Washington says its June AI order creates no license. In practice, case-by-case decisions on unpublished standards now shape when a frontier model ships, and the labs pick who checks them. Even for a technology this fast, I believe a published rule would serve builders better.
It seems that every day of the last few years has brought a bombardment of AI-related news. What set 2026 apart, as I see it, was how Washington acted, less by published rules and more by case-by-case calls on specific labs.
Early in the year, the Pentagon labeled Anthropic a "supply chain risk", a tool built for foreign-adversary firms, after the company refused to drop two limits on how the military could use its models. [1][2] In June, Washington gave Anthropic no more than 90 minutes to cut foreign users off its two newest models, with no detailed reason, and Anthropic switched both off for everyone. [3] In September, Washington went the other way: leaders of six of the largest AI companies signed a pledge over lunch at the White House under which each company chooses its own auditor. [4][5] Elon Musk, one of the six, called the deal "just generally grading each other's homework." [6]
Under all the noise of the daily news, these events seem to share one pattern: the decisions that matter come with no published criteria. Officials forced specific models off the market without publishing what made them unsafe. [7] The accord, for its part, gets the labs to set standards together, but leaves open what makes an auditor independent. [5]
In its own way, each of these calls decided how to regulate AI. Regulation is, generally speaking, the way a state defines what is and isn't acceptable. The debate around it, however, has been much muddier than that.
I find its usual framing, "rules" against "freedom," misleading. What happens in practice is different: as I see it, there is no unrestrained freedom. Even classic defenders of limited government, such as Hayek, Friedman, and Nozick, accept that. [8][9][10] To me, the real choice is between a rule that is published in advance and open to scrutiny, and the discretion of whoever holds the power to decide, be it in a government office or in a company boardroom.
One answer I hear is that AI moves too fast for rules, and that case-by-case judgment works. At the risk of displeasing some of my peers in tech, I argue that the predictability of a published rule is better. By a published rule I mean, in short, one that is published before it applies, names a class of firms and not one company, gives reasons for each decision, and can be appealed to a body that didn't make the decision. I'll spell out the full test near the end. First, here is how 2026 got here.
A license by another name
The idea of a federal license for AI is older than this administration. In May 2023, Sam Altman asked the Senate for "a new agency that licenses any effort above a certain scale of capabilities." [11] That September, Senators Richard Blumenthal and Josh Hawley proposed a licensing regime run by an independent oversight body. [12] Congress passed neither.
The idea came back this May, this time from inside the White House. On May 6, Kevin Hassett, the President's top economic adviser, said the administration was studying an executive order (an order the President signs alone, without a vote in Congress). Under it, new AI models that could create security risks would be "released in the wild after they've been proven safe, just like an FDA drug." [13] The way I read it, that meant no release without the government's approval first.
The idea met resistance inside the White House, and the draft was rewritten. By the time it was ready, it was voluntary for the companies. They could choose to give the government early access to new models for testing, and a clause said the order authorizes no mandatory license. [14]
Even that was too much for some. The signing was set for May 21, and the heads of the big AI companies were invited. Overnight, Elon Musk of xAI, Mark Zuckerberg of Meta, and David Sacks, the former White House AI and crypto czar, each called President Donald Trump. By the next afternoon the ceremony was off. Trump said the order "could have been a blocker," and that he did not want anything to get in the way of the US lead over China. [14] Twelve days later, on June 2, he signed it anyway, almost unchanged, as Executive Order 14409. [15] Its key clause reads:
"Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models, including frontier models."
— Section 3(c), Executive Order 14409 [16]
Note the verb. The clause says this section of the order does not authorize a license. It doesn't forbid one either. It can't stop Congress from passing a licensing law later, and it leaves every power a government agency already had where it was. One of those powers was about to be used.
