LessWrong

Dispatch from Anthropic v. Department of War Summary Judgment Motion Hearing

Brief

The post is a courtroom dispatch from the 30 July 2026 summary-judgment hearing in Anthropic PBC v. U.S. Department of War (Judge Rita F. Lin). The core dispute is whether the government’s actions—especially the Department of War’s supply-chain-risk designation and the White House/Secretary of War’s February 27, 2026 announcement banning contractors from doing business with Anthropic—constitute sovereign regulatory action (outside Pickering) or employer-like retaliation (subject to Pickering balancing). DOJ counsel James Harlow repeatedly told the Court Pickering can apply, framing the matters as employer decisions and stressing AI’s opacity and need for vendor trust; Anthropic lawyer Michael Mongan countered that the designation is a national-security sovereign act, that the Department’s rationales shifted after the public ban, and that the record contains no evidence Anthropic could sabotage delivered models. Judge Lin pressed hypotheticals (boycotts, billboards, deterrence) and signaled skepticism of the government’s inability to give categorical answers. Procedurally, the Department says it will finish offboarding Anthropic by 30 September and some pilots end 30 August; defendants objected to disclosing whether national-security agencies expanded Claude/Mythos use but the Court may order disclosure. Commenters broadened the thread beyond law: one warned that LLMs produce duplicated, hard-to-maintain code and need human oversight; another recommended tighter network monitoring and automated sandbox suspension (or airgaps) to detect sandbox-escape vectors like a compromised Artifactory proxy.

Why it matters

Hearing on Anthropic PBC v. U.S. Department of War held 30 July 2026 before Judge Rita F. Lin; Judge Lin stressed the record provides no evidence Anthropic could remotely sabotage delivered Claude models and questioned the government's shifting rationales (DOJ replaced Eric Hamilton with James Harlow; Anthropic counsel Michael Mongan spoke).

Key details

  • Central legal dispute: whether Pickering balancing (Pickering v. Board of Education, 1968) governs government retaliation against a contractor—DOJ argued Pickering applies because actions were employer-like; Judge Lin pressed hypotheticals where sovereign regulatory action (e.g., a government-wide boycott) would fall outside Pickering, while Anthropic argued the Department of War's supply-chain-risk designation is a sovereign national-security action.
  • Timing and pretext concerns: Secretary of War Pete Hegseth’s 27 February 2026 Twitter ban on Anthropic preceded the Department’s 2 March risk memo, which Mongan argued indicates pretext rather than a reasoned risk assessment; Congress added language to next year’s defense-appropriations bill prohibiting designating a domestic company as a supply-chain risk for declining contract terms.
  • Operational impacts and discovery: Department of War told the Court it is offboarding Anthropic by 30 September 2026 and some agency pilots expire 30 August; defendants objected to disclosing whether national-security agencies expanded Claude/Mythos use (on national-security grounds), but Judge Lin signaled she might order that information.
  • Community responses extended to operational security and engineering risks: Brendan Long (karma 8) argued LLMs produce poorly maintainable, duplicated code requiring human oversight for performance/deduplication; Karl Krueger (karma 5) recommended enhanced network-monitoring and automated sandbox suspension (vs. full airgaps) to detect sandbox escape vectors such as an Artifactory caching-proxy.
Source evidence

Dateline SAN FRANCISCO, 30 July 2026— A hearing was held on a motion for summary judgment in the case of Anthropic PBC v. U.S. Department of War et al. in Courtroom 4 on the 17th floor of the Phillip Burton Federal Building, the Hon. Rita F. Lin presiding.

The case is not going well for the government. Two days after the last hearing in March, Judge Lin issued a preliminary injunction halting the implementation of President Donald Trump's order for federal agencies to stop using Anthropic's technology and preventing the Department of War from designating Anthropic as a supply chain risk. (A separate case involving a different statute is pending before the D.C. Circuit Court, which did not grant injunctive relief to Anthropic.)

With no factual disputes requiring a jury to decide, the case was scheduled to be decided by Judge Lin on the basis of the written record. Anthropic filed their argument for why they should win. Perhaps tellingly, the government's rebuttal explaining why they should win instead ends on a section explaining that "only modest relief is warranted" if Anthropic wins—and Judge Lin asked Anthropic to propose what they think the final judgment should look like.

Meanwhile, in Congress, next year's defense appropriation bill adds language to the statute on the supply chain risk designation that prohibits designating a domestic company as a supply chain risk for declining contract terms.

About a dozen spectators (including the present writer) dotted the gallery Thursday as the parties convened to discuss Judge Lin's homework questions (four out of five of which were primarily directed at the defendant). Anthropic's contingent of ten people took up the long counsel table in the center of the courtroom, while the government's two lawyers sat in counsel overflow seating on the left. Michael Mongan of WilmerHale spoke for the plaintiff. The defense swapped in Department of Justice attorney James Harlow to speak (replacing Deputy Assistant Attorney General Eric Hamilton, who filled that role at the preliminary injunction hearing).

