The US government issued a directive to Anthropic last week. Suspend access to Fable 5 and Mythos 5 for anyone who is not a US citizen. Anthropic complied. The company that spent three years building the world's most aligned AI is now building a citizenship verification system instead.
This is not normal.
Software has never worked this way. If you can download it, you can use it. If you can access a URL, you can interact with the service behind it. Passports have never been part of the tech stack. Now they are, and the mechanism is happening at the model layer.
The enforcement problem is the first thing that breaks. How does Anthropic know who is a citizen? Does it ask for a passport scan at account creation? Does it query immigration databases? Does it cross-reference with employer visa records? There is no API for citizenship. There is no standard for verifying nationality at the inference layer. Anthropic is being asked to build an identity verification regime from scratch, with no due process for the people it excludes.
Consider one person. A PhD student at MIT from India. Physically in the US. Sitting in Kendall Square. Working on alignment research. She wakes up one morning and her Fable access is gone. Her visa is valid. Her research is funded by a US university. But her passport says India, and that is now disqualifying. She cannot appeal to any authority. There is no ombudsman for model access. She is cut off by a government directive she cannot see and a company that is following orders.
Now consider the enforcer. An Anthropic engineer who joined the company to work on AI safety. Her first project after the directive: build a citizenship verification pipeline. She processes access revocation requests. She helps build the infrastructure that cuts off people she might have trained with. She is not an immigration officer. She is a software engineer who now has to decide, through code, who gets to use the model she helped build.
There is a historical parallel here. In the 1990s, the US government classified encryption as a munition and restricted its export. Phil Zimmermann was investigated for publishing PGP. The result was not that encryption stayed in the US. The result was that global crypto standards were built without US influence. The US lost control of the very thing it tried to contain.
The same thing is happening now. By restricting access to the most safety-tested models, the US pushes AI development into ungoverned spaces. Models built without red teams. Models built without monitoring. Models built by people who, because they cannot access Fable, have no reason to follow its safety conventions. Export controls export the risk, they do not contain it.
The cascading effect is the most dangerous part. Once the US proves that citizenship-based model access is enforceable, other countries will copy the template. China restricts its models to Chinese citizens. The EU restricts Mistral to Europeans. Every AI company has to deploy different models in different regions based on local citizenship rules. The global tech stack becomes a political map. Frontier models no longer serve the world. They serve their home countries.
And here is the thing about knowledge. Even if Anthropic builds perfect citizenship verification, the knowledge of how to build frontier models cannot be contained. Research papers are published. Scientists move between countries. The weights might be locked down, but the capability to reproduce them is not. This is the same problem the US had with encryption. You can restrict access to the artifact, but you cannot restrict access to the knowledge that produced it.
What we are watching is the creation of a new kind of border. Not at the physical edge of a territory, but at the API endpoint of a model. A border enforced not by customs agents, but by authentication middleware. A border with no appeals process, no exceptions, and no precedent for being reversed. The digital border at the model layer will be remembered as the moment AI fractured into national silos.