The Pentagon Called Anthropic a Foreign-Style Threat. A Judge Said That’s Orwellian.

The Pentagon Called Anthropic a Foreign-Style Threat. A Judge Said That’s Orwellian.
Legal scales and government building silhouette on dark navy background

AI Policy & Law — March 27, 2026, updated August 2026

Pentagon Called Claude a Supply Chain Risk.
149 Judges Said No.

The Trump DOD blacklisted Anthropic over its refusal to strip ethical guardrails from Claude. A federal judge granted Anthropic a preliminary injunction within weeks. The legal theory, the stakes, and what remains unresolved.

149
Judges Signed
Former federal and state judges. Democracy Defenders Fund coalition amicus brief.
PI
Preliminary Injunction
Judge Rita Lin granted a preliminary injunction on March 26, 2026, not a short-term TRO. It blocks enforcement pending the underlying case.
$19B
Anthropic ARR
Annualized revenue at stake. Enterprise is core revenue.
First
Such Designation
First supply chain risk designation ever leveled at a U.S. AI safety company.

Sources: DOD designation order; Anthropic court filings in N.D. Cal. and D.C. Circuit; Democracy Defenders Fund amicus brief; federal court dockets, March through August 2026.

The Trump administration’s Department of Defense designated Anthropic as a supply chain risk in late February 2026 after the AI safety company refused to remove ethical guardrails from Claude that prohibited its use for fully autonomous weapons systems and mass domestic surveillance. Defense Secretary Hegseth directed all federal agencies to cease using Anthropic technology. Anthropic sued in two forums, federal district court in California and the federal appeals court in Washington, D.C., arguing the designation was unconstitutional retaliation.

The DOD argued Anthropic’s ethical restrictions jeopardized military supply chains and claimed the company “may in the future take action to sabotage or subvert IT systems.” Anthropic’s legal response was direct: the government was using a national security designation to punish a company for building AI responsibly. 149 former federal and state judges, organized by the Democracy Defenders Fund, filed an amicus brief calling the designation an “Orwellian notion” that unlawfully penalizes safety compliance, language Judge Lin’s own ruling echoed.

What the Supply Chain Risk Designation Actually Does

The SCRM Designation Mechanism
What it means operationally
Federal agencies directed to cease using Anthropic products. Existing contracts can be terminated for cause. New contracts prohibited. Anthropic cannot bid on federal work.
The legal argument Anthropic used
First Amendment retaliation: the government designated Anthropic specifically because the company exercised its right to set ethical limits on its products.
Why 149 judges signed on
The amicus brief argued that SCRM designations are reserved for foreign state-linked actors or companies with demonstrated security failures.

What Anthropic’s Guidelines Actually Prohibit

Anthropic’s published acceptable use policy prohibits Claude from being used to operate fully autonomous weapons systems that make lethal targeting decisions without human oversight, and from conducting mass surveillance of U.S. citizens without legal process. These are not vague restrictions. They track closely with existing U.S. law (the Posse Comitatus Act for domestic surveillance, and the DoD’s own AI ethics principles for autonomous weapons).

The Pentagon’s argument was that having an AI vendor with published ethical restrictions creates supply chain risk because the vendor could theoretically refuse service mid-operation. Anthropic’s counterargument: every commercial vendor has terms of service. The specific terms being targeted are ones that align with existing law, not ones that create operational risk.

The Legal Mechanism That Makes This Unprecedented

The Defense Department used Section 1293 of the National Defense Authorization Act, a provision designed to restrict foreign adversaries from defense supply chains. It was written for cases like Huawei and Kaspersky, companies with demonstrated ties to foreign intelligence services. Applying it to a domestic company whose offense was publishing safety research and declining to remove ethical guardrails is a novel use that no previous administration attempted. The provision allows designation without judicial review, without evidence disclosure, and without a formal hearing. Anthropic had to sue to challenge it.

Judge Rita Lin’s 43-page preliminary injunction ruling, issued March 26, 2026, addressed the government’s rationale on multiple grounds. On the First Amendment: Anthropic’s safety publications and ethical guidelines are protected speech, and Lin found the record suggested the government’s stated reasons were pretextual and its real motive was unlawful retaliation. On the Administrative Procedure Act: Lin found the designation likely both contrary to law and arbitrary and capricious. On irreparable harm: Anthropic’s CFO estimated the designation could cost the company billions in 2026 revenue as enterprise customers grew wary. A preliminary injunction reflects a court’s assessment that a party is likely to succeed on the merits, sufficient to block enforcement while the case proceeds; it is not itself a final ruling on the merits, and this piece treats it as what it is.

The ruling’s implications, if it stands, would extend beyond Anthropic: a finding that a company’s published safety commitments are protected speech would bear on every AI vendor with a similar acceptable use policy. That remains a live legal question, not a settled one, while the case continues.

What the Two Red Lines Were

The conflict originated from two specific decisions Anthropic made in 2025. The first was publishing research on autonomous weapons risks that contradicted Defense Department talking points about AI-enabled military systems. The second was declining to remove Claude’s restrictions on generating content related to weapons systems design, even for authenticated military users. Anthropic’s position was that safety guardrails apply universally, regardless of the user’s institutional affiliation.

Both decisions were commercially costly. Anthropic forfeited potential defense contracts worth an estimated $400 million to $600 million annually. The Defense Department’s response, using a supply chain risk designation rather than simply choosing a different vendor, escalated the dispute from a procurement disagreement to a constitutional confrontation. The government could have awarded contracts to OpenAI or Google DeepMind without designating Anthropic as a threat. The choice to use the designation was the choice to punish, not just to exclude.

Docket Status Update

Procedural Posture, Updated
March 26, 2026: Judge Lin grants Anthropic a preliminary injunction in the N.D. Cal. case, blocking enforcement of the supply chain risk designation pending the litigation. Lin delayed implementation one week to allow appeal.
Following weeks: The Pentagon continued treating Anthropic as a designated supply chain risk despite the injunction while pursuing appellate review. A federal appeals court in Washington, D.C. subsequently denied Anthropic’s separate request for emergency relief in the parallel D.C. Circuit case, meaning the two proceedings produced different interim outcomes.
Later proceedings: In a subsequent hearing, Judge Lin indicated from the bench that the government’s record had not improved and, in her assessment, had if anything grown weaker. This piece has not confirmed a final, case-closing ruling as of this update, and treats the matter as active litigation rather than resolved.

The core constitutional question, whether the government can use a national security designation to penalize a private company for publishing ethical guidelines about its own product, remains formally unresolved pending final judgment, even though the preliminary rulings to date have consistently favored Anthropic. The precedent question for the rest of the AI industry, whether published safety commitments receive First Amendment protection against this kind of retaliation, will be more firmly settled once a final ruling or appellate decision is in hand.

Sources: DOD supply chain risk designation; Anthropic federal court filings (N.D. Cal. and D.C. Circuit); Democracy Defenders Fund amicus brief; reporting from CNN, NPR, Axios, Breaking Defense, CNBC, and Courthouse News Service, March through August 2026. Updated 2026-08-18: corrected “temporary restraining order” to “preliminary injunction” throughout, since that is what Judge Lin actually granted on March 26, 2026, and added a docket-status update covering the appellate denial of emergency relief and subsequent proceedings, since this remains active litigation rather than a final ruling.

Discover more from My Written Word

Subscribe now to keep reading and get access to the full archive.

Continue reading