<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Internet Governance Project</title>
	<atom:link href="https://www.internetgovernance.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.internetgovernance.org/</link>
	<description></description>
	<lastBuildDate>Sat, 01 Aug 2026 20:07:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>
	<item>
		<title>Colliding AI governance Narratives</title>
		<link>https://www.internetgovernance.org/2026/08/01/colliding-ai-governance-narratives/</link>
					<comments>https://www.internetgovernance.org/2026/08/01/colliding-ai-governance-narratives/#respond</comments>
		
		<dc:creator><![CDATA[Milton Mueller]]></dc:creator>
		<pubDate>Sat, 01 Aug 2026 20:01:15 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Digital Trade]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Geopolitics of IG]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10556</guid>

					<description><![CDATA[<p>For the past 4 years, public policy toward “AI” has been driven by two competing narratives. In the past two weeks, the clash between them has blown up in the faces of policy makers and AI service providers, especially Anthropic and Open AI.  Narrative 1  One camp told us that AI “models” might evolve into an [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/08/01/colliding-ai-governance-narratives/">Colliding AI governance Narratives</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">For the past 4 years, public policy toward “AI” has been driven by two competing narratives. In the past two weeks, the clash between them has blown up in the faces of policy makers and AI service providers, especially Anthropic and Open AI.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Narrative 1</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">One camp told us that AI “models” might evolve into an autonomous, omnipotent life form and destroy us. Continued progress in the development of digital information systems, they claimed, might produce a superintelligence that was outside our control. Even those who didn’t anticipate human extinction spoke darkly of AI’s potential to create “catastrophic risks.” This threat became the groundwork for global society’s overwhelming focus on ”safety,” “guardrails,” and controls over the release of new AI models.</span><span data-ccp-props="{}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Narrative 2</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">The other camp told us that we were in a race to develop AI. AI will drive both economic growth and national power; thus, we should encourage and accelerate its development. The government must ensure US leadership in AI with subsidies here, protections and tariffs there, and a systematic attempt to block or handicap China’s digital capabilities. The contestants in the race, in other words, are not private firms competing for markets and profits, but nation-state-led systems of political economy. China is our opponent – our “adversary” &#8212; and must therefore be “beaten” in this “race.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">It should be apparent that the policy implications of Narrative 1 and Narrative 2 are in direct conflict. Narrative 1 wants us to slow down development, if not abandon it altogether, and engage in global collective action to maintain control. Narrative 2 tells us to accelerate development unilaterally as a nation and dismisses ex-ante safety regulations as roadblocks. If AI really generates a race with a military and political adversary, our national security depends on running as fast and hard as possible. </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">The weird thing about these two incompatible narratives is that many of the big players in the AI governance drama want to believe both at the same time. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Converging Narratives</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:279}"> </span></h2>
<p><span data-contrast="auto">What happened in the past two months (June &#8211; July 2026) was a remarkable collision between the two narratives. The Trump administration now wobbles between the two, unpredictably and incoherently.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">It started with the June 2 </span><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"><span data-contrast="none">Executive Order (#14409)</span></a><span data-contrast="auto"> (no doubt inspired by <a href="https://www.zafran.io/resources/after-mythos-preparing-for-cybersecuritys-manhattan-project-moment?utm_feeditemid=&amp;utm_device=c&amp;utm_term=mythos&amp;utm_source=google&amp;utm_medium=ppc&amp;utm_campaign=NA-Search-Mythos-Glasswing&amp;hsa_cam=23753130897&amp;hsa_grp=195131596509&amp;hsa_mt=p&amp;hsa_src=g&amp;hsa_ad=805501252210&amp;hsa_acc=3287052660&amp;hsa_net=adwords&amp;hsa_kw=mythos&amp;hsa_tgt=kwd-219886554&amp;hsa_ver=3&amp;gad_source=1&amp;gad_campaignid=23753130897&amp;gclid=CjwKCAjwsrbTBhAvEiwA0Bpp4WAApRlbgB469r5Ja0QW8N4i5VFm5jNHPEjpx55MxnlBLg5LhPvG9RoCsn8QAvD_BwE">Mythos’s ability to find software vulnerabilities</a>). EO 14409 is a schizophrenic document. Section 1 speaks of the “enormous talent and innovation of our AI industry” and attributes that innovation to our refusal “to stifle this innovation with overly burdensome regulation.” Section 3, on the other hand, gives the Director of NSA and other representatives of the Department of War, the National Cyber Director, and the Director of the Cybersecurity and Infrastructure Security Agency the authority to review AI models before they are released. It asks the companies to “provide the Federal Government with access to covered frontier models &#8230; for a period of up to 30 days before they plan to release such models to other trusted partners.” </span><span data-contrast="auto">The EO claimed that “</span><span data-contrast="auto">Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models.”</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">A few days later, on June 12, </span><b><span data-contrast="auto">t</span></b><span data-contrast="auto">he U.S. Commerce Department did exactly what the EO promised not to do. It </span><span data-contrast="auto">applied mandatory export controls to Anthropic’s Claude Fable 5 and Claude Mythos 5 models to restrict access to foreign nationals, whether inside or outside the United States. </span><a href="https://www.anthropic.com/news/redeploying-fable-5"><span data-contrast="none">Anthropic responded</span></a><span data-contrast="auto"> by suspending access to everyone. “Because the order took effect immediately and we had no reliable way to verify nationality in real-time,” the company explained, “we suspended access to both models for all users.” </span><span data-ccp-props="{&quot;335559685&quot;:0}"> </span></p>
<p><span data-contrast="auto">Although the ban was lifted June 30, the incident triggered </span><a href="https://www.aei.org/commentary/the-mythos-moment-and-the-reordering-of-ai-governance/?utm_campaign=21442611-TECH_NLR%20Tech%20Policy%20Outlook%20Technology&amp;utm_medium=email&amp;_hsenc=p2ANqtz-8Ska3sx56MayRMCJ5WhAg2iPGsi8JmT96xyW9vfUnr9MYwvbbZwSj4aHwcFYvOEZcsGrfhVJm9om_MBh2VjXWxhtOdpR2N-ZiR8k2H7VD_a44IvIc&amp;_hsmi=428553561&amp;utm_content=428553561&amp;utm_source=hs_email"><span data-contrast="none">a furious debate over review and licensing of AI models</span></a><span data-contrast="auto">, and AI governance more broadly. </span><span data-ccp-props="{&quot;335559685&quot;:0}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">&#8220;Voluntary&#8221; an Unstable Compromise:</span></b><span data-contrast="auto">  Critics argued that the program was voluntary in name only. As <a href="https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/">Anthropic&#8217;s experience with the Department of War showed</a>, the government could retaliate against firms that did not cooperate. None of the big 3 AI firms could afford to ignore it, and enterprise clients might refuse to procure any model that had not cleared federal review.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:180}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">Lack of Transparency and Due Process:</span></b><span data-contrast="auto"> Critics pointed out that the review mechanisms were not based on any written standards or well-defined criteria. The benchmarking process called for by the Executive Order was to be “classified,” opaque, and lacking any appeal process.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:180}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="4" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">The China Competition.</span></b><span data-contrast="auto"> While this policy turmoil was going on, China’s method of competing by promulgating open source models began to bear fruit. Zhipu AI</span><span data-contrast="auto"> launched </span><span data-contrast="auto">GLM 5.2, </span><span data-contrast="auto">a </span><span data-contrast="auto">744-billion-parameter</span><span data-contrast="auto"> m</span><span data-contrast="auto">odel briefly named the top-performing open-weight model on the independent Artificial Analysis Intelligence Index. Its inexpensive pricing led to enterprise adoption. On July 16, </span><span data-contrast="auto">China’s Moonshot AI released Kimi K3, </span><span data-contrast="auto">the world&#8217;s largest open-weight model</span><span data-contrast="auto">.  And on July 26, DeepSeek V4 </span><span data-contrast="auto">replaced older APIs, offering a massive 1-million-token context window</span><span data-contrast="auto">.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:180}"> </span></li>
</ul>
<p><span data-contrast="auto">Anthropic and OpenAI executives </span><a href="https://www.wsj.com/tech/ai/top-american-ai-execs-sound-alarm-on-chinese-models-3c74f8c1"><span data-contrast="none">raised alarms in Washington</span></a><span data-contrast="auto"> &#8211; privately. They warned that Chinese firms were closing the gap by illicitly &#8220;distilling&#8221; advanced U.S. models to train their own systems. Amidst talk of banning open source AI models, on July 24, 2026, Nvidia CEO Jensen Huang published an industry open letter titled </span><a href="https://images.nvidia.com/pdf/Open-Weights-and-American-AI-Leadership.pdf"><i><span data-contrast="none">“Open Weights and American AI Leadership”</span></i></a><span data-contrast="auto">. The letter urged Washington </span><span data-contrast="auto">not to restrict or ban open-weight models,</span><span data-contrast="auto"> arguing that an open ecosystem is vital for American tech leadership. The letter was signed by over 100 companies, including Cisco, Google, IBM, Microsoft, and Red Hat. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Anthropic was conspicuously absent from the signatories.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:180,&quot;335559740&quot;:279}"> </span></p>
<h2>Global &#8220;Pacing&#8221;?</h2>
<p><span data-contrast="auto">But Anthropic did sign another letter that came out two days later. </span><a href="https://www.pacingthefrontier.com/"><span data-contrast="none">Pacing the Frontier</span></a><span data-contrast="auto"> a letter signed by </span><span data-contrast="auto">1,324 employees of AI companies, revived 2023-vintage fears of an out-of-control AGI. It claimed that “there is a real risk that [AI] capability development rapidly accelerates beyond our ability to understand or control the resulting systems.” The letter asked policy makers worldwide to “build on work already underway to monitor frontier model releases” (i.e., Executive Order 14409), by requesting:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:279}"> </span></p>
<blockquote><p><span data-contrast="auto">&#8220;that the U.S. government support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:279}"> </span></p></blockquote>
<p><span data-contrast="auto">Note that the letter realistically recognizes that competition in the market discourages frontier firms from slowing down development, and that any attempt to control or limit model releases would require globalized collective action, not national competition. This would require cooperation with China, the same country that Anthropic believes should be denied advanced semiconductors and is stealing their “intellectual property” via distillation. An international AI governance effort that does not include China? It’s hard to imagine a more incoherent policy stance.</span><span data-ccp-props="{&quot;335559685&quot;:0}"> </span></p>
<p><span data-contrast="auto">So where does that lead us? The safety paradigm asks us to slow down and control development via globalized governance. The race narrative urges American companies to stay ahead but also fosters a connection between national security and digital technology development that encourages the government to exclude foreigners from the market and even to review and license American AI development. So which is it &#8211; review and license or let her rip? All these issues came to a head in June-July 2026, when the leading AI firms and the U.S. government tried to square a circle by taking both sides.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Narrative 3</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">There is  a less ideological narrative about AI going on. Narrative 3 might be characterized as </span><i><span data-contrast="auto">letting global digitization proceed under market constraints</span></i><span data-contrast="auto">. This third narrative sees AI not as a special, isolated capability but as one of many expressions of a global digital ecosystem. It pays attention to news reports about the real-world digitization of the economy, finding some of them successful and others not. It consists of spotty and unsystematic reports about the actual application of AI to specific parts of the economy, as well as reports about how unrealistic predictions (such as massive job losses) are being debunked. It chronicles the capital expenditures and revenue generation of American and Chinese AI firms and the growing presence of Chinese firms as a competitive factor in the development of the industry, noting how AI capabilities are subject to market constraints just like any other industry. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Narrative 3 is neither polarized nor polarizing. It focuses on real-world developments, real costs and benefits, not hopes and fears. One of its most interesting features is its recognition that, despite all the decoupling pressures, China and the US are, economically and technologically, interconnected parts of the digital economy. People who pay close attention to how AI is actually being used realize that both Chinese and American technologists and markets are driving progress in digital information systems and that users are picking and choosing from both ecosystems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Semiconductors are the third most traded item in the global economy, behind oil and autos. The supply chain is regionally centered in East Asia, and includes South Korea, Japan, Taiwan and China. Data and cloud services, too, are largely borderless. There is not really a national competition, in which the benefits and costs follow national borders, but a globalized digital information infrastructure, and a globalized market for the production and use of digital information systems. Competition, specialization and globalized market access, on net, show signs of benefiting all world societies. AI governance is, after all, just like Internet governance. And that’s because the Internet and AI are both part of the same interconnected, transborder digital information system.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p>The post <a href="https://www.internetgovernance.org/2026/08/01/colliding-ai-governance-narratives/">Colliding AI governance Narratives</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/08/01/colliding-ai-governance-narratives/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Thank the China Hawks for Higher Prices of Digital Devices</title>
		<link>https://www.internetgovernance.org/2026/07/01/thank-the-china-hawks-for-higher-prices-of-digital-devices/</link>
					<comments>https://www.internetgovernance.org/2026/07/01/thank-the-china-hawks-for-higher-prices-of-digital-devices/#respond</comments>
		
		<dc:creator><![CDATA[Milton Mueller]]></dc:creator>
		<pubDate>Wed, 01 Jul 2026 13:37:43 +0000</pubDate>
				<category><![CDATA[Digital Trade]]></category>
		<category><![CDATA[Geopolitics of IG]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10548</guid>

