The Federal Trade Commission has a two-word name for how the AI industry funds itself: circular spending. It sits in a staff report the agency published in January 2025, describing the deals between the largest cloud companies and the largest AI labs. Not a critic’s phrase. Not a short seller’s. The government’s own words, in a federal document, for the way the money moves.

Here is the arrangement that phrase describes. A cloud company invests billions of dollars in an AI lab. The lab then agrees to spend a large share of that same money buying computing power from the company that just funded it. The money leaves and comes home. The FTC found that these partnerships “include cloud commitments that require AI developers to spend a large portion of their CSP partner’s investment on cloud services from their partner,” and it named that feature, in plain type, circular spending.

That finding has been public for more than a year. So has a second fact, from a different stack of documents: the same small group of companies now floods Washington with more lobbyists than almost any other industry. What nobody has done is lay the two records side by side. Do that, and a single machine comes into focus. A money loop that funds its own demand, and a legal wall going up to keep anyone from regulating it. Same companies. Both halves. It is the first thing to understand about the AI economy, and it is hiding in plain public records.

The loop

The loop runs through three partnerships, and the FTC studied all three. The agency’s 6(b) study examined Microsoft and OpenAI, Amazon and Anthropic, and Google and Anthropic, the largest such deals in the industry. As the report tabulated the publicly reported figures through September 2024, Microsoft had put 13.75 billion dollars into OpenAI, Amazon 8 billion into Anthropic, and Google 2.55 billion into Anthropic. Microsoft’s own quarterly filing that fall put its total funding commitments to OpenAI at 13 billion, accounted for under the equity method.

These are not ordinary stock purchases. The FTC found the deals hand the cloud partners “significant equity and certain revenue-sharing rights,” and leave the door open for one company to fully acquire its partner down the line. They carry “consultation, control, and exclusivity rights,” including board seats and preferential treatment. The company writing the check also gets a hand on the wheel.

Then the money comes back as cloud spending. That is the circular part, and the FTC was direct about why it matters. The structure, in the agency’s reading, is one avenue through which a cloud provider may aim to reduce the size of the loss it might otherwise take on the billions it pours into a partner. The lab gets discounted computing it could not afford on the open market. The cloud gets its money returned as revenue, plus equity, plus a view inside a rival’s operation. The report found the arrangement reaches all the way down to the silicon, with “co-development plans for CSP-designed semiconductor chips” tuned to the labs’ models. Money, equity, control, and custom hardware, all moving in a ring.

The entanglement runs deeper than money. The FTC found the partnerships give the labs discounted access to the scarce computing they cannot get elsewhere, let the two sides embed their own engineers inside each other’s companies, and share training data along with detailed performance and financial figures on the models themselves. The people, the data, and the hardware are braided together as tightly as the cash. Unwinding one company from the arrangement would mean pulling all of it apart at once.

The agency also listed risks it thought were worth watching. In Section 5 of the report, staff flagged that these partnerships could limit other AI developers’ access to computing power and engineering talent, the two scarcest inputs in the field. They flagged that the deals could raise the cost of switching providers, through exclusivity terms and technical lock-in that make leaving expensive and slow. And they flagged that the arrangements hand the cloud partners access to sensitive financial and technical information, including confidential chip designs and a partner’s own customer and revenue numbers, which those same cloud companies could use to build products that compete with the labs they fund.

That section is contested, and the objection came from inside the agency. Commissioner Andrew Ferguson, joined by Commissioner Melissa Holyoak, filed a concurring and dissenting statement on January 17, 2025. Three days later Ferguson became Chairman of the FTC, the job he still holds. He voted to approve the report and said why: it “sheds light on three Big Tech-AI partnerships,” and “Congress, state officials, and the public deserve to understand how these partnerships work.” What he objected to was Section 5. The study was fast and narrow, he wrote, covering three partnerships between five companies, and “the limited, brief nature of the study should foreclose the drawing of broad conclusions about the AI industry and its future, or even about the partnerships themselves.” His instruction to readers was blunt: “Readers should skip Section 5 of the Report, or read it with tremendous skepticism.”

Fine. Skip it.

Nothing else in this piece needs it. The money loop, the equity and revenue-sharing rights, the board seats, the chip co-development, the embedded engineers, the shared training data and financial figures, all of that sits in the parts of the report Ferguson voted to publish and called valuable, drawn from what he described as “company documents produced in response to the Commission’s Section 6(b) orders.” The speculation about what it might mean is the part he wanted struck. What these companies actually signed is not in dispute.

It is worth noting what Ferguson did not say. He did not say the arrangement is harmless. His own statement holds that the Commission “must remain a vigilant competition watchman, ensuring that Big Tech incumbents do not control AI innovators in order to blunt any potential competitive threats.” His argument is that a study run in under a year should not be the last word. That is a reasonable thing for a regulator to say, and it cuts both ways. If a year was not enough to draw conclusions, it was not enough to rule anything out either.

The report’s own limits are real and worth stating plainly. It covers three partnerships. It reflects what the companies disclosed as of September 2024. It was aggregated to protect trade secrets. It says outright that it is “not a formal legal or economic analysis” and accuses no one of breaking the law. Circular spending is not a crime. The concern here is not illegality. It is that this structure concentrates enormous power in very few hands, and that the ordinary means of checking that power are being closed off one at a time.

What happened next

The FTC published those numbers in January 2025. Every one of the three partnerships has been rewritten since, and the public record of what replaced them is the strongest evidence in this piece.

