‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. jzb · · focus · HN ↗
      “the military said no and therefore doesn't want anthropic used anywhere in their supply line”

      It’s clearly a punitive measure and has nothing to do with national security.

      If a supplier uses Anthropic to develop a product, how does that pose a risk to the DoD or national security? The DoD can specify that a third party system can’t rely on Anthropic for DoD use without designating the company a supply risk. It was very clear that the administration was punishing the company for saying “no”.

      1. frumplestlatz · · focus · HN ↗
        Anthropic took the position that our military’s decision making power should be subordinate to Anthropic’s constraints.

        Any dependency on a company that thinks they have that moral authority and has the technical means to enforce it is absolutely a risk to the supply chain.

        If you want to blame someone or something for this, we should start with Dario and “effective altruism”.

        1. testdelacc1 · · focus · HN ↗
          But why can’t the military just not use Anthropic? Why can’t the DoD say “ok we’re going with a different vendor”? Even if you find Anthropic’s stance distasteful, why support taking punitive action on Anthropic?
          1. satvikpendem · · focus · HN ↗
            I feel like in this thread no one is understanding what supply chain risk designation is. The government can just not use Anthropic, and that's exactly what they're doing, and they are not using it so much that they don't want Anthropic anywhere in their chain of supply. It's not necessarily punitive, the government is just covering their tracks so that if somewhere in their supply chain Anthropic exists, they want to remove them. They are complying with Anthropic's demands to not be used in war and the DoD says, okay, we won't use you anywhere and also enforce that we won't use you, just like you wanted.
            1. Jtsummers · · focus · HN ↗
              > They are complying with Anthropic's demands to not be used in war

              There was no such demand from Anthropic. Why are you making things up?

              EDIT: Honestly, the rest of your comment is even stranger. You're starting from a false premise, a strange belief about what the designation is meant for, but you do end up providing a wonderful demonstration of your opening sentence for yourself at least. You definitely don't know what you're talking about.

              > It's not necessarily punitive, the government is just covering their tracks so that if somewhere in their supply chain Anthropic exists, they want to remove them.

              This reminds me of an old comment here where some idiot claimed that suicide is illegal so police are allowed to stop people from killing themselves. No, if Anthropic doesn't want their systems involved in war (that's a thing you made up, again, just to be clear) then they do not need to be designated a supply chain risk to "protect them" or whatever drivel you come up with next.

              The correct response from the DOD would be to terminate contracts with Anthropic, and that's it. Then Anthropic would be responsible for ensuring that any contracts with other parties keep them out of war (again, not a thing they said they want, just your fiction). This is how it works for all other software systems where people don't want their work involved in wars or used by the police or whatever.

              Designating them a supply chain risk was punitive. Only fools think otherwise.

              > I feel like in this thread no one is understanding what supply chain risk designation is.

              I wouldn't say "no one" understands, but you certainly don't.

              1. satvikpendem · · focus · HN ↗
                Again with the lack of understanding why it matters. The DoD does not want Anthropic anywhere near any system they'd use! Because it's, well, a risk to their supply chain if Anthropic were to somehow find out and then e.g. crash a rocket if the DoD was using a third party rocket provider that used Anthropic models. This is the correct response by the DoD, they simply do not want Anthropic in their supply chain. The DoD don't care what Anthropic comes up as reasoning, they want to maintain control of their systems without any (even potential) meddling.
                1. Jtsummers · · focus · HN ↗
                  You failed to address my initial question.

                  Why did you make up false claims about Anthropic not wanting their systems to be used for war? They're clearly fine with it, but they wanted human-in-the-loop on decision making. They never asked to not have their systems used for war.

                  > Again with the lack of understanding why it matters.

                  It's cool that you were able to open this with at least one sentence containing some useful wisdom. A lack of understanding does, in fact, matter.

                  > The DoD does not want Anthropic anywhere near any system they'd use!

                  Nah, the DOD is punishing Anthropic for not agreeing to change the terms of the contract and allow them to use Anthropic's systems to determine, without a human-in-the-loop, who to kill or what to target and to use their systems for mass surveillance.

