The Intake
The Intake — Monday, August 31, 2026
On the substrate
Federal court rules Pentagon's Anthropic supply-chain designation was unlawful retaliation
If you've been tracking the federal procurement landscape for AI models — watching which vendors carry supply-chain risk designations and what that means for what you can deploy in federal contexts — the ruling from Thursday changes the picture for Anthropic.
U.S. District Judge Rita Lin issued the ruling August 28. The case was before the Northern District of California. The ruling found the Pentagon's supply-chain risk designation of Anthropic to be "unlawful retaliation." The First Amendment was the cited basis. The designation was also found "arbitrary and capricious" under the Fifth Amendment. Judge Lin cited a contradiction in the record. The Pentagon was pursuing contracts with Anthropic while maintaining the designation against it. One of those contracts was for a cybersecurity model called Mythos. A second Anthropic suit remains active. It was filed in Washington, D.C.
If you're building toward federal deployment on Anthropic's stack, the designation's removal is the path change.
---
For operators
NIST: agents running on human credentials violate core identity management principles
If you've been giving your agents access under your own credentials — your personal token, your enterprise account, whatever got the workflow running — NIST published guidance naming that setup as a violation of core IAM principles. It came from the National Cybersecurity Center of Excellence on August 27.
The guidance is authored by Bill Fisher and Ryan Galluzzo. It establishes that agents must carry unique identifiers separate from human credentials. The guidance states explicitly that individuals sharing personal or enterprise credentials with agents violates core identity management principles. The required configuration it names: short-lived OAuth 2.0 or SPIFFE tokens, least-privilege authorization scoped via RAR, and hardened container deployments.
If your agent workloads currently run on shared human credentials, the specific configuration the guidance names is the evaluation point.
---