There are technologies that change the world gradually, spreading quietly until society grows accustomed to their presence. And there are technologies that bring about such an abrupt disruption that they leave no time for the world to get used to them or even adapt. They immediately create a regulatory vacuum. They cease to be merely a concern for programmers and investors and instead become the epicenter of national sovereignty and global security. The difference between these two types of technology is not one of degree, but of nature. The first coexists with the slowness of the state. The second starkly exposes the state’s inability to keep pace with the very era it has created.

Anthropic, one of the world’s leading artificial intelligence companies, announced in April 2026 that it had created a model so powerful that it decided not to release it. The model is called Claude Mythos Preview. The stated reason: the system identified thousands of high-severity vulnerabilities in virtually all relevant operating systems and browsers in the contemporary digital world. Faced with this discovery, the company chose silence over the product.

That statement, in and of itself, should already be given more attention in the Brazilian public debate than it currently receives. This is not a technology that promises to solve problems. It is a technology that its own creator acknowledges is too dangerous to circulate freely. Over the past sixty days, this decision has triggered a chain of events that spans the U.S. financial system, regulatory diplomacy between Washington and Silicon Valley, and a question that no democracy has yet answered satisfactorily: Who decides what artificial intelligence can and cannot do?

The Model That No One Can See

The Mythos case defies the usual logic of the tech market. Historically, the race for innovation has always rewarded those who launch first. Anthropic has turned that equation on its head. When introducing the Mythos Preview, the company documented in its own technical report that the model had uncovered critical flaws in operating systems and browsers used by billions of people, including vulnerabilities that had remained hidden for decades. Given this power, the company chose not to make the tool available to the general public. Instead, it restricted access to a select group of partners within a program called Project Glasswing.

The initiative is a select coalition of technology companies and security agencies that have been rigorously vetted, designed to identify and fix software vulnerabilities in a controlled manner before any product is widely made available to the public.

The program quickly expanded to include 150 organizations in more than 15 countries. The practical results of this task force justify the authorities’ initial fears, as participants have already identified more than 10,000 high-severity vulnerabilities in critical global software. Glasswing has effectively become a provisional government for digital security—a parastatal structure attempting to contain the spillover of a power that the state itself does not yet know how to manage or regulate.

The decision carries a structural irony. A private company—with no electoral mandate and no obligation to be accountable to a parliament—has become the guardian of knowledge capable of compromising the digital infrastructure of entire nations. And it was this very company—not a government regulatory agency—that identified the risk and imposed a limit on itself. The government came later. It arrived in a turbulent manner.

The financial system on alert

On April 7, U.S. Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell called an emergency meeting with the CEOs of the largest U.S. banks. The sole item on the agenda was the cyber risk posed by Mythos. Banks such as Citigroup, Bank of America, Wells Fargo, Goldman Sachs, and Morgan Stanley sent their top executives to the Treasury headquarters in Washington. The urgency of the meeting reveals something more important than its specific content: financial and monetary regulators have begun to treat a language model as a systemic threat comparable to a credit crisis.

A month later, the International Monetary Fund formalized this concern in an official report. As the Fund highlights in its May analysis, cyberattacks powered by artificial intelligence could create funding strains, heighten concerns about bank solvency, and trigger instability in global markets if multiple institutions were targeted simultaneously. The organization acknowledges that technical barriers still partially protect proprietary financial software, but warns that this protection tends to erode rapidly as AI models become more widespread. The institutional conclusion is unsettling: for the first time, a central bank and an international monetary fund have treated a technology product as a macroeconomic risk factor, on the same level as a liquidity crisis or an asset bubble.

The U.S. government slams the door shut

The third chapter of this sequence is the most serious from an institutional standpoint. On June 9, 2026, Anthropic publicly launched Claude Fable 5, the first commercial version of the new Mythos class made available to the general public. Three days later, on June 12, the U.S. government ordered, through an export control directive, that the company immediately suspend access to Fable 5 and Mythos 5 for any foreign national, whether inside or outside U.S. territory, including the company’s own foreign employees.

