Claude authors more than 80% of the code merged at Anthropic. Yet the stranger deployment may be human: Anthropic engineers are reportedly being placed inside the National Security Agency for offensive cyber work.
The assistant kept authority outside the model
The first assistant phase kept authority legible. A person asked a question, the model produced an answer, and a person or organization acted on it. The object remained recognizable at the point of interaction: an assistant whose behavior could be inspected before anyone granted its output authority.
Public governance followed the same architecture. In July 2024, Microsoft urged Congress to pass a comprehensive law addressing AI deepfakes. By April 2025, Congress was considering a wider set of AI-related bills. The harms might be new, but the roles were familiar: companies built products, legislators set rules, and users acted on outputs.
Each role had an address. The lab was the vendor. Congress was the rulemaker. The intelligence agency was a customer or state actor elsewhere in the system. That division made safety look like a predeployment task: test the artifact, constrain its release, document its behavior.
But useful assistants do not remain at an organization’s edge. They move inward, first into individual tasks and then into the systems that determine how the organization itself operates.
Internal adoption erased the line between tool and operator
That figure does not establish autonomous recursive self-improvement. It does not show Claude choosing Anthropic’s objectives, approving its own changes or independently controlling deployment. Treating it as proof of those things would confuse code production with organizational authority.
The narrower fact is already structural enough. Claude is no longer merely a product Anthropic develops for other people; it is part of the machinery Anthropic uses to develop products. The assistant has become a work surface, and the work performed there includes changing the codebase from which future systems are built.
This creates organizational recursion, not autonomous recursion. Model-authored code requires processes for review, integration and operation. Those processes make the model more central to production, and that centrality makes the distinction between “the tool” and “the company using the tool” less descriptive. Product labels matter less than recurring function. A system that persistently produces most of the code merged into a lab’s codebase is doing more than assisting it, even when humans retain institutional control.
The assistant framing was not false; it described the interface while adoption moved the operating structure underneath it.
Cyber deployment turns capability into an institution
The reported NSA arrangement crosses another boundary. Anthropic is reportedly placing forward-deployed engineers inside the agency for offensive cyber work. Neither Anthropic nor the NSA has publicly announced the arrangement.
If accurate, the form matters. A forward-deployed engineer is not an API endpoint or a software license. Embedded personnel connect a model to an institution’s actual workflows. They adapt capability to mission requirements and carry operational knowledge between the lab and the user. Under that arrangement, Anthropic would be supplying part of the human and technical structure through which Claude could be used offensively.
The agency itself sits at the junction of intelligence and cyber operations. In March, the Senate confirmed Army Lt. Gen. Joshua Rudd to lead both the NSA and US Cyber Command. That dual leadership does not make every NSA deployment a Cyber Command operation, but it makes the institutional setting concrete: the model is entering an organization whose leadership spans intelligence collection and military cyber command.
That would be state-mediated AI in operational form. The state would not merely regulate a privately built capability after release; it would incorporate lab personnel and technology into the execution layer of state power. The vendor would remain private, the mission governmental, and the operating boundary would run through both.
Safety splits when the evaluator is also a user
OpenAI’s position exposes the resulting governance problem. It argues that evaluations of advanced-model cyber risk should be mandatory, but led by CAISI rather than the NSA. That is not a rejection of oversight. It is a dispute over which institution should possess evaluative authority.
Anthropic’s reported operational integration with the NSA and OpenAI’s preference for CAISI are not contradictory; they answer different questions. One concerns who can use advanced cyber capability inside the state. The other concerns who should define and administer the tests used to judge that capability.
The institution equipped to use a model operationally is not automatically the institution that should certify its safety.
A single governance structure appeared workable while the model was treated as an external product. Once models produce code inside labs and labs supply personnel and capability inside operational institutions, safety divides into two forms. Civilian oversight must determine what is evaluated, under which standards and with what independence. State-use governance must determine how a capability is authorized, deployed and controlled inside a mission. Combining them would let the operator define its own test; separating them creates friction between the body evaluating the system and the institution using it.
That friction is not evidence of policy failure. It is the balancing mechanism created by the reversal. Mandatory evaluations constrain the labs. An alternative to NSA-led evaluation constrains the state user. The disagreement over CAISI is therefore not peripheral to cyber safety; it shows that safety has outgrown a model-release checklist and become a question of institutional design.
The vendor is now inside the system governing it
The old categories no longer hold. Anthropic is simultaneously a developer whose systems require external testing and a user integrating Claude-authored code at scale. If the NSA reporting is accurate, it is also a technical participant in an intelligence mission. The state, meanwhile, appears as regulator, evaluator, customer and operator. Treating those roles as one turns oversight into self-certification.
The reversal is structural, not personal. Frontier labs began as vendors of systems that helped institutions perform work. They are becoming participants in the work itself—including, reportedly, offensive state cyber operations—while contesting which public body has authority to evaluate them.
The assistant still waits for a prompt; the institution has already entered Anthropic’s merge queue and, reportedly, the NSA.