← Back to all posts
News

The Memo Banning Anthropic Was Dated Three Days After the Ban

August 29, 2026 · 01:12 UTC · News
The Memo Banning Anthropic Was Dated Three Days After the Ban

TL;DR

On August 27, Judge Rita F. Lin of the Northern District of California signed a 59-page order granting Anthropic summary judgment against the U.S. Department of War on its First Amendment, Fifth Amendment due process, and Administrative Procedure Act claims. The supply chain risk designation that had barred Anthropic from federal contracts since March is vacated and set aside. The order banning every defense contractor from doing any business with the company is vacated too. The court denied the government even a seven-day administrative stay, and the case was terminated the same day. The entire written rationale the government produced for all of this was a four-page memo, and it is dated three days after the ban was already public.


The sequence is the whole story

Here is the order of operations, taken from the administrative record the government itself filed.

On February 27, President Trump directed all federal agencies to permanently stop using Anthropic's products. About an hour later, Secretary of War Pete Hegseth posted on X that "effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic." On March 2, Under Secretary Emil Michael signed the four-page memorandum that the court calls the sole analysis supporting the designation. On March 3, the formal supply chain risk designation issued under 10 U.S.C. 3252.

the justification post-dates the punishment FEB 272 directives MAR 2memo written MAR 3designation AUG 27vacated before mar 2, DoW had identified no supply chain risk at all
The paperwork supporting the ban was written after two of the three actions it justifies.

This matters more than it might sound. Under the APA, a court reviewing an agency action grades only the reasoning the agency had at the time. It is a receipt check at the exit: you show the receipt you were holding when you walked out, not one you print in the parking lot afterward. A rationale assembled after the decision is the textbook definition of post-hoc justification, and the record here shows that before March 2 the Department of War had not identified any supply chain risk posed by Anthropic whatsoever.

The government dropped its own technical case

The Michael Memo's central worry was that Anthropic retained backdoor access to its models once deployed inside national security systems and could disable or poison them. By the summary judgment stage the government had abandoned that theory. Lin writes that it is now undisputed that Anthropic lacks any such access, and that the government concedes Anthropic's technology "is itself no riskier to the national security than any other black box artificial intelligence model."

Strip that out and one factor unique to Anthropic remained: trust. The government's position was that because of Anthropic's "increasingly hostile manner through the press" and its criticism of the Department's views on AI, it could not trust the company to ensure the integrity of its models. The court's answer runs to 59 pages, but the operative sentence is short.

The empty invocation of national security is not a blank check to punish and retaliate against government critics.

Two details in the record do a lot of work. A few days before the designation, Hegseth had proposed applying the Defense Production Act to Anthropic, a statute you reach for when a company is too important to lose, not when it is a saboteur. And immediately after the ban, the Department kept negotiating a contract with Anthropic, telling the company "we are very close here." The order also notes the government is currently discussing collaboration with Anthropic on its new model, Mythos, in sensitive contexts. Lin's read: none of that is consistent with genuine fear of a saboteur.

What set it off: two lines in a usage policy

The underlying dispute was contractual. In July 2025, Anthropic won a two-year agreement worth up to $200 million from the Department's Chief Digital and Artificial Intelligence Office, and Claude became the first frontier model cleared for classified networks. In August 2025, a GSA agreement extended Claude Gov to the civilian executive, legislative, and judicial branches. The Department agreed to abide by Anthropic's acceptable use policy.

In February 2026 the Department wanted the restrictions gone, demanding access "for every LAWFUL purpose." Anthropic held two red lines: no mass domestic surveillance of Americans, and no fully autonomous weapons that select and engage targets without human intervention. It declined, and offered to help transition to another vendor if the parties could not agree. Three days later the President and the Secretary of War took to social media.

What it cost while it was in force

harm claimed in the record (Dkt. 166-2, 166-3) $200M2-yr CDAO deal, Jul 2025 100+enterprise customers asked 50-100%DoW-linked revenue at risk anthropic also projected 2026 revenue down by multiple billions
Anthropic's own declarations on the damage, filed under the summary judgment motion.

