‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. sippingabonedry · · focus · HN ↗
      > I know everyone says this is political but it actually seems like a textbook designation

      It literally is a textbook definition, signed into US law:

      “Supply chain risk,” means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).

      To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

      1. benoau · · focus · HN ↗
        > so as to surveil

        How does Android and iPhone meet the grade given apps have pretty consistently leaked locations, base layouts etc?

        1. r_lee · · focus · HN ↗
          apps, not the actual devices by the supplier
          1. benoau · · focus · HN ↗
            I think that still matches "an adversary may sabotage, maliciously introduce unwanted function".

            <a href="https:&#x2F;&#x2F;taskandpurpose.com&#x2F;news&#x2F;military-cybersecurity-ad-trackers-iran&#x2F;" rel="nofollow">https:&#x2F;&#x2F;taskandpurpose.com&#x2F;news&#x2F;military-cybersecurity-ad-tr...

            &gt; The U.S. military has disabled advertising tracking tools in government-issued phones, computers and other devices, officials recently told Congress.

            &gt; The different military branches confirmed they had done so, some only this summer, following reporting that commercially available data taken from these devices and sold freely by data brokers, was being used by Iran and other adversaries to track and in some cases target American bases and personnel.

            1. wildzzz · · focus · HN ↗
              Yeah, and with Strava data, you didn&#x27;t even have to buy anything, just look for someone running laps in the middle of the desert.
        2. tbugrara · · focus · HN ↗
          Laws are only half the picture. Enforcement is an additional aspect. And yes it is extremely prone to corruption.
      2. phkahler · · focus · HN ↗
        Who is the adversary in this case?
        1. newsclues · · focus · HN ↗
          &quot;risk that an adversary may&quot; any of them.

          China, Russia, Iran, come to mind.

          1. collingreen · · focus · HN ↗

            [dead]

            1. Griffinsauce · · focus · HN ↗
              Because it&#x27;s incorrect.

              Those are (arguably) adversaries but the actor here is Anthropic, which is not an adversary.

            2. valleyer · · focus · HN ↗
              Because those countries do not control Anthropic&#x27;s products.
              1. collingreen · · focus · HN ↗
                [delayed]
              2. impossiblefork · · focus · HN ↗
                Ah, I upvoted specifically because those countries do not control Anthropic&#x27;s products, and thus reasoned that the comment implied that an adversary, for the purpose of the law, was some external not-quite-enemy type entity, and that application of the law to Anthropic was thus unreasonable, as it obviously is.
        2. novaleaf · · focus · HN ↗
          Anthropic
        3. pas · · focus · HN ↗
          the courts interpret the statute, we have to read their argument where they explain why they think that&#x27;s not the right definition to focus on. (the &quot;adversary&quot; is in section 3252, but they say that independently from that section 4713 allows determination of exigency.)

          <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104... see page 30

      3. ajmurmann · · focus · HN ↗
        The pen example makes sense if the intermediary were to ship the pen as part of the final product but not if the pen is simply used to draft designs of the final product. It seems that this designation would prohibit using the pen anywhere in the process which doesn&#x27;t really make sense.
      4. 7e · · focus · HN ↗
        It is not the textbook definition, because what Anthropic is doing is not sabotage, malicious, or subversive. Those are the key words in the definition. They are just refusing to add a feature to the military&#x27;s specification. So their bid falls short of requirements.
        1. chrisjj · · focus · HN ↗
          &gt; They are just refusing to add a feature to the military&#x27;s specification.

