Politics

How the government’s case for blacklisting Anthropic fell apart

When the Department of Defense designated Anthropic a national security risk in early 2026, it justified the move in an internal memo warning the company could “attempt to disable” or “alter the behavior of the model” in real time while deployed in the middle of a military operation, according to court documents. Anthropic didn’t learn of that claim until after it sued the department, and by the time the case reached a judge, the government’s own justification had changed. 

Anthropic’s lawsuit argued the blacklisting was retaliation. Not for refusing the Pentagon’s contract terms, but for publicly criticizing those terms after refusing to drop two specific red lines barring its AI from lethal autonomous weapons and mass surveillance of Americans.

Download the Straight Arrow app today to get the stories that matter free from manipulation, bias or agenda.

Point phone camera here

By the time the case reached summary judgment, the government’s theory shifted. Rather than arguing Anthropic could intervene in real time, it argued Anthropic could build a hidden flaw into a future model, which may not surface until the middle of ongoing warfighting operations.”

Because of Anthropic’s refusal, the company stood to lose a two-year, up to $200 million contract with the Pentagon’s Chief Digital and Artificial Intelligence Office.

The company eventually won a preliminary injunction in late March. On Thursday, U.S. District Judge Rita Lin of the Northern District of California issued a final summary judgment ruling in Anthropic’s favor, nearly six months after the Pentagon’s designation. 

“The empty invocation of national security is not a blank check to punish and retaliate against government critics,” Lin wrote in her order. 

The Pentagon’s shrinking case

The ruling revealed an internal Pentagon memo from March 2, drafted one business day after Defense Secretary Pete Hegseth ordered the Defense Department to begin designating Anthropic a security risk. The memo said AI models are “acutely vulnerable to manipulation,” and that Anthropic could “attempt to disable” or “alter the behavior of the model … in the middle of ongoing warfighting operations.”

Hegseth formally issued the designation the following day, based on the memo’s findings. 

The Pentagon also raised a second concern about “drift,” meaning Claude could “degrade as new data is introduced.” It warned that the Defense Department would be forced to operate a “black box” controlled by a “hostile party, which could contain hidden biases or backdoors.”

The memo became the backbone for the department’s formal designation, court documents stated. They also noted that Anthropic was unaware of these concerns until after it sued.

Under Secretary of Defense Emil Michael, who wrote the original internal memo, repeated his claim in a sworn declaration for Anthropic’s lawsuit on March 17. He warned of potential risks if the company interfered with its models during an operation, “whether by shutting off access to the model or altering its functionality.” But a week later Michael changed his claim.

“Under Secretary Michael’s next declaration, dated March 24, 2026, no longer makes any such claims, and instead discusses only the risk inherent in model updates,” Lin wrote.

But the mid-operation language didn’t stay buried. Three months later, in its June 24 summary judgment brief, the government invoked nearly the same wording. This time the Pentagon argued that a flaw introduced during an update might not surface until “the middle of ongoing warfighting operations.”

Anthropic pushed back on the underlying premise. The company said it can’t access or shut down a model once it’s deployed on Defense Department systems. That’s because updates aren’t installed like conventional software patches, court documents state. New models need to be trained from scratch to replace older ones, and each new version is independently tested and approved by the Defense Department before it’s used. The government never directly disputed the testing process. 

In her ruling, Lin wrote that the Pentagon presented no evidence Anthropic could actually disrupt or alter a model once it was deployed, which she called a concession “that this risk was entirely unfounded.” She added that the government didn’t dispute that it controls when new models are deployed, undercutting its own argument that rapid deployment timelines left no room for thorough testing. 

Lin ultimately characterized the government’s case as reflecting “shifting justifications” that shared little basis in the underlying record. 

Free speech violations 

Throughout the litigation, Anthropic argued the government retaliated against the company for its CEO’s past remarks. In a January essay, CEO Dario Amodei wrote that people needed to “draw a hard line against AI abuses within democracies.” He also discussed the need for “bright red lines” and “guardrails” to prevent what he called “AI-enabled totalitarianism.”

A day before the blacklist, he wrote that while the Defense Department, not private companies, makes military decisions, “in a narrow set of cases … AI can undermine, rather than defend, democratic values.” He said because of that Anthropic couldn’t give the department the access it wanted. 

The next day, President Donald Trump posted on Truth Social, saying the U.S. would never “ALLOW A RADICAL LEFT, WOKE COMPANY TO DICTATE HOW OUR GREAT MILITARY FIGHTS AND WINS WARS!” 

Hegseth later posted his own statement, saying Anthropic “attempted to strong-arm the United States military into submission,” showing the company put “Silicon Valley ideology above American lives.” 

In her ruling, Lin found Hegseth’s use of “strong-arm” was “best read as characterizing Anthropic as applying public pressure” on the military, not describing an actual security threat. She said the government was contradictory: it publicly branded Anthropic a national security risk, yet the Defense undersecretary personally emailed Amodei the day after the designation was finalized, telling him a new deal was “very close.”

“While the record plausibly supports that Defendants would have quietly made a deal with Anthropic after meting out its public punishment,” Lin wrote, “this fact only supports the retaliatory nature of the Challenged Actions.”

It’s at least the third time this year a federal judge has found Hegseth crossed a constitutional line while going after a critic, after ruling in favor of Sen. Mark Kelly, D-Ariz., in February, and The New York Times in March. 

What comes next?

Lin’s ruling settles whether the blacklist was legal, not whether the Pentagon and Anthropic will ever resolve the dispute that started it. The company’s two red lines are exactly where they were in February. In a related case, the federal appeals court in Washington declined to step in and stop the policy for now, saying Anthropic hadn’t proven it needed emergency protection. 

In a statement, an Anthropic spokesperson told TechCrunch that it remained “focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology.”

Round out your reading

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha


Secret Link