The Captured Exception
How the State Learned to Govern AI by Prerogative Instead of Law
The Sovereign Who Slumbers
The letter arrived at 5:21 on a Friday evening, which is the hour at which a government does the things it would prefer not to explain. It was June 12, 2026. Three days earlier, Anthropic had released two of the most capable artificial intelligence models ever built. By midnight on the day the letter came, both of them were dark, not in one jurisdiction but everywhere on earth, switched off by the company that made them because the company could see no other way to comply.
The instrument was a single page. It was signed by the Secretary of Commerce and addressed to one man, the chief executive of one firm. It carried no court’s seal. It had survived no hearing, invited no comment, and rested on no published rule that anyone could read in advance and shape their conduct around. It simply informed Anthropic that before any foreign national could be permitted access to the two models, an individually validated export license would be required. Foreign nationals, the letter meant, anywhere, including the company’s own non-citizen engineers sitting at their desks in California. Among the people who would, on the letter’s plain terms, be barred from the most powerful tool their own employer had ever produced was at least one of the field’s most celebrated researchers, a man whose name appears on the founding papers of modern machine learning and who happens not to hold an American passport. There was, the company reported, no realistic way to police nationality user by user in real time. So it did the only thing the letter left available. It turned the models off for the entire world.
Set this beside what the same government had done ten days earlier and the picture acquires its strangeness. On June 2 the President had signed an executive order with a confident, forward-leaning title about promoting advanced artificial intelligence innovation and security. Its operative posture was deregulatory. It established a voluntary framework for engaging with the makers of the most capable models. It tasked the security agencies with quietly benchmarking those models for dangerous capability. And in a clause that reads, in hindsight, almost as a dare, it expressly disclaimed any mandatory governmental licensing, preclearance, or permitting requirement. The state, in writing, declined to govern this technology as a category through general rule. Then, before the ink was dry, it reached into the life of a single company and governed it by hand.
You could call this a contradiction, and the early commentary mostly did. I want to argue the opposite. It is not a contradiction. It is a coherent and very old form of rule, one with a long pedigree and a recognizable internal logic, and the reason it unsettles us is precisely that we had told ourselves we had abolished it. The arrangement is not the rule of law. It is something else that can sit comfortably alongside the rule of law for years, hollowing it from within while leaving the façade intact: the general rule left deliberately undecided, paired with the exception always held in reserve and exercised, when it is exercised at all, against the individual case. The companion to this essay traced how a handful of private laboratories came to exercise functions we used to think only states could exercise. This one asks the reverse question. Given that the parastate now exists, how does the state actually rule it? The answer, I think, is that it has stopped trying to legislate the category and has instead learned to govern by prerogative: by the letter, the designation, the license withheld. The exception is not a failure of the system. The exception has become the system. And whoever commands the exception is, in the only sense that finally matters, the sovereign.
The decision that proves everything
There is a sentence written by a German jurist in 1922 that has the unfortunate quality of explaining far too much. Carl Schmitt opened Political Theology with it, and it has hung over every serious discussion of emergency power for a century since: sovereign is he who decides on the exception. Schmitt was not a man whose company one keeps lightly; his later choices put him on the wrong side of the worst century in human history. But a diagnosis can be true regardless of the diagnostician, and his was true. The claim is not that the sovereign is the one who makes the laws in ordinary times. Plenty of clerks and committees make laws. The claim is that sovereignty reveals itself only at the border, in the moment when the normal order is suspended, because the power to suspend the order is logically prior to the order itself. Anyone can apply a rule. Only the sovereign can decide that the rule does not, today, for this party, apply.
Schmitt’s deeper move was to notice what the liberal theory of law cannot supply on its own. A legal norm can tell you how a decision is to be reached. It can specify procedures, thresholds, the weighing of factors. What it cannot do, from inside itself, is name the one who decides when the norm has run out, when the situation is novel enough or dangerous enough that no existing rule quite reaches it. That gap is not a defect to be patched by writing more rules. It is constitutive. Every legal order, however elaborate, rests finally on a decision that the order itself cannot generate, and the exception is where that decision becomes visible. He compared it, with characteristic provocation, to the miracle in theology: the moment the lawgiver, like the omnipotent God of the deists turned active again, breaks through the crust of routine and acts. In normal times the sovereign slumbers, indistinguishable from the machinery. Then a situation threatens to become an exception, and the sovereign wakes.
Read the two June instruments through this lens and they snap into focus. The voluntary executive order is the norm, and on Schmitt’s account the norm proves nothing; it is the torpid mechanism, the rule repeated until it has gone numb. The letter is the exception, and the exception proves everything, because in it the power of decision breaks through and shows you where it has been resting all along. The order said: we will not require a license. The letter said: you will not deploy without our permission. Both statements issued from the same government in the same fortnight, and they are not in tension, because the first describes the slumber and the second describes the waking. The state declined to bind itself by a general rule precisely so that it would retain, undiminished and uncodified, the freedom to decide each case as a case. To disclaim the licensing regime in public was not to renounce the power to license. It was to keep that power in its purest and most personal form, available on a Friday evening, answerable to no published standard, exercised by name against one firm while its competitors, holding models of comparable capability, were left untouched.
When the exception stops being temporary
If Schmitt tells you where sovereignty lives, his most penetrating modern reader tells you what happens to a polity that begins to live there permanently. Giorgio Agamben, writing in 2005 with the wars of the new century freshly underway, argued that the state of exception had quietly migrated from the margins of constitutional life to its center, becoming the ordinary technique by which contemporary governments, including the democratic ones, conduct their business. The emergency that was once declared, dated, and meant to end had been replaced by a generalized condition of security in which the suspension of the normal order is simply how the order now runs. Agamben had a phrase for the strange status of the acts produced this way: force of law without the law, with the word law itself struck through, a zone where measures that are not statutes nonetheless carry the compelling force of statutes. The letter to Anthropic lives in exactly that zone. It is not a law. It changed the legal universe of its recipient as completely as any law could.
The reason to take Agamben seriously here is not theoretical elegance. It is the arithmetic. Consider the workhorse of American economic statecraft, the International Emergency Economic Powers Act, which lets the President do extraordinary things once a national emergency is declared. By the Congressional Research Service’s own count, as of the autumn of 2025, presidents had invoked that authority to declare seventy-seven national emergencies, of which forty-six were still in force. The very first emergency ever declared under the modern framework, proclaimed by Jimmy Carter in November 1979 in response to the hostage-taking in Tehran, has never been allowed to lapse. It was renewed, for the forty-sixth time, in November 2025, by a president who was in junior high school when it began. An emergency in its fifth decade is not an emergency. It is a form of government wearing the costume of an emergency, and the costume is never removed because the powers it unlocks are too useful to surrender.
