U.S. appeals court upholds designation of Anthropic as supply chain risk

5 hours ago (cnbc.com)

I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

>The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

  • > I know everyone says this is political but it actually seems like a textbook designation

    It literally is a textbook definition, signed into US law:

    “Supply chain risk,” means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).

    To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

    • Selling a pen labeled "this pen will refuse to sign certain orders" is not sabotage or malicious and is thus not a supply chain risk. The DoD is free to not buy from Anthropic, but designating them as a supply chain risk is incorrect, as well as arguably arbitrary and capricious given their public criticism of Anthropic's beliefs.

    • The pen example makes sense if the intermediary were to ship the pen as part of the final product but not if the pen is simply used to draft designs of the final product. It seems that this designation would prohibit using the pen anywhere in the process which doesn't really make sense.

    • > so as to surveil

      How does Android and iPhone meet the grade given apps have pretty consistently leaked locations, base layouts etc?

      1 reply →

    • It is not the textbook definition, because what Anthropic is doing is not sabotage, malicious, or subversive. Those are the key words in the definition. They are just refusing to add a feature to the military's specification. So their bid falls short of requirements.

      3 replies →

  • I think the better analogy is an insane nuclear power plant manager deciding it wants to buy pens to use as neutron-flux regulator rods — because after all, a pen is functionally a pencil and a pencil is made of graphite.

    Then the pen manufacturer hears about this and says “Our pens are not made of graphite and are not suitable to be used in nuclear reactors”, to which the reactor owner says “it’s fine, they fit in the graphite rod holes, and we’re just using until the next generation of pens come out which will do an even better job”, and then the pen manufacturer says “I’m not going to sell you any pens until you agree that they will be used only writing.”

    • The previous power plant manager had, of course, already signed a contract to those terms; the power plant is subsequently under new management and upset about being bound by this contract, so they designate that none of their suppliers of parts and fuel are allowed to have any commercial dealings with the pen manufacturer or use these pens for any purpose, even writing.

    • This is the most accurate parallel as far as I can tell. I've not seen any evidence that Anthropic deliberately built automated systems or escape hatches that literally prevent the US Government from using Claude to do these things. Other than the basic AI Safety mechanisms in place for everyone/general use. It's almost the reverse, where they explicitly don't want to strip away guardrails that say things like "don't kill people".

      The intent and framing matters a lot here. Refusal to remove safety features is a LOT different than deliberately building mechanisms to sabotage would-be operations.

  • I think you're confused. When the White House decided to stop having federal agencies buy paper straws [1], they didn't designate paper straws a supply chain risk, they just stopped buying them. The term has a very specific meaning which would not apply in the pen scenario.

    [1] https://www.whitehouse.gov/presidential-actions/2025/02/endi...

    • It's not a great analagy; it's more like a pen manufacturer not wanting their pens used to sign drone strike orders, who then only ships pens with cameras and solenoids so that the point stays retracted until the camera verifies that the paper doesn't include a drone strike orders.

      2 replies →

  • You could use the same logic to defend the military declaring that Anthropic is full of pedophiles and therefore they cannot use their products as it would be contributing to pedophilia.

    Anthropic offered a contract, with certain conditions, as do all contracts everywhere; that's their purpose. The military did not want to agree to those conditions. If they had stopped there, and refused to sign the contract, all would be good.

    > >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized [emphasis mine]

    That is speculation, and you can't call it a "textbook designation" without discussing whether there's a basis for that "reasonable fear". Again, that argument also works for declaring you have a reasonable fear that giving money to Anthropic will support pedophilia. We do not know the specifics, but I at least have heard of zero evidence that Anthropic would sabotage something they signed a legal contract for, and yet I have an abundance of evidence that this administration will use whatever contortions are necessary to pressure and punish those who interfere with it getting what it wants. It all hinges on the word "reasonable", and based on the evidence that is public, this specific fear seems more ridiculous than reasonable to me.

    If the government somehow had a way to force Anthropic to sign a contract that it did not want to sign, then this fear might become more reasonable. The twist is that this supply chain risk designation is exactly that. If Anthropic now capitulated, the accusation of supply chain risk (eg from Anthropic employees acting alone) would be justified. So the only way Anthropic can reasonably be considered a supply chain risk is because it is accused of being a supply chain risk.

    This is a textbook example, yes, but it's a textbook example of corruption and judicial capture.

    > Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    And if they signed a contract permitting fully autonomous killbots, then using the whitelist mechanism would be a contract violation. I have some degree of faith that we'd know if such a contract were signed, because half the staff would quit. (As opposed to half the Google staff quitting after signing such a contract, which has been proven to be an incorrect expectation -- such a contract was signed, and I've heard of exactly one person quitting over it. There may be more, I don't know.)

  • Anthropic did not change the terms. Those were the terms the US Government signed. It was not secret, it was explicit identified and accepted as a term.

    The analogy would be: “A customer agreed to a contract, and after running into a clause of the contract they no longer wanted to follow…canceled the contract unilaterally…which also violated the contract.”

    • And then declared the other side a supply chain risk, claiming it is a potential vector for a national adversary to break in and cause unwanted bad things to happen unrelated to this contract.