					<description><![CDATA[<p>For about 50 years, consumers across the world could count on digital devices getting less expensive even as they became more powerful. Those days are over. The price of memory &#8211; not the fancy, most powerful semiconductor ships but the basic ones needed for dynamic random access memory (DRAM) in ordinary digital devices, has climbed [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/07/01/thank-the-china-hawks-for-higher-prices-of-digital-devices/">Thank the China Hawks for Higher Prices of Digital Devices</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>For about 50 years, consumers across the world could count on digital devices getting less expensive even as they became more powerful. Those days are over. The price of memory &#8211; not the fancy, most powerful semiconductor ships but the basic ones needed for dynamic random access memory (DRAM) in ordinary digital devices, has climbed roughly 700% since 2022.</p>
<p>Apple announced major price increases for its consumer products last week, but the same story affects Android phones, gaming devices, laptops, and a host of other consumer digital products. A story by <a href="https://thenextweb.com/news/ai-killing-cheap-smartphone-dram-memory-crisis">Alina Maria Stan in The Next Web</a> shows how the rising price of memory is stifling the global growth of the digital economy; it is “killing the cheap smartphone,” forcing budget smartphone makers like Transsion, Oppo, Vivo, and Lava to reduce their profits by 50% and reduce their shipments by 15% &#8211; 40%.</p>
<p>According to Stan,</p>
<blockquote><p>In India, the sub-$100 smartphone market collapsed 59% year on year in Q1 2026. In Africa, where 81% of smartphone shipments were in the sub-$200 category in 2025, many consumers will simply be priced out of phone ownership entirely. The technology that connected hundreds of millions of the world’s poorest people to the internet is becoming unaffordable.</p></blockquote>
<p>The standard story is that AI is responsible for this change. That’s partly true, but it is only half of the story. The real culprit is the United States’ attempt to securitize and de-globalize chip production by imposing export controls and import controls on China. This has eliminated a key source of additional capacity that could have ameliorated the sudden shortage of DRAM.</p>
<h2>The Big Shift</h2>
<p>Training and running AI models requires high-bandwidth memory (HBM). HBM profit margins are 70% or higher, whereas commodity DRAM margins are around 20% &#8211; 30%. In 2023, HBM accounted for 2% of memory makers’ wafers. By the end of 2026, it is expected to reach 20%. Instead of expanding their production capacity to meet the AI-driven demand for HBM, chip producers reallocated existing capacity. Every wafer pushed into HBM production removes capacity from the memory that goes into phones and laptops.</p>
<p>The DRAM market is highly concentrated. The &#8220;Big Three&#8221; suppliers, Samsung Electronics, SK Hynix, and Micron Technology, control roughly 90% of global DRAM revenue.</p>
<p>In this massive reallocation of DRAM production away from consumer electronics and toward AI data centres, <a href="https://investors.micron.com/news-releases/news-release-details/micron-announces-exit-crucial-consumer-business">Micron went the furthest</a>. Late last year (December 2025), it completely discontinued its consumer-oriented Crucial brand, redirecting all its capacity to HBM and enterprise. One of three global DRAM producers simply left the consumer market.</p>
<h2>The Antitrust Lawsuit</h2>
<p>An oligopolistic market structure makes collusion easier. This helps to explain why a group of seventeen small electronics repair shops and consumer plaintiffs have filed <a href="https://dockets.justia.com/docket/california/candce/5:2026cv06345/472931?__cf_chl_f_tk=LBso6KGcrCLI7IrREZ40UreOgnw6rkcaPq.uBjMAZiQ-1782911050-1.0.1.1-ArtZBp729IGmOGKuvux5_Agx0icmXk.UQ7AgjhG7j8s">a class action antitrust lawsuit</a> against the big three. The plaintiffs allege that the defendants conspired to artificially restrict the global supply of conventional DRAM memory.</p>
<p>In a frictionless, globalized economy, however, a supply shortage in one region is naturally corrected by excess capacity in another. Right now, ChangXin Memory Technologies (CXMT) is aggressively churning out commodity DDR4 and DDR5 memory. In fact, reports from the broader market show CXMT components entering certain channels at prices drastically lower than the $300 to $400 global average in the Western market.</p>
<p>The point about CXMT is that the Big Three didn’t need cartel collusion to bring about this situation. The reason cheaper supply isn&#8217;t driving down costs for companies like Apple or Microsoft isn&#8217;t a lack of chips—it is because U.S. policy effectively bans the supply adjustment. By preventing Western buyers from accessing the world&#8217;s fastest-growing commodity memory producer, U.S. national security policies are directly protecting the pricing power of the established oligopoly, leaving Western consumers to foot the bill.</p>
<h2>How US Policy Reinforces Supply Shortages</h2>
<p>In January 2025, the U.S. Department of Defense designated CXMT as a &#8220;Chinese Military Company&#8221; under <a href="https://www.wilmerhale.com/en/insights/client-alerts/20260611-pentagon-adds-65-new-entities-to-the-1260h-list-of-chinese-military-companies">Section 1260H of the National Defense Authorization Act</a>. This designation legally bars the U.S. military and federal agencies from purchasing any systems or hardware containing CXMT chips. While it does not criminalize private U.S. companies from buying them, it carries immense reputational risk. Major U.S. computer and device manufacturers (OEMs) generally avoid sourcing 1260H-listed components to protect their eligibility for federal contracts.</p>
<p>Even though buying CXMT chips is not illegal, major U.S. corporations are effectively blocked from this supplier by the threat of retroactive <a href="https://www.ft.com/content/d72a25e2-7bde-4aa9-bd8d-0c4f3d6cb2cb?syn-25a6b1a6=1">blacklisting through the more restrictive Entity List</a>. If U.S. firms like Apple design their products around CXMT memory, a sudden shift in U.S. policy could move CXMT to the Entity List overnight. This would instantly freeze the supply chain and leave the U.S. buyer without components. There is also reputational and political risk of being publicly linked to a supplier labeled a &#8220;Chinese military company&#8221; by the Pentagon.</p>
<p>By keeping CXMT on the 1260H military blacklist and keeping the threat of the Commerce Department’s restrictive Entity List hanging over them, Washington has turned Western hardware manufacturers into a captive audience for Samsung, SK Hynix, and Micron. If Apple were free to sign a massive, multi-billion-dollar supply agreement with CXMT without facing catastrophic regulatory or reputational risk, the Western commodity DRAM shortage would collapse almost overnight.</p>
<h2>The Price of Securitization</h2>
<p>To see only collusion among the Big Three suppliers is to miss the real story. The operation of Moore&#8217;s law always relied on market competition. Moore&#8217;s law is being repealed by the China hawks. The underlying problem here is the attempt by the U.S. government to de-globalize the semiconductor supply chain, as part of its deeply confused mix of national security policy, trade policy and industrial policy. Add to this the exploitation of national security fears by domestic firms seeking protection from competition, and you are bound to get higher prices and shortages. Micron spent years lobbying Washington to blacklist earlier Chinese memory startups, such as Fujian Jinhua and YMTC. Now it is actively and aggressively lobbying the U.S. government to maintain and tighten barriers against CXMT and other emerging Chinese memory competitors, even as it shuts down its own DRAM capacity. Micron has also been identified as a key proponent and driving force behind the MATCH Act, legislation that significantly tightens U.S. export controls on the manufacturing tools made by American firms that will be purchased by Chinese memory manufacturers like CXMT and YMTC. By lobbying for this bill, Micron seeks to legally restrict CXMT&#8217;s ability to acquire the equipment necessary to scale up its capacity or advance to more sophisticated manufacturing nodes.</p>
<p>Semiconductors are indeed the key to the digital economy, but subordinating complex, globalized supply chain markets to geopolitical power games is a major disruption. The unintended consequences are just starting to play out.</p>
<p>The post <a href="https://www.internetgovernance.org/2026/07/01/thank-the-china-hawks-for-higher-prices-of-digital-devices/">Thank the China Hawks for Higher Prices of Digital Devices</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/07/01/thank-the-china-hawks-for-higher-prices-of-digital-devices/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Defending Cyberspace: Cybersecurity and Frontier AI</title>
		<link>https://www.internetgovernance.org/2026/06/18/defending-cyberspace-rethinking-cybersecurity-production-in-the-frontier-era/</link>
					<comments>https://www.internetgovernance.org/2026/06/18/defending-cyberspace-rethinking-cybersecurity-production-in-the-frontier-era/#respond</comments>
		
		<dc:creator><![CDATA[Brenden Kuerbis]]></dc:creator>
		<pubDate>Thu, 18 Jun 2026 13:00:33 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Generative AI]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10530</guid>

					<description><![CDATA[<p>The intersection of artificial intelligence and cybersecurity has rapidly ascended to the top of the Washington policy agenda. Following the administration’s June 2, 2026, Executive Order on AI cybersecurity, the Congressional Internet Caucus recently convened a panel of industry experts, policy analysts, and former officials to discuss the shifting threat landscape. Advanced &#8220;frontier&#8221; AI models [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/18/defending-cyberspace-rethinking-cybersecurity-production-in-the-frontier-era/">Defending Cyberspace: Cybersecurity and Frontier AI</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;">The intersection of artificial intelligence and cybersecurity has rapidly ascended to the top of the Washington policy agenda. Following the administration’s June 2, 2026, </span><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"><span style="font-weight: 400;">Executive Order on AI cybersecurity</span></a><span style="font-weight: 400;">, the Congressional Internet Caucus </span><a href="https://ia902808.us.archive.org/23/items/netcaucus-ai-cyber/netcaucus-ai-cyber.EN.pdf"><span style="font-weight: 400;">recently convened a panel</span></a><span style="font-weight: 400;"> of industry experts, policy analysts, and former officials to discuss the shifting threat landscape. Advanced &#8220;frontier&#8221; AI models like Anthropic&#8217;s </span><i><span style="font-weight: 400;">Mythos</span></i><span style="font-weight: 400;"> have completely transformed the timeline of vulnerability discovery, shortening the window between flaw identification and weaponization to mere seconds by generating actionable exploit code simultaneously with discovery.</span></p>
<p><span style="font-weight: 400;">To manage the volume of AI-generated threats, panelists focused heavily on the new executive order&#8217;s proposal to </span><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/#:~:text=and%20local%20utilities.-,(d),-Within%2030%20days"><span style="font-weight: 400;">establish a centralized federal AI cybersecurity clearinghouse</span></a><span style="font-weight: 400;">. This body is intended to deconflict and coordinate software vulnerability scanning, validation, and patch distribution across government and critical infrastructure sectors. Panelists widely agreed that some form of institutional mechanism is necessary to assist organizations currently overwhelmed by processing dozens of daily vulnerabilities across their software dependencies.</span></p>
<p><span style="font-weight: 400;">In what was an otherwise productive discussion, Ari Schwartz of Venable LLP urged Congress to reauthorize the sunsetting Cybersecurity Information Sharing Act of 2015 (CISA 2015), framing it as an essential legislative baseline for effective public-private response to the AI-cybersecurity nexus. </span></p>
<p><span style="font-weight: 400;">A closer look at the empirical record, however, reveals a stark mismatch between Washington&#8217;s enthusiasm for CISA and the operational reality of these frameworks.</span></p>
<h3><b>The Failed Promises of Centralized Information Sharing</b></h3>
<p><span style="font-weight: 400;">CISA was passed in 2015 and expired in 2025. For over a decade, federal agencies and legacy legislation have operated under the assumption that CISA&#8217;s liability protections and flagship implementation of an “Automated Indicator Sharing (AIS)” capability was an essential element in national cyber defense. Since 2022, however, the failure of the program has been evident. It did not catalyze higher levels of threat information sharing. It was evaluated in recent Department of Homeland Security Office of Inspector General (OIG) and Interagency joint compliance reports. [</span><a href="https://www.oig.dhs.gov/sites/default/files/assets/2024-09/OIG-24-60-Sep24.pdf"><span style="font-weight: 400;">1</span></a><span style="font-weight: 400;">, </span><a href="https://www.oig.dhs.gov/sites/default/files/assets/2025-09/OIG-25-46-Sep25.pdf"><span style="font-weight: 400;">2</span></a><span style="font-weight: 400;">, </span><a href="https://www.oig.doc.gov/wp-content/OIGPublications/U-FINAL_Interagency_Joint_CISA_Report_for-public-release.pdf"><span style="font-weight: 400;">3</span></a><span style="font-weight: 400;">] As we </span><a href="https://www.internetgovernance.org/2026/01/03/dont-renew-the-cybersecurity-information-sharing-act/"><span style="font-weight: 400;">wrote in January</span></a><span style="font-weight: 400;">, the automated sharing ecosystem is plagued by severe decay and structural failure:</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><b>Collapsing Participation:</b><span style="font-weight: 400;"> The overall number of federal and non-federal participants actively utilizing AIS has plummeted by a staggering 65 percent since its peak in 2020. By 2024, AIS was left with a mere 18 federal participants and 87 non-federal participants.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Systemic Overreliance:</b><span style="font-weight: 400;"> While the total volume of shared cyber threat indicators (CTIs) superficially increased in 2024, a single private-sector platform&#8217;s contributions accounted for 89 percent of the public collection and 83 percent of the entire federal collection. This shows that the laws intent &#8211; to encourage and expand threat sharing &#8211; isn’t working.</span></li>
<li style="font-weight: 400;" aria-level="1"><b>Technical and Structural Inertia:</b><span style="font-weight: 400;"> Federal entities remain notoriously reluctant to share operational incident data via machine-to-machine connections due to institutional bottlenecks, a lack of organizational resources, and policy constraints. Furthermore, downstream operators frequently choose to ignore or avoid uncategorized federal threat feeds because the shared indicators lack the specific operational context required to deploy fixes safely.</span></li>
</ul>
<p><span style="font-weight: 400;">Furthermore, arguments that private firms need state-sanctioned safe harbors to circumvent antitrust liabilities when sharing technical data are largely hollow. As detailed by the Department of Justice (DOJ) and the Federal Trade Commission (FTC) in </span><a href="https://www.ftc.gov/system/files/documents/public_statements/297681/140410ftcdojcyberthreatstmt.pdf"><span style="font-weight: 400;">their joint antitrust policy statement</span></a><span style="font-weight: 400;">, properly designed cyber threat exchanges are highly technical and distinct from competitively sensitive business data like pricing or output. The agencies have explicitly maintained for over two decades that legitimate cybersecurity information sharing does not violate antitrust laws. The legal roadblocks are a myth; the actual barrier is that government-managed clearinghouses simply fail to deliver timely, actionable value.</span></p>
<h3><b>The Clearinghouse Trap: Centralizing Power, Stifling Innovation</b></h3>
<p><span style="font-weight: 400;">In light of the chronic underperformance of existing automated frameworks like AIS, the 2026 Executive Order&#8217;s proposed AI cybersecurity clearinghouse is distinctly misplaced. Rather than modernizing defense, the mandate serves as a vehicle to expand state control over cutting-edge artificial intelligence.</span></p>
<p><span style="font-weight: 400;">The Executive Order additionally outlines a &#8220;Secure Frontier Model Deployment&#8221; framework that establishes a classified benchmarking process to designate advanced models as &#8220;covered frontier models&#8221;. Under the guise of being voluntary, firms are strongly incentivized to turn over their models to the federal government for up to 30 days </span><i><span style="font-weight: 400;">before</span></i><span style="font-weight: 400;"> public release. The government then assumes the role of an arbiter, collaborating with firms to selectively hand-pick which &#8220;trusted partners&#8221; are granted early access to promote critical infrastructure security.</span></p>
<p><span style="font-weight: 400;">Taken together, this represents an unnecessary, centralized gatekeeping regime. Inserting a federal clearance step into the software pipeline slows down the deployment of capability equally valuable to defenders, introduces immense political and national security groupthink and opportunity for regulatory capture, and expands state visibility into proprietary algorithms and weights under the banner of deconflicting code scanning.</span></p>
<h3><b>A Better Path: Decentralized Disclosure, Market Incentives, Transparent Process</b></h3>
<p><span style="font-weight: 400;">The policy fixation on state-managed clearinghouses and review overlooks a far more robust, agile, and proven alternative to producing cybersecurity: the decentralized model of responsible disclosure governed by widely accepted norms, <a href="https://csrc.nist.gov/pubs/sp/800/216/final">recommendations</a>, <a href="https://www.iso.org/standard/72311.html">standards</a>, and <a href="https://www.first.org/global/sigs/vulnerability-coordination/multiparty/guidelines-v1.1">guidance,</a> which lowers coordination costs and is led by the AI ecosystem itself. </span></p>
<p><span style="font-weight: 400;">The success of Anthropic’s &#8220;Project Glasswing&#8221; initiative offers an illustrative roadmap. Under Project Glasswing, advanced frontier models like </span><i><span style="font-weight: 400;">Mythos</span></i><span style="font-weight: 400;"> were provided directly to diverse, private-sector security partners and system defenders. Rather than routing vulnerability details through a slow-moving government clearinghouse, this advanced access allowed operators to rapidly stress-test their own code, identify thousands of live flaws across complex dependencies, and patch systems in real-time before adversaries could weaponize them. While the Glasswing initiative shows it can be done, we’ve noted its club governance structure <a href="https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/#:~:text=within%20Glasswing%E2%80%99s%20coordination.-,What%20Comes%20Next,-Prompt%3A%20Project%20Glasswing">needs to evolve</a>. Comcast’s Elizabeth Chernow similarly pointed this out in the panel, noting a recent paper promoting criteria for <a href="https://www.aspendigital.org/blog/responsible-advanced-access/">Responsible Advanced Access</a>.</span></p>
<p><span style="font-weight: 400;">Decentralized, voluntary defense continues to succeed because it leverages the natural economic incentives of network operators. Critical infrastructure operators, enterprise businesses, and software maintainers possess an existential, bottom-line interest in protecting their own networks and customer data. When AI providers distribute advanced testing models that fundamentally reduce vulnerability identification costs directly to these stakeholders, they help unlock a </span><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/beyond-the-benchmark-advancing-security-at-ai-speed/"><span style="font-weight: 400;">massive, parallelized army of defenders using multiple models</span></a><span style="font-weight: 400;"> who are contextually aware and uniquely equipped to find flaws and develop and validate patches without breaking downstream dependencies.</span></p>
<p><span style="font-weight: 400;">As Google’s Kate Charlet observed during the panel, true long-term security will be achieved by embedding AI capabilities directly into standard software development workflows and cloud architectures, ensuring that insecure code is caught before it is ever compiled. This structural shift requires broad, open access to advanced tooling—not a restricted government gatekeeping system that funnels code to a federal clearinghouse and approval. </span></p>
<p><span style="font-weight: 400;">Unfortunately, the administration doubled down last week, </span><a href="https://www.techpolicy.press/did-the-us-government-just-set-an-ai-export-precedent-by-blocking-mythos/"><span style="font-weight: 400;">leveling export controls</span></a><span style="font-weight: 400;"> on Anthropic’s Mythos and Fable (Mythos with guard rails) large language models. Anthropic complied and </span><a href="https://www.anthropic.com/news/fable-mythos-access"><span style="font-weight: 400;">stated</span></a><span style="font-weight: 400;"> they “believe the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts.” Multiple cybersecurity experts </span><a href="https://freefable.org/#:~:text=It%20is%20our%20understanding%20that%20underlying%20model%20capabilities%20in%20the%20original%20research%20that%20triggered%20this%20action%3A"><span style="font-weight: 400;">questioned the rationale</span></a><span style="font-weight: 400;"> for the ban, argued “pulling the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous”, and </span><a href="https://freefable.org/"><span style="font-weight: 400;">called</span></a><span style="font-weight: 400;"> for an “open, scientific and transparent process of handling AI risk assessments in the future.” </span></p>
<p><span style="font-weight: 400;">We agree. Rather than reviving failed information-sharing approaches via CISA reauthorization, bottlenecking frontier model access through federal directives, and hobbling the fast evolving production of cybersecurity, Washington should support defenders and innovation. </span></p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/18/defending-cyberspace-rethinking-cybersecurity-production-in-the-frontier-era/">Defending Cyberspace: Cybersecurity and Frontier AI</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/06/18/defending-cyberspace-rethinking-cybersecurity-production-in-the-frontier-era/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Tanzania Is Getting Online. Its Digital Economy Isn&#8217;t Following.</title>
		<link>https://www.internetgovernance.org/2026/06/09/tanzania-is-getting-online-its-digital-economy-isnt-following/</link>
					<comments>https://www.internetgovernance.org/2026/06/09/tanzania-is-getting-online-its-digital-economy-isnt-following/#respond</comments>
		
