Notes on Internet Privacy

Posts and research from the URnetwork team and community.

RSS

The Supply Chain Risk Is American

On Friday, May 1, 2026, the Pentagon awarded classified-tier AI procurement contracts for Impact Level 6 and Impact Level 7 networks to eight firms: Amazon Web Services, Google, Microsoft, Nvidia, OpenAI, SpaceX, Oracle, and Reflection AI. Anthropic was excluded. On February 27, 2026, the Trump administration designated Anthropic a "supply chain risk" — the first American company ever to receive a label historically reserved for entities tied to foreign adversaries. Anthropic's offense: refusing two specific demands from Defense Secretary Pete Hegseth — that Claude be permitted for AI-controlled fully autonomous weapons and for mass domestic surveillance of American citizens. Anthropic's response: *"We cannot in good conscience accede to their request."* The Defense Production Act invocation was threatened. The supply-chain-risk designation was issued. Anthropic sued in San Francisco and the District of Columbia. A federal appeals court denied Anthropic's preliminary injunction April 8. On April 17, Anthropic CEO Dario Amodei met White House Chief of Staff Susie Wiles, Treasury Secretary Scott Bessent, and National Cyber Director Sean Cairncross at the White House; the President, asked about the meeting, told reporters: *"Who?"* On April 19, Axios reported the National Security Agency — an agency the Pentagon oversees — was using Anthropic's Mythos despite the formal ban. On April 30, Bloomberg confirmed: NSA was testing Mythos to find vulnerabilities in Microsoft technology. On May 1, Department of Defense CTO Emil Michael characterized the contradiction: *"With Anthropic, they're a supply chain risk. The Mythos issue is a separate national security moment. … The NSA and Commerce evaluates all frontier models, including Chinese frontier models, to see what the capabilities are at the edge."* Today, Monday, May 4, the same day Anthropic announced a $1.5 billion enterprise-AI joint venture with Blackstone, Hellman & Friedman, and Goldman Sachs — and OpenAI announced a parallel $4 billion "Deployment Company" at a $10 billion valuation — the supply-chain-risk designation against Anthropic remains in force. Capability sanctioned. Capability consumed. The procurement-coercion stack is now an instrument of domestic AI policy.

The Friday announcement

On Friday, May 1, 2026, in a press release titled "Department of Defense AI Agreements," the Pentagon announced classified-network artificial-intelligence procurement deals with eight technology firms: Amazon Web Services, Google, Microsoft, Nvidia, OpenAI, SpaceX, Oracle, and Reflection AI. Networks: Impact Level 6 (Secret) and Impact Level 7 (Top Secret). Stated purpose, per the release: "streamline data synthesis, elevate situational understanding and augment warfighter decision-making in complex operational environments." Specific contract values were not disclosed. The release was published on the war.gov domain — an artifact of the Trump administration's January 2025 renaming of the Department of Defense.

Anthropic was excluded. Anthropic's Claude Mythos Preview — released April 7, 2026 under Project Glasswing — is the most capable cybersecurity-discovery model in the public record. Mythos has identified, per Anthropic's own disclosure and Microsoft's May 1 essay "From capability to responsibility," "thousands of high-severity vulnerabilities, including some in every major operating system and web browser." Mythos has surfaced a 27-year-old previously unknown OpenBSD flaw, a 16-year-old FFmpeg bug that survived 5 million automated scans, and several Linux kernel weaknesses that escalate basic user accounts to root.

The Pentagon procured the eight other vendors. The Pentagon excluded the vendor whose model is, by published benchmarks, the most consequential for the work the Pentagon proposed.

The two red lines

Anthropic's exclusion has a specific, dated, and publicly recorded origin. On Wednesday, February 25, 2026, Defense Secretary Pete Hegseth gave Anthropic CEO Dario Amodei a Friday deadline to roll back the company's safety guardrails on the Pentagon contract use-case. Hegseth threatened three escalations: cancellation of the existing $200 million Pentagon contract; designation of Anthropic as a "supply chain risk"; and invocation of the Defense Production Act to compel Anthropic to tailor its AI models for military use.

The Defense Production Act of 1950 has historically been used for materiel production — steel during the Korean War, semiconductors, COVID-19 vaccine manufacturing, electric-vehicle battery components. The Defense Production Act has never previously been invoked to compel a software-services or artificial-intelligence vendor to produce a specific specification.

Anthropic refused the demand to remove two specific safety guardrails. On Thursday, February 26, 2026, in a public statement: "We cannot in good conscience accede to their request." The two non-negotiables were narrow:

First: no use of Claude for AI-controlled fully autonomous weapons. Anthropic's reasoning: AI is not currently reliable enough to operate weapons.

Second: no use of Claude for mass domestic surveillance of American citizens. Anthropic's reasoning: no laws or regulations cover how AI could be used in mass surveillance.

Anthropic did not refuse all Pentagon use cases. Anthropic dropped its core Responsible Scaling Policy pledge — the categorical bar on training models above a capability threshold without appropriate safety measures, replaced with a relativistic commitment to "match or surpass the safety efforts of competitors." Anthropic moved on the policy bar; Anthropic did not move on the deployment-class red lines.

On Friday, February 27, 2026, President Trump directed federal agencies to cease using Anthropic's products. Hegseth designated Anthropic a "supply chain risk." Defense contractors were notified that they must certify they do not use Anthropic Claude models in their work with the military.

The designation, historically reserved for entities tied to foreign adversaries — Chinese, Russian, Iranian, North Korean — had been applied to an American AI laboratory.

The Reflection AI eighth seat

Among the eight firms announced May 1, seven are commercially established with substantial track records: AWS, Google, Microsoft, Nvidia, OpenAI, SpaceX, Oracle. The eighth is structurally novel.

Reflection AI was founded in 2024 by former Google DeepMind researchers. The company raised approximately $2 billion in 2025. Nvidia is an investor. The company is currently negotiating funding at a $25 billion valuation. Reflection AI participates in a government-supported initiative to create AI models customized for the South Korean market. Reflection AI has not yet announced a commercial product.

Reflection AI is backed by 1789 Capital, the venture fund where Donald Trump Jr. is a partner. 1789 Capital was founded in 2024; its portfolio includes media, AI, energy, and defense-adjacent firms. The May 1 award is the first major Pentagon AI procurement in which the Trump-family financial network is structurally entangled with the procurement decision.

The contrast with Anthropic is sharp. Anthropic, founded 2021, has shipped Claude (multiple versions), Claude Code, Claude Security, and Mythos Preview as validated commercial products. On April 24, 2026, Google announced an investment of up to $40 billion in cash and compute in Anthropic. Anthropic refused to remove safety guardrails on autonomous weapons and mass domestic surveillance. Reflection AI, sixteen months old, has no commercial product, has approximately $2 billion in venture funding, has 1789 Capital as a backer, and was cleared for IL6/IL7 classified-tier networks on May 1.

The April 17 White House meeting

On Friday, April 17, 2026, Anthropic CEO Dario Amodei arrived at the White House for a meeting with Chief of Staff Susie Wiles, Treasury Secretary Scott Bessent, and National Cyber Director Sean Cairncross. The meeting, per multiple outlets and the White House readout, addressed the Anthropic-Pentagon dispute and the operational role of Mythos in U.S. cybersecurity. Following the meeting, the White House described the talks as "productive and constructive."

Asked about the meeting later that day, President Donald Trump told reporters he had "no idea" Amodei was at the White House. "Who?"

Trump told CNBC subsequently that "it's possible" there will be a deal between Anthropic and the Pentagon. Trump's comments do not appear to have been coordinated with the National Cyber Director or with Pentagon leadership. Per Axios reporting on April 29, the White House is drafting executive action that would allow federal agencies to onboard Anthropic — a position that contradicts the Pentagon's February 27 designation.