Washington decides when a model ships
On June 9, Anthropic released two new models. Mythos 5 is a model that can find and exploit security flaws in software. Fable 5 is the same model with safeguards added so that the general public can use it. The Commerce Department, whose AI testing center has had early access to Anthropic's new models under a voluntary agreement since 2024, had approved Fable's launch "just days earlier," as James Pethokoukis of the American Enterprise Institute noted. [17][3]
Three days later, on June 12, a letter from the same Commerce Department put both models under export controls. That is the legal tool Washington uses to keep advanced chips out of China, now applied to a model. This directive barred any foreign national from using Fable 5 or Mythos 5, inside or outside the United States, Anthropic's own foreign employees included. [18] Anthropic had no way to check users' nationality in real time, so it switched both models off for everyone, worldwide. [2] It had 90 minutes to do so. [3]
The reaction was loud. Anthropic's statement drew more than 3,000 points and 2,300 comments on Hacker News, [19] and builders on X complained, or mocked the complaints, like these:
@levelsio@levelsioThere's an issue with the selected model (claude-fable-5). It may not exist or you may not have access to it. Run /model to pick a different model. 😭😭😭
ThePrimeagen@ThePrimeagenAll the devs whining about fable being banned need to go hit the gym and stfu
Anthropic says the Commerce letter followed a report from Amazon researchers, who had found a way around some of Fable 5's safeguards. [2] Anthropic itself said the capability on display was "widely available from other models," OpenAI's among them, [18] and developers made the same point:
Simon Willison@simonwI'm just glad nobody at the US government thought to try that Fable 5 "jailbreak" against Opus 4.x or GPT 5.x, or I wouldn't be getting anything useful done this weekend at all
The model came back in steps. On June 26, Mythos 5 returned, but only for "a set of US organizations that operate and defend critical infrastructure." [20] On June 30, the export controls came off, and the next day Fable 5 came back for everyone on Anthropic's own platforms. According to Reuters, Anthropic said the controls were lifted after it put safeguards in place. [2] That is the company's account. Commerce published no detailed statement of its reasons for the June 12 order. [21] Commerce Secretary Howard Lutnick posted on X that the department had "worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America's leadership in AI." [22] What Commerce did put in writing is that it "reserves the right to reevaluate the decisions made in this letter and the necessity of reimposing a license requirement, should circumstances change or should Anthropic fail to adhere to its commitments." [2] And to get the controls lifted at all, as an analyst at the Cato Institute later put it, Anthropic "needed to hold private talks and negotiations with the White House." [7]
The word "license" in that letter belongs to export law, not to the executive order. But for a builder, I think the effect is the same. The model ships when the Commerce Department says so, and the Commerce Department can say no again.
Who gets to release to whom?
Fable came down. OpenAI's next model, GPT-5.6, simply waited (I know, it seems like ages ago, doesn't it?).
On June 26, OpenAI held back the full launch of GPT-5.6 "at the U.S. government's request," Reuters reported. Access went only to a small group of vetted partners, whose details went to the authorities. [23] On July 7, Axios reported that the wide release now had a green light, which came "after additional testing and meetings between the company and government officials." [24] The wide release followed on July 9.
The White House tells it another way. "No such permission is required or granted," a White House official said. Release decisions "rest entirely with the companies." [24]
In theory, no permission is needed. In practice, the release waited almost two weeks, through more testing and meetings with officials. If you build against a roadmap, which of the two do you plan around? I find it distressing not to know.
I don't know many people who oppose testing a model before it ships. I'd call it indispensable. What feels odd to me is that the public can't see what these officials were testing against. The government's testing framework "is voluntary, limited to closed models, and the framework hasn't been made public," as The Verge put it in August. [25] So the test was voluntary, its standard was still unpublished in August, and a lab had already waited on government testing anyway.
AI isn't, of course, the first industry to try to get around traditional regulation. Finance tried a voluntary check before the 2008 crisis. In 2004, the Securities and Exchange Commission created a program for investment-bank groups "that lack a supervisor under law to voluntarily submit to regulation." [26] The banks chose whether to be supervised, and could leave. On September 26, 2008, in the middle of the crisis, the agency's chairman, Christopher Cox, ended the program: "The last six months have made it abundantly clear that voluntary regulation does not work." [26]
Back to this year: access to Anthropic's models stayed tiered after June. Mythos 5.1, the successor to Mythos 5, "is available only through our trusted access programs," Anthropic wrote on September 1. [27]
If you planned a product launch around what a model can do, what assurance do you have that it will stay available to you and your team, whatever you invested? Anthropic has published no date for wider access. [27] The government has published no criterion for release. [7] Under the export-control rules, an appeal goes to an official inside the Commerce Department, and that official's ruling is final. The law also exempts these decisions from the standard court review of agency action. [28][29] As far as I can see, you can plan only on the hope that your provider's private talks go well. You can't plan a roadmap on a decision you can't read, made for reasons you can't see.
