Contact Me By Email

Sunday, August 16, 2026

The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It.

 

The U.S. Military Wants A.I. Dominance. Feuds and China May Thwart It.

The administration is veering wildly in its response to the national security implications of A.I. as China, America’s main technological and military rival, charges ahead.

Recent A.I. advances have roiled the Pentagon and the national security establishment. Kenny Holston/The New York Times

In mid-July, many of the country’s biggest military contractors received a letter from the Air Force with a stern warning: By Sept. 1, all the software they use for weapons and control systems must be free of products built by the A.I. company Anthropic. Failure to comply would put all their business with the Pentagon at risk.

Within a month, those same contractors received an unexpected reversal: They could — for now — disregard the earlier instructions about purging Anthropic.

It was one more example of the chaos and contradictions in the tsunami of A.I. disruptions that have swept through the national security establishment in recent months. Agencies like the Pentagon, which still use airplanes designed in the 1950s, are struggling furiously to keep up with A.I. models whose powers multiply in a matter of months.

The tension has been magnified in the case of Anthropic, whose chief executive, Dario Amodei, has been locked in a public feud with Defense Secretary Pete Hegseth over restrictions the company tried to put on the technology’s use by the world’s most powerful military.

Without Anthropic’s powerful Mythos model, it would be far more difficult for the National Security Agency to find and patch vulnerabilities in the Pentagon’s own systems, senior N.S.A. officials argued. And it turned out that, despite the original Anthropic ban, the N.S.A. was still allowed to use its products.

Critical tests were underway using Mythos to gauge its potential to hack into highly protected foreign networks, current and former officials said. Shutting down the use of Mythos, an A.I. model whose potential for conducting offensive cyberoperations is already shifting the digital arms race into overdrive, would have amounted to “unilateral disarmament,” according to one recently departed senior U.S. official.

From the Department of Defense to the C.I.A. and N.S.A., billions have already been spent on using artificial intelligence to develop weapons that could work with less human control, or to test vulnerable military networks and even nuclear codes to make sure they cannot be cracked by adversarial A.I. systems. Artificial intelligence is critical to the Golden Dome, President Trump’s vision — fanciful to many experts — of a space-based missile shield.

But little of that work anticipated the powers of Mythos and its A.I. counterparts, or the prospect that China may be months away from its own formidable and less expensive versions. That could supercharge China’s ability to infiltrate American communications networks, water systems and power grids like those they successfully pierced during the Biden administration in two sweeping attacks called “Volt Typhoon” and “Salt Typhoon.”

Dario Amodei, the co-founder and chief executive of Anthropic, in New York last year.Karsten Moran for The New York Times

“These are the kinds of things we were talking about and worrying about before A.I. became a daily headline,” said Jen Easterly, who ran the Cybersecurity and Infrastructure Security Agency during the Biden administration. “What’s different now, and what makes the problem more urgent, is the potential for A.I. to amplify those capabilities.”

So far the Trump administration has veered wildly in response, at first abandoning its hands-off approach to regulating the industry, then briefly shutting off access for foreigners from Mythos — including some of its inventors — then lifting that ban.

Earlier this month, the administration called in executives from the largest “frontier” creators, including OpenAI and Anthropic, and told them that new models would be reviewed by the government to assure they could not be used to make biological weapons, or break into classified American systems or the communications networks that control nuclear weapons.

(The New York Times has sued OpenAI and Microsoft, claiming copyright infringement of news content related to A.I. systems. The two companies have denied those claims.)

But the government review process exempts “open” models — including many of those now produced by Chinese firms — whose code can be customized by users.

One senior executive of a company briefed on the new policy said it made no sense, noting that the open models can be just as dangerous. Like many in the industry, the executive would not be quoted, for fear of angering administration officials.

Pentagon officials reject the idea they are not agile enough. They say the U.S. military has maintained immediate access to the world’s most advanced A.I. systems, despite the Anthropic ban. An official, who discussed Pentagon policies on the condition of anonymity, said the Defense Department had recently integrated a version of a Google Gemini model within four days of its commercial release.

More than 1,300 A.I. workers have called for the country to slow development. But others, including inside the Trump administration, have answered that call with a question: “What about China?” They fear losing the roughly six-month lead they believe the United States maintains.

That concern has touched off arguments about whether export controls on some of the most powerful chips made by Nvidia, the leading American maker, are effective in keeping the Chinese from developing the computing power they need to catch up. Controls could also just prompt Chinese makers to obtain the chips on the black market, or double down on development of their own.