Anthropic’s public response laid bare the tension between technological power and state power with rare clarity. As the company itself stated in an official statement, the government should have the ability to block unsafe deployments, but only as part of a transparent, fair statutory process grounded in technical evidence. And it added, in no uncertain terms, that the government’s action did not follow these principles. To put it in less diplomatic terms: Anthropic complied with an order it considered arbitrary, but made a point of publicly stating that it disagreed with it.

This episode is paradigmatic because it reverses the usual hierarchy between innovation and regulation. There was no legislative process. There was no public hearing. There was no deliberate policy-making. There was a letter, a short deadline, and an abrupt shutdown of a product used by millions of people in dozens of countries. When regulation finally appeared, it did not come in the form of a law. It came as an emergency executive order.

Who decides what AI can do?

This is the crux of the real debate behind the facts. Is a government that blocks access to an artificial intelligence model—without a formal process, without full transparency, and contrary to the technical assessment of the developer itself—exercising legitimate technological sovereignty, or is it engaging in regulatory arbitrariness disguised as national security?

The answer is not simple, and perhaps that is the most important lesson of this episode. Both perspectives contain a partial truth. It is undeniable that sovereign states have the right—and even the duty—to protect their critical infrastructure from technologies with the potential for systemic damage. No mature democracy can treat a tool capable of identifying vulnerabilities in all the world’s operating systems as just another consumer product. But the power to block, exercised without clear rules, without predictable timeframes, and without technical due process, is not sovereignty. It is discretion. And discretion, when applied to technologies that shape the economic lives of millions of people, tends to become an instrument of political dispute, not of collective protection.

The Paradox of Regulation

Still, it would be naive to view U.S. export controls as an adequate and sufficient response. Experts affiliated with the Council on Foreign Relations have already characterized the set of restrictions imposed abruptly as incoherent and potentially self-defeating. The logic is straightforward: broad controls, applied without predictability, limit the ability of U.S. companies to operate globally, retain international talent, and compete with rivals from other regions that are not subject to the same regulatory constraints. Belated regulation is often more dangerous than the absence of regulation, because it arrives without a framework, without process, and without predictability. And it is precisely these three qualities that enable a regulation to inspire confidence.

This is the paradox that runs through the entire crisis: the same government that blocks foreigners’ access to Mythos for reasons of national security is the one that, weeks earlier, had hastily convened bankers out of fear that the same model could destabilize the U.S. financial system. The threat and the response emerge from the same regulatory ecosystem, yet follow logics that are disconnected from one another. There is no visible coordination between the systemic fears expressed by Bessent and Powell, the IMF’s technical warning, and the export directive signed in June. What there is, however, is a succession of ad hoc reactions to a technology that is advancing faster than the institutional capacity to understand it.

The urgency that still has no name

This is not about romanticizing a private company’s decision, nor is it about automatically validating the actions of a government that opted for a block without a transparent process. It is about recognizing that both parties are currently operating in a regulatory vacuum. Self-regulation without external oversight is power without democratic legitimacy. State intervention without a formal process is power without legal predictability. Neither of these approaches, on its own, can sustain a system capable of managing technologies of this magnitude over the long term.

The real urgency, therefore, is neither to prevent the advancement of artificial intelligence nor to blindly trust in the good will of those who develop it. It is to build—at a pace commensurate with that of the technology itself—a legal framework capable of balancing two imperatives that are currently out of alignment: the legitimate need to protect digital sovereignty and the equally legitimate need for regulatory predictability for innovators. Until such a framework exists, the world will continue to react to each new crisis as it did with Mythos: with emergency meetings, hastily signed guidelines, and an awkward silence regarding who, after all, should have the authority to decide what artificial intelligence can and cannot do.

More about 

World

View More

ComTexto in Your Inbox. Contextual Reading, Every Week.

No spam. Only purposeful content.
Perfect. You will soon receive ComTexto in your inbox.
Oops! Something went wrong while submitting the form.