Federal Judge Rules the Pentagon’s “Supply Chain Risk” Label Unlawful
US District Judge Rita Lin, in the Northern District of California, ordered the Defense Department to strip Anthropic of its “supply chain risk” designation — a label that had directed every federal agency, defense and civilian alike, to stop working with the company. Lin found the designation was “unlawful retaliation” in violation of the First Amendment, that it was “arbitrary and capricious,” and that Anthropic had been denied due process under the Fifth Amendment.
The ruling matters partly because of who the label had been reserved for. Anthropic is the first American company ever given a designation historically applied to foreign adversaries. Lin’s finding was not narrow: she concluded Anthropic’s products did not constitute a meaningful national security threat, which removes the government’s stated rationale rather than just its procedure.
It is a first-round win, not a final one. Anthropic filed two complaints against the DOD in March — one in California, one in Washington, DC — and the DC case is still live. The company also lost an appellate bid in April to block the blacklisting while litigation ran, so the appeals track is where this gets tested. But an order to remove the designation, entered weeks before a public S-1, resolves the single ugliest disclosure item on the list.
The Mega-IPO Moves From Confidential to Public, and Soon
Bloomberg reports Anthropic is preparing to file publicly for its IPO in the coming weeks, in an offering expected to raise as much as SpaceX’s record $86.2 billion debut — if not more. The company filed its S-1 confidentially on June 1, four days after closing a $65 billion Series H that set its valuation at roughly $965 billion.
The reported shape: an October Nasdaq listing, with Goldman Sachs, JPMorgan and Morgan Stanley leading. Annualized revenue was estimated at $45–47 billion as of May, up from about $9 billion at the end of 2025 — a five-fold move in under eighteen months, which is the number the entire valuation rests on.
Bloomberg’s framing is that the listing looms over a packed US calendar, and that is the practical story for everyone else trying to go public this autumn. An offering this size does not just price itself; it absorbs the book. Every other AI-adjacent issuer in the queue is now scheduling around a company that has not yet named a date.
China Names Anthropic While Setting Terms for September AI Talks
Yuyuantantian, a social media account affiliated with Chinese state broadcaster CCTV, posted Sunday that the US must first prove its AI companies are subject to the same safety, disclosure and audit rules before any “substantive” discussion with China can happen. The post singled out Claude, accusing it of overstepping user data boundaries, covert monitoring, and transmitting website domains without authorization.
The context is a dispute running the other direction. Anthropic has alleged that a campaign tied to Alibaba’s Qwen lab used roughly 25,000 fraudulent accounts to generate about 28.8 million unauthorized queries between April 22 and June 5, extracting capabilities from Claude through distillation. Beijing’s response has been to reframe Anthropic as the bad actor.
Timing is the whole point. US and Chinese officials are expected to hold AI talks ahead of Xi Jinping’s September 24 state visit, and those talks were meant to cover the serious ground — autonomous weapons, alignment research, shared safety commitments. A single private company becoming the negotiating pretext is a bad sign for the agenda, and Anthropic has no seat at the table to answer for itself.
The Sonnet 5 Price Increase Scheduled for Today Is Not Happening
Check your budget spreadsheet. When Claude Sonnet 5 launched in June, the $2 per million input / $10 per million output rate was explicitly framed as introductory pricing through August 31, with standard pricing of $3/$15 taking effect September 1 — a 50% increase across the board. That increase will not occur. The introductory rate is now simply the price.
The reversal was announced in August but lands today, which is when it actually shows up in anyone’s invoice math. If you built a Q4 forecast against $3/$15, or throttled Sonnet 5 usage in anticipation, or moved workloads to a cheaper tier to stay under a September ceiling — all of that can be unwound. Sonnet 5 is also the default model for free and Pro users, so the consumer-side unit economics were moving in the same direction.
What it signals is more interesting than what it saves. A lab weeks away from a public filing does not cancel a planned 50% price increase because it feels generous. It does that when the competitive floor moved and holding the higher number would have cost more volume than it collected margin.
Model-Switch Hooks, Spend Visibility and Live Subagent Streaming
Claude Code closed August with a run of control-surface work. Two new hook events — PreModelSwitch and PostModelSwitch — let you block, confirm or annotate a model switch, which is the missing primitive for teams that need a session to stay on an approved model. SessionStart resume hooks now also receive session staleness and the estimated re-cache cost before you decide whether resuming is worth it.
Cost visibility got the same treatment. /usage gained a spend limit bar (plus a rate_limits.spend_limit status line field for developers behind a Claude apps gateway), and /cost now shows a per-session prompt-cache line with hit ratio, misses, tokens re-cached, and warm/cold status. That last one is the most quietly useful thing in the release — cache misses are the largest silent cost line in a long agent session, and until now you had to infer them.
