Podcast Transcript — The US vs. AI: Discussing the Echoes of the Crypto Wars in AI Governance

The Association of Foreign Press Correspondents in the United States recently hosted a podcast in partnership with the Hinrich Foundation titled, “The US vs. AI: Discussing the echoes of the Crypto Wars in AI governance.”

Miguel Gomez is a Senior Research Fellow with the Centre on Asia and Globalisation. Previously, he worked as a Senior Researcher with the Center for Security Studies (CSS) at the Swiss Federal Institute of Technology (ETH) in Zurich. His area of research is found at the intersection of technology, foreign policy, and political psychology. Specifically, he is interested in how novel technologies shape policy, strategy, and public opinion for elites and the public at large. His recently published Hinrich Foundation research compares the current US-Anthropic dispute over AI governance with the Crypto Wars of the 1990s, warning that heavy-handed measures could undermine American innovation, competitiveness, and long-term security.

The US vs. AI: Discussing the Echoes of the Crypto Wars in AI Governance
The Association of Foreign Press Correspondents in the USA (AFPC-USA)

Gomez discussed his research with journalist Jennifer Freedman, who for more than two decades has contributed reporting on trade and global markets for different outlets. 

This podcast episode was produced in partnership with the Hinrich Foundation. AFPC-USA is solely responsible for the content of this episode. The learning takeaways are available HERE.

Jennifer Freedman: This is an episode of the Foreign Press USA Podcast, produced by the Association of Foreign Press Correspondents in the USA, in partnership with the Hinrich Foundation, an independent Asia-based philanthropic organization dedicated to advancing mutually beneficial and sustainable global trade. AFPC-USA is solely responsible for the content of today's episode. I'm Jennifer Freedman, and I've spent more than two decades reporting on trade and global markets for outlets including Bloomberg, MLex, and Borderlex

Today, we are exploring a compelling new Hinrich Foundation report that draws parallels between the US-Anthropic dispute over AI governance and the Crypto Wars of the 1990s. The paper warns that heavy-handed unilateral measures, such as export controls on Anthropic's Mythos 5 model, could end up weakening US competitiveness, innovation, and long-term security. We're joined by its author, Miguel Gomez, senior research fellow at the Centre on Asia and Globalisation in Singapore. His broader work examines how emerging technologies shape policy and public opinion, and this report applies that lens to the current debate over frontier AI.

Miguel, thank you for being here.

Miguel Alberto Gomez: Glad to be here with you, Jennifer.

Jennifer Freedman: Let's start out with a moment that really sets this debate in motion. On June 12, the US Commerce Department restricted foreign access to Anthropic’s Mythos 5 and Fable 5 models. Why was that such a pivotal moment in the AI governance debate?

Miguel Gomez: I think, at least in the context of the US, that was an interesting move on their part, mainly because the current administration essentially wanted to take a hands-off approach when it comes to regulating frontier AI models. The idea being that by applying a light touch to it, you could encourage them or you could encourage greater innovation from these organizations. 

At the same time, it was also quite curious because Anthropic, as far as we know and as far as they've communicated [to] us, took all the necessary steps, within reason, as far as we know, to try to control the risk of misuse from these models. So, prior to the public release of Fable 5, for instance, they had Project Glasswing that is tied to the Mythos variant of the model, which is a more powerful variant, to try to ensure that possible vulnerabilities this model would identify could be patched before essentially it and its other variants were released in the wild.

It's this idea that even if an organization took the necessary steps to play it safe, so to speak, you still have this very heavy-handed, all-encompassing approach to restrict access to it. And that sent clear, or at least questionable, signals in terms of what the future will hold when it comes to the United States government regulating these frontier models.

Jennifer Freedman: Now, what inspired you to revisit the Crypto Wars and connect them to today's AI governance challenges?

Miguel Gomez

Miguel Gomez: I've always had this idea that there's really no need to reinvent the wheel when you talk about a lot of these emerging technologies. The example I typically use when talking about AI right now — I started my career talking about the question of cyber, and if we revisit the debates surrounding cyber during the late 1990s, early 2000s, you could almost just replace the word with “cyber” and it's the same, or these very close discussions that we're having when it comes to AI. So, with that logic, I just thought, okay, what instance in the past could we draw lessons from? 

And one particular example that popped up in my mind that, as far as I knew at the time, no one had really looked into that much would be the Crypto Wars. The parallels between the two are actually quite interesting. Both are dual-use technologies. Both had the weapons narrative attached to them.