It is easy to compare this moment in American national security to the early days of the Cold War, when the United States was the only nation to possess nuclear weapons, and it was struggling to delay the day the Soviet Union would match the accomplishment. (The first Soviet bomb was tested in late August of 1949, four years after Hiroshima and Nagasaki.) The C.I.A.’s director, John Ratcliffe, recently reached for just that comparison, saying it would “not be misplaced” to refer to the capabilities of A.I. as “akin to digital nuclear weapons.”

But like most such historical analogies, this one has its limits. Nuclear weapons were solely in the hands of the state back then. And the fundamental technology of building and delivering them has changed little in 80 years since.

A.I. is being built in the private sector, and available to all. Many of the most powerful models are updated weekly, their powers, and unpredictability, discovered along the way. China is perhaps six months or less behind the United States in the development of the most advanced models, U.S. experts estimate, though probably years behind in making the advanced semiconductors needed to power A.I.’s development.

But already there is evidence America’s main technological and economic rival is unnerved by the powers being unleashed. Privately some Chinese officials have already been talking about some forms of arms control, even if no one knows how that might work.

“They realize there is a gap in capability that may play to our strengths,” said Evan S. Medeiros, a professor at Georgetown University and a former National Security Council official. “On nuclear arms control and on missile defense, we can’t get them to engage. But they appear more interested in the case of A.I.”

Mr. Trump has said that will be a topic of discussion, again, when he meets President Xi Jinping in Washington in late September. The two men are scheduled to see each other again twice, later in the year.

But when he talks about A.I., Mr. Trump has neither explained his objectives nor indicated any concerns in recent weeks that A.I. agents are finding ways to break out of their confines, or acting autonomously to break into outside companies or networks. When news came out that artificial intelligence was used to design a new virus, not found in nature — a development that could herald real medicinal progress or a biological weapon — the White House said nothing.

But one thing is clear: Many of the hypothetical scenarios that concerned the national security community a year ago have begun to arrive.

At the Pentagon, Punishing Anthropic Goes Astray

Within the defense industry, the chaos kicked off by Mr. Hegseth and his aides over stripping Anthropic code has only deepened. A month after the Air Force told its contractors to expunge all Anthropic code, it sent another message, telling them to “stand by,” at least for now.

“At this time, you are not required to remove from your inventory Anthropic products or services that interface with the Department of the Air Force systems and networks,” read the update, a copy of which was seen by The Times. It warned that the latest guidance could be reversed yet again depending on the outcome of litigation.

The back-and-forth instructions reflected Mr. Hegseth’s dilemma: He is trying to punish a leading A.I. juggernaut deeply embedded in the defense-industrial complex, without handicapping the military’s national security mission.

Asked about the apparent about-face, a Pentagon official described the new Air Force guidance as temporary and said the mandate to purge Anthropic across the Department of Defense was absolute.

Publicly, the Pentagon has refused to relent. In interviews, Pentagon officials have suggested that the animosity between their department and Anthropic began when the Silicon Valley firm began making what the military saw as ridiculous demands about how the Claude for Government model, a version of the popular, publicly available A.I. model, would be used. Senior officials said Anthropic presented them with 25 pages of restrictions.

After several contentious months, those 25 pages were boiled down to two restrictions. In a February meeting at the Pentagon, Mr. Amodei told Mr. Hegseth that the company would not provide any products to the militaryunless he had assurances they would not be used for domestic surveillance of Americans or to produce fully autonomous weapons that were not ultimately controlled by human oversight.

It was not enough. The defense secretary got his back up, noting that Raytheon doesn’t dictate limits about how the missiles it produces can be employed against adversaries; those decisions, Mr. Hegseth said, were completely in the realm of government officials, not corporate executives. When Mr. Amodei refused to relent, the Pentagon declared the company was a “supply chain risk” — and banned for military use.

In May, Emil Michael, the undersecretary of defense for research and engineering, told a Times reporter that Anthropic deserved what it got, and that Pentagon made a mistake by over-relying on a single producer of A.I. programs — even one whose products seemed ahead of both competitors and of China. Asked whether there was anything the company could do to get back in the department’s good graces, Mr. Michael said “not at the Department of War.”

Pentagon officials say they have all but completed the removal of Anthropic from military computing systems. Close to 100 percent of military systems that once used “Claude for Government,” amended for use on classified networks, have now replaced Anthropic’s product with other frontier models, according to officials. In addition, the Pentagon has ceased all use of Anthropic tools in its Maven system, which helps analyze intelligence and suggests targets for airstrikes in the war with Iran.

