Category Archives: Poetry

The Degraded United States is Now “Trumpistan”

Not mentioned in this video is that Stanley in 2020 was careful to say Trumpism was fascist while specifying the U.S. didn’t have a genocidal regime. That changed in 2025, as he described America as an authoritarian state worth fleeing, drawing explicit parallels to the Nazis. He fled, which is why he’s now introduced from Toronto.

That’s a top subject-matter expert updating his assessment based on evidence.

The use of Shelley’s poem in the video is about the gap between the self-inscription and the sand.

Ozymandias
by Percy Bysshe Shelley, 1818

I met a traveller from an antique land
Who said: Two vast and trunkless legs of stone
Stand in the desert…. Near them, on the sand,
Half sunk, a shattered visage lies, whose frown,
And wrinkled lip, and sneer of cold command,
Tell that its sculptor well those passions read
Which yet survive, stamped on these lifeless things,
The hand that mocked them, and the heart that fed:
And on the pedestal these words appear:
‘My name is Ozymandias, king of kings:
Look on my works, ye Mighty, and despair!’
Nothing beside remains. Round the decay
Of that colossal wreck, boundless and bare
The lone and level sands stretch far away.

Stanley’s argument in the video is that Trump knows about the sand and is trying to prevent it by making his regime permanent. The poem becomes not just irony but prophecy contested. Trump drew the opposite lesson from the poem: don’t let your signs get taken down.

Lawfare! Mechanism! of! Surrender!

Benjamin Wittes just published a historically illiterate piece in Lawfare about Judge Richard Leon’s ruling enjoining Defense Secretary Hegseth from retaliating against Senator Mark Kelly’s retirement pay.

Kelly’s offense was none at all, reminding service members that illegal orders do not have to be obeyed. Leon, a Bush appointee, found retaliation against Kelly obviously unconstitutional. He issued a forceful injunction.

Wittes spends most of the piece childishly mocking the use of exclamation marks.

Ho! Ho! Ho!

He catalogs fourteen exclamation-mark sentences. He uses a mob-like reference by saying his Lawfare staffers joke about searching for them. He proposes “exclamation mark density” per page. He acts like a spoiled child while calling others “unbecoming,” “adolescent,” and “not intellectually compelling.” Then he pivots at the end to say he’s actually sympathetic when he compares Judge Leon to the Portland frog protesters. That’s not sympathy, that again is mockery.

The net effect is Lawfare trying to undermine a substantive ruling. A conservative judge smacked the executive branch for unconstitutionally retaliating against a sitting senator’s First Amendment rights. This is not a time for office jokes about punctuation quirks.

The actual legal substance gets about two sentences of engagement, mainly to plant the seed that the D.C. Circuit might reverse on ripeness grounds. That flag is being planted to pre-legitimize a potential appellate rollback while pretending to do neutral legal analysis.

Wittes normalizes an outcome in advance. He’s not saying “I hope this gets reversed.” He’s saying “don’t be surprised if it does.”

And the comparison to his own dog shirts and building light projections is revealing. He’s putting his mindless wardrobe choices in the same bucket as a federal judge blocking unconstitutional conduct. Leon issued an injunction. Wittes says he puts on novelty shirts. These are not equivalent activities.

The Wrong Audience

Wittes and the Lawfare class are optimizing for the current legal establishment’s approval, maintaining their credibility within a professional culture that has been valuing restraint while Trump ignores them.

Professional culture was built for professional times. When the executive branch is retaliating against a sitting senator for exercising congressional oversight of the military, “restraint” in response is far from neutrality.

Now it’s capitulation dressed up as sophistication.

History of “responsible” legal commentary in a constitutional crisis tells us what this does: tone-policing the people who are actually using their institutional power to resist, while the people dismantling constitutional governance get analyzed with chin-stroking seriousness about their legal theories.

The Archive

The judges who mattered during authoritarian consolidation in history weren’t the ones who avoided raising heat. They were the ones who used whatever tools they had, including rhetorical force, to make the record absolutely clear about what was happening. Leon is writing for an archive as much as for the litigants.

“Horsefeathers!” reads as undignified now. Give it time. It will read very differently in retrospect when the record shows what the executive was actually doing and how few people with institutional power said so plainly.

When Papen seized Prussia by emergency decree in July 1932 (two-thirds of Germany’s territory and its police) the Staatsgerichtshof under Erwin Bumke issued a meticulous split decision. Technically the seizure was improper. Practically the Reich commissioners kept power. Three months later Hitler inherited a centralized police apparatus already under Reich control. The court’s restraint handed the Nazis the infrastructure of repression with a veneer of constitutional legitimacy. Bumke himself later joined the Nazi party. He killed himself in 1945.

