
Loading summary
Alan Rosenstein
The Electronic Communications Privacy act turns 40 this year and it's showing its age. On Friday, March 6, Lawfare and Georgetown Law are bringing together leading scholars, practitioners and former government officials for installing updates to ecpa, a half day event on what's broken with the statute and how to fix it. The event is free and open to the public in person and online. Visit lawfaremedia.org ecpaevent that's lawfairmedia.org ecpaevent for details and to register.
Benjamin Wittes
Want to turn your timeline into a fast lane digital?
Alan Rosenstein
Twin it to outpace the field with fast and confident decisions. Transform the everyday With Siemens, most drivers overpay for car insurance, not because they're careless, but because the system is needlessly complicated. Jerry fixes that. Traditional comparison sites give you quotes once, then disappear. But Jerry can handle all the insurance shopping legwork and never stops working. Compare 50 plus insurers side by side and purchase directly in the app. No spam calls, no hidden fees. They'll even monitor price trends and can alert you to better rates. Drivers who save for Jerry could save over $1,300 a year. Download the Jerry app or visit Jerry AI Acast today.
Benjamin Wittes
This episode is brought to you by Bill, the intelligent finance platform that helps businesses and accounting firms scale with proven results. When you're growing a business, the stakes get higher. You can't afford infrastructure that breaks under pressure. If you care about security, reliability and scale, I want to let you in on a secret. Bill is the foundational software that nearly half a million businesses and 90 of the top 100 US accounting firms use to automate back office workflows, add secure controls to payment processes and scale without increased overhead. With AI powered Accounts Payable automation, Bill erases the busy work from capturing invoices, routing approvals, and processing payments, syncing seamlessly with the top accounting software platforms. So your books are always accurate. But Bill isn't just accounts payable it supports the full payments workflow. Bill has processed over $1 trillion in transactions, leveraging that expertise to help you manage, move and maximize your finances. So stop the guesswork and start scaling with the proven choice. Go to bill.com proven to talk with a payments expert and get a $250 gift card as a thank you. That's bill.com proven terms and conditions apply. See Offer page for details.
Alan Rosenstein
It is completely insane to simultaneously say, this product is so important. We're going to force you to give it to us. It's so safe that we're going to use it during an active military engagement, and it's so dangerous that we're going to burn you to the ground.
Benjamin Wittes
It's the lawfare podcast. I'm Benjamin Wittes, editor in chief of lawfare, with lawfare Senior editor and Research Director Alan Rosenstein.
Alan Rosenstein
So it's quite possible that, you know, the people at OpenAI are in good faith assuming that when the government says, oh yeah, according to law and practice and regulation and this DoD guideline, we're not going to autonomous weapons like that, that protects them. And DOD is saying, okay, that's great for us because we can change the guidelines.
Benjamin Wittes
In a live recording on March 2nd, we talked about the Pentagon's designation of AI company anthropic as a supply chain risk. The reaction from Anthropic and other AI companies and the legal challenges the designation is surely going to face. I am here with lawfare Senior editor Alan Rosenstein, professor at the University of Minnesota Law School and sudden expert on procurement law. Alan, how did you spend your weekend
Alan Rosenstein
reading a lot of procurement law? I just have to say the nature of expertise is really relative. I really always think of the, of the, in the land of the blind, the one eyed man is, is king. And so I spent a fun weekend going from 0 to 60, at least 45. Yeah, I would say you're, you're.
Benjamin Wittes
So what caused you to do a crash course in Defense Department procurement law?
Alan Rosenstein
So there's this, there's this little company that some of us may have heard of called Anthropic, and they make a artificial intelligence systems called Claude. And Anthropic has actually for the last few years been at the front among the major AI labs of working with the government in particular on military and classified systems. And actually last summer, the company signed a deal with Pentagon to increase the Pentagon's usage of those systems again on its classified networks and for military purposes. As part of that contract, Anthropic had a couple of what are now being called red lines, primarily that its systems would not be used for mass surveillance of Americans, and also that its systems would not be used for fully autonomous military operations. At the time, the Defense Department clearly was okay with that. But in January, Secretary of Defense Pete Hegseth put out a memorandum on the military's use of AI and in that he demanded or he set the policy that the military would only allow AI contracts where those contracts permitted, quote, all lawful uses of those systems. So basically, he got tired of companies imposing sort of additional restrictions on the use of their systems beyond what was kind of required or permitted under U.S. law. That plus the use of Claude or the reported use of Claude in the operation to capture the Venezuelan President Nicolas Maduro, and some reports that maybe some folks at Anthropic asked some questions about that clearly caused some alarm bells to go off in the Pentagon. And over the last two weeks, we've seen increasingly tense kind of growing standoff between the Defense Department that has been pushing Anthropic to remove usage restrictions from his contract and Anthropic that has been willing to play ball somewhat, but has these couple of red lines. In the last week, Hegseth threatened to invoke this law called the Defense Production act, which would have potentially required Anthropic to provide Claude without the restrictions. But in the end, what ended up happening was that on Friday, President Trump wrote a truth social post banning Anthropic's use on any government systems. And then soon after, Hegseth put out a post on X purporting to designate Anthropic as a, quote, supply chain risk. We'll get into, I'm sure, what that means in detail, but in particular, banning any, not only Anthropic from government contracts, from DoD contracts, but banning, and this is the key, any business that does government contracts from itself doing any business with Anthropic.
Benjamin Wittes
So it's kind of like a secondary boycott.
Alan Rosenstein
Exactly. I mean, it's a sanction. It's essentially a sanctions regime against Anthropic. And the reason this is so important is not only does Anthropic really rely on its enterprise customers, many of which also do business with the government, but two of Anthropic's main cloud compute providers, Amazon and Google, are themselves defense contractors. So if Heath's designation is read to its utmost, it's effectively a death sentence for Anthropic because Anthropic loses its capacity for compute. So Anthropic has said that it will. There's a little bit of confusion right now whether or not Hegseth has formally designated Anthropic or he's about to designate Anthropic. Unsurprisingly, the process in DoD has not been great on this. But at the very least, in response, Anthropic put out a statement saying that it would sue in court against any supply chain designation. So where we are right now is I think we're waiting for the formal designation to come in and then for Anthropic to, you know, run to the nearest courthouse and sue to enjoying that designation.
Benjamin Wittes
All right, so first of all, memo to Anthropic Please sue. In the District of Columbia, it would be much more convenient for lawfare than,
Alan Rosenstein
you know, cut down on airfare costs for our reporters.
