Judge Voids Pentagon's Anthropic Blacklist: 'National Security Is Not a Blank Check to Punish Critics'
A federal judge has struck down the Pentagon's supply-chain risk designation of Anthropic as unconstitutional First Amendment retaliation, ordering the government to withdraw directives issued after the company refused to allow Claude in autonomous weapons and mass surveillance.
On August 27, 2026, US District Judge Rita F. Lin of the Northern District of California delivered the most consequential ruling yet in the legal war between the Trump administration and Anthropic: a 59-page order voiding the Pentagon’s designation of the AI company as a national security “supply-chain risk” and finding that the government’s campaign against the Claude maker violated the First Amendment and the Fifth Amendment’s due process clause. The order requires the government to withdraw the directives it issued against the company.
The sharpest line of the ruling will likely follow this case into the law books: “the empty invocation of national security is not a blank check to punish and retaliate against government critics.”
What the ruling decides
The order resolves cross-motions for summary judgment in Anthropic PBC v. U.S. Department of War (case 3:26-cv-01996, N.D. Cal.), the lawsuit Anthropic filed on March 9 after a series of escalating punitive measures. Judge Lin concluded that the supply-chain risk label was not a genuine security assessment but punishment for the company’s public criticism of administration policy — and, in the court’s words as reported from the summary judgment record, a wish to make an example of Anthropic for its “arrogance.”
Two constitutional violations anchor the decision:
- First Amendment retaliation. The court found the government designated Anthropic a supply-chain risk because of its “hostile manner through the press” — that is, for bringing public scrutiny to the government’s contracting position. As Lin wrote in the March preliminary injunction that Thursday’s order now makes permanent in effect: “Punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation.”
- Fifth Amendment due process. The sweeping penalties — including a directive that no contractor, supplier, or partner of the US military may conduct any commercial activity with Anthropic — were imposed without the process the law requires.
The judge also noted a factual point that undercut the government’s own narrative: the military kept trying to work with Anthropic even while publicly calling the company a security threat. At the July 30 hearing, Lin said she found it “inconsistent” for the government to claim Anthropic endangers national security while agencies continued — and in some cases expanded — their use of Claude.
How we got here
The dispute has roots stretching back over a year. Anthropic’s relationship with the second Trump administration had been deteriorating since early 2025, with friction over AI regulation, chip export policy, and the company’s usage restrictions on surveillance work for the FBI, Secret Service, and ICE. Administration figures, including AI advisor David Sacks, had accused Anthropic of running “a sophisticated regulatory capture strategy based on fear-mongering” and examined whether Claude was “woke AI.” A July 2025 executive order, “Preventing Woke AI in the Federal Government,” followed.
The break came on February 27, 2026. President Trump ordered federal agencies to stop using Anthropic’s technology, calling it a “radical left, woke company.” The same day, Defense Secretary Pete Hegseth designated the company a supply-chain risk to national security, posting on X: “Effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic … This decision is final.”
The trigger, as reporting established, was Anthropic’s refusal to lift two narrow contractual restrictions on Claude’s use: no mass surveillance of Americans, and no fully autonomous weapons. Anthropic said it could not be confident Claude would be reliable or safe in fully autonomous lethal warfare, and refused to grant the Pentagon “all lawful uses” rights to the model. The standoff reportedly cost the company a contract worth an estimated $200 million, and the Pentagon moved to strip Claude from its systems on a 180-day timeline even after courts intervened.
Anthropic sued on March 9. Judge Lin granted a preliminary injunction on March 26, but the Pentagon’s chief technology officer said the ban stood regardless — and the department pressed on, with the D.C. Circuit declining emergency relief in April on a separate FASCSA designation covering civilian contracts. Thursday’s summary judgment ruling is the definitive word from the California court: the blacklist, as constructed, was lawless.
The government’s argument — and why it failed
At the July 30 hearing, Justice Department attorney James Harlow argued the designation stemmed from a breakdown of trust, not retaliation. His framing was notable: unlike a rifle, AI cannot be disassembled and inspected, so the military must trust vendors to disclose what is “baked into” their models. “Nothing prevents Anthropic in the future from developing new policy positions that can be baked into models for additional guardrails that may or may not be disclosed to the Department of War,” Harlow said.
Lin was unmoved — and her response from the bench distilled the constitutional stakes: “The government’s position is that if a government contractor goes out and publicly criticizes the administration, the government can turn around and say ‘I don’t trust you’ and retaliate against the contractor. I find that position really troubling and at odds with the First Amendment.”
Anthropic’s counsel, Michael Mongan of WilmerHale, told the court there was “nothing in this record that remotely substantiates the suggestion that Anthropic is a national security risk,” noting the government had always known about the two use restrictions before suddenly elevating a “contractual impasse” to a national security designation.
Why this matters beyond one company
Three implications stand out.
1. Safety terms are not disloyalty. The ruling draws a line between a vendor negotiating the terms under which its technology may be used — including safety-motivated limits — and a vendor that poses an actual security risk. Governments remain free to choose not to buy; what they cannot do, on this record, is weaponize procurement infrastructure to destroy a company that spoke out. For every AI lab calibrating how much to restrict military use of frontier models, that distinction now has a federal court’s imprimatur.
2. The circuit split is the real battleground. A second front remains open in Washington, DC, where the D.C. Circuit declined to block a parallel designation covering civilian government contracts — reaching a different conclusion on much the same conduct, and citing the need not to force the military to prolong dealings with “an unwanted vendor” mid-conflict. With Judge Lin’s ruling now final at the district level and the government signaling an appeal, the case is on a path toward the Supreme Court. How far can a government go in punishing a model provider over its safety terms? The answer will shape AI policy for years.
3. It completes a wild week for Anthropic. The ruling lands days after the company opened a research preview of its Model Hardware Standard for controlling robots and lab equipment, secured a $45 billion compute deal with Britain’s Nscale, and continued preparations for what is expected to be a record IPO. A federal court has now affirmatively held that the government’s attempt to brand it a national security threat was unconstitutional — a fact that will feature prominently in that roadshow.
What happens next
The government has indicated it will appeal. The Department of War’s wind-down of Anthropic products, previously scheduled for completion by September 3, now collides with a court order requiring the directives to be withdrawn. Judge Lin has not set a date for further proceedings. And Anthropic, for its part, says it remains “focused on working productively with the government to harness AI for our national security.”
The deeper question the case leaves behind is the one Judge Lin named in March: a democracy cannot let “national security” become a label that converts criticism into a punishable offense. On Thursday, at least, the answer was written into a 59-page order.
Sources
- [1] https://www.reuters.com/legal/government/us-judge-blocks-pentagons-anthropic-blacklisting-2026-08-28/
- [2] https://thenextweb.com/news/judge-strikes-down-pentagon-anthropic-blacklist
- [3] https://qz.com/anthropic-pentagon-blacklist-unconstitutional-ruling-082827
- [4] https://www.courthousenews.com/judge-likely-to-rid-anthropic-of-pentagons-supply-chain-risk-label/
- [5] https://en.wikipedia.org/wiki/Anthropic%E2%80%93United_States_Department_of_Defense_dispute
- [6] https://www.wsj.com/us-news/law/judge-rules-trump-administration-violated-anthropics-first-amendment-rights-0c20c442