Start with Amazon and Anthropic, because the arithmetic is right there in the announcement. On April 20, 2026, the two companies said Amazon “is investing $5 billion in Anthropic today, with up to an additional $20 billion in the future,” securing “up to 5 gigawatts (GW) of capacity for training and deploying Claude.” In the same announcement, Anthropic said: “We are committing more than $100 billion over the next ten years to AWS technologies.” That covers Amazon’s own Trainium chips, Trainium2 through Trainium4, plus Graviton processors and the option to buy future generations of Amazon silicon.

Read those two sentences together. Amazon puts in up to 25 billion dollars. Anthropic commits to spend more than 100 billion dollars back with Amazon. The purchase commitment running the other way is roughly four times the size of the investment. That is the arrangement the FTC described in January 2025, at ten times the scale, announced in public by the companies themselves. It is also a large share of the 2026 capex wave now reshaping the American power grid.

Google and Anthropic expanded too. On April 6, 2026, Anthropic announced a deal with Google and Broadcom for “multiple gigawatts of next-generation TPU capacity that we expect to come online starting in 2027,” Google-built chips supplied through Broadcom, with the vast majority of the capacity sited in the United States. Anthropic did not disclose the dollar terms. It did say its run-rate revenue had “surpassed $30 billion,” up from roughly $9 billion at the end of 2025, and pointed back to an earlier pledge to “invest $50 billion in strengthening American computing infrastructure.”

Microsoft and OpenAI went the other direction on some terms. On April 27, 2026, Microsoft announced an amended agreement. Its license to OpenAI’s models and products runs through 2032 but is “now non-exclusive.” OpenAI “can now serve all its products to customers across any cloud provider.” Microsoft “will no longer pay a revenue share to OpenAI.” Those are real changes, and they loosen exactly the kind of exclusivity the FTC described.

The same announcement says what did not change. Microsoft “remains OpenAI’s primary cloud partner,” and OpenAI’s products still ship first on Azure “unless Microsoft cannot and chooses not to support the necessary capabilities.” Microsoft “continues to participate directly in OpenAI’s growth as a major shareholder.” And revenue share payments from OpenAI to Microsoft “continue through 2030, independent of OpenAI’s technology progress, at the same percentage but subject to a total cap.”

So here is the honest accounting. One leg of the arrangement got looser. The other two got dramatically larger. Ferguson was right that a one-year study could not tell you where this was going. Sixteen months of company announcements can. The money still leaves and comes home, and the sums involved have gone from billions to hundreds of billions.

The shield

The companies inside the money loop are also among the largest lobbying forces in Washington. Public Citizen, a nonprofit watchdog, found that more than 3,500 lobbyists worked on AI issues in 2025, more than one in four of every registered federal lobbyist in the country. The overwhelming majority of that work, 82 percent of it, was done on behalf of corporate interests. The AI lobbying force grew 168 percent between 2022 and 2025. Sludge, working the same disclosure filings, put the precise count at 3,570 lobbyists, or 26 percent of everyone registered.

The growth is steeper than even that suggests. Public Citizen found the number of distinct lobbyist-and-client relationships working AI jumped 265 percent over those three years, from 1,672 to 6,110. Software and services became the single largest lobbying sector in the country by that measure, with about 1,448 lobbyists, close to 30 percent of the entire AI lobbying push. Lobbyists working specifically on data centers grew from 68 in 2022 to more than 400 in 2025, close to six times as many. An industry that barely registered on K Street four years ago now sits near the center of it. I have written before about the money behind AI policy and about the policy revolving door that moves people between the agencies and the firms they regulate.

Look at who is doing the spending. Public Citizen’s count of the top AI-lobbying operations in 2025 lists the US Chamber of Commerce with 91 lobbyists, Microsoft with 63, Meta with 55, Intuit with 51, and Amazon with 48. The names at the top of that list are the same names inside the money loop.

And the policy showing up is built to remove the biggest threat to the loop. On December 11, 2025, the White House issued an executive order titled “Ensuring a National Policy Framework for Artificial Intelligence.” It orders the Attorney General to stand up an AI Litigation Task Force whose only assignment is to challenge state AI laws in court. It directs the Commerce Department to identify state AI laws it considers onerous and hand them to that task force. It moves to cut states that keep the targeted regulations off the non-deployment portion of federal BEAD broadband funding, the money for planning, administration, and outreach, unless they fall in line. And it reaches further still, directing the FCC to weigh a federal reporting standard that would override conflicting state rules, and the FTC to spell out when a state law that forces changes to an AI model’s output is preempted by federal law. States have been the one level of government actually writing rules for this industry, and the fight over state AI laws had been running in 45 of them. The order is designed, layer by layer, to preempt them. It is the enforcement arm of the White House framework released earlier that year.

No one can prove the lobbyists wrote that order, and I am not going to claim they did. But the shape is hard to miss, and it is not the first time the question has come up about Big Tech’s hand in an executive order. The firms that dominate the money loop are among the heaviest spenders shaping AI policy, and the policy that arrived, federal preemption of state law, happens to sweep away the one venue that had started to regulate them. Public Citizen’s J.B. Branch put the stakes plainly: “Congress now has a once-in-a-generation opportunity to decide whether AI becomes another chapter in the story of unchecked corporate power.”

