In March, the Pentagon designated Anthropic PBC a “Supply-Chain Risk to National Security” under 10 U.S.C. § 3252, a statute aimed at adversary sabotage and subversion of covered defense systems. The designation followed Anthropic’s refusal to drop policies restricting Claude’s use for lethal autonomous warfare and mass surveillance of Americans. President Trump publicly described the company as “leftwing nut jobs” who had made a “disastrous mistake trying to strong-arm the Department of War,” and ordered a government-wide ban of Claude. Judge Rita Lin of the Northern District of California granted a preliminary injunction, finding that the record strongly suggested the government’s stated reasons were pretextual.
Anthropic’s designation belongs to a broader emerging pattern. In parallel cases, district courts have permanently enjoined executive orders that used security-clearance suspensions and contracting bars to penalize law firms for representing the president’s adversaries. In Zaid v. EOP, for example, Judge Amir Ali ordered Mark Zaid’s clearance restored after concluding that the government had stripped Zaid of his clearance, without explanation or process, in retaliation for his whistleblower representation work. In all of these cases, the executive reached for national-security authority as a pretext to punish protected conduct, and courts found that the security justification did not fit the action.
These cases expose an unresolved tension between two Supreme Court precedents: deference to executive security judgments in Trump v. Hawaii (2018), and refusal to accept contrived pretextual rationales in Department of Commerce v. New York (2019). The two can be reconciled by asking what kind of judgment the executive has made. Courts should defer where the executive is making a bona fide operational security judgment. But where the executive uses a national security authority to impose collateral punishment, and the record contradicts the stated security rationale, judicial review should not be displaced.
The Doctrinal Gap
In Trump v. Hawaii, the Court applied the deferential “facially legitimate and bona fide” standard drawn from Kleindienst v. Mandel, a 1972 immigration-exclusion case. Although the Court assumed it could “look behind” the proclamation, it applied rational-basis review and asked only whether the policy was plausibly related to the government’s stated objective. While Hawaii arose in the immigration-entry context, its logic follows the Court’s broader explanation that national security threats are predictive and complex, matters in which the executive has institutional advantages over courts.
A year later, in Department of Commerce v. New York, the Court took a different posture. Secretary Ross wanted to add a citizenship question to the upcoming census. To justify his request, he asserted the question was added to enhance the administration’s efforts to enforce the Voting Rights Act. When reviewing the record, the Supreme Court found a “significant mismatch between the decision the Secretary made and the rationale he provided,” and that his rationale “seems to have been contrived.” The Court held that even when agencies have discretion, they must still provide “genuine justifications for important decisions.” The Court therefore held that the action could not stand, explaining courts are “not required to exhibit a naivete from which ordinary citizens are free.”
Those two cases did not have to confront each other as Hawaii sits at the national security-foreign-affairs pole while Department of Commerce sits at the administrative-law pole. The tension arrives when the agency action invokes national security authority, and the record suggests that the agency’s rationale is pretextual. Neither precedent establishes the standard of review governing administrative actions that invoke national security to justify legal sanctions.
What Anthropic Shows
If the Department of War concluded that Claude could not be used in sensitive military settings, courts would have strong reasons to defer to an operational judgment within the executive’s area of expertise. But as the Department used a supply-chain risk designation to punish Anthropic for public advocacy, the case looks different. The issue is whether the national-security authority became a vehicle for retaliation.
The record in Anthropic, as Judge Lin explained at the preliminary-injunction stage, showed a domestic contract dispute over AI usage restrictions, followed by a public presidential attack and a sweeping government-wide effort to shut the company out rather than reflecting § 3252’s concern with sabotage.
The court explained that the Pentagon had granted Anthropic a Top Secret facility security clearance and a $200 million contract during the same period; it later said the company posed a sabotage risk. Nothing in Judge Lin’s order required the Department of War to use Claude in classified systems or sensitive defense operations. The government remained free to stop using Anthropic’s products and find a more permissive AI vendor. What the injunction blocked was the move from refusal to pretextual sanction: the secondary blacklisting, and the de facto government-wide debarment.
Similarly, this pattern was present in the law firm cases. Courts held that the asserted security rationale could not be used as a cover for retaliation. The same was true in Zaid, where national-interest language sat alongside public presidential statements attacking Zaid for protected whistleblower work. As Judge Ali put it, “These are not political questions; they are legal ones.”
A Framework
These cases call for an inquiry that applies an appropriate level of scrutiny, and it should turn on three record-bound questions.
First, is the action an operational judgment or a legal sanction? The government’s decision to use or restrict access to a tool, like Claude, within the national security operational core, such as military systems, deserves substantial deference. A supply-chain risk designation that pressures third parties not to deal with Anthropic, coupled with a government-wide ban, goes beyond operational judgment and imposes a legal sanction.
Second, does the stated security rationale fit the consequence imposed? Security authorities are enacted for specific risks, such as Section 3252 targeting supply-chain sabotage and subversion. The government’s multipronged targeting of Anthropic with government-wide ban, blacklist, and a designation as a national-security threat did not align with the government’s limited rationale. Where the consequence exceeds the risk the statute addresses, the authority has been stretched past the concern that justifies it.
Third, does the objective record support or contradict the stated rationale? This inquiry stems from the Department of Commerce’s rule requiring courts to compare the government’s rationale with the record. Accordingly, where the record itself reveals a significant mismatch between the action taken and the rationale provided, courts “must demand something better than the explanation offered.” In Anthropic, the relevant facts, the timing of the designation, the president’s public statements, and the prior contract and existing clearance, revealed a significant mismatch and were neither speculative nor dependent on intrusive inquiry.
Why Egan Still Applies Where It Should
The principal objection is that pretext review will invite courts into matters they cannot competently judge. Department of the Navy v. Egan (1988) grounds security-clearance deference in the President’s Article II responsibilities and warns that courts have been reluctant to intrude on military and national-security judgments absent clear congressional direction. Justice Thomas made a related point in his Department of Commerce dissent: pretext review, he warned, could transform administrative law because political opponents can always accuse the executive of bad faith.
Judicial competence supplies an important limit on pretext review. Egan’s strong deference to executive judgments about who may access classified information should remain controlling when the action is addressed to classified access or intelligence systems alike. Courts should not decide whether a particular analyst should receive compartmentalized access, or how much weight to assign to sensitive intelligence.
The framework asks whether an action that imposes legal sanction is genuinely tied to the security rationale asserted for it. This requires courts to perform the familiar judicial task of comparing the stated rationale against the record. Even where national-security decisions are committed to agency discretion, Webster v. Doe preserves constitutional claims for courts to review.
Applying Hawaii-style deference whenever the executive uses national security authority turns deference into a labeling trick, detached from the institutional competence that justifies it. This would allow the executive to convert political disputes into national security matters by relabeling them.
Squaring the Cases
As a result, executive actions in the operational core should continue to receive substantial deference, consistent with Hawaii’s recognition of the executive’s institutional advantages in assessing national security risk. When executive action imposes punishment under national security authority, courts should not give heightened deference merely because a security justification has been invoked. In these cases, courts should apply Department of Commerce’s pretext review to determine whether the record shows a mismatch between the rationale offered and the action taken. Anthropic v. Department of War illustrates this distinction. The government remained free to stop using Claude, but it could not transform a contract dispute into a national-security sanction. Deference follows expertise. It does not follow pretext.