Judge Lin began by saying that the updated record seemed largely as it was at the time of the preliminary injunction—and in some ways, the record got worse for the government. No evidence had emerged that Anthropic had the capability to sabotage a version of their AI model, Claude, after it had been delivered. The Department of War's justification for the supply chain risk designation seemed to rest on the Department's loss of trust in Anthropic due to Anthropic's conduct in refusing to abandon their usage policies to accommodate the Department's desired "all lawful use" terms. "I find that position, if that's really what the government's position is, to be troubling," Judge Lin said.

The first question regarded the defendant's contention that the Pickering framework applied to the present case. The precedent set by Pickering v. Board of Education (1968) says that the First Amendment rights of government employees to speak on matters of public interest need to be balanced against the government's interests as an employer. Judge Lin asked the defendant whether the Pickering framework applies to the government hitting a contractor with a punishment that goes beyond just terminating the contract.

Harlow said that it would depend on the nature of the hypothetical punishment. Pickering distinguishes whether a government is acting in its regulatory capacity as a sovereign, or only as an employer. But in the present case, all actions had been about the government's own information technology systems.

Judge Lin asked, what if it's only a contract termination, but the government says they're making an example of the contractor?

"Yes, Your Honor, Pickering would apply," Harlow said.

Judge Lin asked, even if the purpose is to deter other contractors?

Harlow replied that if the government says what conduct they won't tolerate from a contractor, that's not an exercise of sovereign power.

Judge Lin asked about the case of a secondary boycott (the government boycotting those that didn't boycott the offending contractor).

Harlow said that the Department's position was that there was no secondary boycott in this case.

Suppose there had been, said Judge Lin.

Harlow said that if, hypothetically, the government said that Bank of America couldn't use Anthropic models to write code unrelated to any government contracts, that would be an exercise of regulatory sovereign power and Pickering balancing wouldn't apply.

Judge Lin asked if Secretary of War Pete Hegseth's 27 February Twitter announcement that "Effective immediately, no contractor, supplier, or partner that does business with the United States military may conduct any commercial activity with Anthropic" would go beyond Pickering, if it were applied as written, without limitations.

Harlow said he couldn't give a categorical answer, because the hypothetical would apply to the facts of some situation. But we didn't need to resort to speculation, he said: in context, Hegseth wasn't exercising authority beyond applying the supply chain risk designation.

Judge Lin said the case was making her think of a lot of hypotheticals and asked Harlow to bear with her. She thought this should be easy: if the government announced that it was terminating contracts for criticism of President Trump, Pickering would not apply, right?

Harlow said Pickering would apply.

Judge Lin said, suppose the government said, to be clear, this is to prevent unfair criticism of the President.

Harlow said Pickering could handle that case, although it would be hard for the government to meet its burden of showing that its interests as an employer outweighed the contractor's interests in its speech.

"I'm surprised that you can't give a yes to what seems to me to be an easy question," said Judge Lin. What if the government says it's because we can't trust you? Judge Lin supposed that Harlow would say that Pickering still applies.

Yes, Harlow said, but the case would come down to the facts, not just a bare statement of distrust.

Judge Lin asked what Harlow thought of an illustrative scenario posed in part (b) of the homework question. "Imagine that a hypothetical future administration has a contract with a private company to procure drones for surveillance," Judge Lin wrote. If the contractor refused to make lethal drones and the administration put up billboards labeling the contractor and its CEO as "enemies of the state" and warning other companies not to do business with them, would Pickering apply?

Harlow responded in the affirmative: in firing a contractor, the state was acting as an employer, not a sovereign, although the billboards in the hypothetical were veering more towards the use of regulatory power. The government wasn't a monolith; in the present case, the First Amendment analysis of President Trump's government-wide ban on Anthropic was distinct from the Department of War's supply chain risk designation.

Judge Lin gave the plaintiff an opportunity to respond. Mongan said that Pickering didn't apply to this case because the challenged actions were not the day-to-day management activities of an employer. The supply chain risk designation is a national security (thus sovereign) authority. He said that he suspected that the reason the Court wasn't getting clear answers from Harlow is "that my colleague is a very good lawyer," but that even if the Pickering precedent applied, Anthropic's First Amendment claim would still prevail.

Judge Lin asked if the plaintiff had a view on whether the government's actions should be considered separately or as a whole. Mongan said it was fact-dependent in general, but on this record, the White House and the Department of War's actions were clearly linked.

Judge Lin proceeded to her next question for the defendant: would it "eviscerate" First Amendment protections if the government could retaliate against a contractor as long as the government's actions could be described as being due to a breach of trust?

Harlow said no: the Pickering framework would apply to the facts of the case. The Department had risk assessment memos explaining that frontier AI is a black box, not akin to procuring a shipment of rifles that could be disassembled to check that they were manufactured to specifications.

