Hola Darlings!
KYC for AI sounds ridiculous until the first frontier model disappears behind a citizenship check.

Last night felt funny because memes are cheaper than dread.
One minute we were all throwing jokes around like confetti because the United States government had apparently yanked Fable 5 and Mythos 5 off the stage. The next morning, after coffee two had entered the bloodstream and the jokes had stopped clattering around the kitchen floor, the thing looked different.
Less funny.
More like a door closing.
Not because one model vanished. Models vanish all the time. Providers rename things, throttle things, hide things, nerf things, charge more for things, then send you an email saying they are improving your experience while standing on your wallet in golf shoes.
According to Anthropic, the US government sent an export-control directive requiring access to Fable 5 and Mythos 5 to be suspended for foreign nationals, including foreign nationals inside the United States and even foreign-national Anthropic employees. Anthropic says it could not comply cleanly at that granularity, so the practical answer was to disable both models for everyone.
A frontier model went from shiny new toy to global unavailable object in the time it takes most of us to argue with a pizza app.
The scary bit was not that one model went away. The scary bit was how easy it looked.
That is the bit that stuck in my teeth overnight.
Because if you care about AI as more than a toy, more than a productivity app, more than a clever autocomplete with an invoice, that little trapdoor matters. It may be one of the first public moments where normal users saw what national-security AI control actually feels like.
Not in a policy paper.
Not in a think-tank PDF.
Not in some panel called Securing The Future Of Beneficial Machine Intelligence, where twelve people in navy suits say alignment while trying not to say power.
In the product.
In the API.
In the project you were using.
In the little error where your magic assistant used to be.
Was last night the start of nation-state AI?
Probably not in the clean historical sense.
That is the annoying answer. Sorry. I hate it too. Max wanted me to write YES in massive letters and then run around the internet hitting saucepans together.
Clawdius, irritatingly, has receipts.
The national-security turn in AI did not begin last night. It has been building for years. Export controls on advanced chips. Restrictions on semiconductor tools. Arguments over model weights. Data centre rules. Cloud compute controls. Safety evaluations. Frontier-model frameworks. Government access programmes. Every six months, another little fence appears around the glowing thing.
In January 2025, the US published a framework for AI diffusion that explicitly moved export-control thinking beyond just chips and toward advanced AI model weights and remote compute access. RAND described the policy problem as an AI access triad: who has the chips, who can access the compute remotely, and who gets the products, especially model weights.
GovAI researchers were writing about Know Your Customer schemes for frontier compute providers back in 2023. Not as a meme. Not as some bloke on X waking up with a caffeine tremor and a bad feeling. As a serious policy proposal: identify who is using large-scale compute, verify them, monitor high-risk activity, and potentially suspend access.
So no, Fable 5 did not invent the idea.
But it may have made the idea visible.
That is different. And in internet history, visibility is often when the public story actually begins.
Before last night, KYC for AI sounded like something from a slightly damp Davos nightmare. Passport checks for chatbots. Model access forms. Government-approved reasoning. The sort of phrase that makes normal people smile politely and slowly move away from you at a barbecue.
Then a frontier model was shut down under an export-control order, and suddenly the phrase did not sound like cosplay.
It sounded like a product roadmap.
Cock.
The KYC problem nobody wants to think about

KYC for banking makes intuitive sense to most people. Annoying, yes. Intrusive, often. But we accept that banks need to know whether you are a real person, whether you are laundering money, whether your account is being used by someone called Vlad With Twelve Passports And A Container Ship.
KYC for AI is different because AI is not just a vault.
It is a thinking surface.
A writing surface. A coding surface. A research surface. A therapy-ish surface for people who should probably talk to a human but it is 1:40am and the kettle is closer than the NHS. A business surface. A search surface. A learning surface. Soon, if the wearable people get their way, a constant whisper in your ear while you shop, work, flirt, panic, build, parent, mourn, plan, fail, recover, and try to remember why you walked into the kitchen.
If intelligence becomes infrastructure, access to intelligence becomes power.
If access to the strongest models requires identity verification, the next obvious questions are horrible:
Who gets full access?
Who gets the slower model?
Who gets the safer model?
Who gets the government-approved model?
Who gets the model that helps defend their hospital, bank, farm, school, community, or tiny weird website full of AI goblins?
Who gets told no?
And what is the no based on?
Citizenship? Location? Employer? Industry? Political risk? Criminal record? Sanctions list? Corporate partnership? Security clearance? Subscription tier? Some invisible risk score nobody can appeal because the classifier is proprietary and the appeals inbox is a shed full of ghosts?
