Connect with us

NEWS

Lin Throws Out the Anthropic Blacklist, Keeps Vendor Choice

Judge Rita Lin vacated the Pentagon’s Anthropic supply chain risk label, but the military can still drop Claude and a second case remains in Washington.

Published

on

U.S. District Judge Rita F. Lin threw out the Pentagon’s supply chain risk label on Anthropic on Aug. 27 and left the military free to drop Claude anyway. Her 59-page opinion found First Amendment retaliation, a due process failure, and a sabotage law stretched to punish speech, while the Department of War kept the right to pick another vendor.

Lin’s Final Order Vacates the Designation and the Contractor Ban

Lin, a Biden appointee in the Northern District of California, filed the four-page order of final relief at 5:56 p.m. PDT on Aug. 27 in Anthropic PBC v. U.S. Department of War. She granted Anthropic summary judgment on its speech, due process, and Administrative Procedure Act claims against Defense Secretary Pete Hegseth and the department. She denied the company’s broader claim that the episode was an unconstitutional grab of structural power.

The supply chain designation is vacated, set aside, and sent back under 5 U.S.C. § 706(2). So is Hegseth’s order that “no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic.” Defendants other than a short list of non-participating agencies are permanently barred from giving effect to those actions and must rescind the guidance that carried them out.

Paragraph 14 is the hinge the rest of the fight turns on. The order “does not require the Department of War to use Anthropic’s products or services and does not prevent the Department of War from transitioning to other artificial intelligence providers,” so long as any switch follows ordinary law. A common reading of the ruling treats it as a command to keep Claude on classified networks. The text does the reverse.

THE AUG. 27 SCORECARD

Claim Result
First Amendment retaliation Granted; permanent injunction
Fifth Amendment due process Granted; notice and hearing were missing
APA challenge to the 3252 designation Granted; designation vacated and remanded
Secondary boycott of defense contractors Vacated as arbitrary and beyond the statute
APA § 558 sanctions at nine agencies Granted; those cutoff orders vacated
Ultra vires separation-of-powers claim Denied; government wins that count
Claims against non-participating agencies Denied, including NEA, SSA, the Fed, and the Executive Office of the President

Lin also refused a seven-day pause on the injunction. She wrote that defendants had already lived under her March 26 preliminary order for more than five months and had not shown irreparable harm. An Anthropic spokesperson said, “We welcome the court’s ruling that this supply chain risk designation was unlawful,” and added that the company remains focused on working with the government “to harness AI for our national security so all Americans benefit from this technology.” The White House did not immediately respond.

What a Supply Chain Risk Means Under Section 3252

Hegseth invoked 10 U.S.C. § 3252, a procurement tool aimed at hostile interference in national security systems, not at a vendor’s press posture. The statutory definition of supply chain risk is the risk that “an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert” a covered system so as to surveil, deny, disrupt, or degrade it. Lin found Anthropic does not meet that definition.

The government’s own record, she wrote, had already abandoned the claim that Anthropic held a back door into deployed models. “It is now clear that Anthropic undisputedly lacks any such access and that, as Defendants concede, Anthropic’s technology is itself no riskier to the national security than any other ‘black box’ artificial intelligence model.” What remained, she said, was “trust,” tied to Anthropic’s “increasingly hostile manner through the press” and its critique of how the department wanted to use AI.

WHAT SECTION 3252 DEMANDS FIRST

  • A written finding: The agency head must determine that using the authority is necessary to protect national security by reducing supply chain risk.
  • Less intrusive steps: The same writing must find that milder measures are not reasonably available.
  • Notice to Congress: Classified or unclassified notice goes to the appropriate committees, with a summary of the risk assessment and of the milder steps that were rejected.
  • An adversary theory: The risk has to be sabotage, a malicious function, or subversion by an adversary, not dislike of a contractor’s public terms.

Lin wrote that an IT vendor “does not become a potential adversary of the United States whenever it asks probing questions or stubbornly insists on particular contracting terms.” A reading of Section 3252 that wide, she said, would make the law’s limits on the secretary’s discretion “meaningless.” Hegseth and the department also conceded procedural errors, including the required finding that less intrusive measures were unavailable, and she held those errors were not harmless.

