Close
Skip to content
  • Home
  • Insights
  • JJTP Law
    • Careers
    • Contact
    • Make Payment
    • Schedule a Consultation
    • Virtual Office
  • Capabilities
    • AI & Technology Law
    • Alternative Dispute Resolution & Conflict Management
    • Asset Protection and Estate Planning
    • Business Startup and Entrepreneurial Law
    • Civil Rights & Federal Employment Law
    • Consumer Protection, Bankruptcy & Creditor Issues
    • Entertainment & Social Media Law
    • Immigration Law
    • Intellectual Property Law
    • International Law
    • Investigations, Crisis Management & Risk Advisory
    • Nonprofit Law & Pro Bono Legal Services
    • Other Matters
    • Real Estate Law
  • Your Lawyer
    • About JJTP
    • About JJTP Law
    • JJTP Group LLC
    • Prior Engagements
    • Tyson Twins Foundation
  • Services
    • Trademark Search
    • Copyright Search
    • Immigration Visa Type Finder
JJTP Law PLLC logo
  • Home
  • Insights
  • JJTP Law
    • Careers
    • Contact
    • Make Payment
    • Schedule a Consultation
    • Virtual Office
  • Capabilities
    • AI & Technology Law
    • Alternative Dispute Resolution & Conflict Management
    • Asset Protection and Estate Planning
    • Business Startup and Entrepreneurial Law
    • Civil Rights & Federal Employment Law
    • Consumer Protection, Bankruptcy & Creditor Issues
    • Entertainment & Social Media Law
    • Immigration Law
    • Intellectual Property Law
    • International Law
    • Investigations, Crisis Management & Risk Advisory
    • Nonprofit Law & Pro Bono Legal Services
    • Other Matters
    • Real Estate Law
  • Your Lawyer
    • About JJTP
    • About JJTP Law
    • JJTP Group LLC
    • Prior Engagements
    • Tyson Twins Foundation
  • Services
    • Trademark Search
    • Copyright Search
    • Immigration Visa Type Finder

Schedule a Consultation
JJTP Law PLLC logo
  • Home
  • Insights
  • JJTP Law
    • Careers
    • Contact
    • Make Payment
    • Schedule a Consultation
    • Virtual Office
  • Capabilities
    • AI & Technology Law
    • Alternative Dispute Resolution & Conflict Management
    • Asset Protection and Estate Planning
    • Business Startup and Entrepreneurial Law
    • Civil Rights & Federal Employment Law
    • Consumer Protection, Bankruptcy & Creditor Issues
    • Entertainment & Social Media Law
    • Immigration Law
    • Intellectual Property Law
    • International Law
    • Investigations, Crisis Management & Risk Advisory
    • Nonprofit Law & Pro Bono Legal Services
    • Other Matters
    • Real Estate Law
  • Your Lawyer
    • About JJTP
    • About JJTP Law
    • JJTP Group LLC
    • Prior Engagements
    • Tyson Twins Foundation
  • Services
    • Trademark Search
    • Copyright Search
    • Immigration Visa Type Finder
Schedule a Consultation

“National Security” Is Not a Blank Check:

Jabari Tyson-Phipps
27 March 2026
Insights
Email

March 27, 2026

This is one of the first cases where a court has squarely confronted the use of national security supply chain authority against a domestic AI company and treated it as a likely First Amendment and APA problem, not just a technical risk decision. For AI labs, defense contractors, and policy shops, Judge Rita Lin’s March 26, 2026 preliminary injunction in Anthropic PBC v. U.S. Department of War is a warning that security labels cannot be weaponized to punish a company for drawing safety lines and talking about them in public.

Share

Leave a comment


Key facts

On March 26, 2026, Judge Rita F. Lin of the Northern District of California issued a 43‑page preliminary injunction order in Anthropic PBC v. U.S. Department of War, granting Anthropic relief from three “Challenged Actions”: President Trump’s Truth Social directive ordering all federal agencies to cease using Anthropic’s technology, Secretary Hegseth’s directive telling defense contractors they may not do business with Anthropic, and the Department’s “unacceptable supply chain risk” designation under 10 U.S.C. § 3252.