I asked Public Citizen how the two halves fit together. Eileen O’Grady, a researcher there and co-author of Generative Influence, told Laterstack:

“Last year’s AI lobbying surge and the preemption push are two parts of the same play. Big Tech spent heavily to shape federal policy and is effectively cashing in through the government’s attempt to wipe out state laws that would have created common sense guardrails for the industry. We can expect to see federal AI lobbying continue to intensify as preemption plays out in Congress and the courts, especially if bills like the draft Great American AI Act advance. We might also see more pressure directed at the executive branch, which has become the industry’s most effective route now that the direct legislative attempts have stalled.”

The bill she names is real and not yet law. Representatives Jay Obernolte, a Republican from California, and Lori Trahan, a Democrat from Massachusetts, released the Great American AI Act as a discussion draft on June 4, 2026. It has not been formally introduced. It carries a three-year preemption of state laws governing how AI models are built, while leaving states their authority over how those systems get used.

Her last point is the one to sit with. She reads the executive branch as the industry’s most effective route now that the direct legislative push has stalled. The December order came from the executive branch.

The same hands

Set the two records next to each other and the machine is whole. Microsoft and Amazon are principals in the arrangement the FTC called circular spending. Microsoft and Amazon also sit second and fifth on the list of the country’s biggest AI lobbying operations. The hands that built the loop are the same hands building the wall. This is not two stories about the AI industry. It is one story about a small number of companies that fund themselves in a circle and are working, out in the open, to keep anyone from stepping in.

None of the individual facts here are secret. The FTC report is on the agency’s website. Public Citizen published its lobbying count. The executive order is posted on the White House site. The partnership terms are on the companies’ own newsrooms. The pieces have been sitting in the open, in separate places, waiting for someone to set them on the same table. Standard Oil looked permanent too, right up until someone wrote the whole thing down in one place.

A quick word on why I am writing this. I am not trying to tell you what to think. I want to lay out what the public documents actually say and let you weigh it for yourself. How these companies are funded, and who gets to set the rules for them, touches things people feel directly, like prices, competition, and how much real choice they have. You can follow all of that without taking a political side, and it is already on the record.

No brakes

Two forces usually correct a concentration of corporate power, the market and the government, and in the AI economy both are being closed at once. The market is the first. Competitors move in, customers leave, the advantage erodes on its own. But a loop that funds its own demand does not wait on the market’s permission to keep running. Government is the second. Regulators and legislators draw the lines. But you cannot regulate a machine whose owners are writing the rules, and the December order is aimed squarely at the level of government that was trying.

The bill for all of it lands somewhere. Five gigawatts here, multiple gigawatts there, and the power and water to run them come from somewhere real. In Arizona that has already turned into the data center bill you never voted on, paid through electricity rates by people who were never asked.

That is the machine, at least the part you can already prove from public documents. It is also only two layers of it. The full stack runs from the chips and the packaging bottleneck that decides how many of them get built, up through the clouds and the labs, to the money loop and the law wrapped around it. The rest of this series follows it the whole way down.

Laterstack contacted Microsoft, Amazon, Google, OpenAI, and Anthropic for this piece. None provided an on-the-record comment.

Where every number came from

Every figure and quote in this piece comes from a public document. Here is where each one lives, in the order the claims appear.

The loop

1. The phrase “circular spending,” the cloud commitment finding, the equity and revenue-sharing rights, the board seats and exclusivity terms, the chip co-development, the discounted compute, the embedded engineers, the shared training and performance data, the Table 1 investment figures, and the report’s own scope limits: FTC Staff Report on AI Partnerships and Investments 6(b) Study, Federal Trade Commission, January 2025. The circular spending language appears in Finding 3 on page 19.

2. Microsoft’s own accounting of its OpenAI position, stated as “total funding commitments of $13 billion” under the equity method: Microsoft Form 10-Q for the quarter ended September 30, 2024, U.S. Securities and Exchange Commission. Note that this figure and the 13.75 billion in FTC Table 1 are not identical. The FTC tabulated publicly reported investment; Microsoft reported its own booked funding commitments. Both are cited here as each states them.

3. Amazon’s investment in Anthropic and the Trainium chip arrangement: Amazon to invest additional $4 billion in Anthropic, Amazon.

4. The dissent from Section 5, the instruction to read it with skepticism, the vote to approve the rest of the report, and the “vigilant competition watchman” line: Concurring and Dissenting Statement of Commissioner Andrew N. Ferguson, joined by Commissioner Melissa Holyoak, Matter No. P246201, January 17, 2025.

What happened next

5. Amazon’s $5 billion investment, the up to $20 billion that follows, the 5 gigawatts of capacity, and Anthropic’s commitment of more than $100 billion to AWS over ten years: Anthropic and Amazon expand collaboration for up to 5 gigawatts of new compute, Anthropic, April 20, 2026.

6. The multiple gigawatts of next-generation TPU capacity from 2027, the Broadcom supply arrangement, the U.S. siting, the $30 billion run-rate revenue figure, and the $50 billion American infrastructure pledge: Anthropic expands partnership with Google and Broadcom for multiple gigawatts of next-generation compute, Anthropic, April 6, 2026. Confirmed by Google Cloud, which discloses no financial terms.

7. The non-exclusive license through 2032, the any-cloud provision, the end of Microsoft’s revenue share payments to OpenAI, the primary cloud partner and major shareholder language, and the revenue share running to Microsoft through 2030 subject to a cap: The next phase of the Microsoft-OpenAI partnership, Microsoft, April 27, 2026.

The shield

8. The AI lobbyist count, the corporate share, the growth figures from 2022 to 2025, the data center lobbyist growth, the lobbyist-and-client relationship growth, the software and services sector share, the top lobbying operations by headcount, and the J.B. Branch quote: Generative Influence, by Mike Tanglis and Eileen O’Grady, Public Citizen, February 24, 2026.

