US Edition
Your source for latest news
TechnologyAI & national security

Judge Rules Pentagon Illegally Blacklisted Anthropic Over AI Safety Guardrails

A federal judge found that the Defense Department's "supply chain risk" designation of Anthropic was unlawful retaliation for the company's refusal to let its Claude models be used in autonomous weapons or domestic surveillance, vacating the label and permanently blocking the Pentagon's boycott order.

PT
By PressTemps Technology DeskPublished Today, 13:31 ET · 6 min read
Judge Rules Pentagon Illegally Blacklisted Anthropic Over AI Safety Guardrails
File photo: Anthropic CEO Dario Amodei. Photo: Simon Walker / No 10 Downing Street via Wikimedia Commons, CC BY 2.0
What to know
U.S. District Judge Rita F. Lin issued a 59-page order Aug. 27, 2026, granting Anthropic summary judgment and vacating the Pentagon's "supply chain risk" label along with Defense Secretary Pete Hegseth's boycott directive.
The designation stemmed from Anthropic's refusal to let its Claude AI be used for fully autonomous weapons or mass domestic surveillance under a July 2025 classified-network contract; it was the first time the label had been applied to a domestic company.
The judge found the government's action was retaliation for protected speech and rejected the security rationale, though she did not find Trump's phase-out directive exceeded presidential authority.
The administration is expected to appeal to the Ninth Circuit; a separate, narrower Anthropic case remains pending before a federal appeals panel in Washington, D.C.

A federal judge in San Francisco ruled Thursday that the Pentagon acted illegally when it branded the artificial intelligence company Anthropic a "supply chain risk" to national security, delivering the first substantive court defeat for the Trump administration in a six-month standoff over how the military may use commercial AI.

U.S. District Judge Rita F. Lin, of the Northern District of California, granted Anthropic summary judgment on its First Amendment, due process and Administrative Procedure Act claims in a 59-page order, finding that Defense Secretary Pete Hegseth's designation amounted to "unlawful retaliation" for the company's refusal to let its Claude models be used for autonomous weapons or domestic mass surveillance. She vacated the designation and Hegseth's accompanying boycott directive, converted an earlier preliminary injunction into a permanent one, and refused the government's request for even a brief administrative stay while it appeals.

What the order says

Lin's ruling, entered in the Northern District of California case Anthropic filed in March, did not mince words about the government's motive. "Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless," she wrote, adding that the record showed the designation was "based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government."

"The empty invocation of national security is not a blank check to punish and retaliate against government critics."

The judge also rejected the government's underlying rationale on the merits, noting that Anthropic "undisputedly lacks" any backdoor access to its technology once it is delivered to the Defense Department, and that other federal agencies kept meeting and contracting with the company even after the designation took effect — a pattern she said was "not consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security." Anthropic did not win every claim: Lin declined to find that President Trump's directive ordering agencies to stop using Anthropic's products exceeded his executive authority, a split outcome reported Thursday as Anthropic's first courtroom win in the monthslong dispute even as one theory of its case fell short.

How the dispute started

The fight traces back to a July 2025 contract that made Claude the first frontier AI model cleared for use on classified U.S. government networks. Anthropic has maintained two standing restrictions on that access, which it calls its "two red lines": Claude may not be used to operate fully autonomous lethal weapons systems, and it may not be used for mass surveillance of Americans. When the Pentagon pressed the company to drop both restrictions during a contract renegotiation, Anthropic refused.

The dispute escalated publicly in late February, when Trump ordered federal agencies to phase out Anthropic's technology over six months and Hegseth said the company would be designated a supply chain risk, declaring that "no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic." The formal designation followed in early March — believed to be the first time the government has applied that label to a domestic AI company rather than a foreign one — and Anthropic laid out its position in a public statement days later, with chief executive Dario Amodei saying the company's "most important priority right now is making sure that our warfighters and national security experts are not deprived of important tools in the middle of major combat operations." In the same statement, Amodei apologized for a leaked internal memo, written amid the initial fallout, that he said had been intemperate and did not reflect his considered views of the administration — a sign of how personal the dispute had become between the company and Pentagon leadership even as the legal fight was just beginning.

Anthropic sued in two federal courts on March 9, arguing the designation was retaliatory and procedurally unlawful. Lin issued a preliminary injunction blocking most of its effects later that month, and the administration appealed that early ruling without success in seeking to have it lifted before trial. Thursday's order resolves the underlying case on the merits.

The designation drew objections in Washington well before Thursday's ruling. Senator Kirsten Gillibrand of New York, a member of the Senate Armed Services and Intelligence committees, said at the time that the designation was "a dangerous misuse of a tool meant to address adversary-controlled technology," arguing it punished a domestic firm with a mechanism designed for foreign threats. A group of former national security officials sent lawmakers a separate letter warning that turning the authority against an American company was "a profound departure from its intended purpose" that set a troubling precedent for how future administrations might treat companies that resist government demands.

Who felt the fallout

The designation was not symbolic. Contracts covered by the relevant federal acquisition rule obligated contractors to actively screen for Anthropic products, monitor federal contracting databases at least quarterly, report any use of Claude within three business days and submit mitigation plans within ten. Defense contractors with Claude embedded in existing systems, including Lockheed Martin, said they would comply and begin sourcing alternative AI vendors while the designation stood. The freeze also opened space for rivals: both OpenAI and Elon Musk's xAI moved to expand their own footprint inside the Pentagon during the months Anthropic's access was in question.

An Anthropic spokesperson said the company was gratified by the outcome but eager to move past the fight. "We welcome the court's ruling that this supply chain risk designation was unlawful," the spokesperson said. "We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology." The Department of War has not issued a public statement responding to Thursday's order.

The case has been watched beyond the immediate parties because it tested how far an administration could go in using a supply-chain-security authority, typically reserved for firms tied to foreign adversaries, against a domestic company over a policy disagreement. Anthropic was the first AI developer to receive the designation, and the ruling's finding that the label was applied as retaliation for protected speech, rather than for any demonstrated security flaw, sets a marker other AI companies negotiating safety terms with the Pentagon are likely to invoke if they face similar pressure.

What happens next

The administration is widely expected to appeal Lin's ruling to the U.S. Court of Appeals for the Ninth Circuit, following the same path it took after the March preliminary injunction, when the Justice Department sought unsuccessfully to have that earlier order lifted while the case proceeded. A second, narrower Anthropic suit challenging a related designation mechanism remains pending before a federal appeals panel in Washington, D.C., meaning the two sides are likely to keep litigating even as Thursday's order takes immediate legal effect. For now, the ruling removes the compliance burden the designation had placed on defense contractors and restores Anthropic's standing to bid for and hold Pentagon work, though how quickly agencies that shifted to competing AI vendors during the freeze return to Claude is likely to depend on contracts already underway rather than on the court order alone.

More on this story

All Technology