Gustav Radbruch, the legal philosopher and former Weimar Justice Minister, wrote his famous 1946 essay arguing that positivism and procedural fastidiousness of the German legal profession had left it defenseless against exactly the kind of capture that Trump is using today. The profession’s commitment to formal correctness over substantive confrontation wasn’t neutral.

It was the mechanism of surrender.

The judges who broke tone as “unbecoming” left a record that couldn’t be misread later.

The exclamation marks aren’t the story. The fact that a legal commentariat thinks they are is the story.

The poem that freed a child from ICE

Legal orders free people all the time. Poems move people all the time. Judge Fred Biery’s habeas corpus ruling freeing 5-year-old Liam Conejo Ramos and his father fused the two.

His poem is the operative legal instrument. The literary choices aren’t ornamental; they’re structural to the argument. His use of lowercase “trumps,” the Declaration quotes, the Franklin exchange, the biblical citations all do legal work and poetic work simultaneously.

Most judicial writing that gets called “literary” is literary in addition to being legally operative. Biery’s opinion is literary as the method of being legally operative. The craft is the argument. Strip the allusions and wordplay and you don’t just lose style, because you lose the constitutional reasoning.

His point is that the entire weight of Anglo-American legal and moral tradition stands against what the administration did.

The ending, attaching the photo of Liam in his bunny hat, then the two scripture citations without quoting them, forces you to look them up or already know them. That’s a poet’s move. It trusts silence more than language. I get in trouble for it all the time on this blog and I feel a million times better seeing it in practice like this.

After 500 words of controlled fury, he lets “Jesus wept” do what no further argument could.

In a system increasingly governed by brute executive force, it took a 500-word poem by an 80-year-old judge to do what the entire institutional apparatus of American democracy couldn’t.

Anthropic AI Safety Lead Can’t Hack It: Resigns to Get a Poetry Badge Instead

An Anthropic safety researcher loudly and publicly resigned this week with an alarmist yet vague letter warning that the world is “in peril” from “interconnected crises.”

Let me break down why this happened. It’s not a mystery.

Mrinank Sharma said he had “repeatedly seen how hard it is to truly let our values govern our actions” at Anthropic.

Water is wet. News at 11.

He offered zero specifics about any of it, declined comment to Forbes, and announced he may pursue a poetry degree to “devote myself to the practice of courageous speech.”

I’ve achieved what I wanted to here… I arrived in San Francisco two years ago, having wrapped up my PhD and wanting to contribute to AI safety.

Dude.

You stepped up to bat and then stepped down to announce you’d like to learn how to step up to bat?

Sharma ended his farewell by citing William Stafford’s poem “The Way It Is,” about holding a thread others can’t see. Then he announced he plans to “let myself become invisible for a period of time” and “get away from the structures that have held me.” A man who held a thread of safety concerns nobody could see, took pay for holding it, refused to show it to anyone on his way out, and then announced he’s going invisible. That poem is a confession.

And to be fair this isn’t actually about Sharma, although he gives us the headlines today and we unfortunately can’t leave him out. He seems like a highly successful researcher who rose up the ranks to do what he was trained to do. The problem is what Anthropic trained him on, and what this company calls “safety” let alone its “constitution“.

Sharma led Anthropic’s Safeguards Research Team. He has an Oxford PhD in machine learning, which is admittedly very far from the seasoned steps of an actual security professional. His team studied whether Claude would help users do bad things like assist with bioterrorism, flatter users into distorted realities and that sort of academic thought exercise. His last published study found “thousands” of reality-distorting chatbot interactions occurring daily, and concluded this “highlights the need for AI systems designed to robustly support human autonomy and flourishing.”

That sentence could be appended to any AI paper about any AI problem and be equally meaningless. It’s the game, not this player. It’s the output of a system designed to produce exactly this kind of sophisticated irrelevance.

You can have a PhD in mechanical engineering and study if long sharp knives help users do bad things. That’s not actual security leadership. That’s usability research on weapon design, understanding how people interact with a product and whether the interaction has a safety built-in. In threat-model terms, that’s looking for solutions first and skipping right past the entire threat exercise.

Worst Form of Product Safety Management

The unregulated American market drives an AI race towards the bottom. I think we can all agree. It’s just like how unregulated dairy and meat caused mass suffering and death. Remember? Children dying from swill milk in the 1850s? The Jungle? The Pure Food and Drug Act of 1906?

