[agenticwork]
← blog

Anthropic Sues the Pentagon: A Legal Analysis of the Supply Chain Risk Designation

On March 9, 2026, Anthropic filed two federal lawsuits — a 48-page complaint in the Northern District of California and a separate action in the D.C. Circuit — challenging the Trump administration’s designation of the company as a “supply chain risk.” The lawsuits name Defense Secretary Pete Hegseth, GSA Administrator Edward Forst, the Department of Defense, the Department of the Treasury, the Department of State, the General Services Administration, and other federal officials and agencies as defendants.

The case is without precedent. The supply chain risk designation under the Federal Acquisition Supply Chain Security Act (FASCSA) has previously been applied only to foreign adversaries — specifically Huawei and ZTE, companies with documented ties to the Chinese government. This is the first time it has been used against an American company. The legal, commercial, and policy implications extend well beyond Anthropic.

Background: How We Got Here

The dispute traces back to Anthropic’s federal contracts, which included two use-case restrictions the company considered non-negotiable: no use of its AI models for autonomous weapons systems and no use for mass domestic surveillance. These guardrails were not new — they had been part of Anthropic’s published policies since the company’s founding.

In late February 2026, Defense Secretary Hegseth gave Anthropic until February 27 at 5:01 PM to accept “any lawful use” of its technology by the government — effectively demanding that Anthropic remove the two guardrails. Anthropic refused.

On February 27, President Trump directed federal agencies to cease using Anthropic’s products. Hegseth then designated Anthropic a “supply chain risk” under FASCSA, a step that effectively blacklisted the company from all federal procurement. Within days, the DOD, Treasury, State Department, GSA, and other agencies began terminating their Anthropic contracts.

Hours after the blacklisting, OpenAI announced a deal with the Pentagon — a move that drew immediate criticism, including from within OpenAI’s own ranks. OpenAI’s robotics chief subsequently resigned over the deal.

The Lawsuits: What Anthropic Is Arguing

Anthropic’s legal strategy attacks the designation on multiple constitutional and statutory fronts. The complaints, filed simultaneously in two jurisdictions, present overlapping but distinct arguments.

First Amendment: Retaliation for Protected Speech

The California complaint’s most striking claim is that the supply chain risk designation constitutes government retaliation against Anthropic for exercising its First Amendment right to advocate publicly for AI safety. Anthropic argues that its published positions on the risks of autonomous weapons and mass surveillance are protected speech, and that the government’s response — blacklisting the company from all federal work — was punitive action taken specifically because the company refused to abandon those positions.

The First Amendment argument is significant because it frames the case not as a narrow procurement dispute but as a question of whether the government can economically punish companies for their public policy positions on AI safety. If the designation stands, Anthropic argues, it creates a chilling effect: any AI company that publicly advocates for safety guardrails risks losing federal contracts.

Fifth Amendment: Blacklisted Without Due Process

Anthropic also argues that the designation deprived the company of a protected liberty and property interest without due process. The company received no formal notice, no hearing, and no opportunity to contest the designation before it took effect. The 5:01 PM deadline was, in Anthropic’s telling, an ultimatum rather than a process — a demand to accept terms or face consequences, with no mechanism for review or appeal.

Due process claims in government contracting are well-established in federal case law. The argument is that once a company has existing contracts and a track record of government work, it acquires a property interest that cannot be revoked arbitrarily. The government must provide notice, an explanation of the basis for the action, and an opportunity to respond before imposing what amounts to debarment from federal procurement.

APA: Arbitrary and Capricious Agency Action

Under the Administrative Procedure Act (APA), Anthropic argues that the supply chain risk designation was arbitrary and capricious. The company contends that applying a designation designed to protect against foreign adversarial infiltration of US supply chains to an American company headquartered in San Francisco, with no foreign government ties, is a fundamentally irrational use of the statute. The designation, Anthropic argues, bears no rational relationship to the security concerns FASCSA was enacted to address.

FASCSA: Statutory Overreach

The legal arguments around FASCSA — the Federal Acquisition Supply Chain Security Act, codified at 10 USC Section 3252 — are among the most technically specific in the complaints. Anthropic raises several points about the statute’s scope and requirements:

  • Covered systems. Section 3252 applies to “covered systems,” which the statute defines as national security systems. Anthropic argues that the designation was applied as a blanket ban across all federal procurement, not limited to national security systems as the statute requires.
  • Least restrictive means. FASCSA requires that any supply chain action use the “least restrictive means” necessary to address the identified risk. A governmentwide ban on all Anthropic products and services, Anthropic argues, is the most restrictive action possible — not the least. The government could have imposed use-case-specific restrictions, required additional oversight for certain applications, or negotiated contractual safeguards.
  • Risk nexus. FASCSA requires that the designated entity pose a supply chain “risk” in the security sense — the kind of risk posed by hardware or software that could be exploited by a foreign adversary. Anthropic contends that a company refusing to remove safety guardrails from its AI product does not constitute a supply chain security risk within the meaning of the statute.