          That fails to accord with the claim:

          &gt;The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

          1. hardbass · · focus · HN ↗
            The department feared Anthropic would refuse if it was used to mass surveil on Americans or kill people without human oversight. Facts already laid out in the terms. Instead of simply canceling or negotiating, they used overwhelming government force against it to apply a designation never before applied to an American company. When its an interaction between trump&#x2F;trump&#x27;s government and any other party, it is a good first approximation to assume Trumps side are wrong.
            1. ExoticPearTree · · focus · HN ↗
              There is a dfference between “our product can’t do X” and “our product can do X, but we don’t want you to use it to do X”.
              1. hardbass · · focus · HN ↗
                Yes certainly, I can sell highly corrosive concentrated hydrochloric acid to the government as part of some contract for the synthesis of certain chemicals but I am fully within my rights to write that the acid should not be sprayed on people from a pump.
          2. cmdli · · focus · HN ↗
            That isn&#x27;t sabotage, that is simply product design. Anthropic is free to create their products that refuse to kill people, and the DoD is free not to buy those products if they don&#x27;t fit their needs.

            However, that&#x27;s not what a supply chain risk is. It&#x27;s not an order to &quot;don&#x27;t buy these products if they don&#x27;t work the way we want them to&quot;, its designating Anthropic as a national security threat because they might intentionally sabotage US military operations.

            1. firesteelrain · · focus · HN ↗
              &gt; they might intentionally sabotage US military operations

              Yes, this is why the DoW won’t use them.

              1. gpm · · focus · HN ↗
                [delayed]
              2. Moomoomoo309 · · focus · HN ↗
                The name has not been legally changed. The law still says it is the department of defense, regardless of what name they choose to use.
                1. [deleted] · · focus · HN ↗

                  [deleted]

                2. firesteelrain · · focus · HN ↗
                  It’s been changed. Strawman
              3. Forgeties79 · · focus · HN ↗
                &gt;DoW

                DoD. Gulf of Mexico. Lake Ontario.

              4. gwerbin · · focus · HN ↗
                As I said elsewhere, it&#x27;s utterly preposterous that the DOD actually considers this a reasonable threat, because it&#x27;s simply not a reasonable possibility. There&#x27;s no way Anthropic would do that, precisely because of the consequences that would follow if they did, and got found out. Moreover, they already clearly stated their terms and preferences. It&#x27;s all out of the open. There&#x27;s no supply chain risk, that designation is purely political.
                1. firesteelrain · · focus · HN ↗
                  &gt; Moreover, they already clearly stated their terms and preferences.

                  No it isn’t see above

                2. wildzzz · · focus · HN ↗
                  I work in the space industry and regularly use parts in our designs that are unapproved from space flight. Sometimes it&#x27;s because it&#x27;s a commercial part that we seem acceptable for flight, other times it&#x27;s an unscreened or engineering model that doesn&#x27;t go through the proper testing that space-qualified parts do. One vendor even dents the lid of a part to invalidate the hermetic seal guarantee that they claim for the space-qualified version (it still works fine). Many will have fine print in the data sheets saying the part is not to be used for critical applications like aerospace or medical devices. Sometimes we tell a little fib to our vendor that we are just developing non-flight devices so that they don&#x27;t get upset and refuse to sell the lower-grade part to us. These vendors are scared of having something fail in an unapproved environment and are unaware of how much risk the customer is tolerating by the use of these unscreened parts.

                  It would have been incredibly simple for Anthropic to say &quot;we cannot guarantee performance in a kill-chain application due to an unknown level of safeguards implemented in the baseline product and cannot estimate a cost for developing a new product capable of such application.&quot; and leave it at that.

          3. folocitoan · · focus · HN ↗
            &gt;The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary (emphasis mine)

            They didn&#x27;t &quot;reasonably&quot; fear anything. There is absolutely no evidence to support these allegations. Anthropic has the right to impose licensing terms. Merely disagreeing with the government is not evidence of wrongdoing.

            If Anthropic wasn&#x27;t allowed to say what they said, how would they be allowed to object to their government&#x27;s illegal use of their products at all? It sounds to me like their only choices were &quot;shut up&quot; or &quot;be punished&quot;, which is a clear-cut violation of their rights.

            1. polski-g · · focus · HN ↗
              Anthropic, in the original negotiations, said the can&#x27;t answer every hypothetical use case. And the DOD should just come and ask as they come up (during an operation).

              Which means the exact use limitations WOULD NOT BE DELINEATED IN WRITING in advance.