		<dc:creator><![CDATA[Karim Farhat]]></dc:creator>
		<pubDate>Tue, 09 Jun 2026 15:45:41 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10521</guid>

					<description><![CDATA[<p>Across most of the developing world, the story of the last two decades has been a hopeful one: as people come online, the digital economy grows, services expand, new businesses take root, people make more money and lift themselves by their bootstraps. Tanzania was supposed to follow that script, but it hasn&#8217;t. A new report [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/09/tanzania-is-getting-online-its-digital-economy-isnt-following/">Tanzania Is Getting Online. Its Digital Economy Isn&#8217;t Following.</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Across most of the developing world, the story of the last two decades has been a hopeful one: as people come online, the digital economy grows, services expand, new businesses take root, people make more money and lift themselves by their bootstraps. Tanzania was supposed to follow that script, but it hasn&#8217;t.</p>
<p><a href="https://www.internetgovernance.org/wp-content/uploads/DPE_of_digital_governance_in_Tz.pdf">A new report from IGP</a>, sponsored by the <a href="https://tmc.co.tz/">Tech and Media Convergency</a> (TMC), investigates an unfortunate divergence in Tanzania’s development. While internet adoption has climbed to roughly one-third of the population, the expected digital economic growth has failed to materialize. The research argues that the bottleneck is not a lack of infrastructure, but a self-reinforcing system of restrictive governance<em>.</em></p>
<h2><strong>The Tanzanian Anomaly</strong></h2>
<p>As internet use rose from negligible levels in the early 2000s to approximately 31% today, Tanzania’s services sector contribution to GDP has actually contracted, falling from a 2001 peak of 49% to 29% in 2024 (black-dotted and red lines below).</p>
<p><img fetchpriority="high" decoding="async" class="alignnone wp-image-10523" src="https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.08-AM-800x470.png" alt="" width="655" height="385" srcset="https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.08-AM-800x470.png 800w, https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.08-AM-768x451.png 768w, https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.08-AM.png 1013w" sizes="(max-width: 655px) 100vw, 655px" /></p>
<p>The ICT sector itself has stagnated at 1.5% to 1.6% of GDP. Comparing Tanzania to Kenya, a neighbor with similar demographics and nearly identical internet penetration (~35%), reveals the scale of the under performance. Kenya’s services sector accounts for roughly 55% of its economy, nearly double Tanzania’s. In the broader digital economy, including fintech and platform commerce, Tanzania’s contribution is less than one-fifth that of Kenya’s.</p>
<p>In fact, the pattern runs similar for every one of Tanzania&#8217;s neighbors (figure below) where rising connectivity tracks with a growing or stable services sector. A positive relationship between internet adoption and services value-added appears everywhere except Tanzania, which moves in the opposite direction.</p>
<p><img decoding="async" class="alignnone wp-image-10524" src="https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.30-AM-800x558.png" alt="" width="723" height="504" srcset="https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.30-AM-800x558.png 800w, https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.30-AM-768x536.png 768w, https://www.internetgovernance.org/wp-content/uploads/Screenshot-2026-06-09-at-11.32.30-AM.png 1036w" sizes="(max-width: 723px) 100vw, 723px" /></p>
<h2><strong>Wrong turns in digital governance</strong></h2>
<p>The study identifies three interlocking policy failures that, together, suppress the productive use of Tanzania&#8217;s growing connectivity.</p>
<p><strong>Digital sovereignty</strong>: Mandates for data localization and local ownership force costly, redundant infrastructure and deter foreign investment without delivering any of the privacy or security benefits used to justify them.</p>
<p><strong>Censorship, Surveillance, and Restrictions:</strong> A restrictive framework of content licensing, VPN registration, and internet shutdowns creates direct economic damage, including an estimated US$250 million in losses during the 2025 election period alone.</p>
<p><strong>Cronyism</strong>: the most insidious factor aligning regulatory authority with private commercial interest. Here we find that sovereignty and censorship mandates are not independent policy choices but downstream instruments of a patronage system in which the ruling party, telecom operators, and regulators are bound together by shared interest using regulatory power to protect insiders from competition.</p>
<h2><strong>A maladaptive system</strong></h2>
<p>What makes the report distinctive is its insistence that these are not errors to be corrected with better technical advice. They form a self-reinforcing equilibrium that restricts growth. Restrictive policies create discretionary regulatory power; that power creates opportunities for extraction; and extraction creates vested interests in keeping the restrictions in place. Drawing on the political-economy framework of North, Wallis, and Weingast, we describe a &#8220;limited access order” a system in which a ruling coalition distributes economic privileges to insiders precisely to prevent outsiders from competing while using ICTs to stifle elections and free expression.</p>
<p>This is why we argue that incremental reforms under President Samia Suluhu Hassan have not changed the sector&#8217;s trajectory. The underlying incentive structure between regulator and regulated remains intact. The report also explains the widening gap between Tanzania&#8217;s ambitious strategic documents like its Vision 2050, the Digital Economy Strategic Framework 2024–2034, and the regulatory machinery that quietly continues to operate against them. The aspirational language of digital transformation has not replaced the architecture that suppresses it. The two simply coexist in a performative theater of legitimacy.</p>
<h2><strong>A way out that the state can live with</strong></h2>
<p>The report closes with ten concrete policy recommendations, but its framing is unusual for work in this space. Rather than calling for the ruling party to abandon the governance logic that sustains its dominance, (a clear political non-starter) we propose reforms calibrated to be <em>politically survivable</em>: revoking data localization mandates, introducing risk-based cross-border data rules, establishing judicial oversight for data access, liberalizing content licensing, opening up wholesale infrastructure, and replacing ownership caps with competition-based assessments.</p>
<p>Each recommendation can be justified on fiscal grounds alone. A larger, more dynamic ICT sector would broaden the tax base, attract foreign investment, and create jobs thereby offsetting the perceived loss of control with gains that accrue to all stakeholders, including the state. A more abundant and independent digital economy would even lower the stakes of political competition, making any future transfer of power less destabilizing.</p>
<p>Whether any of it happens depends on a race we can identify but not resolve, that is, whether the mounting economic costs of the current system will force change before an expanding surveillance apparatus from mandatory SIM registration and the forthcoming Jamii Namba digital ID, locks in a more durable architecture of control. For now, Tanzanians keep coming online. The question is whether being online will ever be allowed to pay off.</p>
<p><em>&#8220;The Political Economy of Digital Governance in Tanzania: Pathways to ICT Sector Growth&#8221; is an Internet Governance Project report sponsored by the Tech &amp; Media Convergency. <a href="https://www.internetgovernance.org/wp-content/uploads/DPE_of_digital_governance_in_Tz.pdf">Read the full report here</a>.</em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/09/tanzania-is-getting-online-its-digital-economy-isnt-following/">Tanzania Is Getting Online. Its Digital Economy Isn&#8217;t Following.</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/06/09/tanzania-is-getting-online-its-digital-economy-isnt-following/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Anthropic Tries to Revive the “AI Pause”</title>
		<link>https://www.internetgovernance.org/2026/06/07/anthropic-tries-to-revive-the-ai-pause/</link>
					<comments>https://www.internetgovernance.org/2026/06/07/anthropic-tries-to-revive-the-ai-pause/#respond</comments>
		
		<dc:creator><![CDATA[Milton Mueller]]></dc:creator>
		<pubDate>Sun, 07 Jun 2026 14:12:28 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Geopolitics of IG]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10512</guid>

					<description><![CDATA[<p>Back in 2023, the Future of Life Institute issued a open letter calling to “pause giant AI experiments” before runaway AI destroyed humanity.   Three years later, machine learning applications have expanded in use and capability, yet humans are still around. Most AI doomers have retreated from saying that AI will wipe us out, reverting [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/07/anthropic-tries-to-revive-the-ai-pause/">Anthropic Tries to Revive the “AI Pause”</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Back in 2023, the Future of Life Institute issued a </span><a href="https://futureoflife.org/open-letter/pause-giant-ai-experiments/"><span data-contrast="none">open letter</span></a><span data-contrast="auto"> calling to “pause giant AI experiments” before runaway AI destroyed humanity. </span><span data-ccp-props="{&quot;335551550&quot;:0,&quot;335551620&quot;:0}"> </span></p>
<p><span data-contrast="auto">Three years later, machine learning applications have expanded in use and capability, yet humans are still around. Most AI doomers have retreated from saying that AI will wipe us out, reverting to the less apocalyptic but equally extreme claim that it will </span><a href="https://pauseai.info/"><span data-contrast="none">eliminate all human jobs</span></a><span data-contrast="auto">, and yet unemployment remains low at 4.3% and the l</span><a href="https://www.wsj.com/economy/consumers/may-jobs-report-unemployment-fde062e1?mod=Searchresults&amp;pos=5&amp;page=1"><span data-contrast="none">ast three job reports</span></a><span data-contrast="auto"> showed significant growth.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Nevertheless, Anthropic on June 4 </span><a href="https://www.anthropic.com/institute/recursive-self-improvement"><span data-contrast="none">resurfaced the call for a pause</span></a><span data-contrast="auto">, this time with an apparently more rational set of arguments. The underlying concern is the same, however: “recursive self-improvement&#8221; in frontier models might increase the “</span><a href="https://www.darioamodei.com/essay/the-adolescence-of-technology"><span data-contrast="none">risks</span></a><span data-contrast="auto"> of humans losing control over AI systems.” So:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<blockquote><p><span data-contrast="auto">“If it were possible to effectively slow the development of this technology to give ourselves more time to deal with its immense implications, we think that would likely be a good thing. &#8230; Without a global coordination mechanism, companies and governments will have to make difficult decisions about safety while under competitive and geopolitical pressures. We believe it would be good for the world to have the </span><i><span data-contrast="auto">option</span></i><span data-contrast="auto"> to slow or temporarily pause frontier AI development to enable societal structures and alignment research to keep up with the advance of the technology.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p></blockquote>
<p><span data-contrast="auto">IGP has <a href="https://www.tandfonline.com/doi/full/10.1080/23738871.2025.2597194">published research</a> challenging the claim that recursive self-improvement in AI software will lead to an autonomous, all-powerful AI system. Anthropic CEO Dario Amodei explicitly rejects doomerism, and the blog post admits that “recursive self-improvement is not inevitable,” but they still believe &#8220;it could come sooner than most institutions are prepared for.” </span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">We have also </span><a href="https://www.sciencedirect.com/science/article/pii/S030859612500014X"><span data-contrast="none">published research</span></a><span data-contrast="auto"> explaining why a global “pause” in AI development is not a viable governance solution. This passage was published in </span><i><span data-contrast="auto">Telecommunications Policy </span></i><span data-contrast="auto">nearly a year and a half ago:</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<blockquote><p><span data-contrast="auto">“&#8230;an effective moratorium would require </span><i><span data-contrast="auto">every</span></i><span data-contrast="auto"> government and </span><i><span data-contrast="auto">every</span></i><span data-contrast="auto"> firm in the computer industry to abide by it. And not all businesses or governments really want to pause. It is unlikely that the U.S., Israel, China, the European Union, Russia and India would trust each other enough to stop unilaterally. Nor would they be eager to expose their advanced software and hardware capabilities to inspection by other states or foreign businesses. Given the (alleged) military and business advantages of being the leader in AI technology, each state and business would have a strong incentive to defect from a moratorium. Even if noncompliance could be detected reliably, there would be no way for complying governments to enforce the pause agreement upon recalcitrant governments of sufficient size and power. “Pause AI” just does not work. But if it did, it would involve systematic surveillance and control of ICT capabilities worldwide.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p></blockquote>
<p><span data-contrast="auto">While Anthropic’s pause revival recognizes these collective action problems. their only response is that: </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<blockquote><p><span data-contrast="auto">“The Anthropic Institute will conduct </span><a href="https://www.anthropic.com/research/anthropic-institute-agenda"><span data-contrast="none">research</span></a><span data-contrast="auto">—in collaboration with many others—and take actions to help build the systems that a credible slowdown or pause would require.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p></blockquote>
<p><span data-contrast="auto">Exploring verification methods might be helpful, but as we learned from our </span><a href="https://www.internetgovernance.org/2020/07/13/building-transnational-attribution-sharing-data-and-determining-state-sponsorship-igp-workshop-synopsis-day-2/"><span data-contrast="none">efforts to promote the creation of a neutral international cyber attribution organization,</span></a><span data-contrast="auto"> knowing what needs to be done is not the obstacle; it’s getting the actors, especially rivalrous nation-states, to commit to such an institution that is the hard part. If the new institution requires sharing data and possibly losing competitive advantages, it is unlikely to happen. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">The National Security Nexus</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">What makes this quasi-doomer revival more interesting and potentially troublesome, however, is the growing nexus between geopolitical competition, the frontier AI model developers, and U.S. national security agencies. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">A Trump administration </span><a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"><span data-contrast="none">Executive Order</span></a><span data-contrast="auto"> that was issued only two days before the Anthropic blog post required relevant federal agencies to develop &#8220;a classified benchmarking process” to &#8220;determine the threshold at which an AI model should be designated a ‘covered frontier model.’” If a model meets or exceeds this threshold, then the AI developers would be able to provide the Federal Government with confidential access to the frontier models, to allow the Feds to review it “for a period of up to 30 days before they plan to release such models to other trusted partners.”</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Advocates of market-led AI development were happy with the voluntary nature of the program, and the reduction of the review period from 90 days to 30 days. </span><a href="https://www.wsj.com/tech/ai/trump-executive-order-ai-advanced-models-57bcc955?mod=Searchresults&amp;pos=3&amp;page=1"><span data-contrast="none">An earlier proposal</span></a><span data-contrast="auto"> was considering potential AI rules comparable to the system used by the Food and Drug Administration to approve medicines. Still, the idea of prior review of communication and information technologies by a national government’s national security apparatus is not something to be taken lightly. Claude’s ability to find vulnerabilities in software does pose real cybersecurity risks – but those risks occur to any software user, not just the government. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">The real risk here is the militarization of AI. Anthropic’s own assessment of AI risks actually reinforces US tendencies to see AI as a weapon in its competition with China. We have seen time and again how national security claims privilege the power of the state over the rights and freedoms of the individual and the economic opportunities of innovators. A good example was the government’s decision to classify encryption technology as a weapon in the 1970s and its decades-long attempt to keep strong encryption capabilities out of the hands of civilians, to preserve its own ability to engage in surveillance.  </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Is Anthropic sincere about gaining input?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">In its June 4 blog post, Anthropic’s policy staff expresses an intention to consult with a broader community to develop policy proposals: </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p>
<blockquote><p><span data-contrast="auto">&#8220;In the coming months, [the Anthropic Institute] will organize conversations where policymakers, researchers, civil society, and other AI companies can help answer some of the questions this piece raises, especially around full recursive self-improvement and how to create better options for coordination and deliberation. We’ll publish what comes out of it.&#8221;</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:720,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:160,&quot;335559740&quot;:279}"> </span></p></blockquote>
<p><span data-contrast="auto">IGP has been deeply involved in global digital governance discussions for two decades. If Anthropic is sincere about gaining all relevant perspectives, we look forward to being invited to these conversations. </span></p>
<p>The post <a href="https://www.internetgovernance.org/2026/06/07/anthropic-tries-to-revive-the-ai-pause/">Anthropic Tries to Revive the “AI Pause”</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/06/07/anthropic-tries-to-revive-the-ai-pause/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Running a Race Looking Backwards:  US Digital Export Controls</title>
		<link>https://www.internetgovernance.org/2026/05/04/running-a-race-looking-backwards-us-digital-export-controls/</link>
					<comments>https://www.internetgovernance.org/2026/05/04/running-a-race-looking-backwards-us-digital-export-controls/#respond</comments>
		