The architecture is staff-driven: the Defense Secretary issued the designation, the Chief of Staff and Treasury Secretary mediated the company's appeal, the National Cyber Director is in the chain of escalation, and the President is — when asked — uninformed of the specific meetings. AI policy under the second Trump administration operates at Cabinet level with executive review treated as a downstream signal rather than an upstream coordination point.

The NSA Mythos paradox

On Sunday, April 19, 2026, Axios reported that the National Security Agency — an agency under Department of Defense oversight — was using Anthropic's Mythos Preview model despite the Pentagon's February 27 supply-chain-risk designation against the vendor. On Thursday, April 30, 2026, Bloomberg confirmed and extended the report: the NSA was testing Mythos specifically to find vulnerabilities in Microsoft technology.

On Friday, May 1, 2026, on CNBC, Department of Defense CTO Emil Michael directly characterized the contradiction: "With Anthropic, they're a supply chain risk. The Mythos issue is a separate national security moment. We have to make sure our networks are hardened up because that model has capabilities that are particular to finding cyber vulnerabilities and patching them." On the question of evaluating models from blacklisted vendors, Michael added: "The NSA and Commerce evaluates all frontier models, including Chinese frontier models, to see what the capabilities are at the edge."

The architectural reveal is operational. The Pentagon's "supply chain risk" designation prohibits defense contractors from using Anthropic Claude in their work with the military. The Pentagon's own subordinate intelligence agency consumes the same model's capability under a "separate national security moment" framing. The capability is sanctioned at the procurement layer; the capability is consumed at the agency layer. The two layers are decoupled.

Anthropic's lawsuits in San Francisco and the District of Columbia, filed in March 2026, argue that the supply-chain-risk designation is procedurally and substantively unlawful. The federal appeals court in Washington, D.C., on April 8, denied Anthropic's preliminary-injunction request. Litigation continues.

The Wall Street counter-signal

On Monday, May 4, 2026 — today — Anthropic, Blackstone, Hellman & Friedman, and Goldman Sachs jointly announced a new standalone enterprise AI services joint venture. Committed capital: $1.5 billion. Lead investors per Anthropic and Blackstone press releases: Anthropic, Blackstone, and Hellman & Friedman each contribute approximately $300 million; Goldman Sachs approximately $150 million; additional backers include General Atlantic, Leonard Green, Apollo Global Management, GIC (Singapore), and Sequoia Capital. The venture's structural model is Palantir-style forward-deployment: Anthropic engineers embedded inside enterprise customer environments to accelerate AI integration.

Per Jon Gray, Blackstone president: "Break down one of the most significant bottlenecks to enterprise AI adoption." Per Krishna Rao, Anthropic chief financial officer: "Enterprise demand for Claude is significantly outpacing any single delivery model." Per Marc Nachmann, Goldman Sachs head of asset and wealth management: "Democratize access to forward-deployed engineers."

OpenAI, on the same day, announced a parallel "Deployment Company" — $4 billion raised across 19 investors including TPG, Brookfield Asset Management, Advent International, and Bain Capital, at a $10 billion valuation.

The asymmetry is sharp. The Pentagon designates Anthropic a "supply chain risk." Wall Street commits $1.5 billion to forward-deploy Anthropic engineers inside private-equity portfolio companies. Google commits $40 billion in cash and compute (April 24). The U.S. federal-procurement layer treats Anthropic as a sanctioned vendor; the U.S. commercial-investment layer treats Anthropic as a strategic asset; the U.S. intelligence-agency layer treats Anthropic's capability as a national-security tool. Three policies, three layers, one company.

The filter tool that reads Americans

The Pentagon's two-red-line dispute with Anthropic is, at the architectural level, simultaneous with a parallel agency-level contest. On March 17, 2026, the Foreign Intelligence Surveillance Court issued an opinion finding that "filtering tools" the FBI, NSA, and other agencies use to narrow Section 702 raw-data searches "effectively turn foreign-target searches into U.S.-person queries — exactly the kind of backdoor search reformers want to require a warrant for."

The specific filter at issue: the FBI's "Advanced Filter Function" — a UI that allowed users to "select a specific FBI casefile number or facility, using a drop-down menu or search bar" to review communications of individuals in contact with foreign targets. The Department of Justice later "deactivated" the tool after finding that selecting those individuals "resulted in queries of raw information," rather than merely sorting prior search results. The March 2026 FISC opinion: the problem is ongoing and extends beyond the FBI.

The court ordered agencies to "reengineer filter tools." The DOJ is appealing the ruling. The White House had until April 16 to appeal or correct.

On Thursday, April 30, 2026, Senator Ron Wyden secured a Cotton-Warner declassification commitment as the price of his unblocking the 45-day Section 702 extension: ODNI Tulsi Gabbard and acting Attorney General must declassify the March 17 opinion within 15 days of the extension. Today is Day 4 of that 15-day window. Approximately May 15 is the deadline. As of this writing, the declassification has not occurred.

The architectural symmetry: the Pentagon punishes Anthropic for refusing to enable mass-domestic-surveillance capability; the FISC restrains agencies for executing mass-domestic-surveillance queries. Surveillance capability is contested at the vendor layer (Pentagon-Anthropic) and at the agency layer (FISC March 17) concurrently, with the same architectural concern at issue and opposite jurisdictional positions.

A short-term infringement

On Wednesday-Thursday, April 29-30, 2026, the U.S. Senate and House passed a 45-day clean extension of Section 702 (S. 4465). Senate by unanimous consent. House 261-111. Trump signed. The fourth procedural extension since the original April 20 sunset. The new sunset is June 12, 2026.

Earlier that Wednesday, April 29, the House passed a 3-year reauthorization (H.R. 8512) by 235-191. The 3-year measure included a permanent ban on a Federal Reserve central bank digital currency, attached by Speaker Mike Johnson. The Senate rejected the package — the CBDC ban could not assemble 60 Senate votes. The 45-day clean extension was the deescalation.

On the floor of the U.S. House of Representatives prior to the 261-111 vote, Representative Thomas Massie (R-KY-04) — co-introducer of H.R. 8470, the Surveillance Accountability Act — said: "A short-term infringement of the Constitution is still an infringement of the Constitution."

Today is Day 4 of the 45-day window. Forty-one days remain.

RightsCon Lusaka, cancelled

On Friday, May 1, 2026, Access Now published a statement: RightsCon 2026 — the world's largest digital-rights summit, scheduled May 5-8 in Lusaka, Zambia, with 2,600 in-person and 1,100 online registered participants from 150+ countries and 750 institutions — would not take place. The cancellation followed Chinese diplomatic pressure on the Zambian government.

The timeline, per Access Now's own published account:

April 27, 2026: Zambian government press release endorses RightsCon. The same day, Zambia's Ministry of Technology and Science telephones Access Now reporting an "urgent issue" — People's Republic of China diplomats are demanding exclusion of Taiwanese civil-society participants from the conference.

April 28: Immigration officers begin telling arriving participants that the event is cancelled. At 9:33 PM Lusaka time, Zambian state-owned media announces "postponement."

April 29: The Ministry of Technology and Science sends Access Now a WhatsApp letter providing official written communication.

May 1: Access Now publishes its statement; Human Rights Watch parallel statement: "Shutting down RightsCon, the Zambian government is shutting down discussions on crucial human rights issues."

The PRC demand, per Access Now: "moderate specific topics and exclude communities at risk, including our Taiwanese participants, from in-person and online participation." Access Now refused: "This was our red line."

The leverage: the Mulungushi International Conference Centre, where RightsCon was to be held, was refurbished in 2020 with $60 million in Chinese funding. The same week, China successfully pressured Madagascar, the Seychelles, and Mauritius to revoke overflight permits for Taiwan President Lai Ching-te's prior April 22 trip to Eswatini. On May 2, Lai departed for Eswatini for a surprise visit aboard King Mswati III's Airbus A340-313 — the only African nation that maintains formal diplomatic relations with Taiwan.

Taiwan Digital Affairs Minister Lin Yi-jing on Facebook (May 2): the cancellation demonstrates "China's unease over the ideas of freedom, democracy and rule of law that Taiwan and RightsCon represent."

