Anthropic Mythos and Fable Export Controls: A History of Cyber Technology Restrictions
U.S. Government Restricts Anthropic's Frontier AI Models
The White House has ordered Anthropic to restrict the export of its most powerful AI models, Fable and Mythos, to all individuals and entities outside the United States, including foreign nationals residing within the U.S. Following this directive, Anthropic disabled access to both models for all users.
This action represents the first major attempt by the U.S. government to apply export controls to frontier AI. The ban was reportedly triggered by two primary events:
- Suspected China Ties: Anthropic provided access to Mythos via a limited partner program to a South Korean telecom company (widely reported as SK Telecom), which U.S. officials suspected of having ties to China.
- Safety Vulnerabilities: Amazon CEO Andy Jassy alerted the administration after Amazon researchers reportedly discovered a way to bypass safeguards in Fable 5. While Anthropic describes this as a narrow, patched issue rather than a systemic failure, the report contributed to the government's decision.
The Ineffectiveness of Software Export Controls
Historical precedents suggest that government-mandated export controls are generally ineffective at stopping the proliferation of dual-use cyber technologies because software is inherently portable and difficult to contain.
The PGP and Encryption "Crypto Wars"
In the early to mid-1990s, the U.S. government attempted to treat encryption software as a weapon. When Phil Zimmermann released Pretty Good Privacy (PGP), a tool that enabled secure end-to-end encryption, the U.S. Customs Service launched a criminal investigation against him for violating arms export controls.
To circumvent these restrictions, Zimmermann published the PGP source code as a printed book, leveraging free speech protections to ensure the technology remained available. The eventual closure of the investigation paved the way for the modern encryption standards used by billions of people today via platforms like Signal and WhatsApp.
The Wassenaar Arrangement and Spyware
In the early 2010s, the Wassenaar Arrangement—an international treaty governing dual-use technologies—was expanded to include surveillance and hacking software. The goal was to require export licenses for spyware to prevent its use by authoritarian regimes. This effort largely failed due to two systemic weaknesses:
- Lack of Universal Adherence: Key countries, including Israel (a major hub for spyware development), do not adhere to the agreement.
- Discretionary Enforcement: Participating nations often apply the rules inconsistently. For example, the Italian government previously granted export licenses to Hacking Team despite evidence that the company sold tools to oppressive governments to target journalists and activists.
Furthermore, sanctioned consortia like Intellexa have simply relocated operations to jurisdictions with laxer controls, such as Saudi Arabia, to avoid oversight.
Implications for the AI Industry
The current standoff between Anthropic and the U.S. administration establishes a critical precedent for how frontier AI will be regulated. There are two likely trajectories for this conflict:
- Competitive Reversal: The administration may lift restrictions to ensure American AI companies remain globally competitive, acknowledging that international competitors (including those in China) will likely develop similar capabilities regardless of U.S. bans.
- Increased Compliance Burden: AI labs may be required to obtain government approval for every foreign customer, creating a significant administrative burden that could impact the revenue and growth of U.S.-based AI firms.
While some specific actions have seen success—such as the 2022 shutdown of Germany-based FinFisher following an investigation into unlicensed sales to Turkey—the broader history of PGP and the Wassenaar Arrangement suggests that export controls are an insufficient tool for managing the risks of powerful, dual-use software.