A federal judge has ordered the Pentagon to undo its blacklisting of Anthropic, ruling that the government punished the AI company for criticizing it — and that national security cannot be invoked as cover for that kind of retaliation.
U.S. District Judge Rita Lin of the Northern District of California found that the Defense Department violated both the First Amendment and the due process clause of the Fifth Amendment when it designated Anthropic a supply chain risk. In a 59-page opinion, she ordered the government to rescind every directive issued against the company.
"The empty invocation of national security is not a blank check to punish and retaliate against government critics," Lin wrote.
What the fight was actually about
The designation didn't come out of nowhere. It grew out of a 200 million dollar contract dispute over how the Pentagon could run Anthropic's Claude models on classified systems.
Anthropic argued that officials turned on the company after it refused to lift two restrictions: one barring the use of Claude for mass domestic surveillance of Americans, another barring fully autonomous weapons. Those are usage limits Anthropic applies commercially, and it declined to carve out an exception for the Defense Department.
Being labeled a supply chain risk is not a slap on the wrist. The designation effectively signals across the federal government that a vendor is untrustworthy, and it tends to travel — agencies that never had a dispute with the company start treating it as radioactive.
Why the judge sided with Anthropic
Lin's reasoning turned on what the government actually put in the record. She found that the stated rationale rested principally on Anthropic's public criticism of the administration's positions on AI, not on any concrete security finding about the company's systems or supply chain.
That framing matters. Courts give the executive branch wide latitude on genuine national security judgments. What they don't do is accept the label as self-justifying. Lin's opinion draws that line hard: if the record shows the real driver was speech the government didn't like, the security framing collapses.
The due process finding is separate and arguably just as damaging. Lin held that officials stripped Anthropic of liberty interests without adequate notice or a meaningful chance to respond — meaning the company was designated, and the consequences followed, before it had any real opportunity to contest the basis.
Why it matters beyond one company
Every major AI lab now sells to the federal government while also publishing usage policies that restrict what its models can be used for. Those two things are in tension, and until now nobody knew what happened when a lab said no to a specific government request.
This ruling gives a partial answer: a refusal grounded in a published policy is not, by itself, grounds for punishment — and public criticism of an administration's AI positions is protected speech, not evidence of unreliability.
The practical effect is that labs have somewhat more room to hold their lines in contract negotiations. A vendor that fears being blacklisted for saying no is not really negotiating. A vendor with a court order behind it is.
There's a counterweight, though. Nothing in the ruling requires the Pentagon to buy anything from Anthropic. The government retains enormous discretion over who wins contracts, and it can simply choose other vendors without ever explaining why. What it can't do, per this opinion, is issue formal designations that damage a company across the entire federal market as payback.
What happens next
The immediate step is rescission — the directives come down. Whether the administration appeals is the open question, and the answer will say a lot about how much it wants this fight on the record.
For now, the ruling stands as the clearest statement yet that an AI company's safety restrictions and its public statements are not, on their own, a national security problem the government can declare into existence.
Image: Michael Saffle, via Pexels





