Thirty Years Ago, Encryption Was a Munition. Now It's the Weights' Turn.
In the early 1990s, encryption software sat in the same legal category as tanks and missiles. Not metaphorically. It was literally on the United States Munitions List under ITAR. Email a friend abroad a program with more than 40-bit encryption and you were, on paper, an arms smuggler. It sounds absurd now. At the time it was a serious national security position, argued by serious people. And in 2026, that same argument has come back wearing different clothes — this time pointed at AI model weights.
One caveat before we start. This isn’t a snapshot of a live debate raging across Hacker News and Reddit this week. I went looking, and the discourse on this particular framing has been quiet lately. So treat what follows as a structural comparison across a thirty-year gap rather than a poll of current opinion. The comparison is the point.
The Crypto Wars: when code was contraband
In 1991, a programmer named Phil Zimmermann wrote an email encryption tool called PGP and released it onto the internet. The US government opened a criminal investigation almost immediately. The theory: the code crossed a border, therefore munitions trafficking. Zimmermann was under investigation for three years.
The response was one of the great acts of legal trolling in tech history. Zimmermann’s allies printed the PGP source code as a book and published it through MIT Press. Exporting software was regulated. Exporting a book was First Amendment–protected speech. Buy the book overseas, scan it, run OCR, recompile. The regulation didn’t have a hole in it so much as it was a hole, and someone had walked through it in front of witnesses.
The courtroom resolution came in 1996 with Bernstein v. United States. Daniel Bernstein, a grad student, wanted to present a cipher he’d written at an academic conference and was told he needed an export license first. He sued. The court found that source code is expression protected by the First Amendment — the origin of the “code is speech” principle. By 2000, US encryption export controls were effectively dismantled. Every HTTPS connection you make and every end-to-end encrypted message you send is downstream of that fight.
2026: are weights speech, or are they cargo?
The structure of today’s argument is uncannily familiar.
The control case: a frontier model’s weights are billions of dollars of compute and data compressed into a file. Let them propagate freely and you lose any ability to prevent bioweapon design assistance or industrial-scale cyber operations. The US has spent years restricting semiconductor equipment exports on exactly this logic — weights, the argument goes, are the strategic good those machines exist to produce.
The opposing case is Bernstein’s descendants. Weights are an array of numbers. A file. Copying is free, and the architecture can be described in a paper. Drawing a border around that is the same wall PGP walked through with a printing press. And the practical objection lands harder: open-weight models have already been downloaded millions of times, mirrored across every continent. You’re not preventing spread. You’re proposing to un-spill milk.
Three ways the analogy breaks
I want to push back on my own framing here, because the differences are real and they matter.
Encryption was defensive. Every copy of PGP that spread made an individual harder to surveil. The thing the government lost was interception capability. Citizen versus state, clean and legible. AI models are not like that. The same weights that harden a defender’s SOC help an attacker write the payload. The crypto-era claim — the wider it spreads, the safer everyone gets — does not port over cleanly.
Reproduction cost is wildly different. The RSA algorithm was short enough to print on a T-shirt, and people did, as protest. Any competent programmer could reimplement it. Frontier weights require tens of thousands of GPUs and a power budget that shows up on a regional grid. That means export controls actually sit on a physical chokepoint. The main reason crypto controls failed was that anyone could rebuild the banned thing from scratch. That condition doesn’t hold today.
There’s no bit-length equivalent. Crypto rules had a crisp, if arbitrary, dial: 40 bits fine, 128 bits forbidden. Where do you set the dial for AI? Parameter count stopped tracking capability years ago. Training-compute thresholds — the current favorite — decay every time someone publishes an efficiency win, and they publish constantly. Any line you draw starts going stale the day you draw it.
What the history actually teaches
So does that make the controls justified? Here’s my read: the real lesson of the Crypto Wars isn’t “regulation bad.” It’s narrower and more useful — when you try to put border controls on information that propagates freely, the industry you damage most reliably is your own.
Through the 1990s, American companies had to build deliberately weakened export versions of their own products. European and Israeli security firms grew into exactly that gap, selling strong crypto to customers US vendors were barred from serving properly. After 2000, US firms took the market back. But they paid for the detour in years and revenue.
The open-weight ecosystem could rhyme. If US labs are constrained from releasing open models, the gap doesn’t stay empty — it fills with weights from jurisdictions outside the regime, and today that means Chinese and European releases that developers will happily build on. The dangerous applications don’t disappear. The center of gravity of the developer ecosystem just relocates, and it tends not to come back quickly.
The takeaway
Thirty years ago the question was whether you can stop information at a border, and we got something close to an answer. But AI is more expensive, more ambiguous, and genuinely dual-use in a way ciphers never were. Confidently applying the old answer to the new question is its own kind of mistake.
So: are model weights expression, or are they cargo? Whatever you decide today, the more interesting question is whether your answer survives five more years of falling training costs.
Deepen your perspective
Comments
Loading comments...