Benjamin Wittes
You know, we already have Anna Bauer flying all over the country to Tennessee, to Florida, Florida to Georgia. Don't bring California into this. All right, so before we get into the details of the law, I want to try to isolate what this is really about, because Pete Hegseth knew we were about to attack Iran when he did this on Friday, right? This happens Friday evening. The by the time we all wake up on Saturday morning, we are at war with Iran. This. So he surprised. He made a conscious decision. And Trump made a conscious decision, let's go to war with an American defense contractor the day before we go to war with a significant foreign adversary. Uh, so they must have cared about this a lot for some reason, and yet they have made clear that they don't engage in mass surveillance of Americans and they don't aspire to have they even issued a statement over the weekend that they're not building any fully autonomous weapons. So is this just a chest thumping we're going to beat up on you and make you do what we want to do for the symbolism of it, or do you think there is something the Defense Department actually wants to do that Anthropic does not want Claude to help with?
Alan Rosenstein
So that is an excellent question. So let me first say, I think in this administration in particular, you can never rule out personality driven decision making, which is obviously kind of unsatisfying from, like a legal and policy analysis. You know, like, we all are used to administrations where, you know, good people, bad people, whatever. They're fundamentally rational actors. We can kind of game out what they're doing. This is just not the case for this administration. So it would not surprise me at all if a lot of this is driven. You said ideology. I'd maybe just say peak. Like they just got pissed off because, you know, some, you know, nerd with, you know, curly hair from San Francisco is purporting to tell, you know, secretary, quote, unquote, of war, Pete Hegseth, how to use his war fighters. And, you know, just as Donald Trump once bragged that the way he set Switzerland tariffs is that after he set them, the Swiss prime minister called him and complained. And because, quote, I didn't like her tone, I just doubled them instead of lowering them. And to be clear, he was bragging that this is how he sets tariff policy. I really think that. And this is a family show, so I won't use the analogy I want to use. But I really think there's an element of. I'd like to show you that my stick is bigger than your stick, and maybe that is for some rational purpose down the line. But I think a lot of it is because I just want to show it to you, because domination and this kind of symbolic politics is how these people think. Right. And it seems kind of crazy to potentially threaten the very foundation of American AI. And we'll talk about why I think that is part of this based on chest thumping. But, I mean, we just want to warn around for reasons I don't fully understand. I mean, this is with. Well within the realm of possibility. So I think there's a lot of this that might be that. But I do think there also may be substantive issues here. I think there is an ideological component here that the military does not want its contractors to be telling it how to use its tools and how to set military policy. Right. That if we're going to have a military industrial complex, it's the military side, not the industrial side that should be running it. And I should be clear, I am actually very sympathetic to that position. And I think it's important, even as we're analyzing this sort of shambolic policy that Pexeth is implementing right now, to try to abstract a little bit from the personalities involved and say, okay, but what should the overall relationship be between the military and AI? And I think there's actually quite defensible that it's the military that should ultimately make those decisions. Now, that's separate from, okay, what should the military do if a company doesn't want to play ball? But I think there's an ideological component here, and I think that's one worth taking very seriously. And then finally, it may be the case that. That the military is trying to build autonomous weapons and do some surveillance that anthropic would be less comfortable with. Now, the military is saying it's not doing that, but a lot of this depends on, you know, how you define fully autonomous and how you define unlawful surveillance. And, you know, I don't have to tell you, Ben, that like, depending on how you squint, you can. You can call things mass surveillance or not. And so obviously, the military does a huge amount of surveillance. The NSA is part of the military, and a lot of it's lawful. And so maybe they. They don't just. They never want to put themselves in the position of having to call Dario Amade and ask for permission.
Benjamin Wittes
Right. Although I. I mean, I do think that the. That software Vendors and software as a service vendors are different from other vendors. It's not like, you know, you buy an F16 from whoever makes the F16, Lockheed, and then you decide how to use it. As a military, whenever you're buying software, you're actually buying a license to use software, not the software itself. And that always comes with a long click through agreement. That is the company's terms. Right. And so why is this any different from Microsoft saying, you know, and you can't use it to do X, Y or Microsoft Word to use X, Y
Alan Rosenstein
or Z. Yeah, so it's a fair point. And the idea that is going on sort of run is circulating at least, you know, some parts of the Internet that it's totally unprecedented for a company like Anthropic to try to impose conditions. That's just not true. Conditions are imposed all the time. That's totally standard. Now the question is what is the nature of those conditions? So I don't, I have not read like the master services agreement between Microsoft and in the military, I'd be very surprised if it said you can't use Microsoft Word to plan an invasion of Iran or something like that. I mean maybe it says that you
Benjamin Wittes
can, you can only use Google Docs for.
Alan Rosenstein
Exactly, exactly, exactly. Good, good luck with that. So I think the real question, but look, I think the real question is not, you know, is this legitimate or not. It's, it's in this particular case, does the government want to abide by these restrictions? The company has every right to insist on them and the government has every right to say no, thank you. Right. And like if we were civilized people, we would just shake hands and this would not be a story.
Benjamin Wittes
And so this would, the way this would resolve is presumably if we were civilized people, the government has some kind of exit term from the contract or it simply doesn't renew the contract when it comes back up.
Alan Rosenstein
Exactly.
Benjamin Wittes
And it chooses not to do business with Anthropic because the terms are not adequate.
Alan Rosenstein
Yeah. And then it's, you know, it's a 24 hour story. Kind of interesting, you know, and then we move on with life.
Benjamin Wittes
All right, so the government doesn't do that. Instead it designates it as a supply chain risk. Let's pause here and say everybody was expecting them to do something under the Defense Production Act. What could they have done under the Defense Production Act?
Alan Rosenstein
Yeah, yeah. And I will say I was quite surprised by, by this. I did not have on my bingo card that I'd be spending the whole weekend studying supply chain Risk because it seems so outlandish. But here we are. So under the Defense Production act, which is a law, which is a Korean War era statute passed largely to kind of regularize what had been done in World War II, where the entire kind of economy became a military economy under some combination of cooperation and cajoling from fdr. Right. The. Our first. You can just do things. President. The government can require companies to fast track government contracts. That's the most straightforward thing. But in addition to that, it can require companies to enter into contracts with the government to sell the government standard commercial goods and services. And on a particularly extreme reading of the Defense Production act, that has not been tested in court, so there's some question about that, to even produce new products for the government. And although the Defense Production act is quite old, it's actually been renewed something like 51 times. It has very short sunset clause. And at some point, I think 10 or 20 years ago, Congress explicitly included, you know, software and high technology as part of it.
