Is the US's Use of Export Controls on AI Services the Quiet Birth of a Global AI Licensing Regime?
By leveraging its jurisdiction over advanced semiconductors and cloud infrastructure, the U.S. government is quietly transforming export controls into a de facto global licensing system for frontier AI models.
- National Security Advocates
- Prioritize preventing adversary access to WMD-capable AI.
- Commercial AI Developers
- Fear loss of global market share and regulatory overreach.
- Global South & Non-Aligned Tech Sectors
- Concerned about being locked out of the AI frontier.
The short answer
- The U.S. is expanding export controls from physical semiconductors to digital AI models and cloud API access.
- The 2026 Remote Access Security Act (RASA) aims to close the "cloud loophole" by regulating Infrastructure-as-a-Service (IaaS) providers.
- In June 2026, the Commerce Department forced Anthropic to abruptly disable its most advanced models, demonstrating the power of this new regime.
- The framework divides the world into tiers, restricting AI access for non-allied nations and adversaries.
- Critics warn that weaponizing AI access will accelerate the development of independent, foreign tech ecosystems.
If you are building a business on top of a frontier AI model today, your software stack no longer depends just on latency, pricing, or compute availability. It now depends on the geopolitical mood of the U.S. Department of Commerce. For decades, export controls were a tool used to stop physical goods—missile parts, nuclear centrifuges, and advanced semiconductors—from crossing physical borders. But in 2026, the definition of an "export" has quietly expanded to include an API call to a cloud server.[4][6]
The U.S. government is rapidly transforming the Bureau of Industry and Security (BIS) into a global AI gatekeeper. By leveraging its jurisdiction over the physical chips that train and run AI, Washington is attempting to control who gets to access the resulting digital models. What began as a targeted effort to deny advanced hardware to adversaries has morphed into something far more expansive: a de facto, worldwide licensing regime for artificial intelligence services.[6]
The argument is straightforward: the U.S. is using the threat of export controls to force AI developers into a "voluntary" pre-clearance system. Rather than passing a comprehensive AI regulatory bill through Congress, the executive branch is using the Export Administration Regulations (EAR) to mandate that frontier models be reviewed and approved before public release.[4]
This shift represents a profound change in how software is governed. Historically, code and model weights were treated as protected speech or unregulated commercial products. Now, they are classified alongside dual-use military technologies. If this regime solidifies, the global AI market will not be a free-flowing digital commons, but a tightly permissioned network where access is granted or revoked based on U.S. foreign policy objectives.[6]
The clearest evidence of this shift materialized in the summer of 2026. In June, the Department of Commerce abruptly imposed export controls on Anthropic's latest models, Fable 5 and Mythos 5. Citing national security concerns over the models' potential to identify cyber vulnerabilities, the government required Anthropic to disable access for all customers worldwide to ensure compliance.[3][7]
Anthropic stated that the net effect of the order was an abrupt shutdown of its most advanced models for all users, as the company could not reliably screen out foreign nationals from its user base. The action marked a major escalation of U.S. efforts to halt foreign adversaries' AI capabilities, shifting the focus from the chips that power AI to the digital models themselves.[3][7]
To understand how the U.S. enforces this, one must look at the underlying legal mechanics. The initial wave of AI export controls in 2022 and 2023 focused on physical hardware—specifically, preventing the shipment of advanced GPUs to countries of concern. However, policymakers quickly realized that foreign entities could simply rent compute power from U.S. cloud providers, a gap dubbed the "cloud loophole."[2]
To close this, the House of Representatives passed the Remote Access Security Act (RASA) in January 2026, granting BIS the authority to regulate remote access to controlled items via Infrastructure-as-a-Service (IaaS) providers. The mechanism is simple: if you use U.S.-origin chips to train your model, the U.S. claims jurisdiction over how that model is accessed, even if the server sits in Europe or the Middle East.[2][6]
The mechanism is simple: if you use U.S.-origin chips to train your model, the U.S.
