Anthropic PBC v. U.S. Department of War (Anthropic N.D. 2026)
After negotiations over deploying Claude on a military platform broke down over those two restrictions, Secretary of War Pete Hegseth (on X) and President Trump (on Truth Social) announced they were blacklisting Anthropic, and Trump directed all federal agencies to stop using Anthropic's products.
The Department of War formally designated Anthropic a "supply chain risk to national security" under 41 U.S.C. Section 3252, a label the government had previously reserved for foreign adversaries, and ordered its removal from Defense systems within 180 days.
Anthropic sued in the Northern District of California, bringing First Amendment retaliation, Fifth Amendment due-process, Administrative Procedure Act, and ultra vires claims, and moved to enjoin the designation and the federal-wide ban.
Judge Lin granted a preliminary injunction (ECF 134), finding the designation "likely both contrary to law and arbitrary and capricious" and describing the government's conduct as "classic First Amendment retaliation" for Anthropic's public criticism of the Department's position. She found Anthropic received no meaningful notice or pre-deprivation process, and stayed her order for seven days to allow an appeal.
The court heard cross-motions for summary judgment (ECF 166) and a related motion on the administrative record. A merits ruling is pending.
Overview
Overview
Anthropic sued after refusing to remove two usage restrictions on Claude: one prohibiting lethal autonomous drone operations with no human oversight, and one blocking mass surveillance of Americans. Hegseth designated Anthropic a 'Supply-Chain Risk to National Security', the first American company ever to receive this designation, and cancelled all government contracts. Anthropic filed five counts: APA violations, First Amendment retaliation, ultra vires executive action, Fifth Amendment due process, and additional APA sanction violations. Judge Rita Lin granted a preliminary injunction March 26, 2026, finding defendants 'failed to prove' the supply-chain risk designation and a 'high likelihood of success' on the First Amendment retaliation claim.
The Facts
Facts
Defense Secretary Hegseth directed Anthropic to remove two usage restrictions from Claude: one prohibiting use for lethal autonomous weapons without human oversight, and one prohibiting mass surveillance of Americans. Anthropic refused on safety grounds. Hegseth then formally designated Anthropic a Supply-Chain Risk to National Security, the first such designation of an American AI company, effectively barring it from government contracts.
The Issue
Issue
Whether the executive branch may designate a company a national security supply-chain risk in retaliation for refusing to remove ethical restrictions from its AI products, and whether such a designation constitutes unconstitutional compelled speech or viewpoint discrimination.
The Rules
The government may not punish a private party for its protected speech or viewpoint; adverse action taken because of such speech is unlawful retaliation.
Authorizes an agency to exclude a source from a procurement to address a supply chain risk to covered systems, subject to statutory findings and procedures.
A reviewing court shall set aside agency action found to be contrary to law or arbitrary and capricious.
Before a deprivation, the government generally must provide notice and an opportunity to be heard.
The Application
Analysis
Hegseth's demand that Anthropic remove safety restrictions on Claude constitutes government compulsion of private speech. An attempt to coerce removal of the company's own product policy. The government's response, designating Anthropic a supply-chain risk and canceling contracts, uses federal procurement authority as a retaliatory enforcement mechanism, violating the rule that government cannot leverage contracting power to punish constitutionally protected product decisions. Judge Lin found that Anthropic has a high likelihood of success because the timing and sequence (demand → refusal → designation) demonstrate retaliatory intent, and the designation appears motivated by viewpoint disapproval rather than independent national security analysis.
The Conclusion
Conclusion
PENDING. If the court enjoins the designation, Anthropic's safety restrictions on Claude stand and the government cannot use national security labels to coerce removal of AI guardrails. If upheld, the executive may use procurement designations to pressure AI developers over product safety policies.
Flag an issue
This tracker is maintained by BrynoDC and is free because readers fund it. Support