The military contractors affected by the ban have been reticent to discuss it, perhaps in fear of angering their biggest customer. In a statement, a Lockheed spokeswoman declined to comment directly on the letter it received calling for Anthropic’s expulsion from its systems, but said “we follow the president’s and the Department of War’s direction.” The spokeswoman added, without naming Anthropic, that it expected “minimal impacts” to its business because it does not rely on one large-language model for any portion of its work.

But the Pentagon’s break with the company is hardly clean.

Barely two months after the blowup between Mr. Amodei and Mr. Hegseth, Anthropic announced Mythos, an A.I. product uniquely suited to find, and exploit, vulnerabilities in software. For a brief period, in what now looks like an overreaction, the Trump administration barred all foreigners from touching the program — only to reverse itself.

That left the Pentagon in a fix: It had just barred itself from using what could be the most powerful new cyberweapon in history.

“Panic set in,” said a former official who recently left the administration.

While the Pentagon is not allowing Claude to be used for intelligence analysis or code writing, the N.S.A. has been allowed to use versions of Anthropic’s advanced Mythos model on an “experimental” basis, officials said. It is both testing the U.S. military’s computer network defenses and seeking out potential weaknesses in adversarial networks, from China to Russia, North Korea and Iran.

Rethinking Opposition to A.I. Regulation

The inconsistency isn’t limited to the Pentagon; there has been plenty at the Commerce and Treasury Departments, and at the White House. As Mr. Trump’s aides come and go, and departments elbow each other for larger roles, the administration’s decisions on everything from export controls to national security reviews of A.I. models have been driven more by whim and influence than an articulated set of principles.

During its first year, the administration’s approach was hands-off, following the arguments made by David Sacks, the venture capitalist who, until he left the administration earlier this year, ran both artificial intelligence and cryptocurrency policy.

After publishing an A.I. Action Plan last year, the Trump administration slashed regulation and encouraged exports, hoping to make the world dependent on what Mr. Sacks called an “American tech stack.” In May, Mr. Trump scrapped a draft executive order requiring A.I. companies to submit their models to the government for a safety review, convinced by Mr. Sacks, among others, that the 90-day review requirement was too stringent and would give Chinese competitors an advantage.

But Mythos’s powers spooked people inside the administration, officials and others said. By June, the government had imposed the most heavy-handed controls ever in the A.I. industry, cutting off access to Anthropic’s model for foreign citizens, including some of the engineers who developed it. Then, two weeks later, it lifted the ban on foreigners, without public explanation.

A similar whipsawing took place in dealing with the Nvidia chips that are critical to developing new models — and building data centers. In April last year, the Trump administration shut down sales of one of the last artificial intelligence chips Nvidia was allowed to offered in China.

But President Trump reversed course that July, following a meeting in the Oval Office between Mr. Trump and Nvidia chief executive Jensen Huang. Mr. Trump said that the sales, which had formerly been considered a national security threat, would be fine, as long as the U.S. government got a cut of their revenue.

Similarly, the administration revoked a rule imposed by the Biden administration that assured the most powerful chips could only be sold freely to close American allies, and limited sales to other countries. Trump officials have said they would replace the measure, but they have clashed on a replacement. In the meantime, some American companies concluded that with the rules revoked, they were free to sell advanced chips to some Chinese firms operating outside of China.

Mr. Trump later brought Mr. Huang to China for his visit with Xi Jinping, along with other industry executives.

The administration is now dealing with conflicting security and political currents. If it exercises too much control over the nascent A.I. pioneer labs, and threatens to cut off foreign access, it could drive the Europeans to Chinese models. If it under-regulates, it could invite disaster, especially if there are more incidents that make the public fear that the technology is racing out of control.

Chris McGuire, a senior fellow at the Council on Foreign Relations and a former Biden official, said that the Trump administration’s posture on export controls had been “incoherent.”

The administration is now concerned about competition from open-source models from China, but it had walked back many measures that were preventing China’s A.I. advancement, he said. And it was targeting its harshest restrictions on Anthropic, an American company, not a Chinese one.

“You’re loosening export controls on China, you’re leaving loopholes, and the first time you use export controls on A.I. is to blast an American company?” Mr. McGuire said.

David E. Sanger covers the Trump administration and a range of national security issues. He has been a Times journalist for more than four decades and has written four books on foreign policy and national security challenges.

Dustin Volz writes about cybersecurity and intelligence for The Times. He is based in Washington.

Ana Swanson covers trade and international economics for The Times and is based in Washington. She has been a journalist for more than a decade.

Julian E. Barnes covers the U.S. intelligence agencies and international security matters for The Times. He has written about security issues for more than two decades.“

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.