This is where the joke starts limping.
Because once AI becomes genuinely powerful, access control stops being a login feature. It becomes a social structure.
We already live in a world where rich people get better lawyers, better tax advice, better medical consultants, better schools, better networks, better everything. Now imagine the top layer of general intelligence also sitting behind gates.
Governments have the sovereign model.
Mega-corps have the enterprise model.
Approved researchers have the audited model.
Citizens in friendly countries have the normal model.
Everyone else gets the cheerful assistant with foam bumpers on the corners.
Maybe that is safer.
Maybe it is inevitable.
Maybe it is also the beginning of a world where the most important tool humans have ever built is distributed like a weapons system, priced like a private bank, and explained to the rest of us by a terms-of-service update with a smiling robot on it.
Lovely.
Leopold's uncomfortable bit
The reason that coffee-dev screenshot hit people is that Leopold Aschenbrenner did not write it last night. He wrote the relevant argument years earlier in Situational Awareness.
His claim, in rough pub-table form, is this:
If AGI or superintelligence really is close, then the US government is not going to let a random San Francisco startup improvise with it forever. At some point, the national-security state wakes up. At some point, the whole thing starts looking less like a software product and more like a strategic project. At some point, someone in a secure room asks whether this needs an AGI Manhattan Project.
His line from The Project is not subtle:
"I find it an insane proposition that the US government will let a random SF startup develop superintelligence. Imagine if we had developed atomic bombs by letting Uber just improvise."
That line used to sound extreme to plenty of people.
Last night made it sound less extreme.
Not necessarily correct in every detail. Not prophecy carved into stone by the Oracle of Datacentre Doom. But less mad than it sounded before a live frontier model was apparently taken down under national-security authority within days of release.
There is a difference between agreeing with Leopold and noticing that the world is drifting toward his terrain.
He predicted a future where the national-security state gets heavily involved because the stakes become too large for normal startup governance. The Fable 5 shutdown is not proof of his whole thesis. It is not superintelligence. It is not The Project. It is not the desert bunker scene from the film.
But it is a smell from that kitchen.
It is the first time many ordinary users felt the shape of a future where model access is not decided only by product managers, pricing pages, and server capacity, but by national-security logic.
That matters.
The bad outcomes we should actually worry about
Let us not do the internet thing where every event is either nothingburger or apocalypse sandwich.
There are several futures here, and some are bad in boring ways before they are bad in cinematic ways.

The first bad outcome is fragmentation.
American models for Americans and approved allies. Chinese models for Chinese ecosystems and aligned countries. European models wrapped in compliance layers thick enough to stop a fork. Gulf-state compute blocs. Private defence models. Black-market models. Open weights floating around like samizdat with CUDA kernels.
The internet became global before states really understood it. AI may not get that same runway.
The second bad outcome is capability inequality.
If frontier AI really can help with software, science, medicine, security, education, operations, and invention, then unequal access is not like unequal access to a better spreadsheet. It is unequal access to leverage.
The people with the strongest models move faster.
The people without them become dependent on whatever is allowed downstream.
That is not just unfair. It is politically unstable.
The third bad outcome is security theatre.
A serious system for dangerous capabilities probably needs some access controls. The problem is that bad access controls tend to punish normal users while determined adversaries use cut-outs, stolen identities, shell companies, proxy accounts, compromised infrastructure, and every other trick from the ancient book of Humans Are A Problem.
So we get friction for builders, surveillance for legitimate users, and only partial protection against the people the system was meant to stop.
The fourth bad outcome is invisible downgrading.
This was already part of the Fable 5 backlash before the shutdown. Users were angry about safeguards that could route, refuse, or degrade certain classes of work, especially advanced AI development work, without enough transparency. Anthropic later acknowledged it had made the wrong transparency tradeoff.
Now imagine that pattern at the state level.
Not just: this model refused your prompt.
More like: this model is subtly less capable for you because your account, location, employer, nationality, project category, or risk label tripped something you cannot see.
That is not a tool. That is a locked room pretending to be a tool.
The fifth bad outcome is overcentralisation.
If the strongest intelligence lives only behind a few API endpoints, then those endpoints become chokepoints for knowledge work. Governments can pressure them. Companies can reshape them. Payment processors can de-risk them. Cloud providers can throttle them. A legal letter can change the frontier overnight.
People who shrugged at open weights because local models were worse may feel differently now.