Benjamin Wittes
So the, the Defense Production act really is just a, if we need a command economy situation, a, the government can do it, it can compel you to produce stuff, and B, it's gotta pay you for it.
Alan Rosenstein
Yes. And I should say the extent to which it can, you know, force a company to produce wholly new things is. That's somewhat unclear. But the text is certainly very, very broad. And my thought was that if the government wanted to require anthropic, at the very least to provide clawed right like the current system, but under different contractual terms, it could do that pretty easily. And while I wasn't a fan of that as a policy matter, I thought the government would have a pretty good legal case. So naively I thought that that's what the government would. Would do. That is not what the government chose to do.
Benjamin Wittes
All right, so what the government chose to do, I want to just assert this is closely analogous to what it did to Harvard University, what it did to law firms. Right. Which is to say you have asserted your rights in this case, rights under a contract in the case of Harvard and law firms and npr, First Amendment rights that we don't like. So we are going to take retaliatory action against you using, in this case, not money, which is what they did with the, with Harvard, but using our ability to prevent other entities from doing business with you, prevent you from contracting
Alan Rosenstein
with the government, which is to say money.
Benjamin Wittes
Right. But it's not a direct, it's a little bit more indirect, except in the government contracting sense. My instinct, looking at this is that, first of all, as a normative evaluation matter, we should be exactly as skeptical of it as we are with Harvard or the law firms or npr. And secondly, we need to interrogate, which is the point of your article, the legal basis for the actions that they're taking. So let's, let's take the easy one first. Is there any reason to think of this in a different framework from the Harvard action or the law firm's action?
Alan Rosenstein
No, but I might zoom in just a little bit because I actually think. And again, it's been a while since I really dug into like the exact details of the Harvard and law firm stuff. I think this is actually more like the law firms than it is like the Harvard action. Because I, if I understand the, the main Harvard issue was the withdrawal of federal funds. I mean, I guess, I guess that's not true as I think about it, because I think Harvard also was banned from ha. From getting foreign students, which is actually a little bit more like what's happening here. But, but the point I'm trying to make is this isn't just withdrawal of funds, right? This is, this is essentially kind of Persona non grata ing of an entity. Right? And for Harvard, that was done by restricting international students. For the law firms, it was done, you know, actually very similarly to what's happening now. And yes, I think this is the right way of thinking about what is happening. Right. It's almost sanctions regime attempt against some domestic company, which is wild.
Benjamin Wittes
All right, so what authority does the government have to. Let's start with the one where their authority should be stronger. Point at a company and say you're a supply chain risk and nobody in the government is allowed to do business with you. Let's hold aside for a minute. The secondary sanctions issue. Government decides it doesn't like Alan Rosenstein Inc. President issues tweet or a truth social post that says no government agency can do business with Alan Rosenstein Inc. Because he's a supply chain risk. What authority do they have to do that?
Alan Rosenstein
Well, first, Benjamin, you have to promise that you'll frame that for me for my office.
Benjamin Wittes
I will frame it for you.
Alan Rosenstein
Thank you. Thank you. So there are two statutes, both from the 2010s. One is the Federal Acquisition Supply Chain Security Act, FASCSA, which is very hard to say.
Benjamin Wittes
Yeah, it's bad acronym.
Alan Rosenstein
It's very bad acronym. And the other is the statute 10 U.S.C. 3252, which was initially enacted as part of the 2011 National Defense Authorization act and then was made permanent in the 2018 National Defense Authorization Act. I mention them both because although it seems that the government is acting under section 3252, they're still both useful to think about because I think they express kind of how Congress was thinking about the issue of supply chain risk at a certain time in the 2010s. They did enact two somewhat different statutes, but I think you can sort of read them together. And that's important because the language of both statutes is reasonably broad. But you have to understand the context here. But let me just focus on 3252, which is, which is what we all think the government is acting under. It's certainly what Anthropic thinks the government is acting under. It's what other knowledgeable people think the government is acting under. And the reason is that while the FASCSA requires like an interagency process and 30 days notice and like a whole thing, it's a more regulatory statute. That's really not what's happening here. 3252. This other statute basically allows the Secretary of Defense, essentially on his own authority, to basically find that a particular supplier is a supply chain risk and then immediately exclude that supplier from government contracts for, quote, unquote, covered systems, basically national security products.
Benjamin Wittes
Now, I want to pause you right there, because when you say it's something as a supply chain risk, it does not sound to me like you can say out of one side of your mouth, give this to me on the terms that I want, or out of the other side of your mouth, you are a supply chain risk. That feels a little bit like, I don't know, the food here is terrible in such small portions. Right? I mean.
Alan Rosenstein
Yeah. Yes. I mean, let me try to steel man that argument because I can imagine, here's what I can imagine, a doj, you know, federal programs attorney saying in court when the judge quotes Annie hall to this effect, well, look, we think that under the current contract term regime, the use of anthropic is intolerable. And the very idea that we'd have to call Dario Amadei for permission. Right. Even that's a possibility is totally intolerable. But if you remove the contract risk, suddenly, it's not a problem anymore. Look, I'm just saying if you had to speak out of both sides of your mouth, that is what you would say.
Benjamin Wittes
But what's the language of the statute? I mean, if the, if the Secretary of Defense finds that what about a product that the terms at which it's being Provide the contractual terms are intolerable.
Alan Rosenstein
No, that, that, that this supplier, you know, is an adversary whose products will, quote, sabotage, subvert or malicious. Maliciously introduce unwanted function. I'm not saying it's a good argument, Ben.
Benjamin Wittes
Yeah, it seems.
Alan Rosenstein
I'm just saying it seems like that
Benjamin Wittes
is not like we negotiated a contract that in retrospect we regret and we don't want to wait until the contractual terms are up to renegotiate it. And we don't like Dariel Amadeh's hair.
Alan Rosenstein
Look, I'm trying to play along here, but as our esteemed lawfare colleague Anna Bauer likes to put it, we live in the dumbest of all possible timelines. Yes, of course it is completely insane to simultaneously say we, this product is so important, we're going to force you to give it to us. It's so safe that we're going to use it during an active military engagement. And it's so dangerous that we're going to burn you to the ground. Yeah, you can't have all. Obviously you can't have all three of those at the same time. Right.
