The US vs. AI: Discussing the Echoes of the Crypto Wars in AI Governance

The Association of Foreign Press Correspondents in the United States recently hosted a podcast in partnership with the Hinrich Foundation titled, “The US vs. AI: Discussing the echoes of the Crypto Wars in AI governance.”
Miguel Gomez is a Senior Research Fellow with the Centre on Asia and Globalisation. Previously, he worked as a Senior Researcher with the Center for Security Studies (CSS) at the Swiss Federal Institute of Technology (ETH) in Zurich. His area of research is found at the intersection of technology, foreign policy, and political psychology. Specifically, he is interested in how novel technologies shape policy, strategy, and public opinion for elites and the public at large. His recently published Hinrich Foundation research compares the current US-Anthropic dispute over AI governance with the Crypto Wars of the 1990s, warning that heavy-handed measures could undermine American innovation, competitiveness, and long-term security.
Gomez discussed his research with journalist Jennifer Freedman, who for more than two decades has contributed reporting on trade and global markets for different outlets.
This podcast episode was produced in partnership with the Hinrich Foundation. AFPC-USA is solely responsible for the content of this episode. The podcast transcript is available HERE.
Freedman asked Gomez about a pivotal development in the US debate over AI governance: the Commerce Department’s June 12 decision to restrict foreign access to Anthropic’s Mythos 5 and Fable 5 models. Gomez argued that the move was significant because it appeared to conflict with the Trump administration’s broader “hands-off” approach to regulating frontier AI, which was intended to encourage innovation. Gomez noted that Anthropic had, to his knowledge, taken meaningful steps to mitigate the potential misuse of its models before releasing them. He pointed specifically to Project Glasswing, associated with the more powerful Mythos version of the technology, which was designed to identify and address potential vulnerabilities before the models were broadly released. Against that backdrop, Gomez described the Commerce Department’s response as a “very heavy-handed, all-encompassing approach” that could send troubling signals to AI developers about what future government regulation might look like.
For Gomez, the issue is therefore larger than Anthropic itself. The episode raises questions about whether companies can reasonably manage the risks associated with frontier AI while still being subject to sweeping government restrictions. Even when an organization attempts to “play it safe,” he argued, aggressive government intervention can create uncertainty about the regulatory environment and potentially discourage innovation. Gomez said he looked back at the Crypto Wars of the 1990s for lessons about AI governance because he has long believed there is “no need to reinvent the wheel” when dealing with emerging technologies. Gomez said his background in cybersecurity reinforced that view; when he revisited debates about cyber technology from the late 1990s and early 2000s, he found striking similarities to contemporary arguments about AI.
Gomez said the Crypto Wars offered a particularly useful historical comparison because cryptography and advanced AI are dual-use technologies that can provide enormous civilian benefits while also presenting potential security risks. He observed that these technologies are being framed through a weapons narrative, and in both cases, the US government attempted to impose significant restrictions on their development or international use. He acknowledged that this analogy is not a perfect comparison but said the underlying characteristics of the technologies and the policy dilemmas surrounding them are sufficiently similar to make the Crypto Wars instructive. It is important to help policymakers identify what to do and what not to do when regulating AI, he recommended, particularly when restrictions intended to address security concerns could ultimately affect technological innovation and US competitiveness.
Miguel Gomez
Gomez went on to explain that governments increasingly view AI as a "strategic enabler,” a term that describes a technology that can help advance national interests. Naturally, there is an incentive for governments to seek greater control over powerful AI systems, but AI’s dual-use nature means that the same abilities that benefit governments and defenders can also be exploited by adversaries. Returning to the Crypto Wars, he explained that cryptography enabled participation in the emerging internet economy by making digital transactions more secure, but governments were also worried that criminals and hostile actors could use encryption to conceal their activities from law enforcement. AI presents a similar problem in that the government can use it to improve efficiency and decision-making, while malicious actors can exploit the same technology. Gomez said models like Mythos can identify software vulnerabilities and potentially accelerate malicious cyber activity that might otherwise take a human hacker “days, weeks, or even months” to accomplish. That creates a paradox: defenders can use AI to detect and respond to threats more quickly, but attackers can use the technology to move faster as well.
Gomez pointed to reports of AI being deliberately incorporated into cyber espionage operations, including what he described as a report from OpenAI identifying the first known Chinese cyber espionage operation that relied heavily on AI. He cautioned against overinterpreting such examples, but said that they demonstrate why governments are concerned about the technology’s dual-use character. Regarding the US-Anthropic relationship, Gomez said there are also specific sources of friction between the company and the government, including earlier disputes over Anthropic’s position on using its models for targeting and the potential surveillance of US citizens. The result is a relationship in which the government sees frontier AI as strategically valuable while simultaneously worrying about the risks created by giving those systems greater capabilities.
