US AI procurement policy

The Pentagon Is Defying a Federal Court on Anthropic, and Nobody in the Administration Will Say Who Is in Charge

A judge voided the Pentagon's Anthropic blacklist as unlawful retaliation, but the DOD is still enforcing it while Commerce says the fight is over.

Anthropic vs. the Pentagon: Two Rulings, One Contrad… People of Internet Research · US 3 Ruling grounds Judge Lin found First Amendment re… 7 Days to contradiction Emil Michael reasserted the risk d… 30 days Notice period required FASCSA requires agencies to notify… peopleofinternet.com
Anthropic vs. the Pentagon: Two Ruling… People of Internet Research · US 3 Ruling grounds 7 Days to contradiction 30 days Notice period required peopleofinternet.com

Key Takeaways

A ruling with no enforcement mechanism

On August 27, 2026, U.S. District Judge Rita Lin of the Northern District of California entered final judgment against the Department of Defense, holding that its designation of Anthropic as a "supply chain risk" was unlawful on three independent grounds: First Amendment retaliation, a Fifth Amendment due-process violation, and arbitrary-and-capricious agency action that exceeded the Secretary's statutory authority under 10 U.S.C. § 3252 (CNN; EFF). Lin's order was blunt about motive: the designation, she found, rested on a desire "to make a public example out of Anthropic for its 'arrogance' in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model" (Fortune).

One week later, on September 3, Under Secretary of War Emil Michael posted on X: "Anthropic is still a designated Supply Chain Risk at @DeptofWar and for the Defense Industrial Base. Thank you for your attention to this matter!" (x.com/USWREMichael). The statement also cut directly against Commerce Secretary Howard Lutnick, who had told Axios the previous day, at the G20 Innovation Ministerial, that Anthropic had "done what we asked and is back on the right side" and that "we trust Anthropic" (via Time News).

Two designations, one confusing headline

The charitable reading is that this is not pure defiance but a jurisdictional tangle the administration has declined to clarify. Reporting on the case indicates the Department issued two separate supply-chain designations against Anthropic in March: one under 10 U.S.C. § 3252, which is the letter Judge Lin vacated, and a second under the Federal Acquisition Supply Chain Security Act, codified at 41 U.S.C. § 4713, which authorizes agency heads to exclude a contractor after a joint recommendation, a 30-day notice period, and a written necessity determination (Cornell Law, 41 U.S.C. § 4713). That second designation is reportedly still pending before the D.C. Circuit and was untouched by last week's ruling. If Michael's post is technically referring to the surviving FASCSA designation rather than re-asserting the one a federal court just struck down, the administration owes the public — and Anthropic's federal customers — a plain statement saying so.

But even the charitable reading has a limit, and the administration blew past it. Nothing in Michael's post drew that distinction. A one-line assertion that a company is "still a designated Supply Chain Risk," issued a week after a federal court found the underlying rationale to be a pretext for punishing protected speech, reads as a statement that the ruling doesn't matter — not as a careful legal clarification. If the government believes a separate, still-valid designation survives, it needs to say which statute, which record, and why; ambiguity here isn't neutral, it chills every other contractor watching how Washington treats companies that decline instructions on autonomous weapons and mass surveillance.

The steelman for caution — and why it doesn't cover this

There's a real security interest that deserves a fair hearing. The government routinely restricts vendors whose products touch classified networks, and courts generally defer to executive branch judgments on national security where the underlying process is sound. Congress built exactly that authority into FASCSA, with layered internal review and a 30-day notice requirement, precisely so agencies aren't stuck using tools an adversary could compromise. If Anthropic's models genuinely posed a sabotage or data-exfiltration risk, excluding them from classified defense work would be unremarkable procurement hygiene, not retaliation.

That is exactly the case the administration failed to make. Judge Lin's order didn't fault the government for caring about supply-chain security — it found that the technical justification offered, that Anthropic retained "backdoor access" to deployed models, was "demonstrably false and post-hoc," leaving only the company's public refusal to permit fully autonomous weapons targeting and mass domestic surveillance of Americans as the actual trigger (National Law Review). Lin's own words from the July 30 hearing anticipated this outcome: the government's position seemed "at odds" with the First Amendment, and the record had "gotten worse for the government" as the case proceeded (Fortune). National security review that can't survive summary judgment isn't a security process; it's a label applied after the fact to cover a punitive decision.

Why this matters beyond one company

The practical harm here isn't confined to Anthropic. Every AI vendor now negotiating a federal contract has to price in the risk that setting a safety red line — refusing to help build autonomous weapons systems or turn a model toward surveilling citizens — can trigger a blacklist that persists even after a court calls it illegal retaliation. That is a worse outcome for competition and innovation than almost any formal procurement rule the government could have written instead: it replaces predictable statutory criteria with the discretion of whichever official is willing to keep posting.

Congress has the tools to fix this without picking sides in the underlying AI-safety debate. It can require that any FASCSA action against a company already cleared by a federal court be re-justified on an independent record, and it can demand that agencies publicly identify which specific statutory designation they're invoking rather than issuing ambiguous one-line assertions on social media. Until that happens, the operative rule for federal AI contractors is not written in the U.S. Code — it's whatever a Pentagon official decides to post.

Sources & Citations

  1. CNN: Judge rules Pentagon's supply chain risk label unlawful
  2. EFF: Judge Rules DOD Unlawfully Retaliated Against Anthropic
  3. Fortune: Judge says Pentagon punished Anthropic for 'arrogance'
  4. Under Secretary of War Emil Michael on X
  5. Cornell Law: 41 U.S.C. § 4713 (Federal Acquisition Supply Chain Security Act)
  6. National Law Review: analysis of the ruling and the designation it leaves standing
  7. Time News: Lutnick says Anthropic back in administration's good graces