A hearing that produced two deadlines and no ruling

On 30 July, in a San Francisco courtroom, US District Judge Rita Lin heard cross-motions for summary judgment in Anthropic's case against the Trump administration and the Department of Defense. She took both under submission and said she would issue a written order. She did not say when. Lin told the room that the record "in some ways, has gotten worse for the government," and that she did not see additional evidence from the government justifying what it did.

Two clocks kept running out of that hearing. Agency pilot programmes using Anthropic's technology expire on 30 August. The Pentagon plans to complete its product phase-out on 30 September. Both dates precede a ruling that has no date at all. That is the actual shape of this story, and it is not the shape the headlines gave it. The company is winning the argument and losing the calendar.

Three days the government has not explained

The sequence matters more than the substance. Anthropic disclosed its disagreement with the Pentagon over Claude safeguards on 26 February, refusing use for mass surveillance or lethal weapons targeting. On 27 February the administration acted publicly. The government's own risk analysis is dated 2 March, three days later. Lin put it plainly from the bench: "looking at the record doesn't look like as of February 27th, there's any information in the record about what Anthropic could or couldn't do."

This is the part that transfers to you. A risk assessment written after the decision it justifies is not a risk assessment, it is a memo. Every European operator building a third-party file under DORA or NIS2 eventually hands it to a supervisor, and the first thing a reviewer checks is whether the analysis predates the action. Most vendor exit assessments fail that test, because they get drafted once the exit has already been decided upstairs.

What the court could not find in the record

The Department of Defense argued that Anthropic could disable or alter its models during warfighting operations. Lin said she saw no proof the company could alter a delivered model or "flip some kind of kill switch." Strip out the politics and something unusual has happened: a federal court examined, on an evidentiary record, whether a model vendor retains control over a model after delivery, and found nothing establishing that it does.

That question sits in every AI vendor questionnaire in Europe and almost nobody has a documented answer to it. This finding is not binding on a European regulator and it will not be cited in Brussels. It is still the first time the question has been tested rather than assumed. If your own assessment of a model supplier asserts either that the vendor can reach into a deployed model or that it cannot, you now know what evidence for that claim looks like, because a court had to go looking for it.

Six of sixteen, and none of them came back

Sixteen federal bodies held Anthropic contracts, directly or through third parties. Six terminated. That is 37.5 percent of the government customer base gone in the weeks after an announcement made on social media, and months before any court reached the merits. Lin granted a preliminary injunction on 26 March, calling the measures Orwellian and likely unlawful and finding classic First Amendment retaliation. The six contracts did not come back.

Count the days from the other direction. From 27 February to the 30 September completion date is 215 days. From 26 March, the day Anthropic won its injunction, to that same date is 188 days. The company will have spent roughly six months being removed from an estate while holding a court order in its favour. Microsoft, Google, employees of OpenAI and the American Federation of Government Employees all filed briefs supporting it. None of that moved a migration schedule.

Write the clause against the designation, not the verdict

The practical error is treating vendor political risk as a legal question with a legal remedy. Anthropic had standing to sue because Anthropic was the party designated. You, the customer, have none. If your model supplier is labelled a supply-chain risk by a government you do not answer to, your contract does not pause, your migration budget is not reimbursed, and your only lever is the exit clause you wrote before any of it started.

So write it against the trigger rather than the outcome. Three changes worth making this quarter. Define the triggering event as a designation, listing or procurement ban by any G7 government, not a final adjudication. Require the vendor to warrant in writing, with evidence, whether it retains any capability to modify or withdraw a model after delivery. And price a parallel-run period into the exit, because in this case the phase-out dates were set by the party doing the removing and no operator was consulted about them.