Safe AI Now Means Obedient AI
Washington hasn't nationalized the AI labs — it has nationalized the word "safe," and the new standard measures obedience, not what a model won't do.
In federal procurement, a "supply-chain risk" is a label with a specific history. It has been reserved for foreign vendors — companies whose hardware or software could be made to work against the country that bought it. In February, the Defense Department aimed it at an American lab. Anthropic's product worked, and its listed offense was what it refused to do.
America’s warfighters will never be held hostage by the ideological whims of Big Tech. — Pete Hegseth
The designation ended a $200 million contract and barred federal contractors from doing business with the company [1]. The origin sits on February 1, before any dispute existed, in a doctrine the Pentagon wrote down. A commercial AI tool, officials argued, had to be usable for war regardless of what the company that built it believed.
won’t allow you to fight wars — Pete Hegseth
"All lawful purposes" had concrete meanings: mass surveillance of Americans, fully autonomous weapons. They were demanded of Anthropic, then the sole provider of AI on the military's classified networks [2]. The company said no.
No amount of intimidation or punishment from the Department of War will change our position on mass domestic surveillance or fully autonomous weapons. — Anthropic
Across those same weeks, xAI accepted the identical terms — and took the classified deployment Anthropic had held. Officials conceded that the replacement, Grok, was not as reliable or as advanced as what it replaced [2]. No one called it a trade, but the terms were on the table: compliance bought the contract, refusal lost it. From there the machinery ran fast. The guardrails themselves became the threat. The president framed the company's limits as putting American lives at risk.
Their selfishness is putting AMERICAN LIVES at risk, our Troops in danger, and our National Security in JEOPARDY — Donald Trump
Then the ban went total.
I am directing EVERY Federal Agency in the United States Government to IMMEDIATELY CEASE all use of Anthropic’s technology. — Donald Trump
This week, the state opened its own storefront. GenAI.mil gives more than three million personnel one place to buy AI built on Google, OpenAI, and xAI, with the February commitment now written into the shelf: what gets sold is whatever will serve any lawful purpose [3]. The demand side is already scheduled — the Autonomous Warfare Command becomes a four-star combatant command in October 2027 [4]. Last month, Bill Gates called on Washington to impose federal guardrails [5]. The president answered with the whole doctrine in a single sentence.
The only control or ‘guardrails’ that AI needs is a STRONG AND SMART (High IQ!) PRESIDENT, and the U.S.A. has that, in spades! — Donald Trump
The guardrail was not removed. It was relocated — from the system, where it might say no, to the man at the top, whose only specification is obedience. Then the record ran the standard through its own test, dated act by dated act. While the ban stood, the military kept using Claude for intelligence assessments and target identification during the Iran strikes and the Maduro-capture operation [1]. In May, mid-phaseout, the Pentagon emergency-deployed Anthropic's unreleased Mythos model for critical defensive work [6] — an unusual way to handle a genuine supply-chain risk. In August, a federal judge blocked the designation, but the six-month phase-out kept the ban alive as a fact of procurement [7]. And in September the same state opened a dialogue with Beijing that includes a crisis hotline for incidents involving "uncontrollable autonomous agents" [8].
We want to open a communications line, an incident line, so that we have constant communications, especially in the event of some kind of an incident. — Scott Bessent
The technical definition of danger — a system that will not stay controlled — was alive in the state's own diplomacy in the same season it was being written out of the domestic standard. The private market, for its part, never read the designation as a warning about the product. Microsoft says customer spending on the lab's models keeps growing, and the cutbacks at Meta and Microsoft were cost decisions, their own models taking the work [9]. The lab itself kept building channels into the state: a Microsoft 365 connector shipped with beta support for Defense Department endpoints, and the government drafted policies to let the Mythos cybersecurity tool into federal systems [10][4]. None of that is how a state treats a threat. It is how it treats a supplier it still needs. And the loyalty standard was being enforced beyond procurement, too: this week a senator told the lab to stop warning that its product might end the species while pitching a near-$2 trillion IPO, the warning itself treated as disloyalty [11]. Outside Washington, other institutions are still running the older specification — the one that defines safety as a technical limit rather than a promise of compliance. New York's City Council proposed mandating kill switches, third-party validation of bias, privacy, and security, and fines [12].
This is not an industry that should self-regulate. — Julie Menin
Inside the tent, the dissent runs on the same axis: Admiral Frank Bradley, who leads Special Operations Command, insists that however much the software decides, a human has to be able to know the violence lands only where it was meant to.
We, as humans, have to have the confidence that ... it's going to deliver violence only where we intend it to be delivered. — Frank M. Bradley
And the public cast its own vote. When OpenAI signed the classified-network deal that replaced Anthropic, the "QuitGPT" backlash drove Claude to the top of the U.S. App Store [1]. Which is why the last turn in the record lands the way it does. In February, Dario Amodei had set the company's limits in public and said nothing would move them [1]. By late September he was proposing a global safety framework with rules for all U.S. frontier labs [5]. Then came this week's White House meeting with the president who banned it.
if we work with the president, we can win safely — Dario Amodei
Asked what the new arrangement does to the risks that started the fight, the answer was that they are still being worked out.
How we address those risks is still under discussion — Dario Amodei
[3] That is the bend the whole record has been curving toward. For eight months the fight looked like a dispute over a lab's right to say no. What it actually settled was the meaning of the word the fight was fought over. Safety no longer names what a system refuses to do. It names a supplier's willingness to do whatever it is told — and the company that once refused to let the state set its limits ended the season asking the man who banned it to help set them.
- 1. Trump Bans Anthropic After AI Ethics Standoff with Pentagon
- 2. Pentagon Deploys xAI Grok After Standoff With Anthropic
- 3. Pentagon Bans Anthropic AI While Launching GenAI.mil Platform
- 4. Defense Department Signs Eight AI Deals to End Anthropic Reliance
- 5. Bill Gates Urges Trump to Regulate AI Amid Catastrophe Warnings
- 6. Pentagon Deploys Anthropic's Mythos AI Despite Ongoing Phaseout
- 7. Federal Judge Blocks Pentagon Risk Designation of Anthropic
- 8. US and China Establish AI Dialogue Ahead of Summit
- 9. Meta and Microsoft Cut Internal Use of Anthropic AI
- 10. Anthropic Launches Claude Desktop Beta for Linux and Enterprise
- 11. Senator Bernie Moreno Criticizes Anthropic CEO Over AI Safety Warnings
- 12. New York City Council Proposes AI Kill Switches and Fines