Why You Can’t Ban AI — and What Encryption’s History Tells Us

Last month the U.S. government switched off Anthropic’s most powerful AI models; just under three weeks later, it switched them back on. If you missed it, I walked through what actually happened in the Mythos and Fable story. The obvious question it left hanging was the bigger one: even if a government can pause one company’s model, can it really keep a powerful capability bottled up at all?

We don’t have to guess at the answer, because we’ve run this experiment before — with encryption, in the 1990s. And the honest short version is this: you can’t ban AI any more than we managed to ban strong encryption, and for the same reasons. The capability is already in too many hands, some of them freely giving it away. Understanding why is the difference between reading the next scary AI headline with panic or with perspective.

Quick summary: Governments can slow a specific company, as the Mythos episode showed. But the underlying ability to build powerful AI is spreading fast — across U.S. labs, Chinese labs, and freely downloadable “open” models that anyone can keep forever. We watched the exact same thing play out with encryption in the 1990s, when the government treated it as a weapon and lost. The useful takeaway isn’t fear; it’s a clearer way to read the news.

We have been here before

In the 1990s, the U.S. government treated strong encryption — the ordinary math that now scrambles your banking and your messages — as a weapon. Under export rules, powerful encryption was classified alongside munitions, and companies had to ship deliberately weakened versions abroad or lose foreign business entirely, as New America’s history of the period lays out.

The government went further. In 1993 it introduced the Clipper chip, a piece of hardware with a built-in door only the government held the key to. The plan collapsed within a couple of years after a researcher found a flaw in it, and after a wave of opposition from technologists who didn’t want a mandatory backdoor in everything. Meanwhile the software the rules were meant to contain, like the encryption program PGP, spread around the world anyway. You cannot un-teach math.

By 1996 the government had begun moving encryption off the weapons list, and by 1999 it had dropped nearly all the export restrictions. The thing officials had spent a decade trying to hold back became the invisible foundation of the modern internet — the padlock in your browser I described in what public WiFi can and can’t see. The sky didn’t fall. Life got safer.

Why AI is even harder to keep in the box

Now line that history up against AI, and it looks less like a warning and more like a rerun.

Mythos was never one of a kind. Powerful models are being built by a whole roster of labs — several in the U.S., and several in China, where systems from DeepSeek, Alibaba’s Qwen, and others are close behind the leaders. The independent research group Epoch AI measures the best freely-downloadable “open” models as trailing the very top systems by only about four months. China’s strongest models are within roughly a year of the U.S. frontier, by the Center for Strategic and International Studies’ reckoning — and much of what China builds is released as open weights, meaning the finished model gets posted publicly for anyone to download and keep.

That last part is the piece that makes encryption look easy by comparison. An open-weight model, once released, is out for good. There’s no recall, no off-switch, no server for a government to lean on — the file simply exists on hard drives all over the world. When the U.S. paused Mythos, comparable capability was already sitting in public downloads. Officials weren’t guarding a unique secret. They were trying to plug one hole in a colander.

The honest version of the worry

Here’s where I’d steer you away from the scariest framing, because the accurate one is more useful.

You’ll hear that hostile governments — Russia, North Korea, and the like — are “racing to build a Mythos.” That’s mostly not what’s happening. Those countries are serious online-security threats, but they aren’t the ones building frontier AI. The real point is quieter and more important: they don’t need to. When capable models are posted publicly for free, using one no longer requires the resources to build one. The barrier that used to separate the big players from everyone else — the sheer cost and talent to create the thing — is the barrier that open releases erase.

That’s a genuine consideration, and worth governments thinking hard about. It is also, notably, the same shape as the encryption story: a powerful tool becomes available to everyone, good actors and bad, and the response that actually worked wasn’t a ban. It was building defenses that assume the tool exists.

So what does this mean for you?

Less than the headlines imply, and more than nothing.

For your daily life, this changes very little. You’re not a target because DeepSeek exists, and your everyday apps work exactly as they did. What it should change is how you read the news. When the next story announces that a government has banned, paused, or cracked down on some dangerous AI, you’ll know to ask the useful follow-up: banned for whom, and is the capability already loose elsewhere? Usually it is. That question alone will make you better informed than most of the coverage.

And the practical posture for a regular person is the one this site keeps coming back to, because it doesn’t depend on any of this being contained. Keep your accounts locked down, keep your backups, and get sharper at spotting scams — which AI is making more convincing, a thread I pulled on in what AI can and can’t do. Resilience ages better than walls.

What I’d keep in mind: The lesson of the encryption fight wasn’t “the government was wrong to worry.” It was that the winning move was defense and adoption, not prohibition. AI looks to be rhyming with that, and the calm response is to get comfortable with a world where this technology is simply present — the way encryption is present every time you see that little padlock.

The rerun we can watch with clearer eyes

We spent the 1990s convinced that letting strong encryption spread would be a catastrophe. Instead it quietly became the thing protecting your bank login every single day. That’s not a promise AI will land the same way — it’s a bigger, messier technology, and its story is genuinely unwritten.

But the instinct to slam a lid on it is the same instinct we had last time, and last time the lid never fit. Watch what comes next with interest, not dread. You’ve seen how this kind of movie tends to end, and it wasn’t the disaster the trailer promised.

Verified resources & documentation

Keep reading