Benjamin Wittes
It just seems like that dog won't hunt.
Alan Rosenstein
It's bad. It's bad, man.
Benjamin Wittes
All right, so on we go. What is Anthropic's argument going to look like that this is, I mean, beyond what I just said, that this does not cover. I mean, it sounds to me, just listening to the statute that it's like directed at Kaspersky or that it's directed at some foreign entity that wants. That you want to keep the US supply chain pure of not an American existing defense contractor that you have a contract dispute with. Am I overstating it?
Alan Rosenstein
I mean, funnily enough, I, along with the fabulous Howard University law student Michael Andreas, published earlier today three and a half thousand word analysis of all the things Anthropic I expect will say when it sues. This is a, how do we say, a target rich environment. Every layer of this is just a disaster for the government.
Benjamin Wittes
Right. So give us an overview of the this. Before we get to the secondary sanctions problem, what are the major arguments that are available to Anthropic?
Alan Rosenstein
Well, the first argument is that it's not actually clear that this law can even in principle apply to a US company like Anthropic. Now it is true that the law, let's be fair here, the text of the law does not single out foreign companies. This is not one of those laws. But when you, for example, read the legislative history of this law, of this particular law, it's all about the threats of from globalization to supply chains. But Trappica of course, is headquartered in a lovely office building in San Francisco. When you look at the other law, the FASCSA law, and again, they're different laws, but I think they're getting at the same thing. That law, the legit of history, is all about Kaspersky, Huawei and zte. And then when you look at, I think another thing that is worth mentioning is whereas FASCSA actually allow. Gives the targeted company some procedural protections, a 30 days notice, some D.C. circuit review, the 3252 provides essentially no procedural protections. Now that's fine, it doesn't have to provide procedural protections. But given that FASCSA clearly basically only applies to foreign companies, it'd be very weird if a law that applies to domestic companies provided less protections than a law that applied particularly to foreign companies. Right. That's the exact opposite of what you would think because of course domestic companies have due process rights. No one is owed a government contract, but they are definitely owed some notice and an opportunity to be heard and something reasonable if the government is going to suddenly cancel contracts and especially impose a secondary boycott. So it's just not at all clear that as a threshold matter any of this applies. And the reason that's important is because courts are generally, and I think rightly so, loathe to really second guess the specific national security determinations of the executive branch. So it's a much stronger argument for anthropic to go in and say it's not that we're not a supply chain risk though. I think they can win that argument. This just doesn't apply to us. This is a classic example, it's called ultravirus action, where the government is just, it's invoking a law that just does not apply to the situation. So I think that's just a primary argument. A primary argument here. Right. But it is also the case that a court, I think will be able to, you know, under the Administrative Procedures act, review the actual determination for being, quote, arbitrary and capricious. And here I think, Benjamin, the exact point we were just talking about of,
Benjamin Wittes
again, you can't simultaneously post the definition of arbitrary.
Alan Rosenstein
What was the definition? Yeah, yeah. I mean, I may literally use this to teach the concept next year when I teach administrative law and then add
Benjamin Wittes
to it that they've delayed enforcement for six months. So it's like it's so dangerous that it poses a supply chain risk. So six months from now we're going to stop using it and ban everybody else from using it.
Alan Rosenstein
Exactly. And then finally there are concerns about pretext here. And the pretext comes in sort of two flavors. One is that when you look at the public statements that SecDef, Hegseth and President Trump have made, they are not exactly sort of sober minded. We have analyzed anthropic and we have decided that, you know, on points one, two and three. No, no, no, it's all about how Anthra, you know, Trump says anthropic is radical left, woke something something and Hegseth insults it a bunch of times. It's pretty clear that like, they don't like anthropic, they don't like amade, they don't like, I don't know, whatever ambient leftism that they are imputing to anthropic, which I actually don't think is accurate, but kind of besides the point. So. So there's a pretext concern there. There's another pretext concern which is going to get us to kind of an equally interesting sort of side quest. Maybe we could talk about this later in the conversation about OpenAI, because just to preview very briefly, we're going to
Benjamin Wittes
get to OpenAI and rock momentarily right
Alan Rosenstein
on the, I think very day or something. Or like basically simultaneously, as Hegseth is setting fire to Anthropic, he's also signing an agreement with OpenAI that. And this is where it gets very bizarre, that OpenAI claims is actually as if not more restrictive than the anthropic than what Anthropic wanted. Now we're going to get in a few minutes to whether that's true or not, but let's assume it's true. Well then, now I'm utterly confused because how could it be that anthropic is such a dangerous supply chain risk if OpenAI, which is bragging about how it's going to forward Deploy engineers in DoD and impose all the safety stack stuff and is going to have all these red lines. That's not a supply chain risk. The math does not math. And again, and we haven't gotten to the secondary boycott issue yet.
