U.S. District Judge Rita Lin put a 59-page order on the Northern District of California docket on Thursday night, 27 August 2026, and turned a six-month stop-order into a lasting one. The agencies named in Anthropic’s San Francisco case may not carry out President Donald Trump’s instruction to drop the company’s Claude models. Defense Secretary Pete Hegseth’s designation of Anthropic as a “supply chain risk” — a stamp the Pentagon had, until this year, reserved for foreign firms — is vacated as to those defendants. Lin’s reason is not a quarrel about model quality. She wrote that the government made a public example of the company for criticising Pentagon policy on how artificial intelligence may be used, and that it did not have an articulable sabotage case.
By Friday 28 August 2026 the ruling is on the wires at Associated Press, the BBC, The Guardian, NPR and CNBC. The White House has not answered in substance. Neither has the Pentagon. Justice Department lawyers are expected to appeal. A second, narrower case is still pending in Washington, D.C. Readers should hold that last fact in view. Thursday night is a California judgment on a California record. It is not a coast-to-coast deletion of every supply-chain label the department has tried to hang on the lab.
A stamp written for foreign sabotage
The quarrel is six months old. In February, after talks over military use of Claude collapsed, Trump and Hegseth accused Anthropic of putting national security at risk. On 27 February the president posted a directive telling federal agencies to stop using the company’s tools. Hegseth posted his own the same day: Anthropic was a supply chain risk, and any contractor, supplier or partner that did business with the United States military was not to do commercial business with Anthropic. Later filings called that second piece a secondary boycott. A written determination dated 3 March reached the company on the evening of the 4th.
That label is not a press-office insult. Under the statute the Pentagon invoked in California — 10 U.S.C. § 3252 — a supply-chain-risk finding is a tool built to keep foreign sabotage out of military systems. Reporting across AP, the BBC and The Guardian is consistent on the history: until 2026 the public use of the stamp was for companies tied to adversary states. Anthropic, a San Francisco lab, was the first American firm to receive it in the open. CNN described the practical consequence. No part of the Pentagon, including contractors, was supposed to work with the company’s products.
Anthropic’s 9 March complaint called the sequence an “unlawful campaign of retaliation” for refusing unrestricted military use of its technology. Executives have told courts and reporters the designation could cost billions in lost contracts and in reputational harm. The company also said it was given no real chance to contest the finding before the boycott landed — a Fifth Amendment process claim Lin later accepted.
Washington told a different story. Justice Department briefs said the designation flowed from Anthropic’s refusal to accept new contract terms, not from the company’s views on AI safety. Hegseth’s public line was that a private firm should not be allowed to constrain how the American military uses its tools. The White House, in February, called Anthropic “a radical left, woke company” that was trying to control military activity, and said the armed forces answer to the Constitution, “not any woke AI company’s terms of service.” CBS, filing on the ruling, noted that Hegseth had also called the firm “sanctimonious.” At a 30 July hearing, government lawyers added a technical pitch: AI models are “so staggeringly enormous and opaque” that the department cannot inspect them the way it inspects a piece of hardware, so a vendor that will not lift its own limits cannot be trusted inside a weapons network.
Lin had already rejected the wrapping. In March she issued a preliminary injunction that blocked enforcement of the Trump post and the Hegseth designation. She had called the government’s theory “Orwellian.” On 30 July she told the parties the government’s position was “really troubling” and “at odds” with the First Amendment, and that the record had “gotten worse for the government” as the months went on. Thursday night is that temporary block, made permanent for the defendants in her courtroom.
The limits Amodei would not lift
Anthropic’s chief executive, Dario Amodei, would not give the Pentagon unrestricted use of Claude. The company’s line, as AP, the BBC and The Guardian each reported it, was specific rather than atmospheric. It did not want the models used for mass surveillance. It did not want them used in autonomous weapons, including armed drones. Anthropic said the systems were not reliable enough to be put safely into a kill chain. It also treated domestic surveillance as a rights problem, not a feature request.
