The Constitutional AI Standoff: When Safety Principles Became Protected Speech

Readability (Flesch-Kincaid): Grade ~11-12 / 10-13 targetAvg sentence length: ~18 words / 15-22 targetPassive voice ratio: ~10% / below 15% targetNTP claim scan: 21 e-type sourced / 4 n-type / 3 resolved (McKinsey date corrected; EU AI Act confirmed; EU Omnibus conditional)


Previous article: Gen AI Tuesday Part 12: AI Brain Fry: When More Tools Mean Less Intelligence


GEN AI TUESDAY | PART 13

On 26 March 2026, a federal judge in San Francisco used a single word to describe a government action.

That word was "Orwellian."

It appeared in a 43-page preliminary injunction. The subject was not foreign espionage. Not state-backed sabotage. Not a hostile intelligence network. The subject was an AI company that had published two safety constraints on its model, refused to remove them when a government customer demanded it, and been designated a national security risk as a result.

Judge Rita Lin of the US District Court for the Northern District of California found that the Pentagon's supply chain risk designation of Anthropic was "likely pretextual." The real motive, Lin found in her review of the record, was "unlawful retaliation" for Anthropic's public criticism of the government's contracting position. Labelling an American company a potential adversary and saboteur for disagreeing with the government was, in Lin's characterisation drawn from the court record, Orwellian.

The Heaven/Skynet framework has provided the analytical lens across this series: one path toward AI development characterised by transparency and human governance, the other toward opacity and unchecked capability deployment. This article is different from those that came before. The framework is no longer a prediction. A federal court has started mapping it.


What Was Actually at Stake

The Anthropic-Pentagon dispute began in late 2024 through a Palantir partnership and expanded in March 2025 with the launch of Claude Gov, a version of Claude designed for classified network deployment. By early 2026, the parties were negotiating a contract worth approximately US$200 million to expand military AI access further.

The Pentagon's demand was specific: contract language granting "all lawful purposes" access to Claude, with no constraints on use for autonomous weapons or domestic surveillance. Anthropic held two positions. First, Claude would not be used in fully autonomous lethal weapons systems without human oversight of targeting decisions. Second, Claude would not be used for mass domestic surveillance of US citizens.

These constraints are not terms of service. They are embedded in the model's training. Constitutional AI, Anthropic's documented approach to AI development, encodes ethical principles as constraints on model behaviour. You cannot remove them by editing a contract. Retraining the model from that foundation would be required.

The Pentagon did not accept this. When Anthropic went public with the dispute in late February 2026 and CEO Dario Amodei published an AI safety essay explaining the company's position, the response was rapid. According to court documents cited by CNBC and CNN, a Truth Social post ordered all agencies to cease use of Anthropic technology immediately. Defence Secretary Hegseth designated Anthropic a supply chain risk within 24 hours.

The mechanism used, 10 U.S.C. §3252, had never previously been applied to a US-based company. It was designed for foreign adversaries: Huawei, ZTE, companies the US government concluded were extending hostile state intelligence capabilities into Western technology infrastructure. Lin's review of the Pentagon's own records showed the stated reason for the designation was Anthropic's "hostile manner through the press." That is not a technical security finding.



The Ruling and What It Did Not Settle

The preliminary injunction barred all 17 named federal agency defendants from implementing the supply chain risk designation and the presidential directive under §3252. The GSA restored Anthropic to federal procurement schedules on 3 April 2026 in compliance with Lin's order.

On 2 April, the Trump administration appealed to the Ninth Circuit. Assistant Attorney General Brett Shumate filed the appeal. The government's substantive arguments are due by 30 April 2026. A parallel designation under 41 U.S.C. §4713 continues to be contested in the DC Circuit; the Pentagon maintains that designation remains "in full force and effect" independent of Lin's order. Estimates put full resolution across both courts at one to two years.

The legal resolution is not settled. Hold that alongside what Lin's ruling did establish.

Lin's opinion drew on 303 Creative LLC v. Elenis, the 2023 Supreme Court decision holding that the government cannot compel a creative entity to produce expressive content that contradicts its values. Lin found that Anthropic's public statements on AI safety, including Amodei's essay and the company's published position, constituted protected expression on matters of public concern. Courts have long held that matters of public concern sit at the core of First Amendment protections.