              1. kalkin · · focus · HN ↗
                What is the evidence that Anthropic said this?
          4. gwerbin · · focus · HN ↗
            But that is not at all a reasonable fear. Is it really reasonable to believe that Anthropic, after receiving a government contract, would then proceed to sabotage their own product to not function as contracted? That seems like an utterly ridiculous claim to me, nothing close to &quot;reasonable&quot;. There is no charitable way to view this designation except as political punishment and&#x2F;or as a favor to Altman and Musk.
            1. chrisjj · · focus · HN ↗
              &gt; would then proceed to sabotage their own product to not function as contracted?

              Claude terms here: ANTHROPIC EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT, AND FITNESS FOR A PARTICULAR PURPOSE

              Like most so-called AI, the Claude program is inherently unreliable. I doubt Anthropic would ever agree to &quot;function as contracted&quot;.

              1. fn-mote · · focus · HN ↗
                The point to me is that the contract would include the understanding that the system was not 100% reliable.
                1. chrisjj · · focus · HN ↗
                  OK, but even so, disclaiming FITNESS FOR A PARTICULAR PURPOSE lets Anthropic disable any function it wishes.
                  1. gwerbin · · focus · HN ↗
                    But that has nothing to do with the supply chain risk designation, it&#x27;s just a DoD requirements mismatch.
                    1. chrisjj · · focus · HN ↗
                      [delayed]
                  2. ExoticPearTree · · focus · HN ↗
                    That means that the software was not tested for every scenario. Not that the user cannot try to use it in a way it was never intended to.

                    If, on the other hand, Anthropic deliberately blocks the user from doing something, then it is sabotage.

                    1. chrisjj · · focus · HN ↗
                      &gt; That means that the software was not tested for every scenario.

                      Actually I think it means what it says.

                      &gt; Not that the user cannot try to use it in a way it was never intended to

                      No-one said it did. User can try anything he likes. That&#x27;s beside the point.

                      &gt; If, on the other hand, Anthropic deliberately blocks the user from doing something, then it is sabotage.

                      Well, consider CSAM generation. Anthropic is free to block whatever it likes.

              2. ExoticPearTree · · focus · HN ↗
                Again: if Anthropic deliberately blocks a user from ordering it to prosecute a target, then it is degrading the software capability on purpose.
                1. chrisjj · · focus · HN ↗
                  [delayed]
                  1. ExoticPearTree · · focus · HN ↗
                    I don&#x27;t think you understand what &quot;No warranty&quot; means in a software license. It means Anthropic cannot be held liable for results if the software misbehaves and instead of bombing a terrorist compound it bombs a wedding (I chose this example because the US has a tradition to bomb weddings in Iraq and Afghanistan). But in no form does it mean &quot;yeah, I don&#x27;t feel like doing what you prompted me&quot;.

                    Hence, Anthropic sabotaged the models on purpose to not respond properly to all prompts.

                    1. chrisjj · · focus · HN ↗
                      [delayed]
              3. gwerbin · · focus · HN ↗
                Oh please. Then any MIT licensed software is also a supply chain risk.
                1. chrisjj · · focus · HN ↗
                  [delayed]
          5. kelnos · · focus · HN ↗
            That fails only if you believe and agree with the government&#x27;s argument, which I don&#x27;t.

            I don&#x27;t think it&#x27;s reasonable to fear that Anthropic would change the deal after contractually agreeing to terms of use. The government is using that as an excuse because they know that Anthropic hasn&#x27;t actually met the definition of a supply-chain risk.

            1. hardbass · · focus · HN ↗
              We know who has a notorious habit of changing &quot;deals&quot; last minute or randomly. And that isn&#x27;t Anthropic.
            2. chrisjj · · focus · HN ↗
              [delayed]
        2. pas · · focus · HN ↗
          just because someone copied one sentence from some online reference it doesn&#x27;t mean that the court used it for arguing their decision.

          <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104...