There is a detail in this history so apt it could be mistaken for invention. The legal architecture now being turned on artificial intelligence was itself, for seventeen years, held together by precisely this trick. The statute that long governed American export controls lapsed in 2001. Rather than let the entire apparatus of controls expire with it, successive administrations kept the whole system alive by declaring and then annually renewing a national emergency, governing one of the most consequential levers of state power through a fiction of perpetual crisis, until Congress finally gave it permanent footing in 2018 with a law that, pointedly, has no expiration date. The instrument reaching for the off-switch on frontier models was built, brick by brick, out of the very logic Agamben described: the temporary measure that declines to end, the exception that hardens into the standing condition. When people reassure you that the current arrangement is provisional and will soon be regularized, this is the record against which to weigh the promise. The exception has a hundred-year habit of keeping its word in the other direction.
Liberalism’s own confession
It would be too easy, and false, to treat discretionary power as something alien smuggled into the liberal tradition by its enemies. The tradition confessed to it openly, at the founding, in its own scripture. John Locke, whose Second Treatise is as close to a charter document as constitutional liberalism possesses, devoted a chapter to a power he called prerogative, and his definition could be printed on the letter to Anthropic without a word out of place. Prerogative, he wrote, is the power to act according to discretion for the public good without the prescription of the law, and sometimes even against it. Locke did not regard this as a scandal. He regarded it as a necessity, and his reasoning is the steelman that any honest critic of the Anthropic affair must answer first. The legislature, he observed, is too numerous and too slow to foresee every contingency; it cannot be in permanent session, and even if it could, no code drafted in advance can anticipate the case that has not yet arisen. So a latitude is left to the executive to do the things the law has not provided for. His illustration was a house pulled down to stop a fire from spreading through a city: an act plainly outside the letter of the law, plainly justified, plainly something no one would want forbidden in the name of procedural purity.
The administration’s case rests, whether or not it cites him, on Locke’s fire. A novel and dangerous capability, the argument runs, was loose in the world; waiting for notice-and-comment rulemaking while a frontier cyber-weapon circulated would be a kind of suicidal pedantry; the executive must be free to pull down the burning house and sort out the paperwork later. I will take that argument seriously in its place, because it deserves to be taken seriously. But Locke himself supplied the rejoinder, and it is sharper than anything his critics have managed. The danger of prerogative, he warned, is not the bad ruler who abuses it. It is the good ruler who uses it well, because the wise and benign exercise of discretionary power becomes the precedent that a later and worse ruler claims as a matter of right. The reigns of good princes, he wrote, have always been the most dangerous to the liberties of the people, for their successors draw the actions of good rulers into precedent and make them the standard of their prerogative. Grant, for argument, that the model truly was a spreading fire and the Secretary truly was a firefighter. The question Locke forces is the one no emergency ever wants asked. If it was this firm this time, who is it next time, and on whose say-so, and by what warrant that anyone outside the room can ever inspect? Locke’s final consolation was that prerogative is something the people permit and may therefore withdraw, that what is granted can be revoked. Hold onto that thought. The revocability of a privilege is the hinge on which this entire history turns, and we will find it again, much older, in the writ that could dissolve a corporation by asking it a single question.
What law is, and what command is not
To see why the letter is troubling, it helps to be precise about what it is not, and for that we need a working definition of the rule of law that goes beyond the slogan. Three thinkers supply the materials. The Victorian jurist A. V. Dicey gave the tradition its most uncompromising formulation: the rule of law means the supremacy of regular law as against the influence of arbitrary power, and it excludes the existence of arbitrariness, of prerogative, even of wide discretionary authority in the hands of government. Wherever there is discretion, he wrote, there is room for arbitrariness. One can object, rightly, that Dicey’s standard is too pure for any modern administrative state to meet; the welfare and regulatory functions of contemporary government simply cannot run without discretion, and discretion exercised within proper bounds is not the same thing as caprice. That objection is correct and it is also the beginning of the real analysis, because it forces the right distinction. The question is never whether the state may exercise discretion. The question is whether the discretion is structured, published, and reviewable, or secret, individualized, and answerable to no one.
Lon Fuller sharpened the point into something almost diagnostic. Law, he argued, is not simply whatever a powerful office commands; it is an achievement with an internal morality, and there are specific ways to fail at it so completely that the product no longer deserves the name. A regime that issues commands ad hoc rather than through general rules has failed at it. A regime that keeps its rules secret has failed at it. A regime that demands the impossible, or whose rules as administered diverge from the rules as announced, has failed. Run the Anthropic affair against that catalogue and it fails on four counts at once. The directive was aimed at one company rather than a class, which is the failure of generality. Its rationale was never published; the document itself, obtained by reporters, stated no basis for why the restriction was necessary, which is the failure of publicity. Compliance as written was impossible, because no firm can screen its users by nationality in real time, which is why the only available compliance was a global shutdown. And the relation between the rule announced on June 2 and the rule administered on June 12 was one of flat contradiction, a voluntary framework proclaimed and a mandatory license imposed, which is the failure of congruence between word and deed. Friedrich Hayek completes the indictment from the side of liberty. The rule of law, on his account, means a government bound by general, abstract, prospective rules fixed and announced beforehand, so that a person can foresee with fair certainty how the coercive power of the state will be brought to bear and can plan a life accordingly. Its opposite is command directed at particular persons toward particular outcomes. A letter that kills a named product on a Friday with no warning and no stated standard is the pure case of the second thing. Hayek’s own knowledge problem, it is true, cuts both ways and I will not pretend otherwise: a fast-moving frontier technology is exactly the domain where general rules are hardest to write well, and that difficulty is the administration’s strongest card. But the difficulty of writing the rule is an argument for working harder at the rule. It is not a license to govern by hand and call the result security.
The long memory of rule by retraction
None of this is new under the sun, and the historical rhyme is exact enough to be worth dwelling on, because it tells us where such arrangements tend to go. The deepest precedent for a government that suspends a corporation’s most valuable activity by individualized instrument is the Crown’s ancient prerogative to revoke the very charter that gave a corporation its existence. The vehicle was a writ with a beautifully apposite name, quo warranto, meaning by what warrant, a demand that a body show by what authority it dared to exercise its privileges. In the 1680s the English Crown ran a systematic campaign with this writ, and in the archetypal case it brought a quo warranto against the City of London itself and obtained a judgment forfeiting the ancient charter of the capital, stripping the corporation of its liberties until they should be restored on the Crown’s own terms. The campaign reached across the Atlantic; the charter of Massachusetts Bay, which had governed a distant and effectively self-directing colony for half a century, was vacated in 1684, and the autonomous body found that its independence had always been held at the sovereign’s pleasure. This is the precise structure of the letter to Anthropic. Not a general law regulating an industry, but a targeted act of retraction addressed to one body, reaching in to nullify a privilege the body had grown used to treating as its own. It is the quo warranto of the cognitive age, and the question it poses to the laboratory is the same question the writ posed to the City: by what warrant do you operate, and what makes you think the warrant is yours to keep?