The implication, stated carefully because this is a preliminary injunction and not a final ruling, is that Constitutional AI may constitute expressive content. Not contract terms. Not product features. Expressive content, with the constitutional protection that entails.

Lin was explicit about one boundary: the government is free to stop using Claude and procure a more permissive AI vendor. It cannot punish a vendor for having expressed constraints. This article does not claim the court held that vendors can impose any constraint on any customer. It held that retaliation against a vendor for publishing and defending constraints is unconstitutional.

That distinction matters more for enterprise leaders than the headline finding. The Anthropic case is not a precedent for vendor veto power. It is a precedent for vendor values protection.



The Governance Gap This Case Reveals

The series has tracked the Governance Gap since Part 5: the distance between organisations scaling AI adoption and organisations with the maturity to govern what they are deploying. Part 12 extended the gap from institutional to cognitive, establishing that human capacity to oversee AI tools has a ceiling and that most enterprise architectures are designed as if that ceiling does not exist.

This article introduces a third dimension: the contractual governance gap. The difference between what enterprises believe their AI vendor agreements cover and what those agreements have actually been tested against.

Every enterprise that has deployed a foundation model from a vendor with published model constraints, which now describes most enterprises deploying frontier AI, is party to an implicit governance framework they may never have examined in detail. Those constraints govern what the model will and will not do. Most enterprises have never considered what happens when their operational requirements evolve to require something the model refuses.

McKinsey's research on AI maturity has consistently documented this underlying dynamic: investment intent vastly exceeds operational maturity. Nine in ten organisations plan to increase AI investment, yet fewer than one in a hundred consider their AI deployment genuinely mature, meaning AI is fully integrated into workflows and driving measurable outcomes. The organisations scaling without maturity are the most exposed when vendor-customer tensions emerge. They will encounter the governance gap before they have built the framework to address it.

The Pentagon is the most powerful procurement customer on earth, negotiating a US$200 million contract with a vendor already deployed on its classified networks. If resolving that tension required federal court intervention, enterprise leaders should ask a direct question: what is our process for managing this conflict if it happens to us?



Who Filed Amicus Briefs, and Why That Matters

The breadth of support for Anthropic's position is itself a signal.

Amicus briefs were filed by Microsoft Corporation, the Cato Institute, the Electronic Frontier Foundation, the Foundation for Individual Rights and Expression, the First Amendment Lawyers Association, retired US military leaders, industry trade associations including ACT The App Association, the American Federation of Government Employees, and Catholic theologians. Google and OpenAI employees filed supporting briefs individually. Neither company filed as an institution.

The Cato Institute, a libertarian think tank, and the American Federation of Government Employees, a federal workers' union, do not typically file on the same side of anything. The Catholic theological argument drew on just war doctrine: any weapon capable of making targeting decisions without human input violates the principle of proportionality, and surveillance at scale undermines the dignity of the surveilled.

These are Heaven Vector arguments in theological language. The principle that humans must remain in the accountability loop, that AI deployment without human governance creates moral hazard regardless of the technical capability involved, cuts across political, institutional, and religious traditions in a way that suggests it touches something more fundamental than AI policy.

The breadth indicates this case has become a constitutional principle question, not an AI industry solidarity question. The answer will have implications well beyond AI governance.


AI Safety as Protected Expression: An Analytical Frame

Twelve articles into this series, the Heaven/Skynet framework has been applied to adoption statistics, workflow decisions, geopolitical competition, and digital sovereignty. This is the first time it has been tested in constitutional adjudication.

Judge Lin's language creates the conditions for a new analytical concept. We might call it AI Safety as Protected Expression: the proposition that embedding ethical constraints into AI model training constitutes expressive content that a state actor cannot compel the removal of.

To be precise about what this is and is not: it is an analytical synthesis derived from Lin's ruling language and the 303 Creative precedent. It is not a statement of settled law. The case is at the preliminary injunction stage. The Ninth Circuit and DC Circuit proceedings are open. The concept is introduced here as a lens for enterprise governance, not as a legal conclusion.

The analytical frame is useful regardless of how the courts ultimately rule, because it changes the question enterprise leaders should be asking.

The wrong question: does my vendor's AI model comply with my policies? This assumes the vendor is a passive supplier of a configurable tool.

The right question: do I understand the values my vendor has embedded in the model I have deployed, and does my governance framework account for what happens when those values and my operational requirements diverge?

