Connect with us

NEWS

Anthropic Beats the Blacklist as Rivals Keep Pentagon Work

A San Francisco judge vacated Anthropic’s supply chain risk label, while the Pentagon keeps the classified vendors who signed the night of the ban.

Published

on

Judge Rita F. Lin vacated the Pentagon’s supply chain risk label on Anthropic on Thursday, calling the blacklist illegal and baseless. The 59-page opinion still leaves the Defense Department free to keep the AI vendors who signed classified deals the same week the government tried to make an example of the Claude maker.

Lin, a Biden appointee on the U.S. District Court for the Northern District of California, found First Amendment retaliation, a Fifth Amendment due process breach, and a violation of 10 U.S.C. § 3252. The White House did not immediately comment. The government is expected to appeal.

The Court Vacated the Label and Left Vendor Choice Intact

The dispute began as a contract fight over Claude Gov, the dedicated models U.S. intelligence and defense agencies have used since 2024. Anthropic would not drop two limits: no mass surveillance of Americans, and no lethal autonomous warfare. Defense Secretary Pete Hegseth wanted the models available for every lawful military purpose.

On February 27, 2026, President Donald Trump ordered every federal agency to stop using Anthropic. About an hour later Hegseth, on X, designated the company a supply-chain risk to national security and barred any military contractor, supplier, or partner from commercial activity with it. Anthropic PBC sued on March 9 in San Francisco as Anthropic PBC v. U.S. Department of War, case 3:26-cv-01996. Lin blocked the measures in March. Thursday’s judgment makes that halt permanent.

The order of final relief issued Thursday does five concrete things, and one thing it refuses to do.

WHAT LIN ORDERED

  • Speech holding: The challenged actions are declared unlawful retaliation for Anthropic’s protected public critique of Pentagon AI policy.
  • Process holding: The company was denied the notice and chance to be heard that the Fifth Amendment required before the label landed.
  • The blacklist: The supply chain designation is vacated, set aside, and remanded under the Administrative Procedure Act.
  • The boycott: Hegseth’s order that no military partner may do any commercial business with Anthropic is vacated as arbitrary and an abuse of discretion.
  • The carve-out: The Pentagon does not have to use Claude and may still switch vendors if it follows ordinary law.

Lin wrote that the Department of War is free to pick its AI vendor. The broad measures around that choice, she found, were a public punishment dressed up as a sabotage finding.

The empty invocation of national security is not a blank check to punish and retaliate against government critics.

Rita F. Lin, U.S. District Judge, Northern District of California, Aug. 27 opinion

Anthropic lawyer Michael Mongan told Lin at the July 30 hearing that the campaign would “profoundly harm Anthropic” and chill debate on how the military uses frontier models. Company evidence in the case put the hit, if the label stuck, at a 50 to 100 percent drop in defense-contractor revenue and “multiple billions of dollars” in 2026 sales. Spokesperson Danielle Cohen said the firm welcomed the ruling and remains focused on working with the government on national security uses of AI.

A Four-Page Memo Was the Entire Risk File

Lin’s harshest finding is how thin the file was. Defendants submitted an administrative record whose entire rationale, she wrote, is a four-page memo by Under Secretary Emil Michael dated March 2, 2026. That memo post-dates two of the three challenged acts. The government later backed off its main technical claim: that Anthropic had backdoor access to models once they sat on a national security system.

Anthropic, the court said, undisputedly lacks that access. The company submitted unrebutted evidence that it cannot reach or control deployed models. Claude Gov records risk scores on prompts, but those scores are not visible to Anthropic and cannot change the model’s behavior. Defendants conceded the technology is no riskier than any other “black box” AI model.

That left “trust.” The government said Anthropic’s “increasingly hostile manner through the press” meant it could not be trusted to keep its models intact. Lin held that neither the Constitution nor § 3252 lets officials impose sweeping penalties based principally on a vendor’s critique of administration views.

SUPPLY CHAIN RISK

  • The statute: Section 3252 lets the defense secretary exclude a source from a covered procurement after written findings and notice to Congress.
  • The definition: The law defines the risk that an adversary may sabotage a national security system, or maliciously insert a function, so as to surveil, deny, disrupt, or degrade it.
  • The miss: Lin held Anthropic is not an adversary in that sense. Asking hard contract questions does not convert an IT vendor into a saboteur.

Congress wrote those DoD supply chain risk procurement rules for covert tampering in hardware and code, the kind of problem usually tied to a foreign supplier. The secretary must also find that less intrusive measures are not reasonably available, and tell the defense committees what those measures were. Lin found Hegseth recited that finding in boilerplate and never discussed any alternative in the record. Six identical committee notices, she wrote, contained no such discussion.