The same logic governed expression before the modern free press was born. Governments did not, in those centuries, regulate printing through general laws applied after the fact. They governed it by granting and revoking the privilege to print, person by person and title by title. The English Crown chartered the Stationers’ Company in 1557 and ran censorship through licensing, so that the right to publish was a discretionary grant, conditioned and withdrawn at pleasure; the Licensing of the Press Act of 1662 made prepublication approval the law, and the date that historians treat as the true birth of press freedom is not the passage of any grand statute but 1695, the unglamorous year in which that licensing act was simply allowed to lapse. Milton had attacked the whole apparatus half a century earlier in Areopagitica, and his target was exactly the thing now returning: the governance of expression by prior license rather than by general law enforced afterward. The deepest feature of the Anthropic episode is that it reinstates this regime for the most expression-adjacent technology since the printing press. A model may not be deployed unless the sovereign permits this actor to deploy this artifact. That is prior restraint by license, and the entire arc of liberal modernity was supposed to be the story of its abolition.
The retraction need not even be codified to function. After 1858 the British Raj governed the several hundred princely states that covered something like two fifths of the subcontinent not through general imperial legislation but through a doctrine called paramountcy, under which each state kept its internal autonomy while the Crown reserved the ultimate authority and the right to intervene whenever it judged intervention expedient. The decisive feature, the one worth carrying forward, is that paramountcy was deliberately never defined. Its vagueness was the instrument. An indefinite reserve power can be invoked whenever convenient and challenged whenever never, and a governor-general could observe with satisfaction that the British had by degrees simply become the paramount power, without anyone ever having to say in writing what paramountcy precisely permitted. The relationship between the modern state and the frontier laboratory has this shape exactly. Operational autonomy for the lab in ordinary times; an uncodified, undefined reserve power held by the state; and the exercise of that power, when the moment is deemed expedient, through individualized instruments rather than law. The absence of a definition is not a gap in the arrangement. It is the arrangement.
And the institutionalized exception is older still, old enough to suggest it answers to something permanent in political life. The Romans built a standstill of law into their constitution, a formal suspension of the normal order in emergency, and they appointed a dictator for a strictly bounded term to act outside ordinary constraint for the republic’s preservation. What is striking across that distance is that the Romans bounded the thing: a fixed term, a defined trigger, an exception with edges. The Venetian Council of Ten, founded in 1310 and made permanent within a generation, shows the other tendency, the exception that forgets to end. A small magistracy holding extraordinary and secretive powers over the security of the state, acting fast and outside the ordinary institutions, in the name of the republic’s safety, it lasted not six months but four and a half centuries. A handful of officials acting in secret for the safety of the commonwealth is not a description that requires a Venetian costume to fit. It fits a Friday letter signed by one official and explained to no one perfectly well.
The regime AI is being moved into
All of this would be a literary parlor game if the present case were an aberration. It is not. It is the assimilation of a new domain into an existing regime that was prerogative-heavy from birth, and recognizing the regime tells you what to expect. The export-control system runs on a mechanism that should now sound familiar: the so-called is informed letter, by which the Bureau of Industry and Security imposes a license requirement on a specific party by individualized notice, without notice-and-comment rulemaking, used routinely against semiconductor firms and now, for the first time, against a frontier model. The statute that authorizes all this contains a clause that ought to be read aloud whenever anyone insists the courts remain available as a backstop. By its own terms, the functions exercised under it are exempted from the provisions of the Administrative Procedure Act that govern rulemaking and judicial review alike. Export-control determinations are, by statute, largely insulated from the ordinary mechanisms that let a citizen challenge a government action as arbitrary. The forum in which one would contest the letter has been closed in advance, on purpose. The absence of a place to argue is not an oversight. It is the point.
We have, moreover, run this exact experiment once before, and we know how it ended. In the early 1990s the United States classified strong encryption software as a munition, placing mathematics on the same legal list as missiles, so that a cryptographer who wished to publish his own source code had to contemplate registering as an arms dealer. The government floated a scheme for guaranteed access and abandoned it under fire; it pursued the author of a popular encryption program through a three-year criminal investigation while his supporters, to mock the absurdity, printed his source code as a hardcover book that the First Amendment plainly protected. When a federal appeals panel finally looked hard at the licensing scheme, it described the regime in terms that read today like a forecast: a prepublication licensing system vesting boundless discretion in officials, lacking procedural safeguards, operating as an impermissible prior restraint. The opinion was later withdrawn on procedural grounds and so binds no one, which is a caution worth honoring; but as persuasive history it is devastating, because the controls failed anyway. By the turn of the century encryption had been freed, the munitions classification abandoned, the whole effort remembered as a cautionary tale about trying to lock up math. Classifying software as a weapon does bring it under the prerogative-heavy machinery of the arms trade. It does not, on the evidence, work. Whether artificial intelligence is different in the ways that matter, and what follows if it is, is a question for later in this series. For now the relevant fact is simply that the state reached for this regime, and that the regime has a history.
Which returns us to where we began, and to the claim I want to leave standing before the forensics begin. The pairing that looked like hypocrisy, the voluntary order and the mandatory letter ten days apart, is not hypocrisy and not even tension. It is a single coherent posture with a name as old as government. Decline to decide the general rule, and you preserve the exception in its strongest form. Renounce the licensing regime in public, and you keep the power to license in private, unbounded by any standard you would have to publish and could later be held to. The state has not failed to govern artificial intelligence. It has chosen a mode of governing it, one that the rule-of-law tradition spent centuries trying to abolish: the discretionary writ, the revocable charter, the license granted and withdrawn, the reserve power left undefined so that it need never be justified. We were taught to call the replacement of that mode by general, public, reviewable law one of the central achievements of modern liberty. What the letter of June 12 reveals is that the achievement is being run quietly in reverse, in the domain that may come to matter more than any other, and that almost no one has noticed, because it does not arrive as a coup. It arrives as a Friday evening and a single page. How that page came to be written, and what story its authors tell about why, is where we turn next.
The Letter at 5:21
A government that intends to govern a thing by law leaves tracks. It holds hearings, drafts rules, publishes them for comment, argues about thresholds, and eventually produces a text that anyone affected can read and plan around. A government that intends to govern a thing by prerogative leaves a different kind of track, or rather it leaves an absence where the law should be, and then, at the moment of its choosing, a single decisive act. The remarkable feature of American AI policy across 2025 and into 2026 is how cleanly it produced both: an elaborate, sustained, almost demonstrative refusal to write the general rule, followed by one of the most aggressive single interventions in the history of technology regulation. To read the record as drift or incoherence is to miss what it actually shows. The refusal and the intervention are two halves of one method, and the record lets us watch the method assemble itself in real time.