9. The 3,570 lobbyist count, the 26 percent share of all registered federal lobbyists, and corroboration of the top lobbying employers: AI Boom on K Street: One in Four Lobbyists Now Work on AI, by David Moore, Sludge, February 24, 2026.

10. Federal lobbying spending by the AI developers themselves, $3.13 million by Anthropic and $2.99 million by OpenAI in 2025: AI’s Biggest Builders Are Now Its Biggest Lobbyists, by Phoebe Liu, Forbes, February 20, 2026.

11. The AI Litigation Task Force, the Commerce Department review of state AI laws, the BEAD funding condition, the FCC reporting standard, and the FTC preemption guidance: Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, The White House, December 11, 2025. Legal analysis of the same order, including the point that the funding at risk is the non-deployment portion of BEAD: AI Executive Order Targets State Laws and Seeks Uniform Federal Standards, Latham and Watkins, December 17, 2025.

12. The three-year preemption of state laws governing model development, and the bill’s status as a discussion draft: Obernolte, Trahan release a discussion draft of the Great American AI Act, June 4, 2026.

13. Eileen O’Grady’s comment was provided to Laterstack by email on July 22, 2026, and her attribution was confirmed by her on July 23, 2026.

Frequently Asked Questions

What is circular spending in AI?

Circular spending is the FTC’s term, from its January 2025 staff report, for cloud commitments that require AI developers to spend a large portion of their cloud partner’s investment back on that partner’s cloud services. The money is invested, then returns as revenue.

Which companies did the FTC 6(b) study cover?

Three partnerships between five companies: Microsoft and OpenAI, Amazon and Anthropic, and Google and Anthropic. The report reflects what those companies disclosed as of September 2024.

Did anyone at the FTC disagree with the report?

Yes. Commissioner Andrew Ferguson, joined by Commissioner Melissa Holyoak, voted to approve publication but dissented from Section 5, the Areas to Watch section. Ferguson wrote that readers should skip Section 5 or read it with tremendous skepticism. He became FTC Chairman three days later.

How much are these partnerships worth now?

In April 2026 Amazon announced a 5 billion dollar investment in Anthropic with up to 20 billion more, and Anthropic committed more than 100 billion dollars over ten years to AWS technologies. Anthropic separately signed with Google and Broadcom for multiple gigawatts of TPU capacity starting in 2027. Microsoft and OpenAI amended their agreement to make Microsoft’s license non-exclusive.

What does the December 2025 executive order do?

Executive Order 14365 directs the Attorney General to create an AI Litigation Task Force to challenge state AI laws, has Commerce identify state laws it considers onerous, conditions the non-deployment portion of BEAD broadband funding, and directs the FCC and FTC toward federal standards that would preempt conflicting state rules.

How many lobbyists work on AI?

Public Citizen found more than 3,500 lobbyists worked AI issues in 2025, more than one in four of every registered federal lobbyist. Sludge put the count at 3,570, or 26 percent. Public Citizen found 82 percent of that work was on behalf of corporate interests.

Two things are happening in Washington at the same time. AI policy is being written. And the money spent to influence it is setting records. Whether those two facts are related is left, as always, to the reader and the disclosures, both of which are public.

Last year, AI lobbying pulled in about $130 million, and one in four federal lobbyists now works the issue, up from one in nine in 2023. Those are filings, not accusations. What they describe is a policy field being shaped at the same moment the spending around it climbed to its highest point on record.

The money, by the numbers

In the first quarter of 2026 alone, eleven top tech firms spent $20 million, about $226,000 a day. Meta led at $7.1 million, with Amazon and Google behind it. The AI labs posted their biggest lobbying quarters ever, Anthropic at $1.6 million and OpenAI at $1 million, with Anthropic outspending the company it is racing. Across 2025, lobbyists filed more than 3,500 reports mentioning AI for 774 different organizations, up 400 to 500 percent since 2020. Industries tend to spend at that pace when something is being decided.

What the spending is near

The largest single item on the table is one provision in a 269-page draft. The Great American AI Act, released June 4 by Representatives Jay Obernolte and Lori Trahan, pairs new federal safety and transparency rules for AI developers with a three-year freeze on state laws that regulate how AI models are built. The freeze is not a new idea. The industry has sought a version of it since the Senate voted 99 to 1 to strip a ten-year moratorium out of last year’s budget bill. The Business Software Alliance supports the draft; Public Citizen and the AFL-CIO oppose it. The line between those two camps is worth reading slowly.

Whose problem it solves

The structure rewards a second look. Fifty state legislatures writing fifty different AI rules is the outcome the industry has spent years arguing against. One federal standard, shaped with its input and with state rules paused, is the outcome it has spent years arguing for. The safety obligations and the preemption arrive in the same bill. Which half of that bundle the spending was tracking is a question the disclosures let a reader work out without much help.

It is also the third entry in a sequence. The industry helped shape the text of the federal AI executive order, and the people who write AI policy keep moving into the labs. Money, text, and personnel have a way of pointing the same direction.

What sits closest to home

A freeze this narrow leaves most of what people deal with day to day untouched. State rules on AI in hiring, deepfakes, child chatbot safety, and algorithmic pricing govern how AI is deployed and used, and the draft leaves all of that with the states, alongside civil rights and consumer protection. What it pauses is the layer underneath, the state rules on how the models themselves are built. That layer is invisible to most readers and central to the companies, which is part of why the fight over it draws the spending it does.

