How Export Controls Can—and Cannot—Reduce the Risks of Open-Weight Models
On June 12, the Commerce Department issued an export control directive informing Anthropic that a license was required for the export of its Claude Mythos 5 and Fable 5 models to any foreign person, whether inside or outside the United States. Unable to verify each user’s nationality in real time, Anthropic abruptly disabled the models worldwide for all its customers. The legal basis for treating access to a hosted model as an export is questionable, but the source of the government’s leverage was clear: Anthropic continued to control user access to its models and could cut off that access if directed to do so.
Open-weight models present a more difficult problem for export controls. Users can download model weights and run the model on their own hardware. So once the weights are published and copied, the original developer loses effective control over the model, and no export control directive can recall the copies. In addition, many leading open-weight developers are based in China, where the U.S. government has little practical ability to prevent publication. But that does not mean the government lacks any points of leverage in the open-weight ecosystem. Nor does it mean the government should use its leverage wherever it can be found.
Drawing on the Law Reform Institute’s recently published white paper, this article maps the relevant boundaries of export controls and related authorities for open-weight artificial intelligence (AI) and identifies where existing authorities can materially reduce risk and where they should not be stretched. It concludes that broad restrictions on the publication, download, or local use of general-purpose weights would face substantial legal and practical obstacles. Nonetheless, the government retains points of leverage both upstream and downstream of publication, particularly over the supply of computing power used to develop models and the services that help users run or customize them.
How Publication Changes the Regulatory Problem
AI model weights are numerical parameters that are adjusted during training. When combined with the software used to run the model, they help determine how the model converts a user’s inputs into outputs. A developer of a closed-weight model keeps the weights private and gives users access to the finished model through a website or application programming interface (API). In contrast, an open-weight developer makes the weights available for download and allows users to run the model locally, customize it, and build new systems on top of it.
The defining feature of open-weight models is the transfer of control from the developer to the user. This can provide significant benefits to users: It lowers their costs in developing specialized systems, enables them to perform independent research and testing, and allows them to run models without sending sensitive data to the original developer. But there are drawbacks too. The transfer means that the developer loses the ability to reliably monitor downstream use of the model, force updates to safeguards, or disable the model if necessary. Downstream users can modify the model however they wish (subject to any licensing terms), and even ordinary fine-tuning for legitimate purposes can weaken safeguards—or worse, they can be removed deliberately.
Publication also changes how export controls apply to the release of model weights. The Export Administration Regulations, or EAR, generally regulate the export of dual-use commodities, software, and technology. But the regulations carve out technology and software that are “published”—meaning, material that is made publicly available, including through posting online, without restrictions on its further dissemination. General-purpose model weights released under permissive licensing terms will typically fall within this exclusion. In contrast, unpublished U.S.-origin weights generally remain subject to the Commerce Department’s export control jurisdiction.
Chinese developers present a broader jurisdictional and practical problem for export controls. The United States may restrict U.S. companies that transact with such developers or provide upstream or downstream services to them, but it generally cannot prevent a Chinese developer acting abroad from publishing its weights. Attempting to expand U.S. jurisdiction over the publication of foreign model weights would not, by itself, resolve the practical enforcement difficulties. Proposals to “ban” Chinese models are in most cases not actual bans on publication abroad but instead are proposed restrictions on Americans who transact with Chinese model developers or who host, distribute, integrate, or use their models. For example, if the United States prohibited integrating Chinese models into U.S. software, a U.S. business that had built an application around one of those models might need to switch to a non-Chinese alternative, but the Chinese developer could continue publishing its weights abroad. Such policies may be justified, but this should not obscure the fact that the U.S. government generally lacks effective control over the publication of Chinese models abroad—a topic further explored below.
Applying the Marginal-Risk Framework to the Release of Open-Weight Models
The legal reach of export controls should be distinguished from whether and how the government should use these authorities. Export controls are generally discretionary tools for the government and should be crafted, licensed, and enforced in a manner that advances U.S. national security. The policy question in the open-weight context should be guided by the marginal-risk framework adopted by the National Telecommunications and Information Administration in its 2024 report on widely available model weights.