The renunciation
The decision not to govern artificial intelligence as a category was not an oversight. It was policy, pursued deliberately and defended on principle. The administration that took office in early 2025 moved quickly to strip away what it regarded as the regulatory underbrush, issuing an order that spring whose very title announced the removal of barriers to American leadership in the field, and following it with an action plan built around speed, dominance, and the conviction that the United States would win the race by getting out of its own way. When Congress tried to lock that posture in by forbidding the states from regulating AI for a decade, the moratorium was stripped out of the larger bill on the Senate floor and a later attempt to revive it through the defense authorization died as well, which left the federal government in the peculiar position of having no national rule and actively resisting the state-level rules that were filling the vacuum. By the end of 2025 the administration had escalated that resistance into an order directing the Justice Department to stand up a litigation task force whose purpose was to attack state AI laws it deemed onerous, conditioning federal broadband money on compliance and floating theories under which federal agencies might preempt the states directly. Observers at the Brennan Center noted the obvious limit, that an executive order cannot by itself preempt a state legislature, and described the effort as more bark than bite. The bark, however, was the point. The signal to the industry was unmistakable: the center would not be writing rules, and it would fight anyone else who tried.
Against that backdrop the order of June 2, 2026 reads less as a departure than as a culmination. It carried a title balancing innovation against security, and it rested on three pillars. It directed the strengthening of federal and critical-infrastructure cyber defenses. It instructed the Attorney General to prioritize criminal enforcement against AI-enabled cyberattacks. And, at its center, it established a framework for engaging the makers of the most capable models before release. The decisive word attached to that framework was voluntary. By the first of August the security agencies were to develop a classified process for benchmarking advanced cyber capability and designating which systems counted as covered frontier models, with the head of the National Security Agency holding the pen on the designation; developers would be invited, not required, to give the government a window of pre-release access. An earlier draft had set that window at ninety days. The published order set it at thirty, and the reduction was the negotiated peace between the security hawks who wanted a real preview and the deregulators who wanted as little friction as possible. The framework spoke of selecting trusted partners without ever saying what would make a partner trusted. And in the clause that matters most for everything that followed, the order expressly disclaimed any mandatory governmental licensing, preclearance, or permitting requirement.
The renunciation was understood, by the people who secured it, as a renunciation. The administration’s chief AI adviser had pushed hard to keep the framework voluntary and was candid about why, framing a licensing regime as exactly the kind of arrangement that would let the largest laboratories pull the ladder up behind them and capture their own regulator. Analysts at the Center for Strategic and International Studies observed that the order largely codified practices the leading developers had already adopted on their own, and reported that the administration had briefly weighed a licensing scheme before scrapping it. So the situation on June 2 was clear and deliberate. The state had looked at the option of governing this technology through general, published, mandatory rule, and it had said no, in writing, on purpose. Ten days later it governed one company more forcefully than any licensing regime would have permitted.
The intervention
The model at the center of the affair had been the subject of nervous anticipation for months. A preview build had leaked at the end of March, and the company confirmed what the leak suggested, describing the system in the language of a step change and, internally, as the most powerful thing it had ever made. Through the spring the laboratory had been running a restricted defensive-security program, pairing the model with a few dozen and then well over a hundred partner organizations across more than a dozen countries, turning it loose on real codebases to hunt vulnerabilities, and reporting that the exercise had surfaced many thousands of serious flaws. The framing the company chose for all this was consequential in ways it may not have fully reckoned with. It spoke of its most capable systems as needing something like a cyberweapon regime, as artifacts dangerous enough to warrant controls of a kind ordinarily reserved for armaments.
The public launch came on June 9. The company released two models built on the same underlying system. The general-release version shipped with safeguards that deferred flagged cyber, biological, and chemical queries to a less capable model and reportedly triggered in fewer than one session in twenty; it was given a name drawn from the Latin for a told story. The restricted version, with the safeguards lifted, was confined to the vetted partners of the defensive-security program and to approved critical-infrastructure operators, and it was given a name out of Greek that means very nearly the same thing while sounding far more dangerous. The pairing of names was a piece of theater, the safe twin and the perilous twin, and the theater would shortly be turned against its author. The day after launch the company wrote to a Senate committee alleging that a Chinese rival had run the largest known distillation attack against its systems, tens of thousands of fraudulent accounts conducting tens of millions of exchanges over six weeks to siphon the capabilities of its models, and warning that such theft could vault foreign laboratories toward the frontier. The same day, the company’s chief executive published an essay calling, in effect, for the government to hold the authority to block or reverse the release of models that failed safety testing. Both messages asked the state, in their different registers, to take frontier AI seriously as a matter of national security. The state was about to oblige in a manner no one had requested.
At 5:21 on the evening of Friday, June 12, three days after launch, the letter arrived. It came from the Secretary of Commerce, it was addressed to the chief executive by name, and it informed the company that an individually validated export license would be required before any foreign national could be granted access to either model. It invoked a provision of the export regulations and the emerging-technology authority of the controlling statute, and it reached worldwide, sweeping in not only foreign customers but foreign persons inside the United States, including the company’s own non-citizen staff. Because no firm can verify the nationality of every user of a globally available service in real time, compliance as written was a practical impossibility, and the company did the only thing the letter left open to it, disabling both models entirely, everywhere, before the night was out. Its other systems, the ones not named in the letter, kept running untouched. By one account, which rests on a single source and should be held loosely, the company was given ninety minutes to act and no prior warning that a national-security concern even existed. By another thinly sourced detail too apt not to mention and too unverified to lean on, among those who would be barred from the company’s own flagship model under the nationality rule was one of the most decorated researchers in the field, a man whose passport happened to be the wrong color. Whatever the precise choreography, the substance is not in dispute. A cabinet secretary, by letter, on a Friday evening, switched off two of the most capable cognitive tools on earth, and no court, no rule, and no published reason stood between the decision and its effect.
Four accounts of one event
What actually triggered the letter is the part of the story on which no two narrators agree, and the disagreement is itself instructive, because a government that governs by secret exception produces exactly this fog as a byproduct. There are at least four incompatible accounts, and there is no neutral forum in which to adjudicate among them.
In the first, the trigger was a phone call. Amazon, the laboratory’s largest financial backer, employed researchers who had prodded the restricted model into producing information about a cyberattack that it was supposed to refuse, and the company’s chief executive is said to have carried the alarm directly to the Treasury Secretary, from whom it climbed to Commerce and the national cyber leadership. If that account holds, the firm whose researchers lit the fuse was also the firm with the largest stake in the target, a structural conflict sitting quietly at the center of the affair. In the second account, supplied by the administration’s own AI adviser the next day, a credible partner trusted by both the company and the government had discovered a jailbreak, the government had asked the chief executive to fix the flaw or pull the model, and he had refused, leaving the government to issue its control reluctantly, with the ball, as the adviser put it, now in the company’s court. The same official accused the laboratory of having built a sophisticated strategy of regulatory capture out of fear-mongering, and of valuing its consumer business over the safety it advertised.