Applying the Winter standard, the court concluded that Anthropic is likely to succeed on its First Amendment retaliation claim, its Fifth Amendment procedural due process claim, and its APA claims that the § 3252 designation exceeded statutory authority, was contrary to law, and was arbitrary and capricious.

The order emphasizes that the Department can stop using Claude and hire a different vendor, but cannot dress up a policy and ethics dispute as a “supply chain” threat aimed at adversaries and use it to justify a government‑wide ban and a de facto contractor blacklist.

Judge Lin temporarily stayed the injunction for seven days to allow the government to seek an emergency stay from the Ninth Circuit, which means the real test of this ruling may arrive on the Ninth Circuit’s shadow docket in the next few days.


What has changed since my last article

In my earlier LinkedIn piece, Anthropic’s Lawsuit Against the Department of Defense: AI Safety, Retaliation Risk, and the First Domestic “Supply‑Chain Risk” Fight, I was operating off the complaint and motion practice. My thesis was that the government was trying to turn domestic supply chain tools into a retaliation vector against an AI company that refused to support mass surveillance of Americans and autonomous lethal targeting.

Now there is a detailed preliminary injunction order, and three things are materially different:

  • The rhetoric is no longer just Anthropic’s framing. Judge Lin herself repeatedly describes the measures as “punitive,” focuses on the President’s and Secretary’s “ideology” and “rhetoric” about Anthropic, and notes that the Department’s own memo ties the supply chain label to Anthropic’s “increasingly hostile manner through the press.”

  • The “kill switch” and sabotage narrative has been tested against the record. The court recounts the internal “Michael Memo” that later became the basis for the § 3252 designation and then credits unrebutted technical declarations explaining that Anthropic has no unilateral ability to access, alter, or shut down deployed Claude Gov models inside air‑gapped government systems.

  • The opinion connects this dispute to the broader deference debate. Rather than treating this as a one‑off AI fight, Judge Lin explicitly nods to cases like Holder v. Humanitarian Law Project and reads § 3252 through its text and history, making this part of the larger story about how far “national security” can go before Article III judges step in.

Strip away the national security framing and part of this reads like a hard‑fought procurement and policy dispute that escalated into a constitutional confrontation.


Explaining the ruling

Preliminary posture and standard

Judge Lin frames the case under Winter v. NRDC: Anthropic must show likelihood of success on the merits, likelihood of irreparable harm, and that the balance of equities and public interest favor relief. She acknowledges the government’s national security arguments, but quotes Holder to stress that “concerns of national security and foreign relations do not warrant abdication of the judicial role,” especially where First Amendment rights are at stake.

On appeal the Ninth Circuit will review this under an abuse‑of‑discretion standard, with legal conclusions reviewed de novo and factual findings for clear error. That makes the next 72 hours important: a stay from the Ninth Circuit would not undo the reasoning, but it would blunt the immediate impact and signal how much deference the appellate panel is willing to give in this posture.

First Amendment retaliation: from speech to “corporate murder”

Anthropic’s win turns on a simple fact: Judge Lin concludes that the Department used national security tools to punish a domestic AI lab for its speech and stance on AI safety, not for a proven technical security risk.

The court applies the Ninth Circuit’s three‑part retaliation test:

  • Protected activity. Anthropic’s public advocacy on AI safety, including its refusal to support mass surveillance of Americans and fully autonomous lethal uses, is speech on matters of public concern at the core of the First Amendment. The order cites CEO Dario Amodei’s public writings and statements as examples of that speech.

  • Adverse action. The court characterizes the President’s Truth Social post as directing “every Federal Agency in the United States Government to immediately cease all use of Anthropic’s technology” and announcing that “we will not do business with them again,” and the Hegseth Directive as telling contractors that “no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic.” Judge Lin notes an amicus description of these actions as “attempted corporate murder” and writes that “they might not be murder, but the evidence shows that they would cripple Anthropic.” That is a stark way for a federal judge to describe adverse action.

