A federal judge signaled deep skepticism this week that the Trump administration has produced enough evidence to justify designating Anthropic a supply-chain risk and barring the federal government from using its AI technology. A hearing was held to question the factual basis for a ban rooted in what appears to be a policy disagreement, not a security finding.

federal courthouse exterior
Photo by David Guerrero on Pexels

What the judge said

The judge, who had temporarily blocked the ban earlier this year, is now weighing whether to make that order permanent. During the hearing, she described the government’s argument that Anthropic’s public criticism of the Department of Defense justifies the ban as troubling, warning that such a rationale could establish a precedent of retaliation against federal contractors who publicly disagree with the administration.

The Pentagon has also argued that Anthropic could theoretically disable or alter its AI models during warfighting operations. The judge indicated she had seen no evidence Anthropic could alter a delivered model or flip a kill switch.

How the dispute started

The origin of the case is a commercial negotiation, not an incident. Contract talks between Anthropic and the DOD stalled after the company said it would not permit its AI to be used for mass surveillance of Americans or for targeting and firing decisions involving lethal weapons, citing concerns that the technology was not ready for those roles. The Pentagon countered that a private vendor should not dictate how the military uses its tools, and said it intended to deploy them in “lawful” ways.

When negotiations collapsed, the administration labeled Anthropic a supply-chain risk — a designation that effectively removes the company from federal procurement. Anthropic filed two lawsuits challenging the ban and the risk designation. The hearing concerned one of them; the other is being heard in Washington.

The structural question underneath

The supply-chain risk framework was built to keep adversarial hardware and compromised software out of federal systems. Applying it to a domestic AI lab that declined a specific set of military use cases stretches the category in a way courts have not previously tested. Skepticism about the kill switch theory matters because it is the only argument in the government’s filing that resembles a traditional security claim. Strip it out and what remains is a procurement dispute over acceptable-use terms.

That distinction has consequences well beyond Anthropic. The frontier model market is concentrated among a handful of US labs whose commercial customers — enterprises, allied governments, regulated industries — are watching how Washington treats vendors that publish red lines on military use. A permanent injunction would preserve those red lines as a viable commercial posture. A reversal would signal that refusing certain contracts carries a designation risk that flows through to every other federal buyer.

The regulatory environment for AI vendors is fragmenting globally. Silicon Canals has previously examined how the EU’s AI Act phases in obligations around biometrics, hiring, and migration through 2027. The Anthropic case is the American counterpart: not a statute defining what AI can be used for, but a court deciding whether the government can punish a vendor for saying no.