The third account belongs to the laboratory, which described the supposed exploit as a narrow and non-universal bypass amounting to little more than asking the model to read a particular codebase and patch its flaws, insisted that the very same capability was freely available from rival models including a comparable system from its chief competitor, said it had received explicit government approval to deploy the model in the first place, and denied flatly that it had refused to fix anything. The competing stories, as one report dryly noted, have not been reconciled. The fourth account is the most deflating of all, and it comes from the security researchers who looked at the underlying evidence. The expert who reviewed the non-public paper at the heart of the matter concluded that it demonstrated no real jailbreak whatsoever, that the researchers had simply asked the safe model to fix open-source code seeded with deliberately planted vulnerabilities, that the model had initially refused and then complied, and that rival models lacking its guardrails would not have needed any bypass to do the same thing. On this reading the dreaded offensive cyberweapon was a defensive code-review tool behaving more or less as designed, and the whole crisis was a guardrail doing its job slightly too well.
Hovering over these was a fifth thread that may or may not have been the real driver, depending on whom you believed: a worry about Chinese access. One outlet reported the controls were linked to fears that the restricted model had reached an entity with ties to Beijing, a concern the company said it had handled weeks earlier on its own by revoking the access in question, which later reporting suggested had actually involved a South Korean firm rather than a Chinese one. The Secretary’s letter was said to cite the risk of diversion to military and intelligence users in countries of concern. The company maintained that Chinese access was never once raised in the conversations about the jailbreak. And presiding over everything was a claim relayed by a senior senator, that the head of the security agency had told him the restricted model broke into nearly all of the government’s classified systems within hours during a security exercise, a claim that dissolved on inspection into something far more ordinary, a defensive red-team finding vulnerabilities by design, which the senator’s office eventually conceded should not be taken at face value. Five threads, no two consistent, and not one of them testable by anyone outside the room where the decision was made. That is not a flaw in the reporting. It is the native condition of governance by secret prerogative, in which the public is left to choose its preferred rumor because the state has furnished no record against which any rumor could be checked.
The anatomy of the act
Strip away the competing narratives and look only at the form of what was done, and the affair becomes a near-perfect specimen of rule by exception rather than rule by law. Consider what the act lacked. It lacked a stated reason: the letter gave no specifics, was never made public, and when reporters obtained it they found that the Secretary had offered no basis at all for why the restriction was necessary. It lacked generality: it was a command addressed to one company rather than a rule binding a class, and analysts noted that there was no framework in the regulations for this particular authority precisely because it had never been used this way before. It lacked equality of application, the feature Dicey thought definitional, since the directive pointedly said nothing about the comparable model sold by the laboratory’s chief rival, nor about the several other systems, foreign and domestic, that could do the same things and were left entirely alone. It lacked any process, because the controlling statute exempts these functions, by its own terms, from the ordinary requirements of notice, comment, and judicial review. It demanded the impossible, since real-time screening by nationality cannot be done, which is why the only available compliance was total shutdown. It contradicted what had been announced, a voluntary framework promised on the second of the month and a mandatory license imposed on the twelfth. It offered no forum, no court order having issued and none being practically available. And it carried, lest anyone mistake its seriousness, the threat of penalty, the Secretary following up days later with a letter, also obtained by reporters, that raised the prospect of criminal and civil sanction.
Set those features side by side and the contradiction at the heart of the month resolves into coherence. The order of June 2 disclaimed mandatory licensing. The letter of June 12 functioned as mandatory licensing in everything but name, obliging the company to route its deployments through the export-licensing apparatus on the strength of an individualized notice. What had been renounced as a general rule was reinstated as a particular command, which is exactly the maneuver the first half of this essay described. This is the return, for the most expression-adjacent technology of our age, of prepublication licensing, the very regime the modern world congratulated itself on having buried in 1695. The critics grasped this immediately, and the sharpest of them put their fingers on the precise wound. One former official, now arguing for rules-based decision-making, called the approach ad hoc, personalized, opaque, and possibly lawless. A scholar of government contracting framed the matter with a precision worth preserving, conceding that the problem was never that the state exercised discretion, since national security demands latitude, and locating the scandal instead in the absence of any meaningful process. That distinction is the whole argument. Discretion structured by published standards and open to review is the ordinary stuff of governance. Discretion exercised in secret, against one named party, by a single official, answerable to no forum, is something the rule-of-law tradition spent centuries learning to refuse.
The cybersecurity profession, which had every reason to welcome aggressive action against a supposed cyberweapon, instead revolted. More than a hundred practitioners, organized by a prominent security executive and including some of the most respected names in the field, signed an open letter arguing that the restricted model was quite good but not uniquely so, that pulling the best capabilities away from defenders while adversaries advanced was itself dangerous, and demanding that any such controls go through a democratic rule-making process rather than a Friday letter. The organizer of that letter said plainly that almost no one in the industry believed there was a factual basis for the action and called it a self-inflicted wound against American AI. A prominent skeptic of the technology, no friend of the laboratories, observed that the move made little sense on the administration’s own stated terms and warned it would frighten investors and drive foreign-born researchers home. A former administration AI official confessed he could not tell whether he was watching a vendetta against one company or simple national-security zeal run amok, and pronounced the whole thing cartoonish. And Congress, to its credit, noticed. A bipartisan group of House members wrote to the Secretary demanding the legal and technical basis for the action and asking whether the interagency and public-notice steps the statute seemed to require had been followed, warning that an action concerning a single model might establish a precedent with implications far beyond it, and setting a deadline of June 26. The deadline came and went. No written justification appeared.
The predicate they built themselves
Here the story turns, and acquires the quality of a tragedy rather than a mere dispute, because the laboratory subjected to the munitions regime was the one that had spent years insisting its products were very nearly munitions. This is the part worth sitting with. The company had built its public identity around danger. It had described its most capable system as too hazardous to release broadly. It had authored an elaborate framework of safety levels modeled, in spirit and sometimes in vocabulary, on the classification of weapons. It had framed frontier models as relevant to weapons of mass destruction and adjacent to cyberweapons. It had lobbied, days before the letter arrived, for the government to hold the power to block unsafe releases. And it had named its two models, the safe and the unsafe, precisely to dramatize how perilous the unsafe one was. A cybersecurity researcher captured the irony in a sentence that deserves to outlive the episode: describe your product as a munition in every press release, and eventually the government takes you at your word. They wrote the legal predicate themselves, he observed, and called it a brand.
This is not a gotcha. It is the deepest structural point in the entire affair. The conceptual scaffolding the laboratory had erected to argue for its own regulation became the scaffolding the state climbed to assert prerogative over it. The administration’s adviser made the point as an accusation, noting that the company had itself promoted the idea that its model was a cyberweapon needing to be regulated as one, and concluding that responsibility for any vulnerability therefore lay with the company. He was, on this narrow point, hard to refute. The move that classified the model as a controlled item and pulled it under the discretionary export regime rhymes exactly with the encryption wars of the 1990s, when the state declared mathematics a weapon and discovered it could not make the classification stick. The difference this time is that the firm supplied the framing itself. It had wanted to be taken seriously as the steward of something dangerous. It succeeded, and the reward for success was a letter on a Friday evening informing it that something so dangerous could not be entrusted to its discretion alone.
