Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

A Federal Judge Has Told the Pentagon That National Security Is Not a Blank Cheque

Judge Rita Lin ruled that the Defense Department's designation of Anthropic as a supply chain risk was unlawful retaliation under the First Amendment, and arbitrary and capricious besides. The label had told every federal agency to stop buying.

Outspoken Digest Technology Desk

Sunday, August 30, 2026/3 min read

The Phillip Burton Federal Building and United States Courthouse in San Francisco, which houses the United States District Court for the Northern District of California
Photo: Marincyclist via Wikimedia Commons (CC BY-SA 4.0)

On Friday a federal judge in California ruled that the Defense Department broke the law when it branded Anthropic a supply chain risk. Judge Rita Lin found the designation was unlawful retaliation in violation of the First Amendment, that it was arbitrary and capricious, and that the company had been denied the due process the Fifth Amendment requires.

The sentence in the ruling that will be quoted for years is shorter than any of that. The empty invocation of national security, Lin wrote, is not a blank cheque to punish and retaliate against government critics.

What the designation actually did

It is worth being precise about the instrument, because the label sounds technical and its effect was not.

A supply chain risk designation had historically been reserved for foreign adversaries. Applied to Anthropic, it instructed federal agencies, including agencies with nothing to do with defence, to stop working with the company. One American firm was placed in a category built for hostile states, and the practical result was exclusion from the federal market.

The dispute that produced it was not commercial. Anthropic declined to accept terms that would have set aside its own limits on two uses of its models: fully autonomous lethal weapons, and domestic mass surveillance. The company said no to a customer. The customer was the United States government.

The contradiction the judge found

Governments lose cases like this on their own paperwork, and this one did.

Lin pointed to two positions the administration was holding at the same time. It proposed applying the Defense Production Act to Anthropic, an act which presumes a company is essential to national security. And it continued pursuing contracts with the same company, including collaboration on its Mythos model for cybersecurity work.

Both of those are the behaviour of a buyer that wants a product. Neither is the behaviour of a buyer that has identified a threat in its supply chain. Once those facts sat next to the designation, the stated reason stopped being available, and what remained was the timing: the label arrived after the refusal.

Why this is bigger than one company

Because the question underneath it is who sets the limits on what a model may be used for.

The commercial answer has always been that a vendor writes a usage policy and a customer either accepts it or buys elsewhere. That arrangement works until the customer is a government with the power to make refusal expensive by means other than the contract. What the designation tested was whether a supplier's stated red lines survive contact with that power, and until Friday the answer looked like no.

We wrote about the terms Anthropic set out for itself in a piece on the safety first lab, and about what happens when a state reaches for a different lever entirely in the export controls episode. The pattern across both is that AI policy is no longer being written in policy documents. It is being written in procurement, in export licences and now in court.

What the ruling does not settle

Quite a lot, and readers should hold the win loosely.

This was one of two complaints filed in March. The California case is decided; the one in Washington is still running. A district court ruling can be appealed, and an administration that considered the designation worth making once has every incentive to test it on appeal. Anthropic itself lost an earlier bid at the appeals court in April to block the blacklisting while the case ran, so the litigation record here is not one directional.

There is also the matter of what replaces the label. A finding that a designation was retaliatory removes that designation. It does not prevent a government from declining to buy something, which it is entitled to do for almost any reason or none. The remedy for retaliation is narrower than it looks.

The part worth watching

Whether other suppliers now hold their lines.

Every AI company with a usage policy has been watching this, because every one of them will eventually be asked for an exception by a customer large enough to make the request feel like an instruction. The value of Friday's ruling to them is not the outcome. It is that the cost of retaliating became visible and quantifiable, which is the only thing that ever changes a negotiation.

Anthropic's own response was studiedly flat: it welcomed the ruling and said it remained focused on working productively with the government. That is the correct thing to say by a company that has just won, intends to keep selling, and knows the second case is still open.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.