Policy

U.S. Needs AI Security Review Agency After Model Shutdown

The 18-day blackout of two Anthropic models exposed gaps in how America evaluates frontier AI risks and imposes remedies.

Omega Editorial· July 23, 2026· 4 min read

When the U.S. Commerce Department ordered Anthropic to restrict access to its Fable 5 and Mythos 5 models on June 12, 2026, the company concluded the only way to comply was a global shutdown. For 18 days, two of America's most capable AI systems went dark—not because of technical failures, but because the government invoked emergency export controls without a clear process for evaluating the underlying security claims.

The episode, first detailed in War on the Rocks, has reignited debate over how the United States should govern frontier AI models when national security concerns arise. According to Martijn Rasser, vice president for technology leadership at the Special Competitive Studies Project, the current system relies on opaque, ad hoc decisions vulnerable to corporate influence and political pressure. He argues Congress should establish a statutory AI security review agency with clear legal authority, transparent processes, and proportionate remedies.

What happened in June

The shutdown began when Amazon security researchers reportedly discovered a way to bypass the models' safety guardrails. Amazon CEO Andy Jassy relayed the findings to Treasury Secretary Scott Bessent, triggering a 24-hour scramble that ended with Commerce Secretary Howard Lutnick's letter to Anthropic CEO Dario Amodei. The letter required licenses for any "foreign person" to access the models—including Anthropic's own employees—but provided no specific technical details of the national security concern, according to Anthropic.

The timing raised questions. In March, the Pentagon had labeled Anthropic a supply chain risk after the company sought limits on military use of its models. Pentagon officials publicly criticized Amodei, and the department barred contractors from using Anthropic products. Whether personal animosity played a role remains disputed, but the absence of a structured evaluation process meant one company's private claims to a cabinet secretary could trigger sweeping restrictions with no independent validation.

Legal challenges followed quickly. On June 23, Legion LegalTech filed suit arguing the directive exceeded statutory authority, invoking the major questions doctrine that the Supreme Court had used in February to strike down emergency tariffs. The case highlights a core problem: the government lacks purpose-built legal authority to regulate AI security, forcing officials to stretch existing export control and emergency powers in ways courts may not accept.

The case for a review agency

Rasser proposes Congress create an independent agency—built on the existing Center for AI Standards and Innovation within the National Institute of Standards and Technology—with statutory independence, protected funding, and clear mandates. The agency would conduct 30-day pre-release security reviews with third-party validation, accredit independent evaluators, and publish written findings. For acute threats, it would have authority for 72-hour emergency reviews followed by temporary, proportionate remedies and mandatory determinations within 30 days.

The goal is to replace binary choices—approve or shut down—with a graduated response ladder. A narrow exploit might require a patch and monitoring. Moderate risks could mean conditional deployment with enhanced logging. High-risk capabilities with bypassable safeguards would trigger temporary restrictions and required mitigation. Only acute national security threats would justify emergency orders.

Critics worry any such agency would be captured by industry or politicized. Rasser argues the status quo is worse: outcomes currently depend on which CEO has which secretary's phone number. He proposes safeguards including fixed leadership terms, conflict-of-interest rules, multiple competing evaluators, and Government Accountability Office oversight with reauthorization sunsets.

Funding remains a challenge. The Center for AI Standards and Innovation currently has roughly 30 staff and $30 million in total funding since 2024—about one-tenth of what Britain's AI Safety Institute spends. Rasser estimates an equipped agency would need approximately $84 million annually, a fraction of the cost of a single F-35 fighter jet.

Why it matters

Unpredictable U.S. government actions risk pushing developers and enterprises toward Chinese AI alternatives that are increasingly capable and significantly cheaper. When American models can be suddenly cut off for weeks without clear process, the competitive advantage shifts to rivals offering stability. A transparent, court-reviewable security process could restore allied confidence in American AI leadership while providing the predictability that both domestic companies and international partners need to commit to U.S. technology stacks.

The analysis was published by Martijn Rasser in War on the Rocks.

#ai regulation#export controls#anthropic#ai security#frontier models#ai governance

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Policy

Policy· 3 min read

EPA Proposes Letting States Control Air Permit Public Notices

A rule change under consideration would shift oversight of community engagement for minor pollution sources, potentially affecting data center development.

Via WIRED · Jul 23, 2026
Policy· 4 min read

How to Design a U.S. AI Safety Regulator That Actually Works

As the White House reviews proposals for a FINRA-style AI oversight body, five critical design choices will determine whether it becomes trusted infrastructure or a failed experiment.

Via AI Watch · Jul 23, 2026
Policy· 4 min read

Africa's AI Infrastructure Race Requires Grid Planning Now

Data center capacity could grow fivefold by 2030, but power systems must be upgraded before demand overwhelms supply.

Via AI Watch · Jul 23, 2026