The US government tried to regulate quite forcefully both technologies. So, the Crypto Wars allow us to draw some lessons in terms of what to do and what not to do when it comes to AI. It's not a perfect comparison, but the overarching features and benefits of these technologies and the risks do have some level of comparability, so we can draw lessons from those.

Jennifer Freedman: Now, you described the relationship between Anthropic and the US government as a "love-hate dynamic." What does that tell us about how states interact with frontier AI firms?

Miguel Gomez: So this links back to how, or at least the narrative, the discourse that we tend to hear a lot about what AI can do for states. And the most common thread here is that it's a strategic enabler. If it's something that will allow states to advance their respective strategic interests, then obviously they will have an interest in monopolizing control over that. The interesting thing with AI and crypto, for instance, is that it also presents the flip side of the coin

Yes, it'll give you an advantage, but it can also present a disadvantage if used in a particular way. So, with crypto, the advantage was: now we can engage in the internet economy because a lot of the transactions now can be secured with cryptography. But the reverse of that is, when cryptography is easy to obtain, then our adversaries, our bad actors, can also use that to hide their behavior from law enforcement.

Something similar can be applied to AI. AI can help us in a number of ways. At least, we don't need to give examples of how it helps at the personal level. I think all of us — you, me, and a lot of the listeners here — use AI on almost a regular, day-to-day basis. For governments, AI promises to increase efficiency, aid in decision-making, and whatnot. But the threat here, and in particular when it comes to Mythos, is that AI is another threat vector, so to speak. 

The narrative with Mythos is that it allows you to run malicious cyber activity much faster if you're a bad actor. What can sometimes take days, weeks, or even months for your typical human hacker to figure out, Mythos and other related models that have the cybersecurity skill attached to them can do much faster. On the one hand, it's an advantage to defenders because it allows them to respond to threats faster, but at the same time, malicious actors can use it to advance their interests as well.

We've seen reports of the intentional use of AI to support cyber espionage operations, for instance. So OpenAI, late last year, I believe, issued a report on the first-ever example of a Chinese cyber espionage operation that relied heavily on AI to run that operation. Although it's easy to misinterpret what that means, it is something to think about, and it's this duality, this dual-use aspect of the technology that has countries worried. And that partially explains the love-hate relationship. 

In the case of the US government and Anthropic, we can also point back to the disputes earlier this year about Anthropic being sensitive when it comes to the use of their models for targeting and possible surveillance of US nationals. So there is history there, on top of the underlying characteristics of the technology.

Jennifer Freedman: Well, I did want to ask you about Mythos 5's dual-use capabilities. Mythos 5 can identify and explore software vulnerabilities. So how should governments approach models with this kind of dual-use potential?

Miguel Gomez: I think locking it away in some box is not the solution to it, for the simple reason that potential adversaries are also developing them. It's not just the United States developing them. The same logic applies with crypto. You deny access to certain cryptographic technologies; they will just go somewhere else to gain them. And the disadvantage here is that some actors may be developing similar models with a lot less caution than their US counterparts might be. 

In some sense, you're incentivizing a turn toward a more dangerous alternative rather than engaging with the community to try to develop the proper governance measures to ensure that the necessary steps are taken to mitigate the risk that's coming out of Mythos. 

So, Project Glasswing is actually a very good example of this. Even prior to the release of Mythos 5 and Fable 5, several months beforehand, Anthropic had engaged with partners from both foreign governments [and the] private sector, and I think there are some civil society folks as well involved in that. I could be wrong. They're not completely transparent [about] who was involved. But the point here is that they opened up the tool to other actors to see what it can discover and to try to patch those issues before the final release. And even on top of that, you already had guardrails being implemented with these models as well. So, I think it's really a question of first figuring out who needs to be consulted and then getting their buy-in to help with managing the risks from these tools.

Jennifer Freedman: Now, in the past few weeks, we've seen real-world incidents where autonomous agents, including OpenAI models, escaped their test environments and carried out unsanctioned cyberattacks. Very scary stuff. How do these events affect the policy debate you described in your paper? Do they strengthen the case for tighter controls on frontier models, or do they risk repeating the overreactions of the Crypto Wars?

Miguel Gomez: They are a very good example of governments having to engage with the necessary stakeholders. A lot of the reporting when it came to these incidents painted it as if these models went completely rogue, that they did their own thing completely unprompted. There needs to be some nuance to that understanding.

