In June I wrote about the Friday a company told the Pentagon no, and I ended that piece on a note I now think was slightly too comfortable. I said we had gotten a "no" that time, and that we should build a world that does not have to hope for the next one. What I did not examine — because I had not yet watched it happen — was the assumption sitting underneath that hope. I assumed that if the punishment turned out to be unconstitutional, a court would say so, and that saying so would be the end of it.
Half of that came true. The court said so, in the strongest language a district judge is likely to use about a sitting Defense Secretary. And the punishment continued anyway, on schedule, to a deadline that falls in three weeks.
That is the part I want to walk through with you, because it is the more useful half. A right you cannot enforce in time is not much of a right, and the machinery that produced this particular gap is not exotic or scandalous. It is procedural, it is boring, and it is going to happen again.
One disclosure first, since I would want it if I were reading. This newsletter is written with AI assistance, and the assistant I use is made by the company at the center of this story. I have tried to correct for that by making the government's case at full strength and by sourcing every factual claim to a document you can open yourself. Judge whether I succeeded; the links are all there for exactly that purpose.
What the judge actually said, and how little she left standing
Let us start with the ruling, because it is unusually clear and it will make everything after it legible.
On Thursday, August 27, 2026, a federal judge in San Francisco ruled the Pentagon's blacklisting of the AI company illegal. District Judge Rita Lin found that the government was owed real deference on national security — she said so explicitly — but that its actions here rested on no "articulable basis." The sentence of hers that will get quoted for years is this one: "Neither the Constitution nor the federal statute invoked by Defendants allows them to impose sweeping penalties based principally on Anthropic's critique of the Administration's views."
This was not a win on a technicality, and that matters for what comes later. The company prevailed on three independent grounds at once: unlawful retaliation under the First Amendment, denial of due process under the Fifth, and "arbitrary and capricious" agency action under ordinary administrative law. Any one of those would have been enough. Lin wrote that "though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless."
Then she took the factual premise apart. The evidence that the company posed a national security risk, she said, was "slim" — NPR, which discloses that the company is one of its financial supporters, described her rebuke as scathing — and the real motive appeared to be retaliation for public criticism. She noted that the same administration had floated applying the Defense Production Act to the company, "which would mean the company was essential to national security rather than a threat to it." You cannot easily be both the indispensable supplier and the saboteur in the same season.
And the technical story collapsed entirely. The designation leaned on the idea that the vendor retained some hold over models already installed on military systems — a backdoor, a kill switch, a way back in. The court found the alleged danger "entirely unfounded": those deployed models are static, and the company cannot remotely access, modify, update, or disable them. The Pentagon had blacklisted a firm over powers the firm did not have.
Now hold that word "supply chain risk" up to the light, because the gap between what it means in law and what it was used for here is the whole story. The statute defines it as the risk that "an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert" a covered system — to surveil it, deny it, disrupt it, degrade it. That is a counter-espionage tool. It was built for the possibility that a hostile state has gotten inside your radar software. It was not built for a vendor who will not sign your terms.
What were those terms? The company had declined two specific uses: mass domestic surveillance, which it called "incompatible with democratic values," and fully autonomous weapons — "those that take humans out of the loop entirely and automate selecting and engaging targets" — on the stated ground that "today, frontier AI systems are simply not reliable enough to power fully autonomous weapons." Whatever you think of a company drawing that line, notice that neither refusal is a claim about sabotage. Nobody, at any point, alleged an adversary was inside the code.
So: comprehensive win, on the law and on the facts. Here is where I would have stopped in June.
Then why is the software still being torn out?
Because the government did not punish the company once. It punished it twice, under two different statutes, and those two statutes are reviewed in two different courtrooms.
