US Court Strikes Down the Pentagon's Anthropic Label: Judge Rules National Security Is Not a Blank Check

Judge Rita Lin ruled the Pentagon's Anthropic supply-chain label unlawful retaliation for criticism — we read the full 59-page order: the counts won and lost.

US Court Strikes Down the Pentagon's Anthropic Label: Judge Rules National Security Is Not a Blank Check
Table of contents

US Court Strikes Down the Pentagon's Anthropic Label: Judge Rules "National Security Is Not a Blank Check"

"The empty invocation of national security is not a blank check to punish and retaliate against government critics." With those words, federal judge Rita F. Lin closed out one of the strangest tech-policy feuds of 2026: on August 27, she ruled that the Trump administration's designation of Anthropic — the company behind Claude — as a national-security supply-chain risk was unlawful. We read the full 59-page court order, and this analysis explains what actually happened over the past six months, exactly what the court decided, why it was not a total victory for the company, and why the precedent travels far beyond one AI lab. Last updated: August 30, 2026.

Page 1 of Judge Rita Lin's order in Anthropic PBC v. U.S. Department of War


Source: Official court order — Case 3:26-cv-01996-RFL

The feud, from February to August

To understand the ruling, start with what the court documents say happened in late winter.

  • February 27, 2026: President Trump issued a presidential directive designating Anthropic a supply-chain risk to national security.
  • March 3, 2026: Secretary of War Pete Hegseth issued an implementing directive that, per the order's own recitation, declared: "America's warfighters will never be held hostage by the ideological whims of Big Tech. This decision is final." A transition window of no more than six months was set.
  • March 4, 2026: Anthropic received an official letter invoking 10 U.S.C. § 3252, giving the company thirty days to appeal.

The practical effect was close to a total ban: every federal agency — not just defense — was ordered to permanently stop using Anthropic products, and contractors doing any business with the US military were barred from working with Anthropic at all, even on projects unrelated to the military.

The root of the fight, as the case record recounts: Anthropic drew hard lines around the use of its models in fully autonomous weapons and mass surveillance of citizens. The Pentagon's position was that a buyer who pays for a model should not have the vendor controlling how the military uses it. The designation followed — and the court ultimately treated it as punishment.

Anthropic sued the Department in March in two courts, California and Washington, D.C. A preliminary injunction froze the ban, and — as the order itself notes — the government complied with it for more than five months without demonstrating any harm. Then came August 27 and the summary judgment ruling in the California case.

Anthropic, the AI lab behind Claude


Source: Anthropic's official newsroom

What the order actually says

The language of the ruling is unusually blunt for a national-security case:

  • "The record is slim." The government's entire justification before the court was a four-page memorandum written after two of the three challenged actions had already been taken.
  • The government retreated from its core theory. The original risk claim rested on Anthropic having "backdoor access" to its technology after deployment. By the time of the ruling, defendants conceded the point that decided it: Anthropic "undisputedly lacks any such access," and its technology is no riskier than any other "black box" AI model.
  • What remained was "trust." The government's surviving argument was that Anthropic's "increasingly hostile manner through the press" and its criticism of the department's AI views meant it could not be trusted. The court's answer: neither the Constitution nor the invoked statute permits sweeping penalties grounded principally in criticism of the administration.
  • The motive, examined. The court found the government's contemporaneous words and deeds confirmed "a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government" — noting, among other contradictions, that the department kept pursuing a contract with the company even while calling it a threat.

Count by count: what Anthropic won and lost

Headlines said "sweeping win." The order's conclusion is more precise. Here is the final disposition, verbatim in substance:

Count Claim Outcome
II First Amendment Anthropic won (all defendants except non-participating ones)
IV Due Process Clause Anthropic won
I APA challenge to the Hegseth Directive & Supply Chain Designation Anthropic won against Hegseth and the department
V APA § 558 challenge Won against 9 agencies; lost against HHS, Commerce, VA, SEC, NASA
III Ultra vires Lost — the government won this count

Three practical footnotes from the order's closing pages: an order addressing relief "will issue separately" — so remedies are not yet defined; the government's request to stay the permanent injunction for seven days was denied; and the D.C. case remains ongoing independently.

An Anthropic spokesperson said in a statement: "We welcome the court's ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology."

Why the seven-day stay was denied

A detail practitioners will not skip: the government asked the court to pause the permanent injunction for seven days — presumably to prepare an appeal — and the request was denied. The practical meaning is that the designation cannot be enforced against Anthropic while the case moves forward, and agencies that complied with the injunction for five months have no new basis to act on it now. Combined with the separately pending relief order, the government's remaining lever is the Ninth Circuit, where an emergency stay is theoretically available but faces a higher bar than the district court it just lost before.

The administrative-record lesson: how a court audits a security decision

The most exportable part of the ruling is its method. When an executive branch invokes national security, courts ask for the administrative record — the documents that preceded and justified the decision. Here the court found a four-page memo that post-dated most of the actions, while the actual March 3 "determination" documents were not even disclosed to Anthropic until after it sued.

