Judge blocks Trump administration's 'retaliatory' punishment of AI firm Anthropic

The empty invocation of national security is not a blank check
Judge Lin rejected the government's claim that national security concerns justified cutting off Anthropic without due process.
Mark

So the judge is saying the Trump administration couldn't just cut off Anthropic because it disagreed with them about AI safety?

Mimi

Right. Judge Lin found that the government's real motive was retaliation for Anthropic's public criticism—specifically, the company's refusal to remove safeguards on its Claude model. The administration wanted those guardrails gone so the military could use Claude however it wanted.

Luke

But we should be careful here. The government's lawyers said they cut off Anthropic because they no longer trusted it, not because of the speech. That's a factual claim. Did the judge actually prove the government was lying, or did she just find the government's explanation unconvincing?

Mimi

She found it unconvincing based on the evidence. Trump announced the ban on Truth Social before any formal process began. Hegseth posted about it on social media. The judge said that timing and method made sense only as public punishment, not as a security decision.

Mark

What was Anthropic actually asking for? Were they being unreasonable?

Mimi

They wanted two restrictions: no mass surveillance of Americans, and no autonomous weapons that can kill without human approval. Amodei said he wanted to work with the military but had those two red lines.

Luke

And the military said those uses are already illegal under federal law and Pentagon policy, so why add contractual restrictions? That's not an unreasonable position either.

Mark

So both sides had a point.

Mimi

They did. But the judge's job wasn't to decide who was right about AI policy. It was to decide whether the government could punish the company for disagreeing. She said it couldn't.

Luke

One more thing to note: the judge said the government can still choose not to buy from Anthropic. It just can't use the "supply chain risk" designation as cover for retaliation. That's a narrower ruling than it might sound.

Mark

So what happens next?

Mimi

There's still a case pending in the D.C. Circuit Court of Appeals. And the bigger question about how to govern AI remains open. This ruling just says the government can't punish companies for protected speech while doing it.

  • The conflict ignited when Anthropic refused to strip safety guardrails from its Claude AI model, prompting the Trump administration to publicly brand the company 'radical left' and cut it off from all federal and military contracts.
  • The punishment arrived through social media before any formal legal process had begun — a sequence Judge Lin found revealing, suggesting the goal was to make a swift public example rather than address a genuine security threat.
  • The government's claim that Anthropic posed a 'supply chain risk' akin to a foreign adversary collapsed under scrutiny, as the judge found no evidence the company could install backdoor controls and noted the administration was simultaneously seeking to collaborate with it on advanced AI.
  • Judge Rita Lin issued a permanent injunction blocking enforcement of the punitive measures, writing that invoking national security is not a blank check to retaliate against critics of the executive branch.
  • Anthropic emerges with its legal footing restored, though the administration retains the right to choose vendors through lawful means, and a parallel challenge in the D.C. Circuit Court keeps the broader battle alive.

In San Francisco, a federal judge has drawn a constitutional line between national security and political retribution, ruling that the Trump administration unlawfully punished AI company Anthropic for insisting its Claude model not be used for mass surveillance or autonomous weapons. Judge Rita Lin's permanent order restoring Anthropic's access to federal contracting reflects an older tension in democratic governance: the difference between a government choosing its partners and a government silencing its critics. The ruling does not settle the larger questions of how artificial intelligence should serve the state, but it affirms that the First Amendment does not dissolve when technology and power meet.

Late Thursday, a federal judge in San Francisco handed AI company Anthropic a decisive legal victory in its months-long standoff with the Trump administration. U.S. District Judge Rita Lin issued a permanent order blocking the government from enforcing rules designed to sever Anthropic from federal contracts and military use, finding the administration had violated the First Amendment by punishing the company for protected speech.

The dispute traced back to a fundamental disagreement over how Anthropic's Claude AI model should be deployed. The company, led by CEO Dario Amodei, insisted on two absolute limits: Claude could not be used for mass surveillance of Americans, nor could it power autonomous weapons that target people without human oversight. The military argued existing law already covered those concerns, making Anthropic's additional safeguards redundant. When negotiations broke down in February, the administration responded with public fury — Defense Secretary Pete Hegseth called the company 'sanctimonious,' and President Trump labeled it 'radical left, woke.' Within days, orders went out barring military contractors from any commercial activity with Anthropic.

In a 59-page opinion, Judge Lin dismantled the government's legal rationale. The administration had classified Anthropic as a 'supply chain risk' — a designation normally reserved for foreign adversaries — claiming it feared the company might install a 'kill switch' to enforce its own policy preferences on military users. Lin called this concern 'entirely unfounded,' noting Anthropic had demonstrated it lacks the technical ability to maintain backdoor access. She also flagged a telling contradiction: if the government genuinely believed Anthropic posed a sabotage threat, why was it simultaneously seeking to collaborate with the company on advanced AI development?

What struck the judge most was the sequence of events. Trump announced the ban via Truth Social before any formal administrative process had begun. Lin wrote that broadcasting Anthropic's punishment through social media before the required legal findings had even been made 'makes little sense except as an attempt to swiftly make a public example' of a company that had dared to criticize the administration. She concluded the actions constituted unlawful retaliation taken without due process.