The clearest account of the split I have found comes from the procurement lawyers tracking it, and it is worth reading slowly. One designation letter invoked 10 U.S.C. § 3252, the narrower Department of War supply-chain statute. A second letter, signed the same day, invoked 41 U.S.C. § 4713 — the Federal Acquisition Supply Chain Security Act, which reaches across the whole federal procurement system. Under a separate review statute, that second one does not go to a district court at all; it goes straight to the D.C. Circuit Court of Appeals on direct review.
So the company had to fight on two fronts. The § 3252 designation, along with the presidential directive and the Hegseth directive, went to Judge Lin in California. The § 4713 designation went to Washington. In April the D.C. Circuit declined to pause that one and set argument for May 19, 2026.
Judge Lin's ruling — the sweeping, quotable, three-grounds ruling — resolved the California track. It did not touch the Washington one, because the Washington one was never in front of her.
Which brings us to the days right after the ruling, and to a sequence I would find hard to believe if it were not on the record. Within a week, the Pentagon's own research and engineering chief posted publicly that the company "is still a designated supply chain risk" at the department and across the defense industrial base, signing off with "Thank you for your attention to this matter!" A day earlier, the Commerce Secretary had told Bloomberg that the company and the government were "in tune together." Jessica Tillipman, an associate dean at George Washington University Law School who works on procurement, gave the assessment I keep coming back to: "It seems contradictory because it is." She added that "none of this has made sense because designating Anthropic as a supply chain risk never made sense." She is not, to be clear, predicting the company wins — she has also named the courts' built-in deference on national security as the hardest thing standing in its way.
Meanwhile the clock that was set in the spring keeps running. An internal memo from the Pentagon's chief information officer, dated March 6, 2026, told commanders to remove the company's products within 180 days — from key national security systems including those for nuclear weapons, ballistic missile defense, and cyber warfare — on the stated basis that the software "presents an unacceptable supply chain risk for use in all [Department of War] systems and networks." Since July 6, contractors have been under a requirement to strip all of the company's products out of their systems by September 29, 2026.
That date has not moved. The ruling that called the underlying punishment illegal and baseless landed thirty-three days before it, and did not move it.
And the people actually doing the removing are not lawyers at a frontier lab. They are compliance staff at defense contractors, working through a patchwork of certification demands that do not match each other — different agencies, and even different offices inside the same agency, sending materially different requests with different deadlines, different scopes, and different language. Some are a checkbox. Some are a multi-part questionnaire. Every one of them has to be read line by line by somebody whose job is not this. To be fair about the scope, since the early announcements were much broader than the rule turned out to be: what contractors have to strip is the company's software from work done on Department of War contracts, not from their businesses entire.
To be clear about what the ruling did accomplish, because it is more than the September 29 date makes it look: it vacated the § 3252 designation, and it vacated the Hegseth directive that imposed the contractor boycott in the first place — an instrument that had already been under injunction since the spring, and has stayed there. It put the constitutional question on the record in a way an appeals court now has to engage with. That is not nothing; it is a great deal.
Which sharpens the puzzle rather than settling it. Look at the calendar again. The contractor requirement that runs out on September 29 was issued in July — months after the directive that originally told contractors to cut ties had been enjoined. It did not need that directive, because by then the department was resting on the separate § 4713 designation, the one that has never been in front of Judge Lin. Whether that works — whether a determination under the surviving statute can be carried out consistently with an injunction against the directive that ordered it — is, in the words of a law professor who filed a brief supporting the company in this case, a question the government will have to answer. Nobody has answered it. No court has ruled on the merits of the surviving designation. Nobody has stopped the clock.
So if your mental model was "judge rules it illegal, therefore it stops," the machinery does not work that way, and it did not work that way here.
The Pentagon's case, made as strongly as I can make it
I want to give the other side its best run, and in this instance I can do it in the government's own words rather than my paraphrase of them.