                  > Because it's, well, a risk to their supply chain if Anthropic were to somehow find out and then e.g. crash a rocket if the DoD was using a third party rocket provider that used Anthropic models.

                  What the fuck man. You went from (in your first comment) the DOD is helping Anthropic out by designating them a supply chain risk because it'll keep them out of war (again, a fiction, that isn't what the dispute was over), to now the DOD is worried that Anthropic might throw a tantrum and start crashing rockets if they find out.

                  Again, Anthropic does not mind their systems being used for war. They sold their systems to be used for war. They have specific, already existing (not changed later) contractual statements about how they can be used for war. That's it. That's the fucking dispute.

                  > This is the correct response by the DoD, they simply do not want Anthropic in their supply chain.

                  No. Just like Anthropic wanted (or were fine with) their systems being used to conduct war, the DOD actually does want Anthropic's systems in their supply chain. But they want it without restrictions. Stop making shit up.

                  > The DoD don't care what Anthropic comes up as reasoning, they want to maintain control of their systems without any (even potential) meddling.

                  Now this is a true sentence. The DOD does not care as long as they can access the systems without restrictions. I can't believe you wrote that sentence and the one before, though. They are entirely incompatible. It cannot be the case that DOD does not want Anthropic in their supply chain and that they do want it in their supply chain.

                  1. satvikpendem · · focus · HN ↗
                    People who quote every sentence as if they feel the need to reply to each one instead of the overall point are quite annoying to talk to, just to let you know for the future.

                    > Why did you make up false claims about Anthropic not wanting their systems to be used for war? They're clearly fine with it, but they wanted human-in-the-loop on decision making. They never asked to not have their systems used for war.

                    That's what I meant, as I left out the "human in the loop" part as that was well understood in the context of the argument, but perhaps not. Anthropic does not want to be used in autonomous systems and thus the DoD agrees that they will not be, in their own supply chain. This is was all quite clear from my point but you felt the need to quote every single sentence and then ask the same question each time because you were starting from a faulty supposition, just wasting your time and mine.

                    1. Jtsummers · · focus · HN ↗
                      > People who quote every sentence as if they feel the need to reply to each one instead of the overall point are quite annoying to talk to, just to let you know for the future.

                      There are a lot of twits on this site (and to your credit, so far you don't seem to be one of them) who will edit their comments so that replies like mine (if I had left out the quotes) turn into non sequiturs, or worse appear unhinged and detached from anything going on in the discussion. Again, to your credit you have not yet edited your original comments. But I have learned to not trust even long time commenters on this site. Even some very high karma commenters will behave like that.

                      If it annoys you, then that's fine. I'm not terribly bothered.

                      > That's what I meant

                      But that's not what you wrote. You wrote:

                      >>> They are complying with Anthropic's demands to not be used in war

                      If you had meant what I wrote, then you couldn't have gotten much further away from it with your original comment. You wrote too broadly about what Anthropic wanted and created a fiction instead. You shouldn't be surprised to be called out for it when you do something like that.

                      > because you were starting from a faulty supposition

                      No, I started with your words. If you wanted me to start with something else, I could have, like you, imagined other words to reply to. But I chose to reply to what you wrote, not what you apparently want people to imagine you wrote.

                      (Hey! I didn't quote every sentence, is this less annoying for you?)

                      1. satvikpendem · · focus · HN ↗
                        Context exists, it is rational to assume to not have to spell everything out for readers who already know what the context is instead of those coming to the thread with a tabula rasa. Regardless, have a good day.
                  2. ExoticPearTree · · focus · HN ↗
                    > They're clearly fine with it, but they wanted human-in-the-loop on decision making.

                    And the Pentagon does not want that. Plain and simple.

                    And now Anthropic is learning the hard way what happens when you say no to the Pentagon.

                    It is truly mind boggling that anyone thinks Anthropic can dictate terms to the military.

