US AI Regulation Finds Its Footing, but the Ground Keeps Shifting