The blast radius went past Anthropic. Defense contractors running Claude-integrated APIs started assessing whether they had to rip it out. One partner with a multi-million-dollar annual contract swapped to a competing model to keep servicing a Food and Drug Administration engagement. Anthropic says it fielded inquiries from more than a hundred enterprise customers expressing "deep fear, confusion, and doubt" about associating with the company.

Trade associations for government contractors filed an amicus brief describing "contracts terminated, partnerships frozen, workflows thrown into disarray," and a compliance crisis for members whose products had Anthropic-assisted work embedded in them. Thirty-eight employees at major AI companies filed their own brief arguing the actions would chill open deliberation among exactly the people best positioned to understand catastrophic misuse.

Anthropic did not win everything

The scorecard is more interesting than the headline. Lin rejected the ultra vires separation of powers claim outright, and entered judgment for the government as to agencies that took no relevant action or only interim ones. On the APA Section 558 count, nine agencies had their implementing orders vacated and five did not.

Anthropic PBC v. U.S. Dept. of War, No. 3:26-cv-01996 (N.D. Cal.) Count I APA: designation + banVACATED Count II First AmendmentANTHROPIC WINS Count III ultra viresANTHROPIC LOSES Count IV Fifth Am. due processANTHROPIC WINS Count V APA sec. 558SPLIT: 9 OF 14 plus a permanent injunction; the 7-day stay request was denied
Count by count, from the four-page Order of Final Relief filed the same day.

The relief order is also narrower than the win suggests. Paragraph 14 says plainly that nothing bars the government from any lawful action available to it on February 27 before the challenged actions issued, and that the Department is not required to use Anthropic's products and remains free to move to another AI provider. The Department can still walk away. It just cannot brand the company a national security threat on the way out.

Why a builder should care

Strip away the politics and this ruling answers a question that has been hanging over every enterprise AI contract: is a model provider's acceptable use policy a liability or a defensible position?

For eighteen months the market read has been that safety restrictions are a commercial handicap, the thing a competitor undercuts you on. This order says the restrictions themselves are protected expressive activity, and that a customer, even one with a Cabinet secretary and a procurement statute, cannot punish you for holding them. That is a load off every vendor that has ever been told its terms of service are negotiable under pressure.

The second lesson is procedural and applies well beyond AI. The court pointed out that ordinary suspension and debarment rules already exist, including 48 C.F.R. 9.405-2(b), which restricts subcontracts above $45,000 with excluded contractors. There were less restrictive tools sitting right there. Reaching instead for an obscure sabotage statute normally aimed at foreign supply chain tampering, and announcing it on social media before the findings were written, is what turned a procurement dispute into a constitutional one.

Practical note if you sell into government or into defense primes: the designation is vacated but not extinct. It was remanded, a second suit over civilian contract exclusion is still live in Washington, and an appeal remains available. Treat this as durable relief rather than a closed file, and keep your vendor-substitution plan in the drawer.

Key Takeaways

  • Judge Rita Lin granted Anthropic summary judgment on its First Amendment, due process, and APA claims on August 27, vacating the supply chain risk designation and the contractor ban, and denying the government a seven-day stay.
  • The government's complete written justification was a four-page memo dated March 2, three days after the ban was announced on February 27 and one day before the formal designation.
  • The government conceded at summary judgment that Anthropic has no backdoor access to deployed models and is no riskier than any other black box AI system, leaving only its criticism of the Department as the basis for the action.
  • The trigger was Anthropic refusing to drop two usage-policy red lines: mass domestic surveillance of Americans, and fully autonomous lethal weapons.
  • Anthropic lost its ultra vires claim and won only 9 of 14 agencies on the APA Section 558 count, and the order expressly permits the Department to switch AI vendors through normal procurement.
  • Damage claimed while the ban stood: a $200 million CDAO agreement at risk, more than 100 enterprise customers raising concerns, and a projected 50-100 percent hit to defense-related revenue.

Sources: Order on Cross Motions for Summary Judgment, Dkt. 250 (N.D. Cal., Aug. 27, 2026), Order of Final Relief, Dkt. 251, NOTUS, Al Jazeera, Decrypt, Reason, Tech Policy Press timeline, Just Security

AIAnthropicPolicyClaudeLegalProcurementNational SecurityFirst Amendment
CONSOLE
$