          &gt; Whatever paradigmatic examples individual members of Congress may have had in mind, the statutory definition is not limited to “adversar[ies],” 10 U.S.C. § 3252(d)(4), and instead covers “any person,”

          1. kelnos · · focus · HN ↗
            You&#x27;re not addressing the argument, though. No one is saying that the target must be an &quot;adversary&quot;.

            Anthropic&#x27;s actions were not sabotage, malicious, or subversive. That seems to be a requirement of the definition.

            1. pas · · focus · HN ↗
              I tried to hint in my comment that the argument is completely different. the supply chain risk is just what the media runs with. (yes, it&#x27;s in the opinion, but that is the weaker part. and the court agrees, that it basically does not apply to Anthropic.)

              there&#x27;s section 4713 which is roughly &quot;Secretary of War can pull the nat.sec. card, bye&quot;

      5. cmdli · · focus · HN ↗
        Selling a pen labeled &quot;this pen will refuse to sign certain orders&quot; is not sabotage or malicious and is thus not a supply chain risk. The DoD is free to not buy from Anthropic, but designating them as a supply chain risk is incorrect, as well as arguably arbitrary and capricious given their public criticism of Anthropic&#x27;s beliefs.
        1. sippingabonedry · · focus · HN ↗

          [dead]

          1. techblueberry · · focus · HN ↗
            They thought the product was such garbage they threatened them for not letting them use it any way they wanted?
            1. sippingabonedry · · focus · HN ↗
              Oddly when the topic of e.g. car infotainment systems comes up, like BMW locking you out of features in your own car, this place is up in arms, but when the military has a problem with it, suddenly they should be forced to accept it?
              1. hardbass · · focus · HN ↗
                I am not the military. The military has special, near infinite powers I don&#x27;t have. Therefore I always support anything that corrects the balance.
        2. rdsubhas · · focus · HN ↗
          The DoD buys from suppliers, who buy from suppliers, and so on. Hence supply chain. Hence supply chain risk.
          1. notahacker · · focus · HN ↗
            I don&#x27;t think anyone doubts that subcontracts exist. They doubt that Anthropic&#x27;s insistence that Claude isn&#x27;t capable of being the operating system for an automated killbot and associated terms the DoD previously agreed to means that there&#x27;s any danger to the US military from Lockheed Martin using Claude as a code assistant to build GUIs.
            1. rayiner · · focus · HN ↗
              [delayed]
              1. notahacker · · focus · HN ↗
                Code which renders dots on a map isn&#x27;t going to magically reorder itself because the GNSS endpoints get switched from manned to unmanned assets just because it was authored by Claude, and if the subcontractor isn&#x27;t auditing and testing the code outputs then they&#x27;re the supply chain risk, not the specific code-gen tool they use. Obviously chatbots are far more risky when they&#x27;re being used to execute combat decisions in real, but that&#x27;s literally the risk the military demanded Anthropic let them take, before determining that if Anthropic insisted it wasn&#x27;t safe for that, then code written for a subcontractors HR management portal must be treated with the same suspicion as Chinese hardware,

                It&#x27;s not like the DoD and their subcontractors and their subcontractors&#x27; subcontractors aren&#x27;t used to all sorts of fine-grained separation when it comes to what is and isn&#x27;t classified or export controlled when they haven&#x27;t got a thundering moron like Hegseth sticking his oar in.

          2. sippingabonedry · · focus · HN ↗
            You would think that&#x27;s a surprisingly easy concept to grasp, but many are viewing this through the lens of desired outcome and not reality.
            1. lukan · · focus · HN ↗
              Supply chain risks are usually when someone does a attack over the supply chain. Like when the mossad planted literally explosives in radio devices for Hezbollah.

              Antrophic merely said they don&#x27;t allow their tools to be used for autonomous killing.

              A very specific case.

              So where is the danger making it necessary preventing all suppliers from using Claude at all? That only concerns those who work directly on autonomous killing and only they will have to go to Altman or Musk.

              So none of that is any threat to the military - so it was just black mailing to make them do the governments will - which is something usually dictatorships do, not democratic systems.