Not a one-off
A single dramatic act could be dismissed as an aberration, the product of a particular panic on a particular weekend. What forecloses that comforting reading is the surrounding pattern, which shows the same logic operating before and after, in cooler weather. The friction long predated the letter. Earlier in the year the administration had reportedly directed federal agencies to stop using the laboratory’s models after the company refused Pentagon contract terms, having sought carve-outs that would bar its systems from autonomous weapons and mass domestic surveillance. The Pentagon then took a step ordinarily reserved for foreign adversaries, designating the company a supply-chain risk, barring military use of its models, and obliging defense contractors to certify they were not using them. The company sued to challenge the designation, and the suit was still live when the export letter landed. A senior defense official boasted in the days after the letter that the department had expelled the company from its building for good. And yet, in the peculiar way of these things, the same laboratory remained a fixture of Washington policy circles and the security agency reportedly went on using its models even as another arm of the same government treated it as a hazard. Officials, speaking anonymously, described a company that had failed to honor the spirit of the cyber order and had taken the wrong fork at every junction. The phrase captures the mood precisely, a government that had come to regard one of its most capable suppliers as congenitally untrustworthy and had reached for whatever instrument lay closest to discipline it.
Then came the sequel that revealed the method as method. Within weeks, reporting indicated that the chief rival’s next flagship would be released into limited preview with the federal government approving access customer by customer during the preview window, the very staggered, gated, case-by-case path the first company had used for its restricted model before the suspension. If that reporting holds, and it rests on thin sourcing, the significance is hard to overstate. The state would be governing the entire frontier the same way, not through a published rule binding all developers equally, but through a sequence of individualized, discretionary, revocable access decisions, each one a small act of prerogative, the whole adding up to a regime of permission rather than law. Meanwhile the strategic logic was visibly unraveling in the place it was supposed to help. Chinese laboratories shipped their most capable systems as open weights, one of them launching the day after the letter, citing the American ban as its opening and watching its parent’s stock leap by a third. Usage data told the story of the own-goal in numbers: on one major routing platform, Chinese models had climbed from barely one percent of traffic in late 2024 to roughly half by the spring of 2026, and accounted for the majority of consumption among the most-used systems. Analysts noted that the Chinese models still trailed the American frontier by several months on average, but that the control regime was busily pushing foreign customers toward small open-weight systems they could run on their own hardware, beyond the reach of any letter. In Europe the episode fed a swelling appetite for sovereign capability and the recognition, voiced by legislators across the Atlantic, that sovereignty in this century would be measured in code as much as in cannon. And all of this played out around a company that had filed, that same month, the confidential paperwork for a public offering disclosing an annualized revenue approaching fifty billion dollars and a valuation nearing a trillion, which is to say that the entity switched off by a Friday letter was among the most valuable enterprises ever built.
What the pattern establishes is that the letter was not a spasm. It was an expression of a settled relationship, one the next part of this essay will try to name. The state has not regulated the laboratory in the ordinary sense, with rules and process and a forum for dispute, and it has not left the laboratory free in the way a market actor is free. It has done something older and stranger, holding an undefined reserve power over a body it permits to operate, and reaching in, when it judges the moment to require it, through an instrument addressed to one party and explicable to no one. The forensics are complete. The act was secret, individualized, unreviewable, contradictory of what had just been promised, impossible to comply with by any means short of surrender, and aimed with precision at one firm while its mirror images went untouched. The only question left is what to call a form of rule that looks like this, where it leads, and what it costs a civilization to govern its most consequential technology in the permanent grammar of the exception.
By What Warrant
A relationship can be perfectly real and still have no name in the language we are used to speaking. The thing that happened between the American state and the laboratory on the evening of June 12 is neither of the two relationships our political vocabulary readily supplies. It was not regulation, because regulation means general rules, published in advance, applied to a class, contested in a forum, and subject to review; the letter had none of these properties. It was not the freedom of a market actor either, because a market actor cannot be switched off worldwide by a single official acting on a reason he declines to give. The arrangement falls into the gap between our two familiar categories, and the reason it feels uncanny is that we abolished the thing that used to occupy that gap and then forgot we had ever needed a word for it. The word is suzerainty, and the more exact phrase is discretionary suzerainty: operational autonomy granted to a subordinate body in ordinary times, paired with an ultimate authority reserved entirely to the superior and exercised, when it is exercised at all, through individualized instruments rather than law.
Paramountcy over the parastate
This is the shape of the relationship that earlier centuries called paramountcy, and it fits the laboratory and the state with a precision that should unsettle anyone who believed such arrangements belonged to the past. The imperial power that governed the princely states did not legislate for them. It let them run their own internal affairs and held over them an undefined reserve power, intervening when it judged intervention expedient, and the crucial feature was that the reserve power was deliberately never codified, because its vagueness was exactly what made it useful. An indefinite authority can be invoked whenever convenient and challenged almost never. Replace the princely state with the frontier laboratory and the structure is identical. The lab runs its own affairs, prices its own product, ships its own releases, and operates with all the apparent independence of a private enterprise, right up until the moment the superior power decides the moment requires it, and then a letter arrives and the autonomy turns out to have been provisional all along. The lab is not a citizen-corporation living under the equal protection of general law. It is a licensee holding a privilege that can be suspended by writ, which is the logic that once let a court forfeit the charter of the City of London by asking it to show by what warrant it dared to exercise its liberties.
The companion to this essay argued that the frontier laboratories had come to wield sovereign functions without bearing sovereign obligations, that they had become a kind of parastate operating in the hollow where public authority used to sit. This is the other half of that story, the state’s answer to the parastate, and the answer is not what the optimists hoped for. The optimists hoped the state would domesticate these new powers the way modern states domesticated the railroads and the banks and the broadcasters, by writing them into a framework of public law that bound them and protected them in equal measure. The state did something cheaper and older instead. It declined to write the framework and kept the prerogative, governing the most powerful private actors of the age not as subjects of law but as holders of a revocable license, the way a crown once governed the bodies it had chartered into existence. Call it paramountcy over the parastate. The laboratory exercises sovereign-scale capability; the state exercises a sovereign-scale reserve power over the laboratory; and between them there is no general rule, only the autonomy that lasts until the letter comes.
What the arrangement costs
The objection to all of this cannot be that the state exercised power, since states exist to exercise power, nor even that it acted fast in the face of a perceived danger, since speed is sometimes the whole of wisdom. The objection is to the form, and the form has costs that compound quietly and do not show up on any ledger until they are very large. Begin with the most basic. Law, to be law in any sense the tradition would recognize, must be general, and this was a command aimed at one named party rather than a rule binding a class, which means that everyone else building in the same field learned not what the rules are but only that there are no rules, merely a discretion that might fall on any of them next. Law must be public, and this rationale was secret, never released, offering no evidence that anyone outside the decision could examine or rebut, which converts the citizen from a participant who can read the rule into a supplicant who can only guess at it. Law must be predictable, must let a person foresee with fair certainty how coercive power will be brought to bear so that a life or an enterprise can be planned around it, and after this episode no firm in the sector can foresee anything of the kind, which is why the affair instantly created a new category of business risk, the possibility that any product might be extinguished overnight by an instrument against which there is no defense.
