Three decades of failure: Why blocking Anthropic’s Mythos won’t work either

Three decades of failure: Why blocking Anthropic’s Mythos won’t work either

6 0 0

The U.S. government is reportedly considering export controls on Anthropic’s new cybersecurity model, Mythos. If that sounds familiar, it should. We’ve been down this road before — multiple times — and it has never ended well.

Let’s start with encryption in the 1990s. The government tried to restrict the export of strong encryption software, claiming national security concerns. They classified it as a munition. The result? PGP ended up printed in a book — literally, as source code — and shipped overseas. The courts eventually ruled that code was speech. The controls collapsed.

Then came the spyware era. After the Stuxnet and Flame revelations, export restrictions on offensive cyber tools ramped up. The Wassenaar Arrangement tried to control “intrusion software” and “zero-day exploits.” Security researchers immediately howled — the language was so broad it would have criminalized vulnerability disclosure and penetration testing. The U.S. had to walk back parts of it. Meanwhile, nation-states and private actors just moved development to countries with lax controls, or simply ignored the rules.

Now we have Mythos. Anthropic claims it can help defenders find vulnerabilities faster. It’s not even clear if the model is genuinely offensive or defensive — that line gets blurry fast. But the reflex to control it is the same old instinct. Block the export, keep the tech at home, assume everyone else will play along.

They won’t. And that’s the core problem.

Export controls on software — especially AI models — are fundamentally leaky. You can’t stop code from crossing borders. You can’t un-train a model once it’s released. You can’t prevent researchers in other countries from building their own version if they have the resources. The genie doesn’t go back in the bottle.

What these policies actually do is harm domestic innovation. Companies face compliance burdens, lose international customers, and fall behind. Meanwhile, adversaries who don’t care about export laws just build their own tools. The U.S. ends up with a weaker cybersecurity industry and no real security gain.

I’m not saying there’s no risk. Mythos could be misused. But the track record of export controls on dual-use technology is abysmal. Encryption controls failed. Wassenaar controls failed. There’s no reason to believe this will be different.

Instead of trying to lock down models that can’t be locked down, maybe we should focus on what actually works: investing in defensive capabilities, international norms, and rapid response mechanisms. Treat AI like we treat other powerful tools — regulate the harmful uses, not the technology itself.

But that’s harder than slapping an export restriction on a model and calling it a day. So here we are again, repeating a 30-year-old mistake with a new name attached.

Comments (0)

Be the first to comment!