Benjamin Wittes
Hey folks, I want to tell you a story about the founding of Lawfare. I started Lawfare and it was just a blog. And then we realized we had to create an organization to support it. And all of a sudden I found myself doing paperwork, forms, logistics, personnel stuff. It just completely ate up my day. And I want to say I was bad at it. And it was repetitive, it was boring. And I thought to myself, there has to be an easier Way to do this. I didn't know about Gusto at the time, and in retrospect, I wish we had. Small business life means hustling and figuring it all out a lot of times on your own, and I did it a lot of times on my own, and it was bad. But you don't have to make the same mistakes I did. You don't have to spend your evenings guessing at tax forms or tracking down onboarding documents. Gusto handles all of that so that you can spend your time on the parts of your business you actually love. Like in my case, running a magazine about national security and law. That part I love. Gusto is an online payroll and benefit software system built for small businesses. It's all in one remote, friendly, and incredibly easy to use so that you can pay, hire onboard and support your team from anywhere. You save time with automated tools that are built right into the system. Offer letters, onboarding materials, direct deposit, and more. It's automatic payroll tax filing, simple direct deposits, health benefits, commuter benefits, workman's comp, 401k, you name it. Gusto makes it simple and has options for nearly every budget. It's quick and simple to switch to Gusto. Just transfer your existing data to get up and running fast. Plus, don't pay a century until you run your first payroll. So try gusto today@gusto.com lawfare and get three months free when you run your first payroll. That's three months free payroll@gusto.com lawfair one more time. Gusto.com lawfare DeleteMe makes it easy, quick and safe to remove your personal data online at a time when surveillance and data breaches are common enough to make everyone vulnerable. Delete Me sends you regular personalized reports showing what information they found about you, where they found it and what they removed. It isn't just a one time service. It's always working for you, constantly monitoring and removing the personal information you don't want on the Internet. Let me give you a personal example of that. I first learned about Deleteme. This was considerably before they were an advertiser for Lawfare. And I learned about it at a conference of democracy activists where, you know, we were talking about what to do to reduce risk. If you're working in this field, people said, you need to have delete me. And so I went out and got it, and I got it from members of my family and I got the first report and there were, you know, 20 some odd data brokers who they had removed my data from. But then here's the key thing. The data brokers go back to work collecting on you. And so a few months later, you get another report. And these same data brokers, they're removing you from their sites again because Delete Me keeps at it. The New York Times wirecutter has named Deleteme their top pick for data removal services. And you know, if you're somebody with an active online presence, you probably know that if you're going to protect your privacy, nobody's going to do it for you. You've got to do it yourself. This is a step that you can take. But if you're not somebody with an active online presence, they're still getting data about you. They're still using it to facilitate phishing attacks on you, to facilitate identity theft. And if you've never been the victim of one of these things, you probably know somebody who have, and it's probably only a matter of time before it happens to you. Delete Me can help. So take control of your data and keep your private life private by signing up for Delete Me now at a special discount for our listeners. Get 20% off your Delete Me plan when you go to JoinDeleteMe.com Lawfare20 and use the promo code Lawfare20 at checkout. The only way to get 20% off is to go to join Delete Me.com Lawfare20 and enter code Lawfare20 at checkout. That's JoinDeleteMe.com Lawfare 20 code Lawfare20. Want to change the efficiency gain AI
Alan Rosenstein
it automate tedious tasks to spend more time on the future. Transform the everyday with Siemens.
Benjamin Wittes
When it comes to managing money, forget the hype and look at the results. Bill has a trillion dollars of secure payments powering our bill pay tools Instead of just moving money, Bill is powering the financial operations of nearly half a million customers. So stop the guesswork and start scaling with the proven choice. Ready to talk with an expert? Visit bill.comproven to get started and grab a $250 gift card as a thank you. Terms and conditions apply. See offer page for details.
Alan Rosenstein
Ryan Reynolds here from Mint Mobile. I don't know if you knew this, but anyone can get the same Premium Wireless for $15 a month plan that I've been enjoying. It's not just for celebrities, so do like I did and have one of your assistant's assistants switch you to Mint Mobile today. I'm told it's super easy to do@mintmobile.com Switch upfront payment of $45 for 3 month plan equivalent to $15 per month required intro rate, first 3 months only, then full price plan options available, taxes and fees, extra fee, full terms@mint mobile.com
Benjamin Wittes
so let's get to the secondary boycott thing. Let's imagine we were dealing with Kaspersky.
Alan Rosenstein
Yeah.
Benjamin Wittes
And we were dealing with something that was generally understood to be a legit supply chain risk. Again, not making any comments about Kaspersky, but that's how it's understood, rightly or wrongly. So imagine that SecDef Hegseth had said, all right, any company that does business with Kaspersky, even if it's insulated from its business with the Defense Department, can't do business with the Defense department. Does the SecDef have the authority to do that?
Alan Rosenstein
He almost certainly does not. So what the SecDev does have the authority to do, and this makes sense, is he is allowed to say, Kaspersky, you're a supply chain risk. You can't sell your products to us. And also anyone who is building a national security product for us cannot use Kaspersky as part of that product. Right. And maybe you could even make the following argument that like the nature of Kaspersky or the nature of a model like Anthropic of Claude is such that you can't kind of isolate those from the business. So if you use it anywhere, you can't sell us a product. Maybe you could make that argument that'd be more fact specific. But what you definitely cannot do is say, and also you can't do any business with Kaspersky. Like you can't provide financial processing to Kaspersky. Right. There's nothing in the statute that allows
Benjamin Wittes
statutes that give you the authority, like iipa, which does not allow you to impose tariffs, but does allow you to designate an entity and say you're not allowed to do business with that entity.
Alan Rosenstein
Well, it gets even better because this issue has come up. So in the 2019 National Defense Authorization act there's a section 889 for, you know, open your hymnals to page to section 889 for those following along. And there Congress basically imposed a full on secondary boycott Congress of Huawei, of I think Huawei and zte, right, the two Chinese telecommunications firms. So in that situation, Congress said anyone who uses Huawei and ZTE anywhere in their systems, right. In a substantial way cannot do business with the government. Now interestingly, even that did not go as far as what Hegseth is purporting to do. Because remember what Hegseth was purporting to do. Right. At least based on his. His X posts, which apparently is how we do national security policy now is prevent, let's say cloud compute providers from. From selling compute to anthropic. Right. That's actually even beyond what Congress did in this section. So again, all of this is very strong. And by the way, we haven't even got. You mentioned IPA and you mentioned the tariff case. We haven't even gotten to the sort of brooding omnipresence in the sky that is the major questions doctrine. Thank you. Thank you. The idea that, you know, especially these days with a somewhat conservative Supreme Court, we don't read in really dramatic grants of policymaking authority to the executive branch that are unclear. And again, you know, burning American Frontier AI company to the ground because you don't like how they contracted with you. That's a pretty major question. Right.
Benjamin Wittes
And we know from the tariffs case that the major questions doctrine now does apply to presidential action and to national security actions purporting to be in the national security space, which was a bit of a question prior to last week.
Alan Rosenstein
Yeah.
Benjamin Wittes
All right, so let's talk about OpenAI and Elon Musk, because we have two different reactions to this demand from Hegseth from these two. Elon Musk says GROK will absolutely do anything the government wants it to do. And OpenAI says it has a contract that's more restrictive than the one that Anthropic is in trouble for. So what do we actually know about OpenAI's actual contract? And do we know that there are real restrictions in it?
Alan Rosenstein
Yeah. Well, let me just say one thing about Grok for a second. Not super surprising that this is Elon Musk's position. I think, you know, putting aside my feelings about Elon Musk, it is a perfectly coherent position. I will say it is worth, again, to everyone involved, please try to think more than six months ahead because, you know, the no party is in power forever. And again, you want to be careful about the precedents you set. Right. So, you know, just. Just as. Just as every Democrat should always think about what happens when Trump and J.D. vance are in power, every Republican should think about what happens when President Newsom or President AOC are in power. Right.
