Six Months After Trump Banned Anthropic, a Court Rules: Unconstitutional Retaliation

A federal judge ruled that the Pentagon's designation of Anthropic as a "national security supply chain risk" was unconstitutional retaliation aimed at punishing the company's public safety stance, not a genuine security assessment. The case lays bare the unresolved question of who defines safety boundaries when the government is one of AI's largest buyers.

At 5:01 p.m. on February 27, 2026, an ultimatum from the Pentagon expired. Anthropic did not back down. Trump then posted on Truth Social demanding that federal agencies across the country "immediately stop" using any technology from the AI company. Defense Secretary Pete Hegseth subsequently announced that Anthropic would be designated a "national security supply chain risk"—a label typically reserved for foreign adversary entities. The entire ban, from dispute to final blow, took less than 24 hours.

Six months later, on August 28, 2026, U.S. District Judge Rita Lin wrote in her ruling that Hegseth's designation constituted "unlawful retaliation in violation of the First Amendment," that his decision was "arbitrary and capricious," and that it violated Fifth Amendment due process. The ruling flipped the nature of the entire affair: from a business dispute in which an AI company challenged defense requirements into an unconstitutional act of government using administrative power to punish a dissenting voice.

The Spark: A Single Phrase, "Any Lawful Use"

The starting point of this confrontation was an AI strategy memorandum issued by Hegseth in January 2026. The memorandum required all Defense Department AI procurement contracts to uniformly include authorization language for "any lawful use" within 180 days. The phrasing seemed innocuous, but it came into direct conflict with two red lines in Anthropic's existing contract: first, Claude must not be used for mass domestic surveillance of U.S. citizens; second, Claude must not participate in target locking or firing decisions for autonomous weapons without human authorization.

Anthropic's contract was signed in July 2025, with a total value of up to $200 million, for the purpose of "prototyping frontier AI capabilities for U.S. national security." According to CBS News, Claude had already been used by the Defense Department for intelligence analysis, operational planning, and cyber operations. The question was not whether Claude could be used by the military, but who gets to draw the boundaries of that use.

The Pentagon's position was that the military must be able to deploy AI within "any lawful framework," and that a contractor has no right to preset limits. Anthropic CEO Dario Amodei wrote in a statement one day before the deadline that he could not in good conscience agree to the demand, because in certain specific scenarios AI systems would undermine rather than defend democratic values.

Here lies a key cognitive divide. The Pentagon's logic: the law already prohibits illegal acts, so "any lawful use" adds no risk. Anthropic's logic: when AI's judgment speed outpaces the speed of legal review, only technical constraints can provide substantive safeguards beyond legal text. Neither side was lying, but who gets to decide the answer to this judgment call—that is the real power struggle.

OpenAI's Mirror Experiment

The most ironic scene in this affair occurred hours after the ban was announced. That evening, OpenAI CEO Sam Altman announced that OpenAI had signed an agreement with the Pentagon to supply AI technology to the military's classified networks. Altman also stated that the agreement explicitly included two principles—"no mass domestic surveillance" and "human accountability for the use of force, including autonomous weapons systems"—precisely the lines Anthropic was banned for upholding.

The outcome should have been a relief: it turned out the Pentagon could accept these safety provisions. But Altman later admitted to the media that the deal "looked opportunistic and sloppy" and that he "shouldn't have rushed it." OpenAI subsequently revised the contract language to further clarify surveillance limits. According to TechCrunch, Altman's exact words were that they were "really trying to cool things down, but the result clearly backfired."

OpenAI obtained a contract containing the same safety provisions, while Anthropic was placed on a national security blacklist for proposing those same provisions. The juxtaposition itself is testimony, and Judge Rita Lin invoked similar logic in her ruling: the Pentagon's ban was motivated by a desire to "make an example of Anthropic," not by a genuine security assessment.

The Destructive Power of the Blacklist

The damage of the "supply chain risk" designation extended beyond federal contracts themselves. According to Anthropic's complaint filed in California federal court on March 9, government contracts were being canceled one after another, and "hundreds of millions of dollars in near-term revenue" was at risk—because any private company doing business with the U.S. military was also required to cut commercial ties with Anthropic.

The design logic of this chain reaction was identical to the secondary sanctions tools used against foreign entities. Treating an American company headquartered in San Francisco and founded in 2021 as equivalent to a foreign adversary, and deploying tools of the same magnitude against it, is itself an anomalous signal. Representative Lofgren, ranking member of the House Science Committee, later issued a statement saying the Trump administration's attack on Anthropic left her "shocked" and arguing that the move undermined U.S. leadership in global AI safety.

