AI

Anthropic built safety limits the Pentagon wanted removed. A court protected them.

Adrian Kessler

Claude’s creator refused two specific government demands. The Defense Department wanted Anthropic to remove guardrails that prevented its AI model from being used for fully autonomous weapons decisions and for mass domestic surveillance of American citizens. Anthropic declined. The Pentagon responded by formally designating the company a national-security supply-chain risk — a classification that barred every defense contractor in the United States from doing business with Anthropic.

The designation followed a three-day ultimatum from Defense Secretary Pete Hegseth. Its stated legal basis: Anthropic might remotely alter, disable, or install backdoors in Claude models deployed inside military systems. It was the first such designation ever applied publicly to a U.S. company under the relevant procurement statute. Defense contractors scrambled to review existing partnerships, and Anthropic estimated the damage to its commercial revenue in the billions of dollars.

That technical claim did not survive judicial scrutiny. U.S. District Judge Rita F. Lin found it ‘entirely unfounded.’ Deployed Claude models are static files — not live services connected to Anthropic’s servers. The company has no technical channel to modify them after delivery. The government produced no evidence that any such capability existed.

Judge Lin’s 59-page ruling identified three layers of legal failure. The designation violated the First Amendment: it was retaliation against Anthropic’s public statements on AI safety, not a genuine security determination. It violated the Fifth Amendment: Anthropic received no opportunity to contest the blacklist before it took effect. And it failed the Administrative Procedure Act as arbitrary and capricious — the government had raised no supply-chain concerns about Anthropic before the safety dispute began. Court documents showed that after the designation was finalized, the under secretary of defense continued contract negotiations with the company. Internal Pentagon memos cited Anthropic’s ‘Silicon Valley ideology’; the president had publicly called the company ‘RADICAL LEFT, WOKE.’ Lin wrote: ‘The empty invocation of national security is not a blank check to punish and retaliate against government critics.’

The ruling does not fully resolve Anthropic’s situation. A parallel designation under a separate federal statute remains active in a D.C. Circuit case — Anthropic is technically still a supply-chain risk under that proceeding, and legal scholars expect the Northern California ruling to be appealed promptly. The deeper question the case raises — whether federal agencies can systematically use procurement blacklists to shape what safety restrictions private AI companies maintain — is not answered by a single district court order. Lin’s ruling establishes that the mechanism can be challenged and struck down. It does not prevent governments from trying it again on different facts.

Judge Lin issued her ruling on August 27. The government is expected to appeal to the Ninth Circuit. The D.C. Circuit case on the parallel designation has no confirmed hearing date. How the appeals courts read the relationship between executive national-security authority and First Amendment protection for AI safety policy will define a constraint the industry has not had to navigate before.

Tags: , , , , ,

Discussion

There are 0 comments.