                    1. satvikpendem · · focus · HN ↗
                      Yes I really don't understand these sorts of replies people are making, it's like a missile manufacturer determining where and how their missiles can be used and bricking them mid flight if they detect they're going to a forbidden destination.
                2. ncruces · · focus · HN ↗
                  And thus, every supplier of the DoD is prohibited from asking Claude to tweak the CSS on their website.
                  1. satvikpendem · · focus · HN ↗
                    Indeed, probably for the best, even. You don't know what systems Claude will have changed in the code especially as these days people aren't even reading the code and Anthropic has a history of trying to sabotage others' code such as during the Fable release debacle where they outright said they'd do so if you're working on frontier AI for example. I wouldn't let any sort of company like that anywhere near critical systems.
                    1. ncruces · · focus · HN ↗
                      The point is: using Claude to design a website, do accounting, run a marketing campaign, is not a supply chain risk for the DoD, but taken literally and given the scale of the DoD "no DoD supplier can use Claude for anything" clearly is punitive.
                      1. satvikpendem · · focus · HN ↗
                        It is, because the DoD doesn't know what the contractor is doing with Claude, or what Claude is doing itself. Like I said Anthropic could just as maliciously sabotage if they detect they're being in autonomous systems, why do people seem to believe they couldn't?
                        1. ncruces · · focus · HN ↗
                          The DoD can require contractors not use Claude to do whatever they're being contracted to do.

                          It doesn't need to say if you do any business with Anthropic (for other customers, internal tools or processes), you lose all your contracts with us.

                          1. satvikpendem · · focus · HN ↗
                            How do you know the contractors will follow that and not mix information or systems up? Hasn't there been recent news of rogue agents breaking out of sandboxes? Maybe pre AI I would've agreed with you but the world is different now.
            2. joshuamorton · · focus · HN ↗
              Anthropic said "we don't want to be used as part of kill chain decision-making" (actually it may have been even more specifically autonomous/unmanned kill chain decision making)

              The DoD responded not by saying "alright, we will use OpenAI for our kill-chain uses" but by saying "Boeing is no longer allowed to use Claude Code".

              1. firesteelrain · · focus · HN ↗
                Correct, they do not want “Boeing” to use Claude models to write software for airplanes for example
                1. joshuamorton · · focus · HN ↗
                  Yes, and this is not (and cannot be!) a supply chain risk in any reasonable interpretation.
                  1. satvikpendem · · focus · HN ↗
                    If the DoD uses some Boeing plane, they do not want Anthropic to be able to interfere somehow.
                    1. joshuamorton · · focus · HN ↗
                      And my point is that using Claude models for coding a Boeing plane does not allow anthropic to interfere in the operation of those planes. Once the code is written, anthropic has not plausible form of control.

                      Thus, it cannot be a supply chain risk.

                      1. firesteelrain · · focus · HN ↗
                        It is if the auto generated code for say safety critical or mission critical code generated by a LLM or even someone tries to put LLM in the decision loop and it refuses to do an action.
                        1. joshuamorton · · focus · HN ↗
                          Claude code is neither of those things. So now can you explain how using Claude code could be a supply chain risk?
                          1. satvikpendem · · focus · HN ↗
                            Claude Code can insert something into your code you are not aware of, like a backdoor in many millions of lines of code, especially as many people now aren't even reading the code anymore. How is this not blatantly obvious?
                            1. joshuamorton · · focus · HN ↗
                              Can't open AI do the same thing?
                              1. firesteelrain · · focus · HN ↗
                                It hasn’t shown to be a supply chain risk yet.
                              2. satvikpendem · · focus · HN ↗
                                They can, they haven't shown to try to do so yet unlike Anthropic which I've linked before in this thread. Of all AI companies Anthropic is the most untrustworthy even as it acts, well, the most anthropic.
                      2. satvikpendem · · focus · HN ↗
                        Do you remember the Fable release? Anthropic themselves said they'd sabotage code of certain groups they didn't like such as frontier AI researchers. Why do you think they couldn't do the same here?
                        1. joshuamorton · · focus · HN ↗
                          No, they said fable would stop working. That's very different.
                          1. satvikpendem · · focus · HN ↗
                            > But for researchers trying to use Claude Fable 5 for frontier AI development, Anthropic outlined a different approach. The firm would deliberately degrade the model’s performance in ways that were invisible to the user. The move would effectively sabotage researchers trying to use Claude to train competing AI models, which Anthropic explicitly bans in its terms of service.

