TL;DR: U.S. District Judge Rita Lin ruled August 28 that Pete Hegseth's designation of Anthropic as a national security supply chain risk was unlawful retaliation in violation of the First Amendment, denied due process under the Fifth Amendment, and arbitrary and capricious under the APA. The government must rescind all directives. For AI vendors: you can refuse to support autonomous weapons and mass surveillance without losing your legal right to do government business. For contractors currently using Anthropic: the designation is void and you can resume.
On August 28, 2026, U.S. District Judge Rita F. Lin of the Northern District of California struck down the Trump administration's designation of Anthropic as a national security supply chain risk. The 59-page ruling found the government's actions were "unlawful retaliation" against Anthropic for its constitutionally protected policy positions and violated both the First and Fifth Amendments.
The decision is one of the most significant AI governance rulings in U.S. history. It establishes that federal agencies cannot weaponize national security labels to punish AI companies for maintaining safety guardrails on how their models can be used -- even when the customer demanding those guardrails be removed is the Department of Defense.
The docket in Anthropic PBC v. U.S. Department of War, No. 72379655 (N.D. Cal.), is available on CourtListener.
What triggered the dispute
The conflict began in late 2025, when the Pentagon and Anthropic were negotiating a contract to use Claude models in classified military settings. Anthropic maintained two positions it said were non-negotiable:
- Claude would not be used to power fully autonomous weapons -- weapons that could identify and fire on targets without human oversight over each decision.
- Claude would not be used for mass surveillance of American citizens.
The Pentagon insisted it needed unrestricted discretion over how it used models it purchased. Anthropic declined to waive those limits. Defense Secretary Pete Hegseth responded in February 2026 by invoking 10 U.S.C. 3252 and the Federal Acquisition Supply Chain Security Act to formally designate Anthropic a supply chain risk to national security. President Trump subsequently issued a presidential directive extending the blacklist beyond defense agencies to all federal entities.
The practical effect was immediate. Anthropic was cut off from federal contracts. Agencies already using Claude-powered tools were ordered to stop. A company that had been negotiating expanded government partnerships found itself labeled a threat to the country it was trying to serve.
What the court found
Judge Lin's August 28 ruling rested on three legal grounds.
First Amendment retaliation. Lin found that the government's actions were motivated by a desire to punish Anthropic for its public criticism of the administration's position on AI safety, not by a genuine security assessment. She wrote that the government's "words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government." That is textbook First Amendment retaliation: government action taken because of protected speech, rather than because of a legitimate regulatory concern.
Fifth Amendment due process. The designation was imposed without the procedural safeguards that accompany decisions of this magnitude. Anthropic was not given adequate notice of the specific security concerns or a meaningful opportunity to respond before the label took effect. Lin found this violated the due process clause.
APA arbitrary and capricious. Lin also found the designation failed administrative law standards because the government's stated rationale did not hold together. She pointed to three pieces of evidence that exposed the pretextual nature of the national security claim. Hegseth had proposed applying the Defense Production Act to Anthropic -- a law used to compel production of things essential to national security. You cannot simultaneously claim a company is essential to national security and a threat to it. The DOD continued pursuing a contract with Anthropic even after the designation. And the government had partnered with Anthropic's newer Mythos model for cybersecurity work.
On that last point, Lin noted that Anthropic "undisputedly lacks" any backdoor access to its models once they are handed over. The claim that Anthropic posed a security threat through its technology was, on the record before the court, baseless.
"Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless," Lin wrote. "The empty invocation of national security is not a blank check to punish and retaliate against government critics."
What the ruling does not do
Judge Lin was careful to state what her ruling does not require. The government retains full discretion to choose which AI vendors it contracts with. Nothing in the ruling obligates any agency to use Anthropic. What the ruling prohibits is using the supply chain risk designation mechanism as a tool of retaliation against companies that refuse to strip out their safety policies.
A separate Anthropic complaint filed in Washington D.C. federal court remains ongoing. That case covers different aspects of the government's conduct. The August 28 ruling covers the N.D. Cal. claims.
What it means for AI vendors
This ruling establishes legal ground that AI vendors dealing with the government did not clearly have before. Several principles now have judicial backing.
Safety red lines are protected speech. Anthropic's positions on autonomous weapons and mass surveillance were public policy statements. The court treated them as protected expression. An AI company that publicly articulates what its models will not do, and refuses to waive those limits in contract negotiations, is on better constitutional footing than a company that makes quiet side agreements without documenting its positions.
