US Federal Court Vacates the Pentagon's "Supply Chain Risk" Designation of Anthropic
On August 27, 2026, a federal judge in the Northern District of California ruled the supply chain risk designation of Anthropic unlawful, finding First Amendment retaliation, a lack of pre-deprivation process, and action exceeding 10 U.S.C. § 3252. The designation was vacated and the measures permanently enjoined.
On August 27, 2026, Judge Rita F. Lin of the U.S. District Court for the Northern District of California issued a 59-page opinion holding that the Pentagon’s designation of Anthropic as a “supply chain risk” was unlawful1. A separate order signed the same day vacated the designation and permanently enjoined the measures from being carried out2.
The dispute began over a question of how far an AI company can push its own usage policy with a government customer. The Department of War asked Anthropic to remove all usage restrictions on Claude, and Anthropic declined to drop two of them: lethal autonomous warfare and mass surveillance of Americans1. That disagreement escalated into social media directives from the President and the Secretary, and then into exclusion from federal procurement.
The defendant in the case is named the “U.S. Department of War,” and the opinion notes in a footnote that it adopted the parties’ phrasing1.
What Was Vacated
The court considered three measures, which the opinion collectively calls the “Challenged Actions”1.
The first was a directive President Trump posted on Truth Social at 3:47 p.m. on February 27, 2026, ordering every federal agency to immediately cease all use of Anthropic’s technology, with a six-month phase-out period for agencies like the Department of War that were using the company’s products1. The second came a little over an hour later, when Secretary Hegseth posted on X directing the Department of War to designate Anthropic a supply chain risk and stating that, effective immediately, no contractor, supplier, or partner doing business with the U.S. military could conduct any commercial activity with Anthropic1. The third was the formal designation itself, carried out on March 3 and 4. Anthropic received a letter on March 4 signed by Secretary Hegseth and dated the day before, citing 10 U.S.C. § 3252. The letter’s effect was immediate and permanent, with thirty days to appeal1.
According to the opinion, the two posts together created “an immediate, permanent, federal-government-wide bar on using any Anthropic technology (except during a six-month transition period),” and also barred private companies doing business with the military from any business with Anthropic, even work unrelated to the military or national security1.
The order of final relief vacated, set aside, and remanded the designation as exceeding the authority granted by 10 U.S.C. § 3252 and as taken without the procedure required by law2. The portion of the Hegseth post ordering the commercial boycott was also vacated and set aside, as were the steps taken to implement the presidential directive by the Department of War, State, Treasury, DHS, Energy, OPM, NRC, FHFA, and GSA2. Defendants were ordered to rescind all guidance, directives, communications, and instructions issued to effectuate the Challenged Actions2.
Not a Complete Win
Anthropic did not prevail on everything. Its ultra vires separation-of-powers claim (Count III), arguing that the presidential directive exceeded lawful authority, was decided for the government as to all defendants2. On the Administrative Procedure Act claim under 5 U.S.C. § 558, the government prevailed as to HHS, Commerce, VA, the SEC, and NASA2. The government also prevailed on all claims as to the group the opinion calls the “Non-Participating Defendants,” which includes the National Endowment for the Arts and the Social Security Administration2.
The opinion itself states that the Department of War “is undisputedly free to select the AI vendor of its choice,” and that the problem lay in the broad measures imposed on Anthropic1. The relief order likewise specifies that it “does not require the Department of War to use Anthropic’s products or services and does not prevent the Department of War from transitioning to other artificial intelligence providers”2.
Only “Trust” Was Left Standing
The most striking part of the opinion’s structure is how little of the government’s rationale survived.
The court described the administrative record as slim, writing that “a four-page memorandum, which post dates two of the three challenged actions, provides the entirety of the government’s rationale”1. That memorandum is dated March 2, 2026, and was authored by Under Secretary of War for Research and Engineering Emil Michael — the opinion refers to it as the “Michael Memo”1.
The memo stated that AI models “are acutely vulnerable to manipulation,” that Anthropic could “attempt to disable” or “alter the behavior of the model … in the middle of ongoing warfighting operations,” that model “drift” could degrade Claude as new data was introduced, and that the Department of War “would be forced to operate a black box controlled by a hostile party, which could contain hidden biases or backdoors”1. These were the government’s assertions, not findings by the court.
The court found that the government subsequently backed away from the core of that assessment, writing that “Anthropic undisputedly lacks any such access and that, as Defendants concede, Anthropic’s technology is itself no riskier to the national security than any other ‘black box’ artificial intelligence model”1.
What remained was a single factor: trust. The opinion recounts that defendants argued they “cannot trust Anthropic to ensure the integrity of its models” because of the company’s “increasingly hostile manner through the press” and its criticism of the department’s views on AI use, and concluded that “[n]either the Constitution nor the federal statute invoked by Defendants allows them to impose sweeping penalties based principally on Anthropic’s critique of the Administration’s views”1.
The opinion also points to conduct by the government that it found inconsistent with the stated rationale. A few days before the measures began, Secretary Hegseth had proposed applying the Defense Production Act to Anthropic, which would treat the company as essential to national security rather than a threat to it. Immediately afterward, the department continued to pursue a contract with Anthropic, saying “we are very close here.” And as of the opinion, the government was discussing collaboration with Anthropic on its new model, Mythos, in an array of sensitive contexts1. None of that, the court wrote, “is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security”1.
