The U.S. export-control regime can mandate restrictions, but it cannot enforce them without a verification substrate.
On June 12, 2026, Commerce Secretary Howard Lutnick directed Anthropic to suspend access to Claude Fable 5 and Claude Mythos 5 for foreign nationals, including Anthropic’s non-citizen employees. Anthropic could not verify citizenship at login because API keys identify accounts and applications, not individual users’ nationality. It therefore disabled both models worldwide.
The episode exposed the core problem: without identity-proofing infrastructure, a targeted restriction becomes a blunt service cutoff.
The Object of Control Has Migrated
AI export controls have moved through three objects of control:
| Phase | Object of Control | Verification Problem | Status |
|---|---|---|---|
| 1 | Physical chips | Where is the chip, and who owns it? | Deal-by-deal licensing; selected China-bound chips approved under conditions; Blackwell-class products blocked |
| 2 | Cloud access | Who is the customer, reseller, and end user? | IaaS KYC proposal pending; similar requirements appearing in licensing conditions |
| 3 | Model access | Who is using the model, and what is their nationality? | Legal basis unsettled and under litigation |
Physical chips can be inspected and tracked by destination. Cloud access requires customer and reseller screening. Model access requires identity verification at the moment of use, potentially including nationality.
The January 2025 AI Diffusion Rule proposed a three-tier country system, but it was rescinded before taking effect. By mid-2026, access depended increasingly on bilateral agreements and entity-level compliance frameworks. That shift made beneficial-ownership and personnel verification central.
Anthropic and the Verification Constraint
Anthropic’s response illustrates how temporary controls create permanent infrastructure.
After the June directive, the company updated its privacy policy to permit government-ID and biometric collection for identity checks. The export restrictions were subsequently lifted and model access restored, but the new verification capability remained available for future compliance requirements.
Once a frontier lab builds document and biometric verification to survive one regulatory shock, identity proofing becomes part of its standing infrastructure.
Four Verification Layers
Verification is entering the compute stack through four overlapping layers.
1. Silicon: Hardware Attestation
Nvidia has developed location-verification technology for its confidential-computing hardware. The system uses telemetry and network-latency signals to estimate the country where a GPU operates. It does not provide a remote kill switch.
The proposed Chip Security Act would require Commerce to mandate location-verification mechanisms on advanced chips before export. The legislation followed reports of chip diversion and a DOJ case alleging that intermediaries used false documents, staged inspections, and dummy servers to divert AI hardware to China.
Vendors such as GeoComply support mandatory geolocation, arguing that verification could increase trust in U.S. chips. The Semiconductor Industry Association opposes mandates for security features it considers unproven.
2. Cloud Infrastructure: Customer Identification
The proposed IaaS KYC rule would require U.S. cloud providers to:
- verify and document foreign customers;
- screen resellers;
- identify transactions that could support training AI models with malicious cyber potential.
This layer can reuse bank-style AML and KYC infrastructure while adding export-control and end-use screening. Existing identity vendors include Persona, Jumio, Socure, Trulioo, LexisNexis, and Thales.
3. Model Access: Document and Biometric Verification
Frontier labs may need to verify individual users if hosted model access is treated as a release of controlled technology under the Export Administration Regulations.
The legal basis remains disputed. API users receive model outputs, not model weights, architecture, or source code. Previous BIS advisory positions reportedly indicated that some remote-access transactions were outside deemed-export rules.
If courts exclude hosted model access from the definition of a controlled release, nationality checks lose much of their legal foundation. If Commerce prevails or Congress legislates directly, identity verification could become standard across U.S. frontier-model providers.
4. Bilateral Trust Frameworks: Beneficial Ownership
Bilateral frameworks replace transaction-by-transaction controls with audited relationships among governments, infrastructure operators, and investors.
These arrangements depend on beneficial-ownership disclosure, personnel screening, divestment commitments, cybersecurity controls, and continuous reporting.
The UAE and G42 Template
Microsoft’s investment in G42 was accompanied by an Intergovernmental Assurance Agreement covering cybersecurity, physical security, export controls, and KYC practices.
G42 also established a Commerce-approved Regulated Technology Environment and committed to divesting from Huawei. Personnel restrictions reportedly included:
- limiting facility and chip access for individuals from arms-embargoed countries;
- restricting AI training by personnel connected to the Chinese government or China-headquartered organizations;
- barring sanctioned individuals.
By July 2026, the UAE had moved into Country Group A:5, allowing approved entities to purchase advanced chips without individual licenses.
The model is straightforward: a jurisdiction accepts expensive entity-level vetting to obtain streamlined access later. Verification does not disappear after approval. It shifts from licensing each shipment to auditing a trusted counterparty.
| Jurisdiction | Entry Requirements | Subsequent Access | Ongoing Verification |
|---|---|---|---|
| UAE / G42 | Government agreement, regulated environment, Huawei divestment, personnel screening | A:5 treatment and license-free purchases for approved entities | Audits and continuing compliance |
| Saudi Arabia / Humain | Parallel approval process on similar terms | Not established | Not established |
| China | Deal-by-deal licensing and export conditions | Selected chips approved; Blackwell-class products blocked | Case-by-case review |
Commercial Opportunities and Internalization Risk
Compute verification sits inside the broader digital-identity and KYC market. New buyers include chipmakers, hyperscalers, and frontier-model labs.
GeoComply offers one operating template. It built geolocation infrastructure for regulated online gambling and later repositioned the technology for chip-location compliance.
The main commercial risk is internalization. Nvidia is building silicon verification itself because the chipmaker controls the relevant hardware and telemetry. Independent vendors have larger opportunities where platform owners lack specialized identity infrastructure.
| Layer | Incentive to Build In-House | Independent Vendor Opportunity |
|---|---|---|
| Silicon attestation | High | Low |
| Cloud KYC and customer identification | Medium | High |
| Model-level document and biometric checks | Medium | High |
| Bilateral trust frameworks | Low | Medium, primarily consulting and systems integration |
The most defensible vendor opportunities are cloud onboarding, model-user verification, compliance monitoring, and bilateral systems integration. Hardware attestation is more likely to remain controlled by semiconductor platform owners.
The Legal and Regulatory Risk
Application-layer verification depends on whether hosted model access qualifies as a deemed export. A court or statute excluding API access would reduce the need for nationality verification. A ruling or law affirming coverage would make identity-proofing infrastructure a baseline requirement.
Regulatory instability is the broader risk. Compliance systems may be built for rules that are replaced before implementation, creating sunk costs and fragmented technical standards.
Conclusion
Export control has shifted from controlling physical chips to controlling access to compute and models. Every step increases the need to verify location, ownership, customers, personnel, and individual users.
The verification stack is forming across four layers:
- hardware location attestation;
- cloud customer identification;
- model-user identity proofing;
- bilateral beneficial-ownership frameworks.
The bottleneck is no longer writing restrictions. It is building the infrastructure required to enforce them.