The difference is the difference between procurement governance and AI governance. Most enterprises have the first. Most have not thought through the second.

For enterprise architects building governance frameworks on the Heaven Vector, this finding matters beyond the legal outcome. The ALEA model's Ethical Guardrails component, as developed in EA Thursday's Zero Trust series, must account for more than technical enforcement of constraints. It must account for the legal and contractual resilience of those constraints under external pressure. Technical guardrails can be challenged at the procurement layer, as the Anthropic case demonstrates. Governance architecture that does not address this dimension has a structural gap.



The NZ Context

New Zealand has no statutory equivalent to 10 U.S.C. §3252 or 41 U.S.C. §4713. The specific legal mechanism used against Anthropic, a foreign-adversary supply chain designation, has no current NZ counterpart. The specific confrontation that produced the Lin ruling could not replicate here in the same legal form.

The operational version can occur here. A government agency deploys an AI tool and later requires a use the vendor's model constraints prohibit.

The GCDO Responsible AI Guidance for the Public Service addresses transparency, accountability, and risk management in AI procurement. It explicitly requires "oversight by accountable humans with appropriate authority and capability at every stage." What it does not define is the governance process for resolving conflicts between a vendor's embedded model constraints and an agency's operational requirements. The Anthropic case demonstrates that this gap is not hypothetical.

The Government Digital Delivery Agency became operational in April 2026 under the Public Service Commission and absorbs the GCDO function, taking responsibility for all-of-government AI vendor procurement. The GDDA's mandate includes AI supplier strategic agreements and management of AI categories in the government Marketplace procurement platform. This is the first time New Zealand has had a centralised procurement authority with explicit AI vendor management responsibility.

The governance question the Anthropic case raises, what frameworks govern the relationship between a vendor's model constraints and a government customer's operational requirements, is now a question the GDDA will need to address over time. Not because the Pentagon scenario will repeat here identically. Because the underlying tension is universal.

Boards and senior leaders with AI vendor relationships should note this dynamic. The Cyber Sunday series has examined how supply chain governance is a board-level responsibility. The Anthropic case confirms that supply chain risk designations can be applied, even when found to be improper as Lin found in this instance, to domestic vendors for having published safety constraints. Understanding your AI vendor's model constraints is not optional governance due diligence. It is foundational.



What to Do Before the Ninth Circuit Rules

The government's substantive arguments are due to the Ninth Circuit by 30 April 2026. This article publishes 15 April. Enterprise leaders have two weeks before the next inflection point in a case reshaping AI vendor governance. Three actions apply now, independent of how the courts ultimately rule.

Audit your vendors' model constraints. If you have deployed a foundation model, you have accepted a set of design decisions you may not have explicitly reviewed. Read your vendor's model card, acceptable use policy, and published AI safety documentation. Understand what the model will and will not do. This is not a compliance exercise. It is operational risk management.

Test your conflict resolution process. If your operational requirements evolved tomorrow to require something your vendor's model constraints prohibit, what is your governance process? The GCDO guidance requires human oversight at every stage. Human oversight of an AI refusal requires a different governance mechanism from human oversight of an AI action. Most organisations do not have a documented process for the first scenario.

Understand the distinction the court drew. The government is free to choose a more permissive vendor. It cannot punish a vendor for having constraints. For enterprise leaders: you have the same right to choose. You do not have the option to demand constraint removal through commercial pressure. If your requirements exceed your vendor's model constraints, you need a different vendor or a different requirement. The clarity emerging from this case, whatever the final ruling, is that this is a vendor selection question before it is a contract negotiation question.



Two Governance Mechanisms, One Destination

The Anthropic case is not an isolated constitutional dispute. It is one of two major governance mechanisms converging on the same question in 2026: who governs AI behaviour, and on whose terms?

The European Union has answered through regulation. The EU AI Act's Article 4 AI literacy mandate entered force in February 2025; national enforcement authority activates on 2 August 2026, requiring organisations deploying AI to ensure staff have AI literacy proportionate to their role and the system in use. The Anthropic case is, in part, a test of organisational AI literacy at its most consequential level: does the executive team understand what its vendor's model constraints actually are, and what happens when operational requirements conflict with them?

The Digital Omnibus proposal currently before EU legislators, if enacted, would shift the Article 4 literacy obligation from deployers to member states and the Commission. The enforcement date remains on track for 2 August 2026 unless the Omnibus is adopted before then. Verify current legislative status at publication.