A critical tool in this enforcement arsenal is the Foreign Direct Product Rule (FDPR). The FDPR allows the U.S. to assert jurisdiction over items designed or manufactured entirely outside the United States, provided they are produced using U.S. technology or software. In the context of AI, this means that even if a foreign company trains a model in a foreign data center, the U.S. can claim regulatory authority if the data center relies on U.S.-origin advanced computing integrated circuits.[1]
This extraterritorial reach has profound implications for open-source AI. The traditional open-source ethos relies on frictionless, global distribution of code and model weights. However, under the new BIS frameworks, publishing a frontier model's weights on the internet could be construed as an unauthorized "export" if those weights are downloaded by a user in a restricted jurisdiction. The chilling effect on the open-source community is palpable, as developers weigh the risk of federal enforcement against the benefits of collaborative innovation.[1][4][6]
The result is the fracturing of the global AI ecosystem into a tiered access system. Under the framework initially proposed in the 2025 "AI Diffusion Rule," the world is divided into distinct categories. Tier 1 countries—close U.S. allies—face minimal restrictions. Tier 2 countries face caps on compute capacity and model access. Tier 3 countries face a near-total embargo.[1]
This tiered approach forces allied nations and non-aligned countries into a difficult position. European policymakers, for instance, are grappling with how to maintain technological sovereignty while relying on U.S. infrastructure that is subject to sudden export restrictions. Meanwhile, the Global South risks being locked out of the most advanced economic tools of the century unless they align with Washington's security priorities.[5][6]
The U.S. strategy is not purely defensive. Alongside export controls, the administration has launched initiatives designed to facilitate the export of the full U.S. AI technology stack to allied nations. By subsidizing allied access while restricting adversaries, Washington is using AI as a geopolitical carrot and stick.[6]
However, this aggressive posture risks accelerating the very outcome it seeks to prevent: the development of independent, foreign AI ecosystems. By weaponizing access to U.S. technology, Washington is providing a massive incentive for countries like China, and even strategic partners in the Middle East, to heavily subsidize their own domestic semiconductor and AI industries.[6]
There is also the question of administrative capacity. Implementing a global licensing regime for software services requires a fundamentally different skill set than tracking physical shipments of titanium or centrifuges. BIS is historically underfunded and understaffed for the monumental task of auditing API logs, evaluating model capabilities, and enforcing KYC rules across thousands of global cloud providers.[4][6]
Critics argue that a more sustainable approach would focus on transparency and post-release monitoring rather than pre-release licensing. Proposals for digital dashboards that track GPU utilization and end-user compliance offer a less intrusive alternative that still protects national security. Yet, for now, the executive branch appears committed to the pre-clearance model.[6]
Despite its rapid implementation, the legal foundation of this de facto licensing regime remains untested. Commerce's authority under the Export Control Reform Act (ECRA) is broad, but using it to restrict domestic API access or mandate pre-release model testing pushes the boundaries of statutory intent.[4]
Furthermore, the reliance on "voluntary" compliance backed by the implicit threat of emergency export controls creates a precarious regulatory environment. If a major AI developer challenges the Commerce Department in court, arguing that model weights are not "items" subject to traditional export controls, the entire framework could unravel. Until then, the U.S. has quietly established itself as the licensing authority for the world's most powerful technology.[4][6]
Jargon, explained
- Export Administration Regulations (EAR)
- The set of U.S. regulations administered by the Commerce Department that control the export of dual-use items.
- Bureau of Industry and Security (BIS)
- The agency within the U.S. Department of Commerce responsible for advancing national security through export controls.
- Foreign Direct Product Rule (FDPR)
- A rule allowing the U.S. to control items made entirely outside the country if they are produced using U.S. technology or software.
- Infrastructure-as-a-Service (IaaS)
- Cloud computing services that provide virtualized computing resources over the internet, allowing users to rent server space.
- Model Weights
- The numerical parameters within an artificial intelligence model that determine how it processes information and generates outputs.
Sources
[1]Akin GumpNational Security AdvocatesBIS Issues New Framework for AI Diffusion
Read on Akin Gump →
[2]FreshfieldsNational Security AdvocatesRASA and the Future of Cloud Export Controls
Read on Freshfields →
[3]The GuardianCommercial AI DevelopersAnthropic says US has lifted export controls on Fable and Mythos AI models after security fears
Read on The Guardian →
[4]Tech Policy PressCommercial AI DevelopersExport controls have long reached more than physical goods
Read on Tech Policy Press →
[5]Infosecurity MagazineGlobal South & Non-Aligned Tech SectorsThe temporary Anthropic AI shutdown highlighted the risks of AI provider dependency
Read on Infosecurity Magazine →
[6]Factlen Editorial TeamGlobal South & Non-Aligned Tech SectorsSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
[7]Associated PressCommercial AI DevelopersAnthropic says it has taken its latest AI models offline to comply with new export controls
Read on Associated Press →
Comments
Every angle. Every day.
Get opinion stories with full source coverage and perspective breakdowns delivered to your inbox.