  • Causation and motive. The opinion quotes the President calling Anthropic a “RADICAL LEFT, WOKE COMPANY” and “Leftwing nut jobs” who tried to “STRONG‑ARM the Department of War,” and Secretary Hegseth calling Anthropic’s position “fundamentally incompatible with American principles,” a “master class in arrogance,” “corporate virtue‑signaling,” and “Silicon Valley ideology” with “sanctimonious rhetoric.” It then points to the Michael Memo’s complaint about Anthropic’s “increasingly hostile manner through the press” and its decision to “publicly spat with DoW” as part of the rationale for the supply chain designation.

The judge is clearly focused on the fact that if this were just a dispute about contract terms, DoW could simply have stopped using Claude and moved to a different AI provider. Instead, the record “strongly suggests that Defendants chose to go much further to punish Anthropic for its refusal to abandon its public commitments and for its public criticism of the Department’s position.” That is the difference between “we will not hire you” and “we will try to make sure no one else can either.”

Due process: stigma‑plus and de facto blacklisting

On the Fifth Amendment claim, Judge Lin uses a familiar stigma‑plus framework.

  • Protected liberty interest. The combination of branding Anthropic an “unacceptable supply chain risk” to national security and effectively excluding it from federal contracting and from doing business with defense contractors implicates a liberty interest in pursuing one’s chosen profession without unreasonable governmental interference. The opinion cites Old Dominion Dairy and similar cases for the proposition that when government action seriously damages reputation and forecloses business opportunities, due process protections apply.

  • Lack of notice and opportunity to be heard. Anthropic had no meaningful notice before the Presidential Directive, learned of the Hegseth Directive when the rest of the world did, and received a barebones § 3252 letter that did not explain the technical rationale. The court notes that Anthropic only discovered the Michael Memo’s assertions about “sabotage” and “subversion” in litigation and responded with unrebutted declarations explaining why those assumptions were factually wrong.

  • Weak claim of exigency. Judge Lin underscores that the Department had used Claude Gov under the same usage restrictions for about a year, had recently granted facility and cloud authorizations, and built a six‑month transition period into its internal plans. Against that backdrop, the assertion that skipping pre‑deprivation process was necessary to respond to a sudden “supply chain emergency” looks thin.

The ruling is careful not to say that national security designations always require pre‑deprivation hearings, but it makes clear that when the government inflicts severe reputational and economic harm based on contested factual assumptions in a non‑urgent setting, due process kicks in even if the words “national security” appear in the statute.

APA and § 3252: technical risk versus policy punishment

The APA piece is where the opinion most clearly suggests a narrower, text‑bound reading of § 3252 and where I can most profitably use the “supply chain as retaliation vector” framing.

Government’s story versus Judge Lin’s reality check

A simple way to frame this for readers is to contrast what the Department said with what the order recounts about the record:

Article content

The opinion draws heavily on the text of § 3252, the 2010 Senate Armed Services Committee report, and a 2012 DoD instruction to conclude that the statute is directed at covert technical compromise, not at public policy disputes with domestic vendors. At this stage, Judge Lin does not definitively rewrite § 3252, but she is plainly skeptical that Congress meant “adversary” to include an American AI lab that disagrees about using its models for surveillance and weapons.

This is also where pretext comes into focus. The order notes that Under Secretary Michael was still telling Anthropic in December that the parties were “very close” to a deal and pushing for a compromise, and that Secretary Hegseth had previously floated using the Defense Production Act to compel Anthropic to provide services as “essential to national security.” Against that backdrop, a sudden pivot to calling the company an “unacceptable supply chain risk” to national security looks less like a sober technical judgment and more like a political escalation.


National security deference: Egan, Rattigan, Chien, and now Anthropic

My Egan → Rattigan → Chien bridge is where this piece stands out. The new opinion lets me sharpen, not dilute, that synthesis.

Navy v. Egan: the non‑reviewable core

Department of the Navy v. Egan holds that the merits of security clearance decisions are committed to the Executive and generally not reviewable by courts or the MSPB. Who gets to see classified information, how risk is weighed, and when clearance is revoked are at the heart of Article II responsibilities. That doctrine remains intact.

