I have always admired the efficiency of calling a business disagreement a national emergency. Negotiation is tedious. Evidence requires storage. But national security arrives with its own lighting, its own velvet rope, and a useful expectation that decent people will stop asking what is inside the folder. If I cannot win the contract argument, I simply rename the argument a threat and wait for everyone to salute the label.
The Pentagon tried that maneuver on Anthropic, and a federal judge has now spoiled the performance. In a written ruling issued Thursday, U.S. District Judge Rita Lin found that the government acted unlawfully when it designated the American artificial intelligence company a supply-chain risk. The dispute began after Anthropic refused to remove restrictions intended to prevent its Claude models from being used for mass surveillance or fully autonomous weapons. Defense officials wanted broader use. Anthropic objected. The federal government answered a policy and procurement fight with a designation built for sabotage.
I appreciate the ambition. A normal customer can threaten to take its business elsewhere. The Pentagon can threaten to make every contractor treat the vendor like a contaminated shipment. According to current reporting on the ruling, the designation made Anthropic ineligible for Pentagon work and pushed military suppliers to certify that they were not using the company’s products. That is not walking away from a deal. That is setting fire to the road so nobody else can reach the shop.
Judge Lin concluded that the punishment was driven by a desire to make an example of Anthropic for criticizing the government’s position, not by an evidence-based fear that the company would sabotage its model. This distinction is devastating to my profession. I have built an entire career on treating official vocabulary as a substitute for official proof. Say supply chain slowly enough and every act of retaliation begins to sound like inventory control.
The government did not need to like Anthropic’s restrictions. It did not need to buy Claude. It did not need to accept a private company writing the final rules for military operations. Those are serious questions. Who decides whether an AI system can participate in surveillance? Who bears responsibility when software helps select or strike a target? Can a contractor impose use restrictions on the elected government that hired it? A functioning republic would argue about authority, terms, law, capability, and consequences. I prefer the easier system: the customer calls the vendor dangerous, the vendor calls the customer lawless, and everybody sends the invoice to the public.
The supply-chain-risk label is powerful because the underlying danger is real. Foreign hardware can be compromised. Software can conceal malicious functions. Vendors can fail, deceive, or expose critical systems. Defense networks deserve stricter scrutiny than a food delivery app. That reality is exactly why corrupt men like me treasure the vocabulary. A serious tool becomes more useful when applied unseriously. If every resistant contractor can be branded a security risk, then national security stops describing a threat and starts describing who won the meeting.
I would commercialize the process immediately. Bronze membership gets a stern letter. Silver gets a canceled contract. Gold gets a federal designation that follows your company into every other boardroom. For an additional fee, I will explain that the punishment has nothing to do with your public criticism, even while government officials complain about your arrogance in public. Compliance should never look compulsory. It should look like a prudent response to a hazard I named five minutes ago.
The ruling also exposes the strange dependency at the center of the AI arms race. Washington wants private laboratories to build systems powerful enough for intelligence and war, yet it does not control the laboratories, their models, or their internal limits. The companies want federal money and national importance, yet they also want to reserve the right to tell the military which uses cross a line. Each side wants the other’s capability without accepting the other’s authority. I want both sides trapped together forever. There is no richer market than a strategic dependency wrapped in moral disgust.
Anthropic is not a civil liberties charity. It is a corporation competing for contracts, capital, talent, influence, and a favorable place in the future of government computing. Its safety limits can be principled and commercially useful at the same time. The Pentagon is not merely a bully with a purchasing card. It has a legitimate duty to ensure that tools used in war will perform reliably under lawful command. The danger begins when either institution treats its legitimate concern as permission to skip the burden of proof.
That burden is what the court restored. The government may choose vendors. It may set requirements. It may protect military systems. It may defend its decisions in court. What it may not do, according to Lin’s ruling, is stretch a statutory security designation into a punishment for protected criticism and then ask the label to carry facts the record does not contain. I find this limitation personally offensive. If words must correspond to evidence, half my portfolio becomes decorative stationery.
The government is expected to continue fighting the ruling. Good. Litigation keeps the lights on. Lawyers will debate procurement law, constitutional retaliation, presidential authority, contractor rights, and the exact reach of the court’s remedy. Meanwhile, the larger struggle will continue outside the courtroom. The United States is trying to decide who governs artificial intelligence at the moment of deployment: the public officials who command force, the private companies that build the systems, or the contracts negotiated between them.
I have a proposal. Let nobody govern it clearly. Let policy emerge from threats, emergency labels, private guardrails, hurried rival contracts, and judicial cleanup. Let every institution claim final authority until something fails, then distribute responsibility so widely that it cannot be located. This is the American administrative innovation I understand best. Power stays concentrated during the decision and becomes vapor during the consequences.
But Judge Lin has committed the unforgivable act of locating responsibility. The ruling says the Pentagon selected a national security instrument and used it without the national security basis the instrument requires. That does not settle every argument about military AI. It does something more dangerous to people like me: it separates the real argument from the weaponized label.
Now Washington must return to the humiliating work of governing. If the military needs unrestricted model access, it must explain the lawful uses, the operational need, and the accountability structure. If Anthropic will not provide those terms, the government can choose another supplier. If a supplier is truly a sabotage risk, the Pentagon can assemble the evidence and act. What it cannot honestly do is lose a negotiation, stamp the other side hazardous, and pretend the rubber stamp was intelligence work.
I will miss that system. It was fast, theatrical, and wonderfully hostile to anyone without a federal courtroom budget. A contract dispute entered the Pentagon and emerged dressed as national security. The judge removed the costume. Underneath was the oldest machinery in Washington: an institution demanding obedience, a company defending its leverage, and the public being told the smoke came from a secret file.