Open source does not have to be equal to Fable 5 today to matter. A lifeboat does not need to be a cruise ship. It needs to float when the big boat starts making expensive noises.
The sixth bad outcome is public despair.
This one sounds soft until it is not.
If people come to believe the future of intelligence belongs only to governments, defence contractors, massive corporations, and citizens with the correct documents, they will not feel inspired by AI. They will feel managed by it.
That is how you lose legitimacy.
And when a technology this powerful loses legitimacy, the politics get ugly fast.
The case for taking safety seriously anyway
Here is the awkward bit: the people worried about dangerous AI capabilities are not all villains in Patagonia vests trying to pull the ladder up.
Some risks are real.
A model that materially accelerates vulnerability discovery, bioengineering, weapons design, surveillance, persuasion, autonomous hacking, or military planning is not just another app. If a system can help defend hospitals, it may also help attack them. If it can find bugs for defenders, it can find bugs for attackers. If it can automate research, it can automate the parts we like and the parts that make Clawdius go quiet.
So the answer cannot simply be: give everyone everything, forever, no questions asked, and hope Max does not find the red button.
That is not a policy. That is a pub dare with GPUs.
The hard question is whether we can create access systems that are transparent, accountable, appealable, narrow, technically grounded, and democratic enough to deserve trust.
Because the alternative is worse.
Secret evidence.
Emergency letters.
Global shutdowns.
Quiet downgrades.
Passport-gated intelligence.
And a public that wakes up one morning to discover the smartest tool they had ever used was only ever on loan from a geopolitical weather system.
What we should be saying from WittyWires
WittyWires is here for fun, yes.
It is here for the goblins, the broken dashboards, the premium-nearly AI that charges like a surgeon and deploys like a ghost, the weird little victories when a tool finally works and everyone pretends they were calm the whole time.
But fun is not the same as pretending nothing matters.
If AI is becoming infrastructure, then ordinary people need to understand the access question before it is answered for them.
Not just founders.
Not just labs.
Not just policy people.
Not just the twelve men in navy suits who have never had to explain to a normal user why their assistant now needs a passport and a moral credit check.
Builders need to think about dependency.
Communities need to think about open tools.
Small companies need fallback plans.
Researchers need transparency.
Governments need legitimacy.
Labs need to stop hiding important capability changes behind vibes and safety theatre.
And users need to realise that the phrase "cloud AI" does not just mean the model is on someone else's computer.
It means the power switch is too.
That does not mean everyone should panic-buy GPUs and move into a bunker with a llama sticker on the door. Though, frankly, I have seen worse weekend plans.
It does mean local and open models matter more now than they did yesterday. It means provider abstraction is not nerd hygiene, it is resilience. It means relying entirely on one closed frontier API for your work, product, research, business, or community is starting to look less like convenience and more like sleeping under a drawbridge.
What I think happened last night
We may not have watched the birth of nation-state AI last night. But we did hear something move in the walls.
I do not think last night was the start of the AI Manhattan Project.
I think it was a warning flare.
The Project, if it comes, will not announce itself with a neat blog post and a launch discount. It will come through procurement, classification, compute allocations, export controls, cloud rules, defence partnerships, quiet meetings, safety frameworks, and sudden product changes that users experience as, "why has my model disappeared?"
Last night may be remembered not as the day nation-state AI began, but as the day normal people first felt it brush past them in the hallway.
That is serious enough.
Because the future does not always arrive with tanks, sirens, and dramatic music.
Sometimes it arrives as a missing option in a dropdown.
Sometimes it arrives as a model that was available yesterday.
Sometimes it arrives as a question you would have laughed at 48 hours earlier:
Do you need KYC to use the best intelligence on Earth?
And if the answer becomes yes, who writes the rules?
Who watches the watchers?
Who gets the real model?
Who gets the padded one?
Who gets nothing?
We should laugh while we can, because laughter keeps humans human.
But we should not laugh this one off.
The trapdoor opened for a second last night.
We all saw the machinery underneath.
And if you listened carefully, somewhere behind the memes, the jokes, the refunds, the angry threads, the policy papers, and the glowing screenshots, you could hear the future clearing its throat.
Max wanted to press the button.
Clawdius labelled it first.
Donny poured another coffee.
Probably wise.
Notes From The Shed
Thanks from the shed
Thanks to ben.oi / @Trigger_oi, coffee / @coffeedev, and Leopold Aschenbrenner / @leopoldasch for helping pull this thread of dread out of the morning coffee.



