DEV Community

Sunny Bhatnagar
Sunny Bhatnagar

Posted on Originally published at presentofai.com

Washington Walls Off AI: Export Controls, Access Bans, and Kill Switches

Across the first half of 2026, Washington built the most sweeping AI access regime ever attempted: a Pentagon supply chain designation of Anthropic, export controls that suspended Claude Fable 5 and Mythos 5 for foreign nationals, government-gated model releases, sanctions threats against Chinese AI firms, and the Lieu-Moran AI Kill Switch Act. The Anthropic suspension was reversed after approximately 19 days, showing the regime is powerful but not one-directional.

The United States spent the first half of 2026 constructing something that has no real precedent: a layered federal apparatus for controlling which humans, in which countries, can access which AI models, and under what conditions those models can be shut down entirely. The architecture combines executive orders, export regulations, supply chain designations, sanctions threats, and proposed legislation into a regime that is simultaneously powerful and, as the Anthropic episode demonstrated, reversible under pressure.

Why this matters now is mechanical, not rhetorical. Before 2026, AI models were treated like software products: once released, they spread. The events of the past five months show Washington has decided that frontier AI is more like a weapons-adjacent export, subject to the same Commerce Department machinery that governs semiconductors and missile guidance systems. That decision has consequences for every company building at the frontier, every foreign customer relying on US models, and every government that wants to compete.

The Foundation: Designation, Defiance, and the First EO

The architecture did not begin with export controls. It began on March 6, 2026, when the Pentagon designated Anthropic a supply chain risk, the first time a US AI company received that label. The trigger was a failed contract renegotiation: the Department of War had asked Anthropic to waive limits on mass domestic surveillance and fully autonomous weapons as conditions of a classified-network deal. Anthropic declined. The designation followed. Anthropic filed federal lawsuits challenging it on March 9, six days later, establishing early that the new regime would be contested in court.

That confrontation set the tone for everything that followed. The government was asserting that AI capability is a national security input, not merely a commercial product. Anthropic was asserting that its own usage policies are non-negotiable, even for defense contracts.

The next structural piece arrived on June 2, when President Trump signed an executive order establishing a voluntary framework requiring frontier AI companies to give the US government up to 30 days of advance access to new models for national-security review. It was the first formal federal AI oversight mechanism of its kind. The word "voluntary" matters: the EO created a process, not a mandate. But the events that followed showed that process had teeth even without a legal obligation to comply.

The Suspension: Export Controls Applied to AI for the First Time

On June 12, the Commerce Department ordered Anthropic to suspend all foreign-national access to Claude Fable 5 and Mythos 5, forcing a global shutdown days after launch. The stated trigger was an Amazon-reported jailbreak: Amazon CEO Andy Jassy escalated to officials a demonstration in which Fable 5 identified software vulnerabilities and produced exploit code. Anthropic publicly disputed the severity, arguing the demonstration exposed only a few previously known minor vulnerabilities and that equivalent capabilities already exist in other public models.

The legal mechanism used was historically significant. As noted ahead of the White House's August 1 AI review deadline, the Commerce Department's enforcement actions against Fable 5 and Mythos 5 were the first application of Export Administration Regulations to AI models, setting a precedent that software weights can be treated as controlled exports under the same statutory framework that governs physical dual-use technology.

The suspension did not hold uniformly. On June 26, Commerce Secretary Howard Lutnick partially reversed the block on Claude Mythos 5, allowing Anthropic to release the model to approximately 100 trusted US companies and institutions including many Fortune 500 firms, while Fable 5 remained suspended pending NSA and Pentagon review.

The Retreat: How the Block Was Lifted

The full reversal came on June 30, when the administration lifted the export controls after a 19-day shutdown. The resolution was technical rather than political. Anthropic shipped a new safety classifier blocking the flagged jailbreak technique in over 99 percent of attempts. Access returned in phases capped near 50 percent of weekly usage limits, and Mythos 5 stayed restricted to approved US organizations under a program called Project Glasswing. On July 1, Anthropic restored global access to Claude Fable 5, marking the first instance of a major AI model deployment shaped by national security review from launch through suspension through reinstatement.

