- Monday Momentum
- Posts
- A Judge Told the Pentagon It Cannot Punish an AI Company for Saying No
A Judge Told the Pentagon It Cannot Punish an AI Company for Saying No
How Anthropic refused to let Claude run autonomous weapons and mass domestic surveillance, absorbed the first supply chain risk designation ever placed on a US company, and won a First Amendment ruling that reshapes what leverage the government actually has over AI labs
Happy Monday!

Judge Rita Lin's 59-page order found the Pentagon acted on 'a desire to make a public example out of Anthropic for its arrogance in criticizing the government. (Source: NBC News)
In February, Defense Secretary Pete Hegseth gave Anthropic three days. Agree that Claude could be used for "all lawful uses," or be designated a national security supply chain risk; Anthropic refused. On March 3, the Pentagon made good on the threat, the first time the US government has ever applied that label to an American company under a statute written to protect military systems from foreign sabotage. President Trump ordered every federal agency to stop using Anthropic products.
On August 27, US District Judge Rita Lin ruled that the entire action was illegal. Her 59-page order found that the Pentagon violated Anthropic's First Amendment rights by retaliating against protected speech, violated its Fifth Amendment right to due process, and built its national security case on claims about Claude that were, in her words, "entirely unfounded." She wrote that the government acted "based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model." Then she wrote the line that will outlive the case: "The empty invocation of national security is not a blank check to punish and retaliate against government critics."
This newsletter has spent the summer documenting the government asserting control over frontier AI. It pulled Fable 5 with export controls and gated GPT-5.6 through phone calls. Labs responded by proposing equity stakes, tax structures, and self-regulatory bodies. This is the first time a lab simply said no, took the punishment, went to court, and won.
A federal judge ruled the Pentagon illegally blacklisted Anthropic for refusing to let Claude be used in fully autonomous weapons and mass domestic surveillance. Hegseth gave the company three days to accept "all lawful uses" language, then designated it a supply chain risk, the first such label ever applied to a US firm. Judge Rita Lin found First Amendment retaliation, a Fifth Amendment due process violation, and that central Pentagon claims about Claude were unfounded. The government is appealing, and a second sanction remains in effect. The precedent: AI safety policy is protected speech.
What Anthropic Actually Refused
Anthropic sells to the defense and intelligence community. Claude models are deployed across the Department of War and national security agencies for intelligence analysis, modeling and simulation, operational planning, and cyber operations. Through a partnership with Palantir, Claude Gov was cleared for classified military and intelligence work. Anthropic explicitly supports the use of its models for lawful foreign intelligence and counterintelligence missions.
What it refused was the phrase "all lawful uses." In Anthropic's reading, that language would authorize two specific things its usage policy prohibits: lethal targeting by fully autonomous weapons without meaningful human authorization, and mass surveillance of American citizens. Dario Amodei said the company could not "in good conscience" agree, citing doubts that current frontier models are reliable enough for fully autonomous weapons and arguing that domestic mass surveillance is incompatible with democratic values. The Pentagon's response was to treat a vendor's product policy as a national security threat.
What the Judge Found
Lin's order does not read like a close call. She picked apart the government's national security case repeatedly, finding some of its central claims about Claude's capabilities unfounded. The Register's summary was blunt: the Pentagon blacklisted Anthropic partly over things Claude could not actually do.
The procedural findings are as damaging as the constitutional ones. When Hegseth issued the three-day ultimatum and then the designation, the Pentagon had not yet written the assessment explaining why Anthropic posed a supply chain risk. The label came first and the justification was assembled afterward. Anthropic was never given a meaningful chance to contest it, which is the basis of the Fifth Amendment due process finding.
On the First Amendment, Lin held that neither the Constitution nor the statute the government invoked permits it to "impose sweeping penalties based principally on Anthropic's critique of the Administration's views." The supply chain risk statute exists to guard against foreign infiltration and sabotage. It was used against an American company for publishing a usage policy and defending it publicly.
Why This Is Not Over
The government is appealing the ruling; a second Pentagon sanction, imposed the same day under separate public procurement regulations, remains in effect pending a ruling in Washington, where a judge declined to suspend it in April. A narrower related case is still pending before the federal appeals court in DC. Anthropic is not restored to full standing with the federal government, and it may not be for a long time.
There is also a serious argument on the other side: the Defense Department's position is that it cannot allow a private vendor to dictate the boundaries of lawful military activity, and that a company selling into mission-critical systems should not hold unilateral veto power over how the government uses tools it depends on. That concern is not frivolous; if every vendor writes its own foreign policy through a usage policy, procurement becomes unworkable. Then there is a real question about whether an unelected company should decide what counts as an acceptable use of force.
Lin's ruling does not resolve that tension. What it resolves is narrower and, for now, more important: the government cannot answer that question by retaliating against a company for its speech, skipping the process the statute requires, and manufacturing a national security rationale after the fact.
What This Means for Practitioners
For enterprise and government vendors, this is a meaningful precedent. A usage policy is now, at least in this circuit, protected expression rather than an act of obstruction that can be punished through procurement channels. If you sell software with ethical constraints written into your terms, you have more legal ground to defend them than you did a week ago.
For anyone building on frontier models, the case clarifies where the real leverage sits. All summer, the government's power over AI labs looked nearly unlimited: export controls, release gating, informal pressure. Lin's order now marks the boundary. Those tools work when the government has a legitimate, documented rationale, but they fail when the rationale is retaliation.
For AI companies specifically, the timing is instructive. Anthropic could afford this fight: it has record revenue, its first operating profit, a pending IPO, and it absorbed a presidential order cutting it off from federal customers without existential damage. A smaller vendor facing the same ultimatum would likely have signed. Principles are cheaper to hold when you have a balance sheet behind them, which is worth remembering before treating this as a template.
The Bottom Line
Every installment of this story since June has been about labs adapting to government power. Anthropic had its model pulled from the market, so OpenAI offered a 5% equity stake, Google proposed an industry-funded referee, and more than a thousand researchers asked Washington to build a mechanism to slow them down. The consistent posture was accommodation.
This is the exception, and it turned out to matter. A company refused a specific demand on stated principle, took the harshest procurement penalty the government had available, and a federal judge found the penalty illegal, baseless, and partly built on capabilities its model did not possess. The appeal is coming and the second sanction still stands, so nothing here is settled, but the sentence at the center of the order will be cited for years.
In motion,
Justin Wright
If a private company's usage policy is the only thing standing between a frontier model and fully autonomous lethal targeting, is that a reassuring sign that corporate ethics still function as a check, or an alarming sign that a decision this consequential rests with an unelected company rather than law?

