US weaponises AI IoT Cybersecurity Testing
- June 22, 2026
- William Payne

In June, the US Administration issued an Executive Order granting oversight of US AI models to US national security agencies. A fortnight later on June 12, the US Commerce Department issued an order banning “any foreign national” from accessing Anthropic’s two latest AI models, Fable 5 and Mythos 5. The immediate effect for global IoT companies has been to strip them of two frontier AI models that many had specifically planned employing for advanced IoT cybersecurity testing. The wider implication is that global IoT companies could be denied future access to the latest US frontier AI models for both development and deployment.
The US Commerce Department export control directive expressly included the vendor’s own non-US employees operating on US soil. According to data from the Center for Security and Emerging Technology (CSET) and the National Foundation for American Policy (NFAP), there are virtually no elite AI development teams in the United States that do not include foreign nationals in senior and foundational roles. As a consequence the US Commerce Department June 12 ruling calls into question future AI development in the United States.
For advanced IoT cybersecurity testing, such nationality-based restriction is operationally challenging. Modern critical national infrastructure (CNI) and IoT ecosystems, from connected automotive fleets to smart grids, rely on internationalised engineering teams to conduct continuous red-teaming, automated code review, and vulnerability remediation. If a multinational IoT operator integrates a US-hosted frontier model into its threat-detection pipeline, the June 12 precedent dictates that its British, European, or Asian security personnel could be criminalised for accessing the underlying API. This breaks the established cross-border collaborative model of cyber testing.
To maintain legally viable and uninterrupted testing pipelines, global IoT operators may now face having to strip US cloud dependencies from their security architectures, pivoting entirely to open-weight or sovereign models running on local compute where foreign-national restrictions cannot be enforced.
An Illusion of Voluntary Compliance
The June 2 Executive Order (EO) establishes a classified benchmarking process, administered by the Director of the National Security Agency (NSA), to designate systems as “covered frontier models” based on their cyber capabilities. While the EO explicitly disclaims mandatory licensing, the voluntary pre-release framework operates as a de facto pre-clearance regime. Developers are pressured to grant the federal government a 30-day early access window to covered models. This effectively means the US intelligence community now holds control over, and can ban, commercial release of tools that can be utilised to secure next-generation IoT networks.
The EO also directs the Cybersecurity and Infrastructure Security Agency (CISA) to issue Binding Operational Directives (mandatory cyber instructions for federal systems) to expedite the cyber defence of civilian networks, heavily integrating these covered models into US domestic infrastructure.
While the US Office of Management and Budget (OMB) is mandated to redirect federal grant funding toward advanced AI vulnerability detection, creating a US-centric market for defensive AI tools, the classified benchmarking process under the control of the Director of the NSA creates a mechanism to restrict export of those same capabilities to foreign markets.
The Anthropic Zero-Notice Revocation
While not a direct statutory consequence of the June 2 EO, the Commerce Department June 12 Export Restriction on Anthropic’s Fable 5 and Mythos 5 models is a product of the administration’s new national security AI containment philosophy.
The trigger for this intervention was a narrow, non-universal jailbreak (a method of bypassing a model’s safety guardrails to elicit restricted outputs). Specifically, the government cited the model’s ability to read a specific codebase and fix software flaws, a fundamental dual-use capability that is identical to automated vulnerability remediation used daily by cyber defenders. Anthropic’s “defence in depth” strategy (layered, overlapping security controls designed to make jailbreaks expensive and narrow) was disregarded by the regulator.
Anthropic publicly noted that the exact same capabilities are widely available in competing models, including OpenAI’s GPT-5.5.
The gap between the EO’s collaborative rhetoric and the Commerce Department’s Export Restriction order suggests that foreign access to frontier AI is now conditional, dictated by unilateral security assessments rather than commercial agreements.
CNI and IoT Testing Challenges
For operators of critical national infrastructure (CNI) and global IoT networks outside the United States, the Anthropic suspension triggers an operational challenge. Smart grids in the EU, connected automotive fleets in Japan, and automated logistics hubs in the UK increasingly rely on frontier AI for real-time anomaly detection and code-level vulnerability patching. The June 12 directive shows that these dependencies can be severed without notice, leaving national critical systems blind.
The directive also exposes a personnel crisis for internationalised engineering teams. By explicitly banning access for “foreign nationals”, even those employed by the AI vendor on US soil, the directive makes global API integration legally hazardous. This nationality-based restriction breaks the collaborative model of global cybersecurity testing.
The EO’s creation of the AI Cybersecurity Clearinghouse potentially increases the isolation of US cybersecurity developments. Housed under the US Treasury Department, this clearinghouse is designed to coordinate vulnerability scanning and patch distribution exclusively with US critical infrastructure operators. This has been established as an expressly domestic operation. According to international law firms Hogan Lovells and Mishcon de Reya, the effect of this is to structurally lock out non-US IoT and CNI operators from vulnerability intelligence generated by US frontier models, and deny commercial access to the models themselves.
The result is a widening capability gap where US infrastructure is hardened by AI, while allied infrastructure is starved of the same defensive tooling. This directly complicates compliance with stringent local regulations like the EU’s NIS2 Directive.
In response, foreign capitals are accelerating defensive industrial policies. The UK’s £500 million Sovereign AI Fund and the European Commission’s proposed Cloud and AI Development Act (CADA) are reactions to this structural vulnerability, aiming to subsidise domestic ecosystems before US export controls sever access entirely. These policies will gain additional force as a result of the US Administration’s actions in June.