Applying that framework requires the government to determine what a particular control would deny an adversary if implemented. A control provides a reduction in marginal risk if it prevents the transfer of a capability or the provision of access the adversary could not readily obtain from realistic alternatives. If suitable alternatives exist, the control imposes a burden without denying anything to the adversary. The framework also asks whether the risk reduction is worth the price. In other words, do the lost benefits and the burdens imposed outweigh the security gained?
The distinction between absolute and marginal risk is important. Absolute risk measures how dangerous an open-weight model may be as a result of its overall capabilities and how it can be modified, stripped of safeguards, and used without monitoring. Marginal risk considers those same factors but is focused on how much a particular release or transaction would enhance an adversary’s capabilities in threat-relevant domains, relative to what it could obtain from alternatives. Suppose a U.S. developer prepares to release an open-weight model whose cyber capabilities or chemical, biological, radiological, and nuclear expertise are equivalent to those of a freely available Chinese open model. In that case, any government action to block the release would simply impose costs on the U.S. developer and drive users toward the Chinese alternative and would not deny adversaries any threat-relevant capabilities.
A marginal-risk assessment therefore depends on the ability to conduct evaluations of both the U.S. open model and the foreign substitutes for relevant capabilities. General benchmark scores can provide an understanding of the overall capabilities of a model, but they are less useful in assessing marginal risk. The two models may be comparable in ordinary reasoning tasks but very different in helping a user build a biological weapon or exploit software vulnerabilities. Understanding these gaps requires evaluations of threat-relevant capabilities—the kind that the U.S. Center for AI Standards and Innovation and the U.K. AI Security Institute have begun to publish for Chinese models.
The framework also requires policymakers to weigh the benefits from open-weight AI models that may be lost as a result of any control. For example, a biosecurity firm or a university lab can build on an advanced open model for a fraction of what it costs to train an AI model from scratch. A hospital system or defense contractor can run a highly capable model on its own servers, so patient records or sensitive data are not shared with the developer. And openness can help advance security interests in certain contexts, such as where cyber defenders and safety researchers study and counter the threats that frontier models can create. A control that restricts release of open models may undermine any or all of these beneficial activities.
Open-weight AI also has a geopolitical dimension. Competitive American open models help ensure that the world will not simply default to Chinese models when an open model is needed for a particular organization or project. A thriving American open-weight ecosystem will allow the U.S. government and its companies to help shape the technical and safety standards that develop around open-weight AI. And American open-weight models can offer a trustworthy foundation for users, reflecting democratic values free of foreign government censorship and posing a reduced risk of backdoors inserted by a strategic adversary. Forgoing these benefits is a cost of any restriction on U.S. open models and belongs in the marginal-risk calculus.
Where Existing Authorities Earn Their Keep
Under the marginal-risk framework, a strong case can be made for using export controls both downstream and upstream of publication.
Downstream, a deployed model will generate outputs for users, and the disclosure of those outputs is an event distinct from the release of the weights themselves and should be analyzed separately for export control purposes. Many outputs simply restate information that is already public and will generally be excluded under the regulations. But a capable model can also synthesize novel information and generate emergent knowledge that may qualify as controlled information in its own right. Controlled outputs could range from functional exploit code to a synthesis route for a controlled toxin, and their sensitivity level will vary—some may pose unique security concerns and others may be information available from other sources, including other AI models.
That is why not every disclosure of controlled information should be treated as an enforcement priority. There would be little gained by way of reduction in marginal risk and significant burdens imposed on both the regulator and the regulated parties if every violation were enforced. The Commerce Department would be better served by focusing on ensuring developers and downstream actors implement appropriate safeguards to prevent the unauthorized disclosure of truly sensitive outputs in threat-relevant areas—and focusing on the actors that can actually control the release.
Effective leverage may also exist in other downstream services following publication of open weights. First, fine-tuning can enhance a model’s capabilities in a sensitive domain and remove or weaken its safeguards. A service provider could use anti-refusal training to make the model answer requests it would otherwise refuse, or go further and add capability through domain-specific capability training, which trains the model on specialized data and tasks to improve its performance in areas such as biology or cybersecurity.
Second, hosted inference can provide reliable access to an actor that lacks the hardware or expertise to run the model locally. And third, integration with proprietary data or infrastructure can convert a general-purpose model into a more operationally useful system—as when a Chinese autonomous-driving company, Landship, integrated DeepSeek into a self-driving military vehicle marketed by the state-owned defense company Norinco. In each case, it is the service—not merely possession or transfer of the weights—that may supply the marginal capability.
Existing U.S.-person controls restrict certain services that support weapons of mass destruction (WMD) or military-intelligence activities. Such controls can reach activities relating to any open-weight model, whether American or Chinese, and apply to U.S. persons whether they act in the United States or abroad. In a 2025 policy statement, the Commerce Department indicated that U.S. persons providing support with knowledge that the assistance will be used to train AI models on behalf of Chinese parties may need a license when there is a nexus to a WMD or military-intelligence end use. Sometimes, however, that nexus is difficult to identify—because, for example, China’s military-civil fusion policies obscure the nature of the transaction. In those cases, the Commerce Department may issue a categorical rule, as it has done for advanced semiconductors in a 2022 rule, defining categories of U.S.-person support that require a license. The Commerce Department should build on those precedents by applying the same logic to downstream activities involving open-weight models—fine-tuning, hosting, and integration—where such services are likely to materially assist a WMD or military-intelligence end use.
An authority adjacent to export controls that should also be used to address a related downstream risk is the Commerce Department’s Information and Communications Technology and Services (ICTS) program, which was created under the International Emergency Economic Powers Act (IEEPA). The program’s purpose is to protect the American ICTS supply chain from threats posed by foreign adversaries, such as China. It therefore asks a different question from the marginal-risk framework. Rather than asking what a restriction would deny an adversary, the question is what risks a product from such a foreign adversary poses once inside U.S. systems. ICTS authorities can be used to prohibit or mitigate U.S.-nexus transactions involving foreign adversary technology, including AI, that pose an undue or unacceptable risk. Such transactions can include the acquisition, importation, transfer, installation, dealing in, or use of ICTS, including the platforming or data hosting of applications for consumer download. The authority allows for restricting specific transactions, as the Commerce Department did with Kaspersky Lab, or classes of transactions, as the department did previously with connected vehicles linked to China or Russia.
Although the ICTS program may be textually broad enough to reach U.S. individuals downloading or locally using Chinese-origin weights, its prior applications have targeted commercial actors rather than individual users and have focused on ongoing supplier relationships—cases where the foreign developer retains access to the product, pushes updates, and can reach into American systems through it. Maintaining these distinctions keeps the program aligned with its focus on risks arising from a foreign-adversary supplier’s continuing access to and influence over U.S. systems. It also helps reduce the type of First Amendment and related issues that are described below, along with the practical difficulty of enforcing such authorities against individual users.
Consistent with that practice, the Commerce Department could use the authority to restrict a U.S. platform hosting or distributing a Chinese open model in appropriate cases. To reach transactions involving stand-alone weights that are no longer under the developer’s control, the Commerce Department would need to determine that those transactions pose an undue or unacceptable risk because of characteristics inherent in the weights. Weak safeguards or susceptibility to attack could support such a finding for transactions involving a particular model if the severity and likelihood of harm were sufficiently high. Repeated findings across a developer’s models might support broader restrictions involving that developer, but it would be more difficult to justify a conclusion that applies across Chinese open-weight developers as a class.
A deliberately embedded “sleeper agent” or “backdoor” in a model with significant cyber or agentic capabilities would present a stronger basis for finding an undue or unacceptable risk because the risk would reside in the weights themselves even without an ongoing connection to the developer. Evidence of a sleeper agent or backdoor in one model could support restrictions on transactions involving that model or perhaps developer-wide restrictions. A broader prohibition covering transactions across multiple developers would require evidence of a systemic risk common to the defined class—for example, a widespread or state-directed practice among developers in that class. However, no public evidence has established a deliberately embedded sleeper agent or backdoor in a Chinese open model, so that scenario remains theoretical.
Export controls can also be effective upstream of publication. Frontier-scale compute depends on advanced chips, while producing those chips at scale depends on advanced semiconductor manufacturing equipment (SME). The United States and its allies retain substantial leverage over the supply of the most advanced chips and SME, which is what makes them chokepoints. Compute presents a strong case for denial under the marginal-risk framework because China still lacks fully substitutable domestic sources for some of these inputs at scale. Restricting hard-to-replace compute can slow China’s development of capable open models even where controls cannot stop Chinese weights from being published or circulating once published. None of this should be oversold, though. Compute controls carry costs for U.S. industry, including forgone market share in China. Remote access to cloud services remains an open gap, and loopholes persist in SME and chip controls. China has also become effective at adapting to U.S. export controls by accelerating indigenous capabilities, improving efficiency, extracting frontier capabilities from U.S. models through distillation, and employing other methods.
Where Existing Authorities Should Not Be Stretched
The most difficult questions arise with the publication of model weights and their download and use once published. Existing authorities do not provide a clean basis for broad prohibitions in these areas.
The EAR’s “published” exclusion serves an important purpose in keeping the EAR from operating as a general prepublication licensing regime for information and thus in avoiding potential conflicts with the First Amendment. However, this rule is regulatory in nature, and if desired, it could be narrowed by regulation. The current rules already do this in different ways for machine-ready 3D-printable firearm files and certain encryption software. But both carve-backs have a long and thorny litigation history, and neither is a reliable road map for an open-weight carve-back. Unlike the exclusion itself, the First Amendment cannot be narrowed by rulemaking, and a carve-back for model weights may invite the same kind of legal challenge.
The First Amendment analysis of a prepublication licensing requirement imposed on model weights—in effect, a prior restraint—would begin by asking whether the weights are protected expression, or, even if not, whether the restriction disproportionately burdens other protected activities. Courts have protected computer code that communicates ideas, while leaving purely functional code outside the First Amendment’s coverage. In Defense Distributed v. Attorney General of New Jersey, which involved 3D-printable firearm files, the U.S. Court of Appeals for the Third Circuit emphasized that the inquiry is fact-specific, turning on how the files are used and what, if anything, they communicate.
Weights are generally unintelligible through direct review and used primarily for their function, which cuts against their protection. But they also reflect the developers’ creative choices, and some developers use written “constitutions” to shape what a model will say or refuse. AI-generated outputs may also be protected through the rights of model users, supporting a claim that restricting the weights would indirectly burden users’ access to protected information. No court has yet decided where model weights fall—and even if the weights themselves are not protected expression, a licensing requirement could still burden the protected activities of the developers who publish them and the users who rely on them.
Separate from the First Amendment, a prepublication licensing requirement for weights could encounter the Berman Amendment. This statutory provision generally withholds IEEPA authority to regulate, directly or indirectly, the import or export of “information or informational materials,” regardless of format or medium. Because ICTS was created under IEEPA, Berman applies to that program. The EAR, through its statutory authority, the Export Control Reform Act, carries the same limitation for item-based controls (though some have questioned this). Whether model weights qualify as “information or informational materials” is unresolved. The Justice Department, in its bulk sensitive data regulations, defined the term to cover only expressive materials and stated that it does not include data that is technical, functional, or otherwise nonexpressive. On that interpretation, the Berman question turns largely on the same unsettled line between expression and function as the First Amendment analysis above—though it remains legally distinct.
A direct ban on downloading stand-alone weights, or on locally using them after download, would present many of the same legal questions. Such measures would operate directly on Americans’ possession and use of the files, which could therefore raise First Amendment questions—and potentially Berman Amendment issues as well, if the measure directly or indirectly regulated their import or export. The downstream controls discussed earlier carry less of a risk. They generally regulate services that add capability, not the direct exchange of information. But even a service restriction may trigger these constitutional or statutory limitations, as demonstrated by litigation over the first Trump administration’s 2020 attempt to use IEEPA to prohibit distribution, hosting, and certain other services supporting TikTok. Two courts preliminarily enjoined those restrictions on Berman Amendment grounds, finding they would have indirectly prevented the exchange of protected informational materials.
Even apart from these legal questions, the U.S. government should not impose broad restrictions on the download, possession, or local use of general-purpose model weights, whether through the ICTS authorities or otherwise. Policing dispersed users would be difficult, and such measures would burden legitimate uses and deployments of the weights.
Nor does the marginal-risk framework, on the current record, support broad restraints on the publication of U.S.-origin general-purpose weights. Highly capable foreign models already provide comparable capabilities in evaluated threat-relevant domains, and such measures would therefore burden U.S. developers and users without materially denying adversaries the relevant capabilities.
That conclusion is contingent, and the record could change. If future developments create a concrete case in which a tailored restraint would materially reduce a serious national security risk, existing EAR authorities may support a targeted response, depending on the conduct and the risk. But a broad or durable restriction on publication—or one that would depend on a novel reading of those authorities—should rest on purpose-built legislation. The TikTok experience provides a useful institutional analogy. After courts preliminarily enjoined the IEEPA-based restrictions just described, Congress enacted a dedicated statute, and the Supreme Court upheld it as applied to TikTok on narrow grounds tied to foreign control and data security. A model-weight statute would present different legal and policy questions, but the sequence illustrates the value of congressional action when existing authority is an uncertain fit.
A Limited but Important Role
The Anthropic directive worked, whatever its legal merits, because the government found a reachable developer still in control of its model. Open-weight AI offers no comparable control point: The weights become irretrievable at publication, and many of the leading open-weight developers are in China and generally beyond the practical reach of U.S. enforcement. That does not leave the government powerless, but it requires understanding where its leverage actually lies.
Export controls and the related ICTS program can play an important role in addressing the risks from open-weight models, particularly when directed at activities downstream and upstream of a weight’s release. Downstream, export controls can reach disclosures of high-consequence outputs and the services that materially assist WMD or military-intelligence activities, while the ICTS program can restrict foreign-adversary models in U.S. systems when they pose a demonstrated risk. Upstream, compute controls can slow Chinese labs’ development of still more capable models. The marginal-risk framework should guide the policy determination of when to use export controls by asking what a restriction would actually deny an adversary and what it would cost the United States to implement that restriction.
But there are limits to the utility and reach of these authorities. The marginal-risk framework does not, at present, support broad controls on the publication of U.S.-origin general-purpose weights, and broad restrictions on downloading or locally using general-purpose weights would be difficult to enforce and would burden legitimate deployments. Moreover, export controls are not a general regime for governing open-weight models, and managing risks arising from such models will necessarily require other domestic tools, such as risk-management standards, incident reporting, and liability regimes. Export controls are also bounded by jurisdictional and practical limits when models are developed and deployed entirely abroad without a relevant U.S. nexus. As open models become increasingly capable, addressing remaining risk will therefore require sustained international cooperation, particularly with China.
Open-weight models are likely to remain widely available regardless of U.S. policy. They are also likely to present an enduring governance challenge given the complex factors described in this article. The U.S. government would therefore be wise to anticipate how open-weight AI is likely to develop over the coming years and understand what its existing tools can and cannot do before the next perceived crisis forces it to improvise again.