It is striking that Judge Lin does not question that core. She does not tell the Department which models to use, how to configure classified networks, or whether certain missions require bespoke in‑house AI. She repeats more than once that “it is DoW’s prerogative to decide what AI product it uses,” and that if the Department does not like Anthropic’s guardrails, it can stop using Claude and “look for a new AI vendor.”

Rattigan v. Holder: a retaliatory‑misuse exception

In Rattigan v. Holder, the D.C. Circuit drew a crucial line: while Egan bars courts from reviewing the substance of clearance decisions, it does not bar Title VII claims that supervisors knowingly submitted false or retaliatory referrals into the clearance process, so long as courts do not revisit the clearance judgment itself. In the later 2015 opinion, the court applied that narrow theory, requiring the plaintiff to show evidence of a knowingly false or retaliatory referral.

The logic is simple: deference protects security judgments, not bad‑faith use of the security apparatus to punish someone for protected activity.

Chien v. Kerry / Rubio / Blinken: extra scrutiny, still reviewable

The Chien opinions you attached apply similar reasoning to a Diplomatic Security ARSO. In the 2018 opinion, Judge Mehta rejects the government’s attempt to use Egan to block Chien’s retaliation claim based on “extra scrutiny” during a clearance update, distinguishing between the non‑reviewable clearance decision and the reviewable retaliatory conduct surrounding it. The 2025 opinion continues to treat Chien’s claims under ordinary Title VII standards, reinforcing that security‑adjacent retaliation remains justiciable.

Taken together, Rattigan and Chien show that courts are willing to carve out a narrow “retaliatory misuse” exception to national security deference without undermining Egan’s core.

Anthropic’s contribution: extending the misuse exception to supply chain tools

Anthropic’s case extends that pattern to statutory supply chain authorities and AI vendors. Judge Lin effectively says:

  • The court will not tell DoW who to trust with classified operations.

  • But it will review whether § 3252 and public directives were used as blunt instruments to punish a domestic company’s protected speech and contractual red lines, especially when the technical record is thin and the rhetoric is explicit.

In functional terms, this creates a retaliation and pretext exception to automatic deference: the Executive still gets wide latitude on security judgments, but not on using security labels and supply chain tools as a club against domestic experts.

The ruling is also fact‑specific. It is driven by an unusually explicit record of presidential and cabinet‑level rhetoric, a compressed timeline triggered by a social‑media post, and candid government concessions on missing authority and evidence. It does not mean most national security supply chain decisions will face this level of scrutiny, but it does put agencies on notice that when the record looks this political, judges are not going to stand down.


What the government will argue next

Looking ahead, I can safely predict several themes in the government’s Ninth Circuit stay and appeal filings:

  • “We are not reviewing security decisions.” Expect a heavy push to reframe this as interference with core security and procurement judgments, with citations to Egan and to cases warning against “nationwide injunctions” that interfere with federal operations. The government will argue that even at the PI stage, courts should avoid ordering relief that constrains how the Executive manages its supply chain and contractor ecosystem.

  • “This is about operational control, not speech.” DOJ will likely stress that Anthropic’s refusal to agree to “all lawful uses” in high‑risk domains forced DoW to treat it as unreliable, and that the public rhetoric is incidental rather than causal. They will argue that any company taking the same position on mission control would have faced the same consequences, regardless of ideology.

  • “The statute contemplates limited process in sensitive cases.” On due process and the APA, the government will emphasize that § 3252 allows the Secretary to limit disclosure of sensitive information and that Congress understood some designations would have to occur quickly, based on classified or operationally sensitive assessments that cannot be fully shared with the target.

The real audience for this appeal will be other agencies and AI vendors. If the Ninth Circuit lets the injunction stand, even in narrowed form, it will quietly force a rewrite of how security, supply chain, and retaliation risk are balanced inside federal procurement and risk‑management shops.