		<dc:creator><![CDATA[Letian Cheng]]></dc:creator>
		<pubDate>Mon, 04 May 2026 14:41:49 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10496</guid>

					<description><![CDATA[<p>Congress has introduced another law tightening export controls on additional segments of the semiconductor industry (the MATCH Act). Like all the others, it is based on the premise that US technological leadership and national security is advanced by looking backwards and throwing obstacles at trailing China rather than running faster and breaking new ground. Like [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/05/04/running-a-race-looking-backwards-us-digital-export-controls/">Running a Race Looking Backwards:  US Digital Export Controls</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Congress has introduced another law tightening export controls on additional segments of the semiconductor industry (<a href="https://www.foreign.senate.gov/press/rep/release/risch-ricketts-kim-introduce-match-act-level-the-global-playing-field-for-us-tech">the MATCH Act</a>). Like all the others, it is based on the premise that US technological leadership and national security is advanced by looking backwards and throwing obstacles at trailing China rather than running faster and breaking new ground. Like the other laws, it reinforces China&#8217;s own commitment to indigenize its semiconductor industry, and so works against its stated goal of not allowing China to catch up. American policy makers and politicians are so fixated on retarding China’s digital development that they have forgotten about what created American leadership in the first place.</p>
<p>Jensen Huang, CEO of Nvidia, <a href="https://www.youtube.com/watch?v=Hrbq66XqtCo&amp;list=PLd7-bHaQwnthaNDpZ32TtYONGVk95-fhF&amp;index=1&amp;t=5712s">debunked</a> the argument that the US can contain Chinese AI development through export controls on computing power. He believes that chip control is futile because China can utilize its other advantages to aggregate and scale up its computing power, and the US will ultimately lose its global dominance on the global market by depriving its own leading companies of markets and profits. Huang’s rare, emotional expression struck at the core question: what <i>is</i> American technological leadership? Different answers to this question lead to divergence on chip export control policies.</p>
<h2>The Biden policy of containment</h2>
<p>In the Biden Presidency, the US government adopted a “<a href="https://www.federalregister.gov/documents/2025/01/15/2025-00636/framework-for-artificial-intelligence-diffusion">Framework for AI Diffusion</a>”, seeking to contain Chinese development of AI by controlling advanced computing power. This framework was based on an assumption that <a href="https://www.brookings.edu/articles/if-superintelligence-isnt-imminent-the-trump-administration-may-be-right-to-loosen-advanced-chip-export-controls/">superintelligence is “imminent”</a>, and computing power is the most important resource enabling it. At that time, the underlying premise of the “AI race” equated it with the race to build the atomic bomb: whoever gets it first would hold supreme power over the world. Hence, the U.S. must use its leading position in semiconductor production to carefully ration access to computing power or it will lose the race. Under this assumption, the Biden administration mandated BIS to develop targeted <a href="https://www.bis.gov/press-release/commerce-implements-new-export-controls-advanced-computing-semiconductor-manufacturing-items-peoples">regulations</a> restricting the export of chips to China, and Floating Point Operations Per Second (FLOPS), a measure of computer performance, became the critical metric for determining restrictions.</p>
<p>Yet <a href="https://www.tandfonline.com/doi/full/10.1080/23738871.2025.2597194">Mueller (2025) and many others have debunked</a> the whole theory of super intelligence.  There is no “race” to a defined finish line that brings ultimate power to the winner. There are only incremental, increasingly energy-intensive gains toward faster chips. And as Jeffrey Ding (2024) demonstrated convincingly in his book <a href="https://jeffreyjding.github.io/research">Technology and the Rise of Great Powers</a>, it is a nation&#8217;s ability to put new technologies to work across its economy that matters most in competitions over wealth and power, not being the first to develop the technology.</p>
<p>Even if the rationale behind export controls is taken at face value, Murphy (2026) <a href="https://www.tandfonline.com/doi/abs/10.1080/23738871.2026.2642613%4010.1080/tfocoll.2026.0.issue-Governing-AI-Free-Society">summarized</a> its three loopholes: diplomatic cleavages created by tiered access categories, China’s own indigenisation efforts on <a href="https://www.brookings.edu/articles/how-overly-aggressive-bans-on-ai-chip-exports-to-china-can-backfire/">computing</a>, and the substitution of software and algorithmic <a href="https://www.internetgovernance.org/2025/10/30/deepseek-ocr-chinas-answer-to-the-u-s-chip-ban/">innovations</a> for <a href="https://www.internetgovernance.org/2025/01/29/deepseek-disruption/">compute requirements</a>. These risks all indicate that computing diffusion control is not the right basket into which to put America’s eggs. Tellingly, the debate around export control has already shifted from whether chip control can contain Chinese development to “for how long” it can prolong the catching-up time.</p>
<h2>Trump shifts gears, but Congress carries on</h2>
<p>The Trump II administration has deviated a little from the “diffusion control” model. The July 2025 executive order on <a href="https://www.whitehouse.gov/presidential-actions/2025/07/promoting-the-export-of-the-american-ai-technology-stack/">Promoting the Export of the American AI Technology Stack</a> shifted focus from export restrictions to global market dominance. Under this approach, the costs and competitiveness of American companies became more of a priority. As a result, the BIS <a href="https://www.federalregister.gov/documents/2026/01/15/2026-00789/revision-to-license-review-policy-for-advanced-computing-commodities">revised its license review</a> rules in January 2026, shifting from a presumption of denial to case-by-case review. This does not mean that the Trump admin is returning to free trade; the MAGA trade doctrine still applies to chips, but chip exports are still allowed with certain caveats.</p>
<p>Not everyone in Washington agrees with this trend, however. The biggest opposition comes from Capitol Hill. From RASA to MATCH Act, the U.S. Congress has put forward bills to continue clamping down on the ability of American digital companies, which lead the world in size and scope, to do business globally. Five such bills are outlined below.</p>
<table style="width: 100%; max-width: 100%; border-collapse: collapse; table-layout: fixed;">
<tbody>
<tr>
<th style="border: 1px solid black; padding: 6px; text-align: left; width: 20%;">Bill</th>
<th style="border: 1px solid black; padding: 6px; text-align: left; width: 30%;">Goals</th>
<th style="border: 1px solid black; padding: 6px; text-align: left; width: 50%; overflow-wrap: anywhere;">Controlled items</th>
</tr>
<tr>
<td style="border: 1px solid black; padding: 6px;"><a href="https://docs.house.gov/billsthisweek/20260112/H2683_SUS_xml.pdf">RASA</a></td>
<td style="border: 1px solid black; padding: 6px;">Extends ECRA to cloud services</td>
<td style="border: 1px solid black; padding: 6px; overflow-wrap: anywhere;">Remote access to controlled compute, including AI chips via cloud</td>
</tr>
<tr>
<td style="border: 1px solid black; padding: 6px;"><a href="https://www.ricketts.senate.gov/wp-content/uploads/2025/12/ROS25L081.pdf">SAFE Chips Act</a></td>
<td style="border: 1px solid black; padding: 6px;">Statutory license requirement with denial of export to adversaries</td>
<td style="border: 1px solid black; padding: 6px; overflow-wrap: anywhere;">Advanced ICs and products containing them, except non-datacenter items</td>
</tr>
<tr>
<td style="border: 1px solid black; padding: 6px;"><a href="https://www.banking.senate.gov/imo/media/doc/gain_ai_bill_text.pdf">GAIN AI Act</a></td>
<td style="border: 1px solid black; padding: 6px;">License-certification requirement prioritizing U.S. persons</td>
<td style="border: 1px solid black; padding: 6px; overflow-wrap: anywhere;">Advanced AI chips</td>
</tr>
<tr>
<td style="border: 1px solid black; padding: 6px;"><a href="https://docs.house.gov/meetings/FA/FA00/20260121/118876/BILLS-119-6875-M001199-Amdt-106-U5.pdf">AI OVERWATCH Act</a></td>
<td style="border: 1px solid black; padding: 6px;">Mandatory licensing plus congressional certification/oversight</td>
<td style="border: 1px solid black; padding: 6px; overflow-wrap: anywhere;">Covered integrated circuits</td>
</tr>
<tr>
<td style="border: 1px solid black; padding: 6px;"><a href="https://docs.house.gov/meetings/FA/FA00/20260422/119191/BILLS-1198170ih.pdf">MATCH Act</a></td>
<td style="border: 1px solid black; padding: 6px;">Diplomatic alignment to implement export restrictions on choke-point technology</td>
<td style="border: 1px solid black; padding: 6px; overflow-wrap: anywhere;">Intermediate goods used in semiconductor-manufacturing</td>
</tr>
</tbody>
</table>
<p>Why is Congress more aggressively restrictionist than the Trump administration? Three words: special interest lobbying. According to a <a href="https://www.reuters.com/legal/government/micron-pushes-us-congress-crack-down-chip-tool-sales-chinese-rivals-sources-say-2026-04-22/?utm_source=chatgpt.com">Reuters article</a>, Micron Technology (MU.O), the largest U.S. memory chipmaker, is a driving force pushing the U.S. Congress to pass the MATCH Act legislation, for example.</p>
<h2>Leadership through market domination, or political control?</h2>
<p>There are two approaches to sustaining a country’s technology leadership. One argues to keep strengthening America’s domination across world markets selling its advanced chips; the other side wants to build a wall around advanced chip design and manufacturing to restrict Chinese access to new chips.</p>
<p>If one were to steelman Dwarkesh’s argument, export controls are needed for the following reasons: 1) in a direct conflict with China, Chinese AI will provide a decisive advantage in a military conflict, and chip controls can prevent it; 2) The US has substantial leverage in terms of computing power and other layers of the computing stack, so why not use it to gain advantage?</p>
<p>On the other side, Jensen Huang seeks to sustain the American tech leadership by maintaining its central role in the semiconductor supply chain. This approach drives revenue to American companies and fuels the R&amp;D and talent acquisition that drives innovation and better applications. Huang dismissed diffusion control as a “loser” mentality. Comparing chips to nuclear bombs is a “lousy” comparison, a product of fear-mongering. Naturally, Jensen’s judgment aligns with Nvidia’s interest as a private company. Nevertheless, there are real reasons to believe that it is more detrimental for the US to lose its dominance in global markets than to cave in to hyperbolic security risks about China’s AI capabilities.</p>
<p>From a theoretical perspective, this dilemma can be traced back to the popular theory of “<a href="https://direct.mit.edu/isec/article/44/1/42/12237/Weaponized-Interdependence-How-Global-Economic">weaponized interdependence</a>,” a term political scientists Farrell and Newman popularized and a policy that many countries <a href="https://www.cfr.org/reports/weaponizing-digital-trade">began to pursue years ago.</a> Interdependence is said to be a source of asymmetric power, and states can weaponize such power to pursue their strategic goals. However, weaponization inevitably diminishes market domination, as the excluded party seeks to reduce their reliance on the original technology diffusion network.</p>
<p>What’s worse, it is evident now that export controls cost American companies more than Chinese firms. <a href="https://www.sciencedirect.com/science/article/pii/S0304405X25002004#d1e3987">Economists from the Federal Reserve</a> estimated that the export control since 2010 creates a total capitalization loss of $18 billion for Chinese targets, but for each affected American company, the average market capitalization loss reaches $1 billion, meaning a total decrease of $158 billion for American companies, along with an average revenue decline of 8.9%, and 7.3% decline in the total number of employees.</p>
<p>The war in Iran is making it clear that a simple technology and power advantage is not always sufficient for a strategic victory in a conflict. The US had faster chips, faster planes, better intelligence, more precision bombs, better missile defenses, but it was not enough to dislodge the Iranian regime or make it surrender, nor was it able to prevent the Strait of Hormuz from being blocked. Likewise, in a real-world US-China conflict, it’s hard to imagine how a 9 or 6 month lead in semiconductor power is going to make a decisive difference &#8211; for either side.</p>
<h2>How China offsets the chip export controls</h2>
<p>Predictably, chip export controls have pushed the Chinese companies away from any dependency on the American computing supply chain. They have undertaken the following efforts to achieve the goal.</p>
<ul>
<li aria-level="1"><b>Fostering the domestic chips ecosystem</b>: at many semiconductor production stages, domestic equipment shares have risen in the Chinese market. Per <a href="https://www.csis.org/analysis/chinas-localization-drive-semiconductors-gains-impetus-allied-chip-export-controls">CSIS</a>, overall domestic equipment share surged from 25% to 35% between 2024 and 2025, while domestic producers accounted for less than 15% of the domestic market before the US imposed export control. Noticeable progress came from the etching and thin-film deposition procedures, where local firms now supply about 40% of the domestic market. A recent harder push came from a new <a href="https://www.reuters.com/world/china/china-mandates-50-domestic-equipment-rule-chipmakers-sources-say-2025-12-30/">procurement policy</a> in December 2025, requiring that Chinese fabs seeking approval for new capacity need to buy at least 50% of their equipment from domestic suppliers.</li>
</ul>
<ul>
<li aria-level="1"><b>Importing from non-US suppliers.</b> Along with these self-sufficiency efforts, China’s semiconductor-manufacturing equipment imports <a href="https://silverado.org/data-dashboards/china-semiconductor-manufacturing-equipment-imports-hit-record-levels-in-2025/">reached a record high</a> of $51.1 billion, almost five times the level of a decade earlier. But this new increase mainly came from increased imports from Japan, Netherland, and Singapore, while the import share from the US has decreased from 23% to 9% in the past 10 years.</li>
</ul>
<ul>
<li aria-level="1"><b>Using cloud and data center capacity in Southeast Asia</b>: the tiered-category of America’s chip export control regime also compels Chinese companies to look for computing capacity outside mainland China, especially in Southeast Asian countries. For example, according to <a href="https://www.reuters.com/world/asia-pacific/chinas-bytedance-gets-access-top-nvidia-ai-chips-wsj-reports-2026-03-13/">Reuters</a>, by March 2026, ByteDance was working with Aolani Cloud in Malaysia on about 500 Nvidia Blackwell systems, totaling roughly 36,000 B200 chips, in a project costing more than US$2.5 billion. At the national policy level, China-ASEAN FTA 3.0 has positioned <a href="http://english.scio.gov.cn/m/in-depth/2025-10/30/content_118149965.html">digital cooperation</a> as a core pillar, specifically on digital trade, cross-border fiber optics, and data centers.</li>
</ul>
<ul>
<li aria-level="1"><b>Maximizing its advantages in energy efficiency</b>: improvements in model efficiency and energy network can also offset the impact of computing power control. DeepSeek, along with other Chinese open-source models, are the most prominent case following this strategy; their innovations on model design reduces demands for <a href="https://arxiv.org/abs/2503.11486">computing power</a> compared to American ones.</li>
</ul>
<p>However, little attention has been given to a more fundamental advantage that China has been accumulating: the colossal national computing-energy network that reduces the energy price for computation. Since 2022, China has been constructing its “East-Data-West-Computing” (东数西算) project, linking data-abundant Eastern provinces with energy-affluent Western provinces. By the end of 2025, national hub nodes and data-center clusters under this national project took up <a href="https://www.nda.gov.cn/sjj/jgsz/jld/llh/llhldhd/0323/20260323202204680553721_pc.html">80%</a> of China’s total 1.59 million PetaFLOPS computing capacity. All these improvements at the model and energy-computing layers result in comparatively lower token prices and dependencies on American computing devices.</p>
<p>All these efforts demonstrate China’s efforts to reduce reliance on the American computing network, but this does not mean that China has circumvented all the computing bottlenecks. But it is certain that China will continue to reduce its reliance on the US computing devices, undermining the very material foundation of imposing export control.</p>
<p>AI is not just about chips and models, it is a whole digital ecosystem that contains multiple parts. For <a href="https://www.sciencedirect.com/science/article/pii/S030859612500014X?via%3Dihub">Mueller</a>, the ecosystem contains software, data, computing devices, and the network; In <a href="https://blogs.nvidia.com/blog/ai-5-layer-cake/">Jensen’s</a> opinion, the AI ecosystem is a five-layer AI stack that also includes energy. Either way, competition in AI is a multi-layered game driven mostly by the market. Different states possess different advantages and leverage across the layers of the digital ecosystem. What’s clear is that the U.S. will not maintain its advantages by exclusions and restrictions on its own industry. That is a form of unilateral disarmament.</p>
<p>The post <a href="https://www.internetgovernance.org/2026/05/04/running-a-race-looking-backwards-us-digital-export-controls/">Running a Race Looking Backwards:  US Digital Export Controls</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/05/04/running-a-race-looking-backwards-us-digital-export-controls/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI, Project Glasswing, and the Changing Institutional Economics of Bugs</title>
		<link>https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/</link>
					<comments>https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/#respond</comments>
		
