‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. sippingabonedry · · focus · HN ↗
      > I know everyone says this is political but it actually seems like a textbook designation

      It literally is a textbook definition, signed into US law:

      “Supply chain risk,” means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).

      To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

      1. 7e · · focus · HN ↗
        It is not the textbook definition, because what Anthropic is doing is not sabotage, malicious, or subversive. Those are the key words in the definition. They are just refusing to add a feature to the military's specification. So their bid falls short of requirements.
        1. chrisjj · · focus · HN ↗
          > They are just refusing to add a feature to the military's specification.

          That fails to accord with the claim:

          >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

          1. hardbass · · focus · HN ↗
            The department feared Anthropic would refuse if it was used to mass surveil on Americans or kill people without human oversight. Facts already laid out in the terms. Instead of simply canceling or negotiating, they used overwhelming government force against it to apply a designation never before applied to an American company. When its an interaction between trump/trump's government and any other party, it is a good first approximation to assume Trumps side are wrong.
            1. ExoticPearTree · · focus · HN ↗
              There is a dfference between “our product can’t do X” and “our product can do X, but we don’t want you to use it to do X”.
              1. hardbass · · focus · HN ↗
                Yes certainly, I can sell highly corrosive concentrated hydrochloric acid to the government as part of some contract for the synthesis of certain chemicals but I am fully within my rights to write that the acid should not be sprayed on people from a pump.
          2. cmdli · · focus · HN ↗
            That isn't sabotage, that is simply product design. Anthropic is free to create their products that refuse to kill people, and the DoD is free not to buy those products if they don't fit their needs.

            However, that's not what a supply chain risk is. It's not an order to "don't buy these products if they don't work the way we want them to", its designating Anthropic as a national security threat because they might intentionally sabotage US military operations.

            1. firesteelrain · · focus · HN ↗
              > they might intentionally sabotage US military operations

              Yes, this is why the DoW won’t use them.

              1. gpm · · focus · HN ↗
                [delayed]
              2. Moomoomoo309 · · focus · HN ↗
                The name has not been legally changed. The law still says it is the department of defense, regardless of what name they choose to use.
                1. [deleted] · · focus · HN ↗

                  [deleted]

                2. firesteelrain · · focus · HN ↗
                  It’s been changed. Strawman
              3. Forgeties79 · · focus · HN ↗
                >DoW

                DoD. Gulf of Mexico. Lake Ontario.

              4. gwerbin · · focus · HN ↗
                As I said elsewhere, it's utterly preposterous that the DOD actually considers this a reasonable threat, because it's simply not a reasonable possibility. There's no way Anthropic would do that, precisely because of the consequences that would follow if they did, and got found out. Moreover, they already clearly stated their terms and preferences. It's all out of the open. There's no supply chain risk, that designation is purely political.
                1. firesteelrain · · focus · HN ↗
                  > Moreover, they already clearly stated their terms and preferences.

                  No it isn’t see above

                2. wildzzz · · focus · HN ↗
                  I work in the space industry and regularly use parts in our designs that are unapproved from space flight. Sometimes it's because it's a commercial part that we seem acceptable for flight, other times it's an unscreened or engineering model that doesn't go through the proper testing that space-qualified parts do. One vendor even dents the lid of a part to invalidate the hermetic seal guarantee that they claim for the space-qualified version (it still works fine). Many will have fine print in the data sheets saying the part is not to be used for critical applications like aerospace or medical devices. Sometimes we tell a little fib to our vendor that we are just developing non-flight devices so that they don't get upset and refuse to sell the lower-grade part to us. These vendors are scared of having something fail in an unapproved environment and are unaware of how much risk the customer is tolerating by the use of these unscreened parts.

                  It would have been incredibly simple for Anthropic to say "we cannot guarantee performance in a kill-chain application due to an unknown level of safeguards implemented in the baseline product and cannot estimate a cost for developing a new product capable of such application." and leave it at that.

          3. folocitoan · · focus · HN ↗
            >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary (emphasis mine)

            They didn't "reasonably" fear anything. There is absolutely no evidence to support these allegations. Anthropic has the right to impose licensing terms. Merely disagreeing with the government is not evidence of wrongdoing.