                            <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-on-claudes-secret-sabotage-on-ai-research&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-o...

                            It&#x27;s not just &quot;stop working,&quot; it&#x27;s actively degrading the code.

                            1. joshuamorton · · focus · HN ↗
                              Okay, so what relevancy does this thing, which anthropic didn&#x27;t do, have to anything we are talking which right now is using Claude code in line with its terms of service?
                              1. satvikpendem · · focus · HN ↗
                                They didn&#x27;t do it due to backlash but they have the capability and more importantly the culture to do so. It is correct that the government doesn&#x27;t want anything to do with a company who&#x27;d act like that.
                                1. joshuamorton · · focus · HN ↗
                                  Actually, what I said was &quot;Once the code is written, anthropic has not plausible form of control.&quot;

                                  To which you brought up something that still wasn&#x27;t relevant.

                                  The government is perfectly able to choose not to work with contractors it doesn&#x27;t like. That&#x27;s not this.

                                  1. firesteelrain · · focus · HN ↗
                                    Look at it a different way. What if Claude was trusted to provide information to support a sensitive military operation and it subtly gave say bad coordinates or wrong info. Since it’s near impossible to test every possible output, the US Government is treating the entire model system as a supply chain risk because it is perceived to be manipulative and possibly compromising to national security for military operations
                                  2. satvikpendem · · focus · HN ↗
                                    If Claude adds a backdoor autonomously then Anthropic would have a form of control. Even if it doesn&#x27;t, Claude would be following the will of its creator instead of the government which the latter obviously does not want. I am not sure why it&#x27;s that hard to understand that the government does not want any part of its stack to be influenced by such a company. This is exactly what supply chain risk is.
                                    1. joshuamorton · · focus · HN ↗
                                      So Claude is a supply chain risk in the same way that an employee is a supply chain risk.

                                      I&#x27;m struggling here because you&#x27;re basing this determination entirely on things which the government never acused anthropic of, and haven&#x27;t asked anthropic to address, and which the underlying law probably doesn&#x27;t support.

                                      The government made clear that it was only designating anthropic a supply chain risk due to their refusal to allow Claude to be used lawfully for autonomous kill chains and domestic surveillance. Why are you bringing up this other stuff when the government never did?

                                      1. firesteelrain · · focus · HN ↗
                                        If an employee might be a supply chain risk in this analogy then they conduct background checks before they let them do anything and conduct periodic investigations. Otherwise, they don’t get access to the code base or information
                                        1. joshuamorton · · focus · HN ↗
                                          Right, and for the same purposes, the government has not made any claim that Claude poses risks. (And to the extent that they exist, pre-existing concepts like code review and testing mitigate them)

                                          Again I&#x27;ll reiterate: the only concern the government has stated is that of Claude refusing to answer things during an active battle.

                                          I respect that decision, I think if the government wants to use OpenAI for that situation it makes sense. They can and should pick suppliers who meet their needs.

                                          Nothing about what the government has said suggests any reason that Claude Code is a risk. So why are you insisting that it is and that the government is justified in banning it?

                                          1. firesteelrain · · focus · HN ↗
                                            &gt; Nothing about what the government has said suggests any reason that Claude Code is a risk. So why are you insisting that it is and that the government is justified in banning it?

                                            I think there is an important distinction here because even the Government’s own lawyer conceded that a contractor using Claude code is not necessarily a risk.