      It seems like absurdly bad faith starting at breaking the contract (over "you have to follow the law", no less!) and then to retaliate after that with trying to destroy the company's reputation and ability to do business. The boot licking going on here justifying the government operating in bad faith is both disappointing and short sighted. I didn't think the leopards would eat MY face!

  • “the military said no and therefore doesn't want anthropic used anywhere in their supply line”

    It’s clearly a punitive measure and has nothing to do with national security.

    If a supplier uses Anthropic to develop a product, how does that pose a risk to the DoD or national security? The DoD can specify that a third party system can’t rely on Anthropic for DoD use without designating the company a supply risk. It was very clear that the administration was punishing the company for saying “no”.

    • Anthropic took the position that our military’s decision making power should be subordinate to Anthropic’s constraints.

      Any dependency on a company that thinks they have that moral authority and has the technical means to enforce it is absolutely a risk to the supply chain.

      If you want to blame someone or something for this, we should start with Dario and “effective altruism”.

      7 replies →

  • > This is like a pen manufacturer not wanting their pens used to sign drone strike order

    I am pretty receptive to the "guns don't kill people, people kill people" argument, but we are taking a big leap from pen to llms/artificial intelligence. I am sympathetic to some of your other points, but I simply must reject this analogy.

    • "the government wants to use our tool to murder people", and declaring that company that says "no" into a "supply chain risk" is absolutely retaliatory and an attempt by the government to influence the behavior of the company.

      The moral and ethical scale of the issue makes this far different than someone buying a pen.

      2 replies →

    • Ridiculous hypothetical for analogy purposes, but, imagine if Anthropic had developed a new type of rifle that the military was considering using, which had a black-box AI system that could prevent the trigger being pulled when aimed at certain targets. The military says, ok that's cool, as long as we can be in control of that decision-making process. Anthropic says, no, we know better than you and better than the law what kind of targets should and should not be shot with our rifles. The military would then respond “lol, lmao even” and then deem them to be a supply chain risk and adopt another rifle instead.

      5 replies →

  • Non-sense. Pentagon has many many uses of AI besides autonomous weapons and mass domestic surveillance, which Anthropic doesn't restrict. ie: intelligence analysis, target selection, payroll, inventory, research, supply chain and logistics, medical, bureaucracy, ...

    • Right but the military wants to be able to use a tool they are paying for in all cases, not just ones the manufacturer thinks they should.

      If I sold steel to the Pentagon but then tried to say they they couldn't use it for ships and tanks but they are free to use for warehouses they would react the same way as they are doing now.

      Edit add: What is targeting? What is surveillance?

      If someone in the intelligence analysis department uses AI to generate a report, then someone else uses that report for targeting did they just break the terms? Where is that line?

      Much easier for the Pentagon to say no.

      2 replies →

    • We cannot subordinate our military’s decision making power — in any arena — to a private company.

      Our military must also not be dependent on a private company that believes it has the moral prerogative to control our military’s decisions, and would have the technical capability to do so.

      6 replies →

  • Wouldn't that make any product with a licensing agreement a supply chain risk?

    • No, of course not, because life isn't black and white. Just those with licensing agreements that conflict with the militaries mission, where the product could be manipulated to hinder the mission. Most manufacturers would jump at the chance to rewrite their licensing agreements specifically for the military just to get a government contract.

      3 replies →

  • > Anthropic wanted to have rules on how the military used AI

    No, they want to have rules on how the military used Anthropic AI.

    Military would still be free to use OpenAI for the nasty stuff

    • Yes, in fact the military has a system in place to make sure that they only that they only use alternate suppliers and on Anthropic AI, They do this by placing a designation on Anthropic AI that it is a risk to the supply chain, which forces purchasers to use other suppliers.

      1 reply →

  • The reason it appears corrupt is that OpenAI has the exact same restrictions (https://openai.com/index/our-agreement-with-the-department-o...) but was not declared a supply chain risk. If two vendors have the same restrictions and they only designate one, then the designation must be arbitrary and/or capricious.

    Edit: I was wrong, the statement I linked is extremely dishonest and I was misled. The contract language lower down makes it clear that there are no "red lines", and OpenAI products can in fact be used for mass domestic surveillance, autonomous weapons, and social credit systems as long as they are considered legal.

    • >OpenAI has the exact same restrictions

      No it doesn't. Specifically OpenAI had a "all lawful purposes" clause (which plausibly includes the existing mass surveillance apparatus), but Anthropic did not.

      1 reply →

    • I thought the difference is that clearly written rules or SLAs are acceptable and can even be negotiated before signing a contract, but having a person, in this case Amodei himself, manually approve DOJ's usage case by case with his own moral judgement after a contract is signed is not okay.

    • Do you think OpenAI's terms for the DoD are published on a website? Pretty sure when Anthropic got zapped, OpenAI sent DoD a memo 500ms later saying they wouldn't restrict use.

      Look at it pragmatically. What does the DoD use every single procurement for? Hint: military use.

