AI Geopolitics Tech News

Anthropic Sues the Pentagon Monday

Federal courthouse columns

This is the fourth chapter of a story Laterstack has been tracking since February. The Pentagon threatened to revoke Anthropic’s $200 million contract over Claude’s restrictions on autonomous weapons and domestic surveillance. Anthropic refused. President Trump ordered a government-wide ban. Defense Secretary Pete Hegseth slapped the company with a “supply chain risk” designation, a label historically reserved for foreign adversaries. Last week, Silicon Valley picked a side. OpenAI picked the Pentagon.

Now it goes to court. On Monday, March 24 at 1:30 p.m., Judge Rita Lin will hear Anthropic’s request for a preliminary injunction in San Francisco federal court, according to the court docket. The question before her is narrow but the implications are not: should the supply chain risk designation be paused while the full case plays out?

The Legal Arguments

Anthropic filed two lawsuits on March 9, one in the Northern District of California and one in the D.C. Circuit Court of Appeals. The core claim is First Amendment retaliation, according to NPR. CEO Dario Amodei publicly refused to remove safety restrictions from Claude. The government responded by designating his company a national security threat. Anthropic says that sequence is not a coincidence. It is punishment for protected speech.

The DOJ’s 40-page rebuttal, filed March 17, says the opposite. Refusing to accept contract terms is conduct, not speech. The government argues that ruling otherwise would “extend First Amendment protection to every commercial transaction.” The Pentagon says Anthropic’s “red lines” on surveillance and autonomous weapons make the company an “unacceptable risk to national security” because it might disable its technology during operations.

That framing is worth sitting with. The Pentagon’s official position is that a company willing to say no to the military is, by definition, a security risk. Not because of espionage. Not because of foreign ties. Because it might exercise the contractual right to pull its own product.

The Damage So Far

Anthropic is bleeding. Its CFO told the court that the supply chain designation puts hundreds of millions to billions of dollars in 2026 revenue at risk. More than 100 enterprise customers contacted the company with concerns. A financial services firm paused a $50 million contract. A fintech company cut a $10 million deal in half. A pharmaceutical company shortened its contract by 10 months, according to Bloomberg.

The federal government has not waited for the court. The State Department already switched to OpenAI’s GPT-4.1 for its internal chatbot, according to Reuters. Treasury Secretary Scott Bessent confirmed his department is ending all Anthropic use. HHS followed. OpenAI expanded its federal footprint on March 17 with an AWS partnership for classified and unclassified government work.

Every agency that drops Anthropic validates the designation. Every contract that shrinks proves the irreparable harm Anthropic needs to demonstrate in court. The government is building its own case against itself. Whether Judge Lin sees it that way is another question.

The Coalition

What makes this hearing unusual is who showed up to support Anthropic. Microsoft filed an amicus brief warning that the designation could “hamper” U.S. warfighters by forcing abrupt changes to existing products. More than 30 employees from OpenAI and Google DeepMind, including Google chief scientist Jeff Dean, signed a separate brief warning that the blacklist threatens the entire American AI industry. Twenty-two retired generals and admirals, including former CIA Director Michael Hayden, cautioned that abrupt tool changes could harm troops in theater. Former federal judges appointed by both Republicans and Democrats raised concerns about the legal basis for the designation. Catholic ethicists filed their own brief.

On Capitol Hill, Senator Ron Wyden pledged to “pull out all the stops” to fight the ban and predicted bipartisan support, according to Bloomberg. Senate Armed Services Committee leaders from both parties sent a private letter urging the Pentagon to stand down, Axios reported. Representative Sam Liccardo introduced an amendment to the Defense Production Act that would prohibit agencies from retaliating against AI vendors.

Lawfare’s legal analysis was blunt: the statute was not built for this use, the facts do not support it, and the courts will say so.

What Monday Decides

Judge Lin is not ruling on the merits. She is deciding whether to freeze the supply chain designation while the case proceeds. But a freeze would be devastating to the government’s position. It would mean a federal judge looked at the evidence and concluded Anthropic would likely win. It would tell every agency that rushed to drop Anthropic that they jumped too early. And it would establish that labeling an American company a national security threat because it refused to remove product safeguards requires more than a press release from the Secretary of Defense.

The DOJ’s lawyer refused to commit to no further adverse actions before the hearing when Judge Lin asked, according to the East Bay Times. That refusal is itself a data point. If the government were confident in its legal position, there would be no reason to keep the threat open.

What This Means If You Just Use Claude

Most people following this story are not defense contractors. They are developers, writers, analysts, and small business owners who use Claude every day. So here is what the government did and did not have access to, and what Anthropic refused.

Anthropic’s Claude was already deployed across federal agencies for unclassified work. State Department used it for internal search. Treasury used it for policy analysis. HHS used it for data processing. The government had access to the commercial version of Claude, the same model available to any paying customer. It was not a special military build. There were no secret capabilities. It was the same Claude anyone can sign up for.

What Anthropic refused was a set of modifications the Pentagon wanted for classified and operational military use. Specifically, Anthropic would not remove restrictions that prevent Claude from being used for autonomous weapons targeting, where AI selects and engages targets without a human in the loop. Anthropic would not remove restrictions on domestic surveillance of American citizens. And Anthropic maintained contractual “red lines” that gave the company the right to pull its technology if it believed the deployment violated its safety policies.

The Pentagon labeled that refusal a supply chain risk. The designation, historically reserved for foreign adversaries like Huawei and Kaspersky, has never been applied to an American company. The logic: if Anthropic might pull its product during operations, it is unreliable. Unreliable means risky. Risky means banned.

OpenAI took the deal. CEO Sam Altman acknowledged the negotiations were “definitely rushed” but said OpenAI reached an agreement that includes “ethical safeguards.” What those safeguards are, specifically, has not been disclosed. What is public is that OpenAI agreed to operate in classified settings and did not maintain the same red lines Anthropic insisted on.

The Timeline

February 16: Pentagon threatens Anthropic’s $200M contract over Claude’s safety restrictions
February 26: Anthropic publicly refuses to remove guardrails
February 28: Trump orders six-month government-wide phase-out of Anthropic
February 28: OpenAI announces Pentagon deal, including classified deployment
March 1: Treasury Secretary Bessent confirms all Anthropic contracts terminated
March 3: State Department switches to OpenAI’s GPT-4.1
March 9: Anthropic files two lawsuits (N.D. Cal. and D.C. Circuit), alleging First Amendment retaliation
March 17: DOJ files 40-page rebuttal claiming “conduct not speech”
March 17: OpenAI expands government footprint with AWS partnership
March 18: Silicon Valley files amicus briefs supporting Anthropic
March 24: Preliminary injunction hearing, Judge Rita Lin, 1:30 PM, San Francisco

This story started with a $200 million contract and a company that said no. Five weeks later, it involves the First Amendment, national security law, the entire AI industry, both chambers of Congress, and a courtroom in San Francisco. The pattern from our previous coverage holds. The market punishes recklessness. The government punishes refusal. The question Monday is whether the courts will let it.