Capture by Design
On 27 February 2026, the United States government declared war on one of its most politically peculiar citizens
An AI company founded by people who had left OpenAI because they thought AI was too dangerous, now blacklisted by a Republican administration because they thought AI was too dangerous. Within hours, Pete Hegseth and Donald Trump took to social media to accuse Anthropic of endangering national security. Federal agencies were ordered to stop using Claude. The Pentagon began the paperwork to brand the company a “supply chain risk to national security,” a designation normally reserved for firms with ties to adversary states.
Dario Amodei, in an internal memo reported by The Information, told staff the President disliked Anthropic for failing to offer “dictator-style praise.” Trump called the company “radical left” and “woke.”
It was, in its peculiar way, the most clarifying moment American AI governance has had in a decade.
On 26 March, Judge Rita Lin of the Northern District of California issued a preliminary injunction blocking the ban. Her language was unusually sharp for a federal district opinion:
“Punishing Anthropic for bringing public scrutiny to the government's contracting position is classic illegal First Amendment retaliation,” she wrote, adding that “nothing in the governing statute supports the Orwellian notion that an American company may be branded a potential adversary and saboteur of the U.S. for expressing disagreement with the government.”
The administration appealed within a week. As of today, 9 April 2026, the dispute is live, unresolved, and legally unprecedented.
It is tempting to read all of this as political melodrama, one more instalment in the Trump administration's habit of punishing companies that talk back. That reading is not wrong. It is just radically insufficient.
What the Anthropic fight has exposed
Not a Trump problem, or an Anthropic problem, or even an AI-safety-versus-national-security problem. It is something stranger: the firms building the most consequential computational systems of our era are simultaneously the dominant voices shaping how those systems will be governed, and the public clash between one of those firms and the White House has revealed just how few independent levers anyone else has.
A commentary published in early April in the policy trade press put it this way: the dispute reveals something structurally troubling, because it shows that the only place serious arguments about frontier AI are happening at all is inside the rooms of the companies that build it. Take the companies away and the rooms are empty.
That is regulatory capture of a sort, but a kind the literature has never quite described. It is capture that formed before effective regulation existed to be captured. The frontier labs did not corrupt a mature regulatory apparatus. They grew up in a vacuum and then offered, helpfully, to fill it themselves.
The Shape of the Dispute
Stripped of its political theatre, the Anthropic fight is a contract dispute. The Department of Defence wanted access to Claude for “all lawful purposes,” a formulation broad enough to encompass fully autonomous lethal targeting, mass surveillance of US persons, and any other application a creative procurement officer might dream up. Anthropic, whose usage policy explicitly prohibits those applications, refused.
The company offered workable alternatives:
- Access for non-weaponised use cases
- Compartmentalised deployments with documented guardrails
- Joint review of edge cases
The Pentagon's position hardened. Anthropic went public. The administration retaliated. A federal judge found the retaliation probably illegal. The appeal is ongoing.
What makes the dispute so destabilising for the governance conversation is that Anthropic is not behaving as the capture literature would predict. The canonical story assumes that the regulated industry quietly lobbies for weaker rules, funds sympathetic experts, and ends up with a regulatory environment that looks stringent on paper and is toothless in practice.
Anthropic is doing something almost the opposite:
- It is publicly advocating for stricter chip export controls that antagonise Nvidia, Microsoft, and much of the rest of the industry.
- It has argued for pre-deployment evaluation regimes that would bind it as tightly as its competitors.
- It has, at real commercial cost, walked away from contracts the Pentagon desperately wanted signed.
And yet the capture problem has not gone away. It has become harder to see. Because even when the “good” frontier lab fights the administration in court over model use policies, the underlying structural condition is unchanged: Anthropic is still the entity telling the public how dangerous its own models are. Anthropic is still defining what an acceptable evaluation methodology looks like. Anthropic is still running the red teams that decide which capabilities deserve disclosure. Anthropic is still writing the blog posts the policy community quotes back to itself.
The dispute is not a case of capture failing. It is a case of capture succeeding so thoroughly that the public conversation happens entirely within the conceptual vocabulary set by the labs themselves.
A New Kind of Capture
Regulatory capture, as the economists George Stigler and Sam Peltzman formalised it in the 1970s, is a corruption of maturity. It happens after a regulator exists, after rules are written, after a bureaucratic routine sets in and the small, concentrated, informed industry learns how to extract rents from the large, diffuse, ignorant public. The paradigmatic examples are the Interstate Commerce Commission and the railroads, the Civil Aeronautics Board and the airlines, the state liquor boards and the wholesalers. These are stories of drift. Institutions designed to constrain powerful interests began to serve them, because the powerful interests were the only ones who showed up to the meetings.
The AI case is categorically different. There is no mature AI regulator. There is nothing to drift away from.
Instead, what the industry has done is populate the pre-regulatory space with its own objects:
- Voluntary commitments
- Self-administered evaluation regimes
- Multi-stakeholder forums
- “Model cards,” “system cards”
- Responsible scaling policies
- Frontier model forums
Each has legitimate merit on its own terms. Taken together, they form a lattice of quasi-governance that occupies the conceptual territory where independent regulation might otherwise live. By the time Congress or a European regulator shows up with the ambition to do something new, the intellectual infrastructure is already in place, and it has been built by the firms being regulated. The regulator is not captured. The regulatory idea is.
Call this capture-in-utero, or pre-regulatory capture, or, more bluntly, capture by design.