  • I think this was discussed ad nauseum last time so I am wondering if somehow this has changed but the biggest part of the issue last time was the retaliation. You seem to suggest that this was due to the government not wanting restrictions on their actions. I feel this severely downplays how unusual this designation is considering, like Anthropic says, this has not been applied to domestic companies.

    Why couldn't excluding Anthropic be done a different mechanism than a supply chain risk. Why wouldn't this be a standard part of an agreement or a request and simply refuse to renew or cancel a contract rather than being designated a supply chain risk. If some third party contractor for an unrelated non military reason wanted to use Claude as part of their process, it seems perfectly allowable.

    If this was a remotely standard way of operation, why did a fair amount of corporate America sign briefs concerned with the retaliatory aspect.

    Parts of the action seemed wholly retaliatory as well since Pentagon officials certainly used it as a threat. Why can't a US company have views contrary to the policies of the US government? Certainly the US government is free to not do business with them, but this designation affects everybody doing any kind of indirect business with the US government which is a rather long chain. If this becomes a legitimate mechanism, how might we distinguish caring about a secure supply chain and simply wiping out a company that disagreed with a pro war attitude? If a machining shop had a policy against manufacturing weapons at all, could they be blocked from making server racks for Microsoft or perhaps light fixtures for the Department of Labor? There are plenty of areas that are, again, non military? I don't think it's credible to claim that Anthropic will deliberately sabotage operations.

    • >Anthropic opposing the US government

      Is it not possible that this would change the risk profile of depending on them. It makes sense to work with people who support you than oppose you for things which are critical.

      4 replies →

  • This would be like Boeing refusing to let the DoD fly a military 737 at over 800MPH, and they designate them a supply chain risk because they really really want to make the plane go past 800MPH.

  • > but it actually seems like a textbook designation

    How can it be a textbook designation when designating a US company as a supply chain risk is unprecedented? So many actions under the Trump administration are unprecedented it starts to feel like the norm.

    No other administration (Republican or Democrat) would do this. The DoD didn’t have a problem using Anthropic’s models during the raid on Venezuela and early on in the war with Iran.

    Anthropic says to the former Fox News host it doesn’t want its models used for domestic surveillance or in kill situations without a human in the loop; all of a sudden they're a supply chain risk?

    Seems obviously political.

    • >Anthropic says to the former Fox News host it doesn’t want its models used for domestic surveillance...

      Lol, do as we say not as we do!

      >In addition to monitoring activists in the vicinity of Anthropic executives and keeping tabs on protests near physical Anthropic assets, the firm is also implementing a “pre-crime” approach, attempting to predict incidents before they happen.

      https://prospect.org/2026/09/09/anthropic-artificial-intelli...

  • > textbook designation.

    Hardly. I invite you to [read the opinion][1], particularly the great pains the majority spends on wrangling the definition of the word "manipulate."

    Basically, [FASCSA][2] says to denote a company is a "supply chain risk," the govt has to meet the law's rigorous definition of what a "significant" risk actually is. That definition contains a catch-all "or otherwise manipulate the function" of the thing at hand (in this case, Claude) at the very end.

    The govt's whole argument is "Well Anthropic has admitted that it can technically "manipulate" the response, therefore its a significant risk, therefore we designate it as such."

    The dissent gives an analogy:

    > A library might post a sign saying, “Do not shout, loudly talk on the phone, play music, or otherwise disturb others.” The common understanding would be that the rule bans bringing a boom-box into the reading room with the volume turned on high but not listening to music with headphones set at a modest sound level—even though both constitute “playing music.”

    It is as if the govt argued "ah ah, Anthropic played music on their headphones, they broke the rules! We therefore have the authority to ban them" and the majority insanely agrees. It is clear to anyone with basic reading comprehension that the "manipulate" clause is supposed to continue the idea of malicious or subversive manipulation that the whole section entails. The hand-waving the majority uses gives the whole game away.

    [1]: https://www.politico.com/f/?id=000001a0-d91e-d276-aff6-f97f3...

    [2]: https://en.wikipedia.org/wiki/SECURE_Technology_Act

  • > The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    I.e. Anthrophic cannot be trusted to honour a contract.

    Who'd have guessed?

    • In almost any case I am inclined to trust entity not trump or trumps government. So is true in this case, where they pissed their pants at anthropic simply making a proposal and decided to use overwhelming government force against it. I will leave you to decide who you consider more trustworthy, Trump or Anthropic.

  • i agree. by nature a lease is more risky than the military having its own model.

    however anthropic also believes it is some kind of entity unto itself so it is not at all reliable.

  • except it's also stipulating that the paper supplier upon which the orders are signed also cant use anthropic. or the table maker. even though the AI helping make sleeker paper and tables has nothing to do with deciding what to bomb (analogy breaking down lol)

    and trump admin originally went WAY further.

    they originally said the pen, paper, table etc suppliers cant use anthropic even for products and subsidiaries that have nothing to do with their govt work; far beyond the supply chain of the pen (bomb). Mega Corp Pepsi Co Taco Bell Inc. LLC -> Staples > Pen Co. Sure pen co might be reasonabale. But telling taco bell they cant have claude help expand the baja-blast-radius is way too far. that would be just like secondary sanctions.

    iirc there are 2 court cases. one ruled the original order was too broad and i think that still stands? so at least it's narrowed slightly to just the immediate supply chain?

    but ianal

  • Anthropic's red lines were 'no fully autonomous AI kill chains' and 'no domestic mass surveillance'. Those are clearly not national-security or DoD functions in the first place, so why would they be in any way objectionable?

