executive-ordertrade-pressNewsThe Broadside3 min read

Judge says government's Anthropic ban record has "gotten worse"

The court signaled that a supply-chain risk designation built on a contractor's public criticism of DOD, rather than technical vulnerability, may not survive judicial review, and that's a precedent with reach far beyond one AI vendor.


TL;DR

U.S. District Judge Rita Lin told a Thursday hearing that the government's record in its supply-chain ban on Anthropic "has gotten worse," not better, since she issued a preliminary injunction in March. Lin said the evidence suggests Anthropic's public criticism of DOD (not any technical threat) triggered the designation, and that the government's position amounts to claiming a contractor's speech can itself constitute a breach of trust warranting retaliation. DOD continues its phase-out of Claude with a Sept. 30 target date, while other agencies operate under the injunction's protection. No ruling was issued at the hearing.

The most consequential exchange in Thursday's hearing wasn't about Claude access or kill switches. It was Judge Rita Lin connecting the dots the government would prefer stayed disconnected: the record shows Anthropic criticized DOD publicly, and then the designation and ban arrived. Nothing in between (no new technical finding, no vulnerability assessment, no intelligence) improved the government's position.

"If anything, it seems like the record, in some ways, has gotten worse for the government," Lin said from the bench in the Northern District of California. That's a judge telling the executive branch that discovery hasn't helped them. In fact, it may have done the opposite.

Lin's March preliminary injunction already described the government's actions as appearing "designed to punish Anthropic" rather than protect national security. The intervening months of document production (including emails between Anthropic CEO Dario Amodei and DOD's R&E lead Emil Michael) haven't surfaced the justification the government needed. Instead, they appear to have reinforced the retaliation narrative.

What the government is actually arguing

Lin framed the government's position bluntly: if a defense contractor criticizes the administration, that criticism can itself amount to a breach of trust, opening the door for contract cancellation and designation as an enemy of the state. "If that's really what the government's position is," Lin said, she finds it "to be really troubling."

That framing matters because it tests the boundaries of supply-chain risk designation authority in ways that extend well past one AI company. CFIUS-style designations are meant to address technical vulnerabilities, foreign ownership, espionage risk, compromised supply chains. Using them to sanction speech would represent a novel expansion, and Lin appears unwilling to grant it legitimacy.

What happens on the ground

DOJ attorney James Harlow told the court that DOD is continuing its Claude phase-out with a Sept. 30 completion target. Another unnamed agency had preexisting plans to switch providers. Elsewhere, agencies continue using Anthropic tools through sandboxes, pilots, and third-party vendors, including a GSA OneGov pilot program that expires at the end of August. Unless agencies affirmatively renew, that usage stops when the pilot ends.

Anthropic's counsel, Michael Mongan of WilmerHale, said two unnamed agencies paused new contract negotiations while others are still pursuing deals. Since the injunction, Anthropic isn't aware of agencies canceling contracts, though the Pentagon's CDAO canceled one before the court's relief kicked in.

Lin also pressed the government on reports of expanded Mythos model use in national security contexts, noting that such deployment would be inconsistent with DOD's arguments. Harlow resisted, calling the question irrelevant and involving nonpublic information, but indicated a post-hearing submission might be possible.

The precedent that's forming

No ruling has issued yet. But the direction of the court's skepticism is clear, and it's the kind that outlasts one administration's dispute with one vendor. If Lin holds that supply-chain risk designations require something more than a policy disagreement dressed as a trust problem, agencies across government lose a tool they've been treating as largely discretionary. Contractors (AI firms especially, but not exclusively) gain a First Amendment-adjacent shield they haven't had before.

For primes and contractors who've built Claude into production workflows, the immediate question is simpler: does the injunction hold through final judgment, or does it lift and force a scramble to Sept. 30? The answer probably arrives this fall.


Published ·Deep Fathom

Judge says government's Anthropic ban record has "gotten worse" — The Broadside