Technology

Federal Judge Rules Pentagon's Anthropic Blacklist Unconstitutional

Martin HollowayPublished 4w ago5 min readBased on 11 sources
Reading level
Federal Judge Rules Pentagon's Anthropic Blacklist Unconstitutional
Photo by KATRIN BOLOVTSOVA on Pexels

Judge Rita F. Lin of the U.S. District Court for the Northern District of California has ruled that the Pentagon's blacklisting of Anthropic as a supply chain risk was unconstitutional, unlawful retaliation in violation of the First Amendment, and arbitrary and capricious under administrative law standards. The ruling, issued on August 28, 2026, resolves the core claims in Anthropic PBC v. U.S. Department of War et al., No. 3:2026cv01996, a case that has tracked the boundary between government procurement power and constitutional speech protections since its filing in March (The Verge).

The dispute began in fall 2025, when the Department of Defense pushed for unrestricted access to Claude for "all lawful uses." Anthropic refused to remove two restrictions in its military contracts: a prohibition on using its AI for mass surveillance of Americans, and a prohibition on use in lethal autonomous weapons (Washington Technology).

Defense Secretary Pete Hegseth responded by directing the renegotiation of all AI labs' military contracts to permit "any lawful use" and by designating Anthropic a supply chain risk, effectively barring the company from federal contracting. After the blacklisting, the Pentagon signed deals with seven other AI labs, including Google, Microsoft, OpenAI, and SpaceX, to replace Anthropic's role in the Department of Defense (The Verge).

Anthropic filed suit in March, accusing the Trump administration of unlawful retaliation for setting red lines on military use of its AI. The company sought injunctive relief against the policies that blacklisted it and barred it from government contracting, rather than enforcement of the underlying contract terms (The Verge; Justia).

In March, Judge Lin granted a temporary injunction blocking the Pentagon's blacklist, writing that the Department of War designated Anthropic a supply chain risk because of its "hostile manner through the press" and that punishing the company for bringing public scrutiny was "classic illegal First Amendment retaliation" (The Verge). The full ruling now confirms that preliminary assessment on the merits.

The government contested the retaliation theory throughout the litigation. In a March 17 court filing, the Trump administration denied that the blacklisting was unlawful retaliation, arguing it was justified and lawful (Reuters).

The case also produced a notable appellate detour. On April 8, 2026, the U.S. Court of Appeals for the D.C. Circuit declined to block the Pentagon's national security blacklisting, denying Anthropic's motion for a stay. The D.C. Circuit set oral argument for May 19, 2026, and directed the parties to brief three specific questions. Anthropic had asked the D.C. Circuit to review the Pentagon's determination, arguing it was a form of unconstitutional retaliation (Reuters; CNBC). The Northern District of California case proceeded on a separate track, with Anthropic's challenge focused on injunctive relief against the blacklist policies themselves rather than the procurement contract dispute before the D.C. Circuit (Jones Walker; Justia).

Judge Lin's final ruling found that Hegseth's designation was arbitrary and capricious, adding an Administrative Procedure Act violation to the First Amendment retaliation finding. The court's three holdings, taken together, address both the constitutional dimension (retaliation for protected speech) and the procedural dimension (the designation lacking a rational basis under APA standards) (The Verge).

The broader context here is a contracting environment in which the Department of Defense has moved aggressively to secure unrestricted AI access across multiple providers. The Pentagon's deals with seven replacement labs post-blacklisting demonstrate that the government had viable alternative suppliers, a fact that cuts against any argument that Anthropic's exclusion was driven by procurement necessity rather than punitive intent. Whether the government appeals Judge Lin's ruling, and how the D.C. Circuit's parallel proceedings interact with this district court judgment, will shape the practical fallout.

What this enables is a legal precedent affirming that AI labs retain First Amendment protections when they publicly articulate and defend usage restrictions on their models, even in the context of national security procurement. For companies that have built commercial trust on stated safety commitments, the ruling provides a constitutional backstop against agencies that might otherwise use procurement leverage to override those commitments. The case also tests the limits of the "supply chain risk" designation, a mechanism that has been applied across federal technology procurement, as a tool that cannot be deployed to punish vendor speech without surviving both First Amendment and APA scrutiny.

The tension between government demand for unrestricted AI deployment and vendor-imposed usage constraints is not going to resolve with a single ruling. But Judge Lin's decision establishes that the constitutional calculus does not favor the government simply because national security procurement is involved.