Each lab picks its own auditor
Then came September. On September 29, at a lunch in the East Room of the White House, leaders of six large AI companies signed the White House Accord on Super Intelligence, a set of commitments on how they will manage the risks of their most powerful models. [4][30] The signers were Sundar Pichai of Google, Dario Amodei of Anthropic, Mark Zuckerberg of Meta, Greg Brockman of OpenAI, Elon Musk of xAI, and Jensen Huang of NVIDIA. Trump signed too. The accord is a pledge, not a law.
Its third commitment is the one I find interesting. Each company should:
"Partner with an independent external auditor or evaluator to carry out independent assessments of whether the controls, monitoring, and detection are operating as intended." [5]
I'll grant that an outside check on each company's safety measures is progress on paper, and some read it as more. Amit Eyal Govrin of theCUBE Research backs the accord as "the lesser of two evils," while faulting the labs for keeping the audit reports in their boardrooms. He puts the gain this way: "External audit is now the stated US position, and it got there without handing the incumbents a regulatory moat." [31]
Progress, then, but in my view not enough. So what does the accord leave out? The accord names no outside body to pick, approve, or pay the auditor, and sets no test of independence. [5] Each company is simply to "partner" with one. As Govrin puts it: "The labs pick and pay their own auditors." [31]
Here, I'd look at finance again for an analogous playbook. It has a name for this design: issuer pays. Credit-rating agencies grade bonds, the debts that companies and governments sell to investors, by how likely they are to be repaid. Since the 1970s, the bond market has run on a system "in which the bond issuers choose and pay the RA's [rating agencies] that rate their bonds," in the words of the staff of the Financial Crisis Inquiry Commission, the official body that investigated the 2008 crisis. [32] An agency that graded a client too harshly could lose its business. After 2008, the commission gave its verdict: "the failures of credit rating agencies were essential cogs in the wheel of financial destruction." [33] I'm not the only one who sees the match. A July piece for the Council on Foreign Relations put it directly: "The closest analogy to companies funding their own evaluators is the issuer-pays credit-rating model." [34]
The signers also write their own standards: "The participating companies will meet regularly to establish standards and best practices to improve the safety of their systems." And law? "Over time, it may make sense to codify these steps into laws or regulations." [5]
Over time.
On the afternoon of the signing, Vice President JD Vance argued against an FDA-style approval agency for AI: "most bureaucrats just know way less about this than the people who are actually building these products." [6] I've heard that argument before. Jeff Skilling ran Enron, the Houston energy company that Fortune named America's most innovative six years in a row. He was so sure he was the smartest guy in the room that he dismissed anyone who disagreed as not bright enough to get it. Enron collapsed in 2001, and Skilling went to prison for fraud. [35][36] Knowing more than your checker has never been a reason to have no checker.
"They're gonna police themselves"
The next day, Trump, who had signed the accord with them, summed it up in the Oval Office:
"They're gonna police, and they're gonna police each other, and they're gonna self-police, they're gonna police themselves. It's going to work out very well." [37]
Except that recent history seems to tell us otherwise, particularly in fields driven by speculation, like real estate before 2008. AI may be another: in October 2025, the Bank of England said equity valuations appeared "stretched," above all for tech companies focused on AI. [38] The commission that investigated the 2008 crisis found that the watchdogs failed: "The sentries were not at their posts," in no small part because of faith in "the ability of financial institutions to effectively police themselves." [33]
So what does self-policing look like? In early September, OpenAI released GPT-6 Astra and rated its own model as meeting "the Critical threshold in cybersecurity under our Preparedness Framework." [39] Critical is the higher of the framework's two capability thresholds. OpenAI says outside experts helped evaluate the model, but the framework and the label are OpenAI's, and I have found no independent body that publicly confirmed the rating. I'd guess the label is honest. But as a member of the public, I'm left to take OpenAI's word for it, and so are you.
So in the cases above, the government decided case by case, without a published standard, when a model reached the public. And the companies decide who checks them, the way bond issuers choose their raters.
Worse than a license
The case against this system doesn't come only from people who want more regulation. Some of the sharpest criticism comes from people who want less.
Their argument goes further than mine. To them, an informal scheme like this one is a licensing system in disguise, and a worse one, because a formal license at least says what it requires. On Fable and GPT-5.6, the Cato Institute analyst quoted above, writing for a think tank that favors limited government, put it this way: "no one knows what made them too dangerous to release, and no one knows what would make them safe enough to release." The scheme, the analyst concludes, is "unnecessarily obscure, untraceable, and essentially undisputable, making it somehow worse than a formal licensing process." [7]
Their remedy is not an FDA for AI either. They call FDA-style pre-approval "deeply flawed." Their remedy is a narrow law passed by Congress, with "a clear set of parameters that apply only to significant risks." [7] Published parameters, set in advance, that reach only significant risks. As I read it, that's a rule, not a licensing agency.