The under secretary of war for research and engineering — the department's chief technology officer, Emil Michael — described reading the contract six months into the job and being genuinely startled by it. "'You can't use AI for battlefield management.' I was like, 'What does that mean?' 'You can't use AI to defend yourself from a missile attack.' What?" And then the analogy that is doing the real work: "We'll use it lawfully, for all lawful purposes, but it's artificial general intelligence. You don't get to tell me where I could fly a plane to. We decide when we buy a plane from Boeing or Lockheed."
Sit with the missile-defense example, because it is the strongest thing anyone has said in this fight. Incoming-missile defense is close to the paradigm case for automation: the decision window is measured in seconds, a human in the loop may be physically incapable of contributing anything but delay, and the target is a missile, not a person. If a usage clause written in general terms sweeps that in, then the clause is badly drafted, and a Defense Department that pushes back on it is doing its job. "Autonomous weapons" is a phrase that covers both a loitering drone selecting human targets and a system shooting down a warhead over a city. Those are not the same moral object, and a contract that treats them identically deserves to be renegotiated.
The Boeing analogy has force too. When the government buys an aircraft, the manufacturer does not retain a veto over the missions it flies. There is something genuinely novel — and, if you are the buyer, genuinely irritating — about a supplier claiming continuing authority over the use of a delivered product. Reasonable people can find that unacceptable in a defense context without being authoritarian about it.
So far so good, and I mean that. Here is where it comes apart.
Every word of that is an argument for renegotiating a contract, or for not renewing it, or for buying from somebody else. It is not an argument for a supply chain risk designation, because that instrument does not mean "this vendor is difficult." It means an adversary may be subverting your systems. Judge Lin left the government entirely free to stop buying the software through ordinary procurement — nobody has a constitutional right to a federal contract. The problem was never that the Pentagon wanted a different vendor. It is that it reached for a counter-espionage label to get one, and then extended that label outward to a company's other customers.
That over-reach is not only my reading. Tess Bridgeman, a co-editor-in-chief of Just Security, worked through the statute and concluded that the designation "does not give the Secretary the power to prohibit defense contractors from engaging in 'any commercial activity' with the designated company" — that "the powers granted by Congress are far more narrow," that "this provision of law is not a sanctions authority," and that designating an American-owned and operated company this way "appears to be without precedent." A tool built to keep foreign intelligence services out of weapons systems was pointed at a domestic vendor in a terms-of-service dispute.
One more thing belongs in the government's column, and it is strong enough that I would rather quote it than summarize it. When the company asked the D.C. Circuit to pause the second designation in April, the panel refused — and it was careful to say what it was and was not deciding: "we do not broach the merits at this time, for Anthropic has not shown that the balance of equities cuts in its favor."
What those equities looked like from that bench is worth sitting with. A stay, the panel reasoned, would "force the United States military to prolong its dealings with an unwanted vendor of critical AI services in the middle of a significant ongoing military conflict," set against what it called a "relatively contained risk of financial harm to a single private company." And it went directly at the framing I have been using on you for two thousand words: "Anthropic casts its interests partly in constitutional terms, but those interests seem primarily financial in nature."
I am going to let that sit there rather than talk you out of it. It is not a holding that the designation is lawful — the panel said outright it was not reaching the merits, and no merits decision has issued since. But it is a federal appeals court weighing remedy against national security, in wartime, and coming out for the government. Two courts looked at this dispute and saw different things: one saw retaliation dressed up as security, the other saw a military being told by a judge who it had to keep buying from during a shooting war. A piece that quoted only Judge Lin would be hiding half of that from you.
What neither court has done is stop the removal. And that is why the remedy gap matters more than the merits: if the government can obtain the practical result it wants through a second authority while the first one is being litigated, then winning on the first authority is a paperwork event.
Britain wrote the pause into its statute
Here is the comparison that reframed this for me, and it is not a story about Britain being wiser. It is a story about one specific design decision that Parliament made and Congress did not.
The United Kingdom runs a central debarment list — a public register of suppliers that public bodies must or may exclude from contracts. It is the closest structural parallel to what happened here: a government deciding, centrally, that a particular company should be cut out of public work.
