The infrastructure ratchet: What Web3 teaches AI builders about the coming control stack

On 8 August 2022, the US Treasury sanctioned Tornado Cash. Not its founders. Not its users. The code itself. Forty-four Ethereum smart contract addresses were placed on the OFAC Specially Designated Nationals list, alongside arms dealers and sanctioned regimes. Within hours, Infura and Alchemy cut off API access. Circle blacklisted USDC held inside the contracts. GitHub suspended the repository and the accounts of contributors. A permissionless protocol became inaccessible not by touching the blockchain, but by pressuring the infrastructure layers it depended on.
On 13 June 2026, the US Commerce Department issued an export control directive ordering Anthropic to suspend all access to Fable 5 and Mythos 5 for every foreign national, including Anthropic’s own staff. Anthropic had no mechanism to verify citizenship at scale. The only compliant path was a full global shutdown of both models, one of which had launched 3 days earlier and was already serving hundreds of millions of users. The stated reason was a potential jailbreak that OpenAI’s GPT-5.5 also possessed.
Same playbook. Different technology. Four years apart. The AI industry is now living through the thing the Web3 industry lived through between 2015 and 2022, and most practitioners haven’t clocked it yet.
The pattern the crypto industry learned, slowly
The early crypto industry made an argument that coherent people believed: the protocol is permissionless and decentralised. Governments that want to control it will need to regulate mathematics. That argument was made seriously, at length, by technically credible people.
It was wrong. Governments never tried to regulate the mathematics. They regulated the on-ramps. The exchanges. The fiat rails. The infrastructure connecting the permissionless protocol to the real world where people hold accounts and spend money. By the time Tornado Cash was sanctioned, KYC had been mandatory on regulated exchanges for years. DeFi front-ends followed. Node operators remain in progress.
AI’s on-ramps are compute, cloud, and API access. All 3 are now in the government’s sights. The pattern follows the same sequence. The only variation is which layer is currently being gated.
The Infrastructure Ratchet is the 5-stage process by which governments control access to technology they can’t ban outright. Each stage adds a gate at a different layer of the stack. Once a gate exists, it expands. It does not retract.
Stage 1: hardware gate. Stage 2: cloud and infrastructure gate. Stage 3: model access gate. Stage 4: identity verification gate. Stage 5: trusted partner tier. The crypto industry went through all 5. Frontier AI has completed Stage 1, is mid-way through Stage 2, and triggered Stage 3 on 13 June 2026.
The hardware gate closed in January 2026
The BIS rule effective January 2026 made KYC mandatory at the compute layer. Advanced AI chips (the Nvidia H200, the AMD MI325X, and functional equivalents) became subject to export licensing conditions that include written Customer Identification Programs for the consignee. Any organisation procuring GPU clusters at scale is now operating inside a hardware supply chain that is legally required to know who you are and what you’re running.
This didn’t arrive suddenly. The sequence started with the CHIPS and Science Act in 2022, moved through successive rounds of export controls targeting AI semiconductor sales to China and Macau, and culminated in the January 2026 final rule. Each round tightened the net. The hardware gate is closed. Most of the industry is aware of it as a procurement concern. Most are not treating it as an operational one. That distinction probably won’t hold through 2027.
The crypto parallel is the ASIC export controls and mining pool monitoring that preceded exchange regulation. At the time, it read as a peripheral issue affecting a narrow category of hardware buyers. In retrospect, it was the template for everything that followed: governments establishing the precedent that the infrastructure surrounding a technology is governable, before moving to regulate the technology’s access points directly.
The action: Audit your GPU procurement chain. Confirm whether your cloud provider has completed BIS compliance documentation for the compute you’re running AI workloads on. If you’re using spot instances or preemptible GPU capacity from resellers, confirm the provenance. This is now a legal exposure question, not just a vendor management one.
The cloud gate is closing now
The BIS IaaS proposed rule, which closed its comment period in April 2024, would require any US provider of cloud infrastructure to build and maintain written Customer Identification Programs. The framing is financial-services grade: document verification, identity confirmation, sanctions and PEP screening, account provisioning, usage monitoring. The same compliance stack that regulated fintechs spent a decade building, now applying to the layer your AI workloads run on.
Microsoft publicly welcomed the proposed rule. Worth sitting with that. When a hyperscaler accepts a compliance burden it didn’t previously have, it’s because that burden is a competitive moat. The compliance infrastructure costs tens of millions of pounds to build and years to mature. The hyperscalers have it. The long-tail cloud providers don’t. The rule, once finalised, will clarify this market. Smaller providers who can’t certify will lose enterprise AI customers to those who can.
