Judge Rules Pentagon's Anthropic Blacklist Unconstitutional

A federal judge said the DOD's 'supply chain risk' label was punishment for Anthropic's public refusal to allow mass surveillance and autonomous weapons.

On the evening of August 27, 2026, U.S. District Judge Rita Lin of the Northern District of California filed a 59-page order that did not read like a close call. Anthropic had sued the Department of Defense, Defense Secretary Pete Hegseth, and President Donald Trump over a “supply chain risk” label that effectively blacklisted the company from federal work. Lin’s order on cross-motions for summary judgment concluded that the designation “constituted unlawful retaliation in violation of the First Amendment.” The court’s choice of words matters: it is the first time a federal court has told the U.S. military that it cannot punish an AI vendor for publicly saying no to specific weapons and surveillance uses.

What the Pentagon did

The blacklist dates to early 2026. Anthropic had worked with the Defense Department since late 2024 through a Palantir partnership, and in March 2025 launched a standalone Claude Gov product for federal users. In the fall of 2025, DOD pushed for unrestricted Claude access covering “all lawful uses.” Anthropic refused to drop its guardrails on mass surveillance of U.S. persons and on fully autonomous lethal weapons. Negotiations continued through January 2026, with Under Secretary Emil Michael telling CEO Dario Amodei they were “very close here,” according to court findings reported by Washington Technology.

The dispute went public on February 26, 2026, when Anthropic issued a written statement laying out the unacceptable uses it would not authorize. Within roughly 24 hours, Trump posted on Truth Social directing every federal agency to stop using Anthropic’s products, and Defense Secretary Pete Hegseth followed by formally designating Anthropic a “supply chain risk” to national security the same day (February 27, 2026). The directive triggered a cascade across the entire federal government, not just the military, and Hegseth proposed applying the Defense Production Act to the company. OpenAI signed its own Pentagon agreement hours after Anthropic was punished, a sequence TechCrunch flagged at the time.

Anthropic filed two complaints on March 9, 2026, one in California and one in Washington, D.C. On March 27, 2026, Judge Lin issued a preliminary injunction blocking enforcement of the supply chain risk label and the presidential directive, finding that “punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation.” That injunction paused the policy while litigation continued, and the August 27 ruling made the pause permanent on the merits.

What the court actually said

The August 27 order went further than the March injunction. Lin found that neither the Constitution nor the federal statute the Pentagon invoked allowed the government to “impose sweeping penalties based principally on Anthropic’s critique of the Administration’s views.” Her language about the agency’s intent was unusually direct. The judge’s ruling, as quoted by NPR, said the government’s “words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government,” and that the Pentagon’s position “was not based on any articulable basis to believe that Anthropic would actually sabotage its model.” The order also found the measures were “arbitrary and capricious” under the Fifth Amendment because Anthropic received no advance notice or chance to respond, and rejected the Pentagon’s repeated invocation of national security as “not a blank check to punish and retaliate against government critics.”

The court did leave one question open. It did not decide whether a company’s decisions about how its own technology may be used are themselves protected speech, only that Anthropic’s public statements about those decisions were. That narrower holding is enough to win the case but stops short of creating a general right for any AI vendor to refuse military work.

EFF and a coalition of civil liberties groups filed amicus briefs supporting Anthropic, including one brief filed June 18, 2026, in the same case. Google and OpenAI employees, Microsoft, and several industry associations also filed supporting briefs, an unusually broad lineup for a single AI vendor’s courtroom fight.

What This Means

The order is a victory for AI vendors who want to publicly refuse specific military uses of their models without losing every federal contract. It tells the Defense Department that “national security” cannot be the tail end of a tweet that punishes a company for its public stance. That matters beyond Anthropic. Other frontier model providers face the same set of pressures; the Pentagon’s willingness to deploy the supply chain risk label as a punishment tool is now on the record as unconstitutional retaliation, at least on these facts.

The limits are real. The court did not say the Pentagon must buy Anthropic’s products. It did not say a future administration cannot deprioritize a vendor for prosaic procurement reasons. It did not create a general right to refuse lawful orders. It ruled that this particular punishment, justified by this particular mix of public criticism and a thin national-security rationale, crossed the First Amendment line. A separate, narrower appeal remains pending in the D.C. Circuit, and the Justice Department is expected to appeal the California ruling, which means the holding is not final.

The bigger test is what the order does to the government’s playbook. The Pentagon tried, in plain language, to make an example of a vendor that would not bend on autonomous weapons and domestic surveillance. A federal judge has now said, in writing, that this is not how the United States treats companies that criticize the government. Whether that holds on appeal will shape what every other AI lab is asked to do, and what they can safely refuse.

The Bottom Line

A federal court has ruled that the Pentagon’s “supply chain risk” designation of Anthropic was unconstitutional retaliation for the company’s public refusal to allow Claude to be used for mass surveillance of Americans or autonomous weapons. The government is expected to appeal, but for now the order stands: the Defense Department cannot use a national-security label to punish an AI vendor for saying no out loud.