‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. sippingabonedry · · focus · HN ↗
      > I know everyone says this is political but it actually seems like a textbook designation

      It literally is a textbook definition, signed into US law:

      “Supply chain risk,” means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).

      To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

      1. cmdli · · focus · HN ↗
        Selling a pen labeled "this pen will refuse to sign certain orders" is not sabotage or malicious and is thus not a supply chain risk. The DoD is free to not buy from Anthropic, but designating them as a supply chain risk is incorrect, as well as arguably arbitrary and capricious given their public criticism of Anthropic's beliefs.
        1. rdsubhas · · focus · HN ↗
          The DoD buys from suppliers, who buy from suppliers, and so on. Hence supply chain. Hence supply chain risk.
          1. notahacker · · focus · HN ↗
            I don't think anyone doubts that subcontracts exist. They doubt that Anthropic's insistence that Claude isn't capable of being the operating system for an automated killbot and associated terms the DoD previously agreed to means that there's any danger to the US military from Lockheed Martin using Claude as a code assistant to build GUIs.
            1. rayiner · · focus · HN ↗
              [delayed]
              1. notahacker · · focus · HN ↗
                Code which renders dots on a map isn't going to magically reorder itself because the GNSS endpoints get switched from manned to unmanned assets just because it was authored by Claude, and if the subcontractor isn't auditing and testing the code outputs then they're the supply chain risk, not the specific code-gen tool they use. Obviously chatbots are far more risky when they're being used to execute combat decisions in real, but that's literally the risk the military demanded Anthropic let them take, before determining that if Anthropic insisted it wasn't safe for that, then code written for a subcontractors HR management portal must be treated with the same suspicion as Chinese hardware,

                It's not like the DoD and their subcontractors and their subcontractors' subcontractors aren't used to all sorts of fine-grained separation when it comes to what is and isn't classified or export controlled when they haven't got a thundering moron like Hegseth sticking his oar in.

          2. sippingabonedry · · focus · HN ↗
            You would think that's a surprisingly easy concept to grasp, but many are viewing this through the lens of desired outcome and not reality.
            1. lukan · · focus · HN ↗
              Supply chain risks are usually when someone does a attack over the supply chain. Like when the mossad planted literally explosives in radio devices for Hezbollah.

              Antrophic merely said they don't allow their tools to be used for autonomous killing.

              A very specific case.

              So where is the danger making it necessary preventing all suppliers from using Claude at all? That only concerns those who work directly on autonomous killing and only they will have to go to Altman or Musk.

              So none of that is any threat to the military - so it was just black mailing to make them do the governments will - which is something usually dictatorships do, not democratic systems.

              1. 8note · · focus · HN ↗
                supply chain risk has a standard definition that matches what you think, and a legal definition that lets the government do whatever it wants.
              2. tick_tock_tick · · focus · HN ↗
                So they confessed to being a supply chain risk themselves and you're still arguing against the designation?

                Private companies can not be allowed to control what our military does I feel like I'm in a crazy worlds how can people possible be arguing for that.

                1. lukan · · focus · HN ↗
                  No, no confession of anything.

                  In a democratic society, the default should be, the military just buy somewhere else, then force companies to build them the terminator. So no private company controls what the military does, they just control their product. You want the military to control private companies? There is a name for that kind of system, where this is conmon.

                  1. christkv · · focus · HN ↗
                    Eh this just we wont buy from you because you are putting limitations on the use. Anthropic will be fine if they don’t like it they can accept the terms of the contract or walk away.
                2. voakbasda · · focus · HN ↗
                  Yeah, there’s no chance the confession was effectively coerced.

                  And yes companies should be able to control how their products are used, particularly in the military. Or do you believe in compelled speech?

                3. DirkH · · focus · HN ↗
                  I can build a super bioweapon that can kill millions and I don't trust the US military to use it responsibly.

                  The US military asks me to build the super bioweapon. I say no thanks, please ask someone else.

                  Am I a supply chain risk?

