Judge Rules Pentagon Unlawfully Retaliated Against Anthropic Over Surveillance Stance
A federal judge has ruled that the Pentagon unlawfully retaliated against Anthropic by labeling the AI company a national-security “supply chain risk” after Anthropic said it would not allow its technology to be used for mass surveillance of Americans.
In a 59-page order issued Aug. 27, U.S. District Judge Rita F. Lin of the Northern District of California granted summary judgment to Anthropic on its First Amendment retaliation claim, Fifth Amendment due-process claim and multiple claims under the Administrative Procedure Act, the law that governs how federal agencies act. The case is Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996; in court filings, the Defense Department is styled as the Department of War.
Lin found that the Pentagon’s designation of Anthropic as a “supply chain risk” was unlawful. In practice, that designation meant the government could not use Anthropic products and contractors working on government projects were told not to do business with the company for those efforts, sharply cutting off Anthropic from federal work.
The dispute began after Anthropic told the U.S. military that it would not permit its AI products to be used for mass surveillance of U.S. persons. The broader conflict also involved Anthropic’s opposition to the use of its technology in autonomous weapons systems. On Feb. 27, 2026, President Donald Trump posted a directive on Truth Social telling federal agencies to stop using Anthropic technology. Shortly afterward, Defense Secretary Pete Hegseth directed the department to designate Anthropic a supply-chain risk and instruct contractors to stop using it. The department implemented that decision in a March 3 determination letter. Anthropic sued on March 9, and Lin issued a preliminary injunction on March 26 blocking enforcement while the case moved forward. The government appealed that injunction on April 2.
At the center of the case was 10 U.S.C. § 3252, a law that allows the Defense Department to exclude vendors from certain procurements for national-security reasons, but only within substantive and procedural limits. Lin said those limits were not followed. She found the challenged actions violated the statute, were arbitrary and capricious under the APA and denied Anthropic the pre-deprivation process required by the Fifth Amendment before the government inflicted such a severe business restriction.
The judge also found the designation was driven by Anthropic’s speech, not by evidence of the kind of sabotage or security threat contemplated by the statute. The administrative record, she wrote, was thin and relied heavily on the company’s criticism of the government and its refusal to allow certain uses of its models. The order says the challenged actions “constituted unlawful retaliation in violation of the First Amendment” and that the government relied on Anthropic’s “increasingly hostile manner through the press.” Lin further wrote that the actions were intended to “make a public example out of Anthropic.”
The ruling underscored the concrete business stakes for a major AI vendor that had already become a significant defense and intelligence contractor. According to the opinion, U.S. defense and intelligence agencies had used Anthropic’s Claude models since 2024, and the Pentagon had used Claude Gov since March 2025. Anthropic had obtained Top Secret facility clearance, and in July 2025 it received a Defense Department agreement worth up to $200 million.
Lin said vacatur, declaratory relief and injunctive relief were appropriate, and said a separate order on relief would issue. She also denied the government’s request to administratively stay a permanent injunction.
Anthropic welcomed the decision. “We welcome the court’s ruling that this supply chain risk designation was unlawful,” a company spokesperson said in a statement reported by CBS News and other outlets.
Major news outlets have reported that the government is expected to appeal the merits ruling.