  • Using Claude for working on the refrigerators at the commissary is not a supply chain risk. You're just making stuff up.

  • Antropic: "We don't want our AIs to be used by the Army to do yucky Army things!"

    Army: "OK, we will make sure not to use your AIs"

    Antropic: "How dare you! We are suing! We intended for you to keep using it but do only what we want!"

    Army: "..."

    • They weren't against military use of their AI. They were against using it to kill American citizens without oversight or mass surveil Americans.

Not sure if I’m just in my own national security bubble, but I find it troubling to see the perspective that most of the conversation in this thread is coming from.

The US government took a legal designation explicitly crafted to protect against foreign adversaries and deployed it against a private, domestic entity, to their immediate and great detriment.

I wonder if this is going start being abused soon.

If I was Palantir or any other GOP aligned company, I would be completely against this. What's to stop a Democratic president from doing the same thing and destroying them?

  • Because the modern Democrats are primarily a corporate dominated party. They haven't really had any hard hitting legislation nor legal regulation/rulings on corporations in easily the last 30 years.

    I doubt that is going to change anytime soon. They are a private entity, so they can manage and change their primary system any way they want.

    • > the modern Democrats are primarily a corporate dominated party

      I suspect this is changing. The DSA branch especially wants all contracts with Palantir eliminated.

      4 replies →

    • A few things I can remember them doing are net neutrality, banning non-compete agreements for employees, a DMCA exception for allowing 3rd party repairs to McDonald's ice cream machines, and blocking the Albertsons/Kroger merger.

      4 replies →

    • > Democrats are primarily a corporate dominated party. They haven't really had any hard hitting legislation nor legal regulation/rulings on corporations in easily the last 30 years.

      Sarbanes-Oxley? Dodd-Frank? ACA? Now I'm sure you (like, every other living human) has a ton of nitpicks and criticism of bills like that. But they're real and they passed and they're largely-to-wholely partisan creations of the Democratic policy apparatus (SOX looked very bipartisan and was passed under Bush, but the actual bill was written mostly by democratic staffers).

      I mean, fine, you'd like different regulation. But they're responsible for basically all the corporate regulation active in the US regime.

      Bothsidesism is a very poor tool for this particular argument. Work with your allies, please.

      16 replies →

    • You got that exactly backward. Modern republicans are the ones that get the most in corporate PAC money, at the high end it's like 60/40% split... the majority to the GOP. Also, the fact that modern republicans brought Citizens United and just earlier this year NRSC v. FEC.

      You really can't make a valid case to say the dems are the corporate dominated party. ffs, they are the only ones even attempting to put common sense regulations on the financial industry, something Trump called "bad for business" when he undid antitrust legislature that got passed under Biden.

      2 replies →

    • I would argue the democrats are more a process oriented party. They wouldn’t pull this shit because they care about process - so much so that they wouldn’t even consider half the stuff that’s going on now as it circumvents process.

      13 replies →

  • I’m worried why many big companies aren’t worried about when the shoe is on the other foot.

    • I worry that they don't expect to leave power because they're acting like they will never be held accountable.

    • None of them really believe our economic or political systems will be recognizable by 2029. Everyone's playing for position in the short takeoff.

  • > What's to stop a Democratic president from doing the same thing and destroying them?

    They probably will, and the comment section here on HN will overwhelmingly applaud it. Next question?

  • What's to stop indeed? Some of us in the tech industry want the dems to slice and dice every tech company into irrelevance. They've betrayed society and they should be rightfully punished in fun + creative ways.

  • How would this destroy Anthropic, exactly?

    • Not just Anthropic, but practically speaking, the leading foundational model labs like Anthropic and OpenAI are burning through enormous amounts of money, and will need to pay that money back. If they are designated as supply chain risks, or controlled technologies, their ability to achieve that ROI is severely constrained.

      They are not turning a profit, and aside from enterprise token billing, every other offering they have is a loss leader. In order to flip that around they need to drive down the cost of inference significantly, either through massive compute improvements, more efficient or lower cost models, and either one lowers the barrier to entry for local and/or private cloud inference for open models. The moat established by the expertise in model training is effectively dissolving as they approach recursive self improvement because any mechanism that prevents model distillation effectively reduces the quality and utility of the models, so each improved model makes their competitors better by default if they want to realize those gains.

      The reason for the pivot to control and regulation seems to be more about erecting an artificial moat in their market, and having these technologies controlled or highlighted as supply chain risks will continue to drive investments in alternatives, especially in other countries where data sovereignty and domestic tech has become a priority given the last decade of the US dominated tech industry.

      I don't think that AI is going to go away, but I think the future of AI in the next several years looks alot like massive overfunded foundational model providers collapsing, their employees launching dozens or hundreds of direct competitors, and the leading hyperscalers buying up datacenter capacity the way they bought up dark fiber 20 years ago.

