President Trump returned to office with a clear promise to the technology industry, namely that the federal government would get out of the way. He had campaigned on dismantling what he called the Biden administration's overreach on AI safety, installed venture capitalist David Sacks as White House AI and crypto czar, and welcomed Big Tech CEOs to his inauguration as a signal of the partnership he intended.

 

For Silicon Valley, the message was unambiguous. The deregulatory era had arrived, and American AI companies would be free to race ahead of China without bureaucratic friction slowing them down. Almost 18 months later, those same companies cannot release their most advanced models without first receiving a phone call from the Commerce Secretary. The story of how that reversal happened, and what it means for US national security, allied trust, and the global AI race, is one the administration has never fully explained.

The Phone Call That Changed Everything

To understand how unusual this moment is, it helps to trace the tensions that had been building well before the most visible confrontations. Anthropic’s relationship with the Trump administration had already grown strained earlier in the year, when the company refused to allow the US military unrestricted use of its AI models for domestic surveillance and fully autonomous weapons systems, a position the Pentagon responded to by designating Anthropic a supply chain risk, effectively barring defense contractors from using its technology.

 

That dispute was still playing out in two separate federal courts when, in April, Anthropic revealed that its newest model, Claude Mythos Preview, was extraordinarily good at finding software vulnerabilities, the kind of flaws hackers exploit to break into computer systems. According to Anthropic’s own disclosure, Mythos found “thousands of high-severity vulnerabilities, including some in every major operating system and web browser.” In one internal test, the model achieved what researchers call “full control flow hijack,” essentially complete takeover of a target system, on ten separate, fully patched systems that had already received their latest security updates.

 

 

Concerned about the potential consequences of releasing a tool this powerful to the public, Anthropic did not launch Mythos openly. Instead, the company launched Project Glasswing, a restricted early-access program that shared the model with a carefully selected group of more than forty major technology companies, including Apple, Microsoft, Google, and Nvidia, as well as US government agencies, specifically to use Mythos’s bug-finding capabilities to patch critical vulnerabilities before bad actors could exploit them. During one such government testing exercise conducted under that program, Mythos identified vulnerabilities in highly sensitive classified US government systems within hours. Senator Mark Warner later told a Senate hearing that, according to the head of the National Security Agency, “this tool broke into almost all of our classified systems, not in weeks but in hours.”

 

That single fact triggered alarm inside the White House. Vice President JD Vance told a group of tech CEOs on a call that included Sam Altman and Anthropic’s Dario Amodei that models like Mythos could let attackers cripple small banks, hospitals, and water treatment plants faster than local governments could respond. The concern was not abstract; A model that can identify and chain together software vulnerabilities autonomously, at the speed and scale Mythos demonstrated, represents a qualitative shift in what cyberattacks could look like, moving from targeted intrusions carried out by skilled human operators to automated, AI-driven campaigns capable of hitting thousands of systems simultaneously.

 

Within weeks, the administration’s posture shifted from racing ahead to reining in. On June 2, Trump signed an executive order asking AI companies to voluntarily give the government access to their most advanced models, what the order calls “covered frontier models,” for up to thirty days before public release. The order explicitly states that nothing in it creates a mandatory licensing or pre-clearance requirement. On paper, participation was optional.

 

In practice, the voluntary framework did not stay voluntary for long. On June 12, just ten days after the executive order was signed, the Commerce Department issued an export control directive ordering Anthropic to block any foreign national, including its own non-US employees, from accessing Mythos and Fable 5. Since Anthropic had no reliable way to verify every user’s citizenship overnight, the company chose to disable both models for everyone worldwide rather than risk violating the order. As former White House AI adviser Neil Chilson put it afterward, “the US government should not hang a Sword of Damocles over every lab’s head, with no indication when it might drop or why.”

 

Then, on June 26, the same pattern extended to OpenAI, except this time without even a formal order, just a staggered release request paired with a personal warning call from the Commerce Secretary. The voluntary framework had become a precedent, and the precedent had become a habit. What had begun as a targeted response to a genuine national security discovery had quietly hardened into a governing architecture that nobody had formally authorized.

