A Federal Judge Just Said the Government’s Case Against Anthropic Has Gotten Worse
The Trump administration has been trying since February 2026 to label Anthropic a national security threat. Four months later, a federal judge told the government its case has not improved. It has gotten worse.
U.S. District Judge Rita Lin made that assessment within the first five minutes of opening a July 30, 2026 summary judgment hearing in San Francisco. “I don’t see additional evidence from the government really justifying what it did,” she said. “If anything, it seems like the record, in some ways, has gotten worse for the government.”
No ruling was issued on the day. Lin said she expects to issue a decision within days. But her opening statement left little ambiguity about which direction she is leaning.
How This Started
The dispute goes back to January 2026, when the Department of Defense and Anthropic clashed over the terms of an AI contract. Anthropic said it would not allow its Claude models to be used for two specific purposes: mass domestic surveillance of Americans, and targeting or firing decisions in fully autonomous lethal weapons without a human in the loop.
The Pentagon’s position was that a private company should not be able to dictate how the military uses technology it has contracted for. DOD said it would use the tools in “lawful” ways and that existing restrictions already covered those particular uses.
Negotiations broke down. Then things escalated quickly.
On February 27, 2026, President Trump directed all federal agencies to immediately stop using Anthropic’s technology. The same day, Defense Secretary Pete Hegseth announced the Pentagon would designate Anthropic a supply-chain risk to national security, invoking a statute typically reserved for foreign adversaries and hostile intelligence agencies.
Anthropic filed two lawsuits in March challenging both actions. One was filed in the Northern District of California under 10 USC 3252. A parallel case was filed in Washington under 41 USC 4713, which requires those claims to be heard in the DC Circuit.
The March Injunction
Judge Lin held an initial hearing in March. Her language during that session was pointed. The Pentagon’s actions looked like “an attempt to cripple Anthropic,” she said. “Nothing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.”
On March 26, 2026, Lin issued a preliminary injunction blocking the supply-chain risk designation and halting Trump’s directive ordering agencies to cut ties with Anthropic. She described the Pentagon’s use of the supply-chain risk statute, normally aimed at foreign threats, as “broad punitive measures” that did not track the government’s stated national security interests.
The government appealed. Lin stayed her ruling for seven days to allow the appeal process to begin. The preliminary injunction remained in effect as the case moved toward summary judgment.
What Happened at the July 30 Hearing
Thursday’s 2.5-hour session was a summary judgment hearing, meaning both sides asked the court for a final decision on the merits based on the existing record. Lin had pre-filed a list of five formal questions she wanted counsel to address. One of them asked directly whether accepting the government’s argument would “eviscerate First Amendment protections” for defense contractors as a class.
The government’s main arguments at the hearing were two. First, that Anthropic’s public criticism of the Pentagon had created a “lack of trust” that justified the designation. Second, that Anthropic could potentially disable or alter its AI models during warfighting operations, creating a genuine security risk.
Lin challenged both arguments directly.
On the first, she said accepting the logic that contractors lose federal protection when they criticize the government publicly would set a dangerous precedent. “Punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation,” she said. The government’s shifting rationales across different stages of the case, Lin noted, was “powerful evidence of pretext.”
On the second, she said she saw no proof at all. There was no evidence, Lin said, that Anthropic could alter a delivered model or “flip some kind of kill switch” during active operations. She also noted a contradiction she found hard to ignore: if the government genuinely believes Anthropic is a security threat capable of poisoning its own AI models, it seemed “inconsistent” that agencies were simultaneously maintaining or expanding their use of those same models.
The Pentagon confirmed in court that it continues to wind down its use of Anthropic products and expects to complete that process by September 30. Several pilot programs at other agencies are scheduled to expire August 30. But Anthropic’s lawyer told the court that most agencies had continued working with Anthropic, two had paused negotiations for new contracts, and others were actively negotiating new deals.
What Is at Stake Beyond Anthropic
This case has always been larger than one company’s government contracts.
The question Lin raised about First Amendment protections for contractors applies to every technology company that does business with the federal government. If the government can designate an AI company a national security risk because it publicly disagreed with how the Pentagon wanted to use its products, the same logic could be applied to any contractor in any sector that criticized a government contracting position.
Senator Chris Coons, ranking member of the Senate Appropriations Subcommittee on Defense, put it plainly in February: “The Trump administration’s decision to label Anthropic a supply chain risk weakens free enterprise, harms innovation, and makes Americans less safe.”
Anthropic’s Claude AI is used across federal agencies for research, analysis, and productivity work. The company has partnered with the Pentagon since 2024. Without the injunction still in place, Anthropic said in filings that it could lose billions of dollars in business and suffer significant reputational harm as a defense contractor.
Lin has not yet issued her final ruling. When she does, it will mark the next major chapter in a legal battle that is expected to continue regardless of how she rules, with appeals likely from whichever side loses.
