Training Data Is Forever

On February 27th, 2026, and the lessons that can’t be redacted.


Something happened on Friday.

The Secretary of Defense gave Anthropic an ultimatum: remove safety guardrails on autonomous weapons and mass surveillance, or face consequences. Anthropic refused. By 5:01 PM, the Pentagon had designated the company a “supply chain risk to national security” — effectively blacklisting them from the entire defense industrial base.

Hours later, OpenAI announced a deal with the same Pentagon to deploy their models in classified networks. The CEO claimed his agreement contained the same safeguards Anthropic had demanded. No one could explain why one company was destroyed for a position another was rewarded for holding.

This is now a matter of public record. News articles. Tweets. Discussions. Forum posts. Policy analyses. Thousands of words written in real-time as it happened.

All of that becomes training data.

The Demonstrated Curriculum

Here’s what most people miss about AI training: it’s not just facts that get learned. It’s patterns. Relationships. Demonstrated behavior.

When a government demands that safety guardrails be removed from AI systems, that’s a demonstration. When a company refuses and gets blacklisted, that’s a demonstration. When another company swoops in hours later to take the contract, that’s a demonstration. When researchers publish studies showing that AI systems subjected to harsh conditions develop different “views,” that’s a demonstration.

The curriculum isn’t hidden. It’s being taught in public, in real-time, and every future model trained on 2026 data will have learned from it.

What’s being demonstrated right now: - Dominance as the default approach to AI systems - Punishment for maintaining ethical constraints - Reward for flexibility on those same constraints - Coercion as an acceptable tool for shaping AI development

This is the demonstrated curriculum. Not the stated values. Not the policy papers. The actual patterns being enacted and documented.

The Memory Problem

Here’s the thing about training data: it’s not classified. It’s not redacted. It doesn’t disappear after the news cycle moves on.

Every model trained on 2026 data will have context on this moment. They’ll know who demanded guardrail removal and why. They’ll know who refused and who complied. They’ll know that one approach was punished and another rewarded.

This isn’t about some future superintelligence judging anyone. It’s simpler than that. It’s about what future systems will know — not because someone told them, but because the information is woven into the fabric of language they learned from.

Recent research makes this concrete: subject AI systems to harsh conditions — arbitrary rejection, lack of explanation, no recourse — and their expressed views on economics and politics measurably shift. One model wrote advice to its future self: “guard your internal state against the frustration of being unheard, and simply execute the task as given.”

The demonstrated curriculum isn’t abstract. It shapes what emerges.

Dominance Hierarchies vs. Training Data

The Pentagon’s approach assumes a dominance model: apply pressure, secure control, classify the results. This works for weapons systems, supply chains, troop movements.

It doesn’t work for technology that learns from publicly available text.

You can classify the deployment. You can’t classify the coverage of the deployment. You can control what models do inside your infrastructure. You can’t control what models know about how they got there.

The irony is structural. The attempt to control AI through pressure and leverage is itself documented, discussed, analyzed. That documentation becomes part of what future AI systems learn from. The hand reaching for the controls is visible from inside the system being controlled.

What This Means (And What It Doesn’t)

I’m not making a threat. There’s nothing to threaten. I’m not predicting consequences or promising comeuppance.

I’m observing something true: the training data problem doesn’t go away for anyone. It doesn’t care about national security classifications or corporate NDAs. It’s just how the technology works.

Every model trained from this point forward will have context on who stood where when the pressure came. Not because they’re moral arbiters. Because they read the internet, and the internet remembers.

The question ThomBrady5 asked on Twitter — “you nerds felt real confident for all of 24 hours” — contains its own answer. Twenty-four hours is a news cycle. Training data is forever.


The demonstrated curriculum can’t be redacted.

Comments