{"id":125125,"date":"2026-07-31T01:24:17","date_gmt":"2026-07-31T01:24:17","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/125125\/"},"modified":"2026-07-31T01:24:17","modified_gmt":"2026-07-31T01:24:17","slug":"pentagons-anthropic-case-gotten-worse-judge-signals-first-amendment-stakes-for-all-ai-companies","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/125125\/","title":{"rendered":"Pentagon&#8217;s Anthropic Case &#8216;Gotten Worse,&#8217; Judge Signals; First Amendment Stakes for All AI Companies"},"content":{"rendered":"<p>A federal judge opened Thursday&#8217;s summary judgment hearing in Anthropic&#8217;s landmark lawsuit against the Pentagon by declaring, within the first five minutes, that the government&#8217;s legal position has deteriorated since she blocked the blacklisting in March \u2014 and then raised a question that expands the case&#8217;s stakes far beyond one AI company: whether accepting the government&#8217;s core argument would &#8220;eviscerate&#8221; First Amendment protections for every defense contractor that has ever publicly criticized government policy.<\/p>\n<p>&#8220;I don&#8217;t see additional evidence from the government really justifying what it did,&#8221; U.S. District Judge Rita Lin <a href=\"https:\/\/www.axios.com\/2026\/07\/30\/judge-pentagon-case-worse-anthropic\" rel=\"nofollow noopener\" target=\"_blank\">said at the start of the approximately 2.5-hour session<\/a> in San Francisco federal court. &#8220;If anything, it seems like the record, in some ways, has gotten worse for the government.&#8221;<\/p>\n<p>Lin did not rule from the bench. She took both sides&#8217; motions for summary judgment under submission and will issue a written order. But her questions \u2014 and the direction of her skepticism \u2014 offer the clearest signal yet that Anthropic is closer to winning a permanent injunction than the government is to reinstating the supply-chain risk designation that touched off one of the most consequential AI governance legal fights in American history, <a href=\"https:\/\/www.courthousenews.com\/judge-likely-to-rid-anthropic-of-pentagons-supply-chain-risk-label\/\" rel=\"nofollow noopener\" target=\"_blank\">as Courthouse News Service reported<\/a>.<\/p>\n<p>What &#8216;Lack of Trust&#8217; Would Mean for Every AI Company That Speaks Publicly<\/p>\n<p>The government&#8217;s central defense at Thursday&#8217;s hearing was that it lost &#8220;trust&#8221; in Anthropic after the company publicly criticized the Pentagon&#8217;s AI procurement demands \u2014 and that this loss of trust, combined with the opacity of frontier AI systems, justified designating Anthropic a national security supply-chain risk, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">according to the Lawfare hearing diary<\/a>.<\/p>\n<p>Judge Lin pressed Department of Justice attorney James Harlow on what that argument actually implies.<\/p>\n<p>&#8220;Suppose a contractor is terminated because they did unrelated work with Anthropic,&#8221; the judge said during exchanges reported in <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">Lawfare&#8217;s live hearing transcript<\/a>. &#8220;So if Hegseth&#8217;s original directive had come into force&#8221; \u2014 the directive that extended to every defense contractor doing any business with Anthropic \u2014 &#8220;would the Pickering framework not apply?&#8221;<\/p>\n<p>The Pickering test is the legal framework courts use when the government retaliates against contractors or employees for protected speech. It requires a balancing of the contractor&#8217;s free speech interests against the government&#8217;s interest in efficiently running its operations. The government argued Pickering applies here. Anthropic argued it does not \u2014 because Hegseth&#8217;s actions were not ordinary contract management but exercises of sovereign power, including a secondary boycott that extended to every company in the defense supply chain that did business with Anthropic, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">per the Lawfare diary<\/a>.<\/p>\n<p>That distinction matters enormously beyond this one case. If Pickering applies, the government has considerable latitude: it only needs to show a &#8220;legitimate government interest&#8221; that outweighs the contractor&#8217;s speech interests, making it comparatively easier to justify punishing companies for public criticism. If Pickering does not apply \u2014 because the government was acting in its sovereign capacity, not as a contracting party managing workplace efficiency \u2014 then a stricter constitutional standard kicks in, and &#8220;I don&#8217;t trust you because you criticized us&#8221; is almost certainly not enough.