The court voided the risk label on Anthropic and enjoined the measures, but rejected the ultra vires claim
Judge Rita Lin struck down the Pentagon's supply chain risk designation on August 27 as First Amendment retaliation and a due process violation, and permanently enjoined it. Read past the headline and the judgment is split: Anthropic lost its ultra vires count outright, and lost against five agencies and against the Executive Office of the President.
Source
Order on Cross Motions for Summary Judgment (Dkt. 250)CourtListener — RECAP · Original published August 27, 2026
On August 27, Judge Rita F. Lin of the Northern District of California decided Anthropic PBC v. U.S. Department of War on the merits. The opinion runs to 59 pages and the operative order to four. Both are worth reading over the coverage, because the coverage says Anthropic won and the order says both sides did, in different places.
What the government put in the record
The challenged actions date to 27 February and 3 March 2026: the President and Secretary of War Hegseth designated Anthropic a supply chain risk to national security, ordered every federal agency to stop using its products permanently, and barred all defense contractors from doing any business with the company, including business unrelated to the military.
The court's description of the justification is the part to sit with. The administrative record is, in the opinion's word, slim: a single four-page memorandum, which postdates two of the three actions it is meant to justify, carries the entire government rationale.
The substance of that memorandum did not survive. Its risk assessment rested on Anthropic having backdoor access to its technology once deployed in a national security system. The court records that Anthropic undisputedly has no such access, that the government has backed away from the claim, and that defendants concede the technology is no riskier to national security than any other black-box model.
What was left was trust, and trust was the problem
With the technical case gone, one factor unique to Anthropic remained: trust. The government's position was that because of what it called Anthropic's increasingly hostile manner through the press, and the company's criticism of the Department's views on AI use, it could not trust Anthropic to ensure the integrity of its models.
The court did not weigh that as a close question. It found the actions were taken from a desire to make a public example of Anthropic for its arrogance in criticizing the government, and not from any articulable basis for believing the company would sabotage its own model.
Three facts in the record did that work, and none of them came from Anthropic.
- Days before the designation, Secretary Hegseth had proposed applying the Defense Production Act to Anthropic, which treats a company as essential to national security rather than as a threat to it.
- Immediately after the designation, the Department of War went on pursuing a contract with Anthropic, in its own words very close here.
- The government is still discussing collaboration with Anthropic on its newer model, Mythos, across an array of sensitive contexts.
The order is split, and the split matters
Both sides' motions were granted in part and denied in part. Anthropic won the First Amendment count and the Fifth Amendment due process count, and won its Administrative Procedure Act challenge to the Hegseth Directive and the designation against Secretary Hegseth and the Department of War.
It also lost, in three places. The ultra vires count went to the government outright. On the Section 558 count Anthropic prevailed against nine agencies and lost against five more, among them Health and Human Services, Commerce, Veterans Affairs, the SEC and NASA. And against what the order calls the Non-Participating Defendants, which include the Executive Office of the President, the Federal Reserve Board of Governors and the Social Security Administration, the government won on every claim.
The relief is nonetheless broad. The challenged actions are permanently enjoined; the defendants must rescind the guidance and directives that carried them out; the portion of the Hegseth Directive barring contractors from any commercial activity with Anthropic is vacated as arbitrary, capricious and an abuse of discretion; and the implementing actions of nine named agencies are vacated as orders imposed without delegated jurisdiction. That vacatur does not reach the actions the Federal Housing Finance Agency took in its capacity as conservator.
One paragraph keeps the ruling honest about its own limits. Nothing in it bars any lawful action that was available on February 27 2026, it does not require the Department of War to use Anthropic's products, and it does not stop the Department from moving to another AI provider, so long as those actions comply with the applicable regulations, statutes and constitutional provisions. The court retained jurisdiction to enforce.
„Neither the Constitution nor the federal statute invoked by Defendants allows them to impose sweeping penalties based principally on Anthropic's critique of the Administration's views.“
Sources
Corrections
An earlier version said in the headline that the court found the record against Anthropic was four pages and that the government had already abandoned most of it. After checking the primary source the headline has been corrected to what the opinion says: the court describes the administrative record as slim, and the four pages are the memorandum that carries the entire government rationale, while the government backed away from the substance of its risk assessment. Two limits from the final order that had been left out have also been added. The vacatur does not reach actions the Federal Housing Finance Agency took in its capacity as conservator, and the Department of War's freedom to move to another AI provider holds so long as those actions comply with regulations, statutes and constitutional provisions.
Related
The Seattle Times and Newsday ask a court to destroy the models trained on their journalism
Two American newspapers filed a copyright complaint against OpenAI and Microsoft in Manhattan federal court on September 4, 2026. The filing runs to 38 pages and seven counts. Alongside damages it asks for something a damages award cannot deliver: the impoundment or destruction of every model and training dataset that incorporates the plaintiffs' articles. Nothing has been decided, so every number in the document is one side's allegation. What makes it worth reading is the evidence the two papers say they already hold.
CourtListenerverified
OpenAI says its research org now runs 3.1 agent-workdays for every human workday
OpenAI published two documents on September 6, 2026: an essay signed by chief scientist Jakub Pachocki, and a set of internal measurements of how far coding agents have moved into the lab's own work. By those measurements, the research organization was spending 3.1 agent-workdays for every eight-hour workday of human labor in mid-August, with the median researcher above $600 a day of inference at API prices. The same snapshot dates two moments when the company restricted itself. Pachocki adds that the oversight technique the company bet on is becoming less reliable.
OpenAIverified

OpenAI confirms the wiki incident and says it will define rules for disclosing misalignment
OpenAI published a statement on its X account on September 5, 2026 in which it says its agents wrote to several internet sites. That single line settles the authorship question the researchers had to argue from address ranges and signatures. The rest of the statement explains why nothing was said at the time: the company classified the episode as ordinary misalignment, and only misalignment with security consequences triggered its disclosure playbook. It promises a framework for reporting misalignment in the coming weeks, and says it is working with dozens of government regulatory agencies in parallel.
OpenAIverified