The cost that should trouble us most is the erosion of equality before the law, because it is the one that turns the exception from a blunt instrument into a precise one. The directive fell on a single company and pointedly spared its closest competitor, whose comparable model could do the very same things and went entirely untouched. Selective enforcement is not a flaw in a regime of this kind. It is the regime’s central capability. The power to act against one firm and not its rival is, in itself, a power of discipline, of reward, of steering, a way of shaping an entire industry through the example made of one of its members. A state that can switch off your model and not your competitor’s holds something far more valuable than the ability to regulate you. It holds the ability to decide, case by case and for reasons it need never disclose, who flourishes and who does not. And because the export determinations sit, by the explicit terms of the statute, outside the ordinary machinery of judicial review, and because national-security framing further narrows whatever review remains, the body subjected to this power has no forum in which to argue that it was treated arbitrarily. Its realistic options, as the analysts observed, run to negotiation rather than litigation. The absence of a courtroom is not an unfortunate gap in the design. It is the design. A discretion that could be tested in court would not be a prerogative; it would be a rule with extra steps.
Where it goes
Arrangements of this kind have a history, and the history teaches that they are unstable, that governing licensed bodies by discretionary retraction does not settle into a comfortable permanence but resolves, sooner or later, in one of two opposite directions. The hopeful direction is the one the rule-of-law tradition actually traveled. The cruder uses of the charter-revoking writ did not endure; they provoked a backlash that, after the settlement of 1688, curtailed the prerogative and folded it back under law. The discretionary licensing of the press did not endure either; the licensing act was allowed to lapse in 1695, and the date is remembered as a birthday of press freedom precisely because what ended was the regime of prior permission. On this reading, governing by exception is self-undermining over time, because each visible and arbitrary act generates exactly the constituency that will demand a general, published, reviewable rule to replace the discretion. The early signs of that constituency are already visible in the present case: the bipartisan letter from the legislature demanding the legal basis for the action, the revolt of the cybersecurity profession insisting on a democratic rule-making process, the chorus of critics calling the approach ad hoc and possibly lawless. These are the opening moves of the curtailment, the first tugs toward dragging the prerogative back into the domain of law where Dicey and Fuller and Hayek would have it live.
Against that hopeful arc stands the harder history, and it is the one with the better recent record. The temporary measure that quietly becomes permanent is not the exception to the modern state’s behavior; it is increasingly the rule of it. The emergency economic authority that underwrites this whole apparatus has produced dozens of ongoing emergencies, one of them now renewed across five decades, the crisis of 1979 still legally in force under a president who was a child when it began. The Venetian council that began as an emergency magistracy for the safety of the republic lasted four and a half centuries. On this reading the AI exception does not get domesticated into law at all; it regularizes as exception, hardening into a standing regime of government by letter, useful to the state precisely because its indefiniteness is never resolved. Which direction wins is the open question of the moment, and it is worth being honest that there are at least four ways it could break, not two.
It could break toward domestication, the legislature and the courts forcing the discretion into a general and reviewable form, the pattern of 1695 repeating in a new domain. It could break toward permanence, the paramountcy equilibrium persisting indefinitely because an undefined reserve power is simply too convenient to surrender, the pattern of the perpetual emergency. It could break toward fragmentation and futility, the control regime rendered moot by proliferation, which is the lesson of the encryption wars and deserves its own treatment in a moment. And it could break toward the outcome the title of this essay was chosen to name, the one the others tend to overlook. The exception itself can be captured. The double meaning was deliberate. There is the Schmittian exception, the suspension of the normal order that reveals where sovereignty sits, and there is the captured state of the regulatory economists, the apparatus quietly turned to serve the interests it was meant to constrain. Put the two together and you get the most cynical and perhaps the most likely trajectory of all: a discretionary kill-switch held by the state but aimed, increasingly, by whoever has the access and the money to aim it. The administration’s own adviser accused the laboratory of a sophisticated strategy of regulatory capture, and whatever the truth of that particular charge, the accusation cuts in every direction at once. An incumbent that can persuade the government to switch off a rival’s model has acquired a competitive weapon of a kind no antitrust regime contemplates. With political money already flooding into the field through super-PACs devoted to shaping AI policy, and with the revolving door spinning between the laboratories and the offices that regulate them, the prerogative that looks today like the state disciplining the parastate could become tomorrow the parastate disciplining itself, using the state’s hand to do it. The exception, captured, becomes the most efficient instrument of monopoly ever devised, because it requires no market share and no predatory pricing, only a letter and a reason that need never be shown.
The lesson of the last time
The fragmentation scenario is not speculation, because we have run this experiment before and watched it fail. In the early 1990s the United States classified strong encryption as a munition and tried to control the export of mathematics the way it controlled the export of weapons, and the effort collapsed under the weight of its own absurdity. A cryptographer was investigated for years for releasing code that his supporters then printed as a hardcover book to mock the premise, since no one could plausibly forbid the publication of a book. When a federal appeals panel finally examined the licensing scheme it described it as an impermissible prior restraint vesting boundless discretion in officials, language that reads today like prophecy, though honesty requires noting that the opinion was later withdrawn on procedural grounds and binds no one. The controls were abandoned regardless, the munitions classification lifted, the whole campaign remembered as a parable about the futility of trying to lock up things that are really just information. The through-line from the licensing of the Stationers to the munitions list to the export letter is a single idea wearing different costumes across four centuries, prior restraint by individualized permission, and the idea has a poor record of working once the thing it tries to restrain can be copied.
But the parallel is not exact, and the differences are what make the AI case genuinely uncertain rather than simply doomed to repeat the encryption defeat. A frontier model is not a three-line algorithm that fits on a T-shirt. It is an artifact, a vast set of trained weights produced at enormous cost, and artifacts are harder to scatter to the wind than equations are. More importantly, the state now holds a chokepoint that it never held over encryption, the physical bottleneck of advanced computing hardware, a leverage point that exists in the world of atoms rather than the world of math and cannot be evaded by clever publication. And the thing being controlled is different in kind. The encryption fight was about the export of code. This fight is about the gating of deployment and remote access, about who may run inference against a model sitting on someone else’s servers, and it is genuinely contested whether reaching a model through a programming interface is an export at all in the sense the statute means. There is a serious argument, advanced by careful observers, that there is no export here to restrict, that the legal theory underneath the letter is weaker than its authors would like, which is part of why a separate legislative fix for remote access has been floated to cover the gap the existing law leaves open. So the AI control regime is at once legally weaker than the encryption regime, resting on a contested reading of what an export is, and materially stronger, because the compute chokepoint gives the state a grip on the physical substrate that the cryptographers never had to worry about. Which of those two facts dominates will decide whether this ends in domestication, permanence, or the same futile scatter as last time, and the honest answer is that nobody knows yet.