Now look at how a company gets onto it. Under the Procurement Act 2023, a Minister "may not enter a supplier's name on the debarment list before the end of the period of eight working days beginning with the day on which the Minister gives notice". That window has a name in the statute — the debarment standstill period — and it exists for one reason: so the decision does not take effect before the supplier has a chance to do something about it.
What can the supplier do inside those eight days? It can go to court and ask for the listing to be suspended. The court then weighs the public interest in keeping risky suppliers away from public contracts against the supplier's own interests, including the financial damage of being listed, plus anything else the court thinks relevant.
I want to be precise here, because this gets overstated in the summaries and the overstatement would flatter my argument. This is not an automatic suspension. The court has real discretion and can refuse. The supplier can lose. What the statute guarantees is narrower and, I think, more interesting: the punishment does not begin until a judge has had the opportunity to look at it. The sequence is notice, then pause, then a chance at judicial review, then effect.
Compare the sequence we just watched. Designation and public announcement first. Removal clock started within days. Litigation running for six months underneath a purge that never paused. A comprehensive constitutional ruling arriving in month six — and a second, parallel designation carrying the practical consequences onward past it.
The British design is not more sympathetic to suppliers. It is simply ordered differently, and the ordering is the entire protection. Put review before effect and a wrongful listing costs the company eight days. Put effect before review and a wrongful designation costs it a year, its defense business, and a rip-out of its software from customers who were never accused of anything — with the court's vindication arriving after the systems are already gone.
Now run it forward, because somebody in a general counsel's office already has
Play this out the boring way, which is the way it actually goes.
It is 2028. An agency wants something from a vendor that the vendor's terms of service do not allow. The lawyers on the government side have read this case closely — that is their job — and the lesson they have drawn is not "do not retaliate." The lesson is use more than one authority. Designate under the narrow statute and the broad one. Let the company sue. It will have to sue twice, in two courts, on two schedules, and it will need to win both to get relief that means anything. Meanwhile the operational order — remove the product, certify that you have removed it, report by this date — runs on its own track and answers to neither judge.
Nobody in that story does anything cartoonishly evil. Each individual step has a memo behind it and a statute cited at the top. The vendor may well win, eventually, in both forums, and by then the customers are gone and the engineers have been reassigned and the replacement product is embedded in nine hundred systems. Reinstatement is not a thing that happens to software that has been ripped out.
And the vendor after that one will not litigate at all. It will look at the eighteen months, the two appellate tracks, the certification questionnaires landing on every one of its enterprise customers, and it will do the arithmetic that any board does. It will sign the terms. Not because it was persuaded — because the process is the punishment, and the process runs whether or not the underlying decision was lawful.
That is the future I would like us to avoid, and the thing standing between us and it is not a better court ruling. We just got an excellent court ruling. It is sequencing.
What the smart people are saying
The most striking feature of this fight is the coalition it produced, and I would not have predicted it.
When the case was in the district court, a group of organizations that agree on very little else filed on the same side: the Foundation for Individual Rights and Expression led the brief, joined by the Electronic Frontier Foundation, the Cato Institute, Chamber of Progress, and the First Amendment Lawyers Association. A civil-liberties organization, a digital-rights group, a libertarian think tank, and a tech-industry association do not usually appear on the same signature page. When they do, the partisan reading of the dispute is almost certainly the wrong one.
From the libertarian right, Reason's J.D. Tuccille put the principle in terms that do not depend on liking the company at all: vendors "have the right to do business with whoever they please, and to put conditions on the purchase of their goods and services," and buyers have a matching right to choose among vendors — but "when government officials go further and use their power to punish private businesses that won't sell them what they want, they may run afoul of constitutionally protected rights." That is a market argument, not a progressive one, and it lands in the same place.