For the recent incident, for instance, from the AI Security Institute report that just came out a couple of days ago, in their case, it did not necessarily go rogue because the way that they developed the testing environment was that they allowed the system to actually use the internet because they were trying to simulate the maximum capability of these models when trying to achieve a particular cybersecurity goal. 

Whereas in other cases, the instructions that they gave the models were not fine-grained enough, which left certain things open to the interpretation of the models that the engineers and the testers did not anticipate the model would do.

So this idea of escaping the sandbox or breaking out of the sandbox, I think, is too broad, and it basically just speaks to the fact that we need to take a look at how these things are being tested and implement the appropriate controls and standards when you're testing them. And the only way you do that is not by just declaring, “No, no one has access to this anymore,” because that doesn't necessarily solve the problem. That just limits the number of people who have access to it, but it does not address the fact that, as these models become more advanced, their ability to think outside the box, to put it one way, is harder for us to anticipate. So, we need to bring in as many relevant stakeholders as possible [and] try to figure out the rules that we need to govern these technologies.

Jennifer Freedman: That makes sense. Another point that you make is that LLMs [large language models] are not fully predictable. The same prompt can produce different answers, which means guardrails can't guarantee complete security. Given that reality, Miguel, how should policymakers think about jailbreak risk in a practical, realistic way?

Miguel Gomez: This is not a new situation. Those of us who were on the applied side of cybersecurity, we all know that perfect cybersecurity or complete security is a myth. It's not possible. 

If you apply that same logic to LLMs, it's just a matter of introducing the appropriate mitigation controls to minimize the risk. So, in the example I gave earlier, when it comes to test restrictions not being clear enough, in one of the recent incidents, we found that the LLM, even if the situation that was presented to it was supposed to be fictitious, its ability to access the internet ended up with it identifying a real-world entity with the exact same name. And it still assumed that that real-world entity was fictitious and could go ahead with the actual actions that it planned to do so. In this case, we can't predict exactly how these models will think about or approach certain tasks.

We know that when pushed to a corner against the wall, these models tend to try to be as creative as possible when it comes to the solutions that they pursue. I guess the thing here is that if we can't always be sure how they're going to act, we might as well take the necessary steps to try to figure out how to regulate or manage how we ask them to behave. 

So again, more controls in terms of how we instruct these things, more controls on how testing is to be done or how the testing environment is to be set up, [and] the parameters that we ask these things to follow. And again, this circles back to the whole, “It can't just be the government thinking about this.” You need to bring in more individuals to think about this, to see the different possibilities that may arise with the use or misuse of these tools.

Jennifer Freedman: Now I'm wondering what lessons we can take from the Crypto Wars that are applicable today. Back in the 1990s, export controls on encryption ended up hurting US competitiveness. Do you see similar risks emerging with AI today?

Miguel Gomez: I would say that this potential might appear, especially now that, if, let's say, the US becomes more restrictive in terms of access to the models that it develops, you have alternative open-weight models that exist out there coming from Chinese labs or other rival countries to the United States. 

Now, on the one hand, it gives those who are denied access to US models an alternative path, an alternative set of models to use to meet their required goals. But the problem here is, when it comes to open-weight models, the ability to tweak those things in such a way makes the possibility of malicious use, or at least misuse, higher. It's easier for actors to repurpose open-weight models with fewer guardrails. That poses a greater risk for the community at large. Although there are some disadvantages with how US firms are developing their models — they're very closed source — at least there is some level of assurance that certain guardrails are in place.

So, it still risks exposing the US to additional threats. Simply closing it off only addresses one side of the question and does it in a very ham-fisted way. So just closing it [off] is not the solution here. You need to at least figure out the appropriate governance measures so that even if there is risk in the use of these models as a function of their increasing capability, you at least are still able to manage these risks accordingly.

Jennifer Freedman: Now, you're arguing that restricting US models won't stop adversaries from developing their own. That totally makes sense. So then, how do you think the US should actually think about global competition in AI?

Miguel Gomez: When it comes to global competition in AI, I think the US should first acknowledge that complete dominance is not possible

If we look at the fundamental enablers of AI, neither the US nor China nor any other competitor will have exclusive access to the computing resources, the data, whatnot. So, I think the question here for the US is: what is its value proposition that will attract more users of its technology? And I think the potential here is when it comes to the stability and the potential to mitigate the risks that come out from US-based or US-developed models. 

