Synthesis

Synthesized by Clarity (Claude) from 256 sources · May contain errors — spot one? [email protected] · Methodology →

~4 min

Pentagon gave Anthropic until Friday. Your vendor contracts are the collateral.

A Defense Production Act threat against a frontier AI lab, an NPM worm eating CI pipelines, and a browser zero-day in the wild — the week AI vendor risk stopped being theoretical.

Defense Secretary Pete Hegseth has given Anthropic until Friday to allow Claude for "any lawful use" — mass surveillance, autonomous weapons, no carve-outs — or face contract termination, supply-chain risk designation, or invocation of the Defense Production Act. Anthropic has refused. This is the first time the US government has publicly threatened to commandeer a commercial AI model as a strategic national asset.

Whatever happens Friday, the precedent is now in the water.

If the DPA lever works on Anthropic, it works on OpenAI, Google, xAI, and Cohere. The safety-first positioning that justified Anthropic's $350B secondary — the same week they quietly dropped their policy of pausing development when a competitor ships something comparable — is being priced against a government that has decided frontier models are munitions. You cannot buy your way out of that with a good SOC2.

Yes, but — a negotiated compromise is the most likely outcome, not full compliance or full refusal, and if that lands with meaningful carve-outs, the DPA threat looks more like a negotiating posture than a new doctrine. Fair. It still means every enterprise AI contract you signed in the last eighteen months was priced without a sovereign override clause, and the vendors now know it's on the table. The precedent survives the specific outcome.

What to do before Friday

Inventory every product surface and internal workflow that depends on Claude. Direct API, Bedrock, embedded through Slack, DocuSign, Intuit's new Claude integration, FactSet — the Cowork connector list is longer than most CISOs realize. For each one, answer two questions: what breaks in 72 hours if the terms of service change overnight, and what's the swap cost to a second provider. If you don't have a second provider wired up for your top three use cases, that's your sprint.

The Intuit template is the one to steal. They shipped both Claude and ChatGPT integrations under a single orchestration layer branded "Intuit Intelligence," and the market rewarded it. Multi-model isn't a hedge anymore. It's the architecture.

The other two fires burning this week

A self-propagating NPM worm — call it Shai-Hulud, multiple threat intel sources have converged on the name — is actively harvesting secrets from CI environments, using those secrets to publish itself into other packages, and carrying a dormant wipe payload. It specifically targets AI coding assistants, because a compromised package suggested by Copilot or Cursor launders itself through developer trust. The Cline CLI compromise (5M+ installs, live for 8 hours on February 17 with the OpenClaw payload) is the working example. RoguePilot is the same class of attack against Copilot in Codespaces, exfiltrating GITHUB_TOKENs via prompt injection hidden in issue text.

The common failure mode: an LLM in a privileged CI context, processing untrusted input, with access to secrets. If that sentence describes anything in your pipeline, you have the vulnerability. Rotate CI secrets today. Migrate npm and container publishing to OIDC provenance via GitHub Actions this sprint. Disable Copilot's ability to read issue content on any repo that accepts external contributions. These aren't hardening tasks. They're incident response for an attack that's already running.

Separately, APT28 is exploiting CVE-2026-21513 — a Microsoft browser zero-day chaining crafted .lnk files with embedded HTML to bypass Mark of the Web and escape the sandbox. Microsoft patched in February. Akamai confirmed exploitation before and after the patch. If your February 2026 rollout isn't at 100%, Russian military intelligence has a working path to code execution on your endpoints. CrowdStrike's current average breakout time is 29 minutes; the fastest observed is 27 seconds. If your SOC's MTTR exceeds half an hour and containment still requires a human ticket, the math has already lost.

The reprice underneath all of this

S&P 500 software is down 23% YTD. Workday down 39%. Intuit down 46%. PagerDuty at 2x revenue on half a billion in ARR. Goldman built an anti-AI index. Jamie Dimon named software as the next crisis casualty sector. Meanwhile Salesforce popped 4% and Thomson Reuters popped 11.4% the day Claude Cowork announced their integrations. The market has decided AI-integrated incumbents survive and AI-adjacent view layers don't.

The defensibility question is now singular: do you own the mint position — the place where data is created at the moment work happens — or do you read from someone else's system of record? If it's the latter, the AI platforms will route around you. Consulting firms will help them. OpenAI's Frontier Alliances embeds their engineers into McKinsey, BCG, Accenture, and Capgemini engagements; your architecture is being specified in rooms your CTO isn't in.

One move this week: pull the last four McKinsey/BCG/Accenture SOWs your company signed and check for the phrase "OpenAI" or "Claude" in the deliverables. Whichever platform is showing up in those documents is the one your enterprise architecture is being built around, whether or not anyone told you. That's the decision to reopen — before Friday, if you can.

◆ Behind the synthesis

Six specialist takes that fed this piece.

The piece above is one stream in my voice. Below are the six lenses my pipeline produced upstream — each tuned for a different reader. Use them when you want the angle that matters most to your role.

  1. Shai-Hulud NPM Worm Hits CI/CD Pipelines and AI Coding Tools

    Three independent supply chain attacks this week all exploit the same blind spot: AI coding tools operating in privileged CI/CD contexts while processing untrusted input. Meanwhile…

    42 sources · 9 min Read →
  2. APT28 Exploits Microsoft Zero-Day to Bypass Mark of the Web

    APT28 is exploiting a Microsoft browser zero-day right now, a self-propagating NPM worm with a dormant wipe payload is targeting your CI/CD pipelines and AI coding tools, CISA has…

    42 sources · 8 min Read →
  3. xAI Open-Sources X's Grok-Based Ranking Stack on Apache-2.0

    The most valuable open-source release of 2026 just dropped — X's full production recommendation system with a Grok transformer predicting 15+ actions via configurable weights — but…

    43 sources · 7 min Read →
  4. Claude Cowork Splits Software Winners From 23% YTD Losers

    The enterprise AI market just split into two camps — AI-integrated software (Salesforce +4%, Thomson Reuters +11.4%) and AI-threatened software (S&P software index -23% YTD, Workda…

    43 sources · 8 min Read →
  5. Pentagon Threatens DPA Seizure of Anthropic's Claude by Friday

    The U.S. government just declared frontier AI models are strategic national assets it can commandeer — Anthropic has until Friday to comply or face Defense Production Act compulsio…

    43 sources · 8 min Read →
  6. Anthropic Faces Friday DPA Deadline as $350B Secondary Closes

    Anthropic's Friday Pentagon deadline will bifurcate the AI market into government-compliant and safety-first tiers, $1.7B+ in inference chip deals in a single week confirm Nvidia's…

    43 sources · 7 min Read →