Friday, September 11, 2026
AI 인프라 · 뉴스 & 분석
반도체·하드웨어리포트
반도체·하드웨어 · 리포트

상무부, 차세대 AI 모델에 대한 수출 통제 연장 및 특정 신뢰 파트너에 대한 출시 승인

업계 전문지Slicast · September 6, 2026 · 글로벌 · 출처: Mayer Brown
중요도 79

Through targeted, company-specific actions, the U.S. government has taken the unprecedented step of extending export controls to both artificial intelligence (“AI”) models and access to those models, creating uncertainty across the cloud-computing and AI industries.

Background

On June 12, 2026, the U.S. Commerce Department, signed by Secretary Howard Lutnick, issued an Is-Informed Letter (“IIL”) export control directive to Anthropic. The directive requires the company to obtain a license before exporting, reexporting, or transferring (in-country) its Mythos and Fable models, including to any foreign person worldwide—even if that person is employed by Anthropic within the United States. According to public reporting, the Anthropic IIL followed outreach to senior government officials by a U.S. company. That company raised concerns that researchers had identified a method to bypass safety guardrails, granting unrestricted access to cybersecurity capabilities such as identifying previously unknown “zero-day” vulnerabilities and generating working exploit code. In response, Anthropic announced that blocking access solely for foreign persons on short notice was not technically feasible, and consequently disabled the models for all users worldwide.

These actions followed the June 2, 2026, release of an Executive Order on promoting advanced AI innovation and security (see our recent Legal Update), which established a mechanism for voluntary collaboration between the AI industry and the government regarding frontier model deployment.

One week after issuing the Anthropic IIL, Secretary Lutnick issued a second letter on June 26, 2026, exempting “certain trusted partners,” their foreign national employees, and Anthropic’s own foreign national employees from the license requirement applicable to Mythos 5. The letter did not address exemptions for the license requirement applicable to Fable 5. In a parallel announcement, Anthropic confirmed that the U.S. government approved the deployment of Mythos 5 to a “set of U.S. organizations that operate and defend critical infrastructure.” On the same date, another AI model developer announced that, as part of its next-generation model launch, it had previewed the models’ capabilities to the government. At the government’s request, the company began releasing the AI models first to a “small group of trusted partners whose participation has been shared with the government.” The company asserted that this “short-term step” represents “the strongest path to broader availability [of the AI models] in the coming weeks, while we work with the Administration to develop the cyber Executive Order framework and a repeatable process for future model releases.”

Legal Considerations

The Anthropic IIL asserts two substantive grounds for Commerce Department authority. First, Section 4817(b)(1) of the Export Control Reform Act of 2018 (“ECRA”), which authorizes the Commerce Department to establish interim controls on emerging or foundational technologies essential to national security. Second, Section 744.22(b) of the Export Administration Regulations (“EAR”), which authorizes Commerce’s Bureau of Industry and Security (“BIS”) to notify a party that a license is required for specific exports, reexports, or in-country transfers of any EAR-subject item when there is an unacceptable risk of diversion to a “military-intelligence end use” or “military-intelligence end user” in countries of concern, including China and Russia.

Commerce’s exercise of jurisdiction over an AI model as an item subject to ECRA and the EAR is novel. Similarly, BIS’s assertion that providing access to a model constitutes an export, reexport, or in-country transfer marks a significant departure from prior practice.

Controls on AI Models

Under ECRA and the EAR, the Commerce Department identifies commodities, software, and technologies subject to its jurisdiction. If the AI models themselves are the controlled item, this would mark the first time Commerce has treated an AI model—rather than its weights or source code—as controlled technology under the EAR.[1] The January 2025 AI Diffusion Rule, for which the Trump Administration established a non-enforcement policy, extended controls over model weights rather than models, while remaining silent on whether models constitute technology. Statutorily, “technology” is defined to include “information, in tangible or intangible form, necessary for the development, production or use” of a commodity, software, or other technology. The EAR uses the term “required” instead of “necessary.” Notably, the IIL does not specify which Commerce-jurisdiction items these AI models are necessary or required for in terms of development, production, or use.

Controls on API-based Access to an AI Model

The IIL treats remote, API-based access to a model as a “release” controlled under ECRA and the EAR. Historically, however, Commerce’s consistent position has been that remote access to cloud-based software, without the transfer of technology or source code, does not constitute an export—including intangible transfers of technology or “deemed exports.” Three BIS advisory opinions (issued in 2009, 2011, and 2014) have been widely relied upon by the industry and remain published on the BIS website. This longstanding assessment that remote access falls outside export-control jurisdiction is further reinforced by pending congressional legislation: the Remote Access Security Act would amend ECRA to explicitly authorize BIS to regulate remote access to EAR-subject items. The bill’s existence indicates a legislative judgment that additional statutory authority is required for BIS to reach remote access—a premise the IIL appears to bypass by assuming existing authority.

The IIL’s reliance on the EAR’s military-intelligence end-use/end-user provisions—which are tied directly in the regulations to specific countries, including China and Russia—for an access control is also notable. Given the reported offensive capabilities of these models, BIS’s determination of an unacceptable risk to foreign military-intelligence services rests on a factual basis documented in the public record.

Nevertheless, applying these grounds to justify a worldwide license requirement that reaches every foreign person, regardless of country or end use, remains entirely without precedent.

Legal Challenge

The Commerce Department is already facing legal challenges regarding the Anthropic IIL. An Anthropic customer that utilized the Fable 5 model and employs staff in Canada is seeking to vacate and enjoin the directive, arguing among other grounds that it exceeds the government’s statutory authority.[2]

Implications for the AI Industry

If BIS now treats AI models themselves as controlled technology—whether through interim orders or industry-wide directives carrying the force of regulation—that precedent could extend far beyond the models of one or two developers. Similarly, if BIS concludes it can regulate remote access under its current legal authority, it could expand jurisdiction over a wide range of activities involving foreign persons that have historically fallen outside dual-use export controls. Any company offering AI-driven cloud products, particularly dual-use cybersecurity tools capable of identifying software vulnerabilities or repurposed for offensive operations, could face identical scrutiny if BIS applies the IIL’s reasoning broadly.

Under a broad interpretation of the IIL, customer-facing AI-as-a-Service (AIaaS)—where foreign persons remotely access AI outputs—and internal operations, where foreign-national employees develop or maintain AI infrastructure domestically or abroad, could trigger license obligations. A narrower reading suggests BIS aims specifically to curb the offensive output capabilities of these models, rather than asserting general jurisdiction over AI models.

Confronted with what the U.S. government considers a significant national security threat, Commerce has activated available tools, including directives and negotiations. These measures do not preclude more tailored controls in the future, such as the referenced “repeatable process.” For instance, once BIS identifies the technical parameters across concerning AI models, it could publish a control within the Export Control Classification Number 0Y521 holding category. This would establish a common understanding among AI model developers regarding the specific thresholds that trigger U.S. government concern.

How We Can Help

Please reach out to our Mayer Brown team if you have questions regarding how the U.S. government is interpreting the ECRA and EAR, or how it is utilizing the voluntary process outlined in the June 2026 AI Executive Order. We can assist clients in engaging proactively with U.S. authorities and mapping their exposure to potential future controls.

[1] While the EAR’s technology definition includes the word “models,” that reference dates to at least 1996, well before modern AI models existed.

[2] Legion LegalTech, Corp. v. United States, No. 1:26-cv-02225

원문 보기