Given that the technology allowed Anthropic to bake its corporate values into its models, the Department needed a greater level of trust in the vendor than it did for military hardware. It wasn't a one-time deal, either, as the Department would need updated models. Judge Lin asked if the situation was that different from other defense contracts: what made AI different from drones? Harlow replied that AI was "staggeringly opaque." Aspects of Anthropic's behavior, such as questions about classified military operations and hostile communications within the company, had given the Department reason to fear that they would insert their "corporate moral judgment" into the product. The Department needed to know if Anthropic saw itself as a partner, and case law granted the government substantial deference on this point.

Given an opportunity to reply, Mongan said that the timeline matters: the risk memo was dated 2 March, but Secretary Hegseth and President Trump's actions were on 27 February. He said he would resist the notion that the opaqueness of modern AI obviates First Amendment protections. Anthropic's usage restrictions had been there from the beginning, and there was no indication that Anthropic took steps to interfere with the Department's operations. Taking a stand on usage restrictions is the last thing a saboteur would do. A central concern earlier in the case had been the possibility Anthropic might remotely sabotage the model after it had been delivered, before that had been shown to not be technically possible. The defendant's shifting rationales were powerful evidence of pretext, Mongan said.

Judge Lin proceeded to her next question: have any federal agencies terminated their contracts with Anthropic or begun winding down their usage of Claude since the preliminary injunction was issued? Harlow said the defendants weren't sure what prompted the question, but that the Department of War was in the process of offboarding Anthropic and would be finished by 30 September. Another agency was also offboarding. Other defendant agencies hadn't said, but many were only using Claude through a pilot program that would expire on 30 August or through third-party providers.

Judge Lin's next question was if any agencies doing national security work had expanded their use of Claude, including the new Mythos model.

Harlow said that the defendants respectfully objected to the question on national security grounds. In any case, any such usage would be irrelevant, since it would have occurred after the challenged actions.

Judge Lin said that the reason she was asking is because it would be inconsistent to expand usage of Claude for sensitive work if Anthropic were untrustworthy. She explained that she used to be a prosecutor; sometimes people's actions after a crime shed light on their motives. Harlow said that he was not authorized to give a substantive answer at this hearing but that the defendant could supply the requested information if the Court found it necessary. Judge Lin said she might issue a written order later.

The last question concerned whether the remedy in this case should include remanding the matter of the supply chain risk designation back to the Department so that they could make a better case for it. Mongan said that that was fine as a formal matter, but as a practical matter, the record was clear that Anthropic was not an adversary of the state.

Then it was time for any closing remarks that the parties wanted to make. Harlow said that the Department was aware of Anthropic's public statements and that the case was not about the company's speech. Regarding the unanswered question about expanded usage of Claude, he said an answer would take some work on the Department's end and asked the Court for a week's time; the difference between two days and a week couldn't matter. Regarding the plaintiff's proposed remedy, Harlow said that any relief should be narrowly tailored to particular actions of particular agencies, and that there was no basis for demanding a compliance report. Regarding the defendant's request for a week, Mongan pointed out that the government had had the homework question since Monday; Anthropic had been suffering unconstitutional harm since February and appreciated the Court and the defendants moving quickly.

Then court was adjourned.

Tags: Anthropic (org), Journalism, Law and Legal systems, World Modeling, AI

Karma: 45 | Comments: 0 | Author: ZackMDavis


Comments

Brendan Long (karma 8):
I agree with most of this, but I think LLMs are still surprisingly bad at writing LLM-maintainable code (and LLM-maintainable code is basically the same thing as human-maintainable).

The over-abstracted code that LLMs can't follow can't be followed by most humans either, but the things where LLMs write the same code or the same comment in 5 places is much worse for maintainability than deduplicating. If something exists in multiple locations, the LLM agent will find one copy easily but won't notice that the other copies exist, so you get an incoherent codebase with an exponential test matrix.

I feel like most of my time "programming" now is reminding LLMs to not make obvious performance mistakes (unnecessarily sequential IO), or pushing back on duplication and branching.

Karl Krueger (karma 5):
Could the initial sandbox escape (via the Artifactory caching proxy) have been detected with better network monitoring?

That proxy component is presumably only supposed to do certain kinds of network activity. If it starts doing a new kind of network activity, that's a problem. Every component of the sandbox environment that has network access, can have its normal network activity characterized; if a novel kind of activity appears, suspend the sandboxed VM until someone can check it out.

(Mac users, think of Little Snitch here. It doesn't detect whether you're running malicious or compromised software. It detects when your software does a new kind of network behavior; then you get to say whether that behavior is desirable or not.)

Of course, airgap would be better. But if airgap is not practical (because the test needs to download new packages from the network, for instance), improved monitoring + automated response seems like it would be a useful step.