AI Styling Studio — Infinite avatar looks from just 1 photo.Try it now.

BestAITools

Submit your Tool

8000+ AI tools already listed
8K+Tools
100K+/moViews
25K+/moVisitors

AI NewsEncryption, spyware, and now Mythos: History shows why cyber export control doesn’t work

Encryption, spyware, and now Mythos: History shows why cyber export control doesn’t work

8:01 AM IST · June 20, 2026

Encryption, spyware, and now Mythos: History shows why cyber export control doesn’t work

Last Friday, citing unspecified national security concerns, the White Houseordered Anthropicto restrict the export of its powerful AI models Fable and Mythos to anyone outside of the United States, as well as foreign nationals inside the country. Shortly after, the AI giant hastily pulled the plug on both models, which have now been unavailable to anyone for a week. The episode is the first real test of whether the U.S. government can use export controls to contain frontier AI the way it has tried, with very uneven results, to contain encryption and spyware before it. And dramatic as it may sound, how this standoff gets resolved could shape not just Anthropic’s access to foreign markets but the rulebook that other AI labs will have to build around. Some context first.Ever since Anthropic launched Mythos in April, the company has marketed it assome kind of Doomsday cyber machinethat could wreak havoc on the internet if released too widely — which is why, before the ban,only around 150 vetted companies and government organizationshad access to it at all. The goal was helping defenders secure their software and services before the bad guys could reach Mythos-like capabilities. So what triggered the ban? Two subsequent events, reportedly. The first: Anthropic gave a South Korean telecom access to Mythos through its limited partner program, and U.S. officials grew alarmed after identifying the company as one they suspected had ties to China. (The company,widely reportedto be SK Telecom, hasdeniedany China connection.) Amazon CEO Andy Jassy also reportedlyalerted the administrationafter Amazon’s own researchers, he said, found a way around Fable 5’s safeguards. Anthropic disputes the “jailbreak” label, calling it a narrow, already-patched issue rather than a wholesale defeat of the model’s safety measures. The result was the same: the Commerce Department issued an export control directive, and Anthropic had to scramble to immediately limit access to its products — within roughly 90 minutes of being notified, by some accounts. None of this is new, though. Governments have tried to use export controls to limit the proliferation of what they see as dangerous cyber technology for decades, but their track record has been middling at best. The U.S. government was behind what is perhaps history’s most spectacular failure of this approach in the early to mid-1990s. At the time, computer scientists were developing encryption technologies to secure data as it traveled over the internet. One of those encryption products was called Pretty Good Privacy, or PGP, a popular software that could encrypt data and make it virtually impossible to unscramble even if intercepted as it traveled to its intended recipient over the internet. The U.S. government initially saw PGP as a dangerous weapon, fearing it would prevent its intelligence agencies from snooping on emails as they crossed their wires. To stop the distribution of PGP, the U.S. Customs Serviceopened a criminal investigationagainst PGP’s creator Phil Zimmermann for allegedly violating arms export controls. He fought back by publishing PGP’s source codeas a printed book, igniting what is known today as the “Crypto Wars.” Zimmermann later won a key battle when the investigation was closed, paving the way for crucial end-to-end encryption algorithms such as the one used by billions of Signal and WhatsApp users. Later during the early 2010s, researchers began discovering Western-made spyware used against dissidents in the Middle East. In response, several governments agreed to expandthe Wassenaar Arrangement, an international treaty that limits the export of dual-use software and technologies that are used in both civilian and military applications. The idea was to classify surveillance and hacking software as dual-use, thus forcing spyware makers to get export licenses to sell their products abroad. Contact UsDo you have more information about the Mythos ban? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, oremail. But Wassenaar has always had two inherent weaknesses. There are several countries that don’t adhere to the agreement, including Israel, which houses some of the world’s most active spyware makers. The agreement also depends on countries applying it to companies within their borders at their own discretion. For a time, the Italian government allowed one of the country’s then-top spyware makers, Hacking Team, a license to export its tools around the world, despite the company’s track record of selling spyware tooppressivegovernmentsthatused itto hack journalists and human rights activists. Since then,othercountriesin Europe have been lax with spyware makers like Italy. Despite numerous scandals, Europe, home tomany spyware and hacking tools makers, hascontinually failed to curb the export of spywareto authoritarian regimes. Critics say that a recently renewed effort across the bloc of 27 member states to tackle its growing problem of spyware exports to authoritarian states “does not go far enough.” Several spyware makers, such as Intellexa, a sanctioned consortium of spyware companies,  have simply moved their operations to countries with lax export controls. Other spyware makers sought to move their operations to Saudi Arabia for similar reasons. There have been some wins. Germany-based spyware maker FinFishershut down in 2022after a multi-year investigation by German prosecutors into the company forallegedly selling spywareto Turkey without an export license. Investigators previously found the FinFisher spyware had beendeployed on the phonesof critics of Turkey’s government. As of the time of writing, the impasse between Anthropic and the Trump administration remains. There is a reasonable chance the administration will buckle and lift the restriction in the interest of keeping American AI companies competitive worldwide — a move that would amount to tacit acknowledgment that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of what the U.S. restricts. Or, American AI companies could end up needing government approval before serving foreign customers at all, a compliance burden that would invariably dent their bottom line. Given the past experiences that world governments have had with trying to control the reach of software, government-mandated export controls are unlikely to be the right approach to stop malicious actors from abusing powerful dual-use cyber technologies.

read more

Latest AI News

View All News →
Experts say exploiting Anthropic’s Fable isn’t how Kimi K3 got so good