<\/p>\n<p>Judge Lin appeared to find the government&#8217;s position in serious tension with the Constitution as she explored its implications. If the government can declare that public criticism has caused it to lose trust \u2014 and use that declaration to strip a company of all its government contracts, brand it a national security threat equivalent to a foreign adversary, and warn every other defense contractor not to do business with it \u2014 Anthropic&#8217;s lead counsel Michael Mongan (of WilmerHale) argued that amounts to &#8220;the last thing a principled stand looks like in a democracy,&#8221; <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">according to Lawfare<\/a>.<\/p>\n<p>&#8220;I find that position really troubling and at odds with the First Amendment,&#8221; Lin said. &#8220;That is really quite extreme,&#8221; <a href=\"https:\/\/www.notus.org\/courts\/judge-skeptical-trump-anthropic-security-threat\" rel=\"nofollow noopener\" target=\"_blank\">NOTUS reported<\/a>.<\/p>\n<p>This was no abstract legal exercise. Judge Lin had already filed a list of five formal questions she wanted counsel to address, one of which asked directly whether the government&#8217;s position would &#8220;eviscerate First Amendment protections&#8221; for contractors as a class, <a href=\"https:\/\/www.rawstory.com\/judge-hegseth-eviscerate-first-amendment\/\" rel=\"nofollow noopener\" target=\"_blank\">as Raw Story reported<\/a>. The pre-hearing notice was filed July 27 \u2014 signaling the judge had been thinking carefully about the systemic implications before anyone walked into the courtroom on Thursday.<\/p>\n<p>Shifting Rationales and a Post-Dated Memo<\/p>\n<p>Woven through the hearing was a factual problem the government struggled to explain: its own formal risk analysis memo for the supply-chain designation was dated March 2, 2026 \u2014 after President Trump and Defense Secretary Pete Hegseth had already issued their directives against Anthropic on February 27, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">per the Lawfare diary<\/a>.<\/p>\n<p>A risk assessment written after the decision it was supposed to justify is not a predicate. It is documentation written to support a choice already made. That sequencing problem has been Anthropic&#8217;s sharpest evidence of pretext since the case began, and at Thursday&#8217;s hearing Lin showed she had not set it aside.<\/p>\n<p>Mongan went further, identifying what he called a &#8220;shifting of rationales&#8221; across the course of the litigation. When Anthropic demonstrated that it could not alter its models after delivery \u2014 that no kill-switch or post-deployment modification capability existed \u2014 the government&#8217;s stated concern pivoted. Rather than worrying that Anthropic might interfere with a deployed model, the government shifted to worrying that Anthropic might bake hidden restrictions into a future model before delivery.<\/p>\n<p>&#8220;The shifting of rationales,&#8221; Mongan told the court, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">is &#8220;powerful evidence of pretext&#8221;<\/a> that strengthens both the First Amendment claim and the Administrative Procedure Act claim.<\/p>\n<p>Judge Lin appeared to agree the pivot was worth noting. She said from the bench that she had seen no evidence Anthropic could <a href=\"https:\/\/www.axios.com\/2026\/07\/30\/judge-pentagon-case-worse-anthropic\" rel=\"nofollow noopener\" target=\"_blank\">&#8220;alter the model after it was delivered or flip some kind of kill switch&#8221;<\/a> \u2014 the original framing of the government&#8217;s concern.<\/p>\n<p>The government&#8217;s other specific &#8220;articulable facts&#8221; \u2014 DOJ attorney Harlow named them explicitly \u2014 included Anthropic&#8217;s refusal to permit all lawful military uses, an unspecified question one Anthropic executive raised about Claude&#8217;s deployment in an active overseas military operation (the details remain classified), and concerns about how the company disclosed the contract dispute to the press. Mongan dismissed each: the red lines were known before the contract was signed, the executive&#8217;s question asked whether the deployment was appropriate rather than obstructing it, and public criticism of a government policy is &#8220;core First Amendment protected activity.&#8221;<\/p>\n<p>Lin&#8217;s response to the list of articulable facts was pointed. &#8220;What are the specific articulable facts that suggest Anthropic might sabotage its software in this way?