The March 4 letter, invoking § 3252, recited the standard formulas: the designation was "necessary to protect national security" and "less intrusive measures are not reasonably available." The court did not accept the formulas on faith. It compared words with deeds: a department branding the company a threat while simultaneously pursuing a contract with it, collaborating with its new model on cybersecurity, and contemplating the Defense Production Act — a statute for entities essential to national security, not dangerous to it. That internal contradiction is what made the designation "arbitrary and capricious."

Why this matters beyond one company

First, tech-versus-state precedent. A federal court has now held, in plain terms, that an executive branch may not use security and procurement powers to punish a company for public criticism or for refusing specific military uses of its products. Every AI company negotiating with governments — in Washington, Brussels, Riyadh, or Delhi — now has a citable US precedent that vendor red lines are not legally punishable offenses.

Second, a standard for "national security" claims. The order sets a practical bar: invoking national security requires a real record that survives review. A post-hoc four-page memo does not. That is a message with reach well beyond Washington.

Third, the ethics-of-deployment question. The core dispute was Anthropic's refusal to allow its models in fully autonomous weapons and mass surveillance. The court did not decide whether such uses are acceptable — it decided that punishing a company for its public ethical stance violates the Constitution. The distinction gives AI vendors more legal room to set deployment limits with large government customers.

What the court did NOT decide

Precision matters here. The ruling settled the "how," not the "what." It did not order any agency to use Claude. It did not rule on the legality of any military AI use case. It did not say vendors may control government use of purchased technology as a matter of right. And every constitutional win carries the same recurring exception — "except the Non-Participating Defendants" — leaving some agencies' positions undecided in this round.

So treat this as an opened door, not a closed file: the separate relief order, a possible appeal to the Ninth Circuit, and the parallel D.C. case could all reshape the details even if the core principle stands.

What this means for you

  • If you procure AI for an organization: "political risk" is now a vendor-risk category with a courtroom illustration. Smart contracts increasingly include provisions for vendor withdrawal or policy shocks — and open-weights models remain the natural hedge, as we examined in our coverage of Anthropic's own open-weights position.
  • If you follow tech policy: this order is a rare, fully documented (59 pages) example of a court applying ordinary administrative-law scrutiny to AI-era security decisions.
  • If you use Claude day to day: nothing changes for the service today; the long-run effect is on the company's stability and its access to the huge government contracts that anchor its revenue and legitimacy.
  • If you watch the global balance: an American court affirming an AI company's right to refuse weapons uses may strengthen other vendors' hands in similar negotiations worldwide — see also our coverage of the Nvidia-Anthropic GB300 deal on Azure for how sovereignty concerns already shape AI infrastructure deals.
  • If you are a policymaker outside the United States: the order doubles as a checklist. Security designations that lack a contemporaneous record, that rely on post-hoc rationales, or that visibly conflict with a government's own commercial behavior toward the same company are exactly the patterns a reviewing court will strike down. Governments drafting AI procurement rules can either learn that lesson now or relearn it in litigation later.
  • If you are a journalist or researcher covering AI: the docket is public, the key documents are freely downloadable, and the order's factual recitations are cited paragraph by paragraph — a rare case where the primary record is easier to read than most of the commentary about it.

Honest limitations

  • The ruling can be appealed, and the Ninth Circuit could rewrite the ending.
  • The D.C. suit continues; this is one of two tracks.
  • Relief — what the government must actually undo, pay, or reinstate — comes in a separate future order.
  • The Department of War had not published a full public response at the time of writing; reporters including TechCrunch requested comment.
  • The ultra vires loss means some administrative-law avenues stayed closed despite the constitutional win.

FAQ

What did the court decide about the Pentagon and Anthropic?
Federal judge Rita Lin ruled on August 27, 2026 that the government's designation of Anthropic as a supply-chain risk was unlawful, violating the First Amendment and due process, because it amounted to retaliation for the company's public criticism.

Why was Anthropic labeled a national security risk?
After Anthropic refused to allow its Claude models in fully autonomous weapons and mass surveillance, the administration designated the company a supply-chain risk and ordered agencies to stop using it — a move the court found was punishment for criticism, not a genuine security determination.

Did Anthropic win everything?
No. It won the First Amendment, due process, and most administrative claims, but lost the ultra vires count and parts of one administrative claim covering five agencies; a separate relief order is still to come.

Can the US government appeal?
Yes, appeal to the Ninth Circuit is available, and a parallel Anthropic suit in Washington, D.C. remains ongoing.

Who is Judge Rita Lin and which court issued the ruling?
Rita F. Lin is a US district judge in the Northern District of California; the case is numbered 3:26-cv-01996-RFL, and the ruling is document 250 in the docket.

Sources

Anthropic's legal week is crowded: read our coverage of the new Sony and Warner lawsuit against the company and our earlier analysis of the cybersecurity evaluation incidents.