Presidential Authority: No Statutory Basis for a Blanket Ban

Finally, Anthropic challenges the legal basis for the President’s directive ordering all agencies to cease using Anthropic products. The company argues there is no statute that grants the President authority to impose a blanket governmentwide ban on a specific vendor based on a contract dispute over use-case terms. The Procurement Act, which gives the President broad authority over federal purchasing, has limits — and Anthropic argues those limits do not extend to punitive debarment of a company for its published policy positions.

The Government’s Position

The Trump administration has defended the action, though its public statements have been more political than legal in character. The White House, through spokeswoman Liz Huston, maintained that Anthropic’s refusal to accept standard contract language justified the government’s response.

The Pentagon’s stated position is that “any lawful use” is standard contract language for government procurement and that Anthropic’s insistence on carving out specific use cases was itself the departure from normal practice. From the government’s perspective, the two guardrails — no autonomous weapons, no mass surveillance — amounted to a contractor attempting to impose policy constraints on how the military could use a product it had purchased.

The Pentagon declined to comment further on the pending litigation as of March 9.

There is a legitimate tension in the government’s position. Federal procurement has historically involved standard terms of service, and contractors that refuse to comply with government requirements can lose contracts. The question the courts will have to resolve is whether the government’s response — not merely canceling specific contracts but applying a supply chain risk designation that effectively debarred the company from all federal work — was proportionate, legally grounded, and procedurally sound.

The Amicus Brief: Competitors Rally to Anthropic’s Defense

In what may be the most extraordinary development in the case, more than 30 employees of Anthropic’s direct competitors — OpenAI and Google DeepMind — filed an amicus brief in support of Anthropic. The signatories include Jeff Dean, Google’s chief scientist, along with researchers and engineers from both companies.

The amicus brief argues that the supply chain risk designation threatens the entire AI safety research ecosystem. If a company can be blacklisted from government work for advocating AI safety guardrails, the brief contends, the rational business response for every AI company is to stop advocating for safety — or at least to stop doing so publicly. The brief frames Anthropic’s case not as a competitive matter but as an industry-wide concern about the chilling effect of government retaliation on safety research.

The fact that employees at OpenAI — the company that directly benefited from Anthropic’s blacklisting by securing a Pentagon deal hours later — signed the brief is remarkable. It suggests that the AI safety community views the precedent as dangerous enough to override competitive self-interest.

Legal Analysis: What Scholars Are Saying

Legal commentary on the designation has been broadly critical of its legal basis, though analysts differ on which arguments are most likely to succeed.

Lawfare

Lawfare published an analysis arguing that the designation “won’t survive first contact with the legal system.” The piece focuses on the FASCSA arguments, noting that the statute was designed to address foreign adversarial threats to US supply chains and that its application to a domestic company over a contract dispute represents a use of the statute its drafters never intended.

Just Security

Just Security’s analysis emphasizes the statutory scope issue: Section 3252 applies to “covered systems,” which are defined as national security systems. The designation’s application across all federal procurement — including civilian agencies with no national security mission — exceeds the statute’s reach. Just Security also notes that the designation cannot legally affect how federal contractors use Anthropic’s products for non-government customers.

The Hudson Institute Perspective

Michael Sobolik of the Hudson Institute, a conservative think tank with close ties to the defense establishment, offered perhaps the most pointed criticism from the right:

“We’re treating an American AI company worse than we’re treating a Chinese Communist Party-controlled AI company.”

— Michael Sobolik, Hudson Institute, NBC News

This framing is notable because it highlights the irony of a designation created to protect against foreign adversaries being applied more aggressively to an American company than it has ever been applied to the foreign entities it was designed to target.

Anthropic’s Statement

In a blog post accompanying the lawsuits, Anthropic laid out its position in detail. CEO Dario Amodei stated:

“We do not believe this action is legally sound, and we see no choice but to challenge it in court.”

— Dario Amodei, CEO, Anthropic, CNBC

The lawsuits themselves state:

“These actions are unprecedented and unlawful. The Defendants have weaponized a statute designed to protect national security against foreign adversaries, using it instead to punish an American company for exercising its constitutional right to advocate for responsible AI development.”