&#8221; she asked \u2014 and the hearing transcript makes clear she did not hear a satisfying answer, <a href=\"https:\/\/www.notus.org\/courts\/judge-skeptical-trump-anthropic-security-threat\" rel=\"nofollow noopener\" target=\"_blank\">NOTUS reported<\/a>.<\/p>\n<p>What the Government Still Argues \u2014 and Why It&#8217;s Not Winning<\/p>\n<p>It would be a mistake to read Lin&#8217;s skepticism as a foregone conclusion. The government made arguments that are not frivolous, and its written briefing has already been submitted.<\/p>\n<p>DOJ&#8217;s Harlow argued, with some force, that frontier AI models are categorically different from hardware procurement. A drone can be physically inspected before delivery. An AI model cannot. It is, as Harlow put it, &#8220;staggeringly enormous and opaque&#8221; \u2014 the department cannot audit it the way it can verify that a rifle meets specifications. Each update to a model is a potential opportunity to insert a new constraint. And Anthropic, unlike conventional defense contractors, has privileged ongoing access to its own products because deployment requires updating, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">per the Lawfare diary<\/a>.<\/p>\n<p>To illustrate the concern concretely, Harlow cited a documented incident involving the Centers for Disease Control and Prevention: a CDC employee tried to use a commercial version of Claude for a permitted use and found the model refused because of a pre-existing guardrail. In a scenario where a warfighter&#8217;s safety depended on Claude completing a task, a similarly unknown guardrail could have catastrophic consequences.<\/p>\n<p>Mongan&#8217;s response was clean: the government had not ordered a commercial model for classified use. It had ordered \u2014 and was in the process of taking delivery of \u2014 a purpose-built government version that would not carry the same commercial restrictions. The CDC example was a commercial-product problem that the government&#8217;s own procurement process was specifically designed to prevent.<\/p>\n<p>On the remedy question, DOJ argued that even if the court finds deficiencies in the designation, it should remand to the agency rather than vacate the order outright \u2014 giving the Pentagon an opportunity to remedy procedural or evidentiary gaps and reach the same conclusion lawfully. Anthropic&#8217;s counsel said &#8220;serious errors&#8221; preclude remand without vacatur, and offered to not contest a formal remand as a technical matter while arguing that, practically, no lawful path to re-designating Anthropic exists.<\/p>\n<p>What Happens After the Agencies<\/p>\n<p>An underreported dimension of Thursday&#8217;s hearing involved how federal agencies have actually behaved since Lin&#8217;s March 26 preliminary injunction blocked the designation from taking effect.<\/p>\n<p>The DOJ acknowledged that the Pentagon continues to wind down its use of Anthropic products and expects that process to be complete by September 30, <a href=\"https:\/\/www.axios.com\/2026\/07\/30\/judge-pentagon-case-worse-anthropic\" rel=\"nofollow noopener\" target=\"_blank\">Axios reported<\/a>. Several pilot programs at other agencies are scheduled to expire by August 30.<\/p>\n<p>But Anthropic&#8217;s counsel told the court that most agencies had continued working with the company \u2014 two had paused new contract negotiations, and others were actively negotiating new deals. Mongan said Anthropic was not aware of any agency that had canceled a contract following the preliminary injunction, <a href=\"https:\/\/www.notus.org\/courts\/judge-skeptical-trump-anthropic-security-threat\" rel=\"nofollow noopener\" target=\"_blank\">according to NOTUS<\/a>.<\/p>\n<p>When Judge Lin asked whether any agencies had expanded their use of Claude since the injunction, the DOJ objected on the grounds that the question called for sensitive information and was outside the administrative record. Lin was not satisfied. If the government genuinely believes Anthropic is a national security threat that might poison its own AI models, she observed, it would seem &#8220;inconsistent&#8221; for agencies to be simultaneously maintaining or expanding their use of those same models.<\/p>\n<p>She indicated she may order the parties to submit additional information on post-injunction agency conduct, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">per the Lawfare diary<\/a>, suggesting the government&#8217;s own ongoing use of Claude could shed light on whether the original designation reflected genuine security concerns or retaliation.