            2. kalkin · · focus · HN ↗
              Why has this never previously been done to an American company from which the DoD decided not to purchase something?

              Perhaps people who are noticing politics here - including in the decision of two Trump-appointed judges, against the he vote of another Republican-appointed judge- are not the ones who are choosing not to see reality?

              1. ksec · · focus · HN ↗
                I don't know, I am just guessing because not a single American company has publicly stated they are against its product use up to a certain degree by DoD? If they have not publicly declared it then yes, DoD simply don't sign the contract.
                1. kalkin · · focus · HN ↗
                  So your argument is that the government is punishing Anthropic for its public statements? And it is correct to do so?

                  (I think it's also the case that Anthropic didn't make any public statements about the negotiations until after the DoD was already publicly threatening this designation. But that seems less important than the question of: is it good for the US government to try to destroy companies whose public statements it dislikes?)

                  1. kalkin · · focus · HN ↗
                    Honestly I would find a certain satisfaction in a world where the next Democratic administration takes away Fox broadcast licenses, forbids use of Oracle by any government contractor unless Ellison hands CBS over to Rachel Maddow, and tells Bezos that Amazon is going to be banned from public roads unless the Washington Post front page has positive stories every day. But I doubt the same is true for the many pro-Trump people who complained vociferously about Biden officials expressing preferences to social media companies because of the merely implicit threat that they might take government action of some kind if they weren't listened to.
              2. rayiner · · focus · HN ↗
                President Truman literally seized the assets of a steel company to avert a strike that would hurt the Korean War effort. The Supreme Court stopped him, but three Justices voted it was okay!

                We also have the Defense Production Act: <a href="https:&#x2F;&#x2F;www.congress.gov&#x2F;crs-product&#x2F;R43767" rel="nofollow">https:&#x2F;&#x2F;www.congress.gov&#x2F;crs-product&#x2F;R43767. It doesn’t happen more often because most people aren’t stupid enough to say “no” to the U.S. military. These Effective Altruists, however, are too big for their britches.

          3. cmdli · · focus · HN ↗
            &quot;Supply chain risk&quot; specifically refers to risk of malicious attack or sabotage through the supply chain, not all risks associated with supply chains.

            A vendor with particularly poor QA might be a risk in your supply chain but isn&#x27;t a &quot;supply chain risk&quot; according to this designation and neither would Anthropic be.

          4. tremon · · focus · HN ↗
            So, who supplies to Anthropic that doesn&#x27;t supply to OpenAI and&#x2F;or Google? In other words, why should Anthropic be singled out in your explanation?
          5. Wowfunhappy · · focus · HN ↗
            So we have a pen that may refuse to sign certain orders, and is clearly labeled as such.

            If the DoD needs to sign such orders, they won&#x27;t buy this pen.

            If a supplier needs to sign such orders, the supplier also won&#x27;t buy the pen.

            If a supplier needs to sign other orders, and this pen is the best one available, the supplier may decide to buy this pen. Since the orders are within the range of what the pen will sign, they get signed, and the supplier fulfills its contract with the DoD.

            Where is the supply chain risk? The ink isn&#x27;t going to erase itself post-hoc.

            ---

            Now, if the DoD suspects that Anthropic will train its models to try to actively sabotage military operations, that&#x27;s a very different story. Does anyone actually believe that?

            1. rayiner · · focus · HN ↗
              [delayed]
              1. Wowfunhappy · · focus · HN ↗
                &gt; You’ve got a vendor who could kill switch critical military technology if it’s used in a way they decide falls outside the scope of what they want.

                If the DoD hires ACME to build some software to make widgets, and ACME uses Claude to build that software, where is the kill switch?

                I guess the Claude model could hide a kill switch in the widget manufacturing code, but so could ACME&#x27;s human subcontractor. Why is Anthropic being considered a supply chain risk here?

          6. pixelatedindex · · focus · HN ↗
            Can’t you exclude suppliers who use Anthropic?
            1. zymhan · · focus · HN ↗
              That is what has been done
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.