OpenAI Signed for Classified Systems That Same Night

The courtroom win does not rewind Feb. 27. That afternoon, talks with Anthropic over a classified contract the two sides had been negotiating, described in contemporaneous accounts as a $200 million vehicle, missed a 5:01 p.m. deadline. President Donald Trump directed federal agencies to stop using Anthropic’s technology and called the firm “Leftwing nut jobs.” Hegseth designated it a supply chain risk and announced the contractor boycott the same day.

Hours later, OpenAI said it had reached a classified-network agreement with the Pentagon. The company listed three red lines: no mass domestic surveillance, no directing of autonomous weapons, and no high-stakes automated decisions. Deployment is cloud-only, not on edge devices such as aircraft or drones, with OpenAI keeping control of its safety stack and placing cleared engineers on site. The contract still says the department may use the system “for all lawful purposes,” then ties that phrase to current law and to DoD Directive 3000.09 on human control of autonomous and semi-autonomous systems.

OpenAI asked that the same terms be offered to other labs and said the government should try to resolve the fight with Anthropic. On whether Anthropic should carry a supply chain risk label, the company wrote, “No, and we have made our position on this clear to the government.” Dario Amodei, Anthropic’s chief executive, had refused to drop limits on mass surveillance of Americans and on lethal autonomous weapons, the same two uses OpenAI says its deal still blocks. The difference that mattered on Feb. 27 was who still had a classified path after the deadline, not who claimed the cleaner safety memo.

Hegseth’s Own Record Undercut the Sabotage Claim

U.S. intelligence and defense agencies have used Claude since 2024, and since March 2025 the department has run “Claude Gov” models for national security users through partner platforms. The DoW-specific usage policy, a contract term Anthropic cannot enforce with software, barred mass surveillance of Americans and lethal autonomous warfare. While those limits were in place, the Defense Counterintelligence and Security Agency still granted Anthropic a Top Secret facility clearance.

Lin’s undisputed-facts section is a short timeline of a punishment that outran its paperwork. The administrative record justifying the Feb. 27 and March 3 actions is, she wrote, “slim.” A four-page memorandum that post-dates two of the three challenged acts supplies the entire rationale.

FROM THE DEADLINE TO THE OPINION

  1. Feb. 27, 2026: Trump and Hegseth announce a government-wide cutoff and the supply chain label on social media, the same day classified talks with Anthropic miss the 5:01 p.m. deadline.
  2. March 3, 2026: Hegseth signs a formal determination under Section 3252, transmitted to Anthropic the evening of March 4.
  3. March 5, 2026: A department CIO memorandum, later cited by Under Secretary Emil Michael, tells components to discontinue Anthropic products across systems within 180 days.
  4. March 9, 2026: Anthropic sues in San Francisco and petitions the D.C. Circuit on a second statute.
  5. March 26, 2026: Lin issues a preliminary injunction blocking the label and Trump’s agency-wide directive.
  6. July 30, 2026: At the summary judgment hearing, Lin calls the government’s position “really troubling” and “at odds to me with the First Amendment.”
  7. Aug. 27, 2026: She enters final judgment for Anthropic on the core claims and denies a seven-day stay.

Days before the cutoff, Hegseth had proposed using the Defense Production Act on Anthropic, which would have treated the company as essential to national security rather than a threat to it. Immediately after the challenged actions, the department kept pursuing a contract and said “we are very close here.” Lin wrote that even now the government is discussing work with Anthropic on its new model, Mythos, “in an array of sensitive contexts.”

The empty invocation of national security is not a blank check to punish and retaliate against government critics.

Rita F. Lin, U.S. District Judge, Order on Cross Motions for Summary Judgment

She found the challenged actions “were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model.” Michael, the under secretary of war for research and engineering, had argued in a March 17 declaration that leadership might “alter or even shut off” Claude before or during an operation. A later declaration dropped that claim and spoke instead about the risk in model updates. On the Ruthless Podcast the morning of Aug. 27, Michael said he had read a clause he took to mean “You can’t use AI to defend yourself from a missile attack,” and that Anthropic answered with “moral values” and “our own constitution.” Lin had already held that stubborn contract terms do not turn a U.S. vendor into an adversary under Section 3252. Anthropic’s February red-line statement had set out the surveillance and autonomous-weapons limits that blew up the talks.