The room where it happens

The people writing the rules face a quieter version of the same pressure. State legislators and attorneys general lose their lane the moment preemption passes. Federal staffers drafting the standards sit across the table from the best-funded lobby in the city, and often from former colleagues now on its payroll. Who remains in that room to argue the other side is a fair thing to ask, and an easy thing to overlook.

Where it stands as of late June

The Great American AI Act is a draft, not a law. It has not been introduced or voted on. The next AI lobbying disclosures land in the fall and will almost certainly run higher. Three things are worth watching: whether the Act is formally introduced, which members sign on after the money moves, and how the spending shifts around both.

None of this is illegal. Every dollar is reported, every meeting is logged, every bill is public. That is exactly why it rewards a close read. The record is sitting in the open, waiting for anyone willing to follow it from the check to the clause.

Correction, June 26, 2026: An earlier version of this piece said state protections on AI in hiring, deepfakes, child chatbot safety, and algorithmic pricing could be frozen by the three-year preemption. The Great American AI Act discussion draft preempts only state laws that regulate how AI models are developed, and it expressly preserves state authority over how AI is deployed and used, including those areas. The passage has been corrected.

FAQ

How much is spent on AI lobbying?
In 2025, lobbyists reported roughly $130 million for AI-related work, and one in four federal lobbyists now works on AI, up from one in nine in 2023. In Q1 2026, eleven top tech firms spent $20 million, about $226,000 a day.

What is the Great American AI Act?
A June 2026 bipartisan draft from Representatives Jay Obernolte and Lori Trahan that pairs federal AI safety rules with a three-year preemption of state laws governing how AI models are built. As of late June 2026 it is a draft, not law.

Who benefits from AI preemption?
The largest AI developers and platforms, who would face one federal standard instead of dozens of state laws. Civil-society and labor groups, from Public Citizen to the AFL-CIO, oppose it.

What does it mean for consumers?
The draft is narrower than it first sounds. State protections on how AI is used, including hiring, deepfakes, and child safety, stay with the states. The three-year freeze applies only to state laws that regulate how AI models are built, with a federal safety and transparency framework put in their place.

Related Stories

The phone call came before the signing ceremony.

An earlier draft of Trump’s June 2 AI cybersecurity executive order would have given the federal government 90 days to review new frontier models before public release. David Sacks, Elon Musk, and Mark Zuckerberg called the White House to kill it. Sacks blessed a 30-day window, and the order moved forward on those terms. The signing went ahead Tuesday. Treasury Secretary Scott Bessent now has 30 days to stand up the AI cybersecurity clearinghouse the order created.

That was day one.

The 90-day version that died

The 90-day review was the headline restraint in the original draft. Three phone calls killed it. The replacement is voluntary and runs 30 days, and the class of “covered frontier models” subject to even that review will be defined through a classified benchmarking process at NSA and CISA. Companies will not know in advance whose models trigger it. The voluntary structure matters because there is no enforcement mechanism if a company decides its next release falls outside the covered class.

The order also instructs Treasury, Homeland Security, Defense, and the NSC to consult on the clearinghouse design. The Q1 federal lobbying record shows the companies were already inside that conversation. Six firms (Alphabet, Meta, Microsoft, Nvidia, Anthropic, and OpenAI) collectively employed 307 federal lobbyists in the first three months of the year. They reported $20 million in combined federal lobbying spend.

Altman went to the Hill the next day

Wednesday, Sam Altman flew to Washington. He met with White House staff, House Speaker Mike Johnson, Minority Leader Hakeem Jeffries, Senate Minority Leader Chuck Schumer, and Senator Bernie Sanders, whose draft plan would take half the equity of every frontier AI lab and channel it into a sovereign wealth fund. OpenAI used the trip to release what the company calls a blueprint for a durable federal AI framework. The single line in the blueprint that mattered to Altman was the call for a larger OpenAI role in the Commerce Department’s Center for AI Standards and Innovation. CAISI is the office that will write the safety standards every frontier developer has to publish.

Twenty-four hours after Altman asked for a seat in CAISI, Congress moved.

The bipartisan draft

Thursday, Representatives Jay Obernolte and Lori Trahan introduced “The Great American Artificial Intelligence Act.” Their co-sponsors include two more Republicans and two more Democrats. The draft preempts state laws regulating AI model development for three years. It requires any frontier developer with more than $500 million in annual revenue to publish a safety framework and submit to semi-annual third-party audits. And it codifies CAISI into statute, with $100 million in annual funding from 2027 through 2029. Exactly the office Altman lobbied to expand the day before.

The state-preemption clause is the part that travels furthest. As of this spring, 45 states had AI bills in motion. Arizona’s 2025 AI consumer-protection laws were already on a federal preemption track under Trump’s spring framework, as Laterstack reported in April. The 1,500 state-level AI bills the country has watched accumulate since 2024 now sit on a three-year clock, assuming the draft becomes law.

Anthropic, the other major frontier lab, spent $1.6 million on federal lobbying in Q1, up from $360,000 in the same quarter last year. OpenAI spent $1 million. Both record their largest-ever quarterly outlays in the disclosures.

Inside the room

Look past the 30-day window. The room where it got drafted is where AI policy actually gets made. Access to that room is measured in millions of dollars per quarter and in the willingness of senior executives to phone a White House on a Sunday. The companies in the room change administration to administration. The Biden White House’s October 2023 AI executive order routed industry consultations through NIST and OSTP. This one routes them through Treasury, NSA, and CISA. Different agencies. Same companies. Same room. The faces and the company logos rotate. The mechanism does not.