The architectural reveal: civil-society convening, the meta-architecture of digital rights advocacy, is now a procurement target — the diplomatic-pressure equivalent of the Pentagon's supply-chain-risk designation. Both operate by attaching consequences to the choice of participants. Both target the boundaries of acceptable association.

The 95.81% problem

On Monday, May 4, 2026, The Register published research by Noah M. Kenney quantifying the re-identification capacity of publicly available U.S. voter records. The headline numbers:

Name plus ZIP code uniquely identifies 95.81 percent of Texas voters and 87.79 percent of North Carolina voters. The combination is sufficient to re-identify nearly every individual in those states' voter rolls.

Among voters with phone numbers listed, 88.53 percent of North Carolina voters with listed phone numbers have unique numbers within their county.

Among frequent voters — those with 20 or more elections in the record — 98.4 percent have unique turnout patterns. Vote-history alone is sufficient to identify a frequent voter against publicly available rolls.

Texas Department of Public Safety's date-of-birth redaction policy is undermined: 28 percent of Texas voters are uniquely identifiable via ZIP code plus gender alone, despite the redaction.

Most consequentially: the Travis County voter file exposes 320 deployed military families via APO/FPO ZIP code patterns. The military's operational-security training does not extend to the civilian voter-roll publication architecture.

Kenney's policy recommendation: shift from data redaction to access controls — rate limits, identity verification, audit logs, and prohibition on commercial resale.

The connection to the Department of Justice: on April 28, 2026, U.S. District Judge Susan Brnovich (D. Ariz., Trump appointee) dismissed the DOJ's voter-roll lawsuit against Arizona with prejudice — the sixth consecutive DOJ loss in voter-roll litigation. On May 19, 2026, the Ninth Circuit will hear oral argument in the DOJ's appeal of the Oregon dismissal. Common Cause v. DOJ (1:26-cv-01352, D.D.C.), filed April 21 by ACLU/CREW/Protect Democracy/Harvard Democracy Clinic, challenges the underlying EO 14399 architecture: the federal-data-concentration "State Citizenship Lists" project that, per public reporting, has already run more than 33 million voter records through DHS SAVE.

The architectural concern unifies. State-published voter rolls are already a near-perfect re-identification source for the names, addresses, demographics, and turnout patterns of nearly every American voter. Federal centralization (EO 14399) compounds the risk by aggregating and normalizing the data into a single queryable pool. The Pentagon's "supply chain risk" designation against Anthropic punishes refusal to enable mass-domestic-surveillance capability; the FISC March 17 ruling restrains agency-level filter-tool surveillance; the voter-roll re-identification paper documents the underlying data fragility; the Common Cause litigation challenges the federal-aggregation policy. Four threads, one architectural concern.

Iran Day 66

Today, Monday, May 4, 2026, Iran's nationwide internet blackout entered Day 66. NetBlocks: more than 1,560 cumulative hours of shutdown. The longest nationwide internet shutdown ever recorded. Approximately 85 to 90 million Iranians remain offline. Iran's Communications Minister Sattar Hashemi: $35.7 million per day in direct digital-economy cost. NetBlocks: more than $37 million per day. Iran Chamber of Commerce: $30-40 million direct, $70-80 million including indirect. Tehran Stock Exchange overall index has dropped approximately 450,000 points in the past four trading days. DigiKala, Iran's largest e-commerce platform, has laid off 200 employees — approximately 3 percent of its workforce.

On Sunday, May 3, RFE/RL reported Tehran University Medical Faculty Dean Alireza Esthamaty's vignette to ISNA: "professors are forced to take turns using the Internet, and wait in line to use the facilities." On April 30, Iran's Graphic Designers Society, Nursing Organization, and lawyers' associations publicly rejected the Internet Pro tier as discriminatory. Reza Olfat Nasab, head of Virtual Business Association: the internet has become "ownerless."

The credentialed-access pyramid: at the apex, approximately 16,000 historic "white SIM card" holders since 2013; below them, the Ministry of Science nominees (faculty, researchers, doctors); below them, commercial cardholders via the Chamber of Commerce at ten times the standard tariff; below them, approximately 85 to 90 million offline citizens. The credentialed tier is itself rationed.

Three threads in Brussels, one in Mexico, one Wall Street

In Brussels today, May 4, 2026, the European Union's Council, Parliament, and Commission resume the third political trilogue on the CSA Regulation. Trilogue 1: December 9, 2025. Trilogue 2: February 26, 2026. Trilogue 3: today. Trilogue 4: June 29. Target deal: July 2026. The Danish presidency converged on dropping mandatory client-side scanning ("detection orders") in favor of risk-assessment plus mitigation obligations. The voluntary CSAM-scanning ePrivacy derogation expired April 3, 2026, after the European Parliament rejected an extension by 311 votes to 228.

Six days ago, on April 28, the European Commission published its first DMA Review Report — concluding the Digital Markets Act "remains fit for purpose." On the same day, the AI Act Digital Omnibus's second political trilogue collapsed in Brussels after twelve hours over conformity-assessment architecture for AI in Annex I safety products. Next trilogue approximately May 13 under Cypriot Presidency. Original 2 August 2026 General-Purpose AI enforcement deadline legally stands. On April 29, the European Commission preliminarily found Meta's Instagram and Facebook in breach of the Digital Services Act for failing to prevent under-13s accessing services — the report cited Meta's reporting tool requiring "up to seven clicks." Possible fine: up to 6 percent of global annual turnover. The same day, the Commission issued a Recommendation urging seven Member States — Cyprus, Denmark, France, Greece, Ireland, Italy, Spain — to roll out the EU Age Verification App by year-end. Germany has refused to participate. Cybersecurity researchers reportedly hacked the app in approximately two minutes.

In Mexico, June 30, 2026 is the deadline for the country's biometric SIM-registration regime: 127 million phone lines must associate to a government-issued biometric Clave Única de Registro de Población (face, fingerprints, iris) or be cut off. On March 20, 2026, Mexico City's 14th Collegiate Court in Administrative Matters cleared the legal path; the deadline now runs.

On Tuesday, April 28, 2026, Maryland Governor Wes Moore signed HB 895 — the Protection from Predatory Pricing Act — making Maryland the first U.S. state to ban surveillance pricing for food retailers. Effective October 1, 2026. The law prohibits large food retailers (≥15,000 square feet) and third-party delivery services from using consumers' personal data — inferred income, ethnicity, family size, neighborhood, purchasing history — to raise prices for specific individuals. No private right of action: only the Maryland Attorney General may bring suits. Three days later, on May 1, the U.S. House Energy & Commerce and Financial Services Committee Chairs introduced the SECURE Data Act (H.R. 8413) and the GUARD Financial Data Act — federal privacy legislation with broad state-law preemption that could nullify Maryland's ban. The California Privacy Protection Agency filed formal opposition April 27.

The cyber cadence

On Friday, May 1, 2026, the Five Eyes intelligence partnership — CISA, NSA, ASD ACSC (Australia), CCCS (Canada), NZ NCSC, UK NCSC — released its first coordinated multi-agency joint guidance on agentic AI security: "Careful Adoption of Agentic AI Services." Five risk categories named: privilege, design and configuration flaws, behavioral, structural, accountability. The guidance: "Until security practices, evaluation methods and standards mature, organisations should assume that agentic AI systems may behave unexpectedly and plan deployments accordingly, prioritising resilience, reversibility and risk containment over efficiency gains."

On the same day, CISA added two vulnerabilities to the Known Exploited Vulnerabilities catalog. CVE-2026-41940 (cPanel/WHM authentication bypass, CVSS 9.8) — exploited in the wild since at least February 23, 2026; approximately 1.5 million cPanel instances exposed online; ~70 million domains potentially affected; ~550,000 still vulnerable as of May 3. Federal patch deadline: May 3, 2026. By May 4, TechCrunch reported continued exploitation: approximately 2,000 instances compromised in the "Sorry" ransomware campaign. CVE-2026-31431 ("Copy Fail," Linux kernel algif_aead local privilege escalation, CVSS 7.8) — 9-year-old logic flaw, 732-byte Python proof-of-concept achieves root via setuid binaries. Federal patch deadline: May 15. Discovered by Theori using its Xint AI pentesting platform.