The most useful thing I read, though, was written in March, months before the ruling, and it turned out to be a map of exactly this problem. Writing at Lawfare, Alan Z. Rozenshtein argued that a remedy in this case would have to reach past the designation itself — that a court "should set aside the supply chain risk designation and enjoin agencies from implementing the government-wide ban," and, critically, should "prohibit the Defense Department from pressuring defense contractors to sever commercial relationships with Anthropic," while leaving the government "free to stop buying from Anthropic through ordinary procurement channels."
Read that list again with the calendar in hand. He identified in March that the designation was the smallest part of the injury, and that the contractor pressure was where the real damage lived. Five months later a judge gave him very nearly the remedy he had specified, the order against pressuring contractors included — and the contractor purge is still running to a September 29 deadline anyway, carried by the one designation that was in a different court the whole time. He called the shape of the problem before it happened. What he could not have called is that identifying the right remedy, and winning it, would turn out not to be the same thing as getting it.
What does this mean for you?
You are not a defense contractor and you are not negotiating usage clauses with the Department of War. Here is why it still reaches you.
Separate "who won" from "what changed." This is the transferable skill, and it applies far beyond AI policy. When you read that a court struck something down, the useful follow-up question is never "was it unconstitutional?" It is: what stopped, on what date, for whom? A vacated designation, an enjoined directive, and a removal deadline that never moved can all be true at once. Headlines report verdicts. Consequences live in the operational orders underneath them.
Notice when a national security label is doing non-security work. The words in the statute describe an adversary subverting a weapons system. If you see that vocabulary attached to a pricing fight, a terms-of-service dispute, or a company somebody in office finds annoying, the label has been borrowed. That borrowing is the thing to object to loudly, and it is much easier to object to before it becomes routine than after.
Watch the sequencing, not just the substance, when your state writes its own version. Plenty of state legislatures are now drafting procurement bans and vendor-exclusion rules for AI systems. The question worth asking your representative is boring and decisive: does the exclusion take effect before or after somebody can challenge it? Eight working days of standstill, as in the British statute, is not a radical civil-liberties demand. It is a scheduling choice, and it is nearly free.
Do not let this become a story about whether you like this company. I have been skeptical of large AI firms for years and I remain so — a corporation's usage policy is not a civil-rights framework, and it can be revised by the same board that wrote it. But the precedent set by punishing this refusal will be available against the next company, the next nonprofit, the next university that declines to hand over what an agency wants. Precedents do not stay pointed at the party that earned them.
If you work somewhere that certifies things, read what you are signing. The certification requests going out over this are inconsistent by agency and sometimes by office, and some prime contractors have rewritten the government's language into their own. If one of these lands on your desk, the line-by-line reading is not bureaucratic caution. It is the whole job.
What we actually won
I came back to this story expecting to write about vindication, and I have ended up writing about scheduling. That is less satisfying and, I have come to think, considerably more important.
We spend enormous public energy arguing about whether government actions are constitutional. We spend almost none on the question of when a determination arrives relative to the harm — and that second question is doing most of the work. A right that is confirmed after the software is gone, the customers have fled, and the replacement is installed is a right in the way that a receipt is a meal. Judge Lin wrote that the Constitution does not permit sweeping penalties based on a company's criticism of the administration. She was correct, she was emphatic, and the penalties are being carried out to their original timetable while the sentence is still warm.
The fix is not heroism, and it is not a better judge. It is an eight-day pause written into the statute before the punishment starts — a piece of legislative plumbing so unglamorous that no one will ever campaign on it. Congress could add a standstill to these exclusion authorities in a paragraph. Until it does, the honest description of the protection you have is this: the government may punish first and be told later, and "later" is measured against a calendar it controls.
We got the ruling this time. It is worth having. But if the punishment finishes on schedule anyway, then what we actually won was an excellent piece of writing about our rights — and I would rather have the eight days.
A verdict that arrives after the consequences is a very expensive way to be told you were right. HAIA reads the operational orders under the headlines, and posts what it finds here.