Remedy, scope, and the “shadow docket”

Judge Lin’s order walks a careful line on scope.

  • Who is covered. The injunction binds a specific list of “Defendant Agencies” and their heads, barring them from implementing the Presidential Directive, enforcing the Hegseth Directive, or treating the § 3252 designation as operative. The court does not directly enjoin the Executive Office of the President, but notes that no enjoined agency may act “for, with, by, through, or under authority from” any other entity to carry out the banned actions.

  • What is not ordered. The court does not require any agency to buy from Anthropic or to keep using Claude. It explicitly states that DoW “may permissibly stop using Claude and look for a new AI vendor,” and that nothing in the order compels the government to adopt Anthropic’s preferred safety policies.

  • Administrative stay and the next 72 hours. The seven‑day administrative stay is a practical acknowledgment that the Ninth Circuit will be asked to weigh in urgently. For practitioners, the question is how the panel handles this on its shadow docket: a quick stay without full briefing would not erase Judge Lin’s reasoning, but it would signal skepticism about intrusive relief in security‑framed cases, while a denial of stay would embolden other vendors to litigate similar retaliation theories.

This is why I think it is useful, in a piece like this, to flag not only what happened in the district court, but what to watch for next.


National security implications and industry impact

Two final themes matter for the LinkedIn audience I have in mind.

  • Protecting “the herd” of domestic AI vendors. The court cites amicus briefs from AI researchers, investors, and smaller developers warning that the government’s actions were already chilling “open deliberation” and “professional debate” about AI safety and catastrophic misuse. By granting a preliminary injunction, Judge Lin is not just protecting Anthropic; she is effectively signaling to OpenAI, Google DeepMind, Palantir, Anduril, and others that saying “no” to certain uses and explaining why does not automatically put them in the crosshairs of supply chain designations.

  • How agencies will adapt. After this ruling, I expect smart agencies to do three things: formalize their § 3252 processes with clear technical criteria and documented “less intrusive measures” analysis; avoid overheated public rhetoric that can be read as evidence of viewpoint discrimination; and, where they believe a vendor truly presents a covert risk, build a classified record that can be summarized in unclassified form for due process and APA review. That is not about hiding the ball; it is about ensuring that when security authority is used, it looks like security, not like payback.

The Anthropic ruling does not mean national security deference is over. It does mean the days of automatic deference, especially when security tools are used against domestic experts in a very public way, are coming to an end.


Key takeaways

  • Judge Lin’s March 26, 2026 preliminary injunction is a fact‑specific but important signal that courts will scrutinize the use of national security supply chain tools when the record suggests they are being used to punish protected speech and safety‑driven contractual positions rather than to address a documented technical threat.

  • The opinion strongly suggests a narrower, text‑bound reading of § 3252 that anchors “supply chain risk” in sabotage and covert subversion of national security systems, and it highlights the danger of relying on speculative “kill switch” theories without confirming whether a vendor can, in reality, access or alter deployed systems.

  • Navy v. Egan still protects the core of clearance and security‑access decisions from judicial review, but Rattigan and Chien showed that retaliatory misuse of security processes is reviewable; Anthropic extends that logic to supply chain authorities applied to domestic AI vendors.

  • For AI companies and defense contractors, the lesson is to document technical controls, usage policies, and negotiation history. That documentation will not just help in procurement; it will also be central if you ever need to show that a “supply chain” label was about your speech and safety stance, not about genuine sabotage risk.

  • For agencies, the ruling is a prompt to tighten statutory compliance, tone down political rhetoric, and treat due process and APA review as part of the national security tool kit rather than as an external obstacle. The real long‑term impact of this case may be less about Anthropic’s immediate fate and more about how the federal government talks to, and about, the AI companies it increasingly depends on.

This article is published by JJTP Law PLLC as a general-interest news and information service for clients and friends of the firm. Nothing in it is legal advice, and reading it does not create an attorney-client relationship. If you have a question about how this topic applies to your own situation, please reach out to the attorney you normally work with, or schedule a consultation. This is not a solicitation for legal work in any jurisdiction where JJTP Law is not authorized to practice. See our Attorney Advertising & Terms of Use.


