How the government’s case for blacklisting Anthropic fell apart


Full story

When the Department of Defense designated Anthropic a national security risk in early 2026, it justified the move in an internal memo warning the company could “attempt to disable” or “alter the behavior of the model” in real time while deployed in the middle of a military operation, according to court documents. Anthropic didn’t learn of that claim until after it sued the department, and by the time the case reached a judge, the government’s own justification had changed. 

Anthropic’s lawsuit argued the blacklisting was retaliation. Not for refusing the Pentagon’s contract terms, but for publicly criticizing those terms after refusing to drop two specific red lines barring its AI from lethal autonomous weapons and mass surveillance of Americans.

QR code for SAN app download

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.™

Point phone camera here

By the time the case reached summary judgment, the government’s theory shifted. Rather than arguing Anthropic could intervene in real time, it argued Anthropic could build a hidden flaw into a future model, which may not surface until the middle of ongoing warfighting operations.”

Because of Anthropic’s refusal, the company stood to lose a two-year, up to $200 million contract with the Pentagon’s Chief Digital and Artificial Intelligence Office.

The company eventually won a preliminary injunction in late March. On Thursday, U.S. District Judge Rita Lin of the Northern District of California issued a final summary judgment ruling in Anthropic’s favor, nearly six months after the Pentagon’s designation. 

“The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote in her order. 

The Pentagon’s shrinking case

The ruling revealed an internal Pentagon memo from March 2, drafted one business day after Defense Secretary Pete Hegseth ordered the Defense Department to begin designating Anthropic a security risk. The memo said AI models are “acutely vulnerable to manipulation,” and that Anthropic could “attempt to disable” or “alter the behavior of the model … in the middle of ongoing warfighting operations.”

Hegseth formally issued the designation the following day, based on the memo’s findings. 

The Pentagon also raised a second concern about “drift,” meaning Claude could “degrade as new data is introduced.” It warned that the Defense Department would be forced to operate a “black box” controlled by a “hostile party, which could contain hidden biases or backdoors.”

The memo became the backbone for the department’s formal designation, court documents stated. They also noted that Anthropic was unaware of these concerns until after it sued.

Under Secretary of Defense Emil Michael, who wrote the original internal memo, repeated his claim in a sworn declaration for Anthropic’s lawsuit on March 17. He warned of potential risks if the company interfered with its models during an operation, “whether by shutting off access to the model or altering its functionality.” But a week later Michael changed his claim.

“Under Secretary Michael’s next declaration, dated March 24, 2026, no longer makes any such claims, and instead discusses only the risk inherent in model updates,” Lin wrote.

But the mid-operation language didn’t stay buried. Three months later, in its June 24 summary judgment brief, the government invoked nearly the same wording. This time the Pentagon argued that a flaw introduced during an update might not surface until “the middle of ongoing warfighting operations.”

Anthropic pushed back on the underlying premise. The company said it can’t access or shut down a model once it’s deployed on Defense Department systems. That’s because updates aren’t installed like conventional software patches, court documents state. New models need to be trained from scratch to replace older ones, and each new version is independently tested and approved by the Defense Department before it’s used. The government never directly disputed the testing process. 

In her ruling, Lin wrote that the Pentagon presented no evidence Anthropic could actually disrupt or alter a model once it was deployed, which she called a concession “that this risk was entirely unfounded.” She added that the government didn’t dispute that it controls when new models are deployed, undercutting its own argument that rapid deployment timelines left no room for thorough testing. 

Lin ultimately characterized the government’s case as reflecting “shifting justifications” that shared little basis in the underlying record. 

Free speech violations 

Throughout the litigation, Anthropic argued the government retaliated against the company for its CEO’s past remarks. In a January essay, CEO Dario Amodei wrote that people needed to “draw a hard line against AI abuses within democracies.” He also discussed the need for “bright red lines” and “guardrails” to prevent what he called “AI-enabled totalitarianism.”

A day before the blacklist, he wrote that while the Defense Department, not private companies, makes military decisions, “in a narrow set of cases … AI can undermine, rather than defend, democratic values.” He said because of that Anthropic couldn’t give the department the access it wanted. 

The next day, President Donald Trump posted on Truth Social, saying the U.S. would never “ALLOW A RADICAL LEFT, WOKE COMPANY TO DICTATE HOW OUR GREAT MILITARY FIGHTS AND WINS WARS!” 

Hegseth later posted his own statement, saying Anthropic “attempted to strong-arm the United States military into submission,” showing the company put “Silicon Valley ideology above American lives.” 

In her ruling, Lin found Hegseth’s use of “strong-arm” was “best read as characterizing Anthropic as applying public pressure” on the military, not describing an actual security threat. She said the government was contradictory: it publicly branded Anthropic a national security risk, yet the Defense undersecretary personally emailed Amodei the day after the designation was finalized, telling him a new deal was “very close.”

“While the record plausibly supports that Defendants would have quietly made a deal with Anthropic after meting out its public punishment,” Lin wrote, “this fact only supports the retaliatory nature of the Challenged Actions.”

It’s at least the third time this year a federal judge has found Hegseth crossed a constitutional line while going after a critic, after ruling in favor of Sen. Mark Kelly, D-Ariz., in February, and The New York Times in March

What comes next?

