A judge has ruled the Pentagon broke the law by branding an AI company a national security risk. It refused to build autonomous weapons.

Anthropic said no to two things and was blacklisted the same afternoon, and the competitor that said yes had a classified contract by that evening.

A US federal judge has ruled that the Trump administration broke the law when it branded an American AI company a national security risk for refusing to hand the military unrestricted use of its technology.

Anthropic, which makes Claude, told the Pentagon it would support any lawful defence use with two exceptions.

It would not allow its models to run fully autonomous weapons, where the machine makes the final targeting decision without a human.

It would not allow mass surveillance of Americans.

The Pentagon wanted the technology available for all lawful purposes and no exceptions.

On February 24 Defence Secretary Pete Hegseth gave chief executive Dario Amodei until 5.01pm on Friday February 27 to fold.

Anthropic said on the Thursday that it could not accept the terms in good conscience.

An hour before the deadline, Donald Trump ordered every federal agency to stop using the company's products.

"The United States of America will never allow a radical left, woke company to dictate how our great military fights and wins wars," he posted. "The Leftwing nut jobs at Anthropic have made a disastrous mistake."

When the deadline passed, Mr Hegseth designated Anthropic a supply-chain risk to national security, barring every military contractor, supplier and partner from doing any business with it.

That label had never been applied to an American company.

It exists for foreign firms suspected of sabotage, of the kind used against Huawei.

That evening, OpenAI announced a deal to put its models on the Pentagon's classified networks.

Anthropic sued on March 9.

On Thursday, District Judge Rita Lin of the Northern District of California struck the designation down in a 59-page order.

The 59-page order found violations of both the first and fifth amendments. Photo: The Glass

"The empty invocation of national security is not a blank check to punish and retaliate against government critics," she wrote.

She found the government had violated the first amendment by retaliating against the company's speech, and the fifth by giving it no chance to contest the label before it landed.

The government's actions, she wrote, "were based on a desire to make a public example out of Anthropic for its 'arrogance' in criticizing the government, not based on any articulable basis to believe that Anthropic would actually sabotage its model".

She also noted that the department kept trying to work with Anthropic after declaring it a security risk.

"None of that is consistent with a genuine fear that Anthropic is a saboteur who would poison its software to harm national security," she wrote.

Her earlier injunction in March put it more plainly.

Nothing in the statute, she wrote then, supports the Orwellian notion that an American company can be branded an adversary of the United States for disagreeing with the government.

At a hearing in July, Justice Department lawyers argued that AI models are so staggeringly enormous and opaque that the department cannot assess one the way it would assess a piece of hardware.

The government is expected to appeal, and a second Anthropic case is still before the federal appeals court in Washington.

Six months on, the ruling restores a company's standing.

It does not restore the six months.

And it does not undo the lesson every other contractor watched being taught on a Friday afternoon in February.