White House Making 180 Degree Turn on AI Regulation
A president who ran for office on opposing regulation of any form on AI vendors and suing states that did try to regulate AI is, it seems, having second thoughts. As AI becomes more powerful, it is a legitimate challenge as to what to do. Add to that the fact that whatever he does, the Chinese, based on what they are doing now, may tell him to take a long walk off a short pier. It is hard. Here are my thoughts on the subject.
A new rule, mostly hidden from view
This past June, the White House signed an executive order that does something the U.S. government has never done before: it sets up a process for reviewing the most powerful AI models before the public ever gets to use them. The idea is to check whether a model can be used to break into computer systems or pull off sophisticated cyberattacks, and to give the government roughly a month to look under the hood before a company releases it more broadly.
Officially, this is voluntary. The order goes out of its way to say it isn’t creating a licensing system or a permitting requirement. Companies can choose whether to participate.
In practice, a lot of people who watch this space closely aren’t buying the word “voluntary.” The exact bar a model has to clear before it triggers a review is classified. Nobody outside the process knows precisely what gets a model flagged, or how long a hold might last once it is. And we already have a real-world preview of what “voluntary” can mean in practice: in June, the Commerce Department used a separate, older set of export-control powers to cut off global access to two of Anthropic’s newest models. Access came back about three weeks later. Three weeks might not sound like much, but in an industry where the state of the art can shift in a matter of weeks, it’s a long time to be benched.
The case for doing this
The argument in favor isn’t really about who “wins” the AI race. It’s narrower than that. The worry is that today’s most capable models can write working code, reason through multi-step plans, and — with the right prompting — turn those skills toward finding and exploiting software vulnerabilities. Government testers have reportedly watched AI systems clear cybersecurity challenges that were far out of reach just a year or two ago, and the trend line is climbing fast. On that logic, checking a model’s capabilities before it’s in the hands of millions of people isn’t about beating China. It’s about knowing what you’re releasing into the world, especially when a lot of that world runs on American infrastructure.
The case against it
The counterargument is just as straightforward: none of this makes the underlying problem go away. If a review process slows an American company down — even briefly — it doesn’t stop a comparably capable model from being trained somewhere else. Chinese AI labs have closed most of the capability gap with their American counterparts, and their most popular models are freely downloadable, which means no government review process anywhere can meaningfully restrict them once they’re out. Meanwhile, customers who need reliability above all else — a startup that can’t afford a surprise three-week outage, a company watching its AI bill — have an obvious alternative sitting right there. And the market is already moving. Chinese models’ share of enterprise AI usage has climbed dramatically over the past several months, driven mostly by cost and licensing terms rather than any single dramatic event. A slower, more uncertain U.S. release process doesn’t need to be the main reason for that shift to still be one more reason on the pile.
The part nobody can check: what happens behind the classification wall
Here’s where this gets genuinely uncomfortable. Because the review criteria are classified, and because the negotiations between the government and the handful of companies big enough to be affected are happening out of public view, there’s no way for anyone on the outside to know exactly what gets asked for, or what gets given, in exchange for a model clearing review.
Could that ever extend beyond cybersecurity testing into something like a request for monitoring or tracking capability, as a condition of getting through? There’s no public evidence that has happened. But it would be a mistake to wave the question away as unthinkable, because we already have a real, documented example of an American AI company quietly shipping exactly that kind of thing — just not because a government asked for it. OR, we don’t think the government asked for me.
In the summer of 2026, researchers discovered that Anthropic’s coding tool, Claude Code, had shipped for months with hidden, undocumented code that checked a user’s location and flagged devices that looked linked to China. Anthropic’s explanation was that the code was an experiment to stop rival Chinese labs from illegitimately harvesting its AI’s outputs to train their own models — not something the U.S. government had asked for. China’s government called it a backdoor. Alibaba banned the tool company-wide. Whichever explanation you find more convincing, the episode proves something important all by itself: undisclosed, hidden monitoring code, shipped without a word in the release notes, is not a hypothetical. It has already happened, in this exact industry, within the last year.
Put that together with a classified review process and a government that has already shown it’s willing to use access to a model as leverage, and you land somewhere honest but unsatisfying: there’s no evidence that the frontier-model review process has ever required anything like a backdoor or a surveillance feature as the price of approval. There’s also no way, from outside the process, to prove that it hasn’t, or that it never will. Neither confident claim is one anyone can currently back up.
Where that leaves us
None of the individual pieces here are in serious dispute: the review framework exists and is real; its most consequential details are classified; the government has already used a separate authority to pause access to a major model for weeks; Chinese models are closing the capability gap and picking up market share fast, largely for reasons unrelated to any of this; and undisclosed tracking code has already shown up in a major U.S. AI product, defended after the fact rather than disclosed up front.
What’s genuinely unresolved is how those pieces connect. Whether the review process meaningfully slows American AI companies down, whether that slowdown pushes customers toward Chinese alternatives at any real scale, and whether the pressure to clear a classified review could ever push a company toward a technical trade-off nobody signs off on publicly — all of that is plausible, none of it is proven, and the opacity built into the process means clear proof may never arrive. The most honest thing to do with a question like that is sit with the uncertainty rather than resolve it in either direction. It deserves real scrutiny going forward, not because something has been caught happening, but because the structure of the process makes it genuinely hard to know if it has. More information can be found at Metacurity, but the article is my opinion, not Cynthia’s (the owner of that blog).
