Anthropic won. That is not the same as getting the customer back.
TL;DR: On the evening of 27 August 2026, Judge Rita F. Lin (N.D. Cal.) issued a 59-page summary-judgment order vacating the Department of War’s designation of Anthropic as a supply chain risk and permanently enjoining the government from giving it effect — First Amendment retaliation, Fifth Amendment due process, and arbitrary-and-capricious agency action. Her words: the measures were “illegal and baseless.” Here is why that is not the story. Lin already enjoined this designation once, on 26 March. The Pentagon’s CTO publicly said it remained “in full force and effect” anyway, and on 1 May the department cleared eight AI vendors for IL6/IL7 classified networks with Anthropic absent. An injunction did not restore the channel. Meanwhile the practical ban ran wider than the statute ever authorised, because contractors comply with the broad reading when the downside is a supply-chain violation. For buyers: nothing about commercial Claude changed. What changed is that vendor political exposure is now a demonstrated, priced risk — and the checklist item belongs on every provider, not just this one.
What the order does
Three things, and the third is the one that matters legally.
It vacates the designation — the label is void, not merely unenforceable. It permanently enjoins the government from giving it effect, replacing the interim protection that had been running since spring. And it reaches beyond the Pentagon to the presidential directive that told federal agencies to stop using Claude altogether, which is what made this a government-wide problem rather than a defence-procurement one.
The findings are unusually blunt for an administrative-law opinion. Lin described the government’s evidence that Anthropic posed a national-security risk as “slim,” and concluded the designation was “based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model.” She held that neither constitutional nor statutory authority allows the government to “impose sweeping penalties based principally on Anthropic’s critique of the Administration’s views,” and summarised the whole exercise in a line the wires have quoted all day: “the empty invocation of national security is not a blank check to punish and retaliate against government critics.”
She was equally careful about what she was not holding. “Though the Department of War is undisputedly free to select the AI vendor of its choice,” she wrote, “the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless.” The government can still decline to buy Claude. It cannot brand the company a national-security threat for saying no.
Anthropic’s response was one sentence of welcome and one of continuity: “We welcome the court’s ruling that this supply chain risk designation was unlawful,” followed by a statement that the company remains focused on working productively with the government on national security. The White House did not immediately respond. The department is widely expected to appeal.
The part the coverage is skipping
Anthropic already had an injunction. It did not work.
Lin granted a preliminary injunction on 26 March 2026, finding Anthropic likely to succeed on all of its claims. A seven-day administrative stay expired on 2 April and the injunction took effect while the government’s Ninth Circuit appeal proceeded. On the civilian side it worked as designed: the GSA restored Anthropic to USAi.gov and to its Multiple Award Schedule.
On the defence side it did not. The Pentagon’s chief technology officer, Emil Michael, publicly said Lin’s order contained “dozens of factual errors” and asserted that the designation remained “in full force and effect,” on the theory that a Northern District of California ruling did not reach the separate government-wide exclusion authority. Whatever the merits of that reading, the effect was immediate: contractors received no reliable signal that the ban had lifted.
Five weeks later, on 1 May, the department cleared eight AI vendors for its IL6 and IL7 classified networks — SpaceX, OpenAI, Google, Nvidia, Microsoft, AWS, Reflection AI and Oracle. Anthropic, under a court order protecting it from exactly this treatment, was not on the list.
That is the load-bearing fact for anyone building a vendor-risk model. A court order is a slow instrument against a fast administrative one. The designation took effect in days. Unwinding it has taken six months and is not finished.
What six months of exclusion actually cost
The abstraction hides how ordinary the damage was. Per FedScoop’s reporting on the agency fallout: the Department of State moved immediately to implement the directive. HHS disabled enterprise Claude access department-wide, reversing a December 2025 rollout that had put Claude in front of every HHS staff member for $1 a year. Commerce dropped it for analytical report generation and data visualisation. The Energy Department’s Idaho National Laboratory dropped it for coding assistance. CBP dropped it for document summarisation.
None of those are classified weapons programmes. They are the exact mundane workloads any large organisation runs, and they were migrated off a working tool for reasons that had nothing to do with the tool. The GSA OneGov agreement that had made Claude available across the federal civilian, legislative and judicial branches for $1 ran through 10 August 2026 — it expired during the ban, unrenewed.
Migration costs, once paid, are not refunded by a favourable judgment. The agencies that rebuilt on ChatGPT or Gemini are not going to un-rebuild this quarter because a judge in San Francisco vacated a label.
