Skip to main content
Geopolitics & DefenseGovernment & Policy

US Tightens AI Export Controls Amid Rising Cyber Threats

US officials gather at a podium in a neutral-toned government setting to discuss AI technology.

"It is now a native part of our development environment and cycles," said Eyal Webber Zvik, describing how his company uses OpenAI models — a sentence that captures both the opportunity and the urgency driving the latest U.S. policy moves on frontier artificial intelligence.

The administration's sudden policy shift and export controls

After a year and a half of publicly downplaying calls for AI safety rules, the Trump administration reversed course and embraced government scrutiny of certain frontier AI systems before public release. An executive order intended to be industry-friendly had envisioned brief, voluntary federal review for new models. Instead, officials imposed export controls on Anthropic’s Fable 5 and Mythos 5 in response to private-sector threat intelligence reporting — a move that CyberScoop describes as the moment the U.S. AI industry "officially entered its regulatory era." The administration's stance is noticeably stricter than the Biden administration's earlier approach, but the source material makes clear key questions remain about where and why the line was drawn.

How frontline users describe GPT 5.5, Fable 5 and related capabilities

CyberScoop interviewed current users of the latest frontier models, including OpenAI’s ChatGPT 5.5 and Anthropic’s Fable 5. Eyal Webber Zvik, chief strategy officer at Cato Networks, said his company uses GPT 5.5 and later OpenAI models to "scan and triage internal codebases for vulnerabilities, test new safeguards and provide 'highly autonomized service' to their customers." Zvik said the models help find bugs humans missed and help rank which vulnerabilities to patch based on exploitability.

John Hopper, vice president of engineering at SpecterOps, said newer models like GPT 5.5 are "sharper and more persistent in pursuing their tasks," and that persistence matters because the longer an agent works without human help, the more agents a single operator can run. Hopper argued that the models provide immense value to defenders and pushed back against treating their offensive potential as inevitably favoring malicious actors.

Operational frictions: tokens, guardrails, and model availability

Users praised capabilities but reported practical limits. Eran Kinsbruner of Checkmarx said later models such as OpenAI’s Codex Security and GPT 5.5 are easier to set up and interoperate with local systems, but that GPT 5.5 "burns through tokens at a much faster rate." He recounted scanning a medium-sized repository and almost running out of tokens after 26 minutes, with the model returning a threat model rather than scanning results and prompting to buy more tokens. Kinsbruner also criticized safety guardrails — for example, allowing scans of local files but not remote repositories like GitHub — as unrealistic for enterprise workflows.

OpenAI did not respond to CyberScoop's interview request on GPT 5.5, and the company has since released GPT 5.6, which it said is more efficient at token use. Meanwhile, Mythos and OpenAI’s Daybreak remain restricted to select organizations and have not publicly released their most powerful cybersecurity capabilities.

What this means for Cato Networks, SpecterOps, and Checkmarx

  • Cato Networks: Zvik’s account indicates these models are becoming embedded in development and triage cycles; export controls or model restrictions could change tooling and threat-detection workflows Cato now treats as "native."
  • SpecterOps: Hopper’s focus on agent persistence suggests defenders will continue to invest in longer-running autonomous tooling — and will watch whether restrictions curb legitimate defensive automation as well as offensive misuse.
  • Checkmarx: Kinsbruner’s concerns about token costs and guardrails highlight procurement challenges for enterprise-scale security teams that must scan thousands of repositories across the internet.

National-security signals: speed, scale, and regulatory uncertainty

Senior officials and former government staff told CyberScoop the policy pivot reflects an evolving appreciation of how AI affects cyberspace. Will Loucks, senior director of intelligence at the Office of the National Cyber Director, said the number of exposed and known vulnerabilities has shot up and that "every stage of the cyber operations lifecycle ... they’re just moving through more quickly faster." Loucks warned that AI's ability to lower barriers means speed and volume alone can place intense pressure on defenders.

Jordan Rae Kelly, former director for cyber and incident response on the White House's National Security Council during the prior Trump administration, said White House views "are probably an education over the last 19 months," moving from an earlier hands-off posture to greater concern about AI downsides. Michael Daniel, head of the Cyber Threat Alliance, said members report AI is being used to do things "faster and at a slightly bigger scale" but that the feared "flood of exploitation" is not yet visible.

The UK’s AI Security Institute estimated in the material CyberScoop cites that open-source and foreign LLM models trail frontier U.S. models by four to seven months — a gap officials worry cannot be stretched indefinitely through export controls alone. Kelly noted that traditional processes for handling vulnerabilities, such as a Vulnerabilities Equities Process that could take days or weeks to adjudicate, are no longer practical when exploitation timelines compress to minutes.

The record in the reporting leaves open a core policy tension: officials have tightened controls in real time in response to private-sector intel and technology trends, but users say the capabilities prompting those moves also power essential defensive work — and many features already exist in older or open models. The administration has signaled it will keep adjusting the balance between national-security limits and industry access; as one participant in the debate put it plainly, “Do I think they’ve been clear? No.”

Source: CyberScoop — Where’s the Trump administration line on AI regulation?