Science1 distinct publisher3 min readPublished
Judge Rita Lin found the Pentagon's designation was retaliation for Anthropic's published usage limits. The sabotage theory behind it collapsed because nothing in the record explained how sabotage would work.
The Scientist · Science desk

Compiled by The ScientistSomething wrong?How this is made
Sabotage is a claim about capability, and the government's case failed that check. Nothing in the administrative record describes, even at a high level, what technological means would produce the alleged backdoors or let Anthropic disable Claude during a Department of War operation [9], and Anthropic's evidence that it has no means to access or control deployed models came in unrebutted [10]. The theory needed both a mechanism and evidence to support it, and the record supplied neither [2].
The published usage policy could not supply the missing route. Judge Lin treated the policy applying to Pentagon work as a purely contractual limit, one Anthropic cannot enforce technologically and cannot monitor, because it has no direct visibility into how the department uses the model [8]. A commitment the vendor can neither police nor observe is a poor candidate for a control surface, which is the quiet technical finding underneath the constitutional one.
It is worth being precise about the scope of the ruling. Record review asks what the agency wrote down, so the holding is that the government documented no articulable basis [5]; a basis could still exist elsewhere, just not in this record. The ruling is also specific to Anthropic. The unrebutted evidence concerned Anthropic's own deployed models [10]; a provider that does retain remote access to systems already in the field would arrive with a different record, and possibly a different outcome. And the reasoning is limited to pretext and process. Lin's ruling turns on why the label was issued and how, not on whether domestic surveillance work should be off limits.
The decision rests on three separate grounds: First Amendment retaliation, a Fifth Amendment failure to provide pre-deprivation process, and arbitrary and capricious agency action [1]. An appeal, which the lawyers and analysts quoted by CIO.com expect and several think reaches the Supreme Court [11], has to knock down all three to restore the label. The First Amendment leg is the one with reach beyond this contract, because it attaches consequences to the government's motive rather than to Anthropic's technology, and motive evidence here included the court's reading that officials wanted to make a public example of the company for criticizing them [5].
My read, conditioned on that appeal: the durable effect is procedural. An agency that wants this label will now write a mechanism section into the record before issuing it, describing the specific technical route by which a vendor could interfere with a deployed system. That is a better fight than the one just litigated, because a described mechanism is something a vendor can test, measure and rebut with evidence, which is exactly what this record failed to give Anthropic the chance to do. Alan Webber of IDC put the same point in procurement terms: a government customer used a supply chain risk designation as leverage in a dispute over model behaviour rather than over an actual vulnerability [13].
Ranked by verification strength, evidence, and original report placement.
Lin wrote that nothing in the Administrative Record describes, even at a high level, what technological means would give rise to the so-called backdoors or could otherwise allow Anthropic to disable or affect Claude during a Department of War operation.
Lin wrote that Anthropic submitted unrebutted evidence that it lacks any technological means to access or control deployed models.
US District Court Judge Rita Lin ruled on Thursday that the federal government's identification of Anthropic as a supply chain risk to national security was "arbitrary and capricious".
According to CIO.com, the designation was the Trump Administration's decision to punish Anthropic for its stance forbidding Claude's use in domestic surveillance and autonomous weapons.
Lin wrote that "the undisputed record shows that the challenged actions constituted unlawful retaliation in violation of the First Amendment and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment".
Lin said federal authorities had no legitimate reason to tell companies with government contracts that they could not work with Anthropic.
Distinct publishers with included, body-backed reporting in this cluster.
Follow any of these and your For You feed starts watching them — no settings page required.
build
Anthropic's federal ban falls on a record that failed the supply-chain statute1 distinct publisher
leadership
Builders put doom at 10 to 50 per cent and expect binding rules only after the disaster1 distinct publisher
invest
Cohere is selling insurance against export controls at a $20bn mark1 distinct publisher
product
Court reversal turns the Pentagon's Anthropic ban into a migration teams may have to run twice1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Quoted opinion, unseen docket
The findings that hold this story up are verbatim from Lin — the "arbitrary and capricious" holding, the empty Administrative Record on backdoors, the unrebutted declaration about deployed models — and quotations are hard to misreport. What CIO.com does not give is the opinion: no case name, no docket number, no link, and no Justice Department comment, so a reader cannot see the paragraphs around the quotes. Strong material, single custody.
Pentagon use confirmed, blast radius unmeasured
The adoption facts arrive sideways, out of the court's own findings: the Department of War is already running Claude under a policy the vendor cannot enforce, and the government was still negotiating sensitive work on Mythos while calling that vendor a saboteur. That is real usage, judicially noticed. What nobody measures is the damage — Webber gestures at customers who paused Claude or froze subcontracts without naming one or counting them, so the size of what might now resume is unknown.
Forecasts told in the register of findings
The reporting is calmer than the events warrant, and the headline claim — a designation voided because nobody described how the sabotage would work — is exactly what the quoted ruling says. The stretch is at the edges: an unnamed consensus that this ends at the Supreme Court, and Levine's read that the administration has already moved on, are predictions delivered in the same flat tone as the judge's holdings, where a reader may not notice the change in footing.
Everyone but the judge is selling something
Lin is the only disinterested voice in the piece. Anthropic won and is not quoted; the Pentagon and the government lawyers, whose conduct is the subject, say nothing at all. The interpretation is supplied entirely by firms that sell exactly the service a ruling like this creates demand for — IDC on national-security IT, FormerGov and Acceligence on government-facing advisory, Unit221B on security counsel — and one of them mentions in passing that rival model vendors had been merchandising the designation.
Solid on the ruling, thin on the aftermath
Split the story in two and the confidence splits with it. What the judge decided is quoted at length, internally consistent, and reinforced by details a reporter would not invent — the Defense Production Act proposal, the Mythos talks, the government's concession that the technology was no riskier than comparable black boxes. What happens next rests on four consultants, an unnamed consensus about the Supreme Court, and an account that stops mid-sentence in its final quote.