US Judge Bars Pentagon's Blacklist of Anthropic, Calling It First Amendment Retaliation
Key Takeaways
- •US District Judge Rita F. Lin granted Anthropic a preliminary injunction on March 26, finding the Pentagon's supply chain risk designation likely constituted unlawful First Amendment retaliation.
- •Defense Secretary Pete Hegseth designated Anthropic a supply chain risk on February 27, the first such designation applied to a US company, effectively locking it out of defense contracting.
- •The dispute arose from Anthropic's refusal to remove safety guardrails from its AI models, including its prohibition on use for surveillance or autonomous lethal weaponry, amid negotiations over a $200 million Defense Department agreement.
- •A three-judge D.C. Circuit panel denied Anthropic's emergency stay request on April 8, citing governmental equities and active military operations, without ruling on the merits of its claims.
- •The injunction is a preliminary measure rather than a final judgment, and the legality of the designation remains unresolved as the litigation continues.

A federal judge has blocked the Pentagon from treating Anthropic as a supply chain risk, ruling that the designation was likely an act of unlawful retaliation against the AI company for speaking publicly about safety and refusing to remove restrictions from its models.
US District Judge Rita F. Lin issued a preliminary injunction on March 26, finding that the Department of Defense's blacklisting of Anthropic appears to violate the First Amendment. In a 43-page opinion, she described the government's conduct as "classic illegal First Amendment retaliation," drawing a sharp line between legitimate national security concerns and what she characterized as punitive overreach. As a preliminary measure, the injunction preserves the existing state of affairs while the case moves forward; it rests on a finding of likely success but is not a final judgment, and Anthropic's underlying claims remain to be litigated.
How the Standoff Began
The dispute traces back to Anthropic's refusal to comply with Pentagon requests to remove safety guardrails from its AI models. The company specifically declined to permit its technology to be used for surveillance or autonomous lethal weaponry — positions consistent with its longstanding public commitments on AI safety. Such usage restrictions are common among leading AI developers, whose published terms generally bar high-risk applications like weapons work — a practice that takes on new weight when the customer is a defense ministry.
Defense Secretary Pete Hegseth escalated the conflict on February 27, issuing directives that formally designated Anthropic as a supply chain risk. The label, which had never previously been applied to a US company, effectively locked Anthropic out of defense contracting.
The designation arrived in the middle of negotiations over a $200 million Department of Defense agreement, in which the Pentagon maintained it had the authority to dictate how contractors' technology could be used.
On March 9, Anthropic filed lawsuits in both the Northern District of California and the D.C. Circuit, arguing that the designation constituted unlawful retaliation and suffered from procedural defects.
Two Courts, Two Outcomes
Judge Lin in Northern California sided firmly with Anthropic, granting the preliminary injunction and finding the company likely to succeed on the merits of its First Amendment claim. Her opinion highlighted a mismatch between the government's stated national security rationale and the timeline of events, which pointed more toward retaliation than a genuine risk assessment. That sequencing matters: retaliation claims turn on whether protected speech was followed by adverse action, and on whether the government would have acted anyway for the reasons it gave — which is why the chronology of the Pentagon's directives carries such weight.
In the D.C. Circuit, a three-judge panel denied Anthropic's emergency stay request on April 8, weighing governmental equities and citing active military operations. That ruling did not reach the merits of Anthropic's claims, but it reflected a more deferential posture toward executive branch authority in defense matters. With neither court delivering a final word on the designation's legality, the question remains open as the litigation continues.
What the Ruling Means for AI and Defense
The case has no direct precedent. No US company had previously received a supply chain risk designation of this kind — a tool typically reserved for foreign adversaries or entities with documented security vulnerabilities.
At its core, the dispute pits two competing visions of how AI should be governed against each other. The Pentagon's position implies that companies seeking defense contracts must accept military specifications without conditions, including the removal of safety-oriented usage restrictions. Anthropic's position — now backed by at least one federal court — is that the government cannot weaponize procurement decisions to punish companies for their public advocacy about how AI should and should not be used. With the Pentagon among the world's largest technology buyers, the unresolved question of who sets the rules of use — the customer or the developer — reaches well beyond a single $200 million contract.