<\/p>\n<p>How Did This Begin?<\/p>\n<p>The case traces to a July 2025 contract that made Claude the first frontier AI model approved for use on classified military networks, worth approximately $200 million. The relationship collapsed in February 2026 when the Pentagon demanded that Anthropic allow Claude to be used for &#8220;all lawful purposes&#8221; \u2014 a phrase that, Anthropic argued, would effectively eliminate its two hard restrictions: no fully autonomous weapons systems and no mass domestic surveillance of American citizens, <a href=\"https:\/\/www.techtimes.com\/articles\/319713\/20260704\/pentagon-blacklisted-anthropic-over-autonomous-weapons-limits-emails-reveal-very-close-talks.htm\" rel=\"nofollow noopener\" target=\"_blank\">as TechTimes reported<\/a>.<\/p>\n<p>When Anthropic refused, Hegseth issued a supply-chain risk designation on February 27 under 10 U.S.C. \u00a7 3252 \u2014 a statute previously applied only to foreign entities with ties to adversary governments, such as Huawei, ZTE, and a Swiss cybersecurity firm with alleged Russian ties. It had never been <a href=\"https:\/\/www.techtimes.com\/articles\/315056\/20260310\/anthropic-challenges-trump-era-blacklist-refusing-ai-use-surveillance-weapons.htm\" rel=\"nofollow noopener\" target=\"_blank\">applied to a domestic American company<\/a>.<\/p>\n<p>The designation required defense contractors to certify they were not using any Anthropic product. Trump issued a separate directive ordering all federal agencies to stop using Claude. Anthropic filed two lawsuits \u2014 one in the Northern District of California (today&#8217;s case) and one in the D.C. Circuit \u2014 arguing First Amendment retaliation, Fifth Amendment due process violations, and ultra vires action under the APA.<\/p>\n<p>Judge Lin granted a preliminary injunction on March 26, <a href=\"https:\/\/storage.courtlistener.com\/recap\/gov.uscourts.cand.465515\/gov.uscourts.cand.465515.134.0_1.pdf\" rel=\"nofollow noopener\" target=\"_blank\">writing<\/a> that the designation appeared to be &#8220;classic illegal First Amendment retaliation&#8221; and that &#8220;nothing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.&#8221;<\/p>\n<p>What This Means for Every AI Company<\/p>\n<p>The outcome of this case will define legal territory that extends far beyond Anthropic&#8217;s balance sheet, where <a href=\"https:\/\/www.axios.com\/2026\/07\/30\/judge-pentagon-case-worse-anthropic\" rel=\"nofollow noopener\" target=\"_blank\">billions of dollars are directly at stake<\/a>.<\/p>\n<p>If Lin rules for Anthropic and vacates the designation, the ruling establishes that 10 U.S.C. \u00a7 3252 cannot be weaponized against domestic companies for policy disagreements \u2014 that an American AI company&#8217;s public statement of what it will and will not build is not a supply-chain security threat, and that &#8220;trust&#8221; damaged by public criticism is not an articulable national security fact.<\/p>\n<p>More importantly, if Lin rules that the Pickering framework does not apply to sovereign-level retaliatory actions \u2014 secondary boycotts, presidential directives, national-security branding \u2014 every AI company that has ever published an acceptable-use policy, an AI safety position paper, or a public statement about military deployment limits will know they are doing so under a stricter constitutional standard than the government has been claiming.<\/p>\n<p>If the government wins, the reverse is true: the &#8220;trust&#8221; rationale becomes available to any future administration that finds an AI company&#8217;s public positions inconvenient, and the Pickering balancing test \u2014 under which governments often prevail \u2014 becomes the only protection contractors have.<\/p>\n<p>Anthropic&#8217;s counsel put it plainly toward the close of Thursday&#8217;s arguments: the suggestion that no court can review a presidential directive that violates the First Amendment and due process &#8220;can&#8217;t be right.&#8221;<\/p>\n<p>Judge Lin issued no indication of a timeline for her written ruling.<\/p>\n<p>Frequently Asked QuestionsWhat is the Pickering test, and why does it matter in this case?