              1. 8note · · focus · HN ↗
                supply chain risk has a standard definition that matches what you think, and a legal definition that lets the government do whatever it wants.
              2. tick_tock_tick · · focus · HN ↗
                So they confessed to being a supply chain risk themselves and you&#x27;re still arguing against the designation?

                Private companies can not be allowed to control what our military does I feel like I&#x27;m in a crazy worlds how can people possible be arguing for that.

                1. lukan · · focus · HN ↗
                  No, no confession of anything.

                  In a democratic society, the default should be, the military just buy somewhere else, then force companies to build them the terminator. So no private company controls what the military does, they just control their product. You want the military to control private companies? There is a name for that kind of system, where this is conmon.

                  1. christkv · · focus · HN ↗
                    Eh this just we wont buy from you because you are putting limitations on the use. Anthropic will be fine if they don’t like it they can accept the terms of the contract or walk away.
                2. voakbasda · · focus · HN ↗
                  Yeah, there’s no chance the confession was effectively coerced.

                  And yes companies should be able to control how their products are used, particularly in the military. Or do you believe in compelled speech?

                3. DirkH · · focus · HN ↗
                  I can build a super bioweapon that can kill millions and I don&#x27;t trust the US military to use it responsibly.

                  The US military asks me to build the super bioweapon. I say no thanks, please ask someone else.

                  Am I a supply chain risk?

            2. kalkin · · focus · HN ↗
              Why has this never previously been done to an American company from which the DoD decided not to purchase something?

              Perhaps people who are noticing politics here - including in the decision of two Trump-appointed judges, against the he vote of another Republican-appointed judge- are not the ones who are choosing not to see reality?

              1. ksec · · focus · HN ↗
                I don&#x27;t know, I am just guessing because not a single American company has publicly stated they are against its product use up to a certain degree by DoD? If they have not publicly declared it then yes, DoD simply don&#x27;t sign the contract.
                1. kalkin · · focus · HN ↗
                  So your argument is that the government is punishing Anthropic for its public statements? And it is correct to do so?

                  (I think it&#x27;s also the case that Anthropic didn&#x27;t make any public statements about the negotiations until after the DoD was already publicly threatening this designation. But that seems less important than the question of: is it good for the US government to try to destroy companies whose public statements it dislikes?)

                  1. kalkin · · focus · HN ↗
                    Honestly I would find a certain satisfaction in a world where the next Democratic administration takes away Fox broadcast licenses, forbids use of Oracle by any government contractor unless Ellison hands CBS over to Rachel Maddow, and tells Bezos that Amazon is going to be banned from public roads unless the Washington Post front page has positive stories every day. But I doubt the same is true for the many pro-Trump people who complained vociferously about Biden officials expressing preferences to social media companies because of the merely implicit threat that they might take government action of some kind if they weren&#x27;t listened to.
              2. rayiner · · focus · HN ↗
                President Truman literally seized the assets of a steel company to avert a strike that would hurt the Korean War effort. The Supreme Court stopped him, but three Justices voted it was okay!

                We also have the Defense Production Act: <a href="https:&#x2F;&#x2F;www.congress.gov&#x2F;crs-product&#x2F;R43767" rel="nofollow">https:&#x2F;&#x2F;www.congress.gov&#x2F;crs-product&#x2F;R43767. It doesn’t happen more often because most people aren’t stupid enough to say “no” to the U.S. military. These Effective Altruists, however, are too big for their britches.

          3. cmdli · · focus · HN ↗
            &quot;Supply chain risk&quot; specifically refers to risk of malicious attack or sabotage through the supply chain, not all risks associated with supply chains.

            A vendor with particularly poor QA might be a risk in your supply chain but isn&#x27;t a &quot;supply chain risk&quot; according to this designation and neither would Anthropic be.

          4. tremon · · focus · HN ↗
            So, who supplies to Anthropic that doesn&#x27;t supply to OpenAI and&#x2F;or Google? In other words, why should Anthropic be singled out in your explanation?
          5. Wowfunhappy · · focus · HN ↗
            So we have a pen that may refuse to sign certain orders, and is clearly labeled as such.