The holdings were that the measures constituted unlawful retaliation in violation of the First Amendment and that Anthropic was denied the pre-deprivation process required under the Fifth Amendment1. The court further found that the supply chain risk designation violated the statutory scheme of 10 U.S.C. § 3252 and was arbitrary and capricious1. The opinion closes: “The empty invocation of national security is not a blank check to punish and retaliate against government critics”1.
A Usage Policy Is a Contractual Promise
The ruling records a number of facts that are useful material for both sides of an AI procurement contract.
As undisputed facts, the opinion notes that U.S. intelligence and defense agencies have been using Claude since 2024, and that the Department of War has used “Claude Gov,” dedicated models for national security users, through Anthropic partner platforms since March 20251. Anthropic received Top Secret facility security clearance from the department’s Defense Counterintelligence and Security Agency after an 18-month vetting process, and in June 2025 received FedRAMP High and DoD Impact Level 4 and 5 authorization from GSA and the department1. In July 2025, Anthropic was awarded a two-year, up to $200 million agreement by the department’s Chief Digital and Artificial Intelligence Office1. And, the opinion states, the administrative record reflects that “before March 2, 2026, DoW did not identify any potential supply chain risk posed by Anthropic”1.
The turn came in the fall of 2025. While discussing a new deployment of Claude on the department’s “GenAI.mil” platform, the department told Anthropic it must remove all usage restrictions and agree to a provision allowing the department, its contractors, and its subcontractors to use Claude “for all lawful uses”1. Anthropic agreed to eliminate most restrictions but kept two1. In a January 15, 2026 email, CEO Dario Amodei wrote that the proposals were made “with tremendous respect and deference for the D[oW]‘s expertise in this domain,” and arose “from our understanding of how these particular models behave—their capabilities, edge cases, and failure modes—not second-guessing the D[oW]‘s expertise in conducting its operations”1.
The practically important point is how the opinion characterizes the nature of that policy: it “is a purely contractual limit; Anthropic is incapable of enforcing it technologically, and does not have direct visibility into how DoW uses its model”1. An AI vendor’s usage policy, in other words, is enforced as contract language rather than as a technical guardrail in the model. For anyone designing agent controls that lean on a vendor’s policy, that distinction becomes a contract review question.
Ripple Effects, and What Comes Next
The effects are also part of the undisputed record. Before the preliminary injunction issued, defense contractors performing government work using Claude-integrated APIs began reassessing — and in many cases seeking to terminate — their reliance on Anthropic1. The company “received inquiries regarding the [Challenged Actions] from over one hundred enterprise customers expressing deep fear, confusion, and doubt about Anthropic and the repercussions of associating with [the] company”1. In a declaration, Anthropic said the designation, if left standing, could reduce its defense-related client revenue by “50–100 percent” and its “2026 revenue by multiple billions of dollars” — a party’s projection, not a finding by the court1.
Trade associations for government contractors wrote in an amicus brief quoted in the opinion that the harms “affect the entire technology industry, not just Anthropic,” and that member companies faced “a compliance crisis with no clear guidance on applicable requirements”1. Thirty-eight employees from major companies in the AI field also filed a brief arguing that the measures threaten to “chill open deliberation” and “professional debate”1.
On the timeline: Anthropic filed suit on March 9, 2026, and a preliminary injunction issued on March 261. The measures were therefore not halted for the first time by this ruling; they had been frozen under that injunction for more than five months. The court also denied the defendants’ request for a seven-day administrative stay of the permanent injunction, noting that they “have been complying with the Court’s Preliminary Injunction Order for more than five months and had ample opportunity to identify any harms caused by it”1. After the ruling, Anthropic was reported to have said it remains “focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology,” while the Pentagon was reported to have offered no immediate comment3.
The case sits alongside other developments in the relationship between the government and AI companies. The Trump administration signed an executive order on AI and security on June 2, 2026, establishing a voluntary pre-release review framework for frontier models and signaling cooperation rather than regulation. Anthropic itself published its position on open-weights models in July and announced its first Chief Global Affairs Officer on August 4. On August 27, an open letter on collective cyber defense signed by many companies, Anthropic among them, was published. Cooperation on shared problems and open conflict are running in parallel.
The ruling does not stop the Department of War from choosing a different AI vendor. What was at issue was not the choice of supplier but whether criticism could be answered by shutting one company out of an entire industry. The court retained jurisdiction to enforce its order2, and the docket records the civil case as terminated as of August 274.
Sources
- Anthropic PBC v. U.S. Department of War, Order on Cross Motions for Summary Judgment (Dkt. 250) - U.S. District Court, Northern District of California, Case No. 3:26-cv-01996-RFL (August 27, 2026)
- Anthropic PBC v. U.S. Department of War, Order of Final Relief (Dkt. 251) - Order of final relief from the same court (August 27, 2026)
- US judge blocks Pentagon blacklisting of AI firm Anthropic - Al Jazeera (August 28, 2026)
- Anthropic PBC v. U.S. Department of War docket - CourtListener
Was this article helpful?
Thank you!
Received. Thank you!