A San Francisco federal court recently ruled that the Department of War (DOW) and its secretary, Pete Hegseth, “violate[d] the First Amendment” by unlawfully retaliating “against Anthropic for constitutionally protected expressive activities.” The activities involved the company’s public defense—in the face of DOW opposition—of usage restrictions Anthropic imposes on its Claude Gov large language model (LLM).
In granting summary judgment to the AI company on its First Amendment retaliation claim, US District Judge Rita Lin reasoned that President Donald Trump and Hegseth’s designation of Anthropic as “a supply chain risk to national security” and their concomitant imposition of “sweeping penalties” on the company “were based on a desire to make a public example out of Anthropic for its ‘arrogance’ in criticizing the government.”
Under the federal statute at issue in the lawsuit, a “supply chain risk” exists when “an adversary may sabotage” a “national security system.” The evidence Lin reviewed strongly suggested the DOW played the national security card only after Anthropic “publicly aired” its view during contractual negotiations with the DOW that its LLM cannot be used for “mass surveillance of Americans and lethal autonomous warfare.”
The DOW sought to more broadly deploy Claude Gov “for all lawful uses.” It ultimately claimed the supply-chain risk designation fit because it couldn’t “trust Anthropic to ensure the integrity of its models,” given Anthropic’s publicly “hostile posture” toward the government’s usage demands. Lin emphasized that, prior to the public spat, the “DoW did not identify any potential supply chain risk posed by Anthropic.”
It’s one thing to claim something happens for a particular reason, but it’s quite another matter to prove it, especially when First Amendment expressive rights rest in the balance. As Lin crisply encapsulated it in Anthropic PBC v. US Department of War, “The empty invocation of national security is not a blank check to punish and retaliate against government critics.”
Importantly, Lin found that social media posts and other statements Hegseth made “expressly tied Anthropic’s punishment to its attitude and rhetoric in the press.” I previously described for AEIdeas some pugnacious public remarks made by Hegseth and Trump that attacked Anthropic’s supposed liberal ideology. I suggested then that if Anthropic were to win its First Amendment retaliation claim, those statements “likely will have helped” it. Indeed, what an amicus brief filed by the Foundation for Individual Rights and Expression and several other organizations aptly dubbed a “temper tantrum” thrown by the DOW proved beneficial for Anthropic in prevailing before Lin.
Anthropic’s case is not the only time a First Amendment retaliation allegation has been leveled against Trump administration officials for trying to silence critics. Perhaps most notably, former FBI Director James Comey argues that “an official policy of retaliation” against him for publicly criticizing Trump “led directly” to his prosecution for allegedly threatening Trump via an Instagram-posted photograph of seashells on a beach arranged in an “86 47” pattern. Hostile social media posts may affect that case too.
The larger danger for Hegseth and the DOW is that when real threats of substantial harm to national security interests do arise because of flaws or failings in new technologies, judges simply won’t believe them. The judicial deference once rightfully afforded to government officials will have evaporated because of “empty invocation[s] of national security” in cases such as Anthropic’s lawsuit.
Crying wolf about security risks for purposes of squelching First Amendment–protected criticism simply doesn’t pay off—not against Anthropic and not in the long run. In fact, it backfires.
Furthermore, it’s not good for the safe development and deployment of AI tools, particularly as public sentiment in some quarters turns against them and data centers. Should companies such as Anthropic and OpenAI be put in the highly uncomfortable position of having to publicly stifle and suppress honest, passionately held beliefs about the potential dangers or weaknesses of their AI tools because they don’t want to be deemed national security risks and lose business from the government and others? Businesses shouldn’t be forced to choose between publicly engaging in First Amendment–protected expression, on the one hand, and silently doing business with the government, on the other.
Sadly, the depletion and diminution of judicial deference traditionally afforded government officials isn’t confined to that seemingly squandered by Hegseth and the DOW. Attorneys for the US Department of Justice reportedly have lost significant deference since Trump returned to the Oval Office in January 2025. As ProPublica reported in July, “Across the country, federal judges are calling out Department of Justice lawyers, questioning in unprecedented ways whether they can be trusted to tell the truth or uphold centuries-old legal norms.”
Once lost, judicial deference is not easily won back, no matter who controls the Oval Office. It is earned over decades through forthright, honest behavior, not angry accusations.
