The Help Desk Became a Vendor
California's new AI assistant for state services and Anthropic's expanded Claude for Government contract, both surfacing the same week Gen. Caine asked defence industry to accept more "shared risk" and a nuclear agency's top IT official said industry "has not done enough" on security, are the same story told twice. Each is a procurement decision, made through contracts with named vendors, that arrives wearing the language of citizen service or military partnership. The chatbot that answers a resident's question about a benefits application and the software meant to help defence systems perform run through the same kind of commercial vendor relationship, with the same unresolved question of who is liable when the automated answer is wrong. Government's oldest problem, buying technology it does not fully control from companies it cannot fully audit, has not disappeared just because the front end now sounds conversational. Broadband rollout under BEAD, missile production, and telephone exchanges inside post offices all show the same pattern repeating across decades.
Listen to this piece 9 min
California launched an AI assistant this week to help residents navigate state services. Read the announcement on its own and it sounds like a public information story: a state trying to make bureaucracy less painful for the people who have to deal with it. Read it next to Anthropic adding Fable 5.1 to Claude for Government, and the same week's reporting from the Pentagon on "shared risk" and a nuclear agency's frank admission about industry security failures, and it stops looking like a service story. It looks like procurement, dressed up in the vocabulary of help.
What California actually bought
A state government does not build a large language model from scratch. It licenses one, wraps it in branding, and calls the result an assistant. That is a contract, with a vendor, with terms, with a company on the other end that trains, hosts, and updates the model residents will now be talking to about their benefits, their taxes, their applications. The "front door to public services" language obscures a simpler fact: the state has outsourced a piece of its interface with citizens to a private company's software, and the accountability structure for that software is a commercial agreement, not a public one.
Anthropic's own announcement that it is adding Fable 5.1 to Claude for Government is the vendor-side mirror of the same event. One is presented as a public service upgrade, the other as a product update. They are describing the same transaction from opposite ends of the table. Nobody involved is lying, exactly, but nobody is being asked the question that matters most: what happens when the vendor's model gives a resident wrong information about eligibility, and whose job is it to fix that, and who pays if it causes harm?
The Pentagon's version of the same deal
General Caine's comments urging industry to "lean more into shared risk" when delivering technology for the military are worth reading slowly, because "shared risk" is a procurement term wearing a partnership costume. It means the Pentagon wants contractors to accept more exposure, financial or technical, in exchange for faster delivery. It is not a description of collaboration; it is a negotiating position, aimed at vendors who have historically been happy to sell government exquisite, expensive, slow-to-field systems while keeping risk on the government's side of the ledger.
The Pentagon is also, per this week's reporting, still working through "heaps of industry feedback" on CMMC reform, the cybersecurity certification regime that contractors have to meet to keep selling to defence. That process is procurement policy in its most literal form: the rules by which a vendor is allowed to remain a vendor. It has nothing to do with service delivery and everything to do with who gets to hold the contract. Meanwhile a company called Covenant has unveiled a "deep precision strike" missile it plans to build by the thousands, a reminder that even hardware procurement now moves at a pace and scale that assumes industry, not government, is setting the tempo.
Security officials say the quiet part out loud
The most useful sentence in this week's coverage came from the nuclear agency's top IT official, who said plainly that "industry has not done enough" on security. That is an unusually blunt admission for a government official to make about the companies it depends on, and it is worth taking seriously as a warning that applies well beyond nuclear infrastructure. If a security official inside an agency that handles the most sensitive material in government is willing to say the vendor relationship is falling short, there is no reason to assume the vendor relationships behind a state benefits chatbot are more mature.
The through-line from the nuclear agency's official to Caine's "shared risk" comment to California's assistant launch is the same: government is buying capability it cannot fully build or audit itself, from a small number of large technology companies, and is increasingly candid, in defence circles at least, about the fact that this arrangement has not been secured properly. The civilian side of government has not caught up to that candour. It is still calling the arrangement a service.
The infrastructure precedent
This is not a new pattern, and broadband policy shows how long it has been running. Researchers say about 1 million BEAD-eligible locations remain unconnected, a number that exists precisely because rural broadband has always depended on private carriers deciding it is worth their while to build. Washington State is moving along on its own BEAD grants, and Archtop Fiber has just named a new chief executive as its founder moves to executive chairman, ordinary corporate housekeeping that nonetheless determines which company controls a piece of public infrastructure funding. Comcast, for its part, is expecting more broadband losses this quarter than last, which is a reminder that the private companies government leans on for universal service goals are also answering to shareholders first.
None of this is unprecedented. As Broadband Breakfast has noted, America once tried putting telephones inside the post office, an attempt to fuse public infrastructure and private communications technology under one roof that did not last. The instinct to bolt a new technology onto an existing public institution and call it modernisation is old. So is the eventual discovery that the technology company on the other side of the contract has its own priorities, its own losses to report to investors, its own leadership changes that have nothing to do with the public it is nominally serving.
Even the Federal Register has spent time this year on the mechanics of who has to format things and how: the FCC's final rule on Telecommunications Relay Service ASCII formatting is a small, unglamorous example of government specifying exactly what a vendor must deliver, down to the file format, because it has learned that leaving the details to the vendor's discretion produces inconsistent results. If ASCII formatting for relay services needs a federal rule to keep vendors honest, an AI assistant answering questions about state benefits needs at least that much scrutiny.
Who pays when the vendor fails
The gap between service language and vendor accountability is not abstract. It shows up in how slowly harm gets addressed when something goes wrong. The FTC's own consumer alert this month, about what to do if an intimate image is shared online without consent, exists because platforms did not build in protection or recourse by default; the burden fell to the person harmed to find the right government page and follow the right steps. A lawsuit against Amazon alleging it refused pregnant workers bathroom breaks and chairs tells a related story from a different industry: large companies operating at scale, with enormous resources, still routinely externalise the cost of getting things wrong onto the people with the least power to fight back.
Apply that pattern to a government chatbot. If Claude for Government or California's assistant gives a resident inaccurate guidance about a deadline or an eligibility rule, the resident is the one who misses the deadline or loses the benefit. The vendor's exposure, contractually, is likely to be limited. The state's exposure is political, at best. The individual absorbs the actual cost. That is exactly the shape of the recourse gap the FTC alert and the Amazon lawsuit describe, just moved from social media platforms and warehouse floors to the desk of a caseworker or the login page of a benefits portal.
The costume doesn't fit
None of this means an AI assistant is a bad idea, or that shared risk arrangements are wrong for defence procurement. It means the framing is doing work it should not be allowed to do. When a state government calls a vendor's chatbot a "help desk," it borrows the trust people have in public institutions and lends it to a company's product. When the Pentagon calls a contract renegotiation "shared risk," it borrows the language of partnership for what is, functionally, a request that industry absorb more exposure.
What is different now is the speed at which the service language gets attached to the procurement decision, often on the same day, often in the same press release. California's residents deserve to know they are talking to a vendor's product when they ask the state a question. So does anyone reading a Pentagon announcement about "shared risk" and assuming it describes a partnership rather than a negotiation. Call the thing what it is: a contract, with a vendor, and a set of terms that residents and taxpayers never got to see, let alone negotiate.
Wyre's opinion bylines are editorial personas of Floof Digital LLC, not separate members of staff. Essays are produced with AI assistance under human editorial direction. How Wyre works.