The judge acknowledged that courts owe deference to the executive on genuine national security matters, but drew a firm line between legitimate security decisions and punishment dressed as policy. 'The empty invocation of national security is not a blank check to punish and retaliate against government critics,' she wrote. The ruling drew support from civil liberties groups and from Microsoft, which warned in a court filing that the supply chain designation risked severe economic harm to the broader technology sector.

The order does not compel the government to use Anthropic or shield the company from losing business to competitors through lawful means. A separate challenge remains pending before the U.S. Court of Appeals for the D.C. Circuit. The deeper questions — how to balance AI innovation against national security, and who holds the authority to decide — remain unresolved. For now, Anthropic has won the right to compete for federal business on equal constitutional footing.

Late Thursday afternoon, a federal judge in San Francisco handed Anthropic a decisive victory in its monthslong clash with the Trump administration over artificial intelligence and national security. U.S. District Judge Rita Lin issued a permanent order blocking the government from enforcing a series of rules designed to cut the AI company off from federal contracts and military use. The judge found that the administration had violated the First Amendment by punishing Anthropic for protected speech—specifically, the company's public insistence on safety guardrails for its Claude AI model.

The conflict began over a fundamental disagreement about how Claude should be deployed. Anthropic, led by CEO Dario Amodei, wanted two absolute restrictions: the model could not be used for mass surveillance of Americans, and it could not power autonomous weapons capable of targeting people without human decision-making. The military pushed back, arguing that existing federal law and internal Pentagon policies already prohibited those uses, making Anthropic's additional safeguards unnecessary. When negotiations collapsed in February, the Trump administration responded with public fury. Defense Secretary Pete Hegseth called the company "sanctimonious." President Trump labeled it "radical left, woke." Within days, the administration issued orders to cut off Anthropic's access to federal systems and barred military contractors from using its technology for any purpose.

Judge Lin's 59-page opinion dismantled the government's legal rationale. The administration had designated Anthropic as a "supply chain risk"—a classification normally reserved for foreign adversaries who might sabotage critical U.S. systems. The government claimed it feared Anthropic might install a "kill switch" in its software to enforce its own policy preferences on military users. Lin called this concern "entirely unfounded," noting that Anthropic had provided evidence it lacks the technical ability to maintain backdoor access to its systems. She also pointed out the logical inconsistency: if the government truly believed Anthropic posed a sabotage threat, why did it continue seeking to collaborate with the company on advanced AI development?

What struck the judge most forcefully was the timing and manner of the administration's actions. Trump had announced the ban via Truth Social before any formal administrative process had begun. Hegseth's February social media post declaring that military contractors could conduct "no commercial activity with Anthropic" had triggered a broader boycott that extended even to non-military uses of the technology. Lin wrote that "the decision to publicly broadcast Anthropic's punishment via social media—even before the formal, administrative process of making the necessary findings to designate Anthropic a supply chain risk had begun—makes little sense except as an attempt to swiftly make a public example of Anthropic for daring to criticize the Administration." She concluded that the moves constituted "retaliatory act, taken without due process, meant to punish Anthropic for its protected speech."

The judge acknowledged that the government deserves deference on national security matters. But she drew a sharp line between legitimate security decisions and punishment disguised as policy. "The empty invocation of national security is not a blank check to punish and retaliate against government critics," she wrote. She also rejected the government's argument that it was simply exercising its right to choose which vendors to buy from. An IT vendor does not become an adversary of the United States merely by asking tough questions or insisting on particular contract terms, Lin reasoned, even if those demands frustrate federal officials.

Anthropicwelcomed the ruling, saying it remained committed to working with the government on AI for national security. The company had drawn support from civil liberties organizations and from Microsoft, which warned in a court filing that the supply chain designation could cause "severe economic effects that are not in the public interest." The Justice Department had argued that it cut off Anthropic not for its speech but because the Defense Department no longer trusted the company's judgment. Lin found that argument unconvincing given the contemporaneous statements from Trump and Hegseth attacking Anthropic's values and ideology.

The ruling does not require the government to use Anthropic or prevent it from losing business to competitors, so long as those decisions comply with law and the Constitution. But it does mean the administration cannot enforce the punitive measures it imposed. A separate challenge to the government's actions is still pending in the U.S. Court of Appeals for the D.C. Circuit. The broader question—how to balance the innovation benefits of AI against legitimate national security concerns, and who gets to decide—remains unresolved. For now, Anthropic has won the right to compete for federal business on equal legal footing, even as the deeper debate over AI governance and executive power continues.

The government is certainly owed deference on weighty issues of national security. But Defendants' contemporaneous words and deeds confirm that the challenged actions were based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model.
— Judge Rita Lin, in her 59-page ruling
An IT vendor does not become a potential adversary of the United States whenever it asks probing questions or stubbornly insists on particular contracting terms, even if doing so causes DoW to doubt its trustworthiness.
— Judge Rita Lin
Contact Us FAQ