July 21, 2026 (Conversation) When the U.S. Commerce Department ordered Anthropic on June 12, 2026, to immediately prevent all foreign nationals from using the artificial intelligence company’s two most advanced large language models, it disabled its Claude Fable 5 and Mythos 5 models within hours, making them inaccessible to everyone.
Anthropic had little choice. The letter, citing national security concerns, barred access by all foreign nationals, including Anthropic’s own noncitizen employees. With no way to immediately collect and validate each and every user’s nationality, including those who were outside the country, the company shut the models off for everyone.
The Commerce Department agreed to lift its restrictions on June 30 after Anthropic significantly strengthened the models’ safety guardrails. While this may sound like a good thing, these guardrails resulted in a “collapse” of the models’ benchmark scores, demonstrating lower overall intelligence and capacity.
In other words, the department rescinded its directive only after Anthropic’s models were hobbled to the point that many benign queries now trigger the guardrails. According to one experiment, the new Fable 5 completed only 3 of 12 tasks that would have been routine before the new controls.
The Commerce Department’s willingness to effectively shut down Fable 5 and Mythos 5 with almost no notice, and to reverse that decision only after Anthropic severely hindered the models, sent a chill through the U.S. AI industry.
As a legal scholar who studies technology law and policy, I see two fundamental questions arising from this incident: Can the U.S. government act as a gatekeeper to AI models? And did it do so lawfully in this instance?
An unlawful order?
The Commerce Department issued its letter under the Export Control Reform Act of 2018, which was written with hardware in mind. The law prevents companies from exporting dangerous items, such as uranium enrichment centrifuges, without the government’s consent. The letter was the first time the government had used export controls to prevent foreign access to an AI service.
The 2018 act also assigns power over “emerging and foundational technologies.” It empowers the Commerce Department’s Bureau of Industry and Security to require a company to obtain an export license for any access by a foreign national to a specific technology of interest – in this case, Anthropic’s two models.
Although these provisions raise many open legal issues, two stand out.
The first is whether access to Anthropic’s models can be considered an export at all. When a user sends a prompt to Fable 5 or Mythos 5, and the model replies, the only item “exported” is the reply. The model never leaves Anthropic’s servers.
The Commerce Department’s own past guidance has treated remote access to software running on U.S. servers as outside the reach of export controls. The fact that Congress is trying to change this situation further implies that existing law may not apply to an AI model’s output. Future congressional action could give the U.S. government more power to restrict AI access.
The second issue is whether the Commerce Department followed lawful procedures in imposing export restrictions on Anthropic. The so-called “is informed” mechanism, which the department’s letter carried out, is normally used to inform a particular company that a particular type of transaction to a particular country requires government approval.
Even if an AI response to a chat were deemed to be an export under existing law, the order’s sweep of all foreign nationals anywhere on the planet may exceed the power granted to the department. What is clear is that the directive’s legal backing seems uncertain.
Break with the past
Based on my work on law and emerging technologies, I can say that the Anthropic case reflects a change in how the U.S. attempts to control access to potentially dangerous new technologies. The traditional legal process is deliberately slow: Multiple government agencies consider possible control, they request public comment, they coordinate restrictions with U.S. allies, and the Federal Register publishes the resulting regulations.
Some dangerous technologies clearly require immediate action. Even then, though, the government traditionally used a temporary classification known by the code 0Y521. This designation carries safeguards the Anthropic letter lacked.
It requires sign-off from the Defense and State departments. It is published. It expires after a year unless renewed. And it commits the government to reviewing the export control measure with its allies. The Anthropic letter was the opposite: unilateral, secret, open-ended and global.
Why Anthropic isn’t crying foul
It is striking that Anthropic did not contest the order’s legality. The company complied, calling the episode “a misunderstanding.” Company officials subsequently went to Washington – not to litigate, but to negotiate the restriction. Anthropic had previously sued the Trump administration over designating Anthropic as a supply chain risk, so the negotiation may have been strategic, not necessarily a sign of corporate fear.
Negotiation may make sense because Anthropic largely agrees with government controls in certain cases. Just two days before the letter arrived, CEO Dario Amodei published an essay arguing that the government “should have the power to block or deter deployment” of an advanced, or “frontier,” AI model that is considered too dangerous. Going to court to deny that power would undercut Anthropic’s own argument.
Anthropic also built the case against itself. The story that the two Claude models are dangerous comes largely from Anthropic’s own public warnings and thousands of hours of red-team tests done in collaboration with the government.
One wrinkle may also keep these issues out of court: The same 2018 statute strips federal courts of their usual power to shoot down such decisions as arbitrary. So now, anyone challenging a directive in court must show not that the order was unreasonable, but that it was flatly unauthorized or unconstitutional – a far narrower path.
Unchecked power?
The coming legal fight, should it arise, will not be over whether the government can exert this level of control; it already has. The fight will be about how governments can wield this control responsibly. The best case at this point is that this fight takes place in the open, with public input, through lawful legislative processes.
The dystopian alternative is a two-tiered AI order in which governments condition export privileges on secret access to frontier models more powerful than anything publicly known or available.