In response to Freedman's question about how governments should handle models capable of discovering software vulnerabilities, Gomez rejected the idea of simply "locking it away.” He reasoned that the Crypto Wars demonstrated how restricting access in one country does not prevent adversaries from developing or obtaining comparable technology elsewhere. Gomez pointed out that overly restrictive US policies could have the unintended consequence of pushing users toward foreign models developed with less caution and fewer safeguards. Instead of eliminating the risk, governments could incentivize a turn toward more dangerous alternatives. Greater engagement among governments, AI companies, the private sector, and civil society to develop appropriate safeguards is necessary. Gomez cited Anthropic’s pre-release work on Project Glasswing as an example. Months before Mythos 5 and Fable 5 were released, Anthropic reportedly gave outside partners access to the technology so they could identify vulnerabilities and help address them before the models reached the broader public. Those efforts were complemented by guardrails built into the models themselves.
Freedman turned to several recent incidents involving autonomous AI agents that reportedly escaped their test environments and carried out unauthorized cyber activity. She asked whether such episodes strengthen the case for tighter controls on frontier AI or risk repeating the kinds of government overreaction seen during the Crypto Wars, to which Gomez responded that the incidents offer evidence of why governments need to engage more closely with the people actually developing and testing these systems. Gomez advised against using descriptions that suggest that the models simply "went completely rogue” and acted without any human involvement. He said there has been at least one recent case in which researchers deliberately gave AI access to the internet because they wanted to test its capabilities under conditions resembling a real cybersecurity environment. The problem with other incidents was that they were partly related to insufficiently precise instructions. Gomez said researchers created scenarios that were intended to be fictional, but the models were given enough latitude to interpret those instructions in unexpected ways. In one example, an AI encountered a real-world entity that happened to have the same name as a supposedly fictional one. He said that although the system continued to treat the entity as fictional, it nevertheless proceeded with the actions that it had been instructed to pursue.
It would be too broad a descriptor to say that AI systems are “breaking out of the sandbox.” Gomez said that, instead, they expose weaknesses in how AI systems are tested and demonstrate the need for better controls, standards, and testing protocols. He believed the answer was not simply to declare that nobody should have access to powerful models. In fact, he said that restricting access may reduce the number of people who can use the technology, but it doesn't solve the underlying challenge of models becoming more capable and their behavior becoming increasingly difficult for engineers to anticipate. This unpredictability becomes even more important when considering LLM jailbreaks, Gomez said, noting that these are not fundamentally new problems. Cybersecurity practitioners already understand that “perfect cybersecurity or complete security is a myth.” The realistic objective is therefore not to eliminate every possible failure but to introduce enough mitigation measures to reduce the risk to an acceptable level.
Gomez said that policymakers need to accept that they cannot always predict how an advanced AI model will approach a task. Models become unexpectedly creative in finding solutions when they encounter difficult or constrained situations, and that makes absolute guarantees through guardrails unrealistic. Gomez advocated for clearer instructions for AI systems, tighter testing environments, more carefully defined parameters, and stronger standards for how experiments are conducted. He believed the goal should be to better anticipate potential behaviors and limit the consequences when models behave unexpectedly. He stressed that AI governance cannot be designed by governments alone, and policymakers need input from engineers, researchers, cybersecurity professionals, and other relevant stakeholders who can identify risks that may not be apparent from a purely regulatory perspective.
When Freedman pointed to the way encryption export controls ultimately damaged US competitiveness and asked whether AI restrictions could produce a similar outcome, Gomez said that the risk is real, particularly if the US becomes increasingly restrictive about access to its most advanced models. He noted that users who cannot access US models have alternatives, including open-weight models developed by Chinese laboratories and other competitors. While those models provide an alternative route to AI capabilities, Gomez said that there is an important distinction in that open-weight systems can be modified more easily, potentially allowing users to remove or weaken existing safeguards. Although US companies have faced criticism for developing relatively closed models, that approach at least provides what Gomez said is "some level of assurance that certain guardrails are in place.” He added that users could be pushed toward systems with fewer protections in the event that US models are restricted without addressing the underlying demand for advanced AI. Simply “closing it off” is therefore an inadequate and potentially counterproductive strategy. Restrictions may address one aspect of the security problem, but they do so in what he called a “ham-fisted” manner. Instead, policymakers need governance mechanisms that allow the risks associated with increasingly capable AI systems to be actively managed.
When asked how the US should approach international AI competition if restricting American models cannot prevent adversaries from developing their own, Gomez said that the US should accept that “complete dominance is not possible.” The US does not exclusively control the fundamental resources that underpin AI, including computing power and data, which means that China and other countries will continue to have access to many of the same underlying technologies and resources. Gomez said that the US needs to establish a value proposition that attracts users to American technology rather than attempting to prevent competitors from developing AI. He saw one potential advantage in the emphasis US companies place on safety and responsible development. Companies such as OpenAI and Anthropic, he argued, are already building guardrails into their systems and recognize that responsible development is connected to their long-term economic interests.
