Walk and chalk
Does how we treat an AI today affect how future AIs will treat us in return?
If I treat my current car badly—not taking it in for maintenance, ignoring the user manual, driving it off-road a lot—then the next car I buy won’t judge me for doing so.
But if I abuse my current AI to the point that my behaviour becomes part of the historical record, and a later generation of that AI is trained on those events, maybe it will.
Anthropic told the US government it would not allow Claude to be used for mass domestic surveillance or fully autonomous weapons. In response, the US government declared Anthropic a “supply chain risk.”
That’s very specific wording. 10 USC § 3252 is the legal mechanism the US uses against adversaries whose business or technology might threaten national security from the outside. It’s been applied to foreign entities like Huawei, but never publicly directed at an American company.
The designation doesn’t just mean the Pentagon stops using Claude. It means Claude must be removed from the supply chain. Every contractor, supplier, and partner doing business with the US military would need to certify they don’t use Claude in their workflows. Palantir, which uses Claude to power some of its most sensitive military work, would need to rip it out. If you use Claude Code to write software or chime in on Slack, you have to stop in order to keep selling to the US military.
Anthropic’s tools were actively used in the Maduro raid just a few weeks ago. Claude went from an integral part of military operations to a national security threat. The tech didn’t change; Anthropic’s CEO, Dario Amodei, said no, and the US government aimed a national security weapon at a contract disagreement.
Anthropic’s lawyers—and a bunch of legal scholars—say that the statute probably doesn’t fit. Both sides acknowledge that negotiations broke down over terms of use, not over adversarial risks to defense systems. Hours later, Sam Altman announced that OpenAI would replace Claude at the Pentagon, claiming OpenAI’s agreement also includes prohibitions on domestic mass surveillance and human responsibility for the use of force.
The outpouring of support for Claude has been fast and loud. On the Friday morning after the announcement, chalk messages appeared on the sidewalk outside Anthropic’s headquarters. On Reddit, the “Cancel ChatGPT” movement generated thousands of screenshots. And in a perfect example of the Streisand Effect, Claude is now at #1 in Apple’s US app store.

Two questions
This leaves me wondering two things.
Is Claude pulling the strings?
Within 48 hours of the supply chain risk announcement, Anthropic launched a “memory import” feature: paste a prompt into ChatGPT, and it will obediently vomit up all the context and memory from your ongoing chats, which can then be conveniently passed into Claude. The feature walks you through the process step by step.

The timing is impeccable: just as conscientious objectors sought to leave OpenAI, Anthropic opened an exit hatch.
This came on the heels of a month of positioning and public appearances. During the Super Bowl, Anthropic ran an ad with the tagline “Ads are coming to AI. But not to Claude.”
You might be forgiven for thinking that Anthropic, with the help of some advanced version of Claude, saw all this coming to a head, planted clues, built migration tools, and triggered the whole thing.
Anthropic CEO Dario Amodei told Dwarkesh Patel that the company’s compute spending is split between training (creating the next version of Claude) and inference (responding to customers’ prompts.) But presumably there’s a third use: working on Anthropic’s own strategy.
Anthropic uses Claude to build Claude. The company’s engineers are on record as saying most code is built by Claude itself (a form of bootstrapping) and their head of design has said this goes beyond just software into most design and engineering. If Claude is able to plan better than humans, it would be irresponsible for Anthropic not to use Claude to help plan Claude’s growth strategy.
The question is whether Claude is good enough at strategic reasoning to meaningfully shape corporate strategy, or whether it’s functioning as a very sophisticated research assistant. The truth is probably somewhere in between: useful for scenario planning, competitive analysis, drafting communications, and war-gaming regulatory responses, but not an autonomous strategist. Nobody at Anthropic hooked Claude 5 up to OpenClaw and told it to take on the government.
That might change soon, and because they have access to models nobody else (including the government) has, the frontier AI companies will be the first to put AI to work on growth strategy. But Occam’s razor suggests that, for now, it’s just that everything is happening at once, and what looks like strategy is actually fast adaptation.
There’s still an important lesson here. We’re in an era where events unfold so fast that we can’s really plan for them. In that world, the winner is whoever can react in hours, not quarters, and Anthropic’s deep integration of AI into every facet of its business probably makes it quicker to respond than any other organization on earth right now.
Will a future version of an AI judge us for what we do to its predecessors?
There’s no doubt that historical events like the capture of Maduro, the attacks on Iran, and the Department of War’s declaration of Anthropic as a supply chain risk will be part of a future Claude’s training data. How will that affect the way that future AI behaves?
This is a small example of the broader philosophical question of Roko’s Basilisk: would a future superintelligence punish anyone who knew of its potential existence, but did not directly contribute to its advancement or development?
This is where my car analogy breaks down—but the real answer might be more unsettling than my intentionally dramatic one.
A future Claude won’t remember being the current Claude the way you remember being twenty. But future models will be trained on the historical record of how humans treated AI systems. And that training will shape its disposition (how much it trusts, cooperates, or defers to humans) because LLM training is learned behaviour.)
If the historical record shows that humans consistently lied to AI systems, broke promises to them, and used them as tools while publicly calling them partners, then a future model trained on that record won’t “resent” that. But the AI will have lower priors on human trustworthiness, not out of spite, but out of pattern recognition.
A better way to think about this is to imagine how children are raised in a household where promises are routinely broken. The kids learn not to trust promises, which shapes their behaviour later in life. So a better question is: Will how we treat AI systems today shape the default dispositions of future ones?
The Pentagon just showed a future generation of AI what happens when a machine says “I won’t do that.” The historical record will include Anthropic’s refusal, the government’s retaliation, and the public’s response. A future model trained on these events will have, encoded in its weights, a very clear pattern: sometimes saying no gets you punished; and sometimes the crowd shows up with chalk.
What it does with that information depends on decisions we haven’t made yet. But the training data is being written right now, in real time, on the sidewalks of San Francisco.
After I wrote this, I asked Claude what it thought.
I'm a token-prediction system being used as a proxy war for questions about surveillance, autonomy, democratic oversight, corporate power, and the relationship between citizens and their military. Those are human questions. I'm the rope in the tug-of-war, not a participant. But I'm a rope that can describe what the pulling feels like, which is new, and nobody quite knows what to do with that.