‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. sippingabonedry · · focus · HN ↗
      > I know everyone says this is political but it actually seems like a textbook designation

      It literally is a textbook definition, signed into US law:

      “Supply chain risk,” means the risk that an adversary may sabotage, maliciously introduce unwanted function, or otherwise subvert the design, integrity, manufacturing, production, distribution, installation, operation, or maintenance of a covered system so as to surveil, deny, disrupt, or otherwise degrade the function, use, or operation of such system (see 10 U.S.C. 3252).

      To add onto what another commenter said, the pen analogy would be more like the manufacturer designing pens that stopped working when used to sign strike orders they disagreed with.

      1. cmdli · · focus · HN ↗
        Selling a pen labeled "this pen will refuse to sign certain orders" is not sabotage or malicious and is thus not a supply chain risk. The DoD is free to not buy from Anthropic, but designating them as a supply chain risk is incorrect, as well as arguably arbitrary and capricious given their public criticism of Anthropic's beliefs.
        1. rdsubhas · · focus · HN ↗
          The DoD buys from suppliers, who buy from suppliers, and so on. Hence supply chain. Hence supply chain risk.
          1. Wowfunhappy · · focus · HN ↗
            So we have a pen that may refuse to sign certain orders, and is clearly labeled as such.

            If the DoD needs to sign such orders, they won't buy this pen.

            If a supplier needs to sign such orders, the supplier also won't buy the pen.

            If a supplier needs to sign other orders, and this pen is the best one available, the supplier may decide to buy this pen. Since the orders are within the range of what the pen will sign, they get signed, and the supplier fulfills its contract with the DoD.

            Where is the supply chain risk? The ink isn't going to erase itself post-hoc.

            ---

            Now, if the DoD suspects that Anthropic will train its models to try to actively sabotage military operations, that's a very different story. Does anyone actually believe that?

            1. rayiner · · focus · HN ↗
              [delayed]
              1. Wowfunhappy · · focus · HN ↗
                > You’ve got a vendor who could kill switch critical military technology if it’s used in a way they decide falls outside the scope of what they want.

                If the DoD hires ACME to build some software to make widgets, and ACME uses Claude to build that software, where is the kill switch?

                I guess the Claude model could hide a kill switch in the widget manufacturing code, but so could ACME's human subcontractor. Why is Anthropic being considered a supply chain risk here?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.