For DevSecOps teams and platform engineers: this means the layer your internal AI tooling runs on will soon require identity verification at the account level. The API key will follow the passport. The infrastructure gate is not a theoretical future risk. It is an active regulatory proceeding that several major cloud providers are already preparing for in their terms of service.
The action: Pull your cloud provider’s terms of service changelog for the past 6 months. Look for language around AI export compliance, foreign national access restrictions, and Customer Identification Program obligations. This wording is appearing in updated agreements now, before the rule is final. If you find it, determine what it requires of you as the account holder when access is gated at the provider level.
The model gate opened on 13 June 2026
Fable 5 is Stage 3 made visible. The Commerce Department’s export control directive of 13 June 2026 is the first direct precedent for nationality-gating a public AI model’s API access. The legal mechanism is the Export Administration Regulations (EAR), which allow the Bureau of Industry and Security to restrict access to technology classified as a national security risk when accessed by foreign nationals.
There’s a legal complexity underneath this that is still unresolved and worth understanding. When a foreign national prompts a US-hosted AI model and receives a response containing controlled technical information, the question of who the exporter is matters enormously. The most defensible legal analysis frames the company that deployed the model as the exporter for every call a foreign national makes. Anthropic, under this reading, becomes the exporter hundreds of millions of times per day. There is no way to manage that at scale without identity verification at the point of API access.
Every frontier model with dual-use capabilities (cybersecurity, biology, advanced materials, precision engineering) is now a potential export control subject. Fable 5 was the first to get hit. The legal precedent it created applies to any subsequent model with comparable capabilities, from any US-based provider.
The action: Review your AI vendor contracts for export control compliance clauses. If you’re building products on top of frontier model APIs, check whether your terms of service require you to verify the nationality of your end users. If you’re reselling or integrating frontier model access, your users’ nationalities may already create downstream compliance liability for you.
The disclosure trap in voluntary AI review
Roman Storm, co-founder of Tornado Cash, cooperated with investigators. He argued publicly and coherently that he was a developer, that open-source code isn’t money laundering, and that sanctioning a smart contract was constitutionally incoherent. In November 2024, a jury convicted him on money laundering conspiracy, operating an unlicensed money transmitting business, and sanctions violations. He faced up to 45 years.
Anthropic cooperated with the US government before any order required it. It allowed government reviewers access to the underlying Mythos model. It took their feedback seriously and built in guardrails. It completed thousands of hours of pre-launch red-teaming with the US government, the UK AI Security Institute, and third-party organisations. It disclosed upfront that perfect jailbreak resistance is likely impossible for any model. Commerce issued the directive anyway. Reports emerged that a competitor’s CEO had made a phone call to the White House.
Cooperation functions as a disclosure mechanism. What you share during a voluntary review can form the basis for restrictions that follow. A voluntary review process with no binding reciprocal obligation from the government is not a compliance framework. It is a one-sided due diligence exercise conducted by the party with enforcement power. The crypto industry learned this the hard way: cooperating with regulators in 2017 to 2019 led to requirements, not exemptions. The lesson it eventually absorbed was to cooperate with legal counsel present, understand what you’re disclosing, and separate engagement from protection.
The action: Before entering any government model review process, involve export control legal counsel. Establish in writing what the government’s obligations are in return for access to your model or your system. Verbal assurances from agency officials who are later reassigned are worth nothing. The Anthropic case is the precedent: cooperation is not a shield.
The trusted partner tier is the new BitLicense
On 27 June 2026, Mythos 5 was partially restored. Commerce Secretary Howard Lutnick wrote to Anthropic that the model could be released to “certain trusted partners”: a small group of cyber defenders and infrastructure providers. Fable 5, the consumer-facing version, remained offline. The most capable model now sits behind a permissions wall that cleared organisations can pass through. Everyone else gets the guardrailed version, if it returns at all.
In 2015, New York’s Department of Financial Services issued the BitLicense. Exchanges that obtained it could operate in New York. Those that couldn’t, or chose not to, exited. Kraken and Poloniex both left. The BitLicense didn’t ban crypto in New York. It created a two-tier system: licensed operators with full market access, and everyone else with none. By 2020, BitLicense holders had locked in institutional custody relationships, banking partnerships, and client pipelines that unlicensed competitors couldn’t touch, regardless of their technical capability.
The “trusted partner” tier for frontier AI is the same structure at a different layer. Organisations with cleared access to Mythos 5 will develop capabilities, relationships, and operational patterns that consumer-tier operators cannot replicate. The gap between cleared and uncleared access to frontier AI will compound over time, exactly as it did in crypto. The organisations that understand this now and start building the relationships required for cleared status will be in a structurally different position to those who don’t.