The government’s own timeline cut against a sabotage theory. Days before the blacklist, Hegseth had floated using the Defense Production Act on Anthropic, a tool for a firm the country needs rather than a firm it fears. Right after the posts, the department was still chasing a contract and saying it was “very close.” By April, officials were talking with Anthropic about Mythos, its new model, including at the White House, and news accounts in the record had the NSA and NASA starting to use it. Lin wrote that none of that matches a genuine fear the company would poison its software.

OpenAI Closed a Classified Deal the Same Night

Hours after Trump and Hegseth cut Anthropic off, OpenAI said it had reached an agreement to put its models on the Pentagon’s classified network. The company published the terms the next day and updated them on March 2.

OpenAI listed three red lines: no mass domestic surveillance, no directing autonomous weapons, and no high-stakes automated decisions. Its post said the deployment is cloud-only, with OpenAI running the safety stack, no edge devices, and cleared engineers on site. The contract still says the Department of War may use the system for all lawful purposes, inside those limits. OpenAI argued its cloud-only classified deployment terms were tighter than earlier classified AI deals, including Anthropic’s original contract, and said it had told the government Anthropic should not be tagged a supply chain risk.

The court record includes an internal Dario Amodei note, described in The Information and filed in the administrative record, calling OpenAI’s safety layer “safety theater” and calling some of the public messaging “just straight up lies about these issues.” That fight is now beside the operational point. OpenAI is on the classified network under a deal signed the night of the punishment. Anthropic has a judgment that the punishment was illegal.

This week, Anthropic delivered a master class in arrogance and betrayal as well as a textbook case of how not to do business with the United States Government or the Pentagon.

Pete Hegseth, Defense Secretary, post on X, February 27, 2026

Lin treated that language as motive evidence. Hegseth, she noted, tied the penalty to Anthropic’s “arrogance” and to what he called sanctimonious rhetoric and corporate virtue signaling. Justice Department lawyers had argued that talk inside a contract negotiation is not protected speech, and that AI models are “so staggeringly enormous and opaque,” as they put it at the July 30 hearing, that the department cannot vet them like a piece of hardware. Lin called the no-protection theory unsupported. At that same hearing she said the government’s position seemed at odds with the First Amendment, and that the record had gotten worse for the government over time.

Which Agencies Must Rescind Their Anthropic Orders?

The injunction reaches every defendant except a short list of non-participants. Lin also sorted the agencies by whether they issued a final sanction after Trump’s directive. That split decides who must unwind paperwork, and who does not.

AGENCY OUTCOMES IN THE ORDER

Agency group What the court did
Department of War (Pentagon) and Secretary Hegseth Supply chain designation and contractor boycott vacated; permanent injunction
Treasury, State, DHS, Energy, GSA, OPM, NRC, FHFA Implementation orders vacated as sanctions issued without lawful authority
HHS, Commerce, VA, SEC, NASA Anthropic lost its separate APA § 558 claim; no vacatur on that count
National Endowment for the Arts, Social Security Administration, Federal Reserve, Executive Office of the President Treated as non-participating; government judgment on all claims

FHFA’s relief does not cover anything it did as a conservator. Lin granted the government judgment on Anthropic’s ultra vires separation-of-powers count, so the win is the speech, process, and APA holdings, not a ruling that the president lacked power to speak. Defendants must rescind guidance that carried out the challenged actions and take steps to stop their enforcement. The court kept jurisdiction to police that.

Claude’s Seat on Classified Networks Is Already Moving

Before the fight, Claude was inside the building. DCSA granted Anthropic a Top Secret facility clearance after an 18-month vetting. In June 2025, GSA and the department authorized Claude through FedRAMP High and DoD Impact Levels 4 and 5. In July 2025 the Chief Digital and Artificial Intelligence Office awarded a two-year pact worth up to $200 million to integrate AI across the department. In August 2025, Anthropic and GSA said Claude Gov would go to the civilian executive, Congress, and the courts. Until March 2, 2026, the administrative record identified no supply chain risk at all.

HOW THE BLACKLIST WAS BUILT

  1. February 27, 2026: Trump orders agencies to cease using Anthropic. Hegseth posts the risk label and the contractor boycott.
  2. March 3, 2026: The secretary issues the written designation under § 3252 after the Michael memo.
  3. March 9, 2026: Anthropic files in San Francisco and, separately, petitions the D.C. Circuit.
  4. March 26, 2026: Lin issues a preliminary injunction and stays the effective date.
  5. July 30, 2026: Argument on cross-motions for summary judgment.
  6. August 27, 2026: Final relief; the district-court docket is marked terminated.