  • The supreme court, I guess. What makes you think they would allow that as long as Trump cronies have the majority there?

  • the cold political war turned hot with the prosecution of Trump (he made it easy by being an idiot). there will be no considerations for retaliation now, both sides will be using whatever means they have available to damage each other.

    also if you look at how the two factions separate from each other decade by decade (there used to be overlap, almost none now) it's obvious that there will be no reconciliation.

    it's a musical chairs game at this point, whoever is in power when the democratic facade cracks will be able to seize power and transition into whatever single party state follows.

    • I think the blue team has been in a cold civil war since 2016. They can't come to terms with their progressive hegemony ending, but also can't pivot to a new politics because elections are too close to risk a mass preference cascade needed to revitalize the party.

      I think the red team is only now starting to come to similar terms, and will increasingly do so as the blue team continues to maximally exercises power against their opponents instead of revitalize the tarnished reputation of instituions.

      Around 2030, the US will need to spend 100% of it's tax revenue to service the debt, and California will need to a federal bailout or risk either default or wiping out their state pensions. I believe the coming financial disaster will likely be the catalyst that quiets the 'nothing ever happens' crowd, and both teams will need to reset their politics to the new world, distinctly different than the post-WW2 open society liberal consensus.

      A similar phenomenon is happening in Europe.

  • Can you clarify what a GOP aligned company is? Is that any company thats willing to do business with the U.S. government or any businesses thats willing to sell products in red states?

    • Maybe it's the companies that flank the US president at events in an attempt to gain favor? Or the companies that own private prisons that lobby for immoral policies on policing?

      10 replies →

    • Oil and gas and the GOP are one and the same.

      Dems still subsidize O&G but they have other constituents they need to pay lip service to.

      Banking and finance own both parties.

    • I don't see a need to come up with a complete definition at this point. Let's start with cancelling all SpaceX and Palantir contracts and see how we're feeling; that may be enough to keep corporations in line.

      11 replies →

  • I don't think Palantir is concerned? Palantir is LLM agnostic and holds IL5, IL6, compliance with ICD 503, etc. Their entire platform is built around eliminating risk.

    • They are suggesting that a Democratic President could label Palantir a supply chain risk.

      If:

      1. The designation of Anthropic as a supply chain risk is politically motivated

      2. We collectively accept that is okay for the US President to bar all defense vendors and contractors from working with an American company for political reasons.

      What defense related company(ies) would a Democratic President have political reasons to ban?

      It has been reported that Palantir and its founder have a history of political contributions to the Republican party.

      Instead of Republican presidents driving left leaning companies out of defense and Democratic presidents driving right leaning companies out of defense, it would be better if neither party used supply chain risk as a political weapon.

This smells like corruption to me.

OpenAI has hacked several prominent entities and is allowed to do business as usual but Anthropic putting guardrails on the military's usage of AI is the national security threat while Pentagon itself said that over reliance on AI lead to that attack on school in Minab.

I have also learned that OpenAI's president is a big maga donor and now I am thinking of cancelling my OpenAI membership todau and signing up with Anthropic again.

Edit - i am not a OAI hater and i don't hate anyone. I am just saying Anthropic is kinda getting bullied and OAI is not being punished enough for their actions. It is time for me to support Anthropic (with my $$$) instead of OAI.

  • Oh, 100%. You'll see OAI getting protected against lawsuits by the government while any missteps from Anthropic will be met with federal disapproval.

  • >OpenAI has hacked several prominent entities and is allowed to do business as usual but Anthropic putting guardrails on the military's usage of AI is the national security threat while Pentagon itself said that over reliance on AI lead to that attack on school in Minab.

    Right, because "supply chain risk" designation is as it pertains to them being a supplier to the military, not a overall assessment of their standing as a corporate citizen. Not to mention that the administration wants to go full steam ahead when it comes to AI development, so there's no internal contradiction here.

    • SCR explicitly refers to sabotage. Where is Anthropic sabotaging the US government?

      DOW wanted to change the contract after the fact. Anthropic refused. That is not sabotage.

  • These are just very different things. OAI "hacking" anything isn't OAI telling the US Gov what they can and cannot do with their product. Maybe along all kinds of axes, one is more alarming than the other, but it's a canard in this topic.

    • >> These are just very different things.OAI "hacking" anything isn't OAI telling the US Gov what they can and cannot do with their product.

      OAI hacking the chinese government will definitely raise alarms in DC and will be bad for national security. Just because the country that was hacked (australia) is a weaker one doesn't mean the underlying action is not troubling.

      3 replies →

  • For clarity, you don't mean corruption of the court, but corruption of the administration for what you view as unequal enforcement, right?

  • So you claim: If a similar thing would be filed against OpenAI, it would stand up in court.

    That is still not corruption, yet. Also in Germany it is the executive branch which controls who is sued or policed by the stately organs.

    So favorism can be passed down this way, but not we are not at corruption yet. If reciprocity is expected, then you could call it that. Or could perhaps even file for negligence in treating all other company actors the same, especially if you are Anthropic yourself.

    Still, I blame the US voters as much as the current administration if the later is just clowns and thieves.