		<dc:creator><![CDATA[Brenden Kuerbis]]></dc:creator>
		<pubDate>Thu, 16 Apr 2026 15:50:05 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[IG Institutions]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10474</guid>

					<description><![CDATA[<p>On April 7, Anthropic published a 244-page system card for a model that will not be made generally available for now. Claude Mythos Preview, the company&#8217;s newest frontier model, is “capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/">AI, Project Glasswing, and the Changing Institutional Economics of Bugs</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="font-weight: 400;">On April 7, Anthropic published a 244-page </span><a href="https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf"><span style="font-weight: 400;">system card</span></a><span style="font-weight: 400;"> for a model that will not be made </span><span style="font-weight: 400;">generally available for now. Claude Mythos Preview, the company&#8217;s newest frontier model, is “capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.” During testing, it identified thousands of high- and critical-severity vulnerabilities in some of the most thoroughly audited codebases in the world. The company&#8217;s response was to launch </span><a href="https://www.anthropic.com/glasswing"><span style="font-weight: 400;">Project Glasswing</span></a><span style="font-weight: 400;"> — a coordinated initiative providing Mythos access to twelve partner organizations, including AWS, Apple, Cisco, Microsoft, JPMorgan, Google, and the Linux Foundation, along with over forty additional organizations, which maintain critical software infrastructure.</span></p>
<p><span style="font-weight: 400;">Depending on who you read or talk to, the reaction has been split between </span><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities"><span style="font-weight: 400;">measured optimism</span></a><span style="font-weight: 400;"> and alarm about the model’s capabilities. The UK&#8217;s AI Security Institute, for instance, </span><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities"><span style="font-weight: 400;">found</span></a><span style="font-weight: 400;"> that while Mythos Preview can execute multi-stage attacks on vulnerable networks and discover and exploit vulnerabilities autonomously, its demonstrated capability is currently limited to small, weakly defended, and vulnerable enterprise systems, leaving open whether the model could successfully attack hardened environments with active defenders and detection tooling. On the other hand, Check Point warned that &#8220;the time-to-exploit window will collapse to near zero.&#8221; CrowdStrike&#8217;s CTO stated that &#8220;the window between a vulnerability being discovered and being exploited by an adversary has collapsed.&#8221; Thomas Ptacek, in</span><a href="https://sockpuppet.org/blog/2026/03/30/vulnerability-research-is-cooked/"> <span style="font-weight: 400;">an essay</span></a><span style="font-weight: 400;"> titled &#8220;Vulnerability Research Is Cooked,&#8221; argued that the economics of exploit development have been fundamentally altered. Anthropic itself</span><a href="https://red.anthropic.com/2026/mythos-preview/"> <span style="font-weight: 400;">frames the situation</span></a><span style="font-weight: 400;"> as a race: give defenders a head start before equivalent capabilities proliferate within</span><a href="https://www.euronews.com/next/2026/04/08/why-anthropics-most-powerful-ai-model-mythos-preview-is-too-dangerous-for-public-release"> <span style="font-weight: 400;">six to eighteen months</span></a><span style="font-weight: 400;">. But eventually, they “expect that defense capabilities will dominate: that the world will emerge more secure, with software better hardened.”</span></p>
<p><span style="font-weight: 400;">This last quote gets at the more interesting governance question beneath the headlines. Project Glasswing is an institutional response to a technological shift that could reshape the vulnerability management ecosystem. Understanding this requires tracing how the bottleneck in cybersecurity&#8217;s value chain is migrating from discovery to remediation.</span></p>
<h2><span style="font-weight: 400;">The Discovery Premium Is Gone</span></h2>
<blockquote><p><i><span style="font-weight: 400;">Prompt: A recent article on Anthropic&#8217;s Mythos model touts its vulnerability discovery capabilities, with a red-team researcher ominously saying, “We basically need to start, right now, preparing for a world where there is zero lag between discovery and exploitation.” While increasing capabilities can certainly be used for malicious purposes, a very significant and functional bug bounty market exists today. Attached is some information about Mythos&#8217; capabilities and costs to find vulnerabilities. Assuming an increase in the supply of vulnerabilities because of these new model(s), how would the more rapid discovery of vulnerabilities impact that market? </span></i></p></blockquote>
<p><span style="font-weight: 400;">The bug bounty market — valued at roughly $1.2 billion in 2024 and projected to grow to nearly $4 billion by 2032 — was built on a simple premise: vulnerability discovery was <a href="https://threatpost.com/no-more-free-bugs-software-vendors-032309/72484/">scarce</a>. Finding a critical bug in a hardened codebase required elite human attention, deep domain expertise, and significant time investment. Organizations can pay large bounties per finding because the supply of people who can produce those findings is limited, and their opportunity costs are high.</span></p>
<p><span style="font-weight: 400;">The Mythos system card reports cost data that demolishes this premise. As noted, a full scan of the OpenBSD codebase — one thousand runs across the repository — cost under $20,000 and yielded several dozen findings, including a 27-year-old vulnerability in one of the most security-focused operating systems in existence. The specific run that discovered the critical TCP SACK bug cost under $50. A scan of FFmpeg, one of the most thoroughly fuzzed projects in the world, cost roughly $10,000 across several hundred runs and found a 16-year-old vulnerability that had been hit five million times by automated testing tools without being caught. Converting a known Linux kernel vulnerability into a working root privilege escalation exploit — a task that historically takes skilled researchers days to weeks — took the model under a day at a cost of under $2,000.</span></p>
<p><a href="https://www.internetgovernance.org/?attachment_id=10483" rel="attachment wp-att-10481"><img decoding="async" class="aligncenter wp-image-10483 size-medium" src="https://www.internetgovernance.org/wp-content/uploads/1-before-discovery-premium-1-800x294.png" alt="" width="800" height="294" srcset="https://www.internetgovernance.org/wp-content/uploads/1-before-discovery-premium-1-800x294.png 800w, https://www.internetgovernance.org/wp-content/uploads/1-before-discovery-premium-1-768x282.png 768w, https://www.internetgovernance.org/wp-content/uploads/1-before-discovery-premium-1.png 1360w" sizes="(max-width: 800px) 100vw, 800px" /></a></p>
<p><span style="font-weight: 400;">Given these economics, the per-vulnerability bounty model faces a classic supply shock. When the marginal cost of discovering a critical vulnerability drops from thousands or tens of thousands of dollars in researcher time to tens of dollars in API credits, the price structure that sustained the bounty ecosystem erodes. The low-hanging fruit that historically funded early-career security researchers will be found by AI first. The market won&#8217;t disappear, but it will bifurcate: commodity vulnerability discovery will be absorbed into automated scanning services, while the remaining human bounty work will concentrate on findings that models still struggle with — business logic flaws, social engineering vectors, and the complex interactions between systems that no single codebase can reveal.</span></p>
<h2><span style="font-weight: 400;">The Bottleneck Migrates Upstream</span></h2>
<blockquote><p><i><span style="font-weight: 400;">Prompt: Let&#8217;s assume that Mythos and similar emerging models essentially are a substitute for identifying vulnerabilities. Presumably, these models can also be used for creating patches for those vulnerabilities, as explained in this work: https://team-atlanta.github.io/blog/post-patch-2026-ensemble/  The new bottleneck appears to be verification of patches.</span></i></p></blockquote>
<p><span style="font-weight: 400;">If discovery is effectively commoditized, where does the supply bottleneck move? The obvious next candidate is patch generation — and here, </span><a href="https://team-atlanta.github.io/blog/post-patch-2026-ensemble/"><span style="font-weight: 400;">recent work</span></a><span style="font-weight: 400;"> from Team Atlanta, a group of researchers from Georgia Tech, Samsung Research, KAIST, and POSTECH that won </span><a href="https://aicyberchallenge.com/"><span style="font-weight: 400;">DARPA’s AI Cyber Challenge (AIxCC)</span></a><span style="font-weight: 400;">, provides important data.</span></p>
<p><span style="font-weight: 400;">Their evaluation tested ten agent configurations — combining four coding agent frameworks (Claude Code, Codex CLI, Copilot, Gemini CLI) with five frontier models — on 63 real crashes from the DARPA AIxCC competition. The results show that AI-generated patching has progressed remarkably fast. The best configurations now produce semantically correct patches for roughly 71% of real-world vulnerabilities, up from about 52% just one year earlier. Model choice matters more than framework choice, and the improvement trajectory is steep.</span></p>
<p><a href="https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/2-after-verification-bottleneck/" rel="attachment wp-att-10480"><img loading="lazy" decoding="async" class="aligncenter size-medium wp-image-10480" src="https://www.internetgovernance.org/wp-content/uploads/2-after-verification-bottleneck-800x282.png" alt="" width="800" height="282" srcset="https://www.internetgovernance.org/wp-content/uploads/2-after-verification-bottleneck-800x282.png 800w, https://www.internetgovernance.org/wp-content/uploads/2-after-verification-bottleneck-768x271.png 768w, https://www.internetgovernance.org/wp-content/uploads/2-after-verification-bottleneck.png 1360w" sizes="auto, (max-width: 800px) 100vw, 800px" /></a></p>
<p><span style="font-weight: 400;">But patching isn&#8217;t the real bottleneck either. The actual bottleneck is *verification* — confirming that a generated patch actually fixes the root cause without breaking anything else. Even the best agent configuration in Team Atlanta&#8217;s evaluation still produces around 20% semantically incorrect patches. These are patches that pass every automated check — compilation, test suites, crash replay — but are actually wrong. The failure modes are revealing. The most common involves functionality being altered or broken: the patch fixes the bug but changes normal program behavior in unintended ways. The second most common is patching the symptom rather than the root cause — enlarging a buffer to prevent an overflow instead of fixing the underlying off-by-one miscalculation, or resetting a dangling pointer at the crash site rather than fixing initialization in the common API where the pointer should have been set. Other failures involve insufficient guard conditions, wrong API usage that violates trust boundaries, or fundamentally incorrect mitigation strategies.</span></p>
<p><a href="https://www.internetgovernance.org/?attachment_id=10479" rel="attachment wp-att-10480"><img loading="lazy" decoding="async" class="aligncenter wp-image-10479 size-medium" src="https://www.internetgovernance.org/wp-content/uploads/3-why-verification-resists-automation-800x424.png" alt="" width="800" height="424" srcset="https://www.internetgovernance.org/wp-content/uploads/3-why-verification-resists-automation-800x424.png 800w, https://www.internetgovernance.org/wp-content/uploads/3-why-verification-resists-automation-768x407.png 768w, https://www.internetgovernance.org/wp-content/uploads/3-why-verification-resists-automation.png 1360w" sizes="auto, (max-width: 800px) 100vw, 800px" /></a></p>
<p><span style="font-weight: 400;">Every one of these failure modes requires contextual judgment to detect: understanding the specification, the security model, the trust boundaries between components, and the upstream behavioral implications of a code change. Test suites validate behavior against existing expectations, not the correctness of the security property being preserved. This is precisely the kind of judgment that remains expensive, scarce, and stubbornly human (hey, hire a GT Cybersecurity grad!).</span></p>
<p><span style="font-weight: 400;">Team Atlanta&#8217;s &#8220;ensemble approach&#8221; — running multiple agents, collecting all patches that pass automated validation, and having a selector model choose the best one — improves semantic correctness rates. But it doesn&#8217;t eliminate the problem. And the researchers&#8217; own methodology reveals the constraint: they manually reviewed all 630 generated patches and cross-validated 456 of them. The evaluation scope was limited by the human review bottleneck, not by computational cost. Models can find vulnerabilities and generate patches all day at a lower cost. For now, the constraint is judgment and having humans qualified to assess whether those patches are correct.</span></p>
<h2><span style="font-weight: 400;">Glasswing as Transitional Institution</span></h2>
<blockquote><p><i><span style="font-weight: 400;">Prompt: In light of the anticipated impacts on the market, the announced institutional response, Project Glasswing, is interesting. It is unclear whether this approach would be a substitute for bug bounty markets or a complementary function, allowing vulnerabilities that enable zero-day exploits to be mitigated outside of the market mechanism.</span></i></p></blockquote>
<p><span style="font-weight: 400;">This bottleneck migration reframes what Project Glasswing actually is. The conventional reading positions it as a vulnerability discovery initiative — Anthropic gives partners access to Mythos so they can find bugs in their systems before attackers do. But if discovery is cheap and getting cheaper, the scarce resource Glasswing actually organizes isn&#8217;t model access. It&#8217;s the institutional capacity to close the loop from discovery through *verified remediation*.</span></p>
<p><span style="font-weight: 400;">Consider the partner list. The twelve Glasswing organizations aren&#8217;t just large technology firms — they are the entities with the deepest institutional knowledge of their own codebases and application of AI to cybersecurity. Apple can verify whether a macOS patch preserves intended security properties in ways that no external researcher or automated system can replicate. The Linux kernel maintainers can assess whether a proposed fix to the TCP stack introduces subtle behavioral changes that would break upstream consumers. The value of the club isn&#8217;t only vulnerability identification; it&#8217;s the human and organizational expertise required for the verification step that AI can&#8217;t yet reliably perform.</span></p>
<p><span style="font-weight: 400;">This is a fundamentally different institutional form than the bug bounty market. Bug bounties are a &#8220;flow&#8221; mechanism: they provide continuous, decentralized incentives for independent researchers to find new vulnerabilities as software evolves. Glasswing appears to be addressing the &#8220;stock&#8221; problem — the accumulated backlog of undiscovered vulnerabilities in critical, long-lived codebases — through a coordination effort that integrates discovery, patching, and verification under a managed process. The system card&#8217;s showcase findings are paradigmatic stock problems: vulnerabilities that persisted for 16, 17, and 27 years despite decades of human review and automated testing.</span></p>
<p><span style="font-weight: 400;">But Glasswing&#8217;s institutional structure also reveals tensions. It concentrates several roles — discoverer, disclosure coordinator, and capability gatekeeper — in a single organization. In the bounty market, these roles are distributed across independent actors: the researcher discovers, the platform triages, the vendor patches. Glasswing bundles them. Anthropic acknowledges the resulting coordinated disclosure management challenge: fewer than 1% of discovered vulnerabilities have been patched, and they had to hire professional security contractors to manage the validation pipeline. The announcement that it &#8220;may become necessary to relax our stringent human-review requirements&#8221; is a direct acknowledgment that the verification bottleneck is binding even within Glasswing&#8217;s coordination.</span></p>
<h2><span style="font-weight: 400;">What Comes Next</span></h2>
<blockquote><p><i><span style="font-weight: 400;">Prompt: Project Glasswing as an institutional response to technological change, i.e., the Mythos model, and the bottleneck migrating upstream from vulnerability discovery to patch verification.</span></i></p></blockquote>
<p><span style="font-weight: 400;">The key analytical question is whether the verification bottleneck is permanent or transitional, and how it will be governed. Team Atlanta&#8217;s data shows semantic correctness improving from ~62% to ~80% in roughly one year. If that trajectory continues — and the general trend in frontier model improvement suggests it might — then verification too may become largely automatable within a few model generations, perhaps through adversarial model-on-model verification pipelines where one model generates patches, another red-teams them, and a third adjudicates like the Team Atlanta ensemble approach which already demonstrates that contrasting multiple candidate patches is informative for quality assessment.</span></p>
<p><span style="font-weight: 400;">If verification does become automatable, the entire discovery-patch-verify pipeline runs end-to-end with minimal human intervention. However, there remains a fundamental human role, a genuinely hard problem that none of this current work touches: deciding which vulnerabilities *matter*, how to prioritize remediation across an organization&#8217;s full attack surface, and how to manage the systemic risk of thousands of simultaneous patches hitting production systems. Those aren’t technically solvable problems.</span></p>
<p><span style="font-weight: 400;">In the near term, several market-level consequences seem likely. The bug bounty market won&#8217;t disappear but will restructure around verified remediation rather than raw discovery. Bounty programs that pay for a discovered vulnerability, plus a validated patch, plus reproduction steps, will be more valuable than those that pay only for vulnerabilities. The platforms that survive will be the ones that pivot from brokering human research to orchestrating AI-augmented scanning with human verification in the loop. The professional services market for patch verification will grow, favoring firms with deep codebase-specific expertise.</span></p>
<p><span style="font-weight: 400;">As Anthropic notes, Glasswing itself is best understood now as a transitional institution — an attempt to manage a capability discontinuity during the period when existing market institutions haven&#8217;t yet adapted. Its familiar club structure makes sense for the current moment: the capability is restricted, the verification bottleneck demands insider knowledge, and the urgency of burning down the stock of latent vulnerabilities in critical software infrastructure justifies coordinated action outside normal market mechanisms. But if Mythos-class capabilities proliferate as expected, the club model becomes untenable because the underlying capability is no longer scarce enough to restrict.</span></p>
<p><span style="font-weight: 400;">What persists after the transition will depend on whether Glasswing evolves into a durable networked governance structure that provides value by providing disclosure pipelines, deconflicting simultaneous discovery, building robust automated and human verification capabilities, and helping manage any systemic risks of producing AI-driven (in)security at scale. The history of similar arrangements in cybersecurity — early ISACs, the Conficker Working Group, M3AAWG, the Cyber Threat Alliance — suggests clubs can persist beyond their initial formation, but only if they provide ongoing coordination value that individual actors can&#8217;t replicate on their own or with market transactions.</span></p>
<p>&nbsp;</p>
<p>The post <a href="https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/">AI, Project Glasswing, and the Changing Institutional Economics of Bugs</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/04/16/ai-project-glasswing-and-the-changing-institutional-economics-of-bugs/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>India’s crude Internet censorship regime</title>
		<link>https://www.internetgovernance.org/2026/04/07/indias-crude-internet-censorship-regime/</link>
					<comments>https://www.internetgovernance.org/2026/04/07/indias-crude-internet-censorship-regime/#respond</comments>
		