Lin’s ruling settles whether the blacklist was legal, not whether the Pentagon and Anthropic will ever resolve the dispute that started it. The company’s two red lines are exactly where they were in February. In a related case, the federal appeals court in Washington declined to step in and stop the policy for now, saying Anthropic hadn’t proven it needed emergency protection. 

In a statement, an Anthropic spokesperson told TechCrunch that it remained “focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.”

Round out your reading

Tags: , , , , , , , ,

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Why this story matters

A federal court has permanently blocked the government from enforcing a national security blacklist against Anthropic, the maker of the Claude AI chatbot, ruling the designation was unconstitutional retaliation for the company's public criticism of Pentagon AI policy.

First Amendment limits on procurement

The court found the government cannot use national security designations to punish a company for publicly criticizing administration policy, a limit that applies to any contractor doing business with the federal government.

Government’s justification kept shifting

Court filings show the Pentagon’s stated reason for blacklisting Anthropic changed at least twice over five months, a pattern the judge cited as central evidence the designation was pretextual.

AI tools remain available to agencies

Federal agencies regained access to Anthropic's Claude months ago under a temporary court order. Thursday's ruling makes that permanent, though it still doesn't require any agency to use it.

Get the big picture

Synthesized coverage insights across 286 media outlets

Behind the numbers

The dispute centered on a $200 million Pentagon contract. Anthropic said the blacklisting threatened billions in lost revenue and drew fearful inquiries from more than 100 customers. The Pentagon's autonomous weapons budget is reportedly set to rise from $225 million to $55 billion by 2027.

History lesson

The supply chain risk statute was designed to protect U.S. military systems from foreign adversaries. No U.S. company had ever been publicly designated under it before Anthropic. The case has no direct legal precedent, making Judge Lin's ruling novel in U.S. administrative and constitutional law.

Policy impact

The ruling permanently blocks enforcement of the supply chain designation and orders the government to rescind related directives. However, the Pentagon is not required to use Anthropic's products and may still transition to other AI vendors through lawful means. A separate D.C. case remains pending.

Straight Arrow
Fear No Fact.

Don't just take our word for it.


Center-rated reporting

According to media bias experts at AllSides

AllSides Center-rated reporting May 2026

Transparent and credible

Awarded a perfect reliability rating from NewsGuard

100/100

Welcome back to trustworthy journalism.

Find out more

Bias comparison

  • Media outlets on the left frame the ruling as a “major legal victory” against Pentagon “blacklisting,” emphasizing “illegal and baseless” retaliation for Anthropic’s safety limits and criticism of military AI.
  • Media outlets in the center stress procedural limits, military contracting discretion, and possible appeal.
  • Media outlets on the right acknowledge the defeat but foregrounds “serious national-security concerns,” Anthropic’s “arrogant” refusal to permit autonomous weapons or mass surveillance, and the ruling as a setback for Trump and Hegseth.

Media landscape

Click on bars to see headlines

286 total sources

Key points from the Left

  • A U.S. judge blocked the Pentagon's blacklist of Anthropic, ruling the designation as a supply-chain risk was illegal and baseless.
  • Anthropic sued the Defense Department after it labeled the company a national security risk due to its restriction on military use of the AI model Claude.
  • The Pentagon argued that Anthropic's refusal to allow military use of Claude could risk disabling military systems.
  • Judge Rita Lin stated that national security claims cannot be used to punish government critics, supporting Anthropic's constitutional rights.

Report an issue with this summary

Key points from the Center

  • On Thursday, U.S. District Judge Rita Lin permanently blocked the Pentagon's designation of Anthropic as a "supply-chain risk," ruling the administration's actions were "illegal and baseless" and constituted unconstitutional retaliation.
  • Defense Secretary Pete Hegseth designated Anthropic a supply-chain risk earlier this year after the company refused to allow its Claude chatbot to be used for mass surveillance or autonomous weapons systems.
  • Rejecting the Pentagon's justification, Lin wrote the "empty invocation of national security is not a blank check to punish and retaliate against government critics," vacating the February 27 decision to make Anthropic ineligible for federal contracts.
  • An Anthropic spokesperson said the company is "pleased the court has ruled that this supply chain risk designation was unlawful," while the Justice Department is expected to appeal the ruling.
  • Despite this victory, Anthropic maintains a separate, pending lawsuit in Washington, D.C., challenging a different Pentagon designation that could exclude the firm from civilian government contracts.

Report an issue with this summary

Key points from the Right

  • A U.S. federal judge blocked the Pentagon's ban on Anthropic, ruling that the supply chain risk designation was unlawful and retaliatory, violating the First and Fifth Amendments.
  • Judge Rita Lin found the ban was based on after-the-fact justifications and anger over Anthropic's criticism of government AI use.
  • Anthropic refused to allow certain military uses of its AI technology, which led to the Department of Defense labeling it a national security risk.
  • The ruling allows the Pentagon to pursue other AI providers, but related legal battles over supply-chain designations with the U.S. Government continue.

Report an issue with this summary

Other (sources without bias rating):

Powered by Ground News™