Written positions before negotiations matter. The record in this case benefited from Anthropic having documented and publicized its safety policies before the Pentagon contract talks collapsed. Companies that articulate their acceptable use policies in writing, before entering government contract discussions, create the kind of record that supports a retaliation claim if a government agency punishes them for it.
You can refuse a contract without losing your right to other contracts. The ruling confirms that an AI company can walk away from a specific use case -- here, autonomous weapons and mass surveillance -- without the government being able to use that refusal as grounds to cut the company off from all federal business. The retaliatory designation violated the First Amendment precisely because it was disproportionate to any legitimate security concern.
Backdoor access claims must be documented. Lin specifically noted that Anthropic could show it had no backdoor access to deployed models. AI vendors should be able to produce technical documentation demonstrating the same. If a government agency makes a security claim based on alleged backdoor access, the vendor needs records to rebut it.
What government contractors should do now
Companies that were using Anthropic-powered tools before the designation and suspended use in response to the blacklist directives should review their situation. The government has been ordered to rescind all directives against Anthropic. That order covers the presidential directive and the Hegseth directive to federal agencies outside defense.
Contractors that paused contracts or removed Anthropic integrations in response to the designation should get legal guidance on whether they can resume. The ruling voids the designation, but agencies may take time to formally update their guidance, and individual agency compliance officers may not immediately update their posture. Get written confirmation from contracting officers before assuming full resumption is cleared.
For contractors who were never using Anthropic but are evaluating AI vendors: the ruling does not change your procurement process. It does mean you can evaluate Anthropic without the supply chain designation flagging it as a compliance risk.
5-point compliance checklist for AI vendors working with government
1. Publish your acceptable-use policy before negotiations. A public, dated acceptable-use policy that states what your models will not do (autonomous lethal targeting, mass surveillance, specific prohibited uses) creates the predicate record for a First Amendment retaliation claim if a government agency retaliates against those positions. Internal policies that are never disclosed do not establish the same public-speech basis.
2. Document every contract negotiation in writing. When a government counterpart asks you to waive a safety provision, get the request in writing. Your refusal should also be in writing. The paper trail showing that you refused a specific use case -- not that you were generally uncooperative -- is the evidence that distinguishes legitimate security concerns from retaliation.
3. Get outside counsel to review your government acceptable-use policy. Standard consumer acceptable-use policies are not designed for government contracting. The specific language used to describe prohibited uses, the scope of what you retain the right to enforce after handoff, and how you document model access limitations all have legal implications that your procurement team may not anticipate.
4. Know 10 U.S.C. 3252 and FASCSA. These are the statutes the Pentagon used. FASCSA gives agencies broad authority to designate vendors as supply chain risks and exclude them from contracts. The Anthropic ruling limits how that authority can be used -- it cannot be applied retaliatorily -- but the statutes themselves remain on the books. Know what triggers a designation and what procedural protections you are entitled to before one is imposed.
5. Audit your post-handoff access posture. Lin specifically noted that Anthropic could demonstrate it had no backdoor access to models after they were deployed. If your business model involves accessing or monitoring deployed models -- for fine-tuning, telemetry, safety monitoring, or any other reason -- document what that access is, what it is not, and how it is technically controlled. A government agency claiming you have covert access to deployed government systems is a serious allegation; your technical records should be able to refute it quickly.
What comes next
The government can appeal. The D.C. case remains open. And the underlying policy questions -- who controls AI safety guardrails in government deployments, who decides what autonomous weapons AI can touch, and whether the executive branch can unilaterally designate private AI companies as national security threats -- are not resolved by a single district court ruling.
What is resolved, at least in the N.D. Cal., is that the retaliatory use of the supply chain risk label against a company for its policy positions is unconstitutional. That is a meaningful limit on an authority that had been exercised without judicial review.
For the AI industry more broadly, this case suggests that companies with clearly articulated, publicly documented safety policies are better positioned to defend those policies in court than companies that negotiate safety limits quietly. The ruling rewards transparency about what AI models will and will not do -- which happens to align with what regulators, enterprise customers, and the public are increasingly asking for anyway.
Related Reading
- Pentagon Grok AI and Iran strikes: autonomous weapons governance for small teams
- Pentagon AI human oversight and the Gillibrand Act 2026
- Anthropic recursive self-improvement June 2026: governance policy checklist
- Trump June 2026 AI executive order: what compliance teams and federal contractors must do
- FTC AI enforcement actions 2026: all cases analyzed
- Dario Amodei AI regulation proposals: binding rules and what your team should watch
- Claude Code source leak: AI governance lessons for small teams
- AI governance for law firms: privilege and compliance 2026
