
In 1995, a programmer named Adam Back printed the source code for an encryption tool onto a T-shirt and wore it through customs to prove a point: you cannot export-control an idea. Thirty years later, the United States government is betting billions that it can do exactly that with artificial intelligence, but this time, the thing it’s trying to control weighs several tons and requires a multi-billion-dollar factory to build.
The Thesis
The history of the crypto wars demonstrates that export controls on pure information reliably fail. Yet AI is the first technology where the most important inputs are physical rather than informational, which means the old playbook may not apply cleanly. This article examines both sides honestly and argues that AI export controls will partially succeed at the hardware layer while failing almost completely at the model layer, and that policymakers should design strategy around that asymmetry rather than pretending it doesn’t exist.
The Crypto Wars Playbook
The modern debate over AI export controls has a direct ancestor, and it began with an email.
In 1991, Phil Zimmermann released PGP (Pretty Good Privacy), a free encryption program strong enough that governments couldn’t easily break it. The US government responded by opening a criminal investigation into Zimmermann for “exporting munitions without a license,” because under the International Traffic in Arms Regulations (ITAR), cryptographic software was legally classified as a weapon. The same rules that governed missile guidance systems governed a piece of free software.
The absurdity peaked when investigators realized that PGP’s source code had been published in a physical book. Books are protected speech under the First Amendment, so the government’s own logic implied that anyone could legally export the code by mailing the book overseas, and then typing it back into a computer. Adam Back’s T-shirt stunt in 1995 made the contradiction impossible to ignore: if a shirt could carry an export-controlled munition across a border, the control wasn’t controlling anything meaningful.
The legal machinery behind this was the Bureau of Industry and Security (BIS), the Commerce Department agency that administers export controls on dual-use technologies, alongside ITAR’s stricter munitions regime. Critically, “export” was defined broadly enough to include posting code on a public website, meaning a programmer in California could violate federal law by uploading a file that anyone in the world could download. This is the regulatory DNA that today’s AI rules inherit.
The pattern that emerged over three decades is consistent: each attempt to restrict cryptographic knowledge produced workarounds, offshore mirrors, and eventually policy retreat. By the late 1990s, the Clinton administration had largely liberalized crypto exports. By the 2010s, strong encryption was standard in every browser and phone. The controls didn’t stop the spread of the technology; they just delayed it slightly and made the government look technologically illiterate in the process.
Does the Pattern Hold for AI?
Here the analysis splits. The “controls never work” thesis is genuinely strong for software. But AI introduces a variable that cryptography never had: a physical bottleneck.
Why the “controls never work” thesis is strong
Start with the most important fact about AI model weights: they are information. A trained model is, at bottom, a very large file of numbers. Once those numbers exist, they can be copied, compressed, quantized, and posted, exactly like PGP’s source code. There is no physical law that prevents a 400-gigabyte file from crossing a border as easily as a 4-kilobyte one.
The empirical record supports this. Open-weight models from Meta (Llama), Mistral, and DeepSeek have proliferated rapidly despite an increasingly restrictive policy environment. When a frontier-adjacent model is released openly, it becomes globally available within hours, mirrored across dozens of jurisdictions, and fine-tuned by thousands of independent researchers. No enforcement agency can un-ring that bell.
This is why the question “can export controls stop AI” has a documented 30-year answer for the software layer: no. The crypto wars ended in liberalization, not enforcement victory. Every attempt to treat code as a munition ran into the same wall: information doesn’t respect borders, and the First Amendment doesn’t carve out an exception for mathematics.
There’s a deeper structural reason, too. AI model weights regulation faces the same problem crypto did: the regulated artifact is trivially reproducible and the regulated population is enormous. You can license a handful of defense contractors. You cannot license millions of researchers, hobbyists, and foreign labs who can download a file and run it on rented cloud compute.
Why AI is genuinely different, the physical chokepoint argument
Now the counterargument, which is stronger than crypto veterans usually admit.
Frontier AI does not emerge from a laptop. It emerges from advanced semiconductors, and those semiconductors require a supply chain that is among the most concentrated and physically demanding on Earth. The most advanced chips are fabricated by TSMC (Taiwan Semiconductor Manufacturing Company) in Taiwan, using EUV (extreme ultraviolet) lithography machines built exclusively by ASML in the Netherlands. There is exactly one company on the planet that makes EUV machines. There is essentially one company that can use them at the leading edge. You cannot email a lithography system.
This is the crux of the compute chokepoints AI policy argument. Unlike source code, the inputs to frontier AI are physical, monitorable, and finite. A GPU is a physical object with a serial number, a shipping manifest, and a customs declaration. A data center draws measurable power and occupies real land. US chip export restrictions on China and the broader BIS semiconductor export rules target hardware, not speech, which neatly sidesteps the First Amendment friction that doomed crypto controls. You can’t claim a constitutional right to import an H100.
