Power & systems

Before banning Anthropic, the Pentagon threatened to commandeer it

6 min read

Eighteen months to clear Anthropic for classified work. Four pages to brand it a national security risk.

The free AI newsletter
Before banning Anthropic, the Pentagon threatened to commandeer it

On February 24, 2026, in a meeting whose contents nobody disputes anymore, Secretary of War Pete Hegseth gave Anthropic an ultimatum. Either the company agreed to "all lawful uses" of Claude by the military by 5 p.m. on February 27, or it would be designated a supply chain risk and cut off from the Department, its suppliers, and every other federal agency.

Then he added a twist. Absent a deal, the Department could invoke the Defense Production Act to declare Anthropic essential to national security, and force it to keep delivering without the restrictions it was asking for.

A threat to national security, or a supplier so vital it gets commandeered. Both options sat on the table within the same hour.

Three days later, the threat won out. On February 27, Trump ordered every federal agency to drop Anthropic's technology. An hour later, Hegseth ordered the designation, formalized on March 3. On August 27, a federal judge struck those measures down, and it's that February 24 meeting she cites to explain why.

What the ruling actually vacates

The case is Anthropic PBC v. Department of War, No. 3:26-cv-01996, heard in the U.S. District Court for the Northern District of California. Judge Rita F. Lin wrote 59 pages, ruled the same day, and ordered the clerk to close the case.

She found the measures violated the First Amendment, as retaliation against protected speech, and the Fifth, since the company never got a chance to defend itself before being punished. She vacates the supply chain risk designation. She also vacates the part of Hegseth's order that barred any supplier to the U.S. military from doing any business at all with Anthropic, even work with nothing to do with defense.

A permanent injunction now bars the agencies involved from enforcing these measures and orders them to withdraw the guidance issued to implement them. Vacatur erases the measure; the injunction stops anyone from rebuilding it elsewhere.

The government had asked for a seven-day administrative stay to appeal. Denied. The ruling takes effect immediately.

The whole case fit on four pages

The mechanism used against Anthropic is anything but routine, we covered it back when the blacklisting first happened. The statute invoked, passed in 2010, targets a specific risk: an adversary sabotaging or hijacking a national security system. The implementing rules written two years later talk about foreign intelligence services, terrorists, hostile actors. Nothing in that text authorizes cutting a company off from other federal agencies, let alone ordering every defense contractor to stop working with it.

An administrative record is the homework an agency turns in when a judge asks to see its work. This one amounted to a four-page memo. Dated March 2, one business day after Hegseth's instructions, and written after two of the three measures it's supposed to justify. It never once examines the less intrusive measures the law requires agencies to rule out first.

The risk theory behind it collapsed during the case. It rested on the idea that Anthropic would keep backdoor access to its models once deployed. The government eventually conceded that no such access exists, and that Anthropic's technology is no riskier than any other opaque model on the market.

That left exactly one factor specific to Anthropic: trust. The Department argued it couldn't rely on the company because it had engaged "in an increasingly hostile manner through the press" and criticized the Department's views on military AI use. That's where the judge draws the line. Her words, like the other quotations in this piece, come straight from the ruling: "The empty invocation of national security is not a blank check to punish and retaliate against government critics."

Meanwhile, the emails kept coming

The day after the designation, on the morning of March 4, the undersecretary handling the file wrote to Dario Amodei that after review by the lawyers, "we're very close." The judge notes it's hard to square that message with the near-simultaneous portrayal of a hostile company posing an unacceptable risk. You don't keep courting a supplier you suspect of wanting to sabotage its own deliveries.

The rest follows the same arc. By April, the thaw was already underway: White House discussions around the Mythos model, protocols for agencies to use it, first deployments. On this point, the government offered no explanation in the record at all.

The damage landed elsewhere

A penalty against one company never stops at that company. One Anthropic partner, under an annual contract worth several million dollars, switched to a rival model to serve a contract with the U.S. drug regulator. More than a hundred enterprise customers wrote in to voice their concern.

Public-contractor associations filed a brief describing canceled contracts, frozen partnerships, and a compliance scramble with no clear guidance, all shadowed by the fear that the same treatment could hit them tomorrow, with no finding and no process. Thirty-eight industry employees added that the measure was chilling debate among the people best placed to judge these technologies.

It's the effect of a fine posted at the edge of a village. It targets one house, and everyone else lowers their voice.

What the ruling doesn't settle

Three caveats, because writing "Anthropic won against the Pentagon" would be wrong.

The ruling doesn't force anyone to buy Claude. It says explicitly that the Department remains free to pick its AI vendor and go elsewhere, as long as it follows the rules. What's illegal is the punishment, not the breakup.

Anthropic loses on several points too. Its separation-of-powers claim gets tossed for every defendant. Five agencies that only took interim measures escape having their actions vacated, and the injunction doesn't cover agencies that took no action at all, even though they were named in the complaint.

More importantly, a second case remains open, the one we flagged back at trial. It's pending before the federal Court of Appeals in Washington, rests on a different statute than the one vacated in California, and targets Anthropic's exclusion from civil government contracts. Argued on May 19, with the last brief filed August 3, no ruling yet. The government's appeal of the preliminary injunction from March, meanwhile, is on hold by joint request of the parties until Washington rules.

On June 3, the Secretary of War reaffirmed his original decision on that second front: unchanged in scope, still in force.

The government can still appeal the California ruling. As of August 28, nothing was on the docket.

Where it stands

Anthropic's response fit in one sentence, no victory lap: the company said it remains focused on productive work with the government in service of national security. The Pentagon did not respond to requests for comment.

Six months earlier, we wrote here that ethics had become a luxury for losers. What will likely outlast this whole case is one line from the ruling, the one the government never managed to talk its way around: none of this matches a genuine fear that Anthropic is a saboteur poised to poison its own software to harm national security.

Topics covered:

RegulationAnthropicAnalysis

Frequently asked questions

What did the federal judge vacate in the Anthropic case?
She vacates Anthropic's designation as a supply chain risk, along with the part of Pete Hegseth's order that barred any supplier to the U.S. military from doing any business at all with the company. A permanent injunction now bars the agencies involved from enforcing these measures.
Did Anthropic win against the Pentagon?
No. The ruling doesn't force anyone to buy Claude: the Department remains free to choose its AI vendor and go elsewhere. Anthropic also loses on several points, and a second case remains open before the federal Court of Appeals in Washington.
Does the ruling take effect immediately?
Yes. The government asked for a seven-day stay to appeal: denied. The ruling applies right away. The government can still appeal the California ruling; as of August 28, nothing was on the docket.
What was the Pentagon's designation actually based on?
A four-page memo dated March 2, written after two of the three measures it's supposed to justify. The theory of a backdoor into Anthropic's models fell apart during the case. That left just one factor specific to the company: trust, called into question over what the Department called an increasingly hostile manner through the press.
What case is still pending in Washington?
A second case, pending before the federal Court of Appeals in Washington, which rests on a different statute than the one vacated in California and targets Anthropic's exclusion from civil government contracts. Argued on May 19, last brief filed August 3, no ruling to date.
Julien-Pierre Noto

Julien-Pierre Noto

Entrepreneur & Voice from the Field

Julien-Pierre is an entrepreneur with over twenty years of hands-on experience in construction and real estate. For the past three years, he has been working with AI every day in an SME — not in a lab: on real cases, with real clients. Founder of ONDE AI R&D, an applied research lab on human-AI work, he publishes his methods as open source — what works and what doesn't. At Declic Media, he is the voice from the field: applied AI, the kind that has to prove its worth.

All articles by Julien-Pierre →
The free AI newsletter