— Anthropic v. Hegseth et al., N.D. Cal. complaint, TechCrunch

Why This Case Matters Beyond Anthropic

Whatever the outcome, this case will set precedent on several questions that affect every technology company that does business with the federal government — and many that do not.

1. The Chilling Effect on AI Safety Research

If the designation survives legal challenge, the message to the AI industry is unambiguous: publicly advocating for safety guardrails carries the risk of losing all federal business. This is not a hypothetical concern. AI companies derive significant revenue from government contracts. A rational response to this precedent would be to quietly implement whatever safety measures a company believes are appropriate — but to never say so publicly, and to never include them in contracts where they might create friction with government customers.

The amicus brief from OpenAI and DeepMind employees argues precisely this point. AI safety research depends on openness — publishing findings, sharing methodologies, advocating for standards. If companies conclude that openness about safety is commercially dangerous, safety research moves underground or stops.

2. The Supply Chain Risk Designation as Political Tool

FASCSA was enacted to protect US government systems from adversarial foreign influence — specifically, the risk that hardware or software from entities like Huawei might contain backdoors or be subject to foreign government control. Applying this designation to a domestic company over a contract dispute about use-case restrictions is a fundamentally different use of the tool.

If the designation stands, future administrations — of any political orientation — will have a template for blacklisting domestic companies that refuse to comply with policy demands. Today the issue is AI safety guardrails. Tomorrow it could be data localization, content moderation, encryption backdoors, or any other policy area where the government and a technology company disagree.

3. Competitive Dynamics and the Appearance of Favoritism

The timing of the OpenAI Pentagon deal — announced hours after Anthropic’s blacklisting — raised immediate concerns about competitive fairness. The fact that OpenAI’s robotics chief resigned over the deal, and that OpenAI employees subsequently signed an amicus brief supporting Anthropic, suggests that even within the company that benefited from the situation, there is significant discomfort with how it unfolded.

For the federal procurement system to function, companies need to believe that contract awards are based on merit, not on willingness to comply with extralegal demands. If the perception takes hold that federal AI contracts go to whichever company is most willing to drop safety guardrails on demand, the long-term effect on the quality and safety of government AI systems is negative for everyone — including the government.

4. International Implications

The United States has spent years building international coalitions around AI safety norms, including the Bletchley Declaration and bilateral AI safety agreements. Blacklisting an American AI company for maintaining safety guardrails complicates the United States’ ability to advocate for international AI safety standards with credibility. Allied nations watching the dispute will draw their own conclusions about the US government’s actual commitment to the safety principles it has promoted internationally.

The Government’s Strongest Arguments

In the interest of presenting both sides fairly, it is worth examining the legal and policy arguments the government is likely to advance in response.

Sovereign Procurement Authority

The government has broad discretion in choosing its contractors. Federal agencies are not required to purchase from any particular vendor, and the government can decline to do business with companies for a wide range of reasons. The argument would be that Anthropic has no entitlement to federal contracts and that the government’s decision to stop purchasing Anthropic’s products is within its procurement authority.

Standard Contract Terms

The Pentagon’s position is that “any lawful use” is standard language in federal procurement contracts. The argument would be that Anthropic was not being asked to do anything extraordinary — it was being asked to accept the same terms that other contractors accept. A contractor that refuses to accept standard terms can expect to lose contracts.

National Security Prerogative

Courts traditionally give significant deference to the executive branch on matters of national security. The government may argue that decisions about what AI capabilities the military needs — and what restrictions on those capabilities are acceptable — are core national security judgments that courts should not second-guess.

These are serious arguments, and it would be a mistake to assume the case is straightforward. However, the government’s challenge is that it chose the specific tool of a supply chain risk designation — which carries statutory requirements and procedural constraints — rather than simply declining to renew Anthropic’s contracts through normal procurement channels. The choice of mechanism matters legally, and it is the mechanism, not just the outcome, that Anthropic is challenging.

What Happens Next

The cases are in their earliest stages. Anthropic is likely to seek preliminary injunctive relief — asking the courts to suspend the supply chain risk designation while the case is litigated. The government will likely move to dismiss, arguing that Anthropic lacks standing, that procurement decisions are not subject to judicial review, or that national security considerations require deference.