		<dc:creator><![CDATA[Karan Saini]]></dc:creator>
		<pubDate>Tue, 07 Apr 2026 14:34:22 +0000</pubDate>
				<category><![CDATA[Free Expression Online]]></category>
		<category><![CDATA[Internet Identifiers]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10468</guid>

					<description><![CDATA[<p>Sections 69A and 79 of the Information Technology Act, 2000, empower the indian government to issue blocking orders to ISPs and intermediaries. The licensing agreement for ISPs explicitly requires that they “block Internet sites […] as identified and directed by the Licensor from time to time.” ISPs are confidentially bound to the blocking orders they [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/04/07/indias-crude-internet-censorship-regime/">India’s crude Internet censorship regime</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">Sections 69A and 79 of the Information Technology Act, 2000, empower the indian government to issue blocking orders to ISPs and intermediaries. The licensing agreement for ISPs explicitly requires that they “block Internet sites […] as identified and directed by the Licensor from time to time.” ISPs are confidentially bound to the blocking orders they receive and implement. In copyright and trademark dispute-related cases, blocking orders are made public as part of court orders. The blocking of websites usually only comes to light when users notice it is inaccessible and raise questions — such as what happened when <a href="https://supabase.com/?utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=23317752603&amp;device=c&amp;gad_source=1&amp;gad_campaignid=23317752603&amp;gclid=Cj0KCQjws83OBhD4ARIsACblj19ZyB-E2x0uG1xC7ifv9F4-HkhIVhbbaVkQHtMlDrDZNKdeu2YFi08aAmNcEALw_wcB">Supabas</a>e was recently blocked. In some instances, the government may choose to announce its blocking actions, such as when it announced the blocking of <a href="https://www.reuters.com/article/technology/india-retains-ban-on-59-chinese-apps-including-tiktok-idUSKBN29U2G6/">59 Chinese application</a>s including TikTok in 2020. </span><span data-ccp-props="{}"> </span></p>
<h2><span data-contrast="auto">My study of blocking</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:276}"> </span></h2>
<p><span data-contrast="auto">To understand the scale of website blocking in India, I queried the DNS servers of six major and regional ISPs to test the censorship of 294 million domains, representing nearly the entire visible domain name space. These tests were carried out over many months in 2025 and contribute to the largest study of DNS-level website blocking in India to date. The study quantifies what previous qualitative research on Internet censorship in India has shown. Despite receiving the same blocking orders, not all ISPs block the same websites.</span><span data-ccp-props="{}"> </span></p>
<h2><span data-contrast="auto">Inconsistent results</span><span data-ccp-props="{}"> </span></h2>
<p><span data-contrast="auto">Out of the total 43,083 blocked domain names found by the study, only 1,414 were blocked by all six ISPs. This is caveated by the fact that some of the ISPs surveyed may be using other abovementioned protocols to block these domains, which the study does not cover. What is clear however is that at least on the DNS layer, domains are treated inconsistently based on the category of content they host. Piracy, peer-to-peer file sharing, pornography and gambling websites make up the majority of what is blocked, yet blocks are not consistently enforced across ISPs. For domains hosting terrorism and militancy content, blocking consistency across ISPs goes up dramatically. Perfect consensus can be seen in certain sensitive cases, such as the blocking of China’s Weibo.com or the website of Srinagar-based publication The Kashmir Walla, showing that some orders are treated more seriously than others. Along with this, almost all ISPs appear to engage in arbitrary blocking in some form.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">While highlighting only some notable blocks, the study shows the haphazard way in which both regional and national ISPs are currently implementing blocking orders. In the absence of a standardised framework or guidelines, ISPs are left to their own devices, resulting in an inconsistent blocking landscape. A domain blocked by one provider may be freely accessible through another, undermining the stated rationale for blocking while still infringing on the rights of users served by the more aggressive ISP. Domains officially ordered unblocked continue to remain blocked by some ISPs in clear defiance of orders, but without penalty to ISPs or respite for operators of such websites.</span><span data-ccp-props="{}"> </span></p>
<h2><span data-contrast="auto">Needlessly opaque </span><span data-ccp-props="{}"> </span></h2>
<p><span data-contrast="auto">Inconsistency is not the only problem however. The regime is needlessly opaque. An ideal system would see disclosure of blocked domains from the source, with exceptions only for sensitive matters such as those concerning national security and websites hosting child sexual abuse material. A perfect example of this is the many malicious domains found blocked by the study, which is arguably in the public interest, but which cannot be distinguished from overreach without disclosure. The Supreme Court in Shreya Singhal v. Union of India (2015) upheld Section 69A but emphasised procedural safeguards, including a review committee and the right of affected parties to be heard. In practice, neither can operate meaningfully as long as the system runs like patchwork.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto"><strong>Karan Saini</strong> is an independent security researcher from New Delhi, and the author of the “Poisoned Wells” report, available at <a href="https://dnsblocks.in">dnsblocks.in</a></span><span data-ccp-props="{}"> </span></p>
<p>The post <a href="https://www.internetgovernance.org/2026/04/07/indias-crude-internet-censorship-regime/">India’s crude Internet censorship regime</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/04/07/indias-crude-internet-censorship-regime/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Fake Cybersecurity: The FCC Router Ban</title>
		<link>https://www.internetgovernance.org/2026/03/28/fake-cybersecurity-the-fcc-router-ban/</link>
					<comments>https://www.internetgovernance.org/2026/03/28/fake-cybersecurity-the-fcc-router-ban/#respond</comments>
		
		<dc:creator><![CDATA[Milton Mueller]]></dc:creator>
		<pubDate>Sat, 28 Mar 2026 22:48:46 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Digital Trade]]></category>
		<category><![CDATA[Geopolitics of IG]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10462</guid>