 

A Leash With No Visible Hand

What makes this moment genuinely unusual is not that the government is regulating a powerful new technology. Governments regulate dangerous technologies all the time, from pharmaceuticals to aircraft to nuclear materials, usually through laws passed by Congress that establish clear standards, public accountability, and a path to appeal. What is happening to American AI labs right now follows none of that structure. Instead, it relies on a patchwork of export control authority, an executive order with admittedly vague enforcement triggers, and informal pressure delivered through private phone calls between cabinet officials and company executives.

 

Consider how arbitrary the criteria currently appear. When the government partially restored Anthropic’s access to Mythos on June 26, Lutnick’s letter cited “significant progress” the company had made addressing unspecified risks, without detailing what those risks were or what specifically had changed. More than one hundred companies and institutions, many tied to Anthropic’s existing Project Glasswing network, were approved as “trusted partners.” Who exactly qualifies for that label, and why, remains entirely undisclosed. As John Coleman of the Foundation for Individual Rights and Expression put it, “no one knows how these companies are picked and why everyone else is excluded. This is putting too much power in the hands of the government.” Even Sam Altman, whose company largely complied with the government’s request, made his discomfort public. “I just don’t like the idea of the government picking the customers,” he wrote.

 

Furthermore, the national security implications of this opacity cut in multiple directions simultaneously. On one hand, restricting access to models capable of breaching classified systems within hours is a defensible reflex. On the other hand, the same restrictions fell on the NSA itself, which had been actively testing Mythos and found it impressive, only to lose access when the export controls landed. Had Mythos been released without restrictions and exploited in the way Vance described, the consequences could have extended far beyond individual cyberattacks. AI-powered vulnerability exploitation at scale could overwhelm the patching capacity of under-resourced critical infrastructure operators, meaning the damage would fall hardest on precisely the hospitals, water utilities, and community banks that neither have dedicated security teams nor the resources to respond quickly. The administration’s concern was legitimate; However, the method it chose to address that concern has created a different set of risks.

 

Over one hundred cybersecurity executives, including leaders from Adobe and Nvidia, wrote to the administration arguing that removing access to Mythos was actively counterproductive, noting that Mythos is “quite good” at finding and weaponizing software flaws but “not uniquely good at these tasks,” meaning the restriction does little to slow adversaries while meaningfully slowing American defenders. Chinese firm Zhipu released its GLM 5.2 model just one day after the US banned foreign access to Fable 5, and researchers have since found it can match Mythos in bug-finding tasks. China’s 360 Security Technology has separately claimed to have built a tool comparable to Mythos. The gap many assumed would take years to close is now being measured in months.

 

The uncertainty created by this approach is also rattling allies. At the G7 summit in France, leaders from Canada and France raised concerns about becoming dependent on US AI companies that Washington could cut off without warning. Shortly afterward, Canadian firms Cohere and Bell announced a partnership to build “sovereign” AI infrastructure run entirely out of domestic data centers. Kate Koren of the Center for Strategic and International Studies warned that “the longer there isn’t a system in place that will allow US companies to widely release new models, the more likely it is that China will be able to catch up.”

 

Beyond the competitive dimension, the administration’s approach carries a longer-term structural risk. By governing AI through informal executive pressure rather than legislation, the current framework is entirely dependent on the judgment and continuity of the officials currently making the calls. A different Commerce Secretary, a different National Cyber Director, or a different political calculation could produce entirely different outcomes for the same companies and the same models, with no legal standard to constrain or predict the result. That instability is precisely what allies are responding to, and precisely what is accelerating their push toward AI systems that Washington cannot switch off.

 

What emerges from these episodes is a system that functions exactly like a licensing regime in every practical sense, without ever being legislated as one. Companies must seek approval before releasing their most capable products. The government decides, on undisclosed criteria, who gets early access and who waits. Non-compliance carries the threat of export control enforcement, a tool with real legal teeth. And yet, because none of this exists in statute, there is no congressional oversight, no published rulebook, and no formal appeals process. As OpenAI stated in its own blog post, “we don’t believe this kind of government access process should become the long-term default. It keeps the best tools from users, developers, enterprises, cyber defenders and global partners who need them.”