On Saturday, May 2, 2026, Trellix — the cybersecurity firm formed by the 2022 merger of McAfee Enterprise and FireEye, owned by Symphony Technology Group — disclosed unauthorized access to a portion of its source code repository. No attribution; no customer-data scope confirmed. The cybersecurity-firm-hacked beat continues: FireEye 2020, Vercel/Context.ai April 19, Trellix May 2.

On Sunday, May 3, ShinyHunters listed Instructure on its extortion site with a May 6 deadline. Claimed scope: 275 million users, 240-275 million records, approximately 9,000 schools globally, 3.65 terabytes of data, including private student-teacher messages. The vector — third-party SaaS pivot via Salesforce — is the same that produced Rockstar Games (78.6 million records, April 14), Vimeo via Anodot (April 28), Marcus & Millichap (30 million-plus alleged), Amtrak (9.4 million), McGraw-Hill (13.5 million unique emails).

On Monday, May 4 — today — Progress Software disclosed CVE-2026-4670 (CVSS 9.8 authentication bypass) and CVE-2026-5174 (CVSS 7.7 privilege escalation) in MOVEit Automation. Affected: 2025.1.4 / 2025.0.8 / 2024.1.7 and earlier. Approximately 1,400 instances publicly exposed; more than a dozen tied to U.S. state and local government. The 2023 MOVEit Transfer / Clop ransomware incident produced 2,100+ organizational victims.

Mistral, today, launched Vibe Remote Agents on Mistral Medium 3.5 — 128 billion-parameter dense model, 256K context, 77.6% on SWE-Bench Verified. Cloud-side coding agents, multiple parallel sessions.

CISA, today, was reportedly weighing reducing Known Exploited Vulnerabilities remediation deadlines from two-to-three weeks to three days, citing AI-accelerated exploitation including Anthropic's Mythos and OpenAI's GPT-5.4-Cyber. Stephen Boyer, founder of Bitsight: "If you're going to protect civil agencies, you're going to have to move faster." Kecia Hoyt, Flashpoint VP: "Realistically, three days is simply impossible for some environments."

Mandiant's M-Trends 2026 report: median time from initial network access to ransomware-affiliate handoff is twenty-two seconds. In 2022 the same metric was over eight hours. The cyber cadence has accelerated three orders of magnitude in four years.

The architectural counter

If the supply-chain-risk designation's procurement-coercion stack is an instrument of domestic AI policy, the architectural counter is the elimination of the procurable vendor.

Open-weight models cannot be blacklisted. DeepSeek V4 Pro (1.6 trillion parameters, 49 billion active, 1 million-token context) and V4 Flash (284B/13B), released April 24, 2026 under MIT-style licensing, are freely downloadable from Hugging Face. Mistral Medium 3.5 — 128 billion dense, 256K context, modified MIT license — released April 29. OpenAI Privacy Filter (1.5 billion sparse mixture-of-experts, 50 million active, 96% F1 on PII-Masking-300k) released April 22 under Apache 2.0. Llama 3.3, Qwen 3, GPT-OSS. The procurement-coercion instrument cannot reach what is freely downloadable, freely runnable on user hardware, and freely modifiable by anyone with a GPU. The "supply chain risk" designation requires a vendor; open-weight ecosystems decentralize the vendor.

Federated MCP architecture cannot be central-server-compelled. The Anthropic Model Context Protocol, the OX Security disclosure of April 22 affecting approximately 200,000 servers, and the Pillar Security Antigravity sandbox-escape RCE establish that centrally registered agentic-AI tooling is a privileged-third-party-path attack surface. Federated MCP with signed packages and per-organization patch cadence is the architectural mitigation.

End-to-end encryption with user-held keys — Signal, Proton, Tuta, Threema, Matrix per-device cross-signing — renders the Pentagon-Anthropic dispute over mass-domestic-surveillance moot at the protocol layer: what the operator does not hold cannot be compelled. The cryptographic property survives any procurement-coercion or supply-chain-risk designation against the messenger vendor.

Federated identity with selective disclosure — eIDAS 2.0 European Union Digital Identity Wallets, with the December 31, 2026 deadline; W3C Verifiable Credentials Data Model v2.0; W3C Decentralized Identifiers v1.1 — renders voter-database centralization architecturally moot. Prove "registered voter" without exposing the address. Prove "EU citizen" without exposing the date of birth.

Peer-to-peer transport — URnetwork's residential-node relay, Tor Browser 15.0.11 (April 28) with Snowflake / obfs4 / meek pluggable transports, Shadowsocks / V2Ray / Trojan / NaïveProxy, WireGuard at 94 percent consumer-VPN deployment standard — defeats both Russian VPN-detection (22 of 30 popular Android apps) and Iranian carrier-mediated state-internet tier systems.

FIDO2 hardware authentication — YubiKey, Nitrokey, SoloKey — replaces SMS-MFA, which Citizen Lab Bad Connection's 15,700+ tracking attempts and the FBI DCSNet breach demonstrate is operationally penetrated. The hardware key is on the user's device.

Open-firmware hardware — GrapheneOS on compatible Pixel devices (~400,000 active users; Motorola partnership extends to 2027 lineup); LineageOS; OpenWRT — runs code the user can inspect.

Self-hosted services — Matrix homeserver, Nextcloud, Forgejo, Mailcow, Jitsi, Ollama with federated MCP — replace operator-custody with user-operated custody. The blast radius of vendor-side compromise (Trellix, Vercel/Context.ai, Anodot, Salesforce) is bounded.

Confidential-computing enclaves — Azure Confidential Computing, AWS Nitro Enclaves, Enveil, Opaque, plus federated-analysis frameworks (DataSHIELD, Vantage6, OHDSI, Flower, PySyft) — preserve research utility on encrypted data without operator-visible plaintext.

Privacy-preserving cryptocurrencies — Bitcoin Core 27.0 with BIP324 v2 encrypted P2P transport (default) and BIP352 Silent Payments (merged early 2026); Monero FCMP++ on testnet since October 2025 with mainnet hard-fork tentatively mid-2026 (anonymity set leaping from 16 to approximately 152-158 million outputs); Zcash with shielded-by-default — sit outside the operator-policed stablecoin pathway that Tether's $344 million USDT freeze and OFAC's first-ever direct designation of Central Bank of Iran-linked addresses on-chain (Operation Economic Fury) demonstrate as a sanctions-compliance instrument.

The architectural counter to vendor-blacklisting is vendor-elimination. The architectural counter to capability-coercion is user-controlled primitive deployment.

Three clocks

June 12, 2026 — the next Section 702 sunset. The fifth procedural extension is procedurally available. The structural reform — Massie-Boebert H.R. 8470, Lee-Wyden Government Surveillance Reform Act, Lee-Durbin SAFE Act — is not on the floor. Massie has signaled discharge-petition strategy: collect 218 House signatures to bypass committee referral. Today is Day 4 of the 45-day window.

Approximately May 15, 2026 — the Cotton-Warner declassification deadline for the Foreign Intelligence Surveillance Court's March 17 opinion. ODNI Tulsi Gabbard and the acting Attorney General are obligated to release a declassified version. Day 4 of the 15-day window. Eleven days remain.

August 2, 2026 — the European Union's General-Purpose AI enforcement go-live under the AI Act, original date. The Digital Omnibus second trilogue collapsed April 28 over Annex I conformity-assessment architecture; the next trilogue under Cypriot Presidency is approximately May 13. The 2 August deadline legally stands.

