On February 27, Defense Secretary Pete Hegseth designated Anthropic a supply chain risk under an authority designed for foreign adversaries — the first time the federal government had ever applied that label to an American company. The reason, as documented in six months of subsequent litigation, was that Anthropic had refused to accept Pentagon contract terms requiring it to strip Claude of restrictions preventing its use in fully autonomous weapons systems and mass domestic surveillance programs. On Thursday, U.S. District Judge Rita Lin ruled the designation unconstitutional — an act of First Amendment retaliation dressed in national security language, with no factual basis supporting the threat it claimed to address. That same week, NSA Deputy Director Tim Kosiba told an intelligence conference in Bethesda: “We want access to all the models, and we’re going to take advantage of that.” Those two facts, placed next to each other, describe the actual state of AI governance in August 2026 more precisely than either does alone.
The Designation That Couldn’t Survive Scrutiny
The supply chain risk authority Hegseth invoked was built for scenarios like adversarial telecommunications hardware or software with undisclosed foreign-government backdoors — vectors through which a rival state might embed surveillance or sabotage inside critical American infrastructure. The NDAA provisions enabling it were designed for situations involving foreign adversaries with access to U.S. systems. Anthropic is a San Francisco company whose safety position is published on its public website. Hegseth applied the authority anyway, and the government that had never previously used the designation against an American company deployed it in February to punish one for a policy disagreement.
The practical stakes were significant. The designation blocked Anthropic from new federal defense contracts and required existing Pentagon deployments of Claude to be removed entirely by end of September 2026. CEO Dario Amodei described the scope as “narrow” relative to the company’s $14 billion projected annual revenue, most of which comes from commercial and non-military government customers. But the symbolic exposure was larger than the economics: if the supply chain risk authority could be deployed against any domestic AI lab for any publicly expressed position the administration opposed, every lab was looking at a new category of political risk with no obvious upper bound.
The specific dispute turned on what the Pentagon characterized as “all lawful uses” of Claude. Defense officials insisted Anthropic remove restrictions preventing Claude from supporting fully autonomous weapons systems — platforms that select and engage targets without human authorization — and mass surveillance programs targeting domestic populations. Amodei stated publicly that the company “cannot in good conscience accede” to those demands regardless of their legal status. Anthropic’s argument was that a government action being technically lawful does not obligate a private contractor to build toward it, and that its model’s design constraints were a legitimate business and ethical position, not insubordination.
The government’s own legal defense was internally contradictory in a way Judge Lin found dispositive. Before the designation, Hegseth had threatened to invoke the Defense Production Act against Anthropic — a statute the government uses to compel production from companies it considers essential to national security. The Defense Production Act is for companies you cannot afford to lose. The supply chain risk label is for companies you need to remove from your systems. Hegseth reached for both simultaneously, and the contradiction was documented in the court record: the government that argued Anthropic was indispensable also argued it was a threat. Lin noted the contradiction directly.

The timing of the designation itself undermined the claimed rationale. According to Lin’s ruling, Hegseth publicly ordered the supply chain risk designation before the required internal analysis had been completed — the public order preceded the process designed to support it. President Trump contributed context at the time: he publicly declared his administration would “NEVER ALLOW A RADICAL LEFT, WOKE COMPANY” to dictate military AI policy. The paper trail of intent ran ahead of the bureaucratic justification, which is the clearest possible signal that the designation was not a genuine national security determination.
What Judge Lin Found
Lin’s opinion is direct. “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote. The government had argued that judicial deference to national security determinations should effectively shield the designation from review — a reading of executive authority that would have made designations of this type unreviewable in practice. Lin rejected that reading. Deference is owed when the government produces evidence of an actual threat. It is not owed when the government produces post-hoc justifications for a decision reached on different grounds, and when its own conduct contradicts the claimed rationale.
“An IT vendor does not become a potential adversary simply by raising concerns about contracting terms,” the ruling states. Anthropic’s position — that it would not strip restrictions on Claude’s use in autonomous weapons and mass surveillance — was a written, public position stated in Amodei’s name. The government characterized it as insubordination that justified a national security response. Lin found it was protected speech, and that penalizing it through administrative authority was viewpoint-based retaliation. The ruling also found the Pentagon had “failed to explore less-restrictive alternatives” before reaching for a designation authority designed for foreign adversaries.
The specific finding that Hegseth’s designation reflected a desire to “make a public example out of Anthropic for its ‘arrogance’ in criticizing the government” is drawn from the government’s own internal communications and public statements. “None of that is consistent with a genuine fear that Anthropic is a saboteur,” Lin concluded. The ruling vacated the designation and barred the administration from enforcing the measures Anthropic challenged.

