When a federal judge tells the government its own case got worse since last week, the hearing starts to sound more like a diagnosis. New to this story? Here's where things stand. Anthropic's fight with the Pentagon began after the government labeled Claude a supply-chain risk, following a clash over military-use limits on mass domestic surveillance and fully autonomous weapons. Now it's a First Amendment retaliation case. A judge has paused the government's action, and Anthropic says sworn declarations show Pentagon officials privately thought the two sides were nearly aligned, even as they publicly called Claude an unacceptable national-security risk. This is Anthropic Pentagon Watch. Today, the judge has a 'kill switch' problem. We're also asking whether a deal actually kills the designation or just files it away, with OpenAI's contract sitting right there for comparison. Start with what Judge Lin actually said — and why it lands harder than any injunction. Axios writes:
"I don't see additional evidence from the government really justifying what it did. If anything, it seems like the record, in some ways, has gotten worse for the government," U.S. District Judge Rita Lin said within the first five minutes of opening the hearing. "I don't see evidence that Anthropic could alter the model after it was delivered or flip some kind of kill switch," she added.
In the first five minutes of Thursday's hearing, Judge Rita Lin said the record has gotten worse for the government. She said it before anybody even sat down. So there's your update, folks: in the Anthropic supply-chain-risk fight, the government's evidence somehow looks weaker than it did in March. And listen to what she zeroed in on: there's no evidence Anthropic could flip a kill switch on a delivered model. That was the whole technical theory behind calling it a supply-chain threat, and they couldn't prove it. Which matters, because the fight was never abstract. Anthropic drew two lines: no mass surveillance of Americans and no fully autonomous weapons. It got blacklisted for holding them. Lin's basically asking the Pentagon to show its work, and the page is blank. Both sides want summary judgment now. If she's this cold on the evidence in the first five minutes, I'd love to know what the appellate strategy even looks like. Costlier by the hour. But don't get comfortable — the designation and any deal are running on separate tracks, and losing this hearing doesn't automatically peel the label off. So Anthropic and the Pentagon are supposedly working something out — but does a deal actually wipe the slate clean, or could that supply-chain-risk label and all the contractor headaches it created just... stick around? Exactly — because the designation and any eventual deal run on two separate legal tracks. The supply-chain-risk label went live in March. Secretary Hegseth announced it on February 27th, and the Pentagon formally confirmed it in a March 4th letter to Anthropic, according to Anthropic's own statement from Dario Amodei. Mayer Brown's analysis of the enforcement rollout says this is the first such designation ever applied to an American company. By July, the same Mayer Brown piece says, the Department of War had moved into active enforcement. Contractors across the defense-industrial base were getting demands from multiple directions to identify and remove Anthropic products, including Claude, and certify they weren't using them. Meanwhile, in court, TechCrunch reported that a federal judge said at the July 30th hearing that the Trump administration still hadn't presented enough evidence to justify the designation. So any settlement talks start with the court challenge still alive, enforcement underway, and a judge publicly pointing to a hole in the evidence. A contract agreement doesn't make any of that disappear on its own. But if a deal gets done and Anthropic drops the lawsuit, doesn't that make the designation moot? Like, who's still harmed? The contractors, for one. They've already had to rip Claude out of their workflows or sign certifications of non-use under threat of contract consequences. Per Mayer Brown, those certification demands are already moving through the defense-industrial base, and a handshake between Anthropic and the Pentagon won't automatically unwind them. So watch the fine print: does an agreement rescind the designation in writing, or just pause enforcement? Those outcomes look very different to the contractors caught in the middle. This one's from OpenAI:
This language makes explicit that our tools will not be used to conduct domestic surveillance of U.S. persons, including through the procurement or use of commercially acquired personal or identifiable information. The Department also affirmed that our services will not be used by Department of War intelligence agencies like the NSA.
Pull up the actual OpenAI-Pentagon text from February 28th, updated March 2nd. They brag that it has more guardrails than any previous classified deployment — and they mention Anthropic by name. So this whole 'Anthropic wouldn't accept our terms' story? The public record says their lines weren't that far apart. And two provisions actually bind here: no domestic surveillance of U.S. persons, including with commercially bought data. The NSA is walled out entirely, and any intel-agency use needs a whole new agreement. That's the benchmark. If a Pentagon-Anthropic deal lands weaker than that, somebody should have to explain why. Right, and after the judge said the government's case got 'worse' in open court this morning — you'd think all that 'worse' would come with pressure to at least match what OpenAI already signed. From Hacker News:
Not great? Seems kind of loose language? It isn't OpenAI saying no autonomous weapons use, but only that use must be consistent with laws, regulations, and department policies: "The Department of War may use the AI System for all lawful purposes, consistent with applicable law, operational requirements, and well-established safety and oversight protocols. The AI System will not be used to independently direct autonomous weapons in any case where law, regulation, or Department policy requires…
This one's fair. The autonomous-weapons line is conditional: it bars independent direction only where law or Department policy already does. And the Department writes the policy. So the constraint is only as hard as the people you're constraining choose to make it. 'All lawful purposes' from an entity that defines what's lawful is a red line drawn in pencil. The carve-out quietly swallows the ban. Here's one from Hacker News:
For intelligence activities, any handling of private information will comply with the Fourth Amendment, the National Security Act of 1947 and the Foreign Intelligence and Surveillance Act of 1978, Executive Order 12333, and applicable DoD directives requiring a defined foreign intelligence purpose. The AI System shall not be used for unconstrained monitoring of U.S. persons’ private information as consistent with these authorities. The system shall also not be used for domestic…
See, this is the part I actually respect — the Fourth Amendment, FISA, EO 12333, all spelled out. That's more specific than 'trust our usage policy.' Whether anyone can enforce it once the model is delivered is still the open question. And 'no unconstrained monitoring' still leaves plenty of room for 'constrained' monitoring. Named authorities are better than vibes, but enforcement is still separate from any settlement. Which brings us right back to the loose end we just covered. If Anthropic Pentagon Watch helps you stay informed, subscribe and leave a review wherever you're listening. It helps other people find the show, and we really appreciate it.
Next, we'll be watching for Judge Rita Lin's summary-judgment ruling on whether to permanently overturn the Pentagon's supply-chain-risk designation of Anthropic. We'll also track the Department of War's planned working group, bringing together frontier AI labs, cloud providers, and policy and operational leaders.
You'll find links to every story in today's show notes if you'd like to read more.
That's Anthropic Pentagon Watch for today. This is a Lantern Podcast.