The closing

The Pentagon's "supply chain risk" designation against Anthropic — issued February 27, 2026, the first ever applied to an American firm — operates at three layers. At the procurement layer, it bars federal contractors from using Claude. At the litigation layer, it is contested by Anthropic in San Francisco and the District of Columbia, with the first preliminary-injunction denial issued April 8. At the capability layer, it is unenforced: the National Security Agency uses Anthropic's Mythos despite the formal ban, Pentagon CTO Emil Michael characterizes the contradiction as a "separate national security moment," and Bloomberg has confirmed NSA testing of Mythos on Microsoft technology.

The same week the Pentagon awarded eight classified-tier AI contracts excluding Anthropic, Wall Street committed $1.5 billion to forward-deploying Anthropic engineers inside private-equity portfolio companies. Google, in April, committed $40 billion in cash and compute to Anthropic. The U.S. government's procurement-coercion stack treats Anthropic as a sanctioned vendor; the U.S. commercial-investment ecosystem treats Anthropic as a strategic asset; the U.S. intelligence-agency network treats Anthropic's capability as a national-security tool; the U.S. judicial system, four months in, has not yet ruled on whether the underlying designation is lawful.

Anthropic's two red lines — no AI-controlled fully autonomous weapons and no mass domestic surveillance of American citizens — were the architectural fulcrum of the dispute. The Pentagon demanded their removal. Anthropic refused. The Defense Production Act invocation was threatened; the supply-chain-risk designation was issued; the May 1 contract awards excluded the firm; the lawsuits were filed; the appeal was denied; the meeting at the White House happened; the President said "Who?"; the NSA used the model anyway; the Wall Street partnership was announced today.

The architectural pattern, repeated nine times in the eleven days from April 19 to April 30 in yesterday's edition and continuing unbroken across the four days from April 30 to May 4 in this one, is that every privileged third-party path becomes both a privilege and a leak. The Pentagon's procurement-coercion instrument was supposed to be a privilege of the federal government. The "supply chain risk" designation was supposed to be a tool of foreign-adversary policy. Today both are American AI policy instruments, applied to an American AI laboratory whose only refusals were to enable autonomous lethal weapons and mass domestic surveillance of American citizens — and the Pentagon's own subordinate intelligence agency uses the firm's model anyway.

The architectural alternative — open-weight models, federated MCP, end-to-end encryption with user-held keys, federated identity with selective disclosure, peer-to-peer transport, FIDO2 hardware authentication, open-firmware hardware, self-hosted services, confidential-computing enclaves, privacy-preserving cryptocurrencies — does not have a vendor to designate. The procurement-coercion instrument cannot reach a stack that has no procurement layer.

Capability sanctioned. Capability consumed. The supply chain risk is American.

The architectural counter ships today.


References (7 sources)

References (selected)

  • Department of War, May 1, 2026: "Department of Defense AI Agreements." https://www.war.gov/News/Releases/Release/Article/4475177/classified-networks-ai-agreements/
  • CNBC, May 1, 2026: "Pentagon tech chief says Anthropic is still blacklisted, but Mythos is a separate issue." https://www.cnbc.com/2026/05/01/pentagon-anthropic-blacklist-mythos-michael.html
  • The Register, May 1, 2026: "Pentagon keeps Anthropic barred despite Mythos interest." https://www.theregister.com/2026/05/01/mythos_complicates_anthropic_us_gov_breakup/
  • Breaking Defense, May 1, 2026: "Pentagon clears 8 tech firms to deploy their AI on its classified networks." https://breakingdefense.com/2026/05/pentagon-clears-7-tech-firms-to-deploy-their-ai-on-its-classified-networks/
  • Bloomberg, April 30, 2026: "NSA testing Anthropic's Mythos to find flaws in Microsoft tech." https://www.bloomberg.com/news/articles/2026-04-30/nsa-testing-anthropic-s-mythos-to-find-flaws-in-microsoft-tech
  • Axios, April 19, 2026: "Scoop: NSA using Anthropic's Mythos despite Defense Department blacklist." https://www.axios.com/2026/04/19/nsa-anthropic-mythos-pentagon
  • TIME, February 25, 2026: "Exclusive: Anthropic Drops Flagship Safety Pledge." https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/
  • TechPolicy.Press: "A Timeline of the Anthropic-Pentagon Dispute." https://www.techpolicy.press/a-timeline-of-the-anthropic-pentagon-dispute/
  • Microsoft, May 1, 2026: "From capability to responsibility: securing our global digital ecosystem with next-generation AI." https://blogs.microsoft.com/on-the-issues/2026/05/01/
  • Anthropic, Project Glasswing: https://www.anthropic.com/glasswing
  • Anthropic, Mythos Preview: https://red.anthropic.com/2026/mythos-preview/
  • Fortune, May 4, 2026: "Anthropic, Blackstone, Hellman & Friedman, Goldman Sachs joint venture." https://fortune.com/2026/05/04/anthropic-claude-consulting-industry-joint-venture-blackstone-goldman-sachs/
  • Bloomberg, May 4, 2026: "Goldman, Blackstone partner with Anthropic on AI services firm." https://www.bloomberg.com/news/articles/2026-05-04/goldman-blackstone-partner-with-anthropic-on-ai-services-firm
  • Bloomberg, May 4, 2026: "OpenAI finalizes $10 billion joint venture with PE firms to deploy AI." https://www.bloomberg.com/news/articles/2026-05-04/openai-finalizes-10-billion-joint-venture-with-pe-firms-to-deploy-ai
  • TechCrunch, April 24, 2026: "Google to invest up to $40B in Anthropic in cash and compute." https://techcrunch.com/2026/04/24/google-to-invest-up-to-40b-in-anthropic-in-cash-and-compute/
  • Common Dreams, April 30, 2026: "Wyden to Force Declassification of Secret Court Opinion on FISA 'Serious Abuses.'" https://www.commondreams.org/newswire/wyden-to-force-declassification-of-secret-court-opinion-on-fisa-serious-abuses
  • The Hill, April 30, 2026: "Senate passes 45-day FISA extension." https://thehill.com/homenews/senate/5857966-congress-reconsiders-surveillance-reforms/
  • Access Now, May 1, 2026: "RC26 Statement." https://www.rightscon.org/rc26-statement/
  • Human Rights Watch, May 1, 2026: "Zambia: Summit on Human Rights, Technology Effectively Canceled." https://www.hrw.org/news/2026/05/01/zambia-summit-on-human-rights-technology-effectively-canceled
  • Al Jazeera, May 3, 2026: "Taiwan leader visits Eswatini despite China's attempts to block trip." https://www.aljazeera.com/news/2026/5/3/taiwan-leader-visits-eswatini-despite-chinas-attempts-to-block-trip
  • The Register, May 4, 2026: "Public voter records can expose personal data when linked." https://www.theregister.com/2026/05/04/public_voter_records_weaponized_for_privacy_violation
  • Iran International, May 3, 2026: "Iran internet blackout enters 65th day, NetBlocks says." https://www.iranintl.com/en/202605037916
  • Voice of Emirates, May 3, 2026: "65 days of digital isolation: 'Ownerless internet' pushes Iran's e-economy toward collapse." https://www.voiceofemirates.com/en/business/2026/05/03/65-days-of-digital-isolation-ownerless-internet-pushes-irans-e-economy-toward-collapse/
  • Maryland Office of the Governor, April 28, 2026: "Governor Moore Announces Legislation to Protect Marylanders' Pocketbooks, Data Privacy at the Grocery Store." https://governor.maryland.gov/news/press/pages/governor-moore-announces-legislation-to-protect-marylanders%E2%80%99-pocketbooks,-data-privacy-at-the-grocery-store.aspx
  • CISA, May 1, 2026: "CISA Adds One Known Exploited Vulnerability to Catalog." https://www.cisa.gov/news-events/alerts/2026/05/01/cisa-adds-one-known-exploited-vulnerability-catalog
  • The Hacker News, May: "CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV." https://thehackernews.com/2026/05/cisa-adds-actively-exploited-linux-root.html
  • TechCrunch, May 4, 2026: "Hackers are still exploiting the cPanel bug to gain control of thousands of websites." https://techcrunch.com/2026/05/04/hackers-are-still-exploiting-the-cpanel-bug-to-gain-control-of-thousands-of-websites/
  • BleepingComputer: "MOVEit Automation customers warned to patch critical auth bypass flaw." https://www.bleepingcomputer.com/news/security/moveit-automation-customers-warned-to-patch-critical-auth-bypass-flaw/
  • Mistral, May 4, 2026: "Vibe Remote Agents and Mistral Medium 3.5." https://mistral.ai/news/vibe-remote-agents-mistral-medium-3-5
  • CISA: "CISA, U.S. and International Partners Release Guide on Secure Adoption of Agentic AI." https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai
  • Insurance Journal, May 4, 2026: "CISA Considering Three-Day Patch Deadline." https://www.insurancejournal.com/news/national/2026/05/04/868205.htm
  • BleepingComputer: "Instructure confirms data breach, ShinyHunters claims attack." https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/
  • The Hacker News: "Trellix confirms source code breach." https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html
  • DOJ, May 1, 2026: "Coordinated Takedown of Scam Centers Leads to At Least 276 Arrests." https://www.justice.gov/opa/pr/coordinated-takedown-scam-centers-leads-least-276-arrests-alleged-managers-and-recruiters
  • Meduza, April 30, 2026: "Russia blocks VPN access to major platforms." https://meduza.io/en/feature/2026/04/30/russia-blocks-vpn-access-to-major-platforms-moves-to-charge-for-mobile-vpn-traffic
  • Biometric Update: "Mexico court clears path for mandatory phone registry linked to biometric CURP." https://www.biometricupdate.com/202603/mexico-court-clears-path-for-mandatory-phone-registry-linked-to-biometric-curp
  • DeepSeek, April 24, 2026: "DeepSeek-V4 Preview." https://api-docs.deepseek.com/news/news260424
  • EU Parliament Legislative Train, CSA Regulation: https://www.europarl.europa.eu/legislative-train/spotlight-JD22/file-combating-child-sexual-abuse-online
  • Bitcoin Optech, BIP324 v2 P2P Transport: https://bitcoinops.org/en/topics/v2-p2p-transport/
  • Bitcoin Optech, Silent Payments: https://bitcoinops.org/en/topics/silent-payments/
  • Just Security, May 4, 2026: "Early Edition." https://www.justsecurity.org/137924/early-edition-may-4-2026/