The United Kingdom has answered the governance question through voluntary cooperation: the AI Safety Institute model of engaging frontier labs as partners rather than regulating them as risk sources. The Anthropic case stress-tests that model. Voluntary cooperation requires that vendor constraints be respected by government customers. If the US government's position had prevailed, that procurement terms can override model constraints, the voluntary cooperation model would have no floor. The enterprise that cooperates voluntarily with a vendor's principles can have that cooperation overridden by a more powerful party.

The US is now answering the question through constitutional adjudication, case by case, appeal by appeal. Each mechanism produces different compliance timelines and different certainty levels. What they share is the underlying question: when an AI vendor's design principles and a customer's operational requirements diverge, which governs?

The Anthropic case is the first time that question has been answered, even provisionally, by a court.


Where the Series Is Heading

Part 5 established the governance gap as institutional: organisations scaling AI without the oversight frameworks to match. Part 12 established the cognitive governance ceiling: even well-governed organisations will overwhelm their human reviewers if tool adoption outpaces human capacity. This article establishes the legal governance dimension: the constraints embedded in your AI tools may have legal standing, and your governance framework needs to account for what happens when those constraints meet your operational requirements.

The series is building toward a governance architecture argument. The tools are constrained. The humans are limited. The legal frameworks are being established in real time. What enterprise leaders build now will determine whether their AI governance is a designed system that holds under pressure or a scramble to catch up after the fact.

Anthropic drew two red lines and went to court to defend them. Your organisation's governance framework should be clear on where yours are before you have to.

Next week in Part 14: [Teaser TBC from book project]


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is an enterprise architect and technology leader based in Wellington, Aotearoa New Zealand, with more than 30 years of experience in mission-critical platforms, open source deployment, and responsible AI governance. He holds TOGAF, IAPP, and AMInstD credentials and is a publicly identified NZ leader in Architecture and Security. The Hamberger Report: Generative AI 2026 is published as a 36-part LinkedIn series.

The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] CNBC. "Federal Judge Blocks Pentagon from Blacklisting Anthropic as Foreign Adversary Supply Chain Risk." 26 March 2026. [URL]

[2] CNN. "Judge Issues Preliminary Injunction Restoring Anthropic to Federal AI Contracts." 26 March 2026. [URL]

[3] AP. "Trump Administration Files Ninth Circuit Appeal in Anthropic-Pentagon Case." 2 April 2026. [URL]

[4] Axios. "Ninth Circuit Timeline: Government Arguments Due 30 April in Anthropic Case." 2 April 2026. [URL]

[5] Breaking Defense. "Pentagon Designated Anthropic Supply Chain Risk After Public AI Safety Dispute; §4713 Designation Remains Contested." March/April 2026. [URL]

[6] Defense One. "Claude Gov and the Contract That Went to Court." March 2026. [URL]

[7] Inside Defense. "DC Circuit: Pentagon Maintains §4713 Designation Is In Full Force and Effect." April 2026. [URL]

[8] National Catholic Register. "Catholic Theologians File Amicus Brief in Anthropic Case; Just War Doctrine Applied to Autonomous Weapons." 30 March 2026. [URL]

[9] McKinsey and Company. "Superagency in the Workplace: AI Maturity and Investment Research." January 2025. https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/superagency-in-the-workplace-empowering-people-to-unlock-ais-full-potential-at-work

[10] Supreme Court of the United States. "303 Creative LLC v. Elenis." 600 U.S. 570 (2023). [URL]

[11] GCDO/DIA. "Responsible AI Guidance for the Public Service." digital.govt.nz. https://www.digital.govt.nz/standards-and-guidance/technology-and-architecture/artificial-intelligence/public-service-ai-framework

[12] Reseller News. "Government Digital Delivery Agency: Mandate, Structure and AI Procurement Scope." December 2025. [URL]

[13] European Commission. "EU AI Act: Article 4 AI Literacy Obligations and Supervision Timeline." digital-strategy.ec.europa.eu. https://digital-strategy.ec.europa.eu/en/faqs/ai-literacy-questions-answers

Previous
Previous

THE $30 BILLION SIGNAL: WHAT ANTHROPIC'S REVENUE EXPLOSION MEANS FOR ENTERPRISE AI

Next
Next

EU AI Act, Africa's Leapfrog, and What They Mean for Your Strategy