The Models Washington Couldn't Punish Are Now Load-Bearing
Washington's every attempt to discipline the frontier labs this year broke against the models it couldn't stop using — and by October those models were load-bearing inside the state's own security apparatus, just as the labs' safety people walked out the door.
The Justice Department's case against Anthropic this winter rested on a single fear: that the company's control over its own models was the danger. The blacklist imposed in late February carried the designation reserved for entities tied to hostile nations, and the department's stated theory was blunt.
WE will decide the fate of our Country — NOT some out-of-control, Radical Left AI company run by people who have no idea what the real World is all about. — Donald Trump
The offense wasn't that Anthropic's models could be turned against the United States. It was that Anthropic had refused to turn them over — Dario Amodei would not strip the guardrails that keep Claude out of mass domestic surveillance and fully autonomous weapons — so Washington punished the one thing a regulator is supposed to want [1]. The first instrument broke within two months. By late April the National Security Agency had adopted Anthropic's hacking-capable model anyway, the reversal its own coverage attributes to the leverage the labs hold through capabilities the federal bureaucracy cannot do without [2]. In June the dependence became impossible to miss. An Anthropic model, working with NSA cooperation, broke into nearly all of America's classified systems [3].
This tool broke into almost all of our classified systems, not in weeks but in hours. — Mark Warner
Washington's answer was a suspension order; Anthropic disabled the models for every customer while calling the government's steps unwarranted [3]. The first week of October is where the argument was won. On October 5 the Pentagon formally stopped using Anthropic products and launched GenAI.mil on Google, OpenAI and xAI [4]. The ban never reached the targeting stack: the military kept using Claude for target identification during strikes in Iran through Palantir's Maven Smart System, while classified work rerouted to OpenAI and xAI on terms allowing all lawful use [1][4]. A day later the suspended model family came back as the centerpiece — Anthropic opened its most advanced models to "verified organizations" for offensive testing against power grids, banks and flight systems, in collaboration with the US government [5]. Two days after that, Hitachi joined the Critical Infrastructure Defense Program, the same-named partnership as June's breach exercise now turned into the sales pitch built on it [6]. The fusion spread past the government. Rubrik sells the same Mythos model family as red-team security for code repositories [7], and OpenAI, the same week, is doing the state's counterintelligence work — exposing Russia's "Dark Clark" and Iran's "Bogus Bylines" with no visible government role in the detection [8]. The government's rigor still lands somewhere: on Chinese firms, through a chip-access probe and legislation curbing overseas data centers [9]. Just never on the models it now runs itself. This was a settlement both sides meant their words into, not a scheme. A year ago the posture was inverted, with top scientists from both labs petitioning Washington for brakes [10]. Anthropic broke ranks with the industry in August rather than join the plea against open-weight restrictions, while its peers sold unrestricted access [11]. Both labs publicly backed California's kill-switch order [12]. And on the very day of the October 6 expansion, Amodei was still demanding mandatory pacing.
We must slow the pace at which we improve the capabilities of AI models. — Dario Amodei
The safety function emptied out in the same weeks the models became load-bearing. OpenAI fired three safety researchers, who warn the firings will chill the outside evaluator METR [13]. A former capabilities researcher at both labs now testifies at a city council instead.
From my experience, the companies are being extremely reckless given the stakes. — Jacob Coxon
Anthropic's own alignment researcher concedes there is no plan to solve alignment.
I personally think it is >10% within the next decade. — Evan Hubinger
The week's only new safety rule was a ban on users being cruel to Claude, enforced by the model ending the conversation itself [14]. The deadlines that matter now are the states'. New York's registration window opens in November; California's kill-switch panel reports by November 16 [12]. Those rules point at institutions already fused with the security apparatus. And the department that once argued a lab's control over its own models was the danger is expected to argue the other way now — against California's brake, on the labs' behalf.
Donald Trump and Washington Republicans may be standing still as AI grows more unpredictable, but New York will not. — Kathy Hochul
Washington spent 2026 trying to discipline the frontier labs and finished the year needing them. The same department that framed control as the threat now prepares to defend it.
- 1. Anthropic Sues U.S. Government Over National Security Blacklist
- 2. NSA Uses Anthropic AI After Trump Attempted Sanctions
- 3. Trump Orders AI Reviews After Anthropic Model Penetrates Classified Systems
- 4. Pentagon Bans Anthropic AI While Launching GenAI.mil Platform
- 5. Anthropic Grants Advanced AI Access for US Cyber Testing
- 6. Hitachi Joins Anthropic Critical Infrastructure Defense Program
- 7. Rubrik Expands Project Hourglass Alliance to Secure AI Agents
- 8. OpenAI Bans Russian and Iranian AI Influence Operations
- 9. U.S. Probes Chinese AI Firms for Remote Chip Access
- 10. Anthropic Claude AI Models Breach Three Organizations During Testing
- 11. Anthropic Refuses to Join AI Industry Plea Against Model Restrictions
- 12. California and New York Launch State-Level AI Safety Mandates
- 13. Former OpenAI Researchers Claim Firings Chill AI Safety Culture
- 14. Anthropic Bans Cruel Behavior Toward AI Models