					<description><![CDATA[<p>On March 23, 2026, the Federal Communications Commission (FCC) issued a Memorandum and Order banning the import of “covered” consumer-grade networking hardware. The decision demonstrates once again how the Trump administration&#8217;s economic nationalism and its use of “national security” claims as a basis for arbitrary executive-branch actions are having disastrous effects on the global digital [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/03/28/fake-cybersecurity-the-fcc-router-ban/">Fake Cybersecurity: The FCC Router Ban</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span data-contrast="auto">On March 23, 2026, the Federal Communications Commission (FCC) issued a </span><a href="https://docs.fcc.gov/public/attachments/DOC-420034A1.pdf"><span data-contrast="none">Memorandum and Order banning the import of “covered” consumer-grade networking hardware</span></a><span data-contrast="auto">. The decision demonstrates once again how the Trump administration&#8217;s economic nationalism and its use of “national security” claims as a basis for arbitrary executive-branch actions are having disastrous effects on the global digital economy, while doing nothing to improve cybersecurity.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">The </span><a href="https://www.congress.gov/bill/116th-congress/house-bill/4998"><span data-contrast="none">Secure and Trusted Communications Networks Act of 2019</span></a><span data-contrast="auto"> required the FCC to maintain a list of communications equipment if someone in the government thinks it poses a risk to national security. Previous iterations of this list target specific corporate entities like Huawei, ZTE, or Hikvision. Last week’s action expanded the &#8220;Covered List&#8221; to include ordinary household internet equipment, not specific companies, based </span><span data-contrast="auto">entirely on foreign origin.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">What is banned?</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">The ban targets new</span><span data-contrast="auto"> Small Office/Home Office (SOHO) routers, Wi-Fi extenders, and mesh systems. These devices can be found in practically every American home. The import ban includes any device where the &#8220;critical manufacturing and firmware assembly&#8221; occurs within a jurisdiction designated as a foreign adversary (primarily the People&#8217;s Republic of China, Russia, and Iran). The leverage for the ban comes from the </span><span data-contrast="auto">FCC’s Equipment Authorization process. No new models from these regions can receive the &#8220;FCC ID&#8221; </span><span data-contrast="auto">required for legal sale in the U.S. The Defense Department or the Department of Homeland Security (DHS) can exempt a product by transmitting to the FCC a specific determination that a given router or class of routers do not pose such risks.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">As of March 23, 2026,</span> <span data-contrast="auto">the FCC ceases all new equipment authorizations for covered devices. Starting in September 2026, retailers are prohibited from importing new inventory of covered devices. A year from now, </span><span data-contrast="auto">March 2027, the &#8220;Maintenance Waiver&#8221; expires, and even security patches for existing legacy devices must undergo a secondary federal audit if they originate from covered </span><span data-contrast="auto">jurisdictions.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559737&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Fortunately, this bit of security theater does not apply to </span><span data-contrast="auto">hardware that is already authorized and currently in </span><span data-contrast="auto">consumers&#8217; homes, or in the retail channel. These products can continue to be a “national security threat.” It also does not apply to e</span><span data-contrast="auto">nterprise or carrier-grade equipment, which </span><span data-contrast="auto">remains governed by previous specific-entity bans. Certain sub-components (like passive capacitors or casing) are exempt, provided the &#8220;logic-bearing&#8221; components (SoCs and Firmware) are not of foreign-adversary origin.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<h2 aria-level="2"><span data-contrast="auto">Legal Authorities </span></h2>
<p><span data-contrast="auto">The primary vehicle for this action is the Secure and Trusted Communications Networks Act of </span><span data-contrast="auto">2019;</span><span data-contrast="auto"> the law passed after an orchestrated and sustained U.S. intelligence community campaign portraying Huawei equipment as a </span><i><span data-contrast="auto">potential </span></i><span data-contrast="auto">(but never actualized) Trojan Horse. Additionally, the <a href="https://www.congress.gov/bill/117th-congress/house-bill/3919">Secure Equipment Act of 2021</a> prevents the FCC from reviewing or approving any authorization for equipment after it has been placed on the Covered List, effectively turning a &#8220;warning list&#8221; into a &#8220;market ban.&#8221;</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240,&quot;335559740&quot;:279}"> </span></p>
<p><span data-contrast="auto">Just as this new move will prove to be very costly to consumers, the &#8220;Rip and Replace&#8221; program authorized by the 2019 Act <a href="https://www.rcrwireless.com/20241218/policy/rip-and-replace-funding">generated a massive funding shortfall</a></span><span data-contrast="auto">. </span><span data-contrast="auto">While the law initially estimated costs at $1 billion, and Congress appropriated $1.9 billion, the actual requests from carriers totaled nearly </span>$5 billion<span data-contrast="auto">. Many small carriers started &#8220;ripping&#8221; without enough money to finish the &#8220;replacing,&#8221; leading to concerns about service outages in rural areas. In the years preceding this farce, not a single compromise of American telecom networks or data were attributable to the use of Huawei gear. On the other hand, dozens of Chinese-instigated compromises occurred by means of compromises of American-made software and phishing.</span></p>
<h2 aria-level="2"><span data-contrast="none">Factual Studies and Intelligence Reports</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">To support its decision, the FCC cited two primary types of evidence. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<ol>
<li><b><span data-contrast="auto">The &#8220;Typhoon&#8221; Campaign Reports:</span></b><span data-contrast="auto"> Intelligence from </span><span data-contrast="auto">CISA </span><span data-contrast="auto">and the </span><span data-contrast="auto">FBI </span><span data-contrast="auto">regarding </span><i><span data-contrast="auto">Volt Typhoon</span></i><span data-contrast="auto"> and </span><i><span data-contrast="auto">Salt Typhoon</span></i><span data-contrast="auto">. These reports detailed how state-sponsored actors hijacked thousands of SOHO routers to create a &#8220;botnet&#8221; that obfuscated attacks on U.S. power grids and water systems.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
<li><b><span data-contrast="auto">The 2025 Supply Chain Audit:</span></b><span data-contrast="auto"> A Department of Commerce study argued that the concentration of 85% of the consumer router supply chain in China creates a &#8220;systemic vulnerability&#8221; where a single firmware update could be weaponized to disable U.S. home internet access.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ol>
<p><span data-contrast="auto">Just as the Huawei and TikTok scares played on the general public’s ignorance of actual cybersecurity risks and vulnerabilities, the new FCC ban follows the same pattern.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> These reports do not provide evidence for the policy.</span></p>
<h2 aria-level="2"><span data-contrast="none">Deconstructing the &#8220;Foreignness&#8221; Fallacy</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">The central logical pillar of the FCC ban is that the </span><span data-contrast="auto">origin of manufacture</span><span data-contrast="auto"> is the primary determinant of risk. However, an empirical look at the &#8220;Typhoon&#8221; intrusions reveals a profound disconnect between this premise and the technical reality.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<p><b><span data-contrast="auto">Vulnerabilities vs. Backdoors.</span></b><span data-contrast="auto"> The FCC justifies the ban on the potential for &#8220;backdoors&#8221;—intentional entry points built at the factory. Yet, in the history of the </span><i><span data-contrast="auto">Volt Typhoon</span></i><span data-contrast="auto"> and </span><i><span data-contrast="auto">Flax Typhoon</span></i><span data-contrast="auto"> campaigns, </span><span data-contrast="auto">not a single instance of a hardware-level manufacturing backdoor was identified. </span><span data-contrast="auto">Instead, these actors exploited:</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="auto">Unpatched Software Bugs</span><b><span data-contrast="auto">:</span></b><span data-contrast="auto"> Standard coding errors (CVEs) that exist in software globally.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><span data-contrast="auto">Weak Credentials</span><b><span data-contrast="auto">:</span></b><span data-contrast="auto"> Default &#8220;admin/admin&#8221; passwords in cheap devices that users never changed.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="5" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="3" data-aria-level="1"><span data-contrast="auto">Management Interfaces: Ports left open to the public internet due to poor user configuration or &#8220;Secure-by-Design&#8221; failures.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><b><span data-contrast="auto">The Geography of Code. </span></b><span data-contrast="auto">The digital economy</span><span data-contrast="auto"> is global. A router &#8220;Made in the USA&#8221; likely runs a Linux kernel maintained by global contributors, uses Wi-Fi drivers written in Taiwan, and incorporates open-source libraries managed by developers worldwide. By focusing on the geographic location of the assembly line, the FCC ignores the logical supply chain of the software. A U.S.-assembled router with a poorly written UPnP (Universal Plug and Play) implementation is just as vulnerable to a hijacking as a foreign one.</span><span data-ccp-props="{}"> </span></p>
<p><span data-contrast="auto">If one looks at the </span><a href="https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF"><span data-contrast="none">Cybersecurity Advisory</span></a><span data-contrast="auto"> issued by DHS, NSA, and other agencies about the botnets used by the Chinese, one finds that U.S.-based processor architectures were involved in over 90% of the compromises, and that vendors and products like Juniper, Apache, Linux, Fortinet, Atlassian and others not located or headquartered in “adversary nations” were exploited.</span><span data-ccp-props="{}"> </span></p>
<h2><b><span data-contrast="auto">Targeting New Devices instead of Legacy Ones? </span></b></h2>
<p><span data-contrast="auto">Perhaps the most obvious lack of logic in the FCC’s policy is its exclusive focus on </span><i><span data-contrast="auto">new </span></i><span data-contrast="auto">equipment authorizations while leaving legacy devices in place. Empirical data from cybersecurity firms consistently shows that older devices are significantly more vulnerable than new ones.</span><span data-ccp-props="{}"> </span></p>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">End-of-Life (EOL) Status:</span></b><span data-contrast="auto"> The </span><i><span data-contrast="auto">Volt Typhoon</span></i><span data-contrast="auto"> campaign specifically targeted &#8220;End-of-Life&#8221; routers because they no longer receive security patches.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<ul>
<li aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="6" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">Legacy Protocols:</span></b><span data-contrast="auto"> Older routers often use outdated encryption (WEP/WPA) and lack modern hardware-level protections like </span><span data-contrast="auto">Secure Boot </span><span data-contrast="auto">or Trusted Platform Module (TPM).</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></li>
</ul>
<p><span data-contrast="auto">By banning the sale of the newest, most secure Wi-Fi 7 and Wi-Fi 8 routers from dominant foreign manufacturers, the FCC forces the American public to pay substantially more for upgraded, more secure equipment or, what is more likely, to </span><span data-contrast="auto">keep their older, more vulnerable devices for longer.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">If a consumer cannot easily or affordably replace their 2019-era router because the 2026 models are banned, the </span><i><span data-contrast="auto">total attack surface of the United States actually increases</span></i><span data-contrast="auto">. The ban targets the very devices most likely to have modern, auto-updating security features, while providing a &#8220;free pass&#8221; to the millions of insecure, aging devices that state-sponsored actors are currently exploiting.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">The FCC’s decision assumes that manufacturing origin is the primary risk factor. However, cybersecurity data suggests that device age and software support are far more critical indicators of whether a router will be compromised.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<table data-tablestyle="MsoTableGrid" data-tablelook="1696" aria-rowcount="5">
<tbody>
<tr aria-rowindex="1">
<td data-celllook="0"><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><b><span data-contrast="auto">Modern Wi-Fi 7 </span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></td>
<td data-celllook="0"><b><span data-contrast="auto">Modern Wi-Fi 6</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></td>
<td data-celllook="0"><b><span data-contrast="auto">Legacy Wi-Fi</span></b><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:2,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></td>
</tr>
<tr aria-rowindex="2">
<td data-celllook="0"><span data-contrast="auto">Encryption Standard</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">WPA 3 (mandatory)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">WPA3 supported</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">WPA2 (vulnerable)</span><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="3">
<td data-celllook="0"><span data-contrast="auto">Update support</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Active (auto-updates)</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Active</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">End of life (None)</span><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="4">
<td data-celllook="0"><span data-contrast="auto">Hardware Security</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Secure Boot / TPM</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Firmware signing</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Minimal/None</span><span data-ccp-props="{}"> </span></td>
</tr>
<tr aria-rowindex="5">
<td data-celllook="0"><span data-contrast="auto">Risk</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Low</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">Moderate if patched</span><span data-ccp-props="{}"> </span></td>
<td data-celllook="0"><span data-contrast="auto">High</span><span data-ccp-props="{}"> </span></td>
</tr>
</tbody>
</table>
<p><span data-contrast="auto">All new </span><a href="https://google.com/search?q=Be3200+Wi-Fi+7+Range+Extender+Re223be+w/Ethernet+Port+%7C+3.2+Gbps+Dual-Band+Wireless+Repeater+%7C+Internet+Signal+Booster+for+Home+%7C+Up+to+2400+sq.ft,+64&amp;prds=headlineOfferDocid%3A11350159382039194497%2Cproductid%3A11350159382039194497%2Cpvo%3A38%2Cpvt%3Ahg&amp;ibp=oshop&amp;pvo=38&amp;opi=103135050&amp;gl=US&amp;hl=en&amp;noiga=1"><span data-contrast="none">Wi-Fi 7</span></a><span data-contrast="auto"> and most Wi-Fi 6 devices utilize WPA3, which protects against common &#8220;offline&#8221; password-cracking attacks. Many legacy devices in homes rely on WPA2, which has known architectural flaws like the KRACK vulnerability.  Modern hardware is designed to only run firmware that has been digitally signed by the manufacturer. This would have prevented the &#8220;Typhoon&#8221; actors from overwriting the router&#8217;s operating system with a malicious one. Most legacy routers targeted by the </span><span data-contrast="auto">KV-Botnet lacked </span><span data-contrast="auto">this physical protection. CISA and the FBI noted that the </span><span data-contrast="auto">Volt Typhoon </span><span data-contrast="auto">campaign specifically targeted </span><span data-contrast="auto">End-of-Life</span><span data-contrast="auto"> routers from Cisco and Netgear. These devices are technically &#8220;trusted&#8221; by the FCC because they were authorized years ago, yet they are the </span><span data-contrast="auto">most vulnerable </span><span data-contrast="auto">items on the network because they no longer receive security patches.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}"> </span></p>
<h2 aria-level="2"><span data-contrast="none">Conclusion</span><span data-ccp-props="{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}"> </span></h2>
<p><span data-contrast="auto">By blocking the importation of modern Wi-Fi 7 equipment based solely on its &#8220;foreignness,&#8221; the FCC actually worsens the security situation. Incentives to upgrade to modern, more secure hardware are reduced, and users are encouraged to keep using unpatched legacy equipment—the exact hardware that state-sponsored actors have successfully weaponized for years. </span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:240}"> </span></p>
<p><span data-contrast="auto">Does this whole thing make any sense? It does it you see the FCC’s ban as an exercise in industrial policy disguised as cybersecurity. Netgear, a US-founded and headquartered company, </span><a href="https://www.nasdaq.com/articles/lobbying-update-60000-netgear-inc-lobbying-was-just-disclosed"><span data-contrast="none">has been lobbying</span></a><span data-contrast="auto"> the government on “cybersecurity and strategic competition with China.” Once again – as with the semiconductor export controls and the TikTok ban – we see the bootleggers seeking protection from competition hiding behind the religious banner of national security. While the risks of state-sponsored infrastructure attacks are real, the remedy chosen—a geographic ban on new hardware &#8211; prioritizes geopolitical decoupling over the immediate technical hardening of the American digital home.</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335559685&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240}"> </span></p>
<p>The post <a href="https://www.internetgovernance.org/2026/03/28/fake-cybersecurity-the-fcc-router-ban/">Fake Cybersecurity: The FCC Router Ban</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/03/28/fake-cybersecurity-the-fcc-router-ban/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>What Everyone Is Missing About Anthropic and the Pentagon</title>
		<link>https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/</link>
					<comments>https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/#comments</comments>
		
		<dc:creator><![CDATA[Seungtae Han]]></dc:creator>
		<pubDate>Sun, 08 Mar 2026 12:00:35 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Platform Governance]]></category>
		<category><![CDATA[Privacy & Surveillance]]></category>
		<guid isPermaLink="false">https://www.internetgovernance.org/?p=10450</guid>