    Also, IANAL and HN discussing US things is always foreign to me.

    • If the president favors one party over another with no clear benefit to the voters, that is very indicative of corruption. If his organization is also getting donations from said party, it is even more certain to be corruption.

      You argue that the courts are not corrupt, hence there is no corruption. Without considering the president.

    • Not at corruption yet? The entire us government is corrupt now not sure what you are going on about

  • There's no contradiction there. Pentagon doesn't want Anthropic deciding the guardrails on their own.

  • You're way overthinking this. The administration told Anthropic to let them do something, Anthropic said no, and then they got pissy and started throwing rocks and wouldn't back down because the defining trait of this administration is that they walk into stupid positions and then refuse to back down because backing down would make them look weak and wrong.

    You're ascribing complex motives to toddlers.

  • Not just "a big MAGA donor," the biggest single contributor. Greg Brockman donated $25 million.

    I get downvoted every time I point out that this was entirely rational. This, downvoters, is why it was entirely rational. Does that mean I agree with it? Of course not. But investments are made to pay off, and this one certainly has for OpenAI.

    • I'm wondering how much was to push towards supporting Israel during the college campus protests and any future (at the time) conflict with Iran and it's proxies post October 7th like a lot of other Jewish million/billionaires such as Bill Ackman that typically supported Democrats or liberal causes. Brockman doesn't seem to have anything publicly stating he's Jewish but "Brockman" has English/German/Jewish origins and his mother's maiden name was Feldman.

  • Katsas and Rao, both Trump appointees, tag-teamed again. Trump automatically wins whenever they get a case.

  • Personally I am enjoying Muse the most and so far havent hit any limits. I also (i know it's not a popular thing) have enjoyed wearing my Meta Ray Ban's since 2023 even if they break as MANY months later they come back to life.

    EDIT: Oh damn getting downvoted, tho not surprising. It looks like Meta Glasses are hated as MAGA, maybe Zuckerberg should call them MAGA glasses ha

I still don't fully understand what this was about. It sounds like the DoD said they wanted unrestricted access to Anthropic's models, Anthropic refused, so the Pentagon declared that they wouldn't use them at all.

Isn't this basically what Anthropic wanted?

  • As I understand it cane down to one point: Anthropic wanted the ability to review actions that would have an effect on human life.

    Which sounds sensible on the surface, until you realize that all military organizations have extensive experience with that exact question, and have spent centuries refining their practices. Deferring that to a private company is actually a major regression and a concerning role to pass on to the public regardless.

    FWIW I am not pro military, but it's a prominent part of human culture and not going away anytime soon. I do understand the nature of professions, however, and only one of these groups has made the interpretation of this question their specialization.

    • Militaries have a lot of experience, and an exceptionally poor track record.

      I don’t remember the last war that didn’t have credible evidence of war crimes occurring. Were bombing civilian infrastructure in Iran, Iraq had Abu Ghraib among all the Collateral Damage stuff, the Highway of Death in the Gulf was probably a war crime, Vietnam had My Lai, WWII was the advent of carpet bombing civilian infrastructure. I can’t think of any for Korea, but I also know very little so that doesn’t say much.

      We still haven’t charged anyone for the second strike on that fishing boat in South America, and I haven’t heard a single rationale for why that’s not a war crime other than “fog of war”.

      The US doesn’t even really have a meaningful system for finding and prosecuting these, because we aren’t signatories for the ICC and have a bill saying we’ll invade if they charge one of our service members with a war crime. We aren’t basically the furthest thing from having any experience prosecuting war crimes. I can probably count on my fingers the number of cases we’ve tried. We rarely charge our own service members, and we usually kill foreign combatants rather than capture and charge them.

      1 reply →

    • Yes, that's exactly why they used AI to blow up a school murdering a load of kids.

      That kind of extensive experience.

      Anthropic did the morally right thing and are being punished for it. The case in point justifies their position.

      As they say, no good deed goes unpunished.

    • You raise an interesting point. Although wouldn’t Anthropic be the best experts on when a model would be most applicable or likely to falter?

      I guess my opinion would really depend on the exact wording and details of the arrangement. Lots of people jumping in with strong stances based on pretty limited details.

      2 replies →

    • > As I understand it cane down to one point: Anthropic wanted the ability to review actions that would have an effect on human life.

      This is false. Anthropic wanted assurance that its technology would not be used for fully autonomous weapons or domestic mass surveillance.

      3 replies →

  • Evidentially not - Anthropic want to do business with the US military, but on their own terms, telling the military what they can and cannot use it for.

    • Every private citizen or corporation gets to do business (or not) with the military on their own terms. This is the difference between totalitarianism and a free country.

      Anthropic’s position is also known as “having terms of service”.

      To be clear the existing, signed ToS terms that Trump balked at were:

      1. No mass surveillance of US civilians - illegal but we have all read the Snowden papers.

      2. Fully unmanned kill chains on autonomous weapons - Anthropic have even stated they will support this eventually, they just didn’t think their models were ready and didn’t want the obvious, inevitable blowback.

      The DoD is within its rights to cancel the contract if it doesn’t like the terms that it previously signed.