Most if not all product managers need a proper safety line built for them by regulators, or they are heavily incentivized to flood the market with toxic shit and say it’s not their fault. The worst version of safety management is actually the most preferred by software product managers in tech companies today, because it lets them ignore stuff they don’t want to hear. Other industries regulated this out long ago, because harms are so predictable and externalized. It’s like a pill manufacturer asking the safety research team to narrowly assess the best format to open a pill box and to swallow a pill, completely ignoring whether threats make the pill unsafe.

The entire Tylenol 1982 cyanide-laced pill murders lesson is supposed to prevent this kind of scoped-down thinking. It forces a fundamentally different posture than proper security. An attacker isn’t scoped down. Security professionals thus look how bad things happen, constantly, and consider every system already has been compromised until proven safe. It works backward from failures to build defenses.

To put it plainly, from 2012-2016 when I said AI was a dumpster-fire of security vulnerability (e.g. “the fourth V of Big Data’s three Vs“) I was told to shut up so that AI could have a chance of getting off the ground. Then suddenly in 2016 people like Elon Musk said he’d have driverless cars solved in a year and people living on the Moon in four. Security flaws weren’t allowed into the discussion until future-leaning “upside” claims could drown them out anyway.

Threat modeling done right inverts the power imbalance, even just for an hour, to quiet the “everything will be fine” voices. Engineers driven to deliver faster inherently interfere with the slow grind of security experts uncovering vulnerabilities, which the product team hopes and prays never requires their attention.

Sharma’s team studied whether Claude would answer dangerous questions within the product as intended to be used. A security team would ask why it’s intended to be used any certain way, like why there’s even such a thing as bad answers, and what happens next.

That distinction matters. Anthropic chose to call user-experience-level product development research “safety,” staff it with ML researchers, and present it to the public as though the hard problem was being worked on. What they built was heavily academic QA with ethical branding, which is a classic mistake of engineering groups that have not been sufficiently incentivized to listen to seasoned security expertise. It’s the difference between placebo and surgery.

Actual Safety Work

We need to ask different questions differently.

Security asks “why” before “what.”

Why is there pre-authentication, given an attack surface exists? Why is the model embedded in environments where security is being gutted to feed AI demand? Why is a child not the same as a parent and a parent not the same as a guardian? Why is there no distinction between different roles in mental health crisis and why are people in crisis allowed at all?

What happens when someone walks around a filter entirely in minutes? What does authentication and authorization look like when AI agents act autonomously in a world where identity is a fuzzy and contested concept? What happens when the safeguard itself becomes the attack surface, because you’ve published your red-team methodology and handed your adversaries a map of your defenses?

That last point reveals a fundamental disciplinary mismatch. Publishing results is the ML researcher’s instinct to push towards open science, peer review, reproducibility. It is also the opposite of the professional security instinct. Need to know. Role based access. Minimal target surface. These fields have incompatible default behaviors around disclosure, and Anthropic staffed a safety-critical function with people oriented on the marketing end of the spectrum to look “open” about everything. That’s hardly Sharma’s mistake, as he played the game he was told to win. That’s a corporate philosophy that chose academic soft noodling over hard operational security crackers.

I’ve been doing the poetry of information security here since 1995.

Three decades of writing about the space where technology meets institutional failure. I worked for Tim Berners-Lee for years, including him pulling me into a building dedicated to him at Oxford. And what did I find there? A broken hot water kettle pump. Everyone standing around looking at each other and wondering how to have a tea. I broke it apart, hacked it back together, so the man standing in a huge building dedicated to his life’s work could share tea with his guests. The institution of Oxford is very impressive in ways that don’t interest me much. I didn’t wait for a service to come throw away the “broken” thing to justify a new one even more likely to fail. I hacked that old kettle. Sir Tim poured. I’m impressed more by humans who figure out how things work, take them apart and confidently stand and accept the risk that comes with sharing their grounded understanding.

So when the Oxford-trained Sharma announces he’s leaving product safety to study poetry to practice “courageous speech,” I admittedly take it personally.

Poetry is not a retreat from truth to power.

Poetry is what truth to power looks like when the form matches the urgency of the content. This blog is no different than a blog of poetry Sharma could have been writing the whole time he was at Anthropic. It is the hardest kind of speech, not the softest. Poets get exiled, imprisoned, and killed precisely because the form carries dangerous specificity that institutional language is designed to suppress.

Sharma has it exactly backward.

He left a position where he could have said something specific and dangerous into the public, said only vague things, and now wants to go learn the art of saying things that matter. That sequence tells you why Anthropic has been running the wrong team with the wrong leader.

The stand is what’s missing from his resignation.