The asymmetry versus 1990s cryptography is real. Training a frontier model requires industrial-scale resources: tens of thousands of specialized accelerators, enormous HBM (high-bandwidth memory) capacity, and power infrastructure measured in megawatts. That’s a meaningful difference from a graduate student compiling PGP on a workstation.
The honest rebuttal, where the hardware thesis weakens
But the hardware thesis has soft spots, and intellectual honesty requires naming them.
First, compute can be smuggled, obfuscated, or substituted. Enforcement leaks are already documented: chips routed through third countries, shell companies, and transshipment hubs. Physical controls are only as strong as the customs regime enforcing them, and the historical record on smuggling dual-use technology is not encouraging.
Second, algorithmic efficiency keeps lowering the compute threshold. The compute required to reach a given capability level falls relentlessly. Today’s frontier model becomes tomorrow’s commodity, runnable on hardware that isn’t export-controlled at all. A control regime calibrated to 2024’s frontier will be obsolete against 2027’s.
Third, distillation and open-weight fine-tuning let actors approximate frontier capability without frontier hardware. A well-resourced lab can train a smaller model to mimic a larger one’s outputs, capturing much of the capability at a fraction of the compute. This is the model-layer leak that no hardware control can plug.
Finally, a note on discipline: there have been reports circulating about a situation involving Anthropic and something referred to as “Mythos.” These reports are unconfirmed and should not anchor any argument. I mention them only to flag that speculation in this space outruns verification, and serious analysis should rest on documented facts, the PGP record, the BIS rulemakings, the open-weight releases, not on unverified claims.
What This Means for Policy and Practitioners
The practical upshot is a two-track regime: tight hardware controls and porous model controls.
For AI labs, this means compliance burdens that fall hardest on legitimate research. Export licensing requirements create friction, legal risk, and delay for exactly the organizations most likely to publish openly and contribute to the field. The cost is borne disproportionately by smaller labs and academic groups who can’t afford dedicated trade-compliance teams.
For cloud providers, the picture is murkier. If controls expand to cover API access, treating the ability to query a frontier model as a controlled export, the enforcement surface becomes enormous and the First Amendment questions return with a vengeance. A model that answers questions is much closer to speech than a chip is to a munition.
For chipmakers and their supply chains, the controls are the most enforceable and the most consequential. US chip export restrictions on China have already reshaped the industry, forcing reallocation of capacity, accelerating domestic Chinese chip efforts, and fragmenting what was a globally integrated supply chain.
The strategic implication is uncomfortable for everyone: controls may slow adversaries at the compute layer while accelerating open-source workarounds at the model layer. Every restriction on closed frontier models increases the relative value of open-weight alternatives. Every hardware chokepoint creates a market incentive to route around it. The policy is not a wall; it’s a tax on speed.
The realistic verdict is partial success, not total victory or total failure. Hardware controls can impose real delay and real cost. Model controls cannot prevent proliferation. A strategy that pretends otherwise will waste resources and erode credibility.
Key Takeaways
- Export controls on pure information have failed for 30 years, from PGP’s munitions classification to today’s open-weight model releases. The pattern is not a coincidence; it’s structural.
- AI’s physical chokepoints, chips, fabs, compute, make it the first test case where controls might partially work. The hardware layer is monitorable in a way that source code never was.
- Hardware restrictions are enforceable; model-weight restrictions are largely not. Design policy around that asymmetry instead of fighting it.
- Falling compute costs and distillation steadily erode the hardware advantage. Controls calibrated to today’s frontier will be obsolete within a few years.
- The realistic policy goal is delay and cost-imposition, not prevention. Framing matters: a strategy that promises prevention will be judged a failure, while one that promises delay can succeed.
What to Watch Next
Several developments will determine whether the hardware thesis holds or collapses into the crypto-wars pattern.
First, watch the evolution of BIS semiconductor export rules, specifically whether they expand to cover model weights, API access, or cloud compute rentals. Each expansion tests the boundary between hardware control and speech regulation.
Second, track whether open-weight releases continue to close the gap with frontier closed models. If the gap narrows, the hardware chokepoint loses strategic value regardless of enforcement.
Third, watch enforcement actions and smuggling cases. Every documented transshipment case is a data point on whether physical controls actually bind.
Fourth, monitor international coordination, whether allies adopt matching controls or become the leak in the system.
Finally, treat any verified developments on the reported “Mythos”/Anthropic situation as potentially significant, but currently unconfirmed. The lesson of the crypto wars is that the technology always outruns the policy. The open question for AI is whether the physics of silicon will finally slow it down.

