Encryption, spyware, and now Mythos: History shows why cyber export control doesn’t work
Anthropic's AI models Fable and Mythos have been restricted from export due to national security concerns raised by the US government. Specifically, the government grew alarmed after Anthropic provided access to Mythos through its limited partner program to a South Korean telecom, SK Telecom, which US officials suspected had ties to China. Additionally, Amazon CEO Andy Jassy alerted the administration after Amazon's researchers reportedly found a way to circumvent Fable 5's safeguards, which Anthropic disputes as a "narrow, already-patched issue." This development has significant implications for Anthropic, as it had marketed Mythos as a powerful tool for cybersecurity, limiting access to only around 150 vetted companies and government organizations.
The use of export controls to limit the proliferation of powerful cyber technology is not new. In the 1990s, the US government attempted to restrict the distribution of encryption technologies, such as Pretty Good Privacy (PGP), citing national security concerns. However, this effort ultimately failed, as PGP's creator, Phil Zimmermann, published the software's source code in a printed book, paving the way for widespread adoption. Similarly, the Wassenaar Arrangement, an international treaty aimed at controlling the export of dual-use software and technologies, has had limited success in curbing the spread of spyware. Despite these efforts, spyware makers have continued to operate in countries with lax export controls, and several have moved their operations to avoid regulation.
The current impasse between Anthropic and the US government may have significant implications for the AI industry. If the administration buckles and lifts the restriction, it would acknowledge that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of US restrictions. On the other hand, if American AI companies are required to obtain government approval before serving foreign customers, it could create a significant compliance burden, denting their bottom line. As the situation unfolds, it will be crucial to monitor how the US government's approach to export controls affects Anthropic's access to foreign markets and the broader AI landscape.
Key Takeaways
The US government's restriction on Anthropic's AI models Fable and Mythos marks a significant test of export controls on frontier AI.
The effectiveness of export controls in containing powerful cyber technology has been uneven, with past attempts to restrict encryption and spyware having limited success.
The outcome of this standoff could shape the rulebook for other AI labs and determine whether American AI companies will need government approval to serve foreign customers.
The episode highlights the challenges of regulating dual-use technologies, as companies may find ways to circumvent restrictions or move operations to countries with lax controls.
About the Source
This analysis is based on reporting by TechCrunch. Here is a short excerpt for context:
For the last 30 years, stopping the flow of cybersecurity-related software has proven to be ineffective. It's unclear why it would work now with Anthropic’s cybersecurity model Mythos.Read the original at TechCrunch