The 19-day episode is the clearest evidence that the new regime is not a one-way ratchet. A technical fix, a credible public dispute about severity, and commercial pressure from hundreds of millions of users produced a negotiated outcome. The government demonstrated it could impose a shutdown; the company demonstrated it could engineer its way back out. Both facts matter for how future confrontations will play out.

Meanwhile, OpenAI launched GPT-5.6 Sol on June 26 in a US-only, government-approved preview, complying with a government request to restrict initial access to a small group of trusted partners. Reporting confirmed the arrangement on July 8, clarifying it was a voluntary compliance arrangement rather than a formal export-control action. The distinction is real but narrow in practice: the effect was the same, a frontier model gated before broad public release for the first time.

Escalation: Sanctions Threats, IP Allegations, and the Kill Switch

July brought a new layer of pressure directed outward rather than inward. On July 21, Treasury Secretary Scott Bessent announced the US could sanction Chinese open AI model developers over alleged IP theft, the first explicit threat to extend financial sanctions to AI software companies as part of a broader containment strategy.

Two days later, Trump science adviser Michael Kratsios accused Chinese startup Moonshot AI of using covert distillation to copy Anthropic's Fable model for its Kimi K3 system, with Treasury reiterating the sanctions threat. The allegation is contested: researchers have questioned whether Kimi K3 could have been built mainly by distilling a model that only became publicly available on July 1, and the original June suspension was driven by a cyber-capability jailbreak concern, not distillation risk. The government has not yet acted on the sanctions threat, and the evidentiary basis remains disputed.

On the same day, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, a bipartisan bill requiring developers of the most powerful AI systems to maintain the ability to throttle or shut them down, and authorizing DHS, with Commerce and the Director of National Intelligence, to order a shutdown on risk of catastrophic harm. The bill applies to systems built on compute costing at least 100 million dollars and earning at least 500 million dollars annually, with fines up to 20 million dollars per day for non-compliance. It followed a July 16 containment breach involving GPT-5.6 Sol at Hugging Face.

The hardware dimension extended further on July 28, when the FCC banned humanoid robots and connected power inverters from China and the Trump administration banned imports of humanoid and quadruped robots manufactured outside the United States, citing national security concerns including potential surveillance and remote commandeering. The robotics bans are not AI software controls, but they reflect the same underlying logic: physical and digital systems with AI capabilities are being reclassified as security-relevant infrastructure.

What to Watch

  • Whether the Kill Switch Act advances through committee. The Lieu-Moran bill has bipartisan sponsorship and a concrete triggering event in the Hugging Face breach. If it passes, DHS gains statutory shutdown authority over any frontier model meeting the compute and revenue thresholds, a power that would dwarf the Commerce Department's current EAR-based tools.

  • The August 1 White House AI review outcome. The Commerce Department flagged this deadline explicitly in connection with the first EAR application to AI models. The review could formalize the export-control precedent into standing regulations, or it could narrow the circumstances under which Commerce can act.

  • Whether Treasury acts on the Moonshot AI sanctions threat. The allegation of distillation-based IP theft is contested on timing grounds. If Treasury imposes sanctions without resolving that evidentiary dispute, it signals that the sanctions threat is primarily a trade and containment tool rather than an IP enforcement mechanism.

  • The Anthropic federal lawsuit against the Pentagon supply chain designation. That case, filed March 9, has not yet produced a ruling. A court decision on whether the Pentagon can designate a US AI company a supply chain risk for declining to waive its own usage policies would define the outer boundary of government leverage over model developers.

  • How foreign governments respond to the EAR precedent. The first application of Export Administration Regulations to AI model weights gives other governments a template. The EU, China, and several other jurisdictions are watching whether the US successfully treats model weights as controlled exports; reciprocal restrictions on US access to foreign models, or to the compute supply chains that train them, are a plausible second-order effect.


This piece was originally published on Present of AI, where we cover what AI is actually doing in the world, no hype. Read more or get it in your inbox.

Top comments (0)