What it does to a civilization
Step back from the tactics and the scenarios and the question becomes larger and harder. What does it do to a civilization to govern its most consequential technology through prerogative and exception rather than through law? The first thing it does is restore personal rule to the very heart of advanced modernity. We tell ourselves a story about the long arc of political development in which arbitrary power gives way to settled rule, in which the writ and the license and the royal pleasure are gradually replaced by general statutes that apply to everyone alike, and in which the great achievement of the modern constitutional order is precisely that no single official, however senior, can reach into your life and rearrange it on a reason he keeps to himself. The 5:21 sovereign is the negation of that story. An enormous discretionary power, the power to switch off the most capable cognitive tools that have ever existed, has come to rest in the hands of a few officials acting by secret letter, in much the way a small council once acted secretly for the safety of a republic, and the fact that they may be acting in good faith and for genuine public ends does not change the shape of the power, only our present comfort with the people holding it. Locke saw this with terrible clarity three centuries ago. The danger is not the bad ruler who abuses the prerogative. It is the good ruler whose well-meant act becomes the precedent the next and worse ruler claims by right.
The deeper damage is that the erosion arrives without any of the warning signs we are trained to watch for. We expect the rule of law to die, if it dies, in some visible convulsion, a coup, a suspended constitution, tanks in the avenue. What this episode suggests is that it can also die by quiet substitution, the patient replacement of general rule by discretionary command in the one domain that will increasingly matter more than any other, accomplished not through any dramatic seizure but through a voluntary framework announced with fanfare and a mandatory letter sent without one. The rule-of-law tradition was, in large part, the centuries-long labor of replacing the discretionary writ with the general law and the discretionary license with the published rule. The charter-revoking writ was curtailed. The licensing of the press was abolished. These were not small achievements; they were among the load-bearing accomplishments of the modern free order. To govern artificial intelligence by prerogative letter is to run that labor in reverse, to reintroduce the writ and the license for the most powerful and most expression-adjacent technology since the printing press, and to do it so quietly that the reversal attracts a few congressional letters and a professional open letter and otherwise passes almost unremarked. A civilization that governs its most important emerging domain entirely within the state of exception has not necessarily chosen tyranny. But it has chosen to let the exception, rather than the rule, become the place where its most consequential decisions are made, and that is a choice with a direction, and the direction is not toward liberty.
The strongest case for the other side
It would be a failure of nerve to end without putting the opposing case as forcefully as its ablest defenders would, because that case is not weak. They would say, first, that this was not government by exception at all but legitimate and necessary national-security action against a live and specific threat, a frontier system that had been induced to produce dangerous capability, and that to demand notice-and-comment rulemaking while such a thing circulates is to fetishize procedure over survival. They would say, second, that export controls have always worked exactly this way, that the individualized letter is a normal and statutory instrument with decades of precedent behind it, used routinely against chip makers and equipment suppliers, and that there is nothing novel or sinister about reaching for it now. They would say, third, that the combination of a voluntary default and a reserved prerogative for the genuinely dangerous edge case is not abdication paired with arbitrariness but simply intelligent policy, light-touch where it can be and forceful where it must be. They would say, fourth, that the arrangement is temporary and will be regularized, that the benchmarking framework and possible legislation and an international trusted-partners channel are all on their way. And they would say, finally, that to call any of this Schmittian is melodrama, that what we are looking at is mundane administrative discretion dressed up by an essayist in borrowed continental black.
Each of these deserves an answer, and the answers do not require denying the kernel of truth in each. To the first: the trouble was never that the state exercised discretion, since national security demands latitude, but that it exercised discretion with no process at all, and the contested, deflated, possibly nonexistent nature of the threat is exactly what an unreviewable secret procedure is designed to render unfalsifiable, while the sparing of the identical capability in a competitor’s model quietly betrays the security rationale, because a real threat would have argued for controlling the competitor too. To the second: the novelty is real and was conceded even by sober analysts, this being the first use of the emerging-technology authority against a commercial model, with no implementing regulation, a worldwide reach beyond the instrument’s normal scope, and a contested premise about whether remote access is even an export; this was not the routine chip letter. To the third: the contradiction between the voluntary order and the mandatory letter is not a flaw to be explained away but the very structure under examination, a category left ungoverned in general so that it can be governed absolutely in the particular, which is coherent as a form of rule and simply is not the rule of law. To the fourth: the promise that the exception will soon be regularized is the oldest promise the exception makes, and the hundred-year record of temporary emergency powers becoming permanent is the reason to disbelieve it. And to the fifth, the fair concession that keeps this analysis honest: this is a bounded moment within a constitutional order that still functions, where the legislature is asking its questions and the courts remain at least theoretically open, and so the right description is not the collapse of the republic into despotism but something more specific and more insidious, the state of exception as a governing technique colonizing a new and supremely important domain, one Friday letter at a time.
Prerogative either way
There remains the matter of how this particular story ends, and the most important thing to see about the ending is that it does not change the diagnosis. As this is written, the models remain dark, and the betting markets and the hopeful executives expect them to return before long, perhaps within days, perhaps under some newly minted framework for trusted partners that the Secretary has floated but not yet built. Suppose they are right. Suppose the letter is lifted, the models switch back on, the engineers return to their work, and the whole episode recedes into a strange memory of the summer the frontier went briefly dark. It would be natural to read such an ending as vindication, proof that the system corrected itself, that the alarm in these pages was overdone. It would be the wrong reading, and seeing why is the final point. If the models come back, they will come back because the same authority that suspended them by discretion has chosen, by discretion, to restore them. The restoration would not be a right vindicated in a forum. It would be a grant bestowed from above, a permission renewed, which is to say a pardon rather than an acquittal. The power that can give the privilege back on a reason it need not disclose is the identical power that took it away on a reason it never gave, and a privilege that can be returned at pleasure was never anything but a privilege. Prerogative either way.
That is the whole of it, and it is why the frame survives whichever way the affair resolves. The question the old writ posed to the corporation it dissolved was a single devastating question, by what warrant, and the laboratory switched off on a Friday evening has been handed the same question across the centuries. By what warrant does it operate? By the warrant of the state, revocable at the state’s pleasure, governed by no rule it can read and defended in no court it can reach. Whether the warrant is presently revoked or presently restored is a detail of the weather. The climate is the thing, and the climate is one in which the most consequential technology of the age is governed not as the railroads and the banks were eventually governed, by general law that binds the governed and the governor alike, but as the chartered bodies and the licensed printers of an earlier and less free world were governed, by a sovereign who decides the exception and owes no one an account of the decision. The rule of law was the slow triumph over exactly that. We are watching, in the domain that may come to matter most of all, the patient beginning of its undoing, and it does not announce itself with anything so honest as a proclamation. It announces itself with a voluntary framework, and a letter at 5:21 on a Friday, and a question left hanging in the dark. By what warrant. The answer, for now, is the one every prerogative has always given. By mine.