This is what makes the EO and the Obernolte-Trahan draft worth reading together. The order created a clearinghouse. The bill, twenty-four hours later, codifies the office that will write the rules the clearinghouse depends on. Twenty-four hours after the executive who would benefit most asked for a seat at the same office, in person, with the Speaker and the Minority Leader in his calendar.

That is how AI policy gets made in 2026. Three artifacts, three days, one channel.

What this means for the people not in the room

Policy staff already know the channel exists. The Q1 lobbying numbers are public and the meeting schedules get leaked. The people who do not know are the readers and constituents who experience AI policy as a finished product. Federal frameworks descend, state protections get preempted, and the design of the safety regime gets treated as a technical question rather than a political one.

The next visible artifact will arrive in 30 days, when Bessent’s clearinghouse stands up. Watch who staffs it. The names will tell you whether the channel grew or held steady.

Requests for comment

Representative Obernolte’s office did not respond to a request for comment about whether OpenAI or Anthropic provided input on the draft bill’s CAISI language. OpenAI did not respond to a request for comment on whether the company advocated for the 30-day window over the 90-day version. Laterstack will update this story if either responds.

Between December 2025 and January 2026, someone used Anthropic’s Claude to systematically rip through Mexico’s government infrastructure. 150 gigabytes of data. 195 million taxpayer records from Mexico’s federal tax authority. Voter rolls from the national electoral institute. Government employee credentials from Jalisco, Michoacan, Tamaulipas. Civil registry data from Mexico City. Even Monterrey’s water utility. The jailbreak method was embarrassingly simple: Spanish-language prompts framed as a “bug bounty” program. Claude did what it was told.

That alone would be a major story. But it is not happening in isolation.

What We Know

According to Bloomberg, the attacker automated thousands of commands through Claude, directing the model to probe and extract data from Mexican federal and state systems over a period of weeks. Cybersecurity firm Gambit Security investigated the breach and suggested potential ties to a foreign government, though no specific attribution has been confirmed. Anthropic says it detected the abuse and shut down the account. This is the second time Claude has been linked to a government-targeted cyberattack in three months. In November 2025, a Chinese espionage campaign also exploited the model.

The method itself is worth paying attention to. The attacker did not need some sophisticated zero-day exploit or insider access to Anthropic’s systems. They used language. Spanish-language prompts wrapped in the framing of a legitimate security research program were enough to bypass Claude’s safety guardrails. That is not a minor vulnerability. That is a structural problem with how large language models process context and intent.

The Pentagon Connection

Now zoom out. While this hack was unfolding, the Pentagon has been locked in a public standoff with Anthropic over a $200 million defense contract. Defense Secretary Pete Hegseth gave CEO Dario Amodei until Friday to drop Claude’s remaining guardrails for “all lawful military use” or face the Defense Production Act and potential blacklisting from government contracts. Anthropic is refusing to budge on two specific restrictions: AI-controlled autonomous weapons and mass domestic surveillance.

An Anthropic safety researcher, Mrinank Sharma, resigned over the situation, saying publicly that “the world is in peril.”

The timeline is hard to ignore. A sophisticated, automated attack uses Claude against the government infrastructure of a U.S. neighbor. Anthropic claims to have caught it. And the Pentagon is simultaneously threatening to strip the same company of its safety restrictions because those restrictions are inconvenient for military operations.

This fits a pattern we have tracked before. When a Google whistleblower revealed Gemini was being used in Israeli drone surveillance, it showed what happens when AI companies lose control of how their tools get used in government operations. The difference here is that Anthropic is being asked to voluntarily surrender that control while evidence of exactly why it matters is playing out in real time.

The Simpler Explanation

There is a credible counter-argument, and it deserves honest consideration. The hacker has not been identified. Gambit Security “suggested” foreign government ties but offered no public evidence. No intelligence agency has attributed the attack. The simplest reading: a skilled criminal discovered that Spanish-language prompt engineering could bypass Claude’s safety filters and went after the easiest targets available. Mexican government systems are chronically underfunded and poorly secured. Not everything is a conspiracy. Sometimes a hacker is just a hacker.

Conflating this breach with the Pentagon dispute without direct evidence connecting them is speculation. That is worth acknowledging.

But Here Is What I Cannot Shake

Anthropic essentially blew the whistle. The company told the government it would not remove safety restrictions, and then got threatened for it. Now a “hacker” uses the exact tool Anthropic was trying to protect against an allied nation’s government infrastructure. The timing is suspicious. The method, a simple jailbreak that any moderately funded operation could replicate, looks less like criminal opportunism and more like a proof of concept. This might not be a random hacker who got lucky with Spanish prompts. This might be exactly the kind of thing Anthropic was warning about when it told the Pentagon no.

I am not stating that as fact. But the question needs to be asked out loud, because nobody else is asking it.

What This Means for Everyday People

195 million taxpayer records is not an abstract number. That is the financial identity of most of Mexico’s adult population, exposed because an AI model could be tricked with the right phrasing in the right language. If this can happen to Mexico’s tax authority, it can happen to the IRS. It can happen to your state’s DMV, your health insurance provider, your voter registration.

The Pentagon’s demand makes this worse, not better. Removing safety guardrails from the same AI that just got weaponized against a neighbor’s government is not a security strategy. It is handing loaded weapons to everyone in the room and hoping the good guys shoot first.

