A federal judge says the government's case for banning Anthropic has gotten worse U.S. District Judge Rita Lin told the Pentagon on July 30 that its case for banning Anthropic from federal contracts has weakened, not strengthened, since the case began. Lin, who had already issued a preliminary injunction blocking the ban in March, said she sees no additional evidence justifying the supply-chain risk designation imposed after Anthropic refused to let its Claude model power autonomous weapons or surveil American citizens. The judge warned that the government's theory could set a precedent where any federal contractor risks blacklisting for publishing ethical-use policies. U.S. District Judge Rita Lin heard fresh arguments on July 30 in Anthropic's challenge to its Pentagon blacklisting, and told the government plainly that its record has deteriorated, not strengthened, since the case began. The judge overseeing Anthropic's lawsuit against the Pentagon walked out of Thursday's hearing more skeptical of the government than she walked in. That's a notable place to be, because she was already skeptical. As Axios reported, Judge Rita Lin of the Northern District of California told lawyers for the Defense Department: "I don't see additional evidence from the government really justifying what it did. If anything, it seems like the record, in some ways, has gotten worse for the government." This is not a close call on paper. Supply-chain risk designations exist to block foreign adversaries from embedded access to U.S. military systems. The Pentagon applied that label to Anthropic, an American company, after a contract dispute over whether Claude could be used to power autonomous weapons or surveil American citizens. Anthropic said no. The Trump administration responded in late February by directing all federal agencies to immediately cease using Anthropic's technology and ordering Defense Secretary Pete Hegseth to blacklist the company outright. Contractors and suppliers doing Pentagon work were required to certify they weren't using Claude. The company claims the move could cost it billions in lost federal revenue. Judge Lin had already called the designation "troubling" at a March hearing, noting it was the kind of label reserved for state adversaries. She issued a preliminary injunction in late March that temporarily blocked the ban, citing First Amendment retaliation concerns. The government appealed. The D.C. Circuit refused to halt her injunction but didn't rule on the merits. Now both sides have asked for summary judgment, essentially asking her to end it without trial, and her comments Thursday suggest she doesn't think the Pentagon has given her much new to work with. The DOD's position is that Anthropic's refusal to allow certain uses of Claude constituted an unacceptable operational limitation on military capability. When Dario Amodei announced publicly that the company wouldn't let Claude power fully autonomous weapons or be used to surveil American citizens, the Pentagon treated that as a threat to mission readiness rather than a corporate ethics policy. That framing is what Judge Lin keeps questioning. "I don't see evidence that Anthropic could alter the model after it was delivered or flip some kind of kill switch," she said Thursday, pushing back on the implication that Anthropic's guardrails posed a live security risk once a model was deployed. She also flagged in March that the argument justifying the ban on the grounds that Anthropic had publicly criticized the DOD was "really troubling," warning it could set a precedent where any federal contractor risks blacklisting for speaking out against an agency. That's a broad concern. There are hundreds of companies doing AI work for the federal government, and most of them are under pressure to maintain ethical use policies from investors, boards, and regulators outside the U.S. The idea that publishing responsible-use commitments could trigger a supply-chain designation would restructure how every serious AI lab approaches federal contracting. Anthropic filed two lawsuits in March: one in San Francisco challenging the executive directive under the Administrative Procedure Act and on First Amendment grounds, the other in D.C. contesting the supply-chain designation itself under a separate statute. The San Francisco case is where Judge Lin sits and where Thursday's hearing took place. The D.C. case has moved more slowly, and the appeals court there has appeared divided. Why this matters beyond Anthropic OpenAI, Google DeepMind, and every other frontier AI lab with federal contracts is watching this. The government's theory, if it holds, would mean that an AI company's public statements about what its models won't do can be weaponized as a procurement disqualifier. That's a different kind of regulatory risk than licensing requirements or safety mandates, and it's harder to price into a business model. You can hire lawyers to navigate a regulatory regime. It's harder to navigate a regime where good-faith ethics policies are treated as adversarial acts. Judge Lin is not expected to rule from the bench. She typically issues written decisions after hearings, and there's no deadline. But her language Thursday makes the government's path to winning on summary judgment look narrow. If she rules for Anthropic and that ruling holds, it would establish that courts will scrutinize the factual basis for AI-related bans, not simply defer to national security framing. That's a meaningful check on executive overreach in a sector where regulators have been writing the rules as they go. Don't underestimate what it means that a judge is saying the record got worse. Governments generally improve their evidentiary showing as a case develops. The fact that this one appears to have moved in the wrong direction suggests the original designation was built on thin ground, and the courts may be where that finally gets said plainly. Also read: ChipAgents raises $134 million as semiconductor giants pay AI to design their own next chips faster https://startupfortune.com/chipagents-raises-134-million-as-semiconductor-giants-pay-ai-to-design-their-own-next-chips-faster/ • Seedance 2.5 Set to Expand Multimodal Input Support to 50 Media Files https://startupfortune.com/seedance-25-set-to-expand-multimodal-input-support-to-50-media-files/ • Okta buys identity threat startup Permiso for roughly $200 million as AI agents become enterprise security's newest weak spot https://startupfortune.com/okta-buys-identity-threat-startup-permiso-for-roughly-200-million-as-ai-agents-become-enterprise-securitys-newest-weak-spot/