← All posts / Policy

Federal Judge Strikes Down Pentagon's Blacklisting of Anthropic as Unlawful Retaliation

Judge Rita Lin's 59-page ruling vacates the 'supply chain risk' designation against Anthropic, calling the government's measures 'illegal and baseless' and warning that national security is 'not a blank check' to punish critics.

Federal Judge Strikes Down Pentagon's Blacklisting of Anthropic as Unlawful Retaliation

One of the strangest confrontations between Washington and Silicon Valley this year just reached a decisive courtroom milestone. On Thursday, US District Judge Rita Lin of the Northern District of California issued a 59-page ruling vacating the Pentagon’s designation of Anthropic as a “supply chain risk,” declaring that the extraordinary measures the government took against the AI company were “illegal and baseless.”

The order, filed August 27 in case 3:26-cv-01996-RFL, makes permanent a temporary suspension Lin first granted in March. It bars the federal agencies named in Anthropic’s lawsuit from enforcing the designation and from carrying out the directive — reportedly endorsed by President Trump — that all federal agencies stop using Anthropic’s products.

What the judge said

Lin’s decision is unsparing in its language. “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote. Citing the government’s own records, she found that the War Department designated Anthropic as a supply chain risk because of its “hostile manner through the press” — in other words, because the company had publicly criticized administration policy, not because its products posed any genuine security threat.

The ruling states the government’s actions “were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the” administration’s positions on AI use. “Though the Department of War is undisputedly free to select the AI vendor of its choice,” Lin wrote, “the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.” The court ordered the designation vacated and declared the department acted “without authorization by law.”

Back in March, when Lin paused the punitive measures, she was already blunt about their apparent purpose: the government’s actions looked like an attempt to “cripple Anthropic” for exercising its First Amendment rights.

How we got here

The dispute began in late February. On February 24, Defense Secretary Pete Hegseth delivered a formal demand to Anthropic CEO Dario Amodei: remove all usage restrictions from Claude and grant the military full access for any “lawful” purpose — language that could encompass AI-directed targeting, autonomous weapons, and domestic surveillance. Anthropic refused, maintaining that its models are not reliable enough to be safely used in autonomous lethal weapons systems and that it opposes domestic mass surveillance as a violation of rights.

Three days later, Hegseth designated Anthropic a “supply chain risk” — a label born of an obscure government-procurement statute aimed at protecting military systems from foreign sabotage, and normally reserved for foreign firms like Huawei. It was the first time a US company had ever been publicly placed in that category. The Pentagon ordered all federal agencies to permanently stop using Anthropic’s products, and Hegseth publicly accused the company of “arrogance and betrayal.”

Anthropic sued on March 9, arguing the government had retaliated against its protected speech in violation of the First Amendment and denied it due process under the Fifth Amendment — the company was never given a meaningful chance to dispute the designation before it took effect.

Why this matters beyond Anthropic

It’s a boundary-setting precedent for AI policy. The Pentagon’s core argument was that private companies should not be able to constrain military action — that if the government lawfully wants to use a commercially available AI system, the vendor has no standing to draw ethical lines. Lin’s ruling rejects that framing when it is enforced through retaliation: the government may choose its vendors, but it may not weaponize procurement statutes to punish a company for its stated safety positions.

The stakes were existential for Anthropic. The company warned the designation could cost it billions of dollars in lost business and reputational harm, since a formal “national security risk” label would poison far more than defense contracts — allied governments, enterprise customers, and foreign regulators all watch that list. The ruling clears a major cloud just as Anthropic prepares for what could be the largest IPO in history: bankers have signaled a raise that could exceed $100 billion at a valuation around $2 trillion, which would surpass SpaceX’s record-setting June debut.

The fight isn’t over. The government may appeal, and it has already appealed earlier rulings in the dispute. A second, separate lawsuit playing out in Washington, DC remains pending — and it will be heard by a three-judge panel, two of whom are Trump appointees who have expressed open skepticism about Anthropic’s arguments. A favorable ruling in San Francisco is a major win, but not yet the final word.

It tests whether “safety” positions are legally protected speech. One of the quieter implications of Lin’s reasoning is that a lab’s public commitment to usage restrictions — refusing autonomous weapons, refusing mass surveillance — counts as a “protected viewpoint” under the First Amendment. If that holding survives appeal, it would give every AI vendor a constitutional shield against retaliation for declining military use cases, a meaningful check on executive pressure in an era when labs are being courted, and coerced, by governments worldwide.

What happens next

An Anthropic spokesperson said the company welcomed the ruling. The Pentagon and the Department of Justice have not said whether they will appeal Thursday’s final judgment, though administration officials have previously blasted the court’s interference — one line of criticism circulating after the ruling called the judiciary’s pattern of decisions against the administration “overreach.”

For the AI industry, the immediate practical effect is that Claude can return to federal workflows that had frozen it since spring, and Anthropic’s commercial pipeline — including its government business — resumes without the blacklist’s shadow. The deeper effect will take longer to settle: the DC circuit case, a likely appeal, and the October IPO window all loom.

Either way, the precedent now on the books is remarkable. An American AI company refused its military’s demand for unrestricted access to its most capable model, the government responded by blacklisting it with a tool designed for foreign adversaries, and a federal judge — in the strongest terms available — told the government that national security does not license punishment of critics. How durable that precedent proves will shape the leverage of every AI lab that ever has to say no.