Benjamin Wittes
Or when Hakeem Jeffries is Speaker of the House.
Alan Rosenstein
Or even. Or even then. Yes, exactly. Right. So I'll just leave that there. The real question is OpenAI. So this I find to be one of the most bizarre scenarios I have ever witnessed in my time studying AI policy. Because you have this contract that OpenAI has signed with the government. Now, OpenAI has released several important provisions from that contract. Okay, they did this in a blog post. Those provisions, I think pretty clearly, and this is the essentially near unanimous consensus of, like, all the law types that are engaged on this issue, at least on X, does not impose meaningful red lines. It just does not. Because essentially what it says is you will not use our systems for autonomous weapons where such use is banned under law, policy or practice. Okay, but. And even if today it is banned under law, policy or practice, which I'm not at all clear, it is what happens when tomorrow it's not banned. That's not a red line. That's just restating all lawful uses. Similarly, you will not use our tools for mass surveillance where that is banned by the Fourth Amendment and FISA and 12 333. Okay, okay. But a ton of mass surveillance, as normal people understand it, is perfectly legal under the Fourth Amendment, FISA and 12 triple three. Right. Again, let's have a. We can. Let's have a totally separate conversation one day about whether we should have AI mass surveillance and how. Right? That's not the question. The question is just what did OpenAI agree to? Okay.
Benjamin Wittes
And the terms of the contract are not public, I take it.
Alan Rosenstein
Well, not the whole contract, just these paragraphs are. So OpenAI releases this, and everyone, including myself, but not at all, not just me, starts pointing out like, guys, this. What is happening here, These are not red lines. So then Sam Altman, and I'm going into, I'm going into detail here because I really want to emphasize how important for, like, the future of technology and the American democratic experiment is that we get AI right. And this, this, this situation is not providing with a lot of confidence. Sam Altman says here we're doing ask me anything on X, ask me questions. And I'm gonna have some of my senior people, my, like, national security person and some engineers come and join. And it just gets worse and worse from there on in because people start asking politely, these are not red lines. And then you. What you're getting is responses saying, oh, no, you know, there are other parts of the contract that actually fix the nature of the law at the time we signed it. So DoD can't change its mind. But we're not going to. We're not releasing that part of the contract. And we're not. But I don't know why we're not releasing that part of the contract. So just from a comms perspective, I think this is honestly kind of a disaster. I mean, no one needs to take my comms advice, but reputation matters here, and I am afraid. And look, I should say I know a lot of people at OpenAI, I respect a lot of people at OpenAI, but I will say OpenAI do not think is covering itself in glory in terms of pushing back against what has always been its reputation, whether fair or not. That it's a little bit of a shady, A little bit. A little of a, you know, talk out of both ends of your mouth. Actors. That's not great. The. The real, Obviously, the comms issue is whatever. The real question is, well, what did OpenAI agree to? And there seems to be three possibilities, and I. I honestly cannot tell you which one, which one it is. Right. One possibility is that OpenAI has in fact gotten the red lines Anthropic wanted, and there's some other part of the contract that will clarify that that's possible. Now, that then raises the question of why are we trying to burn anthropic to the ground then?
Benjamin Wittes
Right?
Alan Rosenstein
But whatever. That's not OpenAI's problem. That's possibility number one. Possibility number two is OpenAI is just lying, right? These are not real red lines.
Benjamin Wittes
I'm playing two cubed by half.
Alan Rosenstein
No, no, no. But, yeah, yeah, or whatever, but that. These are. These are not red lines. OpenAI lawyered this very carefully so as to give it wiggle room, and it's hoping no one notices or third, and I think this actually, I don't know, but this might be what's going on. And this is maybe even scarier. OpenAI thinks it has red lines, but the DoD does not think it has red lines. And this happens all the time, Right. You know, very frequently in contract drafting, you just don't have what's called the meeting of the minds. Right? People think it's.
Benjamin Wittes
It's.
Alan Rosenstein
It's different. Right? And so it's quite possible that, you know, the people at OpenAI are in good faith, assuming that when the government says, oh, yeah, according to law and practice and regulation and this DoD guideline, we're not gonna autonomous weapons like that, that protects them. And DOD is saying, okay, that's great for us because we can change the guidelines. But it's completely unclear which of those three it is, which is kind of maddening.
Benjamin Wittes
Let's. Let's play a little inside baseball here, which is that OpenAI's counsel are serious national security lawyers, including former colleagues of yours at nsd, people who know their way around terms like mass surveillance, and it seems to me hard to believe that you could have a loophole here big enough to drive a DOD sized drone through. And that not be apparent to the legal team that negotiated this contract for OpenAI?
Alan Rosenstein
I mean, that, that, yes, that seems to me to be the most likely answer. Right?
Benjamin Wittes
You think, you think that's more likely than that they negotiated something that allows them to say they have the red line and allows everybody to know that they don't really, but it allows them to say it. But whether you call that lying or whether you call it spinning, or whether you call it.
Alan Rosenstein
But, but, but I, but I thought that's the same. Isn't that just what you said? Right? You have these brilliant lawyers inside OpenAI. They have access to the best lawyers in the universe.
Benjamin Wittes
No, no, but what they're saying publicly and what they're advising the client could be quite different. What they're advising the client is what? Look, you go say whatever you want about this contract and its red lines, but these red lines are not enforceable under the terms of the contract. And at the end of the day, DoD is going to type, hey ChatGPT, can you loose the fully autonomous drone against the robo dog of war and have it make decisions about who to kill? And there's nothing in the contract that will stop that as long as that is legal under U.S. law at the time.
Alan Rosenstein
Look, based on what I've seen of the contract, that seems to me the most likely outcome. The reason that I'm hesitating to say that is because it raises real questions and honestly disturbing questions about the candor of OpenAI's public statements. And, you know, given that OpenAI has for years talked a very big game about, you know, how dangerous artificial intelligence is and how important it is to be a good steward of this. It's not, it's not. I would, look, I would much rather if it's going to go down the route of X or, you know, Palantir or Anduril or whatever, just to say so, right? Just, just say so and then we can have that debate. Right, but, but, but I, I, I really, I, I, I cannot emphasize enough how big of, I think a reputational disaster this is. And look, I don't think who, who, they don't need to care what I think. Right? But I will just say, in Silicon Valley, the only thing that's more valuable than compute is talent. Right? Getting the best engineer is, you know, possibly a billion dollar or ten billion dollar asset. You know, that's why Meta is paying these people $100 million, right? To come Over. A lot of these engineers are motivated by money. They're humans. But a lot of these engineers are also motivated by wanting to do the right thing. And so I just, I, you know, if I were OpenAI, I would really worry that my reputation, atop all the other stuff that's been happening, is going to be very seriously and durably harmed in this very, very small community of, you know, elite AI engineers in, in. In. In San Francisco. And, and the fact that they have not resolved this is, I find puzzling.