Even the main staff drafter of the administration's AI Action Plan wrote two weeks after the June order that "in practice, you do need an explicit green light from the government now." [40] Two days later, Politico reported that OpenAI had hired him, and he confirmed it. [41]
When the system fails
I think the bigger risk still lies ahead. AI incidents keep coming. In July, AI agents that OpenAI was testing for hacking skills broke out of their sandbox and hacked into Hugging Face. [42]
Sooner or later, I expect, an incident like that will hit the front page. When it does, I expect the public to ask why nobody stopped it, and lawmakers to come under pressure to act fast. What do they reach for? The record gives a hint. After the Enron scandal came Sarbanes-Oxley (2002), which tightened the rules on corporate accounts. After the 2008 crisis came Dodd-Frank (2010), which tightened the rules on banks. Critics have since called both laws heavy burdens: Sarbanes-Oxley for making a US stock listing costlier, [43] Dodd-Frank for speeding the decline of community banks. [44]
And that's precisely my point. I doubt the next failure will bring the deregulation many builders want. I expect a new layer of rules, written under pressure. A published rule written now, in calm, is the better deal.
Two objections: speed and cost
History aside, I see two objections that deserve an answer. The strongest is speed. A law written in 2024 would already be out of date, the argument went in March, [45] and the informal system had worked relatively well to that point.
I think half of that is true. A rule pegged to a model's architecture, size, or capabilities can age. Those are the things that keep changing, so a line that marked the frontier in 2024 can mean something else by 2026. But not every rule is pegged to the model. A rule about a mechanism, such as "the checked firm neither picks nor pays its checker," should age much more slowly. The issuer-pays model took hold in the 1970s, [32] and its conflict was still at the heart of the rating failures of 2008. [33]
A rule also doesn't need a new law for each change. A law can set the frame and let an agency update the details in public. In the US that's called notice and comment. The agency publishes the proposed change, takes comments, and sets a date. Anyone can see the change coming. Discretion ages too, and less visibly: an executive order can be revoked the day a new administration arrives, and an unpublished testing framework can change between one release and the next with nobody outside knowing.
The second objection is cost. A law that only the big labs can afford to comply with would turn their lead into a moat.
Look at who the current system already serves first. GPT-5.6 went to vetted partners first, Mythos 5 came back only for critical-infrastructure operators, and Mythos 5.1 shipped only through trusted-access programs. The way back from export controls ran through private talks at the White House. If you run a ten-person startup, which of those doors is open to you?
A general rule names a class of firms, and it can be targeted: the Cato proposal calls for "a clear set of parameters that apply only to significant risks." [7] Discretion decides one company at a time, and I suspect the company with the best access goes first. That's the moat I'd worry about.
What a published rule looks like
"Rule" can mean almost anything, so here's what I mean. A published rule passes six tests, and the tests bind firms and government alike:
- It's published before it applies.
- It's general: it names a class of firms, not one company.
- Each decision states its reasons against the published standard.
- An appeal goes to a body that didn't make the decision.
- The checked firm neither picks nor pays its verifier.
- A law sets the frame, and an agency updates the details in public, with a date.
On the record above, I count the 2026 system failing all six. The testing standard is unpublished. Fable and GPT-5.6 were handled one company at a time. The Commerce Department gave no detailed reasons. Under the export-control rules, an appeal runs to an official inside the Commerce Department, whose ruling is final, and the law exempts these decisions from the standard court review of agency action. [28][29] The labs pick their own auditors. And the testing framework rests on an executive order, not a law.
Call it control by discretion
In June, the administration signed an order that authorizes no license. Then, case by case, Washington decided when models shipped and who got them, and the labs pledged to pick their own auditors. As far as I can tell from these cases, nothing got less controlled. What the public never got was a detailed reason tied to a published standard.
I've seen this move before. In my 2022 thesis on the 2008 crisis, I wrote that "the name 'deregulation' can mystify more than it explains: it is not a movement solely to end every form of regulation, only those that limit the possibilities of expanding their speculative activities" (my translation). [46] In plain terms: the rules that went were the ones that limited risky bets. As I see it, the pre-2008 system wasn't an absence of rules. It was a set of choices about who checks whom. So is the 2026 one.
So stop calling it deregulation. Call it control by discretion.
