AI Privacy

The Pentagon Blacklisted Anthropic. A Judge Said That Was Unlawful

Editorial illustration of Donald Trump shouting at a judge as an AI wearing an Anthropic T-shirt stands between them in a courtroom.
A court ruling found the Pentagon’s blacklisting of Anthropic unlawful.

The Anthropic Pentagon ruling found that the US government acted unlawfully when it labelled the AI company a national-security supply-chain risk and imposed sweeping restrictions on federal agencies and defence contractors. In a 59-page order filed on 27 August, US District Judge Rita F. Lin granted Anthropic summary judgment on its First Amendment and due-process claims, as well as key administrative-law challenges. The decision was a major victory for Anthropic, but not a win on every claim and not an order forcing the Pentagon to keep using Claude.

The dispute grew from Anthropic’s insistence on restrictions covering mass domestic surveillance and fully autonomous lethal weapons. President Donald Trump and Secretary of War Pete Hegseth responded in February and March by directing agencies to stop using Anthropic products, designating the company a supply-chain risk and telling military contractors they could not conduct commercial activity with it.

What the Anthropic Pentagon Ruling Actually Decided

Judge Lin’s summary-judgment order says the undisputed record showed unlawful retaliation in violation of the First Amendment. The court found the measures were driven by a desire to make a public example of Anthropic for criticising the government’s position, rather than by an articulable belief that the company would sabotage its model.

The court also found that Anthropic had been denied the process required by the Fifth Amendment before the government attached a damaging national-security label and broad commercial penalties. On the Administrative Procedure Act claims, the judge concluded that the Hegseth directive exceeded statutory authority by creating a secondary boycott and that the supply-chain designation was contrary to law, procedurally defective, arbitrary and capricious.

Anthropic won a separate Section 558 claim against the Department of War and several agencies that had issued final orders terminating use of its products. It did not win that claim against agencies whose records showed only interim steps, and the court rejected Anthropic’s ultra vires separation-of-powers claim. The motion was therefore granted in part and denied in part on both sides.

Why the Judge Rejected the National-Security Explanation

The order describes the administrative record as slim. A four-page memorandum supplied the government’s rationale and was prepared after two of the challenged actions. The government had initially raised the possibility that Anthropic could retain backdoor access to technology deployed on national-security systems. The order says it became undisputed that Anthropic lacked such access and that its technology was no riskier on that basis than other black-box models.

That left trust as the factor the government said made Anthropic different. Officials cited the company’s public criticism and what they called an increasingly hostile manner through the press. The court treated those references as evidence that the company’s viewpoint was part of the reason for the punishment.

The judge also pointed to contradictory conduct. Days before the challenged actions, Hegseth had considered using the Defense Production Act, a step that would treat Anthropic as important to national security rather than a threat. After the designation, officials continued discussing a contract and later explored possible collaboration on a new Anthropic model. The order found that behaviour difficult to reconcile with a genuine belief that the company might poison or sabotage military software.

The Blacklist Went Far Beyond Ending One Contract

The government retains broad freedom to choose its suppliers. Judge Lin’s earlier preliminary-injunction order made clear that the Department of War could transition to another AI provider through lawful means. The August ruling does not require it to buy or deploy Anthropic products.

The legal problem was the breadth and stated purpose of the measures. The directives barred federal agencies from using Anthropic technology and sought to stop companies doing military business from conducting any commercial activity with Anthropic, even when unrelated to defence. The court described that as a secondary boycott extending well beyond an ordinary contracting decision.

LiveAIWire’s earlier analysis of AI military strategy described the policy collision behind the case. The Pentagon wants access to frontier models for every lawful military purpose. Anthropic argues that some lawful uses, particularly mass domestic surveillance and fully autonomous lethal weapons, should remain outside its terms. The ruling does not decide the ethics of those uses. It decides how the government may respond when a supplier publicly refuses them.

What Happens to the Supply-Chain Designation

The summary-judgment order says a separate relief order will issue. It concludes that declaratory relief, vacatur and a permanent injunction are appropriate, while addressing the government’s objections to those remedies. The judge denied a request to administratively stay the permanent injunction for seven days, finding no demonstrated irreparable harm after the preliminary injunction had been in place for more than five months.

The court found that a simple remand without vacating the challenged actions would be inadequate because the errors were substantive as well as procedural. It also said an injunction was needed to address the constitutional claims and prevent agencies from resuming unlawful retaliation. The exact operative terms belong in the separate relief order, which means coverage should not pretend the 59-page opinion itself resolves every implementation detail.

The case docket remains the best place to track subsequent filings. The CourtListener docket records the Northern District of California case as Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996-RFL. An appeal is possible, and the dispute has also involved related proceedings in the District of Columbia Circuit.

The Ruling Changes the Government’s Leverage Over AI Labs

The immediate lesson is not that an AI company has a right to a government contract. It is that officials cannot transform a contracting disagreement into a government-wide punishment for protected public criticism without constitutional and statutory consequences. The court repeatedly distinguished lawful supplier choice from measures designed to deter speech and isolate the company from third parties.

That boundary matters beyond Anthropic. Frontier AI providers are becoming infrastructure suppliers to defence, intelligence and civilian agencies while retaining private safety policies that may be stricter than the law. If a government can punish one lab across its entire market for refusing a lawful but controversial use, every competing lab receives a warning about what public disagreement may cost.

LiveAIWire’s reporting on AI export controls showed another way government power can affect access to frontier models. The Anthropic case now adds a constitutional limit: national-security language does not automatically shield retaliation or replace the required administrative process.

What the Court Did Not Decide

The ruling does not settle whether Anthropic’s restrictions are the best military policy. It does not prevent the Pentagon from selecting other providers, ending contracts lawfully or setting legitimate security requirements. It does not award Anthropic victory against every named defendant, and it rejected the separation-of-powers theory advanced in Count III.

It also does not end the litigation risk. The government may appeal, later relief can be contested and related proceedings can produce additional rulings. The decision is nevertheless more than a temporary pause. Summary judgment is a merits ruling based on the developed record, following the preliminary injunction issued in March.

The headline conclusion is supported by the order’s own language and holdings. The Pentagon and wider administration blacklisted Anthropic in practical effect, attaching a supply-chain-risk label, a government-wide stop-use direction and a boycott reaching defence contractors. Judge Lin found the central actions unlawful under the First Amendment, Fifth Amendment and administrative law. The remaining question is not whether the court rejected the blacklist, but how the relief and any appeal shape what happens next.

About the Author

Stuart Kerr is Technology Correspondent at LiveAIWire, covering artificial intelligence, cybersecurity and the social impact of emerging technology. LiveAIWire is an independent, human-led technology publication using AI-assisted research, editorial production and original AI-assisted editorial illustrations under his direction.