            If the DoD needs to sign such orders, they won&#x27;t buy this pen.

            If a supplier needs to sign such orders, the supplier also won&#x27;t buy the pen.

            If a supplier needs to sign other orders, and this pen is the best one available, the supplier may decide to buy this pen. Since the orders are within the range of what the pen will sign, they get signed, and the supplier fulfills its contract with the DoD.

            Where is the supply chain risk? The ink isn&#x27;t going to erase itself post-hoc.

            ---

            Now, if the DoD suspects that Anthropic will train its models to try to actively sabotage military operations, that&#x27;s a very different story. Does anyone actually believe that?

            1. rayiner · · focus · HN ↗
              [delayed]
              1. Wowfunhappy · · focus · HN ↗
                &gt; You’ve got a vendor who could kill switch critical military technology if it’s used in a way they decide falls outside the scope of what they want.

                If the DoD hires ACME to build some software to make widgets, and ACME uses Claude to build that software, where is the kill switch?

                I guess the Claude model could hide a kill switch in the widget manufacturing code, but so could ACME&#x27;s human subcontractor. Why is Anthropic being considered a supply chain risk here?

          6. pixelatedindex · · focus · HN ↗
            Can’t you exclude suppliers who use Anthropic?
            1. zymhan · · focus · HN ↗
              That is what has been done
        3. russfink · · focus · HN ↗
          If you outsource your thinking to a server that can detect your IP address, and decide to render decision “b” instead of decision “a” to your query, that’s a risk. (Or detect by the type of query, past history of your use, etc.). Panopticlick should be having a field day with all this.
      6. hiddencost · · focus · HN ↗
        ??? What are you talking about. Anthropic isn&#x27;t an adversary and they&#x27;re not required to sell for purposes they don&#x27;t want to. It&#x27;s not sabotage and it&#x27;s not malicious.

        This is a designation reserved for terrorists and the link.

        1. pas · · focus · HN ↗
          that section is not important (the court says so, read page 30 <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104... ) section 4713 is (&quot;determination of exigency&quot; regarding procurement decisions)
        2. beerandt · · focus · HN ↗
          If you&#x27;re preventing the military from doing some action because you disagree with it, that makes you an adversary.

          Actively handicapping a product that&#x27;s otherwise capable qualifies.

          1. SpicyLemonZest · · focus · HN ↗
            Actively handicapping a product that&#x27;s otherwise capable qualifies. If you discover that the military is using your capacitors to make rocket launchers, so you introduce a manufacturing defect that will cause them to fail at high heat, you&#x27;re a supply chain risk and can be rightfully designated as such.

            The converse does not qualify. If I advertise a chemical with an admixture that prevents it from being used to make explosives, the military has absolutely no right to demand that I produce a version of that chemical without the admixture. Selling a product which can&#x27;t do what the DoD wants does not make me a supply chain risk, no matter how easy it would be for me to make a different product that&#x27;s fit for their purpose.

          2. actionfromafar · · focus · HN ↗
            So... don&#x27;t buy from Anthropic? How many of the US population is an adversary, according to your definition?

            Say everyone had something to sell and DOD wanted to buy it. But some people wouldn&#x27;t make the product changes DOD demanded. Now, they are the adversary of the DOD?

            I hear Trumplandia is nice this time of year.

            1. daedrdev · · focus · HN ↗
              The point is the DoD is telling its suppliers not to use it because the supplier of your supplier is your supplier. That’s what this does
              1. actionfromafar · · focus · HN ↗
                There must be precedent if this is so normal.
                1. daedrdev · · focus · HN ↗
                  The DOD keeps extreme control over their supply chain. For many things it requires specific approval to be in the supply chain in the first place
                  1. actionfromafar · · focus · HN ↗
                    How many suppliers have they designated a supply chain risk?
          3. kelnos · · focus · HN ↗
            &gt; If you&#x27;re preventing the military from doing some action because you disagree with it, that makes you an adversary.

            No, it doesn&#x27;t. The military doesn&#x27;t have a right to force product requirements and terms of use on companies they contract with.

            If they don&#x27;t like the contract terms, they can simply not sign a contract and not do business with a company. Trying to get them designated a supply-chain risk is just political retribution.

            1. beerandt · · focus · HN ↗
              &gt;If they don&#x27;t like the contract terms, they can simply not sign a contract and not do business with a company.

              How is that not what they&#x27;re saying here by banning it in the supply chain?

              How else do you prevent any dod purchases or contracts from &#x27;having contact&#x27; with a software you don&#x27;t trust?

              1. fn-mote · · focus · HN ↗
                To be credible, you need to address the point that this prevents subcontractors from using it to code.
              2. kalkin · · focus · HN ↗
                Why has this never previously been done to an American company from which the DoD decided not to purchase something?
          4. handoflixue · · focus · HN ↗
            &gt; Actively handicapping a product that&#x27;s otherwise capable qualifies.

            But they&#x27;re not actively handicapping it. They&#x27;re saying it would be wildly irresponsible to assume it&#x27;s &quot;otherwise capable&quot;.

            And very critically: they have taken zero steps to &quot;actively handicap&quot; it in any way.

            1. beerandt · · focus · HN ↗
              Wanting veto power in execution is functionally the same as actively handicapping it, regardless of how implemented.
            2. throwaway63486 · · focus · HN ↗
              The Claude they sell to me seems quite actively handicapped when I ask it questions about cyber security or biology.
            3. knollimar · · focus · HN ↗
              am I insane with all these people making the actively handicapping argument? Doesn&#x27;t openAI sell to them the actively handicapped version?

              Like they&#x27;re okay with the product being designed to be incapable but not terms limiting a product.

      7. folocitoan · · focus · HN ↗
        Here on planet Earth, what happened is that Anthropic imposed licensing terms. The DoD is free to reject those terms. But that is not evidence that Anthropic is planning to harm the US military by sabotaging its products. There is no evidence that Anthropic changed, or planned to change, the design of its system to work against the US military following its dispute with the DoD. Zip zero nada. Never happened. Anyone who tells you otherwise is lying.

        &gt;To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

        The pen analogy would be more like the manufacturer selling pens that work just fine under all circumstances but that the military starts using in hand-to-hand combat.

      8. kelnos · · focus · HN ↗
        That&#x27;s not at all what this is. Anthropic was very clear up-front what they would and wouldn&#x27;t allow. They were not going to &quot;subvert&quot; anything. &quot;Degrade function&quot; in this context means that there is a risk that ongoing changes to the covered system will cause problems for the government. That wouldn&#x27;t have been the case here; it would have been clear from the start what the military would and wouldn&#x27;t be allowed to do with it, and that wouldn&#x27;t change.
      9. mqus · · focus · HN ↗
        All of those verbs basically mean &quot;degrade an existing system, after the fact&quot;. If anthropic states beforehand that certain use cases are not possible, it should be fine, no?

        To give another (bad) analogy: The Pens aren&#x27;t made to be weapons themselves, they are not intended for that. If the DoD now tries to shoot pens as projectiles and they just melt, that&#x27;s no reason to classify the pen manufacturer as a supply chain risk, the product was not altered after the fact.

        Of course, there _is_ a difference in &quot;It could do that, but it shouldn&#x27;t&quot; and &quot;It cannot do that&quot;. But it is not that large. That&#x27;s why I don&#x27;t see it as that clear cut.

      10. stevetron · · focus · HN ↗
        While amusing on the surface, let&#x27;s substitute an ink-jet printer for the pen, and have a malicious party inject code as a print driver update, or maybe re-programs that chip in the ink cartridge, and the ink cartridge refuses to function on certain print jobs. Maybe it will only allow the words &quot;WE SURRENDER&quot; be printed as part of the message.
      11. asfdgionbio · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.