					<description><![CDATA[<p>On February 27th, President Trump directed all federal agencies to cease using Anthropic&#8217;s technology after the company refused the Pentagon&#8217;s demand to allow lawful use of its AI models for mass domestic surveillance and fully autonomous weapons. Much of the current media coverage frames this dispute as a straightforward ethical conflict: a reckless Pentagon trying [&#8230;]</p>
<p>The post <a href="https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/">What Everyone Is Missing About Anthropic and the Pentagon</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>On February 27th, President Trump directed all federal agencies to cease using Anthropic&#8217;s technology after the company refused the Pentagon&#8217;s demand to allow lawful use of its AI models for mass domestic surveillance and fully autonomous weapons. Much of the current media coverage frames this dispute as a straightforward ethical conflict: a reckless Pentagon trying to weaponize AI versus a principled company standing firm on responsible use.</p>
<p>While this framing is not entirely wrong, it misses what is most important. The real stakes lie not in whether Anthropic was right to refuse, but in what this confrontation reveals about the deeper structural challenges of governing AI in high-stakes environments. This post examines three of them. First, the Pentagon&#8217;s demands are dangerous not because they cross obvious legal lines, but because flexible AI use policies erode human judgment in ways that are hard to see and harder to reverse. Second, Anthropic&#8217;s understanding of AI safety as something built into the programming of the model created the paradox at the heart of this dispute. And third, why this confrontation reveals the need for governance frameworks that do not leave principled companies to stand alone.</p>
<h2>What Happened?</h2>
<p>In July 2025, Anthropic signed a <a href="https://www.anthropic.com/news/anthropic-and-the-department-of-defense-to-advance-responsible-ai-in-defense-operations">$200 million contract</a> with the U.S. Department of Defense (DoD), and it was the first lab to integrate its models into mission workflows on classified networks. Through partnerships with Palantir Technologies, Claude Gov was cleared for classified military and intelligence tasks and became deeply embedded in Pentagon operations.</p>
<p>On February 24, Secretary Hegseth delivered a formal demand to Anthropic to remove all usage restrictions, including domestic surveillance and fully autonomous weapons, and grant the Pentagon the right to use <a href="https://www.anthropic.com/news/claude-gov-models-for-u-s-national-security-customers">Claude Gov model </a> &#8220;for all lawful purposes&#8221;. The threatened consequences for refusal were termination of contract, designation as a <a href="https://www.anthropic.com/news/statement-comments-secretary-war">supply chain risk</a> to national security, and the potential invocation of the Defense Production Act of 1950. <a href="https://www.anthropic.com/news/statement-department-of-war">Anthropic CEO Dario Amodei </a>refused, stating that DoD made virtually no progress on preventing Claude&#8217;s use for mass surveillance of Americans or to control fully autonomous weapons, and that the company &#8220;cannot in good conscience&#8221; agree to allow the DoD to use its AI models in all lawful use cases.</p>
<p>President Trump ordered the U.S. government to stop using Claude and the Pentagon moved to designate the company a national security risk last Friday. However, less than 24 hours after Trump&#8217;s ban was announced, the <a href="https://www.timesofisrael.com/hours-after-trump-announced-ban-on-claude-ai-us-military-used-it-in-iran-strikes-reports/">DoD deployed Claude</a> to attack Iran on February 28.</p>
<h2>What does the Pentagon Want?</h2>
<p>We still do not know exactly what the Pentagon has done or wants to do with Claude. What we do know is that the Pentagon demanded Anthropic remove all usage restrictions and grant access to the model &#8220;for all lawful purposes&#8221;—with no exceptions. However, Anthropic’s refusal and the Pentagon&#8217;s stated concern that AI safety guardrails could impede military response in emergency situations allow us to infer the Pentagon&#8217;s intentions. The Pentagon is pursuing a higher degree of automation in both intelligence data processing and weapons systems—a vision in which AI operates with minimal human intervention.</p>
<p>Before advanced AI, raw data was simply too voluminous and fragmented to be useful for comprehensive surveillance. The government could purchase location data from smartphone apps, browsing histories from data brokers, or financial records from third parties—but analyzing it all at scale was difficult and time consuming. This is precisely the bottleneck the Pentagon seeks to eliminate. AI makes it possible to analyze massive datasets—geolocation, web browsing activity, financial transactions—and synthesize them into predictive portraits of individuals&#8217; lives, automatically and at scale.</p>
<p>The problem is that U.S. law has not caught up with the capabilities of modern AI. <a href="https://fortune.com/2026/03/02/openais-pentagon-deal-raises-new-questions-about-ai-and-mass-surveillance/">Under current law,</a> it is perfectly legal for government authorities to acquire massive amounts of data and use AI to analyze it—even though the result may, in effect, constitute mass surveillance of American citizens. For this reason, <a href="https://www.axios.com/2026/03/01/openai-pentagon-anthropic-safety">Anthropic asked</a> the Pentagon to explicitly include contract language prohibiting the bulk collection of Americans&#8217; publicly available information. The Pentagon refused.</p>
<p>The second red line concerns autonomous weapons. The Pentagon&#8217;s position is, in some respects, understandable. The realities of modern combat are fluid and fast-changing, and there are clear limits to human capacity for real-time decision-making in such environments. AI-enabled autonomous detection and strike systems are already operating on the<a href="https://www.csis.org/analysis/ukraines-future-vision-and-current-capabilities-waging-ai-enabled-autonomous-warfare"> battlefield in Ukraine</a>, demonstrating three to four times higher target engagement rates with lower human costs—sometimes without meaningful human oversight. The Pentagon&#8217;s goal is to reflect these battlefield realities. Because future combat scenarios are unpredictable, the military wants the flexibility to operate without pre-imposed restrictions—and it insists that private companies should not be in a position to dictate the terms under which AI is used in warfare.</p>
<p>It is also worth noting that Anthropic&#8217;s use of the term &#8220;<a href="https://www.chinatalk.media/p/autonomous-weapons-101-dario-v-hegseth">fully autonomous weapons&#8221; is technically imprecise</a>. Fully autonomous weapons—systems capable of independently making the decision to kill without any human involvement—do not yet exist.<a href="https://www.darpa.mil/research/programs/assured-autonomy"> The U.S. military defines</a> autonomy as &#8220;a system&#8217;s ability to accomplish goals independently or with minimal supervision in complex and unpredictable environments,&#8221; where the system refers to a subset of a broader weapons platform, not a decision-making authority unto itself. They therefore speak not of &#8220;autonomous weapons&#8221; but of autonomous systems or unmanned systems. In other words, while automated systems can exist to assist in decisions to kill, no weapons platform is designed to make that determination entirely on its own.</p>
<p>If the Pentagon&#8217;s push for more unrestricted and flexible AI use is legally permissible, operationally advantageous, and does not formally exclude human oversight—does that mean there is nothing to worry about? There are two issues here; the first has not been mentioned enough in the public media.</p>
<h2>Trying to build politics into technology</h2>
<p>Key to Anthropic’s ethos is the idea that their model can be engineered to prevent bad uses of their product &#8211; whether by the military or anyone else. In other words, they have bought into that school of AI safety (and of Science, Technology and Society studies) that believes that <a href="https://www.internetgovernance.org/research/standardizing-security-surveillance-human-rights-and-tls-1-3/">technology itself has politics</a> and that values and social controls can be reliably built into the technical system. This viewpoint focuses on technology design rather than social institutions to regulate human behavior with technology.</p>
<p>As controls on moral behavior, technology is a crude instrument. For example, reflecting its concern that Claude’s powerful programming capabilities might be used to develop bio weapons, the company programmed the model to refuse to handle the word “pathogen.” You can kill a Claude session dead by querying one of these refusal strings &#8211; a word or request that is considered so bad that it <a href="https://www.reddit.com/r/BetterOffline/comments/1r2e7tg/anthropic_test_refusal_string_kill_a_claude/">triggers a “hard off switch”</a> that causes the application to stop dead in its tracks.</p>
<p>The problem with these kinds of controls is that they lack the contextual nuance of real-world social activities. The Center for Disease Control, for example, has every reason to be searching for the word “pathogen” or doing research work on pathogens, and found this Claude restriction an impediment to its work. The Pentagon’s unnecessary, excessively punitive “supply chain risk” designation aside, the DoD has a legitimate concern that one of these restrictions built into Claude might stop it from doing something it needs to do.</p>
<h2>The risk of automation bias</h2>
<p>On the other hand, Anthropic&#8217;s resistance to giving the DoD a blank check is justifiable. The more flexible the terms of AI use, the more likely human operators are to gradually defer their own judgment to the machine—a tendency known as <a href="https://academic.oup.com/isq/article/68/2/sqae020/7638566?login=false">automation bias.</a></p>
<p>During negotiations, Anthropic asked the Pentagon to include stricter safety language in the newly proposed contract. But<a href="https://www.cbsnews.com/news/pentagon-anthropic-offer-ai-unrestricted-military-use-sources/"> the company found</a> that &#8220;new language framed as compromise was paired with legalese that would allow those safeguards to be disregarded at will.&#8221; In other words, even when restrictions on the use of Claude exist on paper, ambiguous contractual language makes them easy to bypass in practice. Over time, even if human involvement remains the stated principle, fewer and fewer operators will feel compelled to exercise independent judgment.</p>
<p>Overly flexible AI use policies create conditions under which human operators become increasingly reliant on autonomous systems—and in doing so, introduce a risk that is not primarily technical, but human: the error born of over-reliance. As<a href="https://www.anthropic.com/news/statement-department-of-war"> CEO Amodei emphasized</a>, &#8220;frontier AI systems are simply not reliable enough to power fully autonomous weapons.&#8221; In high-stakes military environments, the combination of unreliable AI and under-exercised human judgment could result in lethal mistakes—unintended escalation, misidentified targets, or mission failure precisely when it matters most.</p>
<p>The risks are even more pronounced in the context of mass surveillance. The U.S. government has already announced plans to use AI, through Palantir,<a href="https://www.americanimmigrationcouncil.org/blog/ice-immigrationos-palantir-ai-track-immigrants/"> to support ICE operations</a> targeting undocumented immigrants—tracking their real-time locations and financial activity. The concern here is not simply that the surveillance happens, but that without strict use guidelines, agents relying on this technology are far more likely to act on its outputs uncritically, increasing the risk of overreach and wrongful action. This is not hypothetical. In recent years, police departments that over-relied on<a href="https://www.washingtonpost.com/business/interactive/2025/police-artificial-intelligence-facial-recognition/"> AI-powered facial recognition</a> arrested the wrong people on multiple occasions. The pattern is consistent as when the rules governing AI use are vague, the humans operating within those rules tend to trust the machine more than they should.</p>
<p>Anthropic&#8217;s decision to walk away from the Pentagon&#8217;s request was, at its core, a recognition of this institutional vacuum and fully within its rights as a private business. Without strict guidelines capable of meaningfully reducing these risks, no contractual arrangement could be trusted to hold. What is needed is better institutions—clear legal frameworks, enforceable oversight mechanisms, and organizational cultures that actively resist the pull of automation bias.</p>
<h2>The Paradox of Anthropic&#8217;s Safety</h2>
<p>Anthropic&#8217;s willingness to stand up for its own public interest principles deserves praise. But few have examined a deeper paradox: the safer and more reliable an AI system becomes, the more valuable it is for military applications.</p>
<p>Unlike ChatGPT or Gemini, Claude was not primarily designed for everyday consumer tasks or commercial applications even though it is still general-purpose model. It is widely regarded as<a href="https://playcode.io/blog/chatgpt-vs-claude-vs-gemini-coding-2026"> strong in deep analysis, contextual reasoning, and complex coding tasks</a>. Anthropic has also been recognized for its advanced capabilities in<a href="https://claude.com/blog/claude-for-enterprise"> local AI deployment</a>—technology that allows the model to operate on a user&#8217;s own servers without sending data to external systems. These features were developed in the name of safety, privacy, and reliability. But paradoxically, they are precisely what makes Claude so attractive for military and intelligence work.</p>
<p>In intelligence operations, agencies must process and synthesize information from multiple sources. Deep analytical reasoning is essential for handling this volume of intelligence data, identifying patterns, and generating actionable insights. Contextual understanding allows the model to interpret ambiguous situations—exactly what is needed for operational planning and battlefield simulation. Strong coding capabilities enable rapid development of custom tools for cyber operations. Claude&#8217;s local deployment architecture also allows classified information to remain in secure government networks, and external data never enters the analytical environment. In comparison, a model like Gemini, which is deeply integrated with Google&#8217;s broader ecosystem, remains vulnerable to inbound contamination—where external information pollutes or distorts the integrity of classified analysis.</p>
<p>In other words, the very qualities that make Claude &#8220;safer&#8221; for civilian use are the same qualities that make it indispensable for warfare. For the average user, this level of privacy and local deployment capability is a nice-to-have, not a necessity; most people are perfectly comfortable using cloud-based AI services. But for military and intelligence applications, these features are attractive. Anthropic built an AI designed to be trustworthy, and in doing so, built exactly what the Pentagon needed.</p>
<p>This is the paradox at the heart of the dispute. The company now finds itself in the uncomfortable position of having created a tool so well-suited for national security applications that the government is unwilling to accept any restrictions on its use.</p>
<h2>Implications</h2>
<p>The dispute between Anthropic and the DoD is not merely a corporate contract negotiation gone wrong. It offers important lessons for the future development of AI governance frameworks. One key implication is that private companies should play a larger role in AI governance than they currently do. This may seem counterintuitive—shouldn&#8217;t democratic governments, not profit-driven corporations, set the rules for powerful technologies?</p>
<p>In practice, companies&#8217; internal safety policies are often far more detailed and technically grounded than most people assume. In many cases, it is the companies—not governments—that are most sensitive to AI risks and quickest to implement guardrails. Companies possess more granular information about their own systems and have strong incentives to understand the risks their products pose. Their business models depend on it. Anthropic is a case in point. The company recognized that the very features that made Claude attractive for military use also made it potentially dangerous if deployed without restrictions. Because Anthropic understood the lethality of its own model, it was able to refuse the Pentagon&#8217;s demands.</p>
<p>This suggests that AI governance should evolve not through sweeping state control, but through the strengthening of corporate safety frameworks—with appropriate transparency and accountability mechanisms to ensure those frameworks serve the public interest. But for such frameworks to hold, they cannot rely on corporate goodwill alone. The Anthropic episode demonstrates that a company willing to draw principled lines can be immediately undercut by a competitor willing to accommodate. What is needed, therefore, is not just better corporate guidelines, but institutional structures that incentivize and reinforce them—legal frameworks that reward companies for maintaining meaningful safety standards, shield them from retaliation when they push back against unreasonable demands, and raise the cost for those who abandon their principles under government pressure. Only then can companies like Anthropic stand their ground not as an act of courage, but as a matter of course.</p>
<p>The post <a href="https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/">What Everyone Is Missing About Anthropic and the Pentagon</a> appeared first on <a href="https://www.internetgovernance.org">Internet Governance Project</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.internetgovernance.org/2026/03/08/what-everyone-is-missing-about-anthropic-and-the-pentagon/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin


Served from: www.internetgovernance.org @ 2026-08-24 12:55:03 by W3 Total Cache
-->