The mechanism is not lobbying in the traditional sense. It is something closer to epistemic dominance. The labs hold the data, run the experiments, publish the papers, train the graduates, fund the think tanks, convene the conferences, and shape the vocabulary. When a newly arrived policymaker asks what the state of the art on dangerous capability evaluation is, the only answer available is the one the labs have written. There is no counter-literature, because there is no counter-infrastructure to produce it.
The United Kingdom's AI Security Institute is one of the few attempts anywhere in the world to build such counter-infrastructure. It is important, underfunded, and fragile. It is not yet large enough to change the overall picture.
The Voluntary Commitment Trap
To see the capture dynamic concretely, consider the July 2023 White House voluntary commitments, the document that came to define Biden-era AI governance before the Executive Order did. Seven companies - Amazon, Anthropic, Google, Inflection, Meta, Microsoft, and OpenAI - signed up to eight principles covering security, safety, and public trust. Eight more signed on in September. Apple joined in July 2024.
For two years, the voluntary commitments have been the closest thing the United States has had to a national AI policy, cited in speeches, referenced in the Executive Order, and treated in the press as a kind of proto-statute.
An academic study published in 2025 attempted, probably for the first time, to evaluate how well the signatories had actually performed against their own commitments. The results were bleak:
- The average score across all companies was 53 per cent.
- The highest scorer, OpenAI, managed 83 per cent.
- On the commitment most relevant to catastrophic risk, model weight security, the average was 17 per cent.
- Eleven of the sixteen companies scored zero.
Nobody had been penalised, because there were no penalties. Nobody had been publicly shamed, because the only people qualified to evaluate compliance were the companies themselves or the small network of nonprofits they funded.
The commitments functioned as a legitimising device: a way for the industry to say governance was happening, and for the administration to say governance was happening, while almost nothing resembling governance was actually happening.
The Frontier Model Forum, founded by Anthropic, Google, Microsoft, and OpenAI the same summer, performed a similar legitimising role. It produced whitepapers on responsible scaling. It issued definitional statements about frontier models. It convened working groups. Its existence has been taken as evidence of self-regulation. And it may well be. But it is self-regulation in the most literal sense: regulation of the self, by the self, for the self, with no exit option for anyone who disagrees.
This is not a moral failure on the part of the individuals involved. Most of them, including the ones at Anthropic now fighting the Pentagon in court, are earnest and thoughtful and alarmed in the way safety-focused engineers tend to be alarmed. The problem is structural. When the same small group of organisations sets the agenda, runs the evaluations, writes the papers, convenes the meetings, and authors the voluntary commitments, the resulting governance architecture reflects their view of the world, including the things they cannot see from inside it.
NIST, CAISI, and the Voluntary Framework Problem
Across town from the White House, the National Institute of Standards and Technology has spent the last three years constructing what it calls the AI Risk Management Framework. The first version was released in January 2023. A generative AI profile followed in 2024. A March 2025 update emphasises model provenance, data integrity, and third-party assessment.
Colorado's AI Act now gives organisations a legal affirmative defence if they can demonstrate alignment with the framework. Regulators at the FDA, SEC, and CFPB reference it with increasing frequency. It is, in many ways, the most serious piece of technical policy work the US government has produced on AI.
It is also, by design, voluntary. The framework is a menu of considerations, not a set of binding requirements. It is the product of a lengthy consultation process in which the firms best positioned to influence its development were, inevitably, the firms with the deepest technical staff and the most resources to commit to standards meetings. The resulting document is careful, impressively researched, and structurally unable to compel anyone to do anything. Its value, advocates argue, is that it provides a common vocabulary that future binding rules can rest on. Its critics respond that the vocabulary itself was shaped by the parties being regulated, and that the “future binding rules” slot remains empty.
In June 2025, the Trump administration renamed the US AI Safety Institute the Center for AI Standards and Innovation, or CAISI. Commerce Secretary Howard Lutnick's accompanying statement was unusually blunt:
“For far too long, censorship and regulations have been used under the guise of national security. Innovators will no longer be limited by these standards.”
The institute kept most of its responsibilities and lost most of its claim to being a regulator-in-waiting. “Safety” was removed from the name. “Innovation” was added. The signal was received.
The rebrand matters because it demonstrates how thin the government's own regulatory identity turned out to be. The institute had been founded in 2023 to give the federal government an independent foothold in AI evaluation. It signed memorandums of understanding with OpenAI and Anthropic that granted formal pre-release model access. It participated in joint evaluations with the UK. When the political winds shifted, it was renamed in a morning, by press release, without legislation, without hearings. An institution that can be erased by a name change was not an institution. It was a vibe.
The Epistemic Monopoly Problem
Behind all of this sits the deepest issue in contemporary AI governance: the people who know how these systems behave are the people who built them.
The frontier labs:
- Employ the overwhelming majority of researchers qualified to evaluate frontier models.
- Own the compute required to run meaningful evaluations.
- Hold the data about how their models respond to inputs at scale.
- Control the access terms under which external parties can test anything.
If a regulator wants to know whether Claude Opus 4 will attempt to exfiltrate its own weights under pressure, the only empirically grounded answer comes from Anthropic's own red team, which ran the tests and wrote the system card.
This is the epistemic monopoly problem, and it is why the usual tools of regulatory design run out of road. An environmental regulator confronting an oil refinery can, in principle, send its own inspectors with their own instruments to measure stack emissions. A pharmaceutical regulator can demand raw trial data and reproduce the analyses. An aviation regulator can order a grounding and inspect every aircraft. These tools work because the
Comments
No comments yet. Start the discussion.