Several factors will shape the litigation:

  • Forum. The Northern District of California tends to be more receptive to claims against executive overreach, while the D.C. Circuit has deep expertise in administrative law and federal procurement. Filing in both courts gives Anthropic strategic options.
  • Discovery. If the cases survive motions to dismiss, discovery could be revealing. Anthropic will seek internal government communications about the designation — particularly any evidence that the decision was politically motivated rather than based on a genuine supply chain security assessment.
  • Congressional attention. The lawsuits will draw congressional scrutiny to FASCSA’s scope and the executive branch’s use of supply chain authorities. There is bipartisan concern — from national security hawks worried about the precedent of treating American companies like foreign adversaries, and from civil liberties advocates concerned about government retaliation for protected speech.
  • Industry response. The amicus brief from OpenAI and DeepMind employees is likely to be followed by additional filings from industry groups, civil liberties organizations, and potentially other AI companies. The breadth of support for Anthropic’s position will signal to the courts how the industry views the precedent.

The Architectural Lesson

For organizations that depend on AI systems for critical operations, this dispute — regardless of its legal outcome — illustrates a structural risk. When a single AI vendor can be blacklisted overnight by executive action, any organization that has built its AI infrastructure around that vendor faces the same disruption the Pentagon experienced. The vendor does not have to be Anthropic. It could be any provider, for any reason. The risk is architectural, not political.

Organizations that build on model-agnostic platforms — routing across multiple providers, supporting self-hosted models, and maintaining the ability to switch providers without re-engineering their systems — are insulated from this category of risk. That is not a sales pitch; it is a straightforward observation about infrastructure design. If your AI platform survives the removal of any single provider, vendor-level political risk becomes a procurement issue rather than an operational crisis.

Worked Example: Three Minutes, Zero Impact

Consider the scenario this architecture is built for. A directive lands that requires cutting off a model provider — every Anthropic and Claude model — across a production system, effective immediately. In a single-provider stack, that is an operational crisis. In a model-agnostic one, it is a configuration change. Here is how that cutover is designed to play out — not in theory or a sales deck, but as the architecture is meant to perform under real pressure.

Model-Agnostic Failover Timeline
T+0
directive in effect
Cease-and-desist directive received
3 min
total elapsed
7:42 AM
directive in effect
All Claude models disabled across all services
DESIGN GOAL
No Service Outage
DESIGN GOAL
No Lost Tokens
DESIGN GOAL
No User Disruption

Here is how it is designed to unfold. A directive to remove all Anthropic models takes effect; within minutes, every Claude model can be disabled across every service and deployment — not deprecated, not scheduled for removal, but switched off in configuration. That is the design goal the architecture targets, not a measured incident.

The reason it took three minutes instead of three hours or three days is SmartModelRouter, the model-routing layer at the core of the platform. SmartModelRouter abstracts all LLM interactions behind a unified API. Application code never calls Claude, GPT, Gemini, or any specific model directly. It calls SmartModelRouter, which routes requests to the appropriate provider based on configurable policies — cost, latency, capability requirements, and availability.

Before — 7:38 AM
SmartModelRouter
├─ Claude 3.5 Sonnet
├─ Claude 3 Opus
├─ GPT-4o
├─ Gemini Pro
├─ Llama 3 (local)
└─ Mistral Large
After — 7:42 AM
SmartModelRouter
├─ Claude 3.5 Sonnet
├─ Claude 3 Opus
├─ GPT-4o
├─ Gemini Pro
├─ Llama 3 (local)
└─ Mistral Large
All traffic auto-rerouted. No code changes.

When Claude models are disabled in SmartModelRouter, active sessions are designed to continue on alternative providers without redeployment, code changes, or container restarts. The configuration change is intended to propagate across all services automatically, so that from the perspective of users and running workflows, nothing should change. The models change underneath. The work continues.

This is exactly why organizations need platforms like ours. Model independence is not theoretical — it is an architectural property you can design for. When a directive to drop a provider lands, the cutover is a configuration change measured in minutes, not a re-engineering project measured in weeks. Three minutes. Zero impact. That is the design goal, and the architecture is built to meet it.

Contrast this with what would have happened in a conventional architecture — one where application code calls the Anthropic API directly, where Claude model IDs are hardcoded in configuration files, where prompt templates are tuned to specific Claude behaviors. In that architecture, removing Claude from production means rewriting code, retesting prompts, redeploying services, and managing the inevitable regressions. That is not a three-minute operation. It is a three-week operation, if you are lucky.

The lesson is not that Anthropic is unreliable. Anthropic builds excellent models and has taken principled positions on AI safety. The lesson is that any vendor can become unavailable at any time, for reasons entirely outside your control — government action, pricing changes, API deprecation, outages, acquisition, or policy changes. The organizations that survive these disruptions are the ones whose architecture does not assume any single provider will always be there.

Sources