Federal judge blocks Pentagon blacklisting of Anthropic, calling it 'illegal and baseless' - NBC News
Judge: Pentagon punished Anthropic for 'arrogance,' and that's illegal - Fortune
Pentagon blacklisted Anthropic over Claude powers it didn't have - The Register
Judge says Pentagon's measures against Anthropic were 'illegal and baseless' - NPR
Judge rules Pentagon's blacklist of Anthropic violated First Amendment - The Hill
Judge blocks Pentagon blacklist of Anthropic as supply chain risk - CNBC
Anthropic sues Trump administration over blacklisting decision - NPR
Pentagon-Anthropic Dispute over Autonomous Weapon Systems: Potential Issues for Congress - Congressional Research Service
Anthropic Refuses Pentagon Demand to Remove AI Security and Safety Guardrails - ASIS International
Pentagon appealing order to remove Anthropic 'supply chain risk' label - Inside Defense
Quick Hits
Anthropic opened a research preview of the Model Hardware Standard, a shared specification letting AI agents operate microscopes, liquid handlers, and robotic arms. It cuts hardware integration from months to minutes, is model-agnostic, and builds on MCP. AWS is supporting it through Strands Robots. (Anthropic)
OpenAI published benchmarks for Jalapeño, its first custom inference chip, built with Broadcom on TSMC N3P in roughly 16 months. OpenAI claims 1.5 to 1.9 times more work per watt than Nvidia across several open models. (TechCrunch)
London-based Inherent emerged from stealth with a $50 million seed, founded by Google DeepMind alumni. Its Faraday agent reportedly outperforms Claude Opus 4.8 and GPT-5.5 at independently reproducing findings from published scientific papers. (AI Weekly)
Agent permissions infrastructure is converging: Google published its Agent Payments Protocol, NIST is doing concept work on agent identity, and the AI AGENT Act (S.5051) is moving in the Senate, all pointing toward verifiable, task-bounded authorization records. (Google Cloud)

If you haven’t listened to my podcast Mostly Humans: An AI and business podcast for everyone yet, new episodes drop every week!
Episodes can be found below - please like, subscribe, and comment!