Remote Control also picked up live streaming of a foreground subagent’s tool calls and results; background subagents, still the default, continue to report status only. Version 2.1.252 shipped August 31 with fixes for commands failing on some Macs and Remote Control sessions stalling. On the API side, responses now carry an anthropic-workspace-id header naming the wrkspc_-prefixed workspace the request’s key resolved to — small, but it ends a whole category of “which workspace was that billed to” guesswork.
$35 Billion to Lambda, With Nvidia Holding the Lease
Anthropic agreed to a $35 billion computing deal with Lambda, the Nvidia-backed cloud provider, for capacity at a data center in Nueces County, Texas — roughly 350 megawatts, developed by infrastructure company Hut 8.
The structure is the part worth reading twice. Nvidia holds the lease on the Hut 8 site. Lambda deploys Nvidia chips there and sells the resulting compute to Anthropic. So the chip vendor is the landlord, its portfolio company is the operator, and the customer is a lab about to go public. That is a lot of the same balance sheet appearing at multiple points in one transaction, and it is becoming the default shape of AI infrastructure financing rather than an exception.
Stack it against the rest of the book: $45 billion to Nscale over six years, more than $100 billion to AWS over a decade, $9.1 billion to Riot Platforms over twenty years, and now $35 billion here. Anthropic is contracting compute in twenty-year horizons against revenue that has never been through a full demand cycle. That is either the correct read on scarcity or the largest fixed-cost bet in software history — and the S-1 is going to have to argue which.
The Claude Science Research Cohort Starts Running Today
Anthropic’s AI for Science cohort begins its funded run today, September 1, through December 1. Up to 50 projects receive as much as $30,000 in Claude credits each, with Modal contributing up to $2,000 in compute for selected teams. Applications closed July 15; awards went out by the end of that month.
The vehicle is Claude Science, the research workbench Anthropic shipped in July — it integrates common research tooling and packages, handles literature analysis and multi-step research execution, refines figures and manuscripts, and is built to emit auditable artifacts rather than untraceable answers. The cohort leans toward biology and biomedical research, though all domains were eligible.
Anthropic has paired this with a broader push: 10,000 free and discounted team seats for scientists and expanded AI-for-Science credits. Credits rather than cash is a deliberate choice — it costs Anthropic marginal inference, and it produces three months of citable, auditable work by named researchers. Three months from now is also, conveniently, right after the listing window.
Anthropic’s IPO Is Now a Geopolitics Trade
Line up today’s stories and notice what is missing from them: a model. Not one item on this list is about Claude being smarter. The three biggest are a court ruling, a foreign ministry proxy, and a lease structure.
Start with the Pentagon ruling, because it is the cleanest. A federal judge did not merely find the process defective — she found the designation was retaliation for protected speech and that the underlying security claim was baseless. For a company whose entire brand thesis is “the lab a general counsel will sign off on,” having a court say the government punished you for what you said is worth more than the federal contracts it unblocks. It converts a risk factor into a credential. The DC case is still open and the Fourth Circuit history is not encouraging, so this is not banked — but the direction reversed.
Then set it beside Beijing. On the same day the domestic legal overhang lifted, a CCTV-affiliated account made Claude the named example in China’s preconditions for AI safety talks. There is a real dispute underneath it — Anthropic’s distillation allegations against accounts tied to Qwen are specific and quantified — but the function of the post is not to litigate that. It is to give Beijing a company-shaped grievance to hold up before the September 24 summit. Anthropic has spent two years arguing that frontier labs should be governed like critical infrastructure. It is now discovering what that means: you get treated as a state instrument by everyone except your own state, and you do not get to send a delegation.
The Lambda deal is where those two pressures meet the balance sheet. $35 billion on top of $45 billion to Nscale, $100 billion-plus to AWS, $9.1 billion to Riot. Every one of those contracts assumes uninterrupted access to Nvidia silicon, US power interconnects, and a policy environment that lets a US lab keep buying both. The Pentagon episode was a live demonstration that the last of those is not guaranteed — one designation, and a company with hundreds of billions in compute obligations loses its government market by memo. Anthropic won that round in court. It cannot litigate the next one in advance.
Which is why cancelling the Sonnet 5 price increase belongs in the same paragraph as all of it. A company carrying that much fixed cost, weeks from a public filing, chose to forgo a scheduled 50% revenue-per-token increase. The only reading that holds is that volume and default-position matter more right now than margin per call — that being the model already running inside Slack, inside school districts, inside 50 funded science labs is the asset, and price is the lever you give up to protect it. The S-1 will show enormous revenue growth and enormous contracted obligations. The question underwriters actually have to answer is whether the moat is the model, the distribution, or a policy environment that changed twice this month and could change again before October.