The Model That Became a Visa

Share

In June 2026, the United States government directed Anthropic to suspend access to its most capable models - Fable 5 and Mythos 5 - for foreign nationals. Commerce Secretary Howard Lutnick wrote to Dario Amodei: the two models would be subject to export controls to any location outside the US, and to all foreign persons within it. The directive arrived without a court order, without a public appeals process, without a notice period that would allow affected users to retrieve their work or arrange alternatives.

There was a stated reason, and it is worth stating, because the argument that follows does not need to pretend otherwise. A rival company had claimed to jailbreak Mythos; officials grew alarmed about national security; the machinery of export control was the tool nearest to hand. Anthropic itself pushed back, calling the concern narrow and the remedy disproportionate. One does not have to decide who was right about the risk to notice what the episode revealed about the infrastructure.

Because here is the part that no amount of reasonable rationale tidies away. Anthropic could not cleanly separate foreign nationals from everyone else - not at the speed demanded - so it did the only thing it could and switched the models off for all customers. The gate built to keep some people out closed on everybody, Americans included. The nationality check was the mechanism; the collateral was universal. An instruction moved through a chain of command, and infrastructure that millions treated as a utility went dark - first for anyone with the wrong passport, then, briefly, for anyone at all.

No law was changed. No court ruled. No treaty was invoked.

The Export Control Logic, Extended

This is described, in the coverage, as an export control action. The framing is technically coherent: the US has an extensive regime of export controls - the Export Administration Regulations, the International Traffic in Arms Regulations - that restricts the transfer of certain technologies to foreign nationals and foreign countries. These regimes were designed for physical goods, then adapted for software, then stretched to cover cryptography, then stretched further to cover hardware.

The extension to AI model access is new. It is also, in retrospect, obvious. If export controls can reach software, and if AI models are software (they are), and if AI capabilities are dual-use technologies (they are), then the machinery was always there. Someone just needed to turn it on.

The Clause was already in the regulations - 15 CFR, dormant, patient, drafted decades before anyone trained a transformer. It did not need to be written. It needed to be noticed, by the right official, on the right morning. The Clause is rarely in a hurry. It can afford not to be; it is already on the books.

However, the governance implications of that switch are not small.

The Assumption Adequacy Decisions Embed

The entire architecture of EU-US data cooperation rests on an assumption so fundamental it is almost never stated: that American legal process is general. The adequacy decisions, the Data Privacy Framework, the standard contractual clauses, the data transfer mechanisms - all of these were negotiated on the assumption that American enforcement applies uniformly, that the FTC enforces the same privacy commitments against any company that makes them, that US courts adjudicate disputes under consistent procedural rules.

Forever Barred analyzed what happens when that assumption breaks down on the enforcement side: when enforcement becomes a discretionary good, available to some and not others, formalized in private settlement agreements. The model access directive breaks the assumption on the access side: when the availability of US-hosted infrastructure becomes contingent on the nationality of the user.

Data adequacy was a privacy question. The Court of Justice asked: does the US offer essentially equivalent protection for personal data? The answer, eventually, was close enough - with conditions, with mechanisms, with ongoing reviews.

Model access is a different layer. It is not asking whether your data is protected. It is asking whether you can use the infrastructure at all. The adequacy framework has no answer for that question, because the adequacy framework was built on the premise that the infrastructure was available and the question was only about its terms of use.

When the US can suspend model access by nationality overnight, the premise is no longer safe. You may find, on a future morning, that the tools your business depends on - the API calls, the agent deployments, the retrieval pipelines - simply no longer work, because someone in a chain of command decided that your passport disqualifies you from infrastructure access. No appeal. No transition period. No court to call.

Scale that anxiety from a business to a state and you arrive at Malta's ChatGPT Time Bomb, which described a government that wired a US commercial AI into its public services as the universal interface for civic life. The Malta analysis worried about where the data went. The model access directive supplies the worry it did not yet have: a country that makes a foreign model its public infrastructure has handed the off-switch to a foreign chain of command. The data-protection question assumed the service would at least keep running. This is the morning it doesn't.

