A federal judge has struck down the Pentagon blacklist of Anthropic, ruling that officials unlawfully retaliated against the artificial intelligence company after it refused to loosen restrictions on military uses of its technology. The decision permanently blocks enforcement of the broader ban and cancels Defense Secretary Pete Hegseth’s February 27 designation of Anthropic as a supply-chain risk.

Judge Rita F. Lin of the U.S. District Court for the Northern District of California found that the government violated Anthropic’s First Amendment rights and relied on reasoning that did not withstand much inspection.

“The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote.

The government is expected to appeal, according to the Associated Press and Axios. A separate case involving another Pentagon designation also remains before the U.S. Court of Appeals for the D.C. Circuit, so the legal conflict has not disappeared. It has merely acquired more paperwork.

Why did the Pentagon blacklist Anthropic?

The dispute began during the winter, when Hegseth sought revised contracts allowing the military to use commercial AI systems for “any lawful use.” Most major technology companies accepted the new language. Anthropic did not.

The maker of the Claude chatbot insisted on keeping two restrictions. Its technology could not be used for:

  • Mass surveillance of Americans
  • Lethal autonomous weapons that select and kill targets without human oversight

Anthropic said those limits covered a narrow category of applications rather than ordinary military operations. Less than 24 hours before a final government deadline, Chief Executive Dario Amodei said the company had “never raised objections to particular military operations nor attempted to limit use of our technology in an ad hoc manner.”

“In a narrow set of cases, we believe AI can undermine, rather than defend, democratic values,” Amodei added.

The Pentagon responded by declaring Anthropic a supply-chain risk, a label designed to protect national-security systems from threats such as sabotage and subversion. Applying it to a domestic company over a contract disagreement was, according to Lin’s ruling, both “arbitrary and capricious.”

The Washington Post reported that the government’s case relied largely on a four-page memorandum. National-security policy is complicated, but apparently four pages were considered sufficient for this particular exercise.

What did Judge Rita Lin rule?

Lin concluded that the Pentagon could choose whichever AI supplier it preferred. What it could not do was impose sweeping penalties on Anthropic because the company publicly challenged the government’s contracting demands.

“Though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless,” she wrote.

The ruling vacated Hegseth’s February 27 decision and permanently barred the government from enforcing the broader blacklist. Lin found that officials had committed “unlawful retaliation in violation of the First Amendment.”

She had reached a similar preliminary conclusion in March, when she temporarily blocked the measures while Anthropic’s lawsuit proceeded. Pentagon records showed that officials objected to the company’s “hostile manner through the press,” Lin wrote at the time.

“Punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation,” she said.

Anthropic attorney Michael Mongan argued that the restrictions “profoundly harm Anthropic” and could discourage other contractors from publicly debating government policy. Twenty-two retired senior military officers supported the company’s challenge. Microsoft also argued that the armed forces need dependable access to advanced technology while maintaining safeguards against mass domestic surveillance and wars initiated without human control.

How large was Anthropic’s military role?

Before the confrontation, Anthropic held a two-year Pentagon agreement worth up to $200 million. According to The Washington Post and court filings, it was also the first frontier-model developer cleared to place its technology on classified military systems.

After negotiations collapsed, the Pentagon moved to reduce its reliance on Claude and signed agreements with seven other AI suppliers. Defense News identified them as:

  • Amazon Web Services
  • Google
  • Microsoft
  • Nvidia
  • OpenAI
  • Reflection AI
  • SpaceX

Pentagon technology chief Emil Michael told CNBC in March that there was “no chance” negotiations with Anthropic would resume.

The restrictions affected more than the company’s direct government work. Defense contractors had to determine whether their systems relied on Claude and, where necessary, prepare to remove those dependencies. Federal News Network reported that two overlapping Pentagon designations created uncertainty about which companies and contracts were covered.

That operational burden matters because modern defense systems often depend on layers of outside software and cloud services. Removing one model provider is not always as simple as cancelling a chatbot subscription and moving on with the afternoon.

Why is the dispute still not over?

Thursday’s decision addresses the broad measures challenged in California, including public and presidential directives enforcing Hegseth’s supply-chain determination. It does not settle Anthropic’s narrower challenge to a separate statutory procurement designation.

That second case remains pending before the D.C. Circuit. The Associated Press and The Guardian reported that the separate classification could still prevent Anthropic from securing civilian federal contracts, even though Lin has blocked the wider Pentagon ban.

The result is an unresolved legal split. Anthropic has defeated one attempt to exclude it across the government contracting system, but another route to restricting its federal business remains under review. An appeal of Lin’s ruling could add a third track.

Anthropic spokesperson Danielle Ghiglieri welcomed the California decision while signalling that the company still wants government work.

“We remain focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology,” she said.

The broader argument is likely to outlast this case: whether an AI supplier may impose its own limits on military deployment, and how far the government can go when those limits conflict with its preferred contract terms. Lin’s ruling says the Pentagon may reject a vendor. It may not convert a policy disagreement into a national-security threat simply because that label carries more force.