Experts say exploiting Anthropic’s Fable isn’t how Kimi K3 got so good

White House science advisor Michael Kratsios said that Moonshot, the Chinese company behind the Kimi K3, the largest available open-weight LLM, built its model by copying Anthropic’s Fable LLM while using chips that aren’t cleared for export to China. “Large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable,” Kratsioswrote, amid reported discussions aboutbanning Chinese open-weight modelsthat have roiled the AI sector. Moonshot did not respond to questions about its training process, and Kratsios did not share more details about the sources of his allegations. Kratsios’ tweet echoed comments from Treasury Secretary Scott Bessent that “we are finding watermarks of our U.S. large language models on many of the Chinese models, and that that’s unacceptable.” It’s not clear what those watermarks consist of, and the Treasury Department did not respond to a query. However, experts are skeptical that distillation—the process of querying an LLM to determine its inner workings and copy its capabilities—is responsible for the advanced capabilities that Kimi K3 displays. “I don’t think you get a model this strong and this quickly on the heels of Fable doing strictly distillation,” Braden Hancock, a researcher at the Laude Institute and co-founder of Snorkel AI, told TechCrunch. “There’s just not even frankly time, right? Fable’s only been publicly available since July 1st. You can’t distill that much data, train a model, and release it in two weeks.” “I’ve been of the opinion that distillation has becoming less and less impactful over time as the Chinese models get closer to the frontier and the training regime shifts to [reinforcement learning],” Nathan Lambert, an AI researcher at the Allen Institute for AI, said in apodcastreleased yesterday. “[I]f it were the case, everyone would be easily able to catch up to a GLM or to a K3 by using its data for distillation. But we have not, or we won’t see this, from supervised fine-tuning alone.” Performing distillation requires a lab to systematically query its target model in order to generate data that can be used for post-training. Sometimes this explicitly involves asking the model to articulate its chain-of-thought to understand how it solves problems. Other times, the prompts and responses from a model are used to train a new model in a process called supervised fine-tuning, or SFT. It’s this fine-tuning process that can result in a model ostensibly created by a third party claiming that it is Claude. Fine tuning is where, in Lambert’s view, the “model picks up its manners.” But Lambert says that the benefits of SFT are becoming less important as models become more complex. To distill Fable-like capabilities would likely require reinforcement learning techniques. In many cases, that means having an agent of the larger model grade the smaller model’s responses, and adjusting based on the grade. The more advanced techniques also require more significant infrastructure. Large reinforcement learning runs can require tens of millions of agents. Using a frontier lab’s API to do that “would be insanely expensive and potentially it would probably be a time bottleneck because these models are pretty slow and to be frank might not even give you a performance uplift.” It seems likely that previous frontier models might have contributed to Kimi; Anthropicpublicly accusedMoonshot, DeepSeek and MiniMax of systematically distilling its models earlier this year. Anthropic said it discovered millions of exchanges between its models and users it identified at those companies through IP addresses and other meta data. Those queries were “distinct from normal usage patterns, reflecting deliberate capability extraction rather than legitimate use.” Anthropic didn’t respond to TechCrunch’s queries about Fable distillation. However, distillation is seen as common among AI companies, not just in China. Elon Musktestifiedearlier this year that his company SpaceXAI distilled OpenAI models to develop Grok, and that the practice was common in the industry. The line between distillation and developing synthetic data sets, for example, can be fairly blurry. “[I]n general, Americans are understating the technical expertise of these Chinese teams,” Hancock said. “One of the founders of Moonshot was a CMU PhD student. These are legitimate researchers and engineers doing solid work. …if American models ground to a halt, I think China’s progress would slow, but would still continue. They’re not just riding coattails here.” It’s also hard to disentangle distillation from the second part of Kratsios’ comment — that Moonshot had obtained advanced Nvidia Chips, Grace Blackwell 300s, and also accessed GB300 equipped-servers in Thailand. Those chips are banned from export to China, but a black market exists, according to Sam Bresnick, a research fellow at Georgetown’s Center for Security and Emerging Technology. In May, the founder of Supermicro, a US server builder, was indicted for smuggling advanced chips into China. “I am a proponent of know your customer laws for data centers across the world,” Bresnick said. “If you are letting a company conduct huge training runs on your state-of-the-art hardware, there needs to be a reporting mechanism for who that company is and what they’re doing.” President Joe Biden’s Department of Commerceproposedfederal know-your-customer rules for data centers in 2024, but no further progress appears to have been made under Donald Trump. Exporters shipping advanced chips abroad, however, aresupposed to ensurethey are only used for approved purposes.

3 hours ago

View

ServiceNow AI Crosses $1 Bn ACV as Enterprise Demand Lifts Q2 Revenue

ServiceNow AI Crosses $1 Bn ACV as Enterprise Demand Lifts Q2 Revenue

The AI annual contract value has topped $1 billion as agentic AI deployments surged ninefold in nine months. The company raised full-year subscription revenue guidance after beating Q2 estimates.

3 hours ago

View

JAN AI & VTU Bring Human-Centred AI Training to Women Engineering Students

JAN AI & VTU Bring Human-Centred AI Training to Women Engineering Students

The company is training women engineers to use AI to address local challenges instead of focusing solely on automation.

3 hours ago

View

[Exclusive] Ex-GitHub CEO Targets Indian Developers for AI-Native Venture

[Exclusive] Ex-GitHub CEO Targets Indian Developers for AI-Native Venture

Former GitHub CEO Thomas Dohmke's startup Entire has launched an India region for its Distributed Git Network to meet data residency requirements.

3 hours ago

View