The precedential weight here runs in both directions. The ruling is significant for AI governance because it establishes that First Amendment protection extends to AI companies’ public policy positions in contractual disputes with the government — that having a published position on what your model will and won’t do is protected speech, not a basis for administrative retaliation. It is also significant because no company had ever needed to establish that protection before February 27. The government is expected to appeal Lin’s ruling. A second Anthropic lawsuit remains pending before the D.C. federal appellate court, challenging the designation on a separate legal basis. The full legal resolution is not yet complete, but the first judicial test of this authority produced a clear answer.
The Intelligence Community’s Parallel Track
The ruling addresses what the government cannot do through the overt, administratively designated, legally reviewable channel. It is less relevant to what the intelligence community has been building through a parallel track. The June executive order that established a voluntary pre-release AI testing framework gave NSA and other agencies a standing access mechanism for commercial AI models that does not go through the public procurement system, does not require contract terms that AI labs can refuse, and is not subject to the First Amendment constraints that Lin’s ruling applies to administrative designations. Under this framework, the NSA is already running Anthropic’s Mythos model experimentally. OpenAI’s GPT-5.6 is FedRAMP-eligible and available to federal customers through the commercial channel. The relationship between AI labs and the intelligence community is already established, through mechanisms that don’t involve anyone invoking supply chain risk authority.
Kosiba’s statement Thursday was explicit about the scope of the ambition. “We want access to all the models, and we’re going to take advantage of that.” He did not specify which companies are currently participating in voluntary pre-release testing or confirm whether any lab has provided unreleased systems. What he described is the goal: comprehensive access, through whatever channels are available and legal. The voluntary framework is one such channel. FedRAMP eligibility is another. Standing experimental programs like the Mythos deployment are a third. None of these required a supply chain risk designation, and none of them are blocked by Lin’s ruling.
The counter-argument matters and should be stated plainly: voluntary means the labs can say no. Anthropic demonstrated this capacity by holding its position on autonomous weapons and surveillance for six months against considerable political and financial pressure, absorbing the blacklist risk rather than removing its restrictions. The ruling establishes that the government cannot escalate past a lab’s refusal with a bigger administrative stick — that is a meaningful constraint on what coercion is available. Whether it changes the trajectory of AI access by the intelligence community is a different question. The NSA was already inside before the ruling. It said publicly on Thursday that it intends to be inside further.
Anthropic said Thursday it “remains focused on productive government collaboration for national security AI applications.” That statement is not a contradiction of the litigation — it is a description of what the company actually wants. It drew a line at autonomous weapons and mass surveillance. It held that line through a federal case. It is still in business with the government that tried to punish it for the line. Courts can block the overt retaliation. What the voluntary frameworks the intelligence community builds alongside those courts look like, and whether the labs’ participation in them remains genuinely unconstrained, is the story that follows. The NSA’s deputy director already told you what it wants. Round one resolved in court. The rest of the relationship is being built outside it.

AI-generated editorial illustration · TemperatureZero · August 29, 2026
Keep reading the signal
Get the Daily Signal — a concise briefing on what actually matters in AI and the systems around it.
Subscribe FreeContinue the archive