AI Policy Wiki
Dashboard

Anthropic v. United States (Pentagon ban challenge)

high confidence · updated 2026-07-31

Anthropic's federal challenge to Trump directive / Hegseth supply-chain-risk designation; Judge Lin preliminary injunction March 26, 2026.

Anthropic v. United States is a federal lawsuit in which Anthropic PBC challenges a February 27, 2026 Trump directive ordering federal agencies to stop using Anthropic's products and an accompanying supply-chain-risk designation of the company by Secretary of Defense Pete Hegseth. On March 26, 2026, Judge Rita Lin granted a preliminary injunction blocking enforcement of both measures, finding the government's actions likely retaliatory against Anthropic's publicly stated use restrictions. A parallel petition for review at the U.S. Court of Appeals for the D.C. Circuit, challenging the supply-chain-risk designation directly, produced a contrary outcome when the panel denied Anthropic's emergency motion to stay on April 8, 2026.

Case information

FieldDetail
Plaintiff[[companies/anthropicAnthropic PBC]]
DefendantsUnited States of America; Department of Defense; Secretary of Defense Pete Hegseth (official capacity)
CourtU.S. District Court (exact district not confirmed in source material — likely N.D. Cal. given Judge Lin and Anthropic's San Francisco HQ); parallel petition for review at the U.S. Court of Appeals for the D.C. Circuit
Trial judgeJudge Rita Lin
FiledMarch 2026 (date approximate; after the February 27 ultimatum and Trump directive)
StatusActive; preliminary injunction granted March 26, 2026

Background

The dispute grew out of disagreement between Anthropic and the Department of Defense over the terms governing military use of Claude. The U.S. military allegedly used Claude in the January 2026 Venezuela/Maduro operation; Anthropic's public position is that it did not discuss that specific use with the Department of War. Anthropic's use policy forbids autonomous weapons and mass surveillance of Americans. The Pentagon pushed to renegotiate Claude Gov contracts for "all lawful use," which Anthropic refused.

According to The Verge (May 26, 2026), the dispute originated in a January 12, 2026 memo from Hegseth demanding renegotiation of existing AI contracts on "any lawful use" terms and arguing that "the risks of not moving fast enough outweigh the risks of imperfect alignment." That memo underlies the February 27 ultimatum and supply-chain-risk designation that followed (Source: theverge.com).

On February 27, 2026, two administrative actions triggered the litigation:

  • A Trump directive ordering federal agencies to cease using Anthropic's products.
  • Hegseth's supply-chain-risk designation of Anthropic, an administrative classification typically applied to foreign-adversary or compromised vendors.

Claims

Anthropic challenges both the directive and the supply-chain-risk designation. The claims advanced, as reflected in Judge Lin's ruling, center on retaliation against Anthropic's public policy positions — its refusal of autonomous-lethal-weapons and mass-surveillance uses — under an implicit First Amendment and administrative-law theory. The parallel D.C. Circuit petition for review challenges the Pentagon's supply-chain-risk designation directly.

Procedural history

Preliminary injunction (March 26, 2026)

Judge Lin issued a 43-page ruling granting a preliminary injunction. It blocks the government from enforcing the ban and the supply-chain-risk designation. The ruling finds that the government's actions were retaliatory against Anthropic's public policy positions (the refusal of autonomous-lethal-weapons and mass-surveillance uses) and holds that the retaliation likely violated the law, on an implicit First Amendment / administrative-law theory.

D.C. Circuit denial of stay (April 8, 2026)

A separate petition for review at the D.C. Circuit, challenging the Pentagon's supply-chain-risk designation directly, produced a contrary outcome 13 days after Judge Lin's preliminary injunction. The D.C. Circuit denied Anthropic's emergency motion to stay the Pentagon designation while the petition proceeds, concluding that "the equitable balance here cuts in favor of the government. On one side is a relatively contained risk of financial harm to a single private company. On the other side is judicial management of how, and through whom, the Department of War secures vital AI technology during an active military conflict." The panel found that "substantial expedition is warranted" in moving the case forward (Source: cnbc.com; thehill.com; axios.com).

D.C. Circuit oral argument (May 19, 2026)

A three-judge D.C. Circuit panel heard nearly two hours of oral argument on Anthropic's challenge to its Pentagon blacklisting. Judge Karen Henderson characterized the Defense Department's "supply chain risk" designation a "spectacular overreach" unsupported by the record, the most skeptical signal from the bench to that point in the supply-chain-risk track (Source: cnbc.com).