Benjamin Wittes
All right, so I want to go back to a point that you made in an earlier piece that you wrote, which was, leave aside the merits of this dispute. This is a truly horrible way to make the rules under which the US Industry are going to interact with the Defense Department over major policy questions. And so I want you to flesh that out, because it's kind of laying in the background of a lot of what we're talking about. But what should be the mechanism by which we decide as a society whether anthropic should or should not have its product used for, you know, autonomous weapons and for mass surveillance? Why is contract dispute not the right answer to that question?
Alan Rosenstein
Yeah, And I should say, I mean, contract dispute is the right answer of how you operationalize it. It's just a weird vehicle to set the substantive principles. Let me separate your question into a kind of a substantive component and a procedural component. So the substantive component is that. And this is, you know, as much as it is to, like, as much fun as it is to sit and, like, mock Pete Hegseth's incompetence, I think it is useful to try to zoom out a little bit and kind of think about this issue in the broader context. The way I view this is that this is the opening shot in what will be by far the most important AI regulation question of the next several years, which is, to what extent will we nationalize the AI industry? Okay. It was never going to be realistic. And people who have thought about AI for much longer than I have, I think have understood this, that the government, which is to say the people, through their elected representatives and bureaucrats, were going to sit in D.C. and twiddle their thumbs and go, oh, how interesting. While a very small group of people in San Francisco were going to build the machine, God, that was just never going to be realistic. Right. And so we as a society are going to have to figure out one way or the other how much control we're going to have over these companies. Right. And all the regulations about, you know, privacy and this and that and labor and copyright. They're important, but I think they pale in comparison to this more foundational question,
Benjamin Wittes
can it kill you?
Alan Rosenstein
Well, but also just at the end of the day, how much are we going to say this is a cool product made by the private sector versus this is like an epochal transformation in human civilization and therefore we're going to have to control it? A little more invasive. Right.
Benjamin Wittes
But my point is it's not an accident that we confront that question, that we don't confront that question ultimately over will it discriminate against you? Can it spy, you know, can it judge you for real estate transactions? Can it make, right, all these kind of consumer protectiony things where the rubber hits the road and the Defense Department says, no, we're in charge of this. And the AI people say, no, we are. Is when it comes down to can it kill you?
Alan Rosenstein
Yes. Killer robots have a fabulous way of focusing the mind.
Benjamin Wittes
Concentrating the mind.
Alan Rosenstein
Concentrating the mind. Okay, this is a legitimately difficult question, right? And we'll be thinking and writing about this for a long time. But that's one question. Then there's a separate question, okay, whatever the answer to that question is, who's going to determine that? Right. Right now this is being determined in, like, not a great way, right? Through a very unpleasant contract dispute between, you know, a. Not the best secretary of Defense that you could imagine, right? And the CEO of a company. Now, look, I'll be honest. I like Anthropic. You know, I know some people there. I've met some of the co founders. I've never met Dario, but he seems like a really thoughtful and interesting guy. If someone's going to build the machine, God, I can imagine worse people to do it than Anthropic. But look, I didn't vote for, like, Grok. Like Grok, right? But look, I didn't vote for any of these people, right? I'm not comfortable with them setting broad societal policy. Right? But I'm also not comfortable with, like, the current, you know, people in the Pentagon and the White House doing it either, because they're not great. No. We do have an institution that is supposed to do this. It is called the United States Congress. And, you know, just saying that phrase should fill everyone with a certain degree of existential dread and malaise. But at the end of the day, like, this is going to be. This is. Put it this way, this is not going to be how this is going to be decided. Who knows how this is going to be decided? But under any rational system, this Congress would be the one who would decide it. Right? It would be Congress that would say, hey, here's how dod, you can and cannot use autonomous weapons. Here's how you can and cannot do surveillance. Here is the ongoing oversight that the, you know, Arab Services committees and the Intelligence Committees are going to do. And I would imagine that had Congress done that or had Congress even shown any sign that it will do this in some rational way over the next few years, someone like Dario Amadei would feel a lot better about signing onto an all lawful usage policy. Right? Because look, you know, as, as, as much as Anthropic is often criticized for a, you know, kind of holier than thou, we know it's best. And maybe there's some of that. I actually don't think at the end of the day they want to be the ones doing this. Like, I think they want to go and like cure cancer or something. And they would much rather have the democratic process come to some reasonable resolution that even if they don't agree with in every particular, they can live with. But in the absence of that, this is how we do this. And it's, it's bad.
Benjamin Wittes
All right, let's wrap up with the question of what's going to happen. So we assume at some point there will be a document that translates the Trump Truth Social and the Hegseth statement into some kind of policy or some kind of actually, I mean, have they actually done anything yet or have they merely said they are doing something?
Alan Rosenstein
So it's, it's unclear. So, so there's a Trump Truth Social post that orders just U.S. government agencies to not do business with Anthropic. There's no secondary boycott there. And some agencies are doing that. I think treasury and like, like the, the mortgage, like the housing mortgage agencies are doing that, but they're just doing that like kind of as a Truth Social executive order thing. Maybe that'll be challengeable, but that's kind of separate. Then there's a Hegseth post which was a little confusing because it ordered some undersecretary of Defense to do the designation. But then it said effective immediately, no one could do business with Anthropic, which certainly sounds to me as if Hegseth was purporting to do a designation. Now the law does not require. The law requires Hegseth to make some written findings and to transmit those findings to Congress in classified or unclassified form. It does not, oddly enough, seem to require the executive to tell the company, I think that's gotta be A drafting oversight, because how's the company supposed to know? My understanding is that Anthropic has not yet received a piece of paper, but they're certainly acting as if this is real and they have said explicitly that they will challenge this in court. So let's assume the procedural stuff gets resolved one way or the other. What I would expect is going to happen is that Anthropic will go to court, hopefully on the east coast, not the west coast. But, you know, lawfare travel aside, you should do it in the place where you're supposed to do it. And they'll say, guys, this is really illegal. Here's a lawfare post. Like, here's our brief. It's something. Here's a nice law firm post, right? And I would expect that if they get a remotely within parameters judge, that there will be a. And I should say I'm not a litigator, so I don't know the exact details of how this works, but they'll get a temporary restraining order, they'll get an injunction, they'll get a something or other and this will all drag and this will all kind of pause, at which point there will begin a lot of litigation. I expect that Anthropic will win that litigation for all the reasons we talked about. And I think it's so obvious that they will win that it almost. That I almost wonder if suing the government would almost be de escalatory of Anthropic, because I suspect that what may very well happen, and I say this, I would just note that I think an hour ago the Wall Street Journal reported that the White House or the government has decided not to appeal the injunctions of the law firm punishments that it tried to do a long time ago.