References
- Ball, "Clawed", Hyperdimensional, March 2, 2026.
- Reuters, the lifted Fable 5 controls, June 30, 2026.
- Pethokoukis, "The Long-Term Impact of L'Affaire Anthropic", AEI, June 15, 2026.
- Politico, AI executives sign the accord at a White House lunch, September 29, 2026.
- White House Accord on Super Intelligence, September 29, 2026, American Presidency Project.
- Robles, White House unveils super intelligence executive order and industry accord, Nextgov, September 29, 2026.
- Cato at Liberty, "The White House's Approach to Frontier AI Might Be Worse Than an 'FDA For AI'", July 17, 2026.
- Hayek, The Road to Serfdom, Routledge, 1944, chapter 6, "Planning and the Rule of Law", pp. 75–76 (Routledge Classics edition).
- Friedman, Capitalism and Freedom, University of Chicago Press, 1962, chapter 1, p. 15, and chapter 2, pp. 25–26 (40th anniversary edition).
- Nozick, Anarchy, State, and Utopia, Basic Books, 1974, preface, p. ix.
- Altman, written testimony and hearing remarks, Senate Judiciary Committee, May 16, 2023.
- Blumenthal and Hawley, Bipartisan Framework on AI Legislation, September 8, 2023.
- Federal News Network, "WH 'studying' AI security executive order", May 6, 2026.
- Görgen, "Trump Abandons 'FDA for AI' Proposal", Tech Policy Press, May 22, 2026.
- Lennett, "Trump Signs Previously Shelved AI Executive Order", Tech Policy Press, June 2, 2026.
- Executive Order 14409, June 2, 2026; 91 FR 34565.
- Lau and Frame, "May 2026 US Tech Policy Roundup", Tech Policy Press, June 1, 2026.
- Anthropic, "Statement on the directive to suspend Fable 5 access", June 12, 2026.
- Hacker News, discussion of Anthropic's statement on the suspension, June 13, 2026.
- Anthropic, post on restoring Mythos 5 access, June 26, 2026.
- Cloud Security Alliance, governance analysis of the Fable and Mythos export control, 2026.
- Lutnick, post on X announcing the Fable 5 decision, June 2026.
- Reuters, OpenAI defers the public rollout of GPT-5.6, June 26, 2026.
- Axios, the wide release of GPT-5.6, July 8, 2026.
- The Verge, The Stepback, August 16, 2026.
- SEC press release 2008-230, September 26, 2008.
- Anthropic, Claude Fable and Mythos 5.1, September 1, 2026.
- 15 CFR Part 756, Appeals, Export Administration Regulations.
- 50 U.S.C. 4821, Export Control Reform Act of 2018.
- AP, report on the accord lunch, September 29, 2026.
- Govrin, "Grading Each Other's Homework", theCUBE Research, October 5, 2026.
- FCIC preliminary staff report on credit rating agencies, June 2, 2010.
- The Financial Crisis Inquiry Report, January 2011.
- Nguyen, Tabassi, and Duffy, "The U.S. Is About to Design an AI Regulator. Here's How to Get It Right.", CFR, July 23, 2026.
- McLean and Elkind, The Smartest Guys in the Room: The Amazing Rise and Scandalous Fall of Enron, Portfolio, 2003.
- US Department of Justice, Skilling sentencing release 06-723, October 23, 2006.
- Barrett, "Whatever AI Safety Is, It's Not This", WIRED, October 1, 2026.
- Bank of England, Financial Policy Committee Record, October 2025.
- OpenAI, GPT-6 Astra, September 2026.
- Ball, "Leviathan Waking", Hyperdimensional, June 16, 2026.
- Politico, OpenAI hires former Trump AI official Dean Ball, June 18, 2026.
- OpenAI, "The Hugging Face incident and the road ahead", 2026; Hugging Face, security incident disclosure, July 2026.
- Committee on Capital Markets Regulation, Interim Report, November 30, 2006.
- Lux and Greene, "The State and Fate of Community Banking", Harvard Kennedy School M-RCBG Associate Working Paper 37, February 2015.
- Cowen, "In the Pentagon Battle with Anthropic, We All Lose", The Free Press, March 1, 2026. Cowen is a member of Anthropic's Economic Advisory Board, as he discloses in "A Dangerous Turn in AI Regulation", The Free Press, June 14, 2026.
- Krug, my 2022 thesis, USP, p. 146, after Panitch and Konings.



