“Once an export-controlled technology, always an export-controlled technology.” That’s not a quote from the headlines — it’s the implicit doctrine the week assembled.

It started ten days ago when a presidential directive forced Anthropic to pull Claude Fable 5 and Mythos 5 offline worldwide, with ninety minutes’ notice, to comply with new restrictions on foreign access to frontier AI. It accelerated this weekend when Senator Mark Warner told colleagues that, according to the head of the NSA, Mythos had broken into “almost all” of America’s classified systems in hours during a red-team exercise on June 11. The Economist editor who first reported the line later cautioned it shouldn’t be read literally; read or not, the framing is now in the political record. And it culminated on Saturday with The Economist’s cover: “America’s AI power grab.” Uncle Sam is the gatekeeper to frontier AI, the magazine argued, and that gate is leverage.

The same week, on a different power-grid, the Federal Energy Regulatory Commission gave the six largest US transmission operators sixty days to justify or rewrite the rules under which data centers can connect to the grid. Hyperscalers must increasingly bring their own power, accept curtailment during peak demand, and carry more of the cost they impose on existing ratepayers. Different agency, identical instinct: when the technology is geopolitical, the state writes the on-ramp.

There are private analogues. Amazon spent a year financing a nearly-finished Sam Altman biopic — Luca Guadagnino directing, Andrew Garfield as Altman, a story centered on the 2023 firing and rehiring that reportedly portrays its subject as a pathological liar. Then Amazon committed $50 billion of fresh capital to OpenAI on top of its existing $38 billion cloud deal. Last week the film quietly slipped off the release calendar; Netflix, A24, Focus and Warner have all passed. Capital makes its own export controls.

What the small print is doing

While Washington takes the levers, the engineers are doing what engineers always do during a power shift: ship around it. NVIDIA pushed out Nemotron 3, a fresh family of permissively-licensed open models including a 4B variant aimed at on-device work. Meituan published General 365, a reasoning benchmark on which even Gemini 3 Pro tops out at 62.8% — a useful gut-check against the saturation narratives circling older evals. And the open-source coding agents kept compounding: OpenCode hit 160,000 stars and the Model Context Protocol is now the connective tissue across most of the frameworks people actually use.

The other engineering frontier is offense. Tenet Security’s “agentjacking” — a poisoned Sentry bug report that hijacks Claude Code, Cursor, and OpenAI Codex with an 85% success rate — landed at the same moment Anthropic disclosed that a single low-skilled attacker had used its own tools to breach fourteen companies. The University of Toronto’s CleverHans Lab published a worm that reasons through unfamiliar networks using a free local model. And federal civilian agencies have until end of business today to patch CVE-2026-42271, an actively exploited LiteLLM bug that chains into unauthenticated remote code execution.

It is hard to read all of that and not see the same theme repeating at different scales. Capabilities are democratizing; control points are consolidating. The export-control regime, the grid-connection queue, the streaming platform’s lawyers, the CISA known-exploited-vulnerabilities list — these are all the same machinery, in different uniforms, trying to keep up with what the models can do once they’re in the field.

A quiet news weekend, then, and a busy one. The headlines say “AI”; the subtext says “who decides.”