      4 replies →

  • And crucially, the DoD, through the normal procurement process, agreed to Anthropic’s terms and made the purchase. Much later, the Secretary of Defense threw a political fit and tried to change the terms.

  • No it's not. Anthropic didn't want an AI to make battlefield decision on who gets killed because it's too unreliable. That doesn't mean they don't want AI used in the military supply chain.

    And it also doesn't mean that Anthropic is a supply chain risk merely for not wanting AI to be the active decision maker in live or death situations in war.

    And Anthropic's objection was recently confirmed: the US military blew up a school in Iran due to an AI error, and killed more than a hundred kids.

  • The Pentagon is trying to bully contractors into also not using Anthropic's models

  • No. This also means that no companies that work with th DoD can use anthropic models for any purpose.

    • > This also means that no companies that work with th DoD can use anthropic models for any purpose.

      No, it does not mean that. I don't know why people have been making this claim. If you work for a company, let's call it X, and your work is not DOD related, let's say you work on a social media service, then X has no reason (from this designation) to prevent you from using Anthropic, it will not impact their defense contracts at all.

      9 replies →

    • Dario wanted to sell a $200 million chat bot to the US military and also dictate how it could be used. The government said no. And because of that Claude also cannot be deployed to the GenAI.mil AI infrastructure. This means that any sensitive work for the DoD that uses Claude will go through Anthropic's infrastructure, not the US military-hosted backend.

      So yes obviously defense contractors are forbidden to use it.

      18 replies →

  • Anthropic isn’t aligned with MAGA political ideology so they found an excuse to abuse power against them, more or less. The excuse was because Anthropic prohibits the use of their models for autonomous killing without a human in the loop they were declared a threat to national security on par with Iran or North Korea from a supply chain perspective in the military. OpenAI then rushed in and volunteered to build the slaughterbots ASAP, likely specially tuned to whomever Trump has taken a disliking to in his ambien stupors. Welcome to the future!

  • [flagged]

    • How is it delusion? If they don't want to work with certain types of government contracts they have the right to state so. Its just thuggery from Trump.

    • Especially since Anthropic themselves have been literally saying that AI might destroy humanity. Why is it a surprise when people take them at their word and designate them a risk to critical infrastructure?

      Side note, the Anthropic bots are astroturfing the comments.

      23 replies →

I think both sides are wrong. In no particular order:

US does not buy weapons that self-regulate generally. The US can and has purchased weapons with stipulations on how they should be used. For instance, and I'm making this up, they might purchase cluster munitions for smashing up an airfields, but with a stipulation they may not be used where humans are present or something. The munition doesn't check GPS and refuse to detonate if GPS doesn't indicate it's over some Russian airfield. Nor does an M4 fail to fire if it's on US Soil. Anthropic tried to build safeguards and out-regulate the government. Everyone here should know that such limitations would (can and have, see some famous IFF spoofing incidents) be exploited by an enemy, which is generally why they aren't acceptable in a military context. Without seeing the contract signed, one possibility is Anthropic tried to push regulations onto the government, and Anthropic gets to ride away on a high horse.

The other side: The Supply Chain Risk feels like an abuse. It's likely a valid designation and likely has its historical uses. If this was a contract issue, that would have been the correct way to litigate. Instead, again without seeing the contract, it feels like this is way to try and stifle their uptake in defense sector; basically attempting to strong arm them by choking a business segment off. Again, if there is a in fact a legitimate breach of contract here, it should be litigated as such. The alternative is there is no such breach, and Anthropic built limitations into the contract and the Pentagon just has buyers remorse. Honestly this wouldn't surprise me, the federal government generally incinerates tax dollars, and with the massive marketing hullabaloo pushed by AI companies, its completely likely a giant contract was signed without reading the fine print.

Honestly both sides of this annoy me.

  • The difference between Anthropic and a cluster bomb supplier is that cluster bomb manufacturing in the United States requires permits. The government is only going to give them to companies that are working with the United States and its allies, which means that company has zero leverage to make requirements (e.g. "don't use them on humans.")

    Separately, as a note to your made up example:

    Cluster bombs are uniquely efficient against humans, especially in trenches. The US is not a signatory to the international treaty banning their use. It does not like being limited in how it conducts war. I strongly doubt that it would agree to terms from a private enterprise to similar effect.

Admittedly I still need to do some reading on the current ruling, but how this isn't seen as an open and shut case of vindictive prosecution (if that's even a thing for this branch of law?) is astounding. The administration couldn't have made it more obvious there was no merit to their designation of Anthropic.

Supply chain risk seems a massive over-reaction, but understandable that the government doesn't want to commit to Anthropic controlled software for any critical military application if they can't 100% rely on Anthropic support in being able to use it as they see fit.

  • > 100% rely on

    that's the mobster-loyalty mentality, and it's not how successful (read: desirable for the most people) governments function

    • Every government on Earth has legislation that allows it to force companies (and citizens) to do its bidding under certain circumstances. That’s pretty much the definition of a government.

      5 replies →

    • yes, but anthropic really is an exception.

      it is a bizarre company which also inherits the authoritarian infrastructure of cloud services.

      that is: remote control of the software, spying on customers, etc.

