Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

AI model export controls: are we replaying the crypto wars?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: The Commerce Department’s brief export controls on Anthropic’s Fable 5 and Mythos 5 replay the same logic that failed in the 1990s crypto wars, where restrictions hit law-abiding defenders more than determined adversaries, according to Corgea. The practical lesson is that AI governance has to assume diffusion, not depend on enforceable scarcity.

NHIMG editorial — based on content published by Corgea: LLMjacking: How Attackers Hijack AI Using Compromised NHIs

Questions worth separating out

Q: How should security teams govern frontier AI that inherits existing access rights?

A: Security teams should govern frontier AI as a privileged consumer of enterprise identity.

Q: Why do model restrictions often fail to reduce real attacker capability?

A: Because attackers can route around formal controls through open-source models, proxy services, leaked weights, or offshore infrastructure.

Q: What breaks when AI access is managed like normal application access?

A: Normal application access assumes stable ownership, predictable usage, and clear review cycles.

Practitioner guidance

  • Define separate access tiers for defensive and commercial use Create distinct approval paths for research, red team, and production usage of frontier models so defenders are not blocked by controls intended for general distribution.
  • Treat model access as an identity lifecycle Assign owners, expiry dates, and revocation criteria to human users and service identities that can invoke AI systems.
  • Preserve auditability for research exceptions Allow supervised exceptions for security validation, but require traceable approvals, scoped environments, and explicit recording of who accessed what model and why.

What's in the full article

Corgea's full article covers the historical comparison and policy argument this post intentionally leaves at the source:

  • The full crypto wars analogy and the specific export-control history behind it.
  • Corgea's direct discussion of Anthropic's Fable 5 and Mythos 5 access restrictions.
  • The article's broader argument about why defenders bear the cost of restrictive policy first.
  • The reasoning behind the claim that adversaries route around controls while compliant organisations absorb the friction.

👉 Read Corgea's analysis of AI export controls and the crypto wars analogy →

AI model export controls: are we replaying the crypto wars?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI export controls create a governance illusion when diffusion is the real risk. The article’s central warning is that restrictions feel decisive because they act at the point of approval, not at the point of misuse. That is a familiar security mistake: assuming administrative friction equals adversary containment. In practice, determined actors substitute open models, overseas access, or alternative delivery channels. Practitioners should read this as a reminder that policy control and threat reduction are not the same thing.

A question worth separating out:

Q: Who is accountable when restricted AI access blocks security work?

A: The accountable parties are the model owner, the access governance team, and the business sponsor for the exception process. If a restriction prevents defensive evaluation, there should be a documented path for review, approval, and audit so security work is not silently subordinated to policy optics.

👉 Read our full editorial: AI model export controls repeat the crypto wars mistake



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

AI export controls create a governance illusion when diffusion is the real risk. The article’s central warning is that restrictions feel decisive because they act at the point of approval, not at the point of misuse. That is a familiar security mistake: assuming administrative friction equals adversary containment. In practice, determined actors substitute open models, overseas access, or alternative delivery channels. Practitioners should read this as a reminder that policy control and threat reduction are not the same thing.

A question worth separating out:

Q: Who is accountable when restricted AI access blocks security work?

A: The accountable parties are the model owner, the access governance team, and the business sponsor for the exception process. If a restriction prevents defensive evaluation, there should be a documented path for review, approval, and audit so security work is not silently subordinated to policy optics.

👉 Read our full editorial: AI model export controls repeat the crypto wars mistake



   
ReplyQuote
Share: