On June 28, 2026, Anthropic tightened Claude access for users in China. Three days later, Anthropic said Commerce lifted export controls on Claude Fable 5 and Mythos 5. Claude was becoming harder and easier to reach at the same time.
A category rule assumed a stable object
In October 2023, the U.S. Department of Commerce reportedly considered export controls on general-purpose AI programs. The design assumption was familiar: identify a class of strategically important technology, decide where it may travel, and regulate the crossing. The rule attaches to the object because the object is presumed to be the stable part of the system.
That logic works cleanly when access resembles a shipment. It breaks down when the controlled capability is reached through accounts, API tokens, cloud infrastructure, and repeated requests. The relevant crossing no longer happens once. It happens every time credentials are issued, resold, disguised, or used to probe a model.
- October 2023: Commerce reportedly considers controls on general-purpose AI programs, defining the problem at the category level.
- April through June 2026: Anthropic later alleges that Alibaba accessed Claude 28.8 million times through roughly 25,000 accounts and used adversarial distillation.
- June 28, 2026: Anthropic tightens Claude access for users in China while transfer sites, foreign-purchased API tokens, proxy services, fake identities, Telegram, and VPNs support circumvention.
- July 1, 2026: According to Anthropic, Commerce lifts export controls on Claude Fable 5 and Mythos 5 as a U.S. letter says the lab agreed to proactively detect and address the models’ security risks.
Each phase exposes the limit of the previous approach. Broad controls identify the capability. Account restrictions identify the user. Evasion forces attention toward behavior. Behavioral enforcement requires telemetry that the regulator does not operate and the model provider does.
Access made the border continuous
The allegations involving Alibaba show why model access stopped being a simple availability question. Anthropic said Alibaba reached Claude 28.8 million times from April through June using about 25,000 accounts. Whatever the allegation’s merits, at that scale the policy problem is not merely whether access is allowed. It is whether dispersed activity can be linked, classified, and interrupted while it is happening.
Anthropic’s China restrictions expose the same shift from another direction. The lab tightened access on June 28, yet sites were buying API tokens abroad and distributing them to Chinese users, while users relied on proxies, VPNs, and fake identities obtained through Telegram. The restriction remained active; the boundary generated an underground access layer around itself.
This is a reinforcing loop, not an enforcement anomaly. Restrictions increase the value of concealed access. Concealed access increases the need for monitoring. More monitoring increases the value of credentials and routes that avoid monitored signals. A border drawn around software becomes an operating system for identity checks, account analysis, incident response, and adaptation.
Reopening arrived with a private control room
Commerce’s decision on Claude Fable 5 and Mythos 5 is narrower than a general relaxation of AI export controls. It concerns two named models, and Anthropic says Commerce lifted the controls. At the same time, a U.S. letter says Anthropic agreed to proactively detect and address their security risks. Permission and enforcement are no longer situated on opposite sides of the decision; permission now carries an expectation of continuing detection.
Anthropic is also developing a standard for rating jailbreak severity with major cloud and model companies, including Amazon, Microsoft, and Google. That work is not yet an established universal standard, and one model-specific decision does not create a complete legal regime. It does reveal the emerging control surface: the lab supplies the monitoring, the cloud and model companies help define how hostile behavior is measured, and market access can reopen without restoring the old assumption of passive distribution.
Export controls were designed so that the state could decide whether a capability crossed a boundary. Under this arrangement, the state still determines access, but the supplier increasingly provides the instruments needed to make access conditional in practice. The company selling the model is also expected to detect the security event, judge its severity, and address it.
The delegated gate has no neutral setting
Lab-run enforcement does not resolve the access problem; it relocates its tradeoffs. Anthropic rolled back a covert Claude Code feature intended to identify China-based users or people affiliated with Chinese AI labs after backlash. The rollback showed that the provider’s technical visibility can exceed the legitimacy of a particular enforcement method.
Once a measurable severity score becomes part of the control system, defenders optimize for what it captures and attackers search for what it misses. The monitored proxy becomes the target, and the original failure returns through the unmonitored route. Transfer sites, disguised identities, and foreign-bought tokens already show what those routes look like.
Nor does lifting controls on two models mean access restrictions are receding. Anthropic tightened Claude access for Chinese users three days earlier. These actions coexist because they occur at different layers. Commerce can reopen export access to specific models while the lab narrows access for specific users, then monitors for attempts to cross the distinction. The regime is becoming more conditional precisely because it is becoming less binary.
The product now contains the border
A model service receives requests and returns outputs. By 2026, that no longer described the whole system. Claude now sits inside a service expected to decide who may connect, recognize disguised access, rate jailbreaks, identify security risks, and respond when use crosses a policy boundary. A service that continuously performs access control has become part of the control regime.
Commerce did not abandon export policy; the regulated object became a stream of interactions rather than a shipment, and the information needed to police it accumulated inside the companies operating it. Reopening access without operational monitoring would recreate the instability exposed by alleged distillation and proxy markets.
The three days between Anthropic’s China restrictions and Commerce’s model-specific decision were not a reversal. They exposed a division of labor: Washington reopened two named models while Anthropic narrowed access for some users and accepted responsibility for monitoring risk inside the service. The border did not leave with the crate; it reappeared in the API log, staffed by the company selling the key.