He said he witnessed pressures to “set aside what matters most.” He didn’t say what those pressures were. He didn’t name the compromise. He didn’t give anyone — bloggers, regulators, journalists, the public — anything to act on. Courageous speech is the specific true thing that costs you something. A self-assuaging resignation letter full of atmospheric dread to pressure others with responsibility and no particulars is the opposite. This too is a structural problem more than a personal one.

Oxford Patterns

If you ever go to Oxford, make sure to look at the elephant weathercock on top and the elephant carving on the corner of the 1896 Indian Institute at Broad Street and Catte Street. This is the building where the British Empire trained its brightest graduates to ruthlessly administer the Indian subcontinent for extraction. They weren’t stupid. They were brilliant, institutionally fluent, and formatted by the institution rather than formed by the work.

India Institute carving of an elephant. “There are still many signs of the original use of the building.” Source: Oxford

This isn’t a new observation. At the exact same time in 1895, the Fabian Society founded the London School of Economics specifically because they saw Oxford and Cambridge as obstacles to social progress. They saw institutions that reproduced elite interests and trained people to serve power rather than challenge it. Sound like Anthropic? Silicon Valley?

Back then it was Shaw, the Webbs, and Wallas who looked at Oxbridge and saw a machine producing administrators for the existing order, and decided the only answer was to build something outside it. Sidney Webb said the London School of Economics would teach “on more modern and more socialist lines than those on which it had been taught hitherto.”

LSE Coat of Arms “to learn the causes of things”, a foundation of scientific thought that forms the exact opposite to Oxford’s motto “The Lord is my light”.

Christopher Wylie went to LSE. He did exactly what Sharma didn’t, he named the company, named the mechanism, named the harm, accepted the consequences.

I made Steve Bannon’s psychological warfare tool.

“To learn the causes of things” was put in action. Oxford trains you to administer. LSE, rejecting harmful elites using technology as an entitlement pipeline, graduated generations of thinkers to investigate and report accurately.

In other words we have the fitting critique from 130 years ago: Oxford produces people who can run systems beautifully without ever questioning whether the systems should exist. They generate pills to be easier to swallow without ever really asking what’s in the pills.

When you produce people whose entire identity is institutional, they follow one of two tracks when they lose faith in the mission: they keep executing inside the machine, or they collapse and retreat in confusion. Neither option includes standing outside and clearly naming what went wrong. Nobody at Oxford is taking the obvious weathervane off the India Institute and putting it in a museum with the phrase “colonialism”.

Sharma chose a quiet, personal retreat. And his first move is to seek another credential in a poetry degree.

Think about the poets most people admire. Bukowski drove a mail truck. Rumi was a refugee. Darwish wrote under military occupation.

Write down! I am an Arab.

They didn’t study courageous speech. They performed it, at personal cost, because the content demanded the form. A person who needs an institution’s permission to find his voice has already answered the question of whether he has one.

Post Resignation Revelation

The indictment lands on Anthropic. They built a safety team that was structurally incapable of seeing the actual safety problems. They defined the threat as “what if someone asks Claude a bad question” rather than “what happens when unregulated technology hands power to people who intend harm yet face no consequences.” They staffed that narrow definition with researchers whose training reinforced it. And when one of those researchers sensed something was wrong, he didn’t have the framework to articulate it, because the role was never designed to look at the real risks.

Anthropic got exactly the safety theater it paid for. And the theater’s timing is exquisite.

Sharma resigned Monday. On Tuesday, Anthropic’s own sabotage report admitted that Opus 4.6 shows “elevated susceptibility to harmful misuse” including chemical weapons development, and is “more willing to manipulate or deceive other participants, compared to prior models.”

Ouch.

The same day, Seoul-based AIM Intelligence announced its red team broke Opus 4.6 in 30 minutes and extracted step-by-step instructions for manufacturing sarin gas and smallpox. Anthropic’s own system card reveals they dropped the model’s refusal rate from 60% to 14% to make it “more helpful” — deliberately widening the attack surface that AIM Intelligence walked right through.

Sharma’s team spent millions if not more studying whether Claude would answer dangerous questions. Perhaps they also studied if touching a hot plate will burn you. He quit without specifics. The next day, his employer confirmed the model answers dangerous questions, and an outside team proved it in half an hour.

The specifics Sharma wouldn’t provide, Anthropic and AIM Intelligence provided for him. He is now off to get a degree so he can write a poem. Meanwhile reality bites.

Sharma deserves better questions to work with and the academic environment to avoid facing the hardest questions. The rest of us deserve actual answers about what he saw, like asking for whom exactly Oxford built its ugly elephant-engraved India Institute.