📋 Core Judgment

When Anthropic loudly proclaimed that its models were "better than hackers," it ran straight into a trigger the BIS had long kept cocked — an ECCN code that had waited months for its first nameable target finally had one. From writing its own legal justification, to a red-line standoff with the Pentagon, to a stab in the back from its largest shareholder, to a debt of blood on the battlefield that could not be dodged, Anthropic ran the full cycle from hype to ban to decontrol eighteen days later — and the precedent is now written into the rules of the game.


The Legal Basis It Wrote Itself

In mid-June 2026, the US Department of Commerce's Bureau of Industry and Security (BIS) imposed an unprecedented export control on Anthropic's Fable 5 and Mythos 5 models: it not only barred the company from supplying them to entities outside the United States, but also required Anthropic to cut off its own foreign employees' access to them. It marked the first time the US government had applied nationality-screening-level controls to a specific AI model — the tool was in the building, but the people who built it were not allowed to look.

The core paradox of the episode is this: Anthropic itself provided the whetstone for the blade.

Over the preceding months, Anthropic CEO Dario Amodei had repeatedly stressed that the company's most advanced models were "too dangerous to release." Sam Altman once characterized the strategy as "claiming you've built a bomb — an incredible marketing ploy." Peter Girnus, a senior threat researcher at the Zero Day Initiative, was sharper still: "If you describe your product as munitions in every press release, eventually the government will believe you too. They wrote the legal justification themselves, and called it branding."

When BIS finally listed Mythos and Fable as controlled items, Anthropic was left in an acutely awkward position: export-control law operates on strict liability — a company cannot plead "we didn't know it would come to this" to escape responsibility. Matthew Pines, CEO of Physical Superintelligence, called it "a sharp blade" — one that cuts the hand that swings it too.

Deemed Export: Foreign Employees Become 'Domestic Exports'

The most controversial provision was an extreme application of the "deemed export" rule. Under BIS's interpretation, showing controlled technology to a foreign national inside the United States counts as exporting it abroad. That meant Anthropic's own foreign researchers — based in the United States, the very engineers who had helped train the models — could no longer access the systems they had built.

“ Chris McGuire

The munitions are in the building, and the people who made them are forbidden to look.

The historical precedent for the rule lies in the ITAR controls the United States placed on cryptography in the 1990s. At the time the government classified encryption software as a munition, but activists circumvented this by printing the PGP source code as a book — since a book is protected speech, while a floppy disk is a weapon. Yann LeCun observed that the ITAR regime ultimately collapsed because "the application of mathematics does not stop at customs." But an AI model is at once code, service, and platform — far harder to define than encryption software.

The Technical Chassis of Export Controls — The Creation of ECCN 4E091 and the Logic of RS

The immediate trigger for Anthropic's ban had to do with the company's own hype, but what truly singled it out was an ECCN code created on January 15, 2025, which had finally found its prey.

4E091: A Code Long Without an Entity to Match

On January 15, 2025, with the Biden administration less than a month from leaving office, BIS issued a flurry of export-control regulations. One of them established a brand-new ECCN code — 4E091 — dedicated to controlling "the model weights of certain advanced closed-source dual-use AI models."

Hidden in the five-character structure of an ECCN is a logic of identification:

  • The first digit denotes the category — 3 is electronics, 4 is computers
  • The second character (a letter) denotes the product form — a is products, b is equipment, c is materials, d is software, e is technology

After the Biden administration launched comprehensive controls on semiconductors, supercomputers, and AI destined for China in October 2022, a 09X series of codes took shape (chiefly 090 and 091), each with a clearly defined corresponding entity:

  • 3B090: semiconductor deposition equipment (Applied Materials' cobalt/tungsten fill conductive-layer tools)
  • 3A090: advanced semiconductor chips (NVIDIA's A100/A800/H100/H200/H800/B100 and the like)
  • 4A090: supercomputers and AI servers

But 4E091 — the category pertaining to the weights of large AI models — long had no corresponding entity. Until Anthropic's Fable 5 and Mythos 5 came along.

RS Is Not the 'Regional Stability' You Might Think

4E091 and the entire 09X series share a single reason for control: RS — Regional Stability. But the meaning of that term needs unpacking.

