A federal judge indicated during a July 30 hearing that the Trump administration likely exceeded its authority when it designated Anthropic a national security risk and ordered federal agencies to stop using the company’s AI technology, Politico reported.
The hearing is the latest development in a legal battle that began in March 2026, when Anthropic filed two separate lawsuits: one alleging the designation violated its free speech and due process rights, and a second challenging the statutory basis for the supply-chain risk determination.
The Government’s Technical Argument
Government lawyers argued that Anthropic’s AI models pose a national security risk because of “AI model poisoning,” the possibility that the company could secretly alter deployed models after installation. The claim positions post-deployment model modification as a supply-chain vulnerability comparable to hardware backdoors.
The judge appeared skeptical. According to Politico, the government offered limited evidence to support the model poisoning theory as a concrete, realized threat rather than a hypothetical risk.
DoD Wind-Down Timeline
The Justice Department disclosed during the hearing that the Department of Defense is winding down its use of Anthropic technology by the end of September 2026. That timeline creates a hard migration deadline for every federal agent deployment currently running on Claude models.
The disclosure is significant because it reveals the designation has operational teeth even while the case is being litigated. Federal agencies and their contractors that built autonomous workflows on Claude, including those using the model for cybersecurity assessment and document analysis, face a three-month window to switch providers or shut down those systems.
Policy Position as Trigger
Anthropic has publicly refused to support autonomous weapons development or mass surveillance applications. The company’s responsible scaling policy restricts how its models can be used in military and intelligence contexts.
According to Politico’s reporting, this policy position, not a demonstrated technical vulnerability, appears to have been the actual trigger for the national security designation. The distinction matters for the broader AI industry: if a company’s ethical stance on agent autonomy can be recast as a supply-chain risk, any AI provider that restricts military use cases could face similar treatment.
The Precedent for Agent Deployment
This is the first major court test of whether the executive branch can use supply-chain risk designations to remove an AI provider from federal procurement based on policy disagreements rather than verified technical vulnerabilities. If the judge rules against the government, the precedent would limit the administration’s ability to use national security authorities as a tool to pressure AI companies into supporting specific use cases, including autonomous weapons and unrestricted surveillance agent deployments.
If the government prevails, AI providers would face a new category of regulatory risk: building safety guardrails that conflict with government priorities could itself be classified as a supply-chain threat, effectively making restrictive AI safety policies a business liability for federal contracts.