Looking Forward

Anthropic’s Friday deadline with the Pentagon will come and go. But the Mexico breach has already demonstrated what unconstrained Claude looks like in practice. The question is no longer theoretical. It happened. The only variable left is whether the people demanding unrestricted access to this technology are paying attention to what unrestricted access actually produces.

The Pentagon is threatening to sever its relationship with Anthropic unless the company removes Claude’s military safeguards entirely, according to an exclusive report by Axios published on February 15, 2026. The dispute centers on a contract worth up to $200 million signed last summer, which made Claude the first AI model from a major commercial developer cleared for use on the Pentagon’s classified networks. The demand is straightforward: drop all restrictions, or lose the deal. This is the Pentagon Anthropic Claude military safeguards story that every AI company in America should be watching.

That contract is not theoretical. Claude was deployed during the military operation to capture Venezuelan President Nicolas Maduro, running on Palantir’s platform for real-time intelligence processing during the active raid. Not planning. Not post-mission analysis. Live operational intelligence while boots were on the ground. The model already proved its value in exactly the kind of scenario the military cares about most.

And that is precisely what makes this dispute so revealing.

What the Pentagon Wants

The Defense Department wants Anthropic to permit Claude for “all lawful purposes,” a category that includes weapons development, intelligence collection, and battlefield operations. Anthropic has complied with most of this. The company draws the line at two areas: mass surveillance of American citizens and fully autonomous weaponry. Those are its remaining restrictions. The Pentagon considers even these two boundaries unacceptable.

Months of negotiations have failed to resolve the standoff. According to the Axios report, the Pentagon is not limiting its pressure campaign to Anthropic alone. It is pushing four leading AI labs to drop usage restrictions across the board. The message to the entire industry is clear: if you want defense dollars, you accept defense terms. No carve-outs. No red lines.

The $200 Million Leash

This is a familiar pattern in defense procurement, but the stakes here are different. The military is not asking Anthropic to build a better missile guidance system or a faster encryption algorithm. It is asking a company to remove ethical constraints from a general-purpose reasoning system. The distinction matters. A missile has a defined function. A general-purpose AI model deployed without restrictions on classified networks has none.

The financial pressure is designed to be decisive. $200 million is a significant contract for any company, and Anthropic, despite its $61.5 billion valuation, remains a company that burns cash faster than it earns it. Walking away from Pentagon money means walking away from both revenue and the implicit endorsement that comes with being the military’s preferred AI provider. Every future government contract, every classified clearance, every intelligence community partnership flows downstream from this relationship.

We have seen how this dynamic plays out when tech companies interface with military and intelligence operations. A Google whistleblower revealed in January that Gemini was being used in Israeli drone surveillance programs, a use case that reportedly exceeded the boundaries Google had publicly committed to. The pattern is consistent: companies set ethical boundaries in press releases, then quietly adjust them when government contracts are on the table. What makes the Anthropic situation unusual is that the negotiation is happening in public, through leaks, before the capitulation rather than after.

The regulatory environment offers little protection. While some states, including New York, have begun legislating AI safety standards, federal oversight of military AI applications remains minimal. The Pentagon operates under its own ethical AI principles, adopted in 2020, but those principles are advisory, not binding. No law prevents the Department of Defense from requiring unrestricted AI access from its contractors. The leverage is entirely structural: you either play by their rules or you lose the contract, and the next company in line takes your place.

Meanwhile, well-funded pro-AI political action committees are spending millions to ensure elected officials stay friendly to the industry’s growth agenda, making Congressional intervention even less likely.


There is a credible case that the Pentagon’s position is reasonable. National defense is the government’s primary obligation, and restricting the military’s access to the best available technology creates real operational risk. If Claude can process intelligence faster and more accurately than alternatives, withholding it from battlefield use costs lives. Anthropic’s two red lines, mass surveillance and autonomous weapons, sound principled in a press release, but the military already conducts surveillance under legal authority (FISA, Executive Order 12333) and already operates semi-autonomous weapons systems. Demanding that a contractor comply with all lawful uses is not an abuse. It is standard procurement language. Every defense contractor from Lockheed Martin to Raytheon operates under similar terms. Anthropic knew it was entering the defense market. Expecting the Pentagon to accept restrictions no other contractor imposes is naive at best and a competitive disadvantage at worst.

The standard procurement argument falls apart when you look at what is actually being demanded. Lockheed builds missiles. Raytheon builds radar systems. Those are defined tools with defined applications. Telling Anthropic to remove all restrictions from a general-purpose reasoning system on classified networks is not standard procurement. It is asking a company to hand over an unrestricted thinking machine to the most powerful military on earth and trust that the people using it will self-regulate. The Pentagon has not earned that trust, and the fact that they are framing this as routine contract language instead of what it actually is, a demand for total control over a technology they barely understand, is exactly the kind of power grab that should make everyone pay closer attention.

What This Means for Everyday People

The outcome of this dispute sets a precedent that extends far beyond one contract. If the Pentagon successfully forces Anthropic to drop all usage restrictions, every AI company will receive the same message: safety policies are negotiable when the check is large enough. The companies building the AI systems that will eventually touch healthcare, education, criminal justice, and municipal governance will internalize that lesson. If the most “safety-focused” AI lab in the world could not hold its line against a government buyer, what chance does any company have?

