Federal Court Rules Pentagon's Blacklisting of Anthropic Was Unconstitutional

A federal judge has ruled that the Pentagon's decision to blacklist AI company Anthropic as a supply chain risk was unconstitutional, amounted to unlawful retaliation for protected speech, and failed to meet basic standards for reasoned government decision-making.
Judge Rita F. Lin of the U.S. District Court for the Northern District of California issued the ruling on August 28, 2026, resolving the central claims in Anthropic PBC v. U.S. Department of War et al., No. 3:2026cv01996. The case has tested where government purchasing power ends and constitutional free-speech protections begin since its filing in March (The Verge).
The dispute traces back to fall 2025, when the Department of Defense pushed for unrestricted access to Anthropic's Claude AI system for what it called "all lawful uses." Anthropic refused to remove two conditions from its military contracts: a ban on using its AI for mass surveillance of Americans, and a ban on use in lethal autonomous weapons (Washington Technology).
Defense Secretary Pete Hegseth responded by ordering the renegotiation of all AI labs' military contracts to allow "any lawful use" and by designating Anthropic a supply chain risk. A supply chain risk designation is a formal classification that effectively bars a company from federal contracting by labeling it a threat to the government's procurement system. After the blacklisting, the Pentagon signed deals with seven other AI labs, including Google, Microsoft, OpenAI, and SpaceX, to cover the role Anthropic had been filling (The Verge).
Anthropic filed suit in March, arguing that the Trump administration had retaliated against the company for setting boundaries on how its AI could be used by the military. Rather than asking the court to enforce the specific contract terms Anthropic had wanted, the company sought to strike down the policies that had blacklisted and excluded it from government contracting (The Verge; Justia).
In March, Judge Lin granted a temporary injunction blocking the Pentagon's blacklist, writing that the Department of War had designated Anthropic a supply chain risk because of its "hostile manner through the press" and that punishing the company for bringing public scrutiny was "classic illegal First Amendment retaliation" (The Verge). Her final ruling confirms that preliminary assessment.
The government contested the retaliation theory throughout the litigation. In a March 17 court filing, the Trump administration denied that the blacklisting was unlawful retaliation, arguing the designation was justified and lawful (Reuters).
The case also took a notable turn through a separate appeals court. On April 8, 2026, the U.S. Court of Appeals for the D.C. Circuit declined to block the Pentagon's blacklisting, denying Anthropic's request for a stay and setting oral argument for May 19, 2026. The D.C. Circuit directed the parties to brief three specific questions. Anthropic had asked that court to review the Pentagon's designation, arguing it was unconstitutional retaliation (Reuters; CNBC). The Northern District of California case proceeded on a separate track, focused on striking down the blacklist policies themselves rather than the procurement contract dispute before the D.C. Circuit (Jones Walker; Justia).
Judge Lin's final ruling found that Hegseth's designation was arbitrary and capricious, a term from the Administrative Procedure Act meaning the government failed to provide a rational basis for its decision. Combined with the First Amendment retaliation finding, the court's holdings address both the constitutional dimension (punishing a company for protected speech) and the procedural dimension (the designation lacking a reasoned basis) (The Verge).
The broader context here is a contracting environment in which the Department of Defense has moved aggressively to secure unrestricted AI access across multiple providers. The Pentagon's deals with seven replacement labs after blacklisting Anthropic show that the government had viable alternative suppliers, a fact that cuts against any argument that Anthropic's exclusion was driven by procurement necessity rather than punishment.
What this ruling enables is a legal precedent affirming that AI labs retain First Amendment protections when they publicly state and defend usage limits on their models, even in the context of national security procurement. For companies that have built commercial trust on stated safety commitments, the decision provides a constitutional backstop against agencies that might otherwise use their purchasing power to override those commitments. The case also tests the limits of the supply chain risk designation, a mechanism used across federal technology procurement, establishing that it cannot be deployed to punish vendor speech without surviving both First Amendment and administrative-law review.
Whether the government appeals Judge Lin's ruling, and how the D.C. Circuit's parallel proceedings interact with this district court judgment, will shape the practical fallout. The tension between government demand for unrestricted AI deployment and vendor-imposed usage constraints is not going to resolve with a single ruling. But Judge Lin's decision establishes that the constitutional calculus does not favor the government simply because national security procurement is involved.