The mechanism is still on the books
This is the part worth understanding in detail, because the mechanism outlives the case.
The designation invoked 10 U.S.C. § 3252, which lets the Secretary exclude sources from defence procurements involving national security systems, and the Federal Acquisition Supply Chain Security Act, applied government-wide through FAR 52.204-30. On the defence side, DFARS 252.239-7017 and 252.239-7018 put contractors under an affirmative duty to mitigate supply-chain risk. The FASCSA clause flows down to all subcontractors.
Those clauses carry a compliance cadence: review SAM.gov at least quarterly, report a covered article within three business days of identifying it, submit a mitigation plan within ten. The designation applied to “all Anthropic affiliates and all products and services” for covered contracts.
Here is the gap that did the real work. Outside counsel reading the authority concluded it “does not prohibit a contractor from having commercial business relationships with Anthropic” outside defence work — Anthropic argued the same thing, that a § 3252 designation “can only extend to the use of Claude as part of [DoD] contracts.” Hegseth’s public statement said something much broader: no contractor, supplier or partner doing business with the US military “may conduct any commercial activity with Anthropic.”
Contractors complied with the broad version. Of course they did. A three-business-day reporting clock and a flow-down obligation to every subcontractor make the cost of guessing wrong enormous, and the cost of switching chat vendors small. The chilling effect was the enforcement mechanism, and it required no legal authority at all. Lin’s order removes the designation. It does not remove the asymmetry that made a contested label behave like a settled ban.
What this means for how you pick AI tools
For consumer and small-business readers: nothing changed. Claude and Claude Code remain where they were on the best AI chatbots and best AI coding tools lists, and the Claude vs. ChatGPT call turns on the same capability and price questions it did last week. Federal procurement fights are not quality signals in either direction.
For enterprise buyers, one genuinely new item earns a place in the vendor review — and it is not “is Anthropic risky.” It is vendor political exposure, asked of every provider:
- Single-provider workloads. Which production paths have no tested fallback, and what is the measured time-to-migrate? The agencies above found out under a deadline. That is the expensive way to learn it.
- Portability of the work, not just the model. Prompts, evaluation suites and fine-tuning artefacts are the switching cost. Contract for export rights before you need them.
- Which list your vendor could land on. This year has produced several: the export-control action that pulled Fable 5 and Mythos 5 offline for 18 days and then lifted them; the covered-frontier-model designations under Executive Order 14409; the approved-customer gating that limited GPT-5.6 Sol at launch. Different vendors, same shape.
- Ask what your vendor refuses to do. Anthropic’s exclusion followed directly from contractual limits on autonomous weapons and mass surveillance it declined to waive. Those limits are a feature for most buyers and a liability for one customer. Know which of your providers has them, because it predicts where each one is politically exposed.
What to watch
Three markers, in order of how much they tell you.
Whether the Ninth Circuit stays the permanent injunction. If it does, the practical position reverts to spring and the vacatur becomes symbolic pending appeal. If it does not, defence-side procurement has to explain why Anthropic is still absent from awards.
Whether the GSA and the civilian agencies move as fast as they did in March. That restoration took days last time. A slow response now would say the chilling effect has outlived its legal basis.
Whether the D.C. case converges or diverges. Two courts have taken different postures on the same dispute since April. A split raises the odds this ends somewhere higher than a circuit.
The White House’s own frontier-AI framework remains unpublished despite being declared complete on 1 August, and the government-equity-stake discussion has gone quiet without resolving. The through-line across all of it is that US AI policy in 2026 is being made through procurement instruments and informal pressure rather than published rules — which is precisely why a vendor can be removed from the federal supply chain in a day and take six months to come back.
Anthropic won the legal argument comprehensively. The operative question for buyers was never whether the label was lawful. It was how long an unlawful one can keep working, and the answer so far is: longer than the litigation.
Frequently asked questions
Can federal agencies use Claude again as of today?
Legally the barrier is gone; operationally that is not the same as a restored channel, and the distinction matters because it has already played out once. Judge Lin's 27 August order vacates the designation and permanently enjoins the government from giving it effect, which is the strongest relief available short of appellate affirmance. But she also granted a preliminary injunction on 26 March covering the same designation, and the Department of War's chief technology officer responded by publicly asserting that the designation remained in full force and effect, arguing the California ruling did not reach the government-wide exclusion authority. Five weeks after that injunction the Pentagon cleared eight AI vendors for its IL6 and IL7 classified networks and Anthropic was not among them. The General Services Administration did restore Anthropic to USAi.gov and its Multiple Award Schedule after the March injunction, so the civilian side has a working precedent for moving quickly. The defence side does not. Expect civilian agency access to normalise first and defence access to stay contested through any appeal.