 

The security concerns that triggered this regime were real, and the instinct to act on them was not wrong. The deeper problem is that a system assembled through phone calls, export orders, and undisclosed criteria is not a durable answer to a challenge of this scale. It leaves American companies unable to plan, allied governments unwilling to depend on US AI infrastructure, and adversaries free to develop and deploy comparable capabilities without equivalent restraint. As Anthropic continues negotiating for the return of Fable 5, as OpenAI awaits broader clearance for GPT-5.6, and as China’s labs close the capability gap month by month, the question is no longer whether the United States needs a framework for governing frontier AI. It is whether the absence of one has already cost more than the risks it was designed to prevent.

References

2026. “Anthropic’s Mythos Model Found Vulnerabilities in Classified U.S. Government Systems, Official Says: AP.” CNBC. June 24, 2026. https://www.cnbc.com/2026/06/23/anthropics-mythos-model-found-vulnerabilities-in-classified-us-government-systems-official-says.html.

 

Bellan, Rebecca. 2026. “OpenAI Limits GPT-5.6 Rollout after Government Request, Says Restrictions Shouldn’t Be the Norm | TechCrunch.” TechCrunch. June 26, 2026. https://techcrunch.com/2026/06/26/openai-limits-gpt-5-6-rollout-after-government-request-says-restrictions-shouldnt-be-the-norm/.

 

Field, Hayden. 2026. “Anthropic’s Mythos 5 Is Back.” The Verge. June 27, 2026. https://www.theverge.com/ai-artificial-intelligence/958458/anthropic-mythos-5-is-back-trump-negotiations.

 

James, Luke. 2026. “Trump Signs AI Executive Order Seeking 30-Day Government Access to Frontier Models before Release — Voluntary Framework Will Include Classified Benchmark to Determine Which Models Qualify.” Tom’s Hardware. June 3, 2026. https://www.tomshardware.com/tech-industry/artificial-intelligence/trump-signs-ai-executive-order-seeking-30-day-government-access-to-frontier-models-before-release.

 

Kampman, Jeffrey. 2026. “Anthropic’s Latest AI Model Identifies ‘Thousands of Zero-Day Vulnerabilities’ in ‘Every Major Operating System and Every Major Web Browser’ — Claude Mythos Preview Sparks Race to Fix Critical Bugs, Some Unpatched for Decades.” Tom’s Hardware. April 7, 2026. https://www.tomshardware.com/tech-industry/artificial-intelligence/anthropics-latest-ai-model-identifies-thousands-of-zero-day-vulnerabilities-in-every-major-operating-system-and-every-major-web-browser-claude-mythos-preview-sparks-race-to-fix-critical-bugs-some-unpatched-for-decades.

 

Knight, Will. 2026. “I Met with China’s Top AI Experts. They’re Freaking Out, Too.” WIRED. June 24, 2026. https://www.wired.com/story/ai-arms-race-china-us-cooperation/.

 

McMillan, Robert , Raffaele Huang, and Amrith Ramkumar. 2026. “China Has Matched Anthropic in Cybersecurity, Resetting AI Race.” WSJ. June 27, 2026. https://www.wsj.com/tech/ai/chinese-ai-anthropic-mythos-cybersecurity-574b02c2.

 

Morales, Jowi. 2026. “OpenAI’s ChatGPT-5.6 Gets the Same Banhammer Treatment as Anthropic’s Mythos from the Federal Government — Source Says That Washington Cautioned OpenAI against Releasing the Model without Receiving Approval.” Tom’s Hardware. June 26, 2026. https://www.tomshardware.com/tech-industry/artificial-intelligence/openais-chatgpt-5-6-gets-the-same-banhammer-treatment-as-anthropics-mythos-from-the-federal-government-source-says-that-washington-cautioned-openai-against-releasing-the-model-without-receiving-approval.

 

Ramkumar, Amrith , Brian Schwartz, and Natalie Andrews. 2026. “How Anthropic’s Mythos Threw the White House AI Strategy into Chaos.” WSJ. May 7, 2026. https://www.wsj.com/tech/ai/trump-ai-anthropic-mythos-regulation-2378971f.

 

Schwartz, Leo, Stephanie Palazzolo, and Amir Efrati. 2026. “Trump Administration Asks OpenAI to Stagger Release of New Model over Security Concerns.” The Information. June 25, 2026. https://www.theinformation.com/articles/trump-administration-asks-openai-stagger-release-new-model-security-concerns.

 

Comments

Write a comment

Your email address will not be published. Required fields are marked *