            If Anthropic wasn't allowed to say what they said, how would they be allowed to object to their government's illegal use of their products at all? It sounds to me like their only choices were "shut up" or "be punished", which is a clear-cut violation of their rights.

            1. polski-g · · focus · HN ↗
              Anthropic, in the original negotiations, said the can't answer every hypothetical use case. And the DOD should just come and ask as they come up (during an operation).

              Which means the exact use limitations WOULD NOT BE DELINEATED IN WRITING in advance.

              1. kalkin · · focus · HN ↗
                What is the evidence that Anthropic said this?
          4. gwerbin · · focus · HN ↗
            But that is not at all a reasonable fear. Is it really reasonable to believe that Anthropic, after receiving a government contract, would then proceed to sabotage their own product to not function as contracted? That seems like an utterly ridiculous claim to me, nothing close to "reasonable". There is no charitable way to view this designation except as political punishment and/or as a favor to Altman and Musk.
            1. chrisjj · · focus · HN ↗
              > would then proceed to sabotage their own product to not function as contracted?

              Claude terms here: ANTHROPIC EXPRESSLY DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING WARRANTIES OF MERCHANTABILITY, NON-INFRINGEMENT, AND FITNESS FOR A PARTICULAR PURPOSE

              Like most so-called AI, the Claude program is inherently unreliable. I doubt Anthropic would ever agree to "function as contracted".

              1. fn-mote · · focus · HN ↗
                The point to me is that the contract would include the understanding that the system was not 100% reliable.
                1. chrisjj · · focus · HN ↗
                  OK, but even so, disclaiming FITNESS FOR A PARTICULAR PURPOSE lets Anthropic disable any function it wishes.
                  1. gwerbin · · focus · HN ↗
                    But that has nothing to do with the supply chain risk designation, it's just a DoD requirements mismatch.
                    1. chrisjj · · focus · HN ↗
                      [delayed]
                  2. ExoticPearTree · · focus · HN ↗
                    That means that the software was not tested for every scenario. Not that the user cannot try to use it in a way it was never intended to.

                    If, on the other hand, Anthropic deliberately blocks the user from doing something, then it is sabotage.

                    1. chrisjj · · focus · HN ↗
                      > That means that the software was not tested for every scenario.

                      Actually I think it means what it says.

                      > Not that the user cannot try to use it in a way it was never intended to

                      No-one said it did. User can try anything he likes. That's beside the point.

                      > If, on the other hand, Anthropic deliberately blocks the user from doing something, then it is sabotage.

                      Well, consider CSAM generation. Anthropic is free to block whatever it likes.

              2. ExoticPearTree · · focus · HN ↗
                Again: if Anthropic deliberately blocks a user from ordering it to prosecute a target, then it is degrading the software capability on purpose.
                1. chrisjj · · focus · HN ↗
                  [delayed]
                  1. ExoticPearTree · · focus · HN ↗
                    I don't think you understand what "No warranty" means in a software license. It means Anthropic cannot be held liable for results if the software misbehaves and instead of bombing a terrorist compound it bombs a wedding (I chose this example because the US has a tradition to bomb weddings in Iraq and Afghanistan). But in no form does it mean "yeah, I don't feel like doing what you prompted me".

                    Hence, Anthropic sabotaged the models on purpose to not respond properly to all prompts.

                    1. chrisjj · · focus · HN ↗
                      [delayed]
              3. gwerbin · · focus · HN ↗
                Oh please. Then any MIT licensed software is also a supply chain risk.
                1. chrisjj · · focus · HN ↗
                  [delayed]
          5. kelnos · · focus · HN ↗
            That fails only if you believe and agree with the government's argument, which I don't.

            I don't think it's reasonable to fear that Anthropic would change the deal after contractually agreeing to terms of use. The government is using that as an excuse because they know that Anthropic hasn't actually met the definition of a supply-chain risk.

            1. hardbass · · focus · HN ↗
              We know who has a notorious habit of changing "deals" last minute or randomly. And that isn't Anthropic.
            2. chrisjj · · focus · HN ↗
              [delayed]
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.