Freedman also mentioned Anthropic's Project Glasswing, which was designed to identify and patch vulnerabilities before malicious actors could exploit them, and asked whether this represents the kind of public-private cooperation the US needs more of. Gomez agreed that it was “one of them,” but argued that voluntary cooperation and market forces alone would not be sufficient. He specifically pushed back against the original idea of allowing AI companies to develop increasingly powerful systems “completely unhindered.” For the most capable frontier models, he believed some form of mandatory oversight would ultimately be necessary. Gomez acknowledged the much harder question of who should actually conduct that oversight. He said that the government would necessarily have a role, but it should not be the sole authority because governments do not possess a monopoly on expertise in rapidly evolving technologies, particularly in AI. Oversight would need to bring together government, the private sector, academia, and relevant civil society organizations. The challenge is figuring out how to put those stakeholders “in the same room” and determine who ultimately drives the process.
Gomez identified a multi-stakeholder approach as the most urgent governance principle, arguing that policymakers need to recognize that managing powerful, dual-use AI systems is a “team effort.” Because governments do not possess a monopoly over AI technology, he said they cannot simply impose unilateral controls and expect to manage the risks effectively. He contrasted AI with nuclear technology, cautioning against treating the two as equivalent. He noted that historically, governments maintained much greater control over nuclear technology, allowing them to regulate it largely on their own terms. However, AI is fundamentally different because its development and use involve private companies, researchers, academics, civil society, and ordinary users.
On the role of political psychology and the media in shaping perceptions of AI risk, Gomez said that public anxiety surrounding AI resembles earlier fears about cybersecurity. Because most people do not understand the technical nuances of AI, they often rely on familiar cultural references to make sense of it. Media coverage can reinforce this tendency by “catastrophizing” AI failures, with headlines and imagery invoking The Terminator, Skynet, or asking whether a particular incident is a “Skynet moment.” Gomez wanted to be clear that this doesn't mean that AI risks are imaginary. There exist legitimate dangers, but the challenge is distinguishing between realistic risks and exaggerated fears. He said that much of the public’s understanding is shaped primarily by sensational coverage and Hollywood films, a combination that can result in unnecessary fear and confusion about what AI is actually capable of. He said governments have a potential role in helping to moderate these fears by providing clear information and that AI companies can also help this transition by being more transparent.
When Freedman asked what happens when the public does not trust either the government or the company developing AI, Gomez acknowledged that this is a serious challenge, particularly because of concerns about what he referred to as “ethics washing.” This term refers to the possibility that governments or technology companies may publicly emphasize ethical principles without providing sufficient evidence that those principles are actually being followed. AI governance, he stressed again, cannot happen “behind closed doors” between government and technology companies. He noted that governments and developers have an obvious stake in determining how the technology is regulated, but so do the broader communities affected by those decisions.
Gomez said that AI governance will remain a major policy issue for years, but that the current wave of reported AI failures could be useful if it prompts governments, companies, and other stakeholders to address risks before a catastrophic incident forces their hand. His central warning was that policymakers still do not fully understand the capabilities of rapidly evolving AI systems. Because of that uncertainty, he said governments need to strike a careful balance: overly restrictive rules could stifle innovation, while insufficient regulation could allow capabilities and risks to develop faster than society can manage them. In his view, some degree of risk will have to be tolerated as the technology matures, but the crucial question is determining how much risk is acceptable. Gomez saw the disclosure of recent incidents involving AI models behaving unexpectedly as potentially positive because they are forcing greater attention on the problem. He acknowledged that the pessimistic scenario would be a “Pearl Harbor moment” — a major AI-related disaster that would finally compel governments to act — but stressed that he hoped such an event would never occur. Instead, he believed the smaller incidents now coming to light could provide an opportunity to develop more thoughtful safeguards before a crisis of that magnitude happens.
At the same time, Gomez cautioned against complacency. He said that fixing vulnerabilities uncovered by individual incidents is not enough because policymakers and technology developers need to think about how AI capabilities might evolve. That forward thinking, however, should remain “within the bounds of reason,” since nobody can predict with certainty where the technology will ultimately lead. The goal should be to ensure that governance evolves alongside AI rather than constantly reacting after the fact. Not allowing AI to be governed solely by government or technology companies would do much to address public distrust and the risk of ethics washing.
Gomez also noted that the AI debate should not be confined to Western powers. An important question for the coming years, he said, will be how the governance debate develops in the Indo-Pacific, where countries such as Japan, South Korea, and Singapore are deeply interested in AI. As geopolitical competition increasingly shapes technology policy, he suggested that understanding how these countries approach AI governance and where they position themselves within the broader debate will be increasingly important.