Current status

The split rulings leave Anthropic excluded from DOD contracts while the D.C. Circuit petition is pending, while Judge Lin's N.D. Cal. preliminary injunction continues to bar enforcement of the Trump directive against the rest of the federal government, allowing Anthropic to continue serving non-DOD agencies during the litigation.

The D.C. Circuit oral argument came the same week the White House was independently nearing a deal to make a version of Anthropic's Mythos model available to the NSA and other U.S. intelligence agencies (The Information, May 25, 2026), and the same week the White House approved a secret $9 billion request to buy frontier AI chips for intelligence-community classified networks (NYT, May 22, 2026). The executive branch was thus expanding Anthropic procurement on the civilian-IC side while the Department of War maintained the supply-chain-risk exclusion (Source: theinformation.com; nytimes.com).

Released correspondence (July 2026)

Newly released court documents in the litigation, published July 2, 2026, revealed months of back-and-forth between CEO Dario Amodei and Undersecretary of Defense for Research and Engineering Emil Michael over safety guardrails for the Pentagon's use of AI — tensions that persisted even as Anthropic resolved its separate export-control dispute with the administration on June 30, 2026 (Source: wsj.com).

A remark by Judge Rita Lin suggesting that federal agencies' own use of Anthropic's cyber-focused Mythos model could undercut the government's position became public on July 31, 2026 (Source: insideaipolicy.com). The argument the remark bears on is the supply-chain risk designation the Department of Defense issued on March 5, 2026, asserting that Anthropic's products could be used to sabotage U.S. operations, which prompted Anthropic's March 9 suit. The date and setting of the remark itself, and whether it came from the bench or in a written order, are not established by the available reporting, whose body sits behind a subscriber wall.

Anthropic's use restrictions and the autonomous-weapons question

The Verge (May 26, 2026) reported two developments in Anthropic's stated position. Anthropic reaffirmed two "red lines": bans on domestic mass surveillance and on weapons that identify, track, and kill targets with zero human involvement. The relationship with DOD has reportedly warmed since the Mythos release on the cybersecurity side, but Anthropic describes the autonomous-weapons and mass-surveillance prohibitions as non-negotiable.

Separately, Dario Amodei has written that "fully autonomous weapons … may prove critical for our national defense" and offered to "work directly with the Department of War on R&D to improve the reliability of these systems." Tech Justice Law's Maddy Batt called the language "fundamentally in tension" with international humanitarian law. The company's stated commercial-product red line and Amodei's R&D offer to the Department of War operate on different premises (Source: theverge.com).

The FY27 NDAA Chairman's mark, released the same day (FY27 National Defense Authorization Act (Chairman's Mark)), updates the rules governing autonomous weapons, setting up a collision between the legislative vehicle and Anthropic's stated red line at the June 4 markup (Source: theverge.com).

The same Verge investigation notes that eight companies — Google, Microsoft, AWS, Nvidia, OpenAI, Reflection, Oracle, and SpaceX — have signed deals to deploy AI on classified networks. Anthropic's autonomous-weapons and mass-surveillance red lines are a commercial cost it is absorbing while those eight competitors take classified-network business without comparable public restrictions (Source: theverge.com).

Precedent and commentary

Judge Lin's March 26 ruling is the first federal-court ruling that the U.S. government cannot retaliate against an AI vendor for publicly stated use restrictions. The ruling treats supply-chain-risk designations as reviewable and as enjoinable where retaliation intent is present. The April 8 D.C. Circuit denial of stay shows the dual-track posture is not stable: the same designation can be enjoined as retaliatory in one court while being upheld as a defensible national-security determination in another, depending on which procedural vehicle reaches the bench first. Observers have noted downstream implications for Anthropic, OpenAI, and any frontier lab whose use policy may conflict with future U.S. government requests, and the case bears on whether lab-level AI governance functions as a constraint on U.S. military and intelligence use.

Note on confidence

The primary complaint and preliminary-injunction order text have not been retrieved. Ruling details are triangulated from multi-source reporting (CBS, Axios, NBC, Reuters, Breaking Defense, Military Times, TechPolicy.Press, TIME, NYU Stern). The court, docket, and parties should be verified when primary documents become available.

Source summary

Full context: Anthropic Claude Gov + Pentagon Dispute (2025–2026) (sources/).

Relationships