从 PGP 到 Mythos:一段未能阻止任何人的出口管制简史
From PGP to Mythos: a brief history of export controls that didn't stop anyone

原始链接: https://techcrunch.com/2026/06/19/encryption-spyware-and-now-mythos-history-shows-why-cyber-export-control-doesnt-work/

美国政府已下令 Anthropic 暂停出口其先进的人工智能模型 Fable 和 Mythos,理由是出于国家安全考虑。此前有报告称这些模型存在潜在的安全绕过风险,且对其外国合作伙伴与中国的所谓关联表示担忧。目前,相关模型仍处于离线状态,业界正等待一个能为人工智能分发建立长期监管框架的解决方案。 这一事态发展标志着出口管制能否有效遏制“前沿”人工智能的一次重大考验。从历史上看,此类尝试——包括 20 世纪 90 年代的“加密战争”以及根据《瓦森纳协定》监管间谍软件的努力——效果参差不齐或收效甚微。批评人士认为,这些管制往往会失败,因为企业会简单地迁往监管较宽松的司法管辖区,或者像加密技术那样,证明该技术根本无法被压制。 目前的僵局使美国陷入了困境:强制执行严格的合规性可能会阻碍美国的竞争力,并给人工智能实验室带来沉重的监管负担,而如果执行不力,则可能让竞争对手占据优势。归根结底,这种情况凸显了在管理强大的军民两用网络技术方面所面临的持续困境,并使人们怀疑传统的出口限制是否是人工智能时代的可行方案。

Hacker News 最新 | 往日 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 从 PGP 到 Mythos:一段未曾阻挡任何人的出口管制简史 (techcrunch.com) 7 点,由 Brajeshwar 发布于 17 分钟前 | 隐藏 | 往日 | 收藏 | 2 条评论 | 帮助 loloquwowndueo 1 分钟前 | 下一条 [–] > 出错了。请在 TechCrunch 上关闭您的广告拦截器。 不,那其实意味着事情进展得很顺利——我的广告拦截器让我免受干扰性、欺骗性、危险内容的轰炸。 专业提示:阅读模式可以绕过这个激进的“滚开”横幅。 回复 rdtsc 6 分钟前 | 上一条 [–] > 据报道,亚马逊首席执行官安迪·贾西(Andy Jassy)在亚马逊自己的研究人员发现绕过 Fable 5 安全防护措施的方法后,也向政府发出了警报。Anthropic 反驳了“越狱”这一标签。 在那儿做着上帝的工作呢,安迪,谢了(反讽)。 想知道 Anthropic 内部关于他这一举动的消息是什么样的。Anthropic 有表情包 Slack 频道吗? 回复 准则 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Last Friday, citing unspecified national security concerns, the White House ordered Anthropic to restrict the export of its powerful AI models Fable and Mythos to anyone outside of the United States, as well as foreign nationals inside the country. Shortly after, the AI giant hastily pulled the plug on both models, which have now been unavailable to anyone for a week. 

The episode is the first real test of whether the U.S. government can use export controls to contain frontier AI the way it has tried, with very uneven results, to contain encryption and spyware before it. And dramatic as it may sound, how this standoff gets resolved could shape not just Anthropic’s access to foreign markets but the rulebook that other AI labs will have to build around.

Some context first. Ever since Anthropic launched Mythos in April, the company has marketed it as some kind of Doomsday cyber machine that could wreak havoc on the internet if released too widely — which is why, before the ban, only around 150 vetted companies and government organizations had access to it at all. The goal was helping defenders secure their software and services before the bad guys could reach Mythos-like capabilities. 

So what triggered the ban? Two subsequent events, reportedly. The first: Anthropic gave a South Korean telecom access to Mythos through its limited partner program, and U.S. officials grew alarmed after identifying the company as one they suspected had ties to China. (The company, widely reported to be SK Telecom, has denied any China connection.) Amazon CEO Andy Jassy also reportedly alerted the administration after Amazon’s own researchers, he said, found a way around Fable 5’s safeguards. Anthropic disputes the “jailbreak” label, calling it a narrow, already-patched issue rather than a wholesale defeat of the model’s safety measures.

The result was the same: the Commerce Department issued an export control directive, and Anthropic had to scramble to immediately limit access to its products — within roughly 90 minutes of being notified, by some accounts.

None of this is new, though. Governments have tried to use export controls to limit the proliferation of what they see as dangerous cyber technology for decades, but their track record has been middling at best. 

The U.S. government was behind what is perhaps history’s most spectacular failure of this approach in the early to mid-1990s. At the time, computer scientists were developing encryption technologies to secure data as it traveled over the internet. One of those encryption products was called Pretty Good Privacy, or PGP, a popular software that could encrypt data and make it virtually impossible to unscramble even if intercepted as it traveled to its intended recipient over the internet. 

The U.S. government initially saw PGP as a dangerous weapon, fearing it would prevent its intelligence agencies from snooping on emails as they crossed their wires. To stop the distribution of PGP, the U.S. Customs Service opened a criminal investigation against PGP’s creator Phil Zimmermann for allegedly violating arms export controls. He fought back by publishing PGP’s source code as a printed book, igniting what is known today as the “Crypto Wars.” 

Zimmermann later won a key battle when the investigation was closed, paving the way for crucial end-to-end encryption algorithms such as the one used by billions of Signal and WhatsApp users. 

Later during the early 2010s, researchers began discovering Western-made spyware used against dissidents in the Middle East. In response, several governments agreed to expand the Wassenaar Arrangement, an international treaty that limits the export of dual-use software and technologies that are used in both civilian and military applications.

The idea was to classify surveillance and hacking software as dual-use, thus forcing spyware makers to get export licenses to sell their products abroad. 

Contact Us

Do you have more information about the Mythos ban? From a non-work device and network, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

But Wassenaar has always had two inherent weaknesses. There are several countries that don’t adhere to the agreement, including Israel, which houses some of the world’s most active spyware makers.

The agreement also depends on countries applying it to companies within their borders at their own discretion. For a time, the Italian government allowed one of the country’s then-top spyware makers, Hacking Team, a license to export its tools around the world, despite the company’s track record of selling spyware to oppressive governments that used it to hack journalists and human rights activists. 

Since then, other countries in Europe have been lax with spyware makers like Italy. Despite numerous scandals, Europe, home to many spyware and hacking tools makers, has continually failed to curb the export of spyware to authoritarian regimes. Critics say that a recently renewed effort across the bloc of 27 member states to tackle its growing problem of spyware exports to authoritarian states “does not go far enough.”

Several spyware makers, such as Intellexa, a sanctioned consortium of spyware companies,  have simply moved their operations to countries with lax export controls. Other spyware makers sought to move their operations to Saudi Arabia for similar reasons.

There have been some wins. Germany-based spyware maker FinFisher shut down in 2022 after a multi-year investigation by German prosecutors into the company for allegedly selling spyware to Turkey without an export license. Investigators previously found the FinFisher spyware had been deployed on the phones of critics of Turkey’s government. 

As of the time of writing, the impasse between Anthropic and the Trump administration remains. There is a reasonable chance the administration will buckle and lift the restriction in the interest of keeping American AI companies competitive worldwide — a move that would amount to tacit acknowledgment that AI labs elsewhere, including in China, will likely reach similar capabilities regardless of what the U.S. restricts. Or, American AI companies could end up needing government approval before serving foreign customers at all, a compliance burden that would invariably dent their bottom line. 

Given the past experiences that world governments have had with trying to control the reach of software, government-mandated export controls are unlikely to be the right approach to stop malicious actors from abusing powerful dual-use cyber technologies.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

联系我们 contact @ memedata.com