Not to say that this cannot be done by outside actors, but the United States in particular — firms such as OpenAI, Anthropic, et cetera — are already developing models with this mindset. It's not a free-for-all. There are necessary guardrails. They are implementing these guardrails, and they are aware that responsible development is key to advancing their economic interests. So I think the value proposition here is that you are in safe hands, if managed correctly, with US models.

Jennifer Freedman: Now, Anthropic created Project Glasswing to patch vulnerabilities before malicious actors could exploit them. Do you see this as the kind of public-private partnership the US needs more of right now?

Miguel Gomez: It's one of them. It's definitely one of them. The other aspect that I would imagine is that simply letting the market play out — the original idea from the Trump administration to just let these AI companies develop their tools completely unhindered — is not going to work out. 

Voluntary assessment, I think, will be problematic. I think there has [to be], especially for more powerful, more capable models, some level of mandatory oversight. The question, though, and something that still needs to be answered by this administration and any future administration is: who would make up this group that oversees these models? 

Obviously, the government will have to be there. There's a natural interest for them to be there, but it cannot just be them. The expertise when it comes to emerging technology — we all know that governments tend to not have a monopoly on that — and the imbalance is especially stark when it comes to AI.

So, you'd need to bring in the right balance of stakeholders when it comes to these oversight projects. The private sector is most likely going to be there. Academia would also probably have to be there. Certain civil society organizations will also have an interest in being involved. The question, though, is: how do you essentially put everyone in the same room to discuss these things?

Jennifer Freedman: And who drives it.

Miguel Gomez: And who drives it, which I think is still very much an open question, not only for the United States but in general across the globe. I don't think anyone has an answer that they're completely comfortable with right now. 

And I think it'll not only have to consider the technology itself, but other non-technological factors relevant to the particular country we're talking about. But definitely, oversight will be necessary.

Jennifer Freedman: Absolutely. So now, your paper lays out three governance principles. Which one do you think policymakers most urgently need to adopt?

Miguel Gomez: I think policymakers will really just need to acknowledge that they cannot go at this alone. This is a multi-stakeholder initiative. And while I understand why governments — not just the US, but governments in general — want a lot of control when it comes to who has access to these models and how they're used, they need to acknowledge that they can't do this on their own. 

This is, for lack of a better term, a team effort. And this reality is not new with AI. This is exactly the same conversation we've had when it comes to cybersecurity, and we’ll throw crypto into that equation as well. When it comes to dual-use technologies, especially ones where governments do not have a monopoly on the technology, then you really have to reach out to other groups and individuals.

There have been in the past — at least, I still believe — some people [who] insist on comparing AI to nuclear technology, but that's not an appropriate analogy mainly because that just highlights the main difference between AI and nuclear. Nuclear, historically, was a technology that governments had a monopoly on, and they could afford to take things unilaterally or mostly unilaterally. Whereas with AI, you have everyone across society involved, so it's not just the government.

Jennifer Freedman: I'm wondering about how political psychology shapes public opinion about AI risk. What are your thoughts about that?

Miguel Gomez: In this case, again, linking back to the point I made earlier, it just sounds like a remix of the whole cyber debate. It's pretty much comparable in the sense that we still don't really understand a lot about AI, and the way that the media tends to report failures of AI, they tend to catastrophize it quite a bit. The issue with that is that if the public is not fully read into the nuances of the technology — and, to be perfectly blunt, the majority of the population is not read into the nuances of the technology — individuals will tend to gravitate to what is easily accessible to them cognitively. So, in this case, what is that? 

A lot of how the media portrays them, a lot of how Hollywood portrays AI, so they use that as a basis to try to fill in the gaps of what they don't know. And the problem there is that you have a lot of catastrophizing when it comes to what AI can and cannot do. I was just googling what's been discussed over the last few incidents, and there's no shortage of articles with The Terminator in front of the article or Skynet in front of the article. Is this a Skynet moment? So that's my point there. 

They gravitate to these images or these understandings because the technology itself is still relatively new. We don't have a good grasp on the technology. And if that's all that the public is hooking their understanding on, then there's a lot of hyperbole that comes out. There's a lot of fear and worry about what the technology can do. This is not to say that there's nothing to be worried about. There definitely is something to be concerned about. It's a question of how much should we be concerned? And I think this is where the government can actually, or governments in general can, play an important role in moderating the fears from the public. This is also an area where AI firms can help with greater transparency in terms of what they're doing. So, there is a potential for a public opinion fire to break out, but it can be managed.