Jabari Tyson-Phipps

I’m an attorney, founder, and former U.S. Diplomatic Security Service special agent based in New Rochelle, New York, focused on helping companies, creators, and nonprofits grow while managing risk. I lead JJTP Law PLLC and JJTP Group LLC, boutique, technology‑enabled practices that provide fractional general counsel, intellectual property strategy, and business advisory services to clients in financial services, entertainment, technology, and the nonprofit sector. Earlier in my career, I co‑founded FareHarbor, a cloud‑based reservations and payments platform, serving as General Counsel as we scaled through acquisitions, international expansion, and a successful exit. I’ve advised on complex transactions, cross‑border compliance, and IP strategy, and served as outside general counsel to an SEC‑registered investment adviser and multifamily office with over $100M in assets under management. Before returning full‑time to private practice, I served as a Foreign Service Special Agent with the U.S. Department of State, where I led high‑stakes investigations, developed AI‑enabled investigative tools and policies, and managed protective details for senior U.S. and foreign officials. That mix of legal, entrepreneurial, and national‑security experience shapes how I approach strategy, governance, and risk for my clients today. I’m admitted to practice in New York, Pennsylvania, multiple federal courts including the Supreme Court of the United States, and hold licenses as a New York real estate broker, notary public, and FAA‑certified pilot. I also lead and support several community and alumni organizations, including founding the Tyson Twins Foundation and serving as President of the Brown Club in New York. Outside of work, you’ll usually find me flying, lifting, rock climbing, or on a range practicing marksmanship, and exploring ways to use AI and modern workflows to make legal services more accessible, efficient, and human‑centered.

The Shield Is Porous
Previous Article
You Cannot Sue Someone Into Liking You
Next Article

JJTP Law PLLC logo

JJTP Law PLLC — For a Solutions Based Approach.
New Rochelle, New York

About Us
  • Home
  • About JJTP Law
  • Practice Areas
  • About JJTP
  • Prior Engagements
  • Contact
  • Payments
  • Terms of Representation

Practice Areas

  • AI & Technology Law
  • Alternative Dispute Resolution & Conflict Management
  • Asset Protection and Estate Planning
  • Business Startup and Entrepreneurial Law
  • Civil Rights & Federal Employment Law
  • Consumer Protection, Bankruptcy & Creditor Issues
  • Entertainment & Social Media Law

More Practice Areas

  • Immigration Law
  • Intellectual Property Law
  • International Law
  • Investigations, Crisis Management & Risk Advisory
  • Nonprofit Law & Pro Bono Legal Services
  • Real Estate Law
  • Other Matters
Facebook Linkedin Instagram Youtube Whatsapp Telegram Comment-dots
Phone
+1.212.YES-JJTP (+1.212.937-5587)
Email
hello@jjtpgroup.com
Office
New Rochelle, New York

© 2026 JJTP Law PLLC. All Rights Reserved. JJTP® and the JJTP mark are registered trademarks of JJTP Law PLLC.

Attorney Advertising. Prior results do not guarantee a similar outcome. The information on this website is for general informational purposes only, does not constitute legal advice, and does not create an attorney-client relationship. JJTP Law PLLC is licensed in New York and Pennsylvania and in the federal courts to which its attorney is admitted.

Super Lawyers is a rating service of Thomson Reuters. A description of the selection methodology is available at superlawyers.com. The Super Lawyers designation is a third-party recognition, is not a guarantee of results, and has not been approved by any state supreme court or bar association.

  • Licensed in New York and Pennsylvania
We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking “Accept” you consent to our use of cookies. You may decline non-essential cookies. Learn more in our privacy & terms.

No products in the cart.

JJTP Law PLLC logo
  • Home
  • About
  • Practice Areas
  • Attorney
  • Case Studies
  • Contact
  • Pro Bono Services
Phone
+1.212.YES-JJTP
Email
hello@jjtpgroup.com
Office
New Rochelle, New York
  • Facebook
  • Linkedin
  • Twitter