Judge Rules Pentagon's Anthropic Blacklist Was Illegal Retaliation
A federal judge found the Pentagon's supply-chain-risk designation of Anthropic violated the First Amendment and was retaliation for its weapons-use limits.
A federal judge has ruled that the Pentagon broke the law when it blacklisted Anthropic earlier this year, and the reasoning in that ruling matters more than the outcome. U.S. District Judge Rita Lin, in a 59-page order issued August 28, found that the Department of Defense’s decision to designate Anthropic a supply-chain risk was not a security judgment at all. It was retaliation, and it violated the First Amendment.
This is the sequel to a story we covered back in July, when unsealed court emails showed the Pentagon calling Anthropic’s autonomous-weapons red line “not workable” the day after the blacklist went into effect. That earlier post ended on an open question: a preliminary injunction had paused enforcement, but the underlying case was still live. Judge Lin’s ruling is the answer to that open question, and it’s a stronger one than the injunction alone suggested.
What the ruling actually says
Strip the legal framing down to its core claim: a “supply-chain risk” designation is supposed to mean a company’s products pose a security or reliability threat to the government that uses them. Judge Lin found that wasn’t what happened here. Instead, her order describes the blacklist as stemming from a “desire to make a public example out of Anthropic” for publicly criticizing the administration’s AI policy and for holding firm on two limits it places on military use of Claude: no fully autonomous weapons systems and no domestic mass surveillance.
That distinction is the whole case. A government agency is allowed to decide it doesn’t want to buy a vendor’s product. What it isn’t allowed to do, under the First Amendment, is punish a vendor for speech or policy positions by dressing the punishment up as a security determination. Judge Lin’s order draws that line explicitly, calling the Pentagon’s stated justification “illegal and baseless” rather than merely mistaken or overbroad.
Why the timeline is the evidence
The July court filings already made this a hard case for the Pentagon to win. The emails between Dario Amodei and then-Under Secretary of Defense Emil Michael showed the two sides describing themselves as “very close” on contract terms in the same week the blacklist was imposed, with Michael’s own message treating the autonomy red line as a negotiating obstacle rather than a security flaw. A negotiator who thinks he’s close to a deal with a security risk generally doesn’t send an email like that. Judge Lin’s order leans on exactly this kind of internal contradiction: the paper trail from the Pentagon’s own side undercut the security rationale before the case ever got to trial.
That’s worth sitting with, because it’s a rarer outcome than the framing “AI company sues government and wins” suggests. Most disputes over discretionary government procurement decisions are hard to win precisely because agencies get wide latitude to decide who they buy from and why. This case worked against that latitude only because the agency’s own contemporaneous communications documented the retaliatory motive in writing. Take away the “not workable” email, and this is a much harder case for Anthropic to have brought at all.
What doesn’t change
It’s worth being precise about what this ruling does not settle. The underlying policy dispute — whether “no fully autonomous weapons” and “no domestic mass surveillance” are workable limits for a company that wants defense revenue, versus the government’s preference for coverage of “all lawful uses” — is untouched. Anthropic still holds those two lines. The Pentagon, or a future administration, is still free to decide it doesn’t want to buy from a vendor that holds them, as long as it says so honestly instead of laundering the decision through a supply-chain-risk label. The government is expected to appeal, and an appellate court could narrow or overturn the First Amendment finding even if the factual record stays the same.
What the ruling does establish, at least for now, is a real cost to disguising a policy disagreement as a security finding: courts will look at the internal paper trail, and internal paper trails are not written with litigation in mind. Any agency considering a similar move against a different vendor now has a 59-page precedent describing what that costs when the emails don’t match the official story.
Why this is the story to watch, not the headline version
The easy version of this story is “AI safety wins one against the government.” That framing survives about as long as it takes to reread the actual dispute. Nobody in this case argued that AI shouldn’t be part of defense procurement, and nobody argued Anthropic shouldn’t sell to the military at all — it already does. What got litigated, and what a judge just ruled on, is much narrower: whether a government customer can retaliate against a vendor for refusing a specific contract term by using a designation that’s supposed to be reserved for actual security concerns. That’s a procedural and constitutional question, not a referendum on whether AI safety commitments are good policy.
It’s also not the last round. The underlying contract dispute over the two limits is still unresolved, an appeal is expected, and every other frontier lab chasing defense revenue is watching to see whether “no autonomous weapons” survives as a workable industry position or becomes something regulators route around. That’s the actual open question here, and it’s still open.