That is a product decision with a political price, or a political decision with a product wrapped around it, depending on the speaker. The Pentagon heard a vendor trying to write rules of engagement from California. Anthropic heard a demand that it disable the limits it had built in. The argument was never really about whether Claude could draft a briefing note. It was about whether a private lab could keep a military customer from pointing the same model at a population, or at a machine that fires without a person in the loop.
Hours after the government moved against Anthropic, OpenAI — the maker of ChatGPT, and Anthropic’s principal rival — struck its own deal to work with the Pentagon. Both companies are preparing for closely watched initial public offerings. The contrast did not need a caption. One lab said no to unrestricted military use and was labelled a supply-chain threat. The other said yes, on the same afternoon.
Lin later pointed to a fact the sabotage theory struggles to explain. Other parts of the US government kept meeting and working with Anthropic after the Pentagon’s move. “None of that,” she wrote, “is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security.” In a June interview with Axios, Trump himself said that while he had previously viewed the company as a national security threat, he no longer believed it was. The public example, in other words, outran the president’s own stated fear.
The company’s lawsuit also noted that the military had praised Claude in the past. That is not a small inconsistency if the current theory is that the same vendor is a saboteur. Lin treated the contemporaneous words — arrogance, woke, sanctimonious, make an example — as better evidence of motive than the after-the-fact national-security memo.
Three defects in 59 pages
Lin granted Anthropic’s motion for summary judgment and denied the government’s cross-motion. She is a Biden appointee. The length of the opinion is not decoration. It walks through three independent defects. Any one of them, on her account, is enough to knock the California designation down.
On the First Amendment, the “undisputed record” showed “unlawful retaliation.” The government’s own words and deeds, contemporaneous with the February posts, showed a desire to make a public example of Anthropic for its “arrogance” in criticising the administration, “not based on any articulable basis to believe that Anthropic would actually sabotage its model.” National security, she wrote, is “not a blank check to punish and retaliate against government critics.” An “empty invocation” of it does not fill the cheque. Neither the Constitution nor the statute the Pentagon cited allows “sweeping penalties based principally on Anthropic’s critique of the Administration’s views.” In an earlier round she had already called the pattern “classic First Amendment retaliation.” Thursday she made that the holding.
On the Fifth Amendment, Anthropic was denied the process it was owed before the deprivation. The company was not given a genuine chance to contest the finding before contractors were told to cut ties. Lin treated that as a due-process failure, not a clerical miss.
On the Administrative Procedure Act, Hegseth’s decision violated the governing statutory scheme, was arbitrary and capricious, and exceeded the authority in § 3252. Earlier in the case she had found that the government had not considered less intrusive measures, had relied on a risk assessment from the wrong official — the under secretary for research and engineering rather than the under secretary for intelligence, as the department’s own regulation required — and had stretched “supply chain risk” past the text. A vendor who “pushes back,” she had said, does not become an “adversary” under that statute. The government’s apparent position that pushback equals hostility was, in her phrase, deeply troubling and inconsistent with the words Congress actually enacted.
The order takes effect immediately. The agencies in the California case are directed to rescind the guidance and instructions that carried out the challenged actions. The Hegseth directive is vacated. Trump’s social-media instruction, as applied to those agencies, is not to be enforced. Anthropic lawyer Michael Mongan had told Lin in July that the conduct “profoundly harm[s] Anthropic” and threatened to “chill speech and debate on a very important issue.” The 59 pages are the court’s answer to that chill. The speech was protected. The penalty, in this docket, was not.
An Anthropic spokesperson, in a line given to AP, the BBC, The Guardian, NPR and CNBC, said the company welcomed the ruling that the designation was unlawful and remained “focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.” As of Friday morning in London, the White House had not responded to requests for comment. Neither had the Pentagon.
The other courthouse is still open
Thursday night is not a nationwide wipe, and it should not be written as one. Anthropic sued in two places because the Defense Department used two legal hooks.
