AI Export Controls: A Primer on History, Challenges, and Policy Implications

An in-depth examination of AI export controls, from historical precedents like PGP encryption to recent restrictions on Anthropic's models, exploring why these policies often fail to achieve their intended goals.

Understanding Export Controls in the Digital Age

Export controls are government regulations that restrict the transfer of certain technologies, products, or information to foreign entities, ostensibly to protect national security interests. In the context of AI and cybersecurity, these controls aim to prevent adversaries from accessing technologies that could be used for military purposes or to undermine democratic institutions. The underlying premise is that by controlling access to advanced capabilities, governments can maintain strategic advantages and prevent the proliferation of dangerous technologies.

The recent restrictions on Anthropic's Mythos and Fable models represent the first major test of applying export controls to frontier AI systems. The Commerce Department's directive forced Anthropic to immediately cut off access to these models for non-US citizens, effectively requiring the company to suspend access for everyone since compliance would have meant firing foreign employees. This dramatic intervention marks a significant departure from the Trump administration's previously hands-off approach to AI regulation, signaling a new willingness to use export controls as a tool for AI governance.

The challenge with software-based export controls lies in the fundamental nature of digital technologies. Unlike physical goods that must cross borders through monitored checkpoints, software consists of bytes and bits that can easily traverse international boundaries through various means. This inherent characteristic makes enforcement particularly difficult and creates opportunities for circumvention that don't exist with traditional export-controlled items like military hardware or specialized manufacturing equipment.

Lessons from the Crypto Wars and PGP

The most instructive historical precedent for AI export controls comes from the 1990s battle over Pretty Good Privacy (PGP) encryption software. The U.S. government initially classified strong encryption as a dangerous weapon, fearing it would prevent intelligence agencies from intercepting communications. When Phil Zimmermann created PGP, which could encrypt data to make it virtually impossible to unscramble, the U.S. Customs Service opened a criminal investigation against him for allegedly violating arms export controls.

Zimmermann's response proved the futility of trying to control software distribution through traditional export mechanisms. He published PGP's source code as a printed book, exploiting the fact that printed materials were protected under the First Amendment and not subject to the same export restrictions as software. This clever workaround ignited what became known as the 'Crypto Wars' and demonstrated how determined actors could circumvent export controls through creative means.

The government eventually abandoned its investigation of Zimmermann, effectively acknowledging the impracticality of controlling encryption software exports. This victory paved the way for the widespread adoption of end-to-end encryption algorithms that now protect billions of users on platforms like Signal and WhatsApp. The PGP case established a crucial precedent showing that export controls on software technologies often fail to achieve their intended objectives while potentially stifling beneficial innovations.

The Wassenaar Arrangement and Spyware Control Attempts

Following discoveries of Western-made spyware being used against dissidents in the Middle East during the early 2010s, governments expanded the Wassenaar Arrangement to include surveillance and hacking software as dual-use technologies requiring export licenses. This international treaty was designed to prevent spyware makers from selling their products to authoritarian regimes that would use them against journalists and human rights activists. The classification of surveillance software as dual-use technology represented a significant expansion of export control frameworks into the cybersecurity domain.

However, the Wassenaar Arrangement has demonstrated two fundamental weaknesses that continue to undermine its effectiveness. First, several countries with significant spyware industries, including Israel, don't adhere to the agreement, creating safe havens for companies seeking to avoid restrictions. Second, the agreement relies on individual countries to apply controls at their own discretion, leading to inconsistent enforcement and regulatory arbitrage opportunities for determined actors.

The track record of spyware export controls illustrates these systemic problems. Italy allowed Hacking Team to export its tools globally despite the company's history of selling to oppressive governments. European countries have repeatedly failed to prevent spyware exports to authoritarian regimes, with critics arguing that recent reform efforts 'do not go far enough.' Companies like Intellexa have simply relocated operations to countries with lax export controls, while others have sought to move to jurisdictions like Saudi Arabia for similar regulatory advantages.

The Anthropic Mythos Ban: A Real-World Test Case

The recent export control directive targeting Anthropic's Mythos and Fable models provides a contemporary case study in the challenges of applying traditional export controls to AI systems. The ban was reportedly triggered by two specific incidents: Anthropic's provision of Mythos access to a South Korean telecom company suspected of having Chinese ties, and Amazon CEO Andy Jassy's alert to the administration about potential security vulnerabilities in Fable 5's safeguards. These events prompted the Commerce Department to issue an immediate export restriction, giving Anthropic approximately 90 minutes to comply.

Anthropic had marketed Mythos as a potentially dangerous cyber capability, limiting access to only around 150 vetted organizations before the ban. The company's own marketing strategy, which emphasized the model's potential for cyber disruption, may have inadvertently contributed to government concerns about its proliferation. The restriction forced Anthropic to suspend access entirely rather than attempt the practically impossible task of segregating users by nationality while maintaining operations with foreign employees.

The incident reveals the practical impossibility of implementing nationality-based restrictions on AI models in globally integrated technology companies. Unlike traditional export-controlled goods, AI models are accessed through cloud services by distributed teams of employees and customers worldwide. The binary choice between complete suspension and potential violation of export controls demonstrates how poorly suited traditional export control frameworks are to the realities of modern software distribution and AI service delivery.

Allied Concerns and Technological Sovereignty

The Anthropic export controls have significantly strained relationships with key allies who view the restrictions as evidence that the U.S. government maintains a 'kill switch' over critical AI technologies. European leaders, already concerned about technological dependency on American companies, have cited the incident as validation of their tech sovereignty initiatives. European Commission spokesperson Thomas Regnier stated that the case 'further underlines Europe's need for technological sovereignty,' while European Parliament debates featured even pro-tech voices calling for reduced reliance on U.S. AI infrastructure.

The reaction from European policymakers has been particularly sharp, with former Meta executive turned parliamentarian Aura Salla arguing that 'Europe cannot keep building its tech stack on access that can be switched off overnight by a foreign government.' This sentiment reflects broader concerns about the weaponization of technological dependencies and has accelerated European efforts to develop indigenous AI capabilities. The incident has provided political ammunition for those advocating for policies that would 'reserve our data and our market preliminarily for European tech to scale it and build our own frontier AI.'

These allied reactions highlight a fundamental tension in U.S. export control policy: restrictions intended to maintain American technological advantages may actually accelerate the development of competing capabilities by both rivals and allies. The policy creates incentives for trusted partners to reduce their dependence on American technology, potentially undermining the long-term strategic objectives that export controls are meant to serve. This dynamic suggests that export controls may be counterproductive when applied to technologies where network effects and global collaboration are crucial for maintaining leadership.

The Circumvention Problem and Enforcement Challenges

The history of export controls on digital technologies reveals a consistent pattern of circumvention that undermines their effectiveness. In the spyware industry, companies have demonstrated remarkable adaptability in evading restrictions through jurisdictional arbitrage, corporate restructuring, and technical workarounds. The case of FinFisher, which shut down in 2022 after German prosecution, represents one of the few enforcement successes, but even this victory came only after years of investigation and was limited to a single jurisdiction.

The fundamental challenge lies in the nature of software itself, which can be copied, modified, and distributed through countless channels that are difficult to monitor and control. Unlike physical goods that must pass through customs checkpoints, digital technologies can be transmitted instantly across borders through encrypted channels, peer-to-peer networks, or even published as academic research. The PGP case demonstrated how source code could be legally exported as printed material, while modern technologies offer even more sophisticated methods for circumventing restrictions.

Reports suggest that Chinese entities have already found ways to access Mythos despite the export controls, illustrating how quickly determined actors can circumvent software restrictions. The global nature of the internet, combined with the ease of creating shell companies and using proxy services, makes it extremely difficult to prevent access to digital technologies by specific nationalities or organizations. These enforcement challenges suggest that export controls may create compliance burdens for legitimate users while failing to prevent access by the very actors they are intended to restrict.

Policy Implications and Future Directions

The Anthropic case represents a critical juncture in AI governance, with potential outcomes that could reshape how the U.S. approaches technology export controls. The administration faces a choice between maintaining restrictions that may prove unenforceable while damaging American competitiveness, or acknowledging the limitations of export controls and seeking alternative approaches to AI governance. The recognition that 'AI labs elsewhere, including in China, will likely reach similar capabilities regardless of what the U.S. restricts' suggests that export controls may be fighting an ultimately futile battle against technological diffusion.

Commerce Secretary Howard Lutnick's proposal to give 'trusted partners' privileged access to frontier models represents an attempt to balance security concerns with allied relationships, but this approach carries its own risks. Making access to American AI capabilities a privilege that Washington can grant or revoke creates incentives for allies to develop alternatives and may accelerate the fragmentation of the global AI ecosystem. The policy effectively positions the U.S. as a gatekeeper while encouraging both rivals and allies to pursue technological independence.

The broader lesson from decades of failed export controls on digital technologies suggests that alternative approaches to AI governance may be more effective than traditional restrictions. Collaborative frameworks that emphasize shared standards, joint research initiatives, and coordinated responses to malicious uses may prove more successful than unilateral attempts to control technology diffusion. The challenge for policymakers is developing governance mechanisms that can address legitimate security concerns while preserving the international cooperation and open innovation that have historically driven technological progress.