The judgment does not rewind the stack. MeriTalk reported that Under Secretary Michael said in June the department had finished about two-thirds of its shift off Anthropic infrastructure, with a presidential-directive deadline of Sept. 29 for defense components and industrial-base partners to remove the software. A government lawyer told Lin in late July, Bloomberg reported, that the Pentagon meant to finish winding down by Sept. 30. On May 1 the Pentagon announced classified-network agreements with OpenAI, Alphabet, Nvidia, SpaceX, Microsoft, Amazon, and Reflection for lawful operational use.

Those deals are the practical sequel to Thursday’s order. Lin can wipe a label. She cannot draft the department back onto Claude, and paragraph 14 of her order says so in plain terms.

A Narrower Fight Continues in the D.C. Circuit

The San Francisco case is the big statutory and constitutional fight. It is not the only one. Anthropic also petitioned the U.S. Court of Appeals for the D.C. Circuit, No. 26-1049, over a March 3 determination under 41 U.S.C. § 4713, a different supply-chain authority aimed at covered procurement actions. That petition was already raising, in an April 8 order, novel questions about what counts as a supply-chain risk under § 4713 and what qualifies as an urgent national-security interest.

MeriTalk reported that a three-judge D.C. Circuit panel declined to halt the Pentagon’s restrictions while that case proceeds, the reverse of Lin’s March injunction in California. TechCrunch noted the D.C. suit is still ongoing. Until that court rules, the government still has a second statute in play even though the § 3252 designation in California is vacated.

Defenders of the original label, in replies to coverage of the ruling, went after Lin’s appointing president rather than the text of § 3252. The opinion already answers that frame with the government’s own paper: a backdoor theory it abandoned, a Defense Production Act pitch that treated Anthropic as essential, and ongoing Mythos talks that assume the same lab is safe enough to use. The classified work, meanwhile, has been moving to firms that signed. Thursday’s order restores Anthropic’s legal standing. It does not put Claude back on the networks the department has spent the spring and summer leaving.

Frequently Asked Questions

What Is a Supply Chain Risk Under Section 3252?

Covered procurement actions under the statute are narrow: excluding a source that fails qualification standards or a supply-chain evaluation factor, or withholding consent for a subcontract, all in the course of buying a national security system or an IT item that goes into one. The secretary of defense, Army, Navy, or Air Force may act only after consulting procurement officials, putting the findings in writing, and notifying the congressional defense committees, with intelligence committees added when the system sits in the National Intelligence Program or Military Intelligence Program.

Did the Ruling Force the Pentagon to Use Claude?

No. Paragraph 14 of the Aug. 27 order states that it does not bar any lawful step that was available on February 27, 2026, before the challenged actions, and gives the example that the department need not use Anthropic and may transition to other providers if it follows applicable rules. Lin also denied Anthropic judgment on its ultra vires separation-of-powers count, so the president’s own directive is constrained by the First Amendment holding rather than wiped as beyond Article II.

What Process Did Anthropic Miss Before the Label?

Ordinary contractor suspension and debarment rules in the Federal Acquisition Regulation give notice and a chance to respond. Section 3252 skips those steps, Lin noted, presumably because most hostile adversaries are foreign actors without due process rights. She still found a Fifth Amendment liberty interest in Anthropic’s reputation once the government formally branded it an adversary, and held that the record showed no urgency that justified skipping a hearing, especially because the Michael memo came after two of the three punishments had already been announced on social media.

How Does the D.C. Circuit Case Differ From the California Suit?

The D.C. petition attacks a March 3 determination under 41 U.S.C. § 4713, not the 10 U.S.C. § 3252 designation Lin vacated. In April the D.C. Circuit asked whether it even has jurisdiction under 41 U.S.C. § 1327, which channels review of covered procurement actions, and whether the government had directed specific covered procurement actions against Anthropic. A loss or win there would not automatically undo Lin’s First Amendment injunction, and the reverse is also true.

What Extra Language Did OpenAI Add on March 2?

After the first announcement, OpenAI and the department added clauses stating that, consistent with the Fourth Amendment, the National Security Act of 1947, and FISA, the system shall not be intentionally used for domestic surveillance of U.S. persons, including through commercially acquired personal information, and that the department understands this to bar deliberate tracking of U.S. persons. The department also said OpenAI’s services would not be used by intelligence agencies such as the NSA without a new agreement, and that it would convene a working group of frontier labs and cloud providers.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending