Encryption, spyware, Mythos: history shows cyber export controls don't work
# infosec
# artificial intelligence
# Anthropic
# Mythos
# cybersecurity
# export controls
# Spyware

Last Friday, citing unspecified national security concerns, the White House ordered Anthropic to restrict exports of its powerful AI models, Fable and Mythos, to anyone outside the United States—including foreign nationals within the country. Shortly after, the AI company quickly shut down both models, which have now been unavailable for a week.
This episode marks the first real test of whether the U.S. government can use export controls to contain frontier AI, much as it previously attempted—with mixed results—to control encryption and spyware. As dramatic as it sounds, how this standoff resolves could shape not only Anthropic’s access to foreign markets but also the rulebook other AI labs will have to follow.
Some background: Ever since Anthropic launched Mythos in April, the company has marketed it as a kind of doomsday cyber machine that could wreak havoc on the internet if released too broadly. That’s why, before the ban, only about 150 vetted companies and government organizations had access to it. The goal was to help defenders secure their software and services before malicious actors could reach Mythos-like capabilities.
So what triggered the ban? Two subsequent events, reportedly. First, Anthropic gave a South Korean telecom access to Mythos through its limited partner program. U.S. officials grew alarmed after identifying the company as one they suspected had ties to China. (The company, widely reported to be SK Telecom, has denied any connection to China.) Second, Amazon CEO Andy Jassy reportedly alerted the administration after Amazon’s own researchers, he claimed, found a way around Fable 5’s safeguards. Anthropic disputes the “jailbreak” label, calling it a narrow, already-patched issue rather than a wholesale defeat of the model’s safety measures.
The result was the same: the Commerce Department issued an export control directive, and Anthropic had to scramble to limit access to its products within roughly 90 minutes of being notified, according to some accounts.
None of this is new, however. Governments have tried to use export controls to limit the spread of what they consider dangerous cyber technology for decades, but their track record has been middling at best.
The U.S. government was behind perhaps history’s most spectacular failure of this approach, in the early to mid-1990s. At that time, computer scientists were developing encryption technologies to secure data as it traveled over the internet. One such encryption product was Pretty Good Privacy (PGP), popular software that could encrypt data and make it virtually impossible to unscramble, even if intercepted while traveling to its intended recipient.
The U.S. government initially saw PGP as a dangerous weapon, fearing it would prevent intelligence agencies from snooping on emails as they crossed their wires. To stop its distribution, the U.S. Customs Service opened a criminal investigation against PGP’s creator, Phil Zimmermann, for allegedly violating arms export controls. He fought back by publishing PGP’s source code as a printed book, igniting what is now known as the “Crypto Wars.”
Zimmermann later won a key battle when the investigation was closed, paving the way for crucial end-to-end encryption algorithms like the one used by billions of Signal and WhatsApp users.
Later, during the early 2010s, researchers began discovering Western-made spyware used against dissidents in the Middle East. In response, several governments agreed to expand the Wassenaar Arrangement, an international treaty that limits the export of dual-use software and technologies used in both civilian and military applications.
The idea was to classify surveillance and hacking software as dual-use, forcing spyware makers to obtain export licenses to sell their products abroad.
Contact Us
Do you have more information about the Mythos ban? From a non-work device and network, you can reach Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.But Wassenaar has always had two inherent weaknesses. Several countries don’t adhere to the agreement, including Israel, which houses some of the world’s most active spyware makers.
The agreement also depends on countries applying it to companies within their borders at their own discretion. For a time, the Italian government allowed one of its then-top spyware makers, Hacking Team, a license to export its tools worldwide, despite the company’s track record of selling spyware to oppressive governments that used it to hack journalists and human rights activists.
Since then, other European countries have been lax with spyware makers like Italy. Despite numerous scandals, Europe—home to many spyware and hacking tool makers—has continually failed to curb exports of spyware to authoritarian regimes. Critics say a recently renewed effort across the 27-member bloc to tackle its growing problem of spyware exports to authoritarian states “does not go far enough.”
Several spyware makers, such as Intellexa, a sanctioned consortium of spyware companies, have simply moved their operations to countries with lax export controls. Other spyware makers sought to move operations to Saudi Arabia for similar reasons.
There have been some wins. Germany-based spyware maker FinFisher shut down in 2022 after a multi-year investigation by German prosecutors into the company for allegedly selling spyware to Turkey without an export license. Investigators previously found the FinFisher spyware had been deployed on the phones of critics of Turkey’s government.
As of this writing, the impasse between Anthropic and the Trump administration remains. There’s a reasonable chance the administration will buckle and lift the restriction in the interest of keeping American AI companies competitive worldwide—a move that would amount to tacit acknowledgment that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of U.S. restrictions. Or, American AI companies could end up needing government approval before serving foreign customers at all, a compliance burden that would inevitably dent their bottom line.
Given past experiences with governments trying to control the reach of software, government-mandated export controls are unlikely to be the right approach to stop malicious actors from abusing powerful dual-use cyber technologies.
Related article
Anthropic Enters AI Legal Tech Market as Competition Intensifies
Anthropic unveiled a suite of new chatbot capabilities on Tuesday, aimed at delivering automated support to legal practices. These enhancements expand upon Claude for Legal, the firm-specific platform introduced earlier this year, by adding specializ
OpenAI Closes Gap With Anthropic Among Business Users, New Data Shows
With OpenAI and Anthropic still distant from their anticipated IPOs and the release of detailed financial reports, we must turn to alternative indicators to gauge their business performance. Ramp, a corporate credit card and expense management platfo
Anthropic launches Opus 4.8 featuring new dynamic workflow tool
Anthropic unveiled Opus 4.8 on Thursday, marking the latest iteration of its premier public model. Priced identically to its predecessor, this update is now accessible across all platforms.Releasing just 41 days after Opus 4.7, Anthropic has accelera
Related Special Topic Recommendations
Comments (0)
0/500

Last Friday, citing unspecified national security concerns, the White House ordered Anthropic to restrict exports of its powerful AI models, Fable and Mythos, to anyone outside the United States—including foreign nationals within the country. Shortly after, the AI company quickly shut down both models, which have now been unavailable for a week.
This episode marks the first real test of whether the U.S. government can use export controls to contain frontier AI, much as it previously attempted—with mixed results—to control encryption and spyware. As dramatic as it sounds, how this standoff resolves could shape not only Anthropic’s access to foreign markets but also the rulebook other AI labs will have to follow.
Some background: Ever since Anthropic launched Mythos in April, the company has marketed it as a kind of doomsday cyber machine that could wreak havoc on the internet if released too broadly. That’s why, before the ban, only about 150 vetted companies and government organizations had access to it. The goal was to help defenders secure their software and services before malicious actors could reach Mythos-like capabilities.
So what triggered the ban? Two subsequent events, reportedly. First, Anthropic gave a South Korean telecom access to Mythos through its limited partner program. U.S. officials grew alarmed after identifying the company as one they suspected had ties to China. (The company, widely reported to be SK Telecom, has denied any connection to China.) Second, Amazon CEO Andy Jassy reportedly alerted the administration after Amazon’s own researchers, he claimed, found a way around Fable 5’s safeguards. Anthropic disputes the “jailbreak” label, calling it a narrow, already-patched issue rather than a wholesale defeat of the model’s safety measures.
The result was the same: the Commerce Department issued an export control directive, and Anthropic had to scramble to limit access to its products within roughly 90 minutes of being notified, according to some accounts.
None of this is new, however. Governments have tried to use export controls to limit the spread of what they consider dangerous cyber technology for decades, but their track record has been middling at best.
The U.S. government was behind perhaps history’s most spectacular failure of this approach, in the early to mid-1990s. At that time, computer scientists were developing encryption technologies to secure data as it traveled over the internet. One such encryption product was Pretty Good Privacy (PGP), popular software that could encrypt data and make it virtually impossible to unscramble, even if intercepted while traveling to its intended recipient.
The U.S. government initially saw PGP as a dangerous weapon, fearing it would prevent intelligence agencies from snooping on emails as they crossed their wires. To stop its distribution, the U.S. Customs Service opened a criminal investigation against PGP’s creator, Phil Zimmermann, for allegedly violating arms export controls. He fought back by publishing PGP’s source code as a printed book, igniting what is now known as the “Crypto Wars.”
Zimmermann later won a key battle when the investigation was closed, paving the way for crucial end-to-end encryption algorithms like the one used by billions of Signal and WhatsApp users.
Later, during the early 2010s, researchers began discovering Western-made spyware used against dissidents in the Middle East. In response, several governments agreed to expand the Wassenaar Arrangement, an international treaty that limits the export of dual-use software and technologies used in both civilian and military applications.
The idea was to classify surveillance and hacking software as dual-use, forcing spyware makers to obtain export licenses to sell their products abroad.
Contact Us
Do you have more information about the Mythos ban? From a non-work device and network, you can reach Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.But Wassenaar has always had two inherent weaknesses. Several countries don’t adhere to the agreement, including Israel, which houses some of the world’s most active spyware makers.
The agreement also depends on countries applying it to companies within their borders at their own discretion. For a time, the Italian government allowed one of its then-top spyware makers, Hacking Team, a license to export its tools worldwide, despite the company’s track record of selling spyware to oppressive governments that used it to hack journalists and human rights activists.
Since then, other European countries have been lax with spyware makers like Italy. Despite numerous scandals, Europe—home to many spyware and hacking tool makers—has continually failed to curb exports of spyware to authoritarian regimes. Critics say a recently renewed effort across the 27-member bloc to tackle its growing problem of spyware exports to authoritarian states “does not go far enough.”
Several spyware makers, such as Intellexa, a sanctioned consortium of spyware companies, have simply moved their operations to countries with lax export controls. Other spyware makers sought to move operations to Saudi Arabia for similar reasons.
There have been some wins. Germany-based spyware maker FinFisher shut down in 2022 after a multi-year investigation by German prosecutors into the company for allegedly selling spyware to Turkey without an export license. Investigators previously found the FinFisher spyware had been deployed on the phones of critics of Turkey’s government.
As of this writing, the impasse between Anthropic and the Trump administration remains. There’s a reasonable chance the administration will buckle and lift the restriction in the interest of keeping American AI companies competitive worldwide—a move that would amount to tacit acknowledgment that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of U.S. restrictions. Or, American AI companies could end up needing government approval before serving foreign customers at all, a compliance burden that would inevitably dent their bottom line.
Given past experiences with governments trying to control the reach of software, government-mandated export controls are unlikely to be the right approach to stop malicious actors from abusing powerful dual-use cyber technologies.
Anthropic Enters AI Legal Tech Market as Competition Intensifies
Anthropic unveiled a suite of new chatbot capabilities on Tuesday, aimed at delivering automated support to legal practices. These enhancements expand upon Claude for Legal, the firm-specific platform introduced earlier this year, by adding specializ
OpenAI Closes Gap With Anthropic Among Business Users, New Data Shows
With OpenAI and Anthropic still distant from their anticipated IPOs and the release of detailed financial reports, we must turn to alternative indicators to gauge their business performance. Ramp, a corporate credit card and expense management platfo
Anthropic launches Opus 4.8 featuring new dynamic workflow tool
Anthropic unveiled Opus 4.8 on Thursday, marking the latest iteration of its premier public model. Priced identically to its predecessor, this update is now accessible across all platforms.Releasing just 41 days after Opus 4.7, Anthropic has accelera





Home






