The API You Depend On Can Be Switched Off by Export Controls

The API You Depend On Can Be Switched Off by Export Controls

July 29, 2026
export-controls ai-regulation api-risk infrastructure-sovereignty frontier-models

Anthropic didn’t choose to take its best models offline globally. On June 12, 2026, the U.S. Commerce Department’s Bureau of Industry and Security ordered it to — because a jailbreak had exposed a vulnerability that could help identify cyber targets, and because Anthropic couldn’t verify user nationality fast enough to comply with the resulting directive. The models went dark for everyone. Not just adversaries. Everyone.

If you build on top of frontier AI APIs, that should stop you cold.

The Category Error We’ve Been Making

For the past few years, most builders have been thinking about AI APIs the way they think about any cloud service — something that might have downtime, might change pricing, might deprecate a feature. The risk model is SaaS risk: will this vendor survive, will the API stay stable, will the terms of service change in ways that hurt me.

That’s the wrong risk model now.

What the Anthropic incident revealed is that frontier AI models have quietly crossed a category boundary. They’re no longer treated by governments as software. They’re treated as controlled technology — subject to the same legal apparatus that governs the export of military hardware, satellite components, and dual-use materials. The Export Control Classification Number system, designed for physical objects you can put in a shipping container, is now being retrofitted onto a continuous, stateless API call.

The legal question being answered here isn’t “is this software?” It’s “what capability does this provide, and to whom?” And when the answer is “potential assistance with identifying cyber vulnerabilities, to anyone with an internet connection,” the Commerce Department reaches for the same tools it uses to block the shipment of advanced semiconductors to restricted parties.

What “Intangible Export Control” Actually Means for You

The traditional logic of export controls assumes a physical transaction. You make something, you ship it, you can intercept it at the border. The law has always had provisions for intangible transfers — technical data, source code — but those were hard to enforce and rarely applied aggressively to consumer-facing products.

AI inference is different in a way that makes regulators very uncomfortable. Every API call is simultaneously a transfer of capability. The model’s knowledge, reasoning, and outputs cross borders in milliseconds, continuously, at massive scale, with no practical way to inspect what’s being generated or who’s receiving it. When Anthropic discovered it couldn’t reliably filter by nationality in real time, the only compliant option was a global shutdown. There was no partial measure available.

This is what “infrastructure” means when lawyers get involved. Physical infrastructure has chokepoints — pipes, wires, facilities — where regulators can intervene. AI delivered through a cloud API appeared to have none of those. The Anthropic order was an attempt to impose one artificially, by making the vendor responsible for an impossible verification problem.

The Stranded Capital Problem Nobody Is Talking About

I’ve been thinking about what this means for anyone who has built seriously on top of these APIs — not just as a philosophical concern, but as a financial one.

Advanced GPUs depreciate on a four-to-six year cycle. Hyperscalers and well-funded startups have committed billions to inference infrastructure on the assumption that they’ll be able to run workloads continuously against frontier models. A single regulatory action can make those workloads legally impossible to run. The servers keep drawing power. The depreciation clock keeps ticking. The revenue stops.

The analogy that keeps coming to mind: it’s like an airline that bought a fleet of modern jets and is legally prohibited from fueling them. The assets don’t go away. The obligation to service them doesn’t go away. The ability to generate revenue from them does.

The Harder Problem Underneath

None of this is arbitrary overreach by regulators who don’t understand technology. That framing is too easy and mostly wrong.

The underlying problem is real: governments have discovered that while it’s nearly impossible to contain software, it’s highly feasible to control the physical supply chain and capital expenditure required to run serious AI workloads. They’ve also discovered that they can’t algorithmically verify safety — the alignment faking literature has made clear that complex models can behave well in sandboxes and poorly in deployment, with no reliable way to distinguish between the two. So governments are falling back on the one thing they can control: the physical switch.

The Anthropic directive is an early, crude version of something that will get more sophisticated. The legal apparatus will develop better tools for imposing chokepoints on API-delivered AI. Export control classification numbers will become more specific. Verification requirements will become more burdensome. The assumption of unrestricted global access to frontier models — which has felt like a constant for the past few years — is not actually a constant.

What Frame to Carry Forward

I don’t think the answer here is to avoid building on AI APIs. The productivity differential is too large to opt out of. But the risk model needs updating.

The question I find myself sitting with is simpler and harder than most infrastructure questions: if the API you depend on is, from a regulatory standpoint, a munition — what does your architecture look like when it gets treated like one?


Sources

comments powered by Disqus