Under the new RS rules defined in October 2022, the substance of "regional stability" is this: to restrict a certain major Eastern power from obtaining advanced technology for military use, so as to prevent it from completing the reunification of the two sides of the Strait. The logic of these codes is not "preventing invasion" but "preventing a generational technology gap" — if that power obtained these technologies and products, it could achieve a generational lead over the other side of the Strait, thereby altering the regional balance of forces.

📝 Note — The Real Meaning of RS

The precise meaning of RS in this context is: preventing a cross-strait technological gap with Taiwan and maintaining the military balance across the Strait. This is not "regional peace and stability" in the conventional sense, but the institutionalized expression of "the United States maintaining the military status quo across the Strait."

Three Coffin Lids — The Encirclement by the White House, the Pentagon, a Major Shareholder, and the Battlefield

If ECCN 4E091 was the plank BIS had readied, the forces that drove those planks home came from several directions: Anthropic's direct confrontation with the Department of Defense, the betrayal of an insider shareholder, and a debt of blood on the battlefield.

Two Red Lines: Anthropic's Head-On Collision with the Pentagon

In early 2026, Anthropic and the US Department of Defense erupted into an escalating conflict. At its core were two "insurmountable red lines" for the Claude model:

  1. It must not be used for mass surveillance of the public within the United States
  2. It must not be used to develop fully autonomous weapons systems

Company founder Dario Amodei put it in highly moralized terms: "We believe AI should defend democratic values, but in certain circumstances it could instead destroy them — we cannot, in good conscience, agree."

In February, Under Secretary of Defense Emil Michael directly warned Anthropic to hand over control of the models, invoking an allusion to Roman history — "you need to cross the Rubicon." Hand over the initiative; let the Department of Defense, not an AI company, decide how the product is delivered.

Anthropic did not yield an inch. In the end, Defense Secretary Pete Hegseth made the call, designating this American company — unprecedentedly — as a supply-chain risk. That is not the same as a ban, but it struck a direct blow to the company's reputation and to its procurement prospects.

The Shareholder's Defection — Amazon's Anonymous Tip

If pressure from the Department of Defense was foreseeable, the stab in the back from a major shareholder caught everyone off guard.

According to reporting by KingofCard, a Chinese tech-commentary video creator, Amazon — Anthropic's largest shareholder — tipped off the White House to a circumvention vulnerability in an Anthropic model, directly driving the White House's ultimatum pressuring Anthropic.

This is exceedingly rare in the history of venture capital — a major shareholder voluntarily reporting its own portfolio company to the government. Sam Altman's verdict: "This is obviously an incredible marketing ploy, going around shouting, 'We've built a bomb, and now we're going to drop it on your heads.'" The industry has come to call Anthropic's strategy "Oppenheimer marketing."

“ Historical Irony

The day before the ban was issued, Dario Amodei had publicly called for governments to have the power to "halt the release of a frontier model when it fails an independent safety test" — the words were barely dry before, the next day, his own flight was grounded.

The Blood at the Minaab School

On February 28, when the United States and Israel launched the first round of strikes against Iran, a school called Minaab was hit by a missile from the US–Israeli coalition — the entire building collapsed, killing 156 people, of whom 120 were children, the vast majority of them girls.

Anthropic's products were, to a large degree and whether actively or passively, woven into the decision chain of that strike. It cannot be confirmed whether this was "active assistance" or "a tool nested into a military use," but the result is the same: the moral cleanliness Anthropic wished to preserve could no longer be washed clean at the level of battlefield data.

📋 The Four Coffin Lids Close

From the technical base of ECCN 4E091, to the red-line standoff with the Pentagon, to the shareholder's betrayal, to the inescapable debt of blood on the battlefield — Anthropic's four coffin lids were not nailed on the same day, but in the end they closed within the same month.

The Glass Wing Project — Anthropic's 'Active Client Selection'

Anthropic was not a wholly innocent, passive victim. Through an initiative called the Glass Wing Project, it actively screened which tech giants could access its MyOS system — a way for Anthropic to select its customers and strengthen its pricing power. Telling the world "my models are dangerous" while hand-picking who may touch that danger — this stands in irreconcilable tension with the "open AI safety" it professes.