Further Discussion

The Supply Chain Risk Is American

The Pentagon's "supply chain risk" designation has crossed. Historically reserved for entities tied to foreign adversaries — Chinese, Russian, Iranian, North Korean firms — the designation went, on Friday, February 27, 2026, to an American artificial-intelligence laboratory: Anthropic. The first U.S. company ever to receive the label. The trigger: Anthropic's refusal of two specific demands from Defense Secretary Pete Hegseth. First: Claude must be available for AI-controlled fully autonomous weapons. Second: Claude must be available for mass domestic surveillance of American citizens. Anthropic refused both. *"We cannot in good conscience accede to their request."* Hegseth threatened to invoke the Defense Production Act of 1950 — the federal materiel-production authority used historically for steel, semiconductors, COVID-19 vaccines, electric-vehicle batteries — never previously for software or AI services. Trump directed federal agencies to cease using Anthropic's products. The supply-chain-risk designation issued. Defense contractors notified that they must certify they do not use Anthropic Claude in their work with the military. On Friday, May 1, 2026 — three months later — the Pentagon announced classified-tier AI procurement contracts for Impact Level 6 and Impact Level 7 networks with eight firms: Amazon Web Services, Google, Microsoft, Nvidia, OpenAI, SpaceX, Oracle, and Reflection AI. Anthropic was excluded. Reflection AI, the eighth seat, was founded in 2024 by former Google DeepMind researchers. Approximately $2 billion raised in 2025. Negotiating a $25 billion valuation. Nvidia is an investor. **1789 Capital — the venture fund where Donald Trump Jr. is a partner — is a backer.** Reflection AI has not yet announced a commercial product. The contrast with Anthropic is sharp. Anthropic shipped Claude (multiple major versions), Claude Code, Claude Security, Mythos Preview. Mythos identified, by Anthropic's disclosure and Microsoft's confirmation, "thousands of high-severity vulnerabilities, including some in every major operating system and web browser." Mythos surfaced a 27-year-old previously unknown OpenBSD flaw, a 16-year-old FFmpeg bug surviving five million automated scans, and Linux kernel privilege-escalation bugs. On April 24, 2026, Google announced a $40 billion investment in cash and compute in Anthropic. On May 4 — today — Anthropic, Blackstone, Hellman & Friedman, and Goldman Sachs announced a $1.5 billion enterprise AI services joint venture. OpenAI announced a parallel $4 billion "Deployment Company" at a $10 billion valuation. The Pentagon designates Anthropic a supply-chain risk. Wall Street commits $1.5 billion to forward-deploying Anthropic engineers inside private-equity portfolio companies. Google commits $40 billion. The U.S. National Security Agency — an agency the Pentagon oversees — is using Anthropic's Mythos despite the formal ban. Bloomberg confirmed on April 30: NSA is testing Mythos on Microsoft technology. On May 1, Department of Defense CTO Emil Michael characterized the contradiction directly: *"With Anthropic, they're a supply chain risk. The Mythos issue is a separate national security moment. We have to make sure our networks are hardened up because that model has capabilities that are particular to finding cyber vulnerabilities and patching them."* On evaluating models from blacklisted vendors: *"The NSA and Commerce evaluates all frontier models, including Chinese frontier models, to see what the capabilities are at the edge."* Capability sanctioned. Capability consumed. The procurement-coercion stack operates at three layers. At the procurement layer, defense contractors must certify Anthropic-free. At the litigation layer, Anthropic's lawsuits in San Francisco and the District of Columbia challenge the designation; the federal appeals court in D.C. denied Anthropic's preliminary-injunction request April 8. At the capability layer, the NSA uses Mythos anyway. Three layers. Three policies. One company. On April 17, Anthropic CEO Dario Amodei met White House Chief of Staff Susie Wiles, Treasury Secretary Scott Bessent, and National Cyber Director Sean Cairncross at the White House. The talks were "productive and constructive." Asked about the meeting, the President told reporters: *"Who?"* Per Axios reporting on April 29, the White House is drafting executive action that would allow federal agencies to onboard Anthropic. Trump told CNBC subsequently: *"It's possible"* there will be a deal. The architectural reveal: AI policy under the second Trump administration operates at Cabinet level (Hegseth, Wiles, Bessent, Cairncross, Michael) with executive review treated as a downstream signaler rather than an upstream coordinator. The "supply chain risk" designation, the Defense Production Act threat, the contract awards, the NSA's continued use of the model, the lawsuit posture, the White House meeting, the President's *"Who?"* — the seven elements describe a procurement-coercion architecture that is staff-driven, executive-uninformed, judicially contested, and operationally inconsistent. The same architectural pattern repeats elsewhere this week. On May 1, Access Now cancelled RightsCon 2026 — the world's largest digital-rights summit, scheduled May 5-8 in Lusaka, Zambia, with 2,600 in-person and 1,100 online registered participants from 150 countries — after Chinese diplomatic pressure on the Zambian government to exclude Taiwanese civil-society participants. Demand: *"moderate specific topics and exclude communities at risk, including our Taiwanese participants."* Access Now refused: *"This was our red line."* Diplomatic-pressure procurement-coercion at civil-society convening scale. Same structure, different vector. On May 4 — today — researcher Noah M. Kenney's paper in The Register documented that name plus ZIP code uniquely identifies 95.81 percent of Texas voters and 87.79 percent of North Carolina voters; that 28 percent of Texas voters are uniquely identifiable via ZIP plus gender despite DOB redaction; that 320 Travis County deployed military families are exposed via APO/FPO ZIP code patterns. The data-publication architecture that the federal government's EO 14399 voter-database centralization would aggregate is already a near-perfect re-identification source. On May 1, the Five Eyes intelligence partnership — CISA, NSA, ASD, CCCS, NZ NCSC, UK NCSC — issued its first coordinated multi-agency joint guidance on agentic AI security, noting that organizations should *"assume that agentic AI systems may behave unexpectedly."* On May 4, CISA was reportedly weighing reducing Known Exploited Vulnerabilities patch deadlines from 2-3 weeks to **3 days** — citing AI-accelerated exploitation including Anthropic's Mythos and OpenAI's GPT-5.4-Cyber. Mandiant's M-Trends 2026 report places median initial-network-access-to-affiliate handoff at 22 seconds, down from 8 hours in 2022. The cyber cadence has accelerated three orders of magnitude in four years. Today, May 4, Iran's nationwide internet blackout entered Day 66. NetBlocks: more than 1,560 cumulative hours. Tehran University Medical Faculty Dean Alireza Esthamaty: *"professors are forced to take turns using the Internet, and wait in line to use the facilities."* The credentialed-access pyramid — 16,000 historic white-SIM-card holders since 2013, Ministry of Science nominees, commercial cardholders at ten times standard tariff, ~85-90 million offline citizens — is the carrier-mediated equivalent of the Pentagon's procurement-coercion stack. Both are state-administered credentialing systems that allocate access to capability based on certification of compliance. On May 4, Brussels resumed the third political trilogue on the EU CSA Regulation. On May 1, Russia's mobile carriers requested up to six months' delay on the planned 150-rubles-per-gigabyte mobile-VPN traffic charge. On June 30, Mexico's deadline for biometric SIM-registration takes effect — 127 million phone lines must associate to a government-issued biometric Clave Única de Registro de Población or be cut off. On May 6, ShinyHunters' deadline expires for Instructure / Canvas LMS — 275 million users, 9,000 schools globally, the largest LMS breach ever reported. The unifying observation. Capability — to deploy a frontier AI model, to convene civil-society discussion, to publish voter rolls, to identify at scale, to surveil, to evade surveillance — is now subject to procurement-coercion at every layer. The Pentagon coerces the AI vendor. China coerces the civil-society convener. Federal voter-rolls policy coerces the state-level data-publication architecture. Russia coerces the mobile carrier. Iran coerces the citizen credential. Mexico coerces the SIM-card ownership. ShinyHunters coerces the breach victim. The procurement-coercion instrument is a malleable policy tool. Its target is the boundary of acceptable association. Its operative direction is to make the boundary itself the point of leverage. Anthropic's two red lines — autonomous lethal weapons and mass domestic surveillance of American citizens — were the test case. The Pentagon's response: designate the vendor, contract with eight others, threaten the Defense Production Act, deny the preliminary injunction, while the subordinate intelligence agency uses the same model anyway and Wall Street commits $1.5 billion to a forward-deployment partnership with the same firm. The supply chain risk is American. The boundary is procurement. The procurement is coerced. The capability is consumed regardless. **Key stat:** Pentagon · Feb 27 supply-chain-risk designation · first American firm · Anthropic refused autonomous weapons + mass domestic surveillance · May 1 8-firm classified-tier contracts (AWS / Google / Microsoft / Nvidia / OpenAI / SpaceX / Oracle / Reflection AI) · Reflection AI 1789 Capital · April 19 Axios + April 30 Bloomberg NSA-Mythos · May 1 Emil Michael "separate national security moment" · April 24 Google $40B · May 4 Anthropic+Blackstone+Hellman+Goldman $1.5B · May 4 OpenAI Deployment Company $4B / $10B · April 17 Amodei-Wiles-Bessent-Cairncross · "Who?" · April 8 appeals court denial · lawsuits ongoing SF + DC · May 1 RightsCon Lusaka cancelled (Chinese pressure) · 2,600 attendees displaced · May 4 voter-roll re-identification 95.81% TX + 320 deployed military families · May 1 Five Eyes agentic AI guidance · May 4 CISA 3-day KEV proposal · 22-second M-Trends median · Iran Day 66 / 1,560 hrs · Russia VPN tariff delayed · Mexico biometric SIM June 30 · ShinyHunters Instructure 275M / May 6 deadline. **Urgency:** Procurement-coercion is the new architecture of AI policy. Capability survives the procurement boundary; the procurement boundary is itself the leverage.

Open Weights Don't Get Blacklisted

If procurement-coercion is the new architecture of AI policy — if "supply chain risk" can be designated against an American AI lab and the company's capability used by the same Pentagon's subordinate agency anyway — the architectural counter is **vendor-elimination**. Open-weight models have no vendor to designate. **DeepSeek V4 Pro** (1.6 trillion parameters, 49 billion active, 1 million-token context) and **DeepSeek V4 Flash** (284B/13B), released April 24, 2026 under MIT-style licensing, are freely downloadable from Hugging Face. **Mistral Medium 3.5** (128 billion dense, 256K context, modified MIT, 77.6% on SWE-Bench Verified) released April 29 — and on May 4 today extended with Vibe Remote Agents for cloud-side autonomous coding. **OpenAI Privacy Filter** (1.5 billion sparse mixture-of-experts, 50 million active, 96% F1 on PII-Masking-300k) released April 22 under Apache 2.0. **Llama 3.3, Qwen 3, GPT-OSS.** Plus dozens of fine-tunable distillates and federated forks. The procurement-coercion instrument cannot reach what is freely downloadable, freely runnable on user hardware, and freely modifiable by anyone with a GPU. The Pentagon's "supply chain risk" designation requires a corporate target — a vendor with assets, contracts, and a location. Open-weight ecosystems decentralize the vendor. There is no central party to designate. On April 14, 2026, Vidoc Security Lab reproduced Anthropic Claude Mythos Preview-class cyber-vulnerability findings on eight small open-weight models — one with only 3.6 billion active parameters at $0.11 per million tokens. The capability gap between frontier closed models and open-weight peers is 3 to 6 months at the very edge, and substantially smaller at most operational use cases. The procurement-coercion stack is downstream of capability commodification. The architectural counter extends across every layer. **End-to-end encryption with user-held keys.** Signal, Proton, Tuta, Threema, Matrix with per-device cross-signing. The cryptographic property: the service operator cannot produce the plaintext regardless of regulatory pressure, legal obligation, commercial incentive, or supply-chain compromise of the operator's infrastructure. Anthropic's two red lines — no Claude for autonomous weapons, no Claude for mass domestic surveillance of American citizens — were drawn at the deployment layer. The cryptographic primitive draws the line at the protocol layer: what the operator does not hold cannot be compelled or coerced. **Federated identity with selective disclosure.** eIDAS 2.0 European Union Digital Identity Wallets, with the December 31, 2026 deadline. France Identité, Italy IT Wallet, Denmark, Greece, Ireland, Cyprus's "Digital Citizen," Spain. W3C Verifiable Credentials Data Model v2.0 first public working draft. W3C Decentralized Identifiers v1.1 Candidate Recommendation Snapshot. Voter-database centralization (the Common Cause v. DOJ challenge to EO 14399 and the SAVE-program piping that has run more than 33 million voter records) becomes architecturally moot when the verification primitive is federated. Prove "registered voter" without revealing the address. Prove "EU citizen" without exposing the date of birth. Prove "professional credential" without naming the licensing body. **Peer-to-peer transport.** URnetwork's residential-node relay routes traffic through consumer infrastructure rather than carrier-metered paths or commercial-VPN IP pools. Tor Browser 15.0.11 (April 28) with Snowflake, obfs4, and meek pluggable transports. Shadowsocks, V2Ray, Trojan, NaïveProxy — application-layer traffic patterns that defeat the commercial-VPN-detection signatures Russia's 22-of-30 Android-app corpus deployed. WireGuard at 94 percent consumer-VPN deployment standard. For Iran's Day 66 carrier-mediated state internet, the architectural counter is a mesh that does not depend on the state-controlled carrier. For Mexico's June 30 biometric-SIM deadline, the counter is transport that does not depend on the SIM-credentialed mobile network. **FIDO2 hardware authentication.** YubiKey, Nitrokey, SoloKey. Hardware keys replace SMS-MFA, which Citizen Lab's "Bad Connection" Report 192 (15,700+ tracking attempts via SS7/Diameter via 019Mobile, Tango Networks, Sure) and the FBI DCSNet/Salt Typhoon breach demonstrate is operationally penetrated. The credential is on the user's hardware. The carrier is irrelevant. **Open-firmware hardware.** GrapheneOS on compatible Pixel devices — approximately 400,000 active users. The Motorola partnership announced March 2026 ends Pixel-only deployment for the 2027 lineup. LineageOS on other Android hardware. OpenWRT on routers. Klipper on 3D printers. The device runs code the user can inspect; the vendor is a participant in a user-controlled stack, not the exclusive trust boundary. Apple's late-March 2026 statement on Lockdown Mode: *"not aware of any successful mercenary spyware attacks against a Lockdown Mode-enabled Apple device."* For users who cannot run GrapheneOS, the iOS hardening configuration is the strongest commercial baseline. **Self-hosted services.** Matrix homeserver replaces Discord or Slack. Nextcloud replaces Google Drive or Microsoft OneDrive. Forgejo or Gitea replaces GitHub. Jitsi replaces Zoom. Mailcow replaces commercial-operator email. Ollama with LangChain, LlamaIndex, and federated MCP replaces commercial-API AI inference. The blast radius of vendor-side compromise — Trellix May 2 source-code breach, Vercel/Context.ai April 19 OAuth pivot, Anodot/Salesforce ShinyHunters campaign across Rockstar 78.6M / Vimeo / Marcus & Millichap 30M+ / Amtrak 9.4M / McGraw-Hill 13.5M / Instructure 275M — is bounded by user-operated custody. **Confidential-computing enclaves.