The Sovereignty Argument, Newly Concrete

The European Commission has been arguing for European AI sovereignty for several years. The arguments have been largely competitive - Europe must develop its own capabilities, its own champions, its own infrastructure, to avoid dependence on US or Chinese platforms. The arguments are correct, and they have not yet produced a European model that competes at the frontier.

The model access directive is a different argument for the same conclusion. Not "Europe should build its own because it wants to compete." But: "Europe must build its own because it cannot rely on US infrastructure that can be switched off by executive action, at any time, for any foreign national, without judicial review."

This is a harder argument to dismiss. It does not require believing that Europe can win an AI race. It only requires acknowledging that infrastructure you cannot depend on is infrastructure that, at some point, will not be there. The European Commission, announcing on 14 June that it is examining the practical consequences of the directive - and warning that such measures "should not be discriminatory against partners" - is arriving at the same question.

The same erosion, seen from the enforcement side rather than the access side, runs through Forever Barred.

The timing is notable. The Sophists Have Infrastructure Now traced the ideological coalition that opposes AI regulation in terms of shared vocabulary and shared interests. In the same period that US AI deregulation was being advanced as the liberation of innovation from bureaucratic overreach, the US government was demonstrating that American AI infrastructure is subject to precisely the kind of administrative control that regulation was supposed to constrain. The deregulation is for domestic companies. The control is for foreign users.

This structure has a name in trade policy: asymmetric openness. You lower barriers for your own industry to enter foreign markets, while maintaining the ability to close your own market to foreign participants. The opening is principled; the closure is sovereign.

What a Visa Is, and What a Model Is

A visa is a document that says: this person may enter. There are procedures. There are appeal processes. There are consular offices. There are bilateral treaties that specify which nationals receive which treatment, under which conditions, with which recourse if things go wrong. Visas are blunt instruments, but they are instruments embedded in legal architecture - architecture that took decades to build precisely because "your government decided you can't cross this line" is a thing that happens to real people with real needs.

An AI model access directive says: this person may not use. The difference is that visas have all of the above. The directive had a compliance deadline.

The users affected - European researchers, Japanese engineers, Brazilian lawyers, Indian hospitals - had been using these systems under the implicit assumption that access would be governed by contract, not by nationality. The contract is governed by the jurisdiction of the switch.

This is not, to be clear, the first time US export controls have caught foreign nationals by surprise. Cryptography researchers discovered this in the 1990s. Hardware engineers discovered it when GPU export controls expanded. Each time, the initial reaction was: surely the rules weren't meant to apply this broadly. Each time, they were.

The model access directive is the AI chapter of this story. It will not be the last chapter. The next one will probably involve training data, or fine-tuning pipelines, or the compute infrastructure that runs inference. The machinery of export control is designed for iterative extension.


There is a version of this piece that ends with a recommendation: build European models, fund European compute, create genuinely portable infrastructure. That recommendation is correct and will appear in approximately every policy document published in Brussels this year.

This version ends elsewhere: with the observation that the infrastructure was always a gate. Until June 2026, the gate was usually open, and the opening felt like a feature. It was a feature whose duration depended on a policy decision that no user had visibility into and no court had approved.

The model felt like a tool. When it stopped working based on where you were born, it revealed what it had always been: infrastructure subject to sovereign control, offered to foreign users on terms that could be revised without notice.

The gate was always there. The sign was just taken from the darkest corner and nailed onto them.

Update, 30 June 2026: The Commerce Department lifted the controls, eighteen days after imposing them. Mythos 5 may now be released to a select group of "trusted partners" — companies and federal agencies the Secretary has determined can be trusted. The gate, in other words, opens the same way it closes: by discretion. Nothing above required revision.