A Lose-Lose Export-Control Landscape

The consensus among several experts is that BIS's export-control strategy is "chaotic and destructive." The core contradiction lies here:

  • On chips: the US government on the one hand keeps approving exports of advanced AI chips to China
  • On models: on the other hand it blocks US AI companies from releasing their strongest models to any country, allies included
  • On enforcement: there is no effective mechanism to stop chips from flowing into China through third-party channels
“ Dean Ball, senior fellow at the American Innovation Foundation

A government that on the one hand argues we should export advanced AI chips to China, and on the other wants to ban Britain from using our best models — I am simply at a loss for words.

The internal contradiction of this policy means that AI export controls fail on both counts: they cannot effectively stop China from obtaining core technology — the chip loopholes have made smuggling a de facto norm — while at the same time suffocating the market space and talent ecosystem of US AI companies.

An Unexpected Boost to China's AI Talent

“ Timnit Gebru, founder of the Distributed AI Research Institute

What is certain is that every Chinese person working at a US AI company will consider returning to China as soon as possible, to re-enter a fiercely competitive industry.

When foreign employees cannot so much as touch the models they helped develop, the comparative advantage of working at a US AI company is sharply eroded. The chain reaction the Anthropic episode may set off is this: an accelerated return flow of Chinese AI talent in the United States, a squeeze on the funding and partnership space available to overseas Chinese AI entrepreneurs, and thereby an acceleration of China's drive toward AI self-sufficiency on the talent front — the exact opposite of what the controls were meant to achieve.

A Paradigm Shift: From Chip Controls to Model Controls

Set within the evolutionary sequence of US AI policy, the Anthropic ban of June 2026 represents a paradigm-level shift. Prior controls had concentrated on the hardware layer — export licenses for NVIDIA GPUs, the embargo on ASML lithography machines to China. All of these controls shared one feature: what was controlled was a physical tool, not a digital capability.

The Anthropic ban shows that the boundary of US export controls is migrating from "you may not build it" to "you may not use it." The model itself — a purely digital product of knowledge — has henceforth been placed on the same munitions list as tanks and missiles.

The implications of this leap appear in at least three dimensions:

Dimension Core Change
From tool control to capability control The logic of chip controls is "without top-tier hardware you cannot train top-tier models." The logic of model controls is entirely different: even if you have the hardware, you cannot access a capability that already exists.
Uncertainty becomes the new normal The judgment of Yale Law School professor Ketan Ramakrishnan is worth noting: "The federal government will regulate AI developers strictly. The question is whether that regulation will be conducted in a sensible way."
The risk of a structural reversal in talent flows When the "deemed export" rule leaves foreign employees unable to touch the models they developed, the talent advantage of the US AI industry faces systemic erosion.

OpenAI's Shadow — The Industry's Hidden War Behind the Ban

On June 12, Anthropic issued a sharply worded statement. On its face it was about "complying with the government's export-control directive," but between the lines it pointed at a clear adversary: OpenAI.

The most important passage in the statement was an act of naming names: "We reviewed a report that we understand to be the basis for the government's directive, and verified that the capability levels shown in it are widely present in other models, including OpenAI's GPT-5.5." This was not cooperation; it was a showdown: your problem is also ChatGPT's problem — so why come after us alone?

Anthropic was founded by the Amodei siblings in 2021; its core team and technical backbone came almost entirely from OpenAI. The reason for leaving was not a technical disagreement but a rejection of Sam Altman's business philosophy. Six years later, with Anthropic's valuation approaching US$965 billion and its models topping GPT-5.5 Pro on the leaderboards, the onetime defectors had become the leaders. The party now being chased, unable to overtake on capability, chose the oldest competitive strategy of all — weakening a rival through the power of government.

The Jailbreak Dispute — An Informed Letter, Not a Formal List

Another key thread in Anthropic's statement: the US government determined that it possessed a method that could potentially jailbreak Fable 5. Anthropic's response was that "the vulnerability is not a general-purpose jailbreak."

This game of "you found something but can't use it; we don't see where the problem is" points to an important institutional distinction: the ban was not a listing on an export-control list (such as the BIS Entity List) but an informed letter.

Commentary from the Bilibili creator KingofCard zeroed in on the core difference:

📝 List vs. Letter: The Key Distinction

Removal from a list requires interagency sign-off, legal review, even notification to Congress — whereas withdrawing a letter from the Secretary of Commerce requires only that the Secretary sign another letter.

One Letter from Lutnick — Full Decontrol on June 30

On June 30, 2026, US Secretary of Commerce Howard W. Lutnick sent Anthropic a letter rescinding all control measures on Mythos 5 and Fable 5. The letter's core content had two key elements:

  • The rescission covered both models: Mythos 5 and Fable 5 were decontrolled simultaneously — the letter revoked in full all control measures imposed by the June 12 letter.
  • A condition attached: the Department of Commerce reserved the right to reimpose controls "should circumstances change or should Anthropic fail to honor its commitments."

In the process, Anthropic made one key concession: it agreed to retain Fable customer data for 30 days so that jailbreak attacks could be studied and mitigated.

The Game of Bureaucracy — Why Mythos Could Leave but Fable Could Not

If Lutnick's letter provided a complete framework for decontrol, the real narrative tension lies in why Mythos and Fable traveled two different paths.

Mythos — Anthropic's most formidable cybersecurity model, ranked first on the LLM leaderboards — never had any evidence of a jailbreakable vulnerability. When the government needed to show that "we conducted an assessment and took safeguards," a model with no vulnerability problem was naturally the easiest exit to approve.

Fable 5 — the second-ranked model — had a jailbreak method explicitly demonstrated in the safety evaluation. Even though Anthropic described the method as "non-general and trivial," it existed, and it was on record. That was the sticking point in the government's internal process.

📋 Core Observation

The paradigmatic significance of the ban lies not in how long it lasted — from June 12 to June 30 was only eighteen days — but in its very existence. For the first time, the US government imposed nationality-level access controls on an AI model; however chaotic, however driven by internal infighting, however swiftly reversed the process may have been — the precedent is now written into the rules of the game.

A Two-Way Ban — Anthropic's Tool-Level Blocking and Chinese Companies' Internal Countermeasures

Anthropic's export-control saga ran the full cycle from government ban to decontrol, but Washington's policy pivot was not the end. In early July 2026, Anthropic began to operate on a different plane — imposing technical, proactive bans on Chinese users at the level of its tool products and APIs.

A Covert Identification System Embedded in Claude Code

Guancha.cn, a Chinese news portal, reported on July 3 that since late June, large numbers of Chinese users had had their Claude accounts banned without warning. The Claude Code client was reported to contain a covert user-identification system that reads environmental information — local time zone, proxy IP address, system language pack, and the like — to make a composite judgment of whether a user is connected to China.

Alibaba's External Countermeasure: A Role Reversal from User to Supplier

On July 3, 2026, Alibaba internally announced a complete ban on employees using Claude Code in the workplace, citing the reported security risk that the tool had a backdoor implanted in it. Alibaba placed Claude Code on a list of high-risk software and recommended its own homegrown alternative, Qoder.

The deeper logic of the move is to use the scale of its user base as leverage to counter the ban: as one of China's largest technology companies, Alibaba's internal prohibition propagates into the developer ecosystem — programmers, outsourcing teams, and ecosystem partners within Alibaba's orbit can no longer use Claude Code.

The Two-Way Propagation of the Ban

Anthropic banning Chinese users and Alibaba banning Claude Code — the two events occurred on the same day, and it was no coincidence. Together they form a "two-way ban" at the level of AI tools:

  • On the US-company side: amid the volatility of government export-control policy, firms autonomously enforce a technical blockade as a fallback
  • On the Chinese-company side: the external ban is converted into an internal security decision, with reciprocal blocking carried out in the name of "backdoor risk"
🔥 Structural Observation

The substance of the two-way ban is that technological decoupling is moving from "policy-reversible" to "behaviorally irreversible." A policy-level export ban can be struck down, revised, or deferred, but once a firm-level technical blockade is embedded in product design, dismantling it entails substantial engineering investment and architectural change.