Logo
FrontierNews.ai

Federal Judge Blocks Pentagon's Ban on Anthropic, Ruling Safety Guardrails Are Protected Speech

A federal judge has blocked the Pentagon's attempt to blacklist Anthropic, ruling that the company's decision to maintain safety guardrails on its AI models is protected speech under the First Amendment. The decision marks a significant legal victory for Anthropic and sets a precedent that refusing a customer over safety policies cannot be classified as a security defect.

Why Did the Pentagon Try to Ban Anthropic?

The conflict began when Anthropic refused to remove guardrails that prevent its AI models from being used for fully autonomous weapons targeting or mass surveillance of US citizens. In response, Defense Secretary Pete Hegseth designated Anthropic as a "supply chain risk" and instructed federal agencies to stop using its tools. Anthropic challenged the designation in court, arguing it was unlawful retaliation that violated the company's free speech and due process rights.

US District Judge Rita Lin issued a 59-page ruling on August 27, 2026, finding the Pentagon's actions violated the First Amendment and were "arbitrary and capricious." Lin wrote that "the empty invocation of national security is not a blank check to punish and retaliate against government critics," directly addressing the government's use of national security as justification.

The judge flagged a critical inconsistency in the Pentagon's position: while publicly invoking the Defense Production Act as a lever to cut off Anthropic, the Department of Defense was simultaneously pursuing contracts with the company and collaborating on Mythos, Anthropic's cybersecurity model. "You do not invoke national security to cut off a vendor you are also trying to buy from," Lin noted.

What Does This Mean for Government AI Policy?

The ruling is narrower than headlines suggest. Anthropic challenged two separate designations, and a parallel case in Washington DC remains pending, meaning the company is technically still labeled a supply chain risk today. However, the decision establishes a crucial legal principle: a company's safety policy is protected speech, and refusing to modify that policy cannot be treated as a security vulnerability.

Paradoxically, the same week the Pentagon lost in court, it deepened its reliance on Anthropic's models. NSA Deputy Director Tim Kosiba announced that the agency intends to use a voluntary pre-release testing framework that gives the government up to 30 days with qualifying frontier models before public release. "We want access to all the models," Kosiba said, confirming the NSA already uses Mythos experimentally to test military network defenses.

Tim Kosiba

This creates an unusual dynamic: the institution that spent a year punishing Anthropic over its refusal to lift safety limits is now deepening its dependence on that lab's models and requesting early access to new ones.

How Is Anthropic Expanding Its AI Capabilities?

Beyond the legal victory, Anthropic has rolled out significant product updates that expand Claude's ability to handle real-world business tasks. The company released a native built-in browser for Claude and officially launched Claude in Chrome to all paid users, moving both tools out of limited pilot phases.

The built-in browser operates independently from your personal browser, allowing Claude to complete web-based tasks without touching your tabs, bookmarks, or login credentials. When you assign Claude a task requiring internet access, such as "Pull this month's invoices from the supplier portal," the browser automatically opens in a sidebar and handles form filling, data extraction, and navigation.

Claude in Chrome, which exited its pilot phase on the same day, now performs actions autonomously with security verification. Each action is checked by a security classifier before execution to ensure it matches your original request. Users concerned about autonomous actions can disable this feature and require manual approval for each step.

What Security Measures Protect Against AI Misuse?

Anthropic implemented three layers of protection against prompt injection attacks, which occur when malicious instructions hidden in web content try to override a user's original commands.

  • Probe Scanning: Anthropic scans web content for known attack patterns before Claude interacts with it, comparing proposed actions against your original request.
  • Security Classifiers: A trained classifier blocks actions that deviate from your instructions, with the attack library updated continuously from internal testing, external red teams, and real-world monitoring.
  • High-Risk Site Blocking: Anthropic directly blocks access to certain high-risk sites, though users can override this when necessary.

Testing showed dramatic improvements in security across Claude's model lineup. Against attacks constructed by professional red teams, the success rate dropped from 17.6% (without protection) to 3.8% when tested against Claude Opus 4.5. After adding probes and security classifiers, attack success rates fell to zero for Claude Sonnet 5, Claude Opus 5, and Mythos 5, with Claude Fable 5 at just 0.3%, all manually confirmed as low-risk scenarios.

However, Anthropic acknowledged the limits of these defenses. The company stated that "these measures can significantly reduce risks but cannot eliminate them, and prompt injection is always a moving target." Attacks blocked today may not be blocked tomorrow.

Anthropic

How Should Users Approach AI Browser Tools Safely?

Anthropic recommends a cautious approach to the new browser capabilities, particularly for sensitive data.

  • Start with Trusted Sites: Begin using the built-in browser or Claude in Chrome only with websites you trust and have used before.
  • Monitor Financial and Personal Tasks: Do not leave tasks involving money, medical information, or other people's personal data unattended; watch the process and stop immediately if anything seems unusual.
  • Selective Login Import: By default, Claude cannot see your browser tabs, bookmarks, or passwords. You can selectively import login credentials by site, and banking, email, and single sign-on sites are not imported by default.

The contrast with OpenAI's approach is striking. OpenAI launched Atlas, a standalone AI browser with a Chromium kernel and ChatGPT embedded in the sidebar, on October 21, 2025. The product was shut down on August 9, 2026, after just 292 days. OpenAI's narrative at launch emphasized that "the browser is the new entry point, and whoever controls the browser will control the AI era." However, the company ultimately concluded that asking users to switch browsers was too high a barrier, as it required moving bookmarks, passwords, extensions, and entire work identities.

Anthropic took a different approach: instead of asking users to adopt a new browser, the company integrated the browser into Claude itself. When a task requires web access, the sidebar automatically opens a dedicated browser window, eliminating the need for users to change their primary browsing environment.

What Do Recent AI Benchmarks Show About Claude's Performance?

In a newly released scientific benchmark called Terminal-Bench-Science, which tests 70 expert tasks across five scientific fields, Claude Opus 5 led the field at 30.0%, ahead of GPT-5.6 Sol at 22.4% and Claude Fable 5 at 21.4%. Claude Opus 4.8 scored 10.5%. Notably, the performance gap between generations of the same model was wider than the gap between different labs' models, suggesting that model iteration matters more than brand loyalty.

Anthropic also released Claude Fable 5, a smaller, more efficient model, as part of its expanding lineup. The company now offers Claude Opus (its most capable model), Claude Sonnet (a mid-tier option), Claude Fable (for cost-sensitive applications), and Mythos (specialized for cybersecurity), giving users options across different performance and cost profiles.

Anthropic welcomed the court ruling and stated it remained "focused on working productively with the government to harness AI for our national security so all Americans benefit from this technology." The company has maintained that certain AI uses would be incompatible with democratic values, particularly mass domestic surveillance and fully autonomous weapons systems.