** Azure Confidential Computing, AWS Nitro Enclaves, Google Cloud Confidential Computing, Enveil, Opaque, plus federated-analysis frameworks (DataSHIELD, Vantage6, OHDSI, Flower, PySyft). Compute happens on encrypted data. The operator does not see plaintext. Federated analysis sends compute to the data rather than data to the compute, preserving research utility without the data-transfer surface that the prior week's UK Biobank Alibaba listing falsified. **Privacy-preserving cryptocurrencies.** Bitcoin Core 27.0 ships BIP324 v2 encrypted P2P transport by default — majority of Bitcoin P2P traffic now encrypted. BIP352 Silent Payments merged early 2026; Cake Wallet, BitBox, Nunchuk shipped support; new BIPs in 2026 include BIP376 (PSBTv2 Silent Payments tweak fields) and BIP392 (descriptor format). Monero FCMP++ on testnet since October 3, 2025; cryptographic key audit running May 11–22; mainnet hard-fork tentatively mid-2026; anonymity set leaping from 16 to approximately 152-158 million outputs. Zcash with shielded-by-default. For users in Operation Economic Fury jurisdictions — where USDT can be frozen at OFAC's request and Tether's $4.4 billion-plus cumulative freezes establish the operational baseline — these privacy-preserving instruments sit outside the operator-controlled stablecoin pathway entirely. Each primitive ships today. None requires a procurement decision. None has a vendor for the Pentagon to designate. None has a corporate operator for OFAC to subpoena. None has a CEO for a White House Chief of Staff to negotiate with. None has a $25 billion valuation for 1789 Capital to underwrite. The deployment is operational work. Hours for an individual to switch messenger and enable hardware-key 2FA. An afternoon to enroll in an identity wallet. A weekend for an open-firmware reflash. A quarter of engineering time for a mid-sized organization to migrate to self-hosted inference and federated MCP. The benefit is structural. Anthropic's two red lines — no autonomous lethal weapons, no mass domestic surveillance — were drawn at the deployment layer of one company's product. The cryptographic primitive draws the same lines at the protocol layer of every user's device. The Pentagon's "supply chain risk" designation against Anthropic operates by punishing one vendor's deployment-class veto. The user-controlled primitive stack does not have a deployment-class veto to punish; the architecture itself is the veto. The Wall Street counter-signal — Anthropic's $1.5 billion joint venture with Blackstone, Hellman & Friedman, and Goldman Sachs announced today, May 4, 2026, alongside Google's prior $40 billion investment, alongside OpenAI's parallel $4 billion Deployment Company at a $10 billion valuation — operates at the commercial-investment layer. The procurement-coercion stack operates at the federal-procurement layer. The architectural alternative operates at the user-hardware layer. Three clocks run. **June 12, 2026** — the next Section 702 sunset; today is Day 4 of the 45-day window; forty-one days remain. **Approximately May 15, 2026** — the Cotton-Warner declassification deadline for the FISC March 17 opinion documenting "serious abuses" in FBI U.S.-person queries via filtering tools that effectively turn foreign-target searches into U.S.-person queries; today is Day 4 of the 15-day window; eleven days remain. **August 2, 2026** — the European Union General-Purpose AI enforcement go-live; the Digital Omnibus second trilogue collapsed April 28; the next trilogue under Cypriot Presidency is approximately May 13; the 2 August deadline legally stands. In the days inside those clocks, the Pentagon's procurement-coercion stack will continue to operate. The NSA will continue to use Mythos. The lawsuits in San Francisco and the District of Columbia will continue. Trump will continue to be uncertain about whether he met Amodei. Wall Street will continue to invest. RightsCon will not happen in Lusaka. The voter rolls will continue to expose 95.81 percent of Texas voters and 320 Travis County military families. Iran's Internet Pro tier will continue to ration access at the credentialed level. Russia will continue to charge mobile-VPN traffic at 150 rubles per gigabyte. Mexico will approach its biometric-SIM deadline. The cPanel exploitation will continue. Trellix will reckon with its source-code breach. The Instructure ransom will resolve or escalate. The Five Eyes guidance will be advisory. The CISA 3-day proposal will be debated. And the user-controlled primitive stack — open-weight models, federated MCP, end-to-end encryption with user-held keys, federated identity with selective disclosure, peer-to-peer transport, FIDO2 hardware authentication, open-firmware hardware, self-hosted services, confidential-computing enclaves, privacy-preserving cryptocurrencies — will continue to ship today, deployable by anyone with the operational time to deploy it. The procurement-coercion stack requires a vendor to coerce. The user-controlled primitive stack does not have a vendor. Open weights don't get blacklisted. The architectural alternative has shipped. **Key stat:** DeepSeek V4 Pro 1.6T params · Mistral Medium 3.5 + Vibe May 4 · OpenAI Privacy Filter Apache 2.0 · Vidoc reproduction $0.11/M · Signal · Proton · Tuta · Threema · Matrix · eIDAS 2.0 Dec 31 2026 · W3C VC v2.0 / DID v1.1 · URnetwork · Tor 15.0.11 · Shadowsocks/V2Ray/Trojan · WireGuard 94% · FIDO2 (YubiKey/Nitrokey/SoloKey) · GrapheneOS ~400k · LineageOS · OpenWRT · Lockdown Mode · Matrix homeserver · Nextcloud · Forgejo · Mailcow · Jitsi · Ollama · DataSHIELD/Vantage6/OHDSI · Azure Confidential / AWS Nitro / Enveil / Opaque · Bitcoin Core 27.0 + BIP324 + BIP352 · Monero FCMP++ mainnet HF mid-2026 · Zcash shielded-by-default **Urgency:** The procurement-coercion stack requires a vendor. Open weights and user-controlled primitives have no vendor. The architectural alternative ships today.

Comics

#1The Supply Chain Risk Is American
#2Open Weights Don't Get Blacklisted