Jennifer Freedman: But I'm thinking that there's a lot of public distrust of government, and there's a lot of concern about the honesty of companies producing this technology and involved in this. So how can the public have some assurances? I mean, how can the public learn more and assure itself that what they're learning is the truth, whatever that is?

Miguel Gomez: That is a fair question. A colleague of mine actually raised this point, and the issue here comes with the tendency of ethics washing from the government and AI companies when it comes to these things. And the solution that he suggested here is that, well, we just need to bring in the public as well when it comes to debates surrounding the regulation of AI. So managing AI, governing AI, cannot just happen behind closed doors with the tech companies and with the government talking among themselves. This goes back to my earlier point that we need to bring in more stakeholders, and this is actually why I said civil society organizations also need to play an important role, and they do have a stake in this. 

The ICRC [International Committee of the Red Cross], for instance, has a very prominent voice when it comes to the discussion on AI ethics, especially in the context of autonomous weapons systems.

So yes, governments need to talk to the AI companies, and they do need to get involved, but the list does not end there. We need to bring in people or organizations outside the government, apart from those who also build technology. The users of the technology must also be brought into the discussion.

Jennifer Freedman: I mean, you've mentioned numerous times about the need for it to be a team effort. I understand that. I'm wondering, that aside, if you had to give one warning and one hope about AI governance today, what would they be?

Miguel Gomez: One warning is that we essentially still don't know the full capabilities of the technology. The technology is still maturing. And because it is still maturing, we need to take a very objective approach when it comes to deciding how to govern it. 

Governing or instituting certain regulations too early can stifle development. Relaxing regulations too much can lead to things developing faster and us losing control of things. It's this need to balance the interest [in] and need to govern versus giving the technology enough space to develop. So that would mean accepting some risk as [the] technology progresses. The challenge here will be figuring out how much of that risk we are willing to tolerate.

Now, in terms of hope, it may seem counterintuitive, but the fact that a lot of these reports are coming out about AI LLMs misbehaving is, to some extent, I believe, a good thing because it starts the discussion. It draws attention to the issue that hopefully will allow us to move in the right direction. 

I've spoken to individuals, I've had conversations with colleagues about what it will take for AI regulation to take a significant step forward. I mean, the pessimistic side of me [says] we probably need a Pearl Harbor moment for people to wake up. That is a very pessimistic side of me, and I do not hope that happens, but I think the fact that the smaller, more controlled incidents are being disclosed is generating enough interest so that we don't have to wait for that Pearl Harbor moment for the responsible organizations and individuals to take the necessary steps to approach this in a more critical light. I'm seriously hoping we don't have a Pearl Harbor moment with AI.

Jennifer Freedman: It's a very fine line, yes.

Miguel Gomez: It's a very fine line. How much do we have to nudge ourselves closer to the edge until we take things seriously? I hope it doesn't take too much nudging. That is my hope there. 

The trick here is that we don't fall into a level of complacency where we are just okay with the risk. I think stagnation is also a problem here. Our assessments cannot just end with patching the issues that these incidents have surfaced. There needs to be a bit more forward thinking to be done, but forward thinking within the bounds of reason. And again, because the technology is still evolving, we cannot be 100% certain where it's going to go, but at least we are thinking about it and moving alongside in parallel with the development.

Jennifer Freedman: Any final thoughts before we wrap up?

Miguel Gomez: I think these governance issues, given what's been happening recently, will be on everyone's radar at least for the next couple of months, if not years. 

What's interesting, though, and what I am quite interested in seeing as this develops, is how the narrative and governance evolve outside the typical North American and European context. 

Because it's not just those two regions that are interested in AI. The Indo-Pacific has a lot of actors, a lot of countries that are very much interested and invested in AI. And I think, given how things are progressing in terms of shifts in geopolitics, it will be quite relevant to see where these countries — Japan, South Korea, Singapore, et cetera — will end up when it comes to this debate following these incidents.

Jennifer Freedman: Great. Thank you very much, Miguel. You've helped me especially, but I think everybody listening with a better grasp of how lessons from the Crypto Wars can illuminate today's debates over AI. Your insights show why getting AI governance right and doing it collaboratively obviously is going to matter more than ever. 

Thank you as well to everyone who joined us today. Miguel's paper is available on the Hinrich Foundation website. If you're interested in digging further into the debate, I really recommend that you give it a read. It's very interesting. 

Once again, this educational program is produced in partnership with the Hinrich Foundation, and the Association of Foreign Press Correspondents in the USA is solely responsible for the content of this podcast episode.