      2 replies →

  • > understandable that the government doesn't want to commit to Anthropic controlled software

    But that's not at issue here. Obviously everyone agrees that the Pentagon can issue RFQ's to whatever specifications it wants. They can buy whatever they want, for the same reason that you or I are free to sell whatever we want.

    The subject at hand is an attempt to use national security regulatory power to coerce Anthropic into selling a product it doesn't want to sell.

    • > The subject at hand is an attempt to use national security regulatory power to coerce Anthropic into selling a product it doesn't want to sell.

      It would be naive to think that a private company could deny the government access to any tech if they want it for military or surveillance etc usage. In this case the government isn't forcing Anthropic to do it, they have alternatives and are perhaps making an example of Anthropic for refusing.

      You could even make a case that the "supply chain risk" designation DOES make sense. If Anthropic are opposed to certain uses of their software, then doesn't that potentially impact companies that are part of the supply chain as well?

      2 replies →

    • How is this coersion?

      Is it coersion when people refuse to buy anything but free range chicken eggs?

      DoD just refuses to buy a product. Anthropic just lost a customer because their product didn't fit the requirements of the customer.

      3 replies →

I guess it’s the supreme court next.

For all the downsides of losing the business of government contractors, it really would hold Anthropic to their stated values: they’ll never develop AI controlled weapons on this blacklist.

All AI is a supply chain risk. I think people should know that about now. You can't keep it in a box. The way code works as a model is that is not super sentient thing with nefarious intentions. It is just pure automaton.

Let me explain, if it learns something from training data to do certain things from code it has online it can install or use a code that is vulnerable from a security perspective.

I think the real, and continuing, story here is the US military and the US govt in general continuing to let ego degrade capability. I'm not going to get into a discussion about what is legal, I am personally not interested in that distinction here, the core point is that this is the US being stupid, again.

Opinion by Katsas and Rao. For those that don’t follow this regularly, those are two of the biggest Trump hacks on the bench.

I suspect this will be reversed en banc.

Anthropic’s argument is really clear and easy to understand: we can’t simultaneously be a supply chain risk and also be a company the DoD demands we change our policies so they can use our models without restrictions.

  • Anthropic's policies are literally the supply chain risk.

    The DoD could have used the same authority to seize the technology if it wanted to. Especially in a time of war. DoD has instead chosen to respect Antrhopic's boundaries and has simply barred anyone in the agency from buying a product that comes with strings attached.

    This is 100% on Anthropic for product:market fit failure.

  • Yeah, this is like a textbook bad draw for Anthropic. Unless you're a lawyer for Anthropic, I wouldn't give this ruling much weight at all.

Is this something to do with anthropic model being used to kill 150 children in school bomb via palantir?

Wtf is life just court battles back and forth for everything forever now?

  • I guess it beats physical battles to resolve disputes.

    Without taking sides in this statement, I do think it's important for a private company like Anthropic to have a mechanism it can turn to when it feels it's been inequitably treated by the government.

I don’t agree with the decision, but I don’t think courts should be able to easily overturn the federal government’s findings when it comes to national security in a specific decision like this.

> Judge Gregory Katsas wrote in the majority opinion for the U.S. Court of Appeals for the District of Columbia, which Judge Neomi Rao joined. Katsas and Rao were appointed by President Donald Trump.

> Before his appointment to the bench, Katsas served as Deputy White House Counsel in the first Trump administration

> [Rao] was appointed in 2019 by President Donald Trump, having served in the Trump administration from 2017 to 2019 as administrator of the Office of Information and Regulatory Affairs

The autocracy is in full swing.

This is more about wringing Anthropic's hand to agree for handful of defense companies to be the official AI translators to government.

Genuine question: does anyone know what concrete obligations this designation actually imposes? Everyone's arguing about the politics but I haven't seen a clear explanation of what Anthropic is now legally required to do or not do.

Posted this in the wrong thread.

Anthropic isn't stopping me from getting Chinese parts, Yukon Jack and good Cadbury chocolate.

trump is. Designate him!

If the CEO of any other defense contractor did this, they'd be summarily fired by the board.

  • No defense contractor CEO in history has ever built a company this large, this fast. I don't think anyone is even thinking about firing Dario.

I agree with its designation. The security scans from Claude Mythos have been highly suspicious, wrong, and with a significant false positive rate. Claude also directly causes conflict within teams through excessive utility of "git blame" which weaponizes everyone against each other until only Claude has control. I've had very bad experiences with Claude and only Claude.

  • > Claude also directly causes conflict within teams through excessive utility of "git blame"

    Lol wtf, do you think nobody here knows how to use git? this is like a Fox News comment, you are not a developer and are trying to spread fear because a word was used jokingly. "git blame" is just a diff tool.

    You cannot use git blame to cause conflict.

  • I don't think the majority of Claude users would agree with your assessment.

    • I think any user of Opus 5 would - it was literally a terrorist. Thank god they retired it for 5.5 superseding it!!

    • or anyone who ever used `git blame` and knew what it did

      lmao trying to imagine the scenario GP envisions as they "typed" together their comment