A US judge ruled the DoD illegally punished Anthropic for refusing mass surveillance work. The implications reach every EU AI operator.
elcome to issue nineteen. This week's biggest story has nothing to do with Brussels, yet it says everything about why the AI Act exists. A federal judge ruled that the US Department of Defense unlawfully retaliated against Anthropic for refusing to let its technology be used for mass surveillance. Meanwhile, Texas and Florida are pulling back automated licence plate reader networks, proving that public pressure on AI surveillance can actually win. We dig into both, and explain what they mean if your business depends on any of these tools.
Let’s go.
yours, Flux

Flux Weekly is a 6-minute briefing for people who have to actually make AI work in Europe. Sole traders to enterprise, one issue every Friday morning.

- New We added a vendor ethics section to the Flux compliance checklist this week, prompted by the Anthropic ruling: it now prompts you to document which use cases your AI suppliers have formally refused.
- Updated The Flux ALPR risk tracker has been updated to reflect the Texas and Florida rollbacks, relevant if your business uses vehicle or footfall analytics tools that rely on similar sensor networks.
- ICYMI If you missed issue 18, the EU AI Office has already sent formal requests for information to model providers, so the enforcement clock is running whether or not your suppliers have told you about it.
A US Judge Ruled the Pentagon Illegally Punished Anthropic for Refusing Mass Surveillance Work, and That Should Matter to You

The ruling in plain English. A federal judge found that the US Department of Defense designated Anthropic a 'supply chain risk' specifically because the company told the military it would not allow its technology to be used for mass surveillance of US persons. The court called that designation unlawful retaliation against protected speech. Anthropic refused, got punished, and then won in court. That sequence is worth sitting with.
Why this lands in your inbox. EU operators building on or procuring from major AI model providers now have a concrete data point: at least one leading model company has a documented, court-tested position against mass surveillance use. That is exactly the kind of vendor ethics record your AI Act due-diligence process should be capturing. If your procurement team is not asking suppliers about use-case refusals and their track record, this case is your prompt to start.
Does your AI inform a decision that affects a person's job, credit, education, or essential service?

- ✓No new enforcement actions published this week, but the AI Office's RFI programme from issue 18 continues to run in the background.
- ✓Meta's $17 billion US settlement includes age-assurance requirements that mirror debates already live under the EU's Digital Services Act.
- ✓California's AB 1709 social media ban for under-16s passed the legislature, adding to the global patchwork of age-gating rules that EU operators must track.
- ~Texas Governor Greg Abbott banned certain automated licence plate reader deployments on 28 August, a significant rollback of mass surveillance infrastructure.
- ~


- 1Anthropic Usage Policyvendor policy
Anthropic's public document listing prohibited use cases for its models, including surveillance of individuals.
Why we like it. After this week's ruling, this is the baseline example of what a documented use-case refusal policy looks like. Screenshot it for your procurement folder.
- 2EFF's Surveillance Self-Defenceprivacy toolkit
A practical guide from the Electronic Frontier Foundation covering digital threat modelling for individuals and organisations.
Why we like it. If you are responsible for employee data or customer data processed by AI tools, the threat models here map directly onto your AI Act data governance obligations.
- 3EU AI Office GPAI Code of Practiceofficial guidance

The Best Compliance Signal This Week Came from a US Courthouse
By John Ferguson
I will be honest: when I first read the Anthropic ruling, my instinct was to file it under 'interesting US legal drama, not my problem.' Then I read it properly.
A court found that the US government retaliated against an AI company for refusing to enable mass surveillance. The company had a written ethics position. It refused a specific use case. It documented that refusal. And when it got punished for that, it had something concrete to take to a judge.
That is the AI Act due-diligence dream scenario playing out in real life, just in a different jurisdiction. The AI Act asks you to assess the providers you build on. This ruling tells you exactly what a good provider looks like when things go sideways: they have positions, they enforce them, and they can prove it.
If your vendor shortlist does not include questions about documented use-case refusals, this week is a good week to add them. Four hundred and forty-seven days is not as long as it sounds.
John Ferguson · Founder, Agentic Fluxus

Short answer.Because the model providers you buy from operate globally, and their conduct in other jurisdictions shapes how trustworthy they are in yours. The AI Act requires you to assess third-party AI components before deploying them. A vendor with a court-tested record of refusing harmful use cases is easier to defend in an audit than one without any documented ethics position at all.
Does your vendor due-diligence process include asking suppliers about use cases they refuse?

The US Department of Defense designated Anthropic a 'supply chain risk' after the company refused to let its models be used for mass surveillance of US citizens. A federal judge ruled that designation was unlawful retaliation against protected speech.
Meta settled with 52 state attorneys general for $17 billion over child safety failures, but the Electronic Frontier Foundation says the settlement actually makes things worse by mandating age-assurance technology that surveils all users, not just minors.