The Course of the Legal Battle

On March 9, 2026, Anthropic filed two federal lawsuits simultaneously: one against the Pentagon's "supply chain risk" designation, and one against the president's directive ordering federal agencies to stop using Claude. On August 28, U.S. District Judge Rita Lin ruled on the first lawsuit, siding with Anthropic. According to CNBC and NPR, the judge found that the Pentagon's designation violated the First Amendment because its motive was to punish Anthropic for publicly stating its safety position, rather than being based on a genuine supply chain risk assessment.

The second lawsuit—against the presidential executive order itself—is still ongoing as of now. The Pentagon's six-month phased elimination plan for Claude is also being implemented, and other agencies, including the Treasury Department, have announced they will stop using Anthropic products. Whether the court ruling is enough to reverse this situation still depends on the subsequent battle at the implementation level.

This Is Not Just One Company's Problem

From an industrial structure perspective, this confrontation exposed a structural tension the AI industry has long avoided: when the government becomes one of the largest buyers of AI infrastructure, who ultimately defines "safety principles"?

Anthropic's business model depends on the brand credibility of "responsible AI." If it abandons its safety boundaries under government pressure, that brand foundation collapses; if it holds the line, it faces bans and the loss of the government market. This dilemma is not unique to Anthropic—any AI company with defense-sector business will sooner or later face the same multiple-choice question.

Even more worth interrogating is the logical flaw in the phrase "any lawful use" itself. In a reality where AI-assisted decision-making is far faster than legal review, the boundary of "lawful" is dynamic in real time, not static text at the moment a contract is signed. The technical restrictions Anthropic sought to write into the contract were essentially doing, on behalf of the law, something the law currently cannot do: embedding behavioral constraints at the model level, rather than relying on after-the-fact legal accountability.

That logic is not part of the U.S. government's procurement framework. The Pentagon's procurement logic: we buy a tool, and the tool's user bears legal responsibility. Anthropic's safety logic: the tool itself should embed non-bypassable behavioral boundaries, because tracing user responsibility in the AI context is often after-the-fact and insufficient for prevention. These are two fundamentally different philosophies of risk allocation, and they are difficult to reconcile outside a courtroom.

Independent Judgment

The court ruling defined the nature of this affair: the Pentagon's ban was political punishment, not a security judgment. But that conclusion does not mean Anthropic's stance came without cost. The government market it lost, the contracts already canceled, and the wait-and-see attitude among corporate customers that resulted are all real business losses that a legal victory cannot automatically offset.

More critically, the affair has a cautionary effect on those who follow: in the current political climate, an AI company's safety stance can itself become a commercial risk factor, not merely a brand bonus. This forces every AI company with a position in the government market to reassess one question: when policy positions conflict with commercial survival, where exactly is the boundary of "responsible AI"?

On a longer timeline, OpenAI ultimately secured a contract containing the same provisions, and the court ruled the ban unconstitutional. This shows that the line Anthropic held was not non-negotiable; it was rejected in the wrong way. But before that outcome arrived, it had already paid months of costs. This is not a story either side deserves applause for, but an expensive lesson about how to get through the gap period in AI governance frameworks.

Sources: - [Trump orders federal agencies to stop using Anthropic's AI technology - CBS News](https://www.cbsnews.com/news/trump-anthropic-ai-order-federal-agencies/) - [Trump orders US agencies to stop using Anthropic technology - Federal News Network](https://federalnewsnetwork.com/artificial-intelligence/2026/02/anthropic-refuses-to-bend-to-pentagon-on-ai-safeguards-as-dispute-nears-deadline/) - [Anthropic Refuses Pentagon Demand to Remove AI Security and Safety Guardrails - ASIS Online](https://www.asisonline.org/security-management-magazine/latest-news/today-in-security/2026/february/Anthropic-Refusal/) - [OpenAI strikes deal with Pentagon hours after Trump admin bans Anthropic - CNN Business](https://www.cnn.com/2026/02/27/tech/openai-pentagon-deal-ai-systems) - [OpenAI's Sam Altman announces Pentagon deal with 'technical safeguards' - TechCrunch](https://techcrunch.com/2026/02/28/openais-sam-altman-announces-pentagon-deal-with-technical-safeguards/) - [Anthropic gets its first court win over the Pentagon's supply-chain risk label - TechCrunch](https://techcrunch.com/2026/08/28/anthropic-gets-its-first-court-win-over-the-pentagons-supply-chain-risk-label/) - [Judge blocks Pentagon blacklist of Anthropic as supply chain risk - CNBC](https://www.cnbc.com/2026/08/28/judge-blocks-pentagon-blacklist--anthropic-.html) - [Anthropic sues Pentagon over rare "supply chain risk" label - Axios](https://axios.com/2026/03/09/anthropic-sues-pentagon-supply-chain-risk-label) - [Judge says the Pentagon can't designate AI company Anthropic a 'supply chain risk' - NPR](https://www.npr.org/2026/08/28/nx-s1-5947951/judge-says-the-pentagon-cant-designate-ai-company-anthropic-a-supply-chain-risk)