversaries, was claimed to be justified by the Pentagon’s stated concern that Anthropic might manipulate its software — a “risk of sabotage,” to use the Department of Justice’s phrasing. Lin called this concern “entirely unfounded,” citing evidence that Anthropic cannot maintain backdoor access to its systems. As Forbes’ Michael Posner noted earlier this year, “Claude runs on air-gapped classified networks where no vendor can push a live update without the military’s own security review.”
Lin’s ruling doesn’t compel association. The Department of Defense is free to do business with whomever it likes. And it is: The Pentagon announced new contracts with a number of AI vendors in early May and, as reported by The Washington Post, expects to have finished removing Anthropic’s tools from its systems by the end of September. What changes is that defense contractors — Boeing, for example — are also free to do business with whomever, including Anthropic.
Pete Hegseth designated Anthropic as a supply chain risk twice, under two different statutes. This ruling addresses only one statute. The other designation technically remains pending a second lawsuit in the D.C. Circuit.
If I can be frank, it’s hard to write about this with anything but a kind of exhaustion. I mean, “We have confirmed that the illegal thing is not permitted” is just maintenance of the status quo. Meanwhile, very disturbing things are happening in the frontier labs and, as my colleague Joe has just written, there are a lot of concerning questions that are not getting answered. I cared very much about the dispute between Anthropic and the government six months ago, and today I wonder how much of that is just concern over the precise orientation of deck chairs on the Titanic.
The analyses and opinions expressed on AI StopWatch reflect the views of the individual contributors and the sources they cover, and should not be taken as official positions of the Machine Intelligence Research Institute.
You can receive emails of dispatches as we write them, or subscribe to our Daily Digest for a once-a-day compilation.


