‹ BackHN Continuity

Thread

U.S. appeals court upholds designation of Anthropic as supply chain risk

499 points · 900 comments · cramer4next

  1. ApolloFortyNine · · focus · HN ↗
    I know everyone says this is political but it actually seems like a textbook designation. Anthropic wanted to have rules on how the military used AI, the military said no and therefore doesn't want anthropic used anywhere in their supply line.

    This is like a pen manufacturer not wanting their pens used to sign drone strike orders, now the military needs to have a special box of pens that don't have stipulations attached. With AI usage it would be the same thing except applied to entire product chains. It seems like it would just add more complexity to operations.

    You can agree with the rules anthropic wanted, but having rules set by a private company at all that apply to the military does seem fair for the military to object to.

    >The Department reasonably feared that Anthropic might manipulate Claude’s design to prevent it from performing national-security functions that the Department deems contractually authorized and necessary

    Though they'd probably put the DoD on the cybersecurity whitelist today, the very idea of the claude whitelists for certain functionality already exists and is being used by them today.

    1. jzb · · focus · HN ↗
      “the military said no and therefore doesn't want anthropic used anywhere in their supply line”

      It’s clearly a punitive measure and has nothing to do with national security.

      If a supplier uses Anthropic to develop a product, how does that pose a risk to the DoD or national security? The DoD can specify that a third party system can’t rely on Anthropic for DoD use without designating the company a supply risk. It was very clear that the administration was punishing the company for saying “no”.

      1. frumplestlatz · · focus · HN ↗
        Anthropic took the position that our military’s decision making power should be subordinate to Anthropic’s constraints.

        Any dependency on a company that thinks they have that moral authority and has the technical means to enforce it is absolutely a risk to the supply chain.

        If you want to blame someone or something for this, we should start with Dario and “effective altruism”.

        1. testdelacc1 · · focus · HN ↗
          But why can’t the military just not use Anthropic? Why can’t the DoD say “ok we’re going with a different vendor”? Even if you find Anthropic’s stance distasteful, why support taking punitive action on Anthropic?
          1. satvikpendem · · focus · HN ↗
            I feel like in this thread no one is understanding what supply chain risk designation is. The government can just not use Anthropic, and that's exactly what they're doing, and they are not using it so much that they don't want Anthropic anywhere in their chain of supply. It's not necessarily punitive, the government is just covering their tracks so that if somewhere in their supply chain Anthropic exists, they want to remove them. They are complying with Anthropic's demands to not be used in war and the DoD says, okay, we won't use you anywhere and also enforce that we won't use you, just like you wanted.
            1. joshuamorton · · focus · HN ↗
              Anthropic said "we don't want to be used as part of kill chain decision-making" (actually it may have been even more specifically autonomous/unmanned kill chain decision making)

              The DoD responded not by saying "alright, we will use OpenAI for our kill-chain uses" but by saying "Boeing is no longer allowed to use Claude Code".

              1. firesteelrain · · focus · HN ↗
                Correct, they do not want “Boeing” to use Claude models to write software for airplanes for example
                1. joshuamorton · · focus · HN ↗
                  Yes, and this is not (and cannot be!) a supply chain risk in any reasonable interpretation.
                  1. satvikpendem · · focus · HN ↗
                    If the DoD uses some Boeing plane, they do not want Anthropic to be able to interfere somehow.
                    1. joshuamorton · · focus · HN ↗
                      And my point is that using Claude models for coding a Boeing plane does not allow anthropic to interfere in the operation of those planes. Once the code is written, anthropic has not plausible form of control.

                      Thus, it cannot be a supply chain risk.

                      1. satvikpendem · · focus · HN ↗
                        Do you remember the Fable release? Anthropic themselves said they'd sabotage code of certain groups they didn't like such as frontier AI researchers. Why do you think they couldn't do the same here?
                        1. joshuamorton · · focus · HN ↗
                          No, they said fable would stop working. That's very different.
                          1. satvikpendem · · focus · HN ↗
                            > But for researchers trying to use Claude Fable 5 for frontier AI development, Anthropic outlined a different approach. The firm would deliberately degrade the model’s performance in ways that were invisible to the user. The move would effectively sabotage researchers trying to use Claude to train competing AI models, which Anthropic explicitly bans in its terms of service.

                            <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-on-claudes-secret-sabotage-on-ai-research&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;anthropic-responds-to-backlash-o...

                            It&#x27;s not just &quot;stop working,&quot; it&#x27;s actively degrading the code.

                            1. joshuamorton · · focus · HN ↗
                              Okay, so what relevancy does this thing, which anthropic didn&#x27;t do, have to anything we are talking which right now is using Claude code in line with its terms of service?
                              1. satvikpendem · · focus · HN ↗
                                They didn&#x27;t do it due to backlash but they have the capability and more importantly the culture to do so. It is correct that the government doesn&#x27;t want anything to do with a company who&#x27;d act like that.
                                1. joshuamorton · · focus · HN ↗
                                  Actually, what I said was &quot;Once the code is written, anthropic has not plausible form of control.&quot;

                                  To which you brought up something that still wasn&#x27;t relevant.

                                  The government is perfectly able to choose not to work with contractors it doesn&#x27;t like. That&#x27;s not this.

                                  1. satvikpendem · · focus · HN ↗
                                    If Claude adds a backdoor autonomously then Anthropic would have a form of control. Even if it doesn&#x27;t, Claude would be following the will of its creator instead of the government which the latter obviously does not want. I am not sure why it&#x27;s that hard to understand that the government does not want any part of its stack to be influenced by such a company. This is exactly what supply chain risk is.
                                    1. joshuamorton · · focus · HN ↗
                                      So Claude is a supply chain risk in the same way that an employee is a supply chain risk.

                                      I&#x27;m struggling here because you&#x27;re basing this determination entirely on things which the government never acused anthropic of, and haven&#x27;t asked anthropic to address, and which the underlying law probably doesn&#x27;t support.

                                      The government made clear that it was only designating anthropic a supply chain risk due to their refusal to allow Claude to be used lawfully for autonomous kill chains and domestic surveillance. Why are you bringing up this other stuff when the government never did?

                                      1. satvikpendem · · focus · HN ↗
                                        Please read the entire opinion first as it explains exactly what the government thinks. The majority of the court says the Department reasonably worried that Claude-supported “critical defense system[s]” might “fail[] to engage” as expected. Those are concerns about how a supplier-controlled model performs inside a system, not merely politicking. See the opinion, especially pp. 12 and 19–21: <a href="https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-1049-2194984.pdf" rel="nofollow">https:&#x2F;&#x2F;media.cadc.uscourts.gov&#x2F;opinions&#x2F;docs&#x2F;2026&#x2F;09&#x2F;26-104.... my point about Fable or adding a backdoor is not that they do that, it&#x27;s that they have a documented history of trying to change model behavior in unspecified ways just because they don&#x27;t like a certain group of people and it is not worth the risk for the government to have something like that sprung upon them, at any point, at all. A private company cannot ever have the ability to dictate to the government what it can and cannot do, and if that company doesn&#x27;t want to comply, the government is reasonable in excising them from their systems, which is what this supply chain risk designation is.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.