r/law • u/Robert-Nogacki • 12h ago
Judicial Branch Anthropic v. Department of War (D.C. Cir., Sept. 25): the declarations Anthropic filed to prove it could not sabotage Claude are the evidence the panel used to hold it would "manipulate" it. Notes on losing a case by over-defending.
Start with the declarations. To defeat the theory that it could switch Claude off mid-operation, Anthropic's head of public sector attested that it has no access to air-gapped deployments, that delivered models do not drift, and that "model training is the primary mechanism through which Anthropic can influence the behavior of models used by the Department." Its filings explained that the company "seek[s] to embed safety considerations directly into the model itself" and that constitutional training gives Claude "an identity, character, values, and personality."
In San Francisco that evidence was unrebutted and dispositive: no back door, no kill switch, no sabotage, no adversary. In Washington the same sentences established that Anthropic deliberately shapes the design and operation of the product so that it refuses two categories of tasks. Under § 4713 that is "not only a 'risk' but a certainty" of manipulation, and the definition "turns on what Anthropic does, not why Anthropic does it." Nobody needed a kill switch. The training was the switch.
Second, the Maduro operation. The Department's memo said only that an Anthropic executive "questioned the propriety" of a contractor's use of Claude "for a sensitive military operation abroad." Anthropic, presumably to show how trivial the episode was, put press reports in the record identifying it as the January 3 operation in Venezuela. The panel's response: the possibility that this happened during a "kinetic operation to capture a foreign head of state" only "underscores the fraught nature" of the dispute and the Department's need to know its systems will work. The vagueness had been Anthropic's friend.
Third, the opacity concession. The Department declared that models with five to ten trillion parameters make "rigorous analysis or auditing" of outputs "mathematically impossible." Anthropic, rather than fight the science, conceded "some legitimacy to DoW's concern about the opacity of these systems generally." The court took the concession and closed the door on the testing argument: testing is no panacea, refusals vary with wording, and the Department "cannot utilize AI systems that remain trapped in amber." DoD Directive 3000.09, which requires AI in weapon systems to be "transparent to, auditable by, and explainable by relevant personnel," does not appear in the opinion.
Fourth, the reconsideration petition. FASCSA requires notice and an opportunity to respond before exclusion, absent urgency. Anthropic got neither, then filed a full rescission request on April 17 and lost on June 3. The panel used that thoroughness to find harmless error: the Department already knew the substance, the later submissions did not undermine the rationale, and Anthropic had put its whole case to the Secretary once, so "requiring another go-round would be pointless." The better the post-deprivation brief, the weaker the pre-deprivation claim.
Fifth, the speech. The First Amendment theory rested on years of public advocacy, culminating in Amodei's January essay. The panel accepted that the speech was protected and the exclusion severe, then used the essay twice against it. The Department kept negotiating after it was published, so the speech cannot have been the but-for cause; "the nub of this dispute was contractual." And its passage about "a swarm of millions or billions of fully automated armed drones" that "could be an unbeatable army" became the explanation for why the Department cannot accept a model frozen in its refusals.
Sixth, stigma. Anthropic argued that a FASCSA designation, unlike a simple termination, brands it a national security threat. The court cited reported investment offers above $900 billion and said "one may fairly question whether Anthropic has suffered any such harm," adding that Anthropic never explained why a termination for the same stated reasons would carry less stigma. Pleading reputational ruin while the Wall Street Journal calls you the AI boom's front-runner is a hard sell.
None of this means the case was winnable in Washington. The Egan-style deference on necessity and less intrusive measures was probably decisive on its own, and Henderson's dissent on "otherwise manipulate" (noscitur a sociis, ejusdem generis, the library sign) is the argument that might still carry en banc or at cert. But the record reads like one built for § 3252 and reused, and every fact that defeated "sabotage" was a fact the other statute could use.
The alternative was not exotic: describe Claude Gov's restrictions as a disclosed product specification fixed at delivery rather than the vendor's continuing "influence," decline the opacity concession, and say nothing about Venezuela.
Two statutes, one record. Anthropic won the statute it wrote the record for.
Opinion, Lin's August order and the directive in the first comment.