Order forced Anthropic to block global access to its two most advanced AI models

The directive forced Anthropic to disable the models for all users because the company had no way to immediately collect and validate each user’s nationality, including those outside the United States. The Commerce Department agreed to lift its restrictions after Anthropic significantly strengthened the models’ safety guardrails — controls that resulted in what Marinotti described as a “collapse” of the models’ benchmark scores, demonstrating lower overall intelligence and capacity. In one experiment, the new Fable 5 completed only 3 of 12 tasks that would have been routine before the new controls.

Marinotti, an associate professor of law at Indiana University who studies technology law and policy, writing in The Conversation, identified two open legal issues with the order. The first is whether access to Anthropic’s models can be considered an “export” at all under the Export Control Reform Act of 2018, a law written with hardware exports in mind — preventing companies from exporting dangerous physical items such as uranium enrichment centrifuges without government consent. When a user sends a prompt to Fable 5 or Mythos 5 and the model replies, the only item that crosses a border is the reply. The model never leaves Anthropic’s servers. The Commerce Department’s own past guidance has treated remote access to software running on U.S. servers as outside the reach of export controls, and the fact that Congress is attempting to change the situation further implies that existing law may not apply to an AI model’s output, Marinotti said.

The second issue concerns whether the Commerce Department followed lawful procedures in imposing the restrictions. Marinotti said the “is informed” mechanism the department’s letter used is normally employed to notify a specific company that a particular type of transaction to a particular country requires government approval. Even if an AI response to a chat were deemed an export under existing law, Marinotti said the order’s sweep — covering all foreign nationals anywhere on the planet — may exceed the power granted to the department.

The traditional export control process is deliberately slow, Marinotti wrote. Multiple government agencies consider possible controls, request public comment, coordinate restrictions with U.S. allies, and the Federal Register publishes the resulting regulations. When immediate action is required, the government has historically used a temporary classification known by the code 0Y521. That designation carries safeguards the Anthropic letter lacked: it requires sign-off from the Defense and State departments, it is published, it expires after a year unless renewed, and it commits the government to reviewing the export control measure with its allies. The Anthropic letter, Marinotti said, was the opposite: unilateral, secret, open-ended and global.

Marinotti noted that Anthropic did not contest the order’s legality. The company complied, calling the episode “a misunderstanding.” Company officials subsequently went to Washington — not to litigate, but to negotiate the restriction. Anthropic had previously sued the Trump administration over designating the company as a supply chain risk, so the negotiation may have been strategic, not necessarily a sign of corporate fear, Marinotti said.

Negotiation may make sense because Anthropic largely agrees with government controls in certain cases, Marinotti wrote. Just two days before the letter arrived, CEO Dario Amodei published an essay arguing that the government “should have the power to block or deter deployment” of an advanced, or “frontier,” AI model considered too dangerous. Going to court to deny that power would undercut Anthropic’s own argument. Marinotti also noted that the story that the two Claude models are dangerous comes largely from Anthropic’s own public warnings and thousands of hours of red-team tests done in collaboration with the government.

One additional factor may keep the legal questions out of court, Marinotti said. The same 2018 statute strips federal courts of their usual power to overturn such decisions as arbitrary, meaning anyone challenging a directive must now show not that the order was unreasonable, but that it was flatly unauthorized or unconstitutional — a far narrower path.

The coming legal fight, should it arise, will not be over whether the government can exert this level of control, Marinotti said — it already has. The fight will be about how governments can wield this control responsibly. The best case, he wrote, is that the fight takes place in the open, with public input, through lawful legislative processes. The dystopian alternative, he wrote, is a two-tiered AI order in which governments condition export privileges on secret access to frontier models more powerful than anything publicly known or available.