The action: Determine which tier your organisation needs to be in, and whether that’s a decision you’ve actually made or just assumed. If your use case requires frontier-level cybersecurity, biological research, or advanced engineering capabilities, start building the government agency and AI provider relationships that lead to trusted partner status. Waiting until the gate is fully formed means operating on the consumer tier indefinitely.
Open source buys time, not sovereignty
The open-source argument about AI is being made today in almost exactly the terms the crypto community used about decentralised protocols in 2019 to 2021. The argument: if the model weights are publicly available, no export control directive can put the capability back in the bottle. Anthropic itself acknowledged this in its June 2026 statement, noting that a model on the level of Fable 5 will eventually be available as open-source. DeepSeek R1’s release in January 2025 already demonstrated that open-weight models can reach near-frontier capability with substantially lower compute.
This is probably true. The open-source window is real. It is also time-bounded. The regulatory response to open-weight AI capability won’t be to ban the weights directly. It’ll be to pressure the infrastructure that serves them: the CDNs, the model hubs, the GPU cloud providers running inference. Hugging Face has already received legal inquiries about specific models. The pattern is identical to what happened to privacy coins after 2022. Monero and Zcash are still running. They’re also delisted from every major regulated exchange, increasingly difficult to purchase without identity verification, and effectively unavailable to institutional participants. The protocol survived. The accessible, liquid, institutional market for the protocol did not.
Open-weight AI models will likely follow the same trajectory: technically available for download, practically gated for production use at scale. The infrastructure layer will be where the gate lands, not the model file.
The action: If your AI strategy includes open-weight models as a sovereignty hedge against proprietary model restrictions, use the window that currently exists. Fine-tune and deploy on infrastructure you control, in jurisdictions with clear or absent regulatory frameworks for model hosting, with export control legal advice on your specific position. The window won’t remain open indefinitely. Build now.
Build the compliance stack before it’s built for you
Every crypto exchange that built KYC infrastructure early ended up in a stronger position when regulation arrived than those who scrambled to retrofit it. Coinbase invested heavily in compliance from 2014 onwards. When the BitLicense launched, it was among the first to obtain it. That lead translated into institutional client relationships and banking partnerships that latecomers couldn’t access regardless of their trading volumes or technical sophistication. The compliance investment became a market position.
The compliance stack for AI model access is already visible. It mirrors fintech almost exactly: document verification and identity confirmation at onboarding; nationality and sanctions screening against OFAC, HM Treasury, and UN lists; beneficial ownership checks for organisational accounts; usage monitoring with suspicious activity reporting analogous to SARs in banking. Anthropic’s own Responsible Scaling Policy already requires KYC at ASL-3 capability levels. The architecture exists at the frontier. The question is whether you build toward it intentionally or react to it when a directive lands in your legal team’s inbox.
For platform engineers building internal AI tooling on top of frontier APIs: an API gateway that routes to a frontier model without knowing who the caller is will need retrofitting. The retrofit is harder than building it right from the start. The identity and access management layer at your AI gateway is a design decision you’re making now, either deliberately or by omission.
The action: Map your AI access architecture against the 5 stages of the Infrastructure Ratchet. Hardware: confirm BIS compliance at your compute provider. Cloud IaaS: check your provider’s updated terms for export compliance language. Model API: review your vendor contract for nationality verification obligations. Identity gate: decide now whether you’re building identity verification into your AI gateway layer. Trusted partner tier: determine whether your use case requires cleared access, and start building the relationships that lead there. This mapping takes a day. The retrofit, under deadline, takes months.
The only question that matters
The crypto industry spent 5 years arguing that decentralised technology was ungovernable. The infrastructure surrounding it turned out to be very governable indeed. The result is a system where the underlying protocol remains technically permissionless, but every accessible route through it runs through a compliance checkpoint. Most participants in that market now operate inside a KYC framework they would have found unimaginable in 2015.
Frontier AI is at the same inflection point the crypto industry reached around 2021, just before Tornado Cash. The Infrastructure Ratchet has started clicking. The hardware gate is locked. The cloud gate is closing. The model gate opened on 13 June 2026 and hasn’t fully re-opened.
The ratchet clicks one way. It did in crypto. The architecture of compliance is already being built around frontier AI. The only variable is whether your organisation is inside that architecture by design, or whether you’re going to find out where you stand when a government directive lands on a Friday evening at 5:21pm.