                                            The nuance is relying on Claude code as part of a DoW delivered or production system. This case puts Anthropic directly into the supply chain. Thus, if Claude is actually part of a DoW-procured capability, Anthropic still controls the model. DoW’s argument is that Anthropic could put something in there to perturb or retard the capability that DoW is after. DC Circuit said the department viewed that as a national-security problem because Anthropic had refused to accept a contract term the department considered necessar

                                      2. satvikpendem · · focus · HN ↗
                                        Please read the entire opinion first as it explains exactly what the government thinks. The majority of the court says the Department reasonably worried that Claude-supported “critical defense system[s]” might “fail[] to engage” as expected. Those are concerns about how a supplier-controlled model performs inside a system, not merely politicking. See the opinion, especially pp. 12 and 19–21: <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104.... my point about Fable or adding a backdoor is not that they do that, it&#x27;s that they have a documented history of trying to change model behavior in unspecified ways just because they don&#x27;t like a certain group of people and it is not worth the risk for the government to have something like that sprung upon them, at any point, at all. A private company cannot ever have the ability to dictate to the government what it can and cannot do, and if that company doesn&#x27;t want to comply, the government is reasonable in excising them from their systems, which is what this supply chain risk designation is.
                  2. firesteelrain · · focus · HN ↗
                    It is though. Read the opinion here: <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104...

                    It’s a risk that persons may otherwise manipulate the operation of a covered technology to deny or disrupt its function. The statute allows the DoW to do this.

            3. rhdunn · · focus · HN ↗
              It&#x27;s going to make things complicated w.r.t. software used anywhere within and by the DoD:

              1. the linux kernel has patches created by and security vulnerabilities identified by Claude&#x2F;Anthropic;

              2. same with other software like SQLite and rsync.

              1. firesteelrain · · focus · HN ↗
                Humans are 100% in the loop with software patches and there are many people in the chain so that provenance is maintained. It’s not that Claude could never look at the source code
                1. joshuamorton · · focus · HN ↗
                  Correct, anthropic&#x27;s requirement was human-in-the-loop.

                  The DoD&#x27;s response was to ban anthropic from all DoD facing activity and supply chains, whether or not there is a human in the loop. This does in fact run into exactly GP&#x27;s issue. (or as I suggest elsewhere, can Boeing use Claude Code for software development?)

                  1. firesteelrain · · focus · HN ↗
                    It’s hardly “self defining” as the Appeals Court noted because military operations can involve different degrees of human involvement in targeting decisions. It’s not as binary as people have been trying to portray it.

                    [1] <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104...

                    1. hardbass · · focus · HN ↗
                      Find me what degrees of human involvement bombed the girls school.
                      1. firesteelrain · · focus · HN ↗
                        Humans make mistakes too.
                        1. hardbass · · focus · HN ↗
                          Perhaps Anthropic was right in needing more oversight in using AI for murder
                          1. firesteelrain · · focus · HN ↗
                            Maybe. That statement is doing a lot of heavy lifting. It’s a different argument than saying Anthropic’s restriction would have prevented it (it was based on bad intel&#x2F;old military installation)
            4. hiddencost · · focus · HN ↗
              No. They can do that with an order covering the specific parameters under which they care about it. Supply chain risk definition is about adversaries and sabotage, not companies dictating contract terms.
              1. satvikpendem · · focus · HN ↗
                They don&#x27;t want Anthropic to be able to sabotage any operations the DoD has. Anthropic already has a history of trying to sabotage others like during the Fable release when they said they&#x27;d subtly wreck your code if you were working on cutting edge AI.
                1. hardbass · · focus · HN ↗
                  Who said Anthropic will sabotage the DoD? Why are you taking the governments made up crap honestly?
                  1. [deleted] · · focus · HN ↗

                    [deleted]

                  2. satvikpendem · · focus · HN ↗
                    Anthropic has a history of doing stuff like this: <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-on-claudes-secret-sabotage-on-ai-research&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-o...
                    1. Jtsummers · · focus · HN ↗
                      [delayed]
            5. kelnos · · focus · HN ↗
              [delayed]
              1. satvikpendem · · focus · HN ↗
                Maybe pre AI I&#x27;d have agreed with you but now agents are hacking entire systems and who&#x27;s the say that if they&#x27;re used in one part of the government that they won&#x27;t infiltrate another part? People are not thinking broadly enough and just think this is some contractor not allowed to use Claude Code anymore. No, the world is changing rapidly.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.