Judge Rita Lin, sitting on the U.S. District Court in California, voided the Defense Department’s supply-chain risk designation against Anthropic on Thursday and ordered the label lifted. She found the government’s action unlawful on two separate constitutional grounds. A second lawsuit over the same designation is still pending in a Washington court.

Lin’s opinion keeps those two findings distinct, and the distinction matters for what happens next. Under the First Amendment, she held that branding Anthropic a supply-chain threat was retaliation for the company refusing to lift safety restrictions the government wanted removed. Under the Fifth Amendment, she found Anthropic never got the pre-deprivation hearing it was owed before losing its eligibility to sell to federal buyers. On top of both, she called the underlying decision arbitrary and capricious, an administrative-law defect independent of the constitutional ones.

The fight traces back to guardrails Anthropic has refused to drop: limits on using Claude to run fully autonomous weapons or to conduct bulk surveillance of the public. Defense Secretary Pete Hegseth and President Trump imposed the risk label earlier this year and told every federal agency, defense-related or not, to cut ties with the company. Hegseth’s position was that a vendor does not get to tell the military how to use hardware and software it has already paid for.

Lin’s opinion leans on the government’s own inconsistency to knock down that justification. She noted Hegseth had separately floated invoking the Defense Production Act, which would treat Anthropic as essential to national security, the opposite framing of a supply-chain threat. She cited the Pentagon’s ongoing effort to negotiate a new contract with Anthropic, plus its parallel work with the company’s Mythos model on cybersecurity, as evidence the risk label never matched the government’s actual behavior. Lin wrote that the record shows Anthropic “undisputedly lacks” a backdoor into its own technology once it reaches the Defense Department, cutting the legs out from under the stated security rationale.

Anthropic brought two separate lawsuits against the Defense Department in March, one in California and one in Washington, D.C. Thursday’s decision resolves only the California case. The D.C. suit remains open, which means the broader question, whether a federal buyer can condition a contract on a vendor dropping its own product-safety limits, is not yet settled across the board. Anthropic’s statement to TechCrunch welcomed the ruling and said the company remains focused on working with the government on national-security applications of its models.

The label Lin struck down has historically applied to suppliers tied to foreign adversaries, not to domestic vendors disputing how their own products get deployed. Using it against a U.S. AI lab over an internal safety policy, then watching a federal judge void that use on First Amendment grounds, hands every lab selling into government contracts a concrete precedent for how far a customer’s leverage extends before a usage restriction counts as protected speech. Hegseth’s underlying argument, that purchasing power includes the right to override a vendor’s guardrails, did not survive judicial scrutiny in California. It has not yet been tested in the pending D.C. case, and the policy dispute over what the military can demand from AI vendors is far from over.

For labs holding firm on restrictions against autonomous weapons targeting or domestic surveillance, this ruling is a roadmap for defending those limits in court instead of trading them away to keep a contract alive. Procurement teams at every major AI vendor should now expect government counterparties to probe contract language for leverage the courts just denied the Pentagon here.

TechCrunch (Rebecca Bellan) reported this ruling on August 28, 2026.