Skip to main content
Why Risk Labels Without Evidence Fail in CourtThird-Party & Supply Chain
6 min readFor AI Governance Leaders

Why Risk Labels Without Evidence Fail in Court

When a federal judge ruled that the Pentagon's actions against Anthropic were "illegal and baseless," it exposed a pattern that governance teams can't afford to ignore. Government agencies and enterprises keep making the same mistakes when they classify AI vendors as supply chain risks. These aren't minor procedural errors. They're fundamental failures in how organizations justify their risk decisions, creating legal exposure that compounds over time.

The Anthropic lawsuit, filed after the company was labeled a supply chain risk, reveals why these mistakes persist. Organizations rush to classify threats without building the evidentiary foundation that would survive scrutiny. They assume the label itself carries weight. It doesn't.

Why These Mistakes Keep Happening

Risk classification failures stem from three structural problems. First, teams conflate concern with evidence. A geopolitical worry or a vendor's corporate structure triggers alarm, but no one documents the specific threat mechanism. Second, governance frameworks often lack clear criteria for what constitutes a supply chain risk in AI systems. ISO/IEC 42001's AI Management System requirements address supply chain considerations, but many organizations haven't operationalized these into decision rules they can defend. Third, there's a false confidence that government authority or internal policy autonomy shields these decisions from challenge. It doesn't, as the Pentagon learned.

Mistake 1: Classifying Risk Without Documented Threat Mechanisms

Why it happens: Teams identify a vendor characteristic they don't like (foreign ownership, cloud infrastructure location, data handling practices) and jump straight to "supply chain risk" without mapping how that characteristic could compromise your AI system's integrity, availability, or confidentiality.

The real consequence: You can't defend your classification in court or to auditors. When Anthropic sued, the Pentagon couldn't point to specific evidence justifying the label. The judge's ruling wasn't about whether Anthropic posed a risk. It was about whether the Pentagon proved it. Your legal team faces the same burden if a vendor challenges your exclusion from procurement or your termination of an existing contract.

The specific fix: Document the threat pathway. If you're concerned about a vendor's data residency, specify: "Customer prompts processed in [jurisdiction] create exposure under [specific regulation] because [concrete mechanism]. This violates our Technical Documentation (Annex IV) requirement that personal data remain within approved territories." Reference the actual control failure, not just the characteristic you dislike. Your risk register should read like a causal chain, not a list of vendor attributes.

Mistake 2: Applying Inconsistent Classification Standards

Why it happens: Different teams assess different vendors using different criteria. Your procurement team flags one AI provider for foreign data centers while approving another with identical infrastructure. There's no enterprise-wide standard defining what triggers a supply chain risk classification.

The real consequence: Inconsistency proves arbitrary action. If you exclude Vendor A for a characteristic that Vendor B shares, you've just demonstrated that the characteristic isn't your real concern. This undermines every risk decision you've made. It also creates operational chaos as teams can't predict which vendors will pass review.

The specific fix: Build a classification matrix tied to your AI system risk tiering. For high-risk AI systems under the EU AI Act, your supply chain criteria should map to Annex III obligations. Define thresholds: "Vendors processing training data for high-risk systems must demonstrate SOC 2 Type II compliance and data residency in approved jurisdictions." For systems subject to SR 11-7 model risk management expectations, specify what vendor access to model artifacts triggers enhanced due diligence. Apply these standards uniformly. Document exceptions with specific justifications.

Mistake 3: Skipping Due Process Before Public Classification

Why it happens: Organizations announce risk classifications without giving vendors notice or an opportunity to respond. Speed feels like decisiveness. You're protecting the enterprise by acting fast.

The real consequence: You've just handed the vendor's legal team their opening argument. The Pentagon's "illegal and baseless" ruling hinged partly on procedural failures. When you classify a vendor as a supply chain risk without due process, you're vulnerable even if substantive concerns exist. Courts and arbitrators look at whether your process was fair, not just whether your conclusion was reasonable.

The specific fix: Implement a notice-and-response protocol. Before you classify a vendor as a supply chain risk, send them a written notice specifying your concerns and the evidence supporting them. Give them 15 business days to respond. Review their response with your legal team before finalizing the classification. This doesn't mean you have to accept their rebuttal, but it means you've created a record showing you considered their position. Your final decision document should reference their response and explain why it didn't change your conclusion.

Mistake 4: Treating AI Supply Chain Risk as a Binary Classification

Why it happens: Teams default to yes/no: either a vendor is a supply chain risk or they aren't. This oversimplification ignores that risk exists on a spectrum and can be mitigated through controls.

The real consequence: You exclude vendors you could have used with appropriate safeguards, limiting your AI capabilities. Worse, you create all-or-nothing legal exposure. If a court finds your "high risk" classification was unjustified, you can't fall back to "moderate risk with controls" because you never documented that option.

The specific fix: Adopt risk tiering for AI vendors that mirrors your AI system classification. A vendor might pose acceptable risk for limited-risk AI systems but require additional controls for high-risk deployments. Document what those controls are: contractual data handling requirements, audit rights, escrow arrangements for model weights, or air-gapped deployment options. Your vendor risk assessment should specify both the risk level and the mitigation pathway. This gives you defensible middle ground and operational flexibility.

Mistake 5: Failing to Maintain Classification Evidence Over Time

Why it happens: You classify a vendor based on current evidence, but you don't refresh that assessment as circumstances change. The vendor gets acquired, changes their data practices, or moves infrastructure. Your classification stays static.

The real consequence: Your risk classification becomes factually wrong, and you can't prove it was ever right. If you're still blocking a vendor based on a three-year-old assessment, and their corporate structure has changed twice since then, you're defending yesterday's decision with yesterday's facts. That's how "baseless" rulings happen.

The specific fix: Tie vendor risk classifications to your AI system Post-Market Monitoring cadence. For vendors supporting high-risk AI systems, reassess supply chain risk quarterly. For others, annual review is sufficient. Your reassessment should verify that the original threat mechanisms still exist and check for new risk factors. Document what changed and what stayed the same. If a vendor remediates the issue that triggered your classification, you need a process to downgrade their risk tier. Static classifications create legal liability and operational inefficiency.

Prevention Checklist

Before you classify any AI vendor as a supply chain risk:

  • You've documented the specific threat mechanism, not just vendor characteristics
  • Your classification criteria are written, published internally, and applied consistently
  • You've given the vendor notice of your concerns and time to respond
  • You've considered risk tiers and mitigation options, not just binary exclusion
  • You've identified what evidence would change your assessment
  • Your legal team has reviewed the classification and supporting documentation
  • You've established a reassessment schedule tied to system risk level
  • Your decision references specific requirements from your AI Management System or applicable regulations
  • You can explain why this vendor poses risks that similar vendors don't
  • You've preserved all evidence supporting your classification in your Validation Evidence

The judge's ruling against the Pentagon wasn't just about one company. It's a template for how courts will evaluate your AI supply chain decisions when vendors push back. Build classifications you can defend, or don't build them at all.

You Might Also Like