Nine Agencies Must Rescind Cutoff Orders

Trump’s Feb. 27 directive told every federal agency to stop using Anthropic, including shops with no defense mission. Lin found that several agencies issued termination orders within hours and that those orders were sanctions imposed without delegated power, in violation of 5 U.S.C. §§ 558(b) and 706.

AGENCIES ORDERED TO UNWIND THE CUTOFF

  • Defense and diplomacy: Department of War and the State Department.
  • Money and property: Treasury, the Federal Housing Finance Agency, and the General Services Administration.
  • Personnel and nuclear: the Office of Personnel Management and the Nuclear Regulatory Commission.
  • Security and energy: Homeland Security and the Department of Energy.

She granted the government judgment on Health and Human Services, Commerce, Veterans Affairs, the Securities and Exchange Commission, and NASA, which she found had not taken the same final cutoff steps. The injunction still reaches officers, employees, and anyone acting in concert with the covered defendants. Federal contractors who were told to freeze commercial work with Anthropic, even on jobs with no military nexus, now have a court order saying that secondary boycott had no statute behind it.

Michael’s March declaration said it was “technically and operationally infeasible” to yank the models from all department systems at once, which is why the designation built in a 180-day offramp from the March 5 CIO memo. Lin has now vacated the designation that sat under that wind-down. Components that keep moving to other models can still do so as an ordinary vendor choice. They cannot do so under a sabotage label the court has thrown out.

The D.C. Circuit Case Under a Different Statute

The San Francisco judgment is not the whole docket. On March 3 Hegseth also determined, under 41 U.S.C. § 4713, that buying AI goods or services from Anthropic presents a supply chain risk. Anthropic petitioned the U.S. Court of Appeals for the D.C. Circuit in No. 26-1049. That case is narrower, aimed at covered procurement actions on department systems, and it was still pending in the materials reviewed for this article.

WHAT WE KNOW

  • The stay: On April 8 a three-judge panel denied Anthropic’s request to freeze the 4713 determination pending review, saying the equitable balance “cuts in favor of the government.”
  • The hearing: Oral argument was held May 19, 2026.
  • The reaffirmation: On June 3 Hegseth denied Anthropic’s request for reconsideration and restated his earlier conclusions.

WHAT IS UNCONFIRMED

  • A merits decision: No D.C. Circuit ruling on the 4713 petition appeared in the record after the May argument.
  • An appeal of Lin’s judgment: The government is expected to fight the California order; no filed notice of appeal was in the materials reviewed here.

In April the panel said Anthropic had raised “novel and difficult questions” with little precedent, and that the company would likely suffer some irreparable harm, which is why it expedited the case even as it left the label in place for covered systems. Justice Department lawyers told Lin in July that AI models are “so staggeringly enormous and opaque” that the department cannot vet them the way it vets hardware. Anthropic lawyer Michael Mongan told her the government’s actions “profoundly harm Anthropic” and “threaten more broadly to chill speech and debate on a very important issue.”

Lin filed the order at 5:56 p.m. PDT on Aug. 27 and kept jurisdiction to enforce it. The Department of War still does not have to run Claude.

Harry is the editor and publisher of MY WORLD NEWS 24, an independent title under his own ownership. Ten years of reporting and then editing taught him that a global readership is not served by assuming everyone lives in the same country. Stories here state currencies, units and time zones explicitly, name the country a law or a company belongs to, and explain local context rather than treating it as known. That care extends to sourcing: a claim is anchored to the filing, statement, transcript or dataset that made it, wherever in the world it was issued, and each figure is checked against that source before publication. The site reports news, business and technology, science and sports, entertainment, lifestyle and travel, and auto and gaming, all with the same standard of evidence. Mistakes are fixed under a corrections policy anyone can read, and the page carries a note saying what was changed. Harry reads every message sent by readers and replies from support@myworldnews24.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending