Anthropic Wins as Judge Bars Pentagon From Punishing AI Ethics Policies

August 29, 2026:

Anthropic Wins as Judge Bars Pentagon From Punishing AI Ethics Policies
Anthropic Wins as Judge Bars Pentagon From Punishing AI Ethics Policies
The Pentagon seal is seen in the briefing room at the Pentagon in Washington, DC, on March 31, 2026.
Oliver Contreras/AFP via Getty Images

A federal judge permanently barred the Pentagon Thursday night from enforcing its blacklisting of Anthropic — issuing a ruling that, for the first time in American law, establishes that the government cannot wield the supply-chain risk statute to punish domestic AI companies for publicly stating the limits of how their technology can be used.

U.S. District Judge Rita F. Lin of the Northern District of California found, in a 59-page summary-judgment order, that the Defense Department violated Anthropic’s First Amendment right to free speech and its Fifth Amendment due process protections. The ruling vacates Defense Secretary Pete Hegseth’s supply-chain risk designation, permanently enjoins the government from giving it effect, and establishes a constitutional floor that now covers every AI company maintaining an acceptable-use policy — not just Anthropic.

“The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote in her ruling.

“Though the Department of War is undisputedly free to select the AI vendor of its choice,” she added, “the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.”

How the Dispute Began

The conflict stretches back to July 2025, when Anthropic and the Pentagon struck a landmark agreement: Claude became the first frontier AI model approved for use on classified military networks, under a contract worth approximately $200 million.

But the partnership collapsed. As the two sides renegotiated contract terms, the Pentagon demanded that Claude be available for what it described as “all lawful purposes” — language that, Anthropic argued, would eliminate two specific restrictions the company had maintained since its founding: no use in fully autonomous weapons systems that engage targets without human input, and no use in mass domestic surveillance of American citizens.

Anthropic CEO Dario Amodei refused to remove those guardrails. The Pentagon’s position was that no private contractor could restrict the lawful use of a critical military capability. After negotiations failed, Hegseth issued a supply-chain risk designation on February 27, 2026, under 10 U.S.C. § 3252 — a statute whose legislative history is built entirely around protecting military systems from foreign adversaries such as Huawei, ZTE, and Kaspersky, and which had never been used against domestic companies.

The designation required defense contractors to certify that they did not use Anthropic’s Claude models in Pentagon-related work. President Trump separately ordered all federal agencies to stop using Anthropic’s technology entirely. The practical consequences were immediate: Anthropic’s contracts were canceled, its models began being removed from military systems, and the shadow over its broader government and commercial relationships produced documented financial disruption exceeding $180 million in affected negotiations.

What Judge Lin Found

Anthropic filed suit in federal court on March 9, challenging both the supply-chain risk designation and the presidential and secretarial directives as unconstitutional retaliation. Judge Lin granted a preliminary injunction on March 26, writing that the measures appeared to be “classic illegal First Amendment retaliation” and that nothing in the governing statute supports “the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.”

The July 30 summary judgment hearing, where Lin had already signaled the government’s case had “gotten worse” since March, produced no immediate ruling — but the full opinion issued Thursday night confirmed her direction.

Lin found the blacklisting was driven by a desire to make a public example of Anthropic for its public criticism of the government’s AI procurement demands — not by any articulable threat to national security. She pointed to a fundamental contradiction in the government’s own record: the formal risk assessment memo that was supposed to justify the supply-chain risk designation was dated March 2, 2026 — four days after the Trump and Hegseth directives it was meant to support had already been issued. A risk assessment written after the decision it was supposed to justify, Lin wrote, suggested the record was assembled “after the fact” to justify the foreordained conclusion.

A second contradiction proved equally damaging. The day after the designation was announced, Pentagon Under Secretary Emil Michael told Anthropic’s leadership that the two sides were “very close” to reaching a deal. The White House later discussed possible uses of Anthropic’s more advanced Mythos model in sensitive government settings. “None of that,” Lin wrote, “is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security.”

The court also identified a critical engineering finding that undermined the government’s stated rationale: Anthropic “undisputedly lacks” any backdoor access to Claude once it is delivered to the Defense Department, meaning the company cannot modify, restrict, or interfere with a deployed model after handoff. The government’s shifting concern — first that Anthropic might “flip a kill switch” on a deployed model, then that it might “bake restrictions” into a future model before delivery — was, Lin found, exactly the kind of moving-rationale that constitutes powerful evidence of pretext.

“An IT vendor does not become a potential adversary of the United States whenever it asks probing questions or stubbornly insists on particular contracting terms, even if doing so causes DoW to doubt its trustworthiness,” she wrote.

On the due process claim, the ruling found that the Pentagon failed to give Anthropic adequate notice or a meaningful opportunity to respond before stripping it of its ability to operate within large swaths of the federal marketplace. The government also failed to notify congressional committees in the manner required by the statute itself before invoking the designation.

Anthropic welcomed the ruling. “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology,” an Anthropic spokesperson said.

Why Every AI Company’s Ethics Policy Is Now a Protected Document

The ruling’s implications reach far beyond Anthropic’s balance sheet, where quarterly revenue reached a record $11.5 billion — roughly 14 times higher than the same period the prior year — demonstrating that the commercial markets continued operating even as the legal cloud persisted.

What the ruling establishes is a constitutional floor: the government cannot use 10 U.S.C. § 3252, or the “national security” label it authorizes, to punish any domestic AI company for publicly stating what its technology will and will not do. Every frontier AI lab currently holding government contracts — OpenAI, Google, Cohere, and others — maintains acceptable-use policies that restrict military or surveillance applications of their models. Those policies are now protected speech.

The Computer & Communications Industry Association, which filed an amicus brief in the case, had warned that a government victory would create a rational-calculation problem across the tech industry: companies would hesitate to enter federal contracts if maintaining publicly stated ethical positions could result in being branded a national security threat equivalent to Huawei. That risk, for the §3252 pathway, is now closed, as the CCIA amicus brief argued.

The ruling also resolves the specific question that had remained open since the July 30 hearing: whether the First Amendment framework known as the Pickering test applied, or whether a stricter constitutional standard governed because the government was acting in its sovereign capacity (issuing national security designations, extending a secondary boycott to every defense contractor) rather than as an ordinary contracting party managing a procurement relationship. Lin found the broader standard controlled — and the government’s “lack of trust” argument, rooted in Anthropic’s public criticism, did not survive it.

The Government’s Argument, Fairly Stated

The Department of Justice made arguments that were not frivolous and that the court took seriously before rejecting them.

DOJ attorneys argued that frontier AI models are categorically different from conventional defense hardware. A drone or a rifle can be physically inspected before delivery and verified against a specification. An AI model cannot: it is, as government lawyers put it, “staggeringly enormous and opaque.” Each model update represents a potential opportunity to introduce new constraints that the government has no ability to audit before deployment.

To illustrate the practical risk, the government cited a documented incident at the Centers for Disease Control and Prevention, where a CDC employee tried to use a commercial version of Claude for a permitted task and found the model refused because of a pre-existing guardrail — a restriction the employee had no way of anticipating.

Anthropic’s counsel responded that the government had not ordered a commercial model for classified use. It had ordered — and was in the process of receiving — a purpose-built government version that would carry neither the same restrictions nor the same commercial guardrails, making the CDC incident structurally irrelevant to the procurement at hand.

Lin acknowledged the genuine complexity of AI procurement but found that none of these considerations, even taken together, provided an “articulable basis” for believing Anthropic would sabotage its models — the standard the statute requires before a supply-chain risk designation may be issued against any vendor.

Not Over Yet

Despite Thursday’s ruling, Anthropic’s legal situation is not fully resolved. The company has a separate case pending in the U.S. Court of Appeals for the District of Columbia Circuit, challenging a related supply-chain risk designation issued under a different federal law: the Federal Acquisition Supply Chain Security Act (FASCSA), codified at 41 U.S.C. § 4713. That case, discussed in detail in the Jones Walker two-courts analysis, involves a distinct statutory authority and a separate judicial review mechanism.

The California case and the D.C. case are parallel tracks, not the same proceeding. The D.C. Circuit case involves a separate statutory designation with a separate court review mechanism. Oral argument in the D.C. case was held May 19, 2026, before a panel of three Republican-appointed judges — Judges Karen LeCraft Henderson, Gregory Katsas, and Neomi Rao. The D.C. Circuit denied the emergency stay in April, writing that lifting the designation “would force the United States military to prolong its dealings with an unwanted vendor of critical AI services in the middle of a significant ongoing military conflict.” At argument, the panel appeared divided; while Henderson had previously called the Pentagon’s original move “a spectacular overreach,” the panel had denied the emergency stay.

The D.C. case remains pending. Until it is resolved, Anthropic retains some supply-chain risk status in certain Defense Department contracting contexts. Even a complete Anthropic victory in both cases would not require the Pentagon to resume working with the company — the government retains the right to choose its vendors; it simply cannot punish vendors for their public positions.

The Trump administration is widely expected to appeal Thursday’s California ruling to the Ninth Circuit.

What Comes Next for AI and Military Procurement

Thursday’s ruling does not answer the underlying question that the Anthropic dispute crystallized: who controls the ethical conditions under which AI is deployed in military operations — the companies that build and maintain the models, or the governments that procure and use them?

Lin’s ruling answers only the constitutional dimension: the government cannot silence the companies’ answer to that question by branding them national security threats. What happens next in the policy arena — whether Congress acts to create clearer procurement frameworks, whether future administrations try different legal pathways, whether the AI industry collectively establishes industry-wide standards for military deployment — is unsettled.

For Anthropic specifically, the ruling removes a significant legal cloud. The company’s record quarterly revenue shows the commercial markets continued operating, but the government-adjacent revenue that Anthropic lost — the Pentagon contract, the contracts of defense contractors who had to certify non-use of Claude, the relationships chilled by the six-month wind-down period — represents a real and documented cost of the company’s stand.

For other AI companies, the ruling delivers a more durable benefit: the constitutional assurance that maintaining a published acceptable-use policy, and publicly defending it when a government agency disagrees, is protected speech. The government knew Anthropic’s red lines before the $200 million contract was signed. The ruling says the government cannot, upon finding those lines inconvenient, turn them into a national security emergency.

The Pentagon has not publicly stated whether it will appeal.


Frequently Asked Questions

What does “permanent injunction” mean, and what does it require the government to do?

A permanent injunction is a final court order — as opposed to the preliminary one Lin issued in March — that resolves the case on the merits and makes the relief indefinite. The order requires the government to rescind all directives it issued against Anthropic under the challenged authority: the §3252 supply-chain risk designation, the Hegseth directive barring defense contractors from doing business with Anthropic, and the Trump administration’s directive ordering all federal agencies to stop using Anthropic’s technology. It does not require the Pentagon to restart its work with Anthropic; the government retains the right to choose whichever AI vendor it prefers, as confirmed by the NOTUS ruling analysis.

Does this ruling protect other AI companies if the government tries to blacklist them for their ethics positions?

For companies facing the same statutory mechanism — a supply-chain risk designation under 10 U.S.C. § 3252 — yes. Lin’s ruling establishes binding precedent in the Northern District of California and is persuasive authority elsewhere: that §3252 cannot be applied to domestic AI companies because of their public positions on how their technology should be used, and that “lack of trust” rooted in a company’s public speech is not an articulable supply-chain risk. Any future administration seeking to use this specific statute against a domestic AI company for a similar reason would face this ruling as a direct precedent. A government seeking to blacklist companies through different statutory authorities — like the FASCSA designation still being litigated in the D.C. Circuit — would be on a separate legal track, as the CCIA D.C. Circuit brief explains.

What is still unresolved after this ruling?

The D.C. Circuit case challenging the FASCSA designation (41 U.S.C. § 4713) is still pending after a May 19, 2026 oral argument. That designation involves a different statute, a different judicial review mechanism, and a panel that denied the emergency stay and appeared more sympathetic to the government than Judge Lin was. Until the D.C. case is resolved, Anthropic retains some supply-chain risk status in specific defense contracting contexts — meaning the full legal cloud has not lifted yet. The government is also expected to appeal Lin’s California ruling to the Ninth Circuit, which could take months or longer to resolve.

If AI companies can maintain ethics limits, can the government still deploy AI for autonomous weapons?

Yes. Thursday’s ruling does not restrict what the government does with AI systems it acquires through other vendors. It only restricts the government from punishing Anthropic for maintaining its positions — and it explicitly preserves the Pentagon’s right to select any other vendor it prefers. OpenAI and Google both signed Pentagon contracts after Anthropic’s blacklisting, and those agreements were structured without Anthropic-style standalone restrictions on autonomous weapons or domestic surveillance use, as documented in the Wikipedia dispute timeline. The ruling does not affect those arrangements.

Source link