Does this change anything if we are a commercial company with no government contracts?
Directly, nothing. No price, model, rate limit or contract term changed for commercial Claude customers at any point in this dispute, and none changed on 27 August. Indirectly there is one thing worth internalising: the practical scope of the ban was always wider than its legal scope, because of how procurement compliance behaves under uncertainty. Defence Secretary Hegseth's statement said no contractor, supplier or partner doing business with the US military may conduct any commercial activity with Anthropic. Outside counsel reading the underlying authority reached a narrower conclusion — that 10 U.S.C. 3252 reaches the use of a covered article in defence procurements and does not prohibit a contractor from having commercial business relationships with the vendor outside that work. Many contractors complied with the broad reading anyway, because the cost of being wrong about a supply-chain clause is far higher than the cost of switching models. That asymmetry, not the statute, is what made the designation bite.
What exactly did the judge decide, and on what grounds?
Judge Rita F. Lin of the U.S. District Court for the Northern District of California ruled on cross-motions for summary judgment in Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996, issuing a 59-page order on the evening of Thursday 27 August 2026. She found three independent defects. First, First Amendment retaliation: the evidence of national security risk was 'slim,' and the measures were, in her account, 'based on a desire to make a public example out of Anthropic for its arrogance in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model.' Second, a Fifth Amendment due-process violation in how the designation was imposed. Third, arbitrary and capricious agency action under ordinary administrative-law review. She was careful to preserve the government's discretion as a buyer — 'though the Department of War is undisputedly free to select the AI vendor of its choice, the evidence demonstrates that the broad measures imposed on Anthropic were illegal and baseless' — and framed the limit as one on punishment rather than on procurement. The order vacates the designation and permanently enjoins enforcement, and also reaches the presidential directive that agencies stop using Claude.
Is this over, or will the government appeal?
It is not over, and the litigation has been running on two tracks since March. The government appealed Lin's preliminary injunction to the Ninth Circuit after a seven-day administrative stay expired on 2 April, and reporting on the 27 August order indicates the administration is expected to challenge it as well. A second, narrower case remains before the federal appeals court in Washington, D.C., where Anthropic lost a bid on 8 April to have the blacklisting temporarily blocked — the D.C. and California courts have taken visibly different postures on the same underlying dispute. The realistic timeline for finality is quarters, not weeks, and one plausible end state is a circuit split that pushes the question toward the Supreme Court. For planning purposes, treat the current status as 'legally protected, practically contested' rather than resolved.
What should we actually change in our AI vendor process because of this?
One thing, and it is cheap: add a political-exposure line to the vendor risk section you already run for uptime and data residency, and answer it for every model provider rather than only for Anthropic. The useful questions are concrete. Which of our workloads sit on a single provider with no tested fallback, and how long would a forced migration take? Does our contract give us export rights over prompts, evaluations and fine-tuning artefacts, or does switching mean rebuilding them? If a provider were removed from a federal schedule or an export-control list tomorrow, which of our deliverables would stall? These are the same questions the Fable 5 export-control episode raised in June, and the same ones the covered-models regime raises for release timing. Anthropic is the vendor this happened to; it is not the only vendor it could happen to, and a process that names one company has learned the wrong lesson.
Sources
- TechCrunch — Anthropic gets its first court win over the Pentagon's supply chain risk label (28 August 2026)
- NPR / KUNC — Judge says the Pentagon can't designate AI company Anthropic a 'supply chain risk' (28 August 2026)
- ABC News — Judge says Pentagon's measures against Anthropic were 'illegal and baseless'
- CNBC — Judge blocks Pentagon blacklist of Anthropic (28 August 2026)
- CourtListener — Anthropic PBC v. U.S. Department of War, No. 3:26-cv-01996 (N.D. Cal.) docket
- Mayer Brown — Anthropic supply chain risk designation takes effect: next steps for government contractors (March 2026)
- Breaking Defense — Judge grants Anthropic preliminary injunction but Pentagon CTO says ban still stands (March 2026)
- FedScoop — Anthropic faces fallout across federal agencies from DOD clash
- GSA — OneGov agreement offering Claude to all branches of government for $1 (12 August 2025)
- Jones Walker — Two courts, two postures: what the DC Circuit's stay denial means for the Anthropic-Pentagon dispute
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.