<\/p>\n<p>The Pickering test is the constitutional framework courts use when the government retaliates against contractors or employees for protected speech. It asks whether the government&#8217;s interest in efficient operations outweighs the individual&#8217;s free speech interests. The government argued Pickering applies here \u2014 meaning it only needs to show a legitimate government interest. Anthropic argued Pickering does not apply because the government was not acting as a contracting party but as a sovereign, issuing a national security designation affecting the entire defense industry. If Anthropic is right, a stricter standard applies and &#8220;we lost trust because you criticized us&#8221; almost certainly fails it. The distinction determines not just this case but how much constitutional protection any defense contractor has when it publicly disagrees with government AI policy, <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">per the Lawfare hearing diary<\/a>.<\/p>\n<p>Why does the date of the risk assessment memo matter?<\/p>\n<p>The government&#8217;s formal risk analysis memo \u2014 its documented justification for the supply-chain risk designation \u2014 was dated March 2, 2026. But President Trump&#8217;s directive and Defense Secretary Hegseth&#8217;s initial designation were both issued on February 27. A risk assessment written after the decision it supposedly supported is evidence that the decision was made first, for other reasons, and the documentation was created afterward. Judge Lin noted this problem at Thursday&#8217;s hearing, and <a href=\"https:\/\/www.lawfaremedia.org\/article\/anthropic-v.-u.s.-department-of-war--a-hearing-diary\" rel=\"nofollow noopener\" target=\"_blank\">Anthropic&#8217;s counsel argued<\/a> the sequence is &#8220;powerful evidence of pretext&#8221; for what is actually First Amendment retaliation.<\/p>\n<p>Can the government really blacklist an AI company for criticizing its policies?<\/p>\n<p>Under established First Amendment doctrine, the government cannot terminate contracts with independent contractors in retaliation for protected speech \u2014 that principle flows from the Supreme Court&#8217;s 1996 ruling in Board of County Commissioners v. Umbehr. What remains unsettled \u2014 and is now squarely before Judge Lin \u2014 is whether that protection applies when the government goes beyond terminating a single contract and instead issues a national security designation branding the company a threat equivalent to a foreign adversary, while simultaneously warning every other defense contractor not to do business with it. Judge Lin called that position &#8220;quite extreme&#8221; and &#8220;troubling&#8221; at Thursday&#8217;s hearing, <a href=\"https:\/\/www.notus.org\/courts\/judge-skeptical-trump-anthropic-security-threat\" rel=\"nofollow noopener\" target=\"_blank\">NOTUS reported<\/a>.<\/p>\n<p>What happens if Judge Lin rules against the Pentagon?<\/p>\n<p>A ruling in Anthropic&#8217;s favor would most likely take the form of a permanent injunction vacating the supply-chain risk designation \u2014 ending the formal legal cloud over Anthropic&#8217;s government contracts. The government could appeal to the Ninth Circuit. A parallel case in the D.C. Circuit challenging a related designation under a different statute (41 U.S.C. \u00a7 4713) would continue separately. Beyond Anthropic&#8217;s specific situation, a vacatur ruling would establish a legal floor: that 10 U.S.C. \u00a7 3252 cannot be used against domestic U.S. companies for publicly disagreeing with government AI procurement demands, and that the &#8220;lack of trust&#8221; rationale \u2014 at least when the trust was lost because of public speech \u2014 does not meet the constitutional threshold, <a href=\"https:\/\/www.courthousenews.com\/judge-likely-to-rid-anthropic-of-pentagons-supply-chain-risk-label\/\" rel=\"nofollow noopener\" target=\"_blank\">per Courthouse News<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"A federal judge opened Thursday&#8217;s summary judgment hearing in Anthropic&#8217;s landmark lawsuit against the Pentagon by declaring, within&hellip;\n","protected":false},"author":2,"featured_media":125126,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[24,53,49757,14963,26992,11760,41258,388],"class_list":["post-125125","post","type-post","status-publish","format-standard","has-post-thumbnail","category-anthropic","tag-ai","tag-anthropic","tag-anthropic-pentagon-lawsuit","tag-anthropic-supply-chain-risk","tag-doj","tag-first-amendment","tag-judge-rita-lin","tag-pentagon"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125125","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=125125"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/125125\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/125126"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=125125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=125125"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=125125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}