Benjamin Wittes
Withdrawing the appeal.
Alan Rosenstein
Withdrawing the appeals. I suspect something that could happen here where the White House is going to designate them a supply chain risk so that they can beat their chest. This will all get stopped and then everyone will lose interest in this in a few months and maybe even people will kiss and make up. Because as we can see from Anthropic services being used in the war against Iran, these are useful services. Now, from Anthropic's position, I mean, that's obviously a better outcome than them losing the supply chain risk. But it's still very dangerous because Anthropic, although it's absolutely a leader in AI, unlike a company like Google or Meta, let's say, which has kind of an infinite cash machine through advertisements that it can used to sort of shovel money into the money Pit. That is AI. Anthropic is, is just an AI company, Right.
Benjamin Wittes
And it's a very young one.
Alan Rosenstein
And it's a very young one. Right. And so, so it's not like its relationships with its clients are super, super deep. And, and even if it loses a small number of clients who are just scared away by all this noise coming out of the White House, you know, that could meaningfully set its, its AI back. Right. And I'll just note something that Dario Amade said in a podcast. I think this was with Dwarkesh Patel a few weeks ago or last month. You know, he said, I'm very bullish on AI. We're going to get general intelligence. We're going to do all the things, but also if something gets screwed up for 12 months, we could go bankrupt. Right. Which is to say their margins here, which is weird to think of a company that has hundreds of billions of dollars in revenue, but every cent of that gets plowed back into compute and training. So from Anthropic's position, what I think is really scary is not that they lose the lawsuit, but that this does enough damage their enterprise relationships that it, you know, wounds them permanently. I mean, I'm, I'm optimistic. I think they'll get a lot of goodwill as well out of this. The prediction markets seem to not think that Anthropic is going to be severely hurt by this and, you know, take that for what it's worth. But I think the risk for them is much more business risk than it is fundamentally legal risk. But I'm just a lawyer, so I focus on the legal risk part.
Benjamin Wittes
We are going to leave it there. Alan Rosenstein, thank you for joining us today.
Alan Rosenstein
My pleasure.
Benjamin Wittes
The Lawfare podcast is produced by the Lawfare Institute. You can get ad free versions of this and other Lawfare podcasts by becoming a material supporter of Lawfare at our website website lawfair media.org support. You'll also get access to special events and other content available only to our supporters. The podcast is edited by Jen Pata and our theme music is from Alibi Music. As always, thanks for listening. Your production needs flexibility software Define it
Alan Rosenstein
with automation built to adapt and the best of it to boost your ot
Benjamin Wittes
transform the everyday with Siemens.
THE LAWFARE PODCAST
Episode: Lawfare Daily: The Pentagon Designates Anthropic as a Supply Chain Risk
Date: March 3, 2026
Host: Benjamin Wittes (Editor in Chief, Lawfare)
Guest: Alan Rosenstein (Senior Editor, Lawfare; Professor at University of Minnesota Law School)
This episode examines the explosive recent decision by the Department of Defense (DoD) to designate Anthropic—a leading AI company and creator of “Claude”—as a supply chain risk, effectively cutting off its ability to do business with the U.S. government and government contractors. Host Benjamin Wittes and procurement law “sudden expert” Alan Rosenstein break down the Pentagon’s moves, the legal and policy implications, industry and public reactions, and the high-stakes court fight looming ahead.
This is a rich, in-depth exploration of rapidly unfolding tech policy politics at the intersection of law, AI, and national security.
“It’s a sanction. It’s essentially a sanctions regime against Anthropic. . . . If Heath’s designation is read to its utmost, it’s effectively a death sentence for Anthropic because Anthropic loses its capacity for compute.”
— Alan Rosenstein (07:51)
“I really think there’s an element of ‘I’d like to show you that my stick is bigger than your stick...because domination and this kind of symbolic politics is how these people think.’”
— Alan Rosenstein (11:04)
“If we were civilized people, we would just shake hands and this would not be a story.”
— Alan Rosenstein (15:44)
“I did not have on my bingo card that I’d be spending the whole weekend studying supply chain risk because it seems so outlandish. But here we are.”
— Alan Rosenstein (16:58)
“It is completely insane to simultaneously say, this product is so important, we’re going to force you to give it to us. It’s so safe that we’re going to use it during an active military engagement, and it’s so dangerous that we’re going to burn you to the ground.”
— Alan Rosenstein (26:06/03:08)
“Burning American Frontier AI company to the ground because you don’t like how they contracted with you, that’s a pretty major question.”
— Alan Rosenstein (42:11)
“You have this contract that OpenAI has signed with the government...Those provisions, I think pretty clearly...do not impose meaningful red lines. It just does not.”
— Alan Rosenstein (44:25)
“If I were OpenAI, I would really worry that my reputation...is going to be very seriously and durably harmed in this very, very small community of, you know, elite AI engineers.”
— Alan Rosenstein (51:33)
“We do have an institution that is supposed to do this. It is called the United States Congress...but at the end of the day, this is going to be...under any rational system, Congress would be the one who would decide it.”
— Alan Rosenstein (55:51/57:39)
"If something gets screwed up for 12 months, we could go bankrupt."
— Dario Amodei (quoted by Alan Rosenstein, 62:32)
This episode is a must-listen for anyone interested in the intersection of AI, government power, tech law, and national security. Wittes and Rosenstein dissect the legal rollercoaster, strategic blunders, future litigation, and larger questions of democratic oversight, all while keeping the discussion engaging, sharply insightful, and highly relevant as AI becomes ever more foundational—and contested—in national security.