The California case, before Lin, attacked the § 3252 designation, the presidential social-media directive, and the Hegseth boycott order. That is the case she has now finished on summary judgment. It binds the defendants named in that lawsuit. It does not, by itself, rewrite every other procurement rule in the federal code.
The second case is narrower and is still live. It concerns a different rule — a Federal Acquisition Supply Chain Security Act designation under 41 U.S.C. § 4713 — that the Pentagon has used in an effort to keep Anthropic out of civilian government contracts as well as military ones. That fight sits in Washington, D.C., before the federal appeals court there. CNBC, filing on Friday, noted that until it is resolved Anthropic can still, in a technical sense, carry a supply-chain-risk label under that other statute. The D.C. Circuit earlier declined to stay the designation and set the matter for argument. Two courts. Two postures. One win on Thursday. One docket still open.
The government is expected to take Lin’s order up. An appeal would go to the Ninth Circuit. A stay pending appeal is possible; it is not automatic. For now the California injunction is permanent and in force against the agencies in the case.
Justice Department lawyers had also argued that Anthropic’s refusal to lift its restrictions could leave commanders uncertain about how Claude would behave in an operation, and could even risk disabling systems in the field. Lin did not treat that hypothetical as a substitute for an articulable sabotage showing. Uncertainty about a vendor’s terms of service is a contracting problem. It is not, in her reading, the same thing as a foreign-intelligence implant in a missile battery — which is the harm the supply-chain statute was written to reach.
What Friday’s coverage does not settle
By Friday 28 August 2026 the story has moved from a San Francisco docket onto the main wires. AP led on Lin’s finding that the Pentagon had acted illegally by punishing Anthropic for criticising the Defense Department’s views on AI use. The BBC led on unlawful retaliation and on the fact that a supply-chain-risk law “typically reserved for companies based in countries that pose a threat to the US” had been turned on an American company. The Guardian led on the 59 pages, the bar on enforcing Trump’s drop-Claude order, and the vacatur of Hegseth’s designation. NPR carried the AP account. CNBC underlined the D.C. remainder. That spread is the news cycle. It is not a second court speaking.
The holding that will travel, if it survives appeal, is the First Amendment one. A presidential social-media post is still government action when it tells agencies to freeze a critic out of federal work. A defence secretary’s boycott order is still government action when it tells every military contractor to stop buying from that critic. Lin’s point is that you cannot dress that up as sabotage when your own contemporaneous words say you are making an example of the company’s “arrogance.” If a US AI lab can be dropped into the same statutory box as a foreign adversary for refusing to strip safety limits, then the next lab that says no to a weapons use-case is on notice. Mongan’s chill is the policy question the opinion answers, for this docket, in the company’s favour.
It is also a fight about who writes the rules for military AI: the civilian labs that train the models, or the department that wants to point them at a battlefield and at a population. Amodei chose the first answer and took a blacklist for it. OpenAI chose the second and took a contract. Lin has now said the first answer is speech, and that the blacklist, in California, was illegal.
Max24 is not going to treat a large-language model as a reviewed product, and it is not going to pretend a San Francisco judgment is a D.C. judgment. The 59-page order is on file. The named California agencies are barred. The D.C. case is not. An appeal is coming. As of Friday 28 August 2026, that is the state of the fight: a judge has refused to let the Pentagon use a foreign-sabotage stamp as a punishment for an American company that talked back.
Hero photograph: The Pentagon, Arlington, Virginia, looking northeast toward the Potomac River and the Washington Monument. Credit: Master Sgt. Ken Hammond, U.S. Air Force / U.S. Department of Defense. Public domain (U.S. government work). Via Wikimedia Commons.
Syed Aqeel (Founder, CEO, and Developer) — wrote / author this story. Syed Aqeel (Founder, CEO, and Developer) — verified this story.

Comments(0
No comments yet. Be the first!