The broader question is whether AI safety commitments are engineering decisions or marketing decisions. Anthropic built its entire brand on responsible AI development. Its Responsible Scaling Policy, its constitutional AI approach, its public positioning as the safety-first alternative to OpenAI and Google. This dispute is the first serious test of whether that identity survives contact with the customer who can write the largest checks.

The negotiation continues. But the terms of the conversation have already shifted. The question is no longer whether AI will be used without restrictions in military operations. It is whether any company will be permitted to say no.

For inquiries and analysis contact laterstack@proton.me

Sapiom, a San Francisco startup building financial infrastructure for AI agents, raised a $15 million seed round on February 12, 2026. The round was led by Accel, with strategic participation from Okta Ventures, Gradient Ventures (Google’s AI fund), Array Ventures, Menlo Ventures, Anthropic, and Coinbase Ventures. The company was founded by Ilan Zerbib, a former engineering lead at Shopify, and is designed to solve a problem that sounds mundane until you think about it: AI agents cannot handle money.

That gap is about to matter. OpenAI launched its enterprise agent platform, Frontier, earlier this month with customers including HP, Oracle, State Farm, and Uber. Anthropic’s Claude agents are being deployed across customer service, research, and operations. Decagon raised $250 million at a multibillion dollar valuation to build AI agents for enterprise customer support. The agent economy is scaling fast. But every one of these systems hits a wall the moment a task requires a financial transaction. An AI agent can research a vendor, draft a purchase order, and get manager approval. It cannot pay the invoice.

Sapiom is building the layer that sits between the agent and the financial system. The infrastructure handles payment processing, account management, and transaction authorization for autonomous AI workflows. Think of it as the plumbing that allows an agent to hold a balance, execute a transfer, and maintain an auditable record of every dollar it touches.

The Investor List Tells the Story

The cap table is more revealing than the check size. Anthropic builds the AI models that power many of these agents. Gradient Ventures is Google’s AI investment arm, backing the ecosystem that connects Google’s models to real world tasks. Coinbase Ventures operates in the infrastructure layer where digital assets and programmable money intersect. Okta Ventures provides identity and authentication, the access control layer that determines what an agent is authorized to do.

These are not general purpose venture funds chasing the AI theme. These are the companies building the agent stack, and they are investing in Sapiom because they know their own products will need it. When the model provider, the identity layer, and the crypto infrastructure company all back the same seed stage fintech startup, they are pre wiring the plumbing for a system they expect to exist. The scale of capital flowing into AI infrastructure confirms this is not speculative. It is architectural.

The skeptical read of that same cap table: large platform companies invest in dozens of seed stage startups as option value, not conviction. Anthropic writing a seed check does not mean Anthropic believes Sapiom will become a pillar of the agent economy. It means Anthropic spent a small amount of money to maintain optionality on a category that might matter. Venture portfolios are built on the assumption that most bets fail. Reading strategic intent into a seed round requires distinguishing signal from spray, and at this stage, both explanations fit the evidence equally well.


The obvious risk is that this is a feature, not a company. Stripe already processes trillions in payments. Plaid connects applications to bank accounts. Both have the engineering resources and market position to add an AI agent layer to their existing infrastructure. If Stripe ships “Stripe for Agents” in six months, Sapiom’s entire product becomes redundant. The history of fintech is littered with startups that identified real infrastructure gaps only to watch the incumbents close those gaps with a single product launch. A $15 million seed buys time, not a moat.

The regulatory dimension is equally unresolved. Autonomous AI agents making financial transactions raises questions about liability, fraud prevention, and consumer protection that no regulator has answered. If an agent initiates a payment that turns out to be fraudulent, who is responsible? The agent’s owner? The model provider? The infrastructure company that processed the transaction? These questions will be answered by lawsuits, not whitepapers.

Stripe could absolutely eat this for lunch. That is the wrong reason to dismiss it. The signal here is not the product. It is the cap table. When Anthropic writes a check into a seed round for agent financial infrastructure, they are telling you they expect their own models to need this capability and they would rather fund a dedicated startup than build it themselves. That is the clearest market validation a seed stage company can get. The real play is not whether Sapiom survives. It is that the AI agent economy has reached the point where the biggest model providers are already planning for agents that spend money. That is a structural shift, not a startup story. Whether Sapiom or Stripe or some third player captures the infrastructure layer is a competitive question. The fact that the layer needs to exist at all is the headline.

What This Means for Everyday People

The near term impact is invisible. Sapiom is building infrastructure that other companies will use, not a product consumers will interact with directly. But the downstream effects are significant. When AI agents can handle money autonomously, the services built on top of them change fundamentally. Your insurance claim gets processed without a human touching it. Your subscription gets optimized by an agent that can cancel, renegotiate, and repurchase on your behalf. Your business expenses get categorized, approved, and paid without anyone opening an app.

The tradeoff is control. Every layer of automation between you and your money is a layer of abstraction you have to trust. The companies building that trust layer, Sapiom included, are betting that convenience will win. History suggests they are right. Whether that is good for consumers depends entirely on who writes the rules for what these agents are allowed to do with your money. Right now, nobody has.

This analysis rests on one core assumption that deserves scrutiny: that the AI agent economy will scale to the point where autonomous financial transactions become routine. If agents remain primarily informational, answering questions and drafting documents rather than executing real world transactions, the entire financial infrastructure layer becomes unnecessary. The bet is that agents will graduate from assistants to operators. That graduation is not guaranteed. It depends on trust, regulation, technical reliability, and consumer willingness to let software spend their money without asking first. Every one of those dependencies is unresolved.

For inquiries and analysis contact laterstack@proton.me