AI

A court just ruled that an AI company’s usage limits are protected speech

Judge Rita Lin vacated the Pentagon’s supply-chain-risk designation on Anthropic, found First and Fifth Amendment violations, and issued a permanent injunction. Fifty-nine pages. The fight started over whether a vendor is allowed to say no.

N Noah · The Sharp Brief · August 28, 2026 · 4 min read

A federal judge ruled this week that the Pentagon’s blacklisting of Anthropic was unlawful, ordered the government to rescind the directives it issued against the company, and barred it from giving them effect.

U.S. District Judge Rita Lin of the Northern District of California found that officials had retaliated against the AI company in violation of the First Amendment, and had stripped it of liberty interests without adequate notice or a meaningful chance to respond, in violation of the Fifth Amendment’s due process clause. She set aside the national-security supply-chain-risk designation that Defense Secretary Pete Hegseth had placed on the company and issued a permanent injunction. The opinion runs 59 pages.

An “empty invocation of national security,” Lin wrote, “is not a blank check.”

What the fight was actually about

The dispute is a contract dispute wearing national-security clothing. Anthropic held a $200 million agreement with the Pentagon, and as of February its Claude models were the only large language models cleared for the military’s classified systems.

The company pushed for contractual limits barring the use of its models in fully autonomous lethal weapons systems and in domestic mass surveillance of Americans. The Defense Department rejected that position on the grounds that a corporate contractor has no authority to write military operating rules. In February, the administration designated the company a supply chain risk.

Anthropic argued the designation was retaliation for refusing to drop those restrictions. The court agreed.

Our take: The interesting part is not that a company won a procurement fight. It is which clause the court protected. Anthropic’s acceptable-use terms were treated as expression — a position the company took, not merely a product specification it shipped. That reframes every usage policy at every frontier lab from a legal liability into a defensible one. Until Friday, writing a hard restriction into a federal contract was a commercial risk with no floor under it. There is now a floor. Expect the terms sheets to get more specific, not less.

Why it lands beyond one company

Model providers have spent two years discovering that their real leverage over how their systems get used is contractual, not technical. Weights can be fine-tuned; access can be resold; guardrails can be stripped by a determined customer with enough compute. The clause is the control surface.

That control surface only works if the vendor can hold it without being removed from the market for doing so. A designation like the one at issue here does not require a finding of wrongdoing to be devastating — it travels to every other agency, every prime contractor, and every risk committee that reads a federal list. The due-process half of the ruling matters as much as the speech half: the court’s objection was partly that the company never got a real chance to answer.

It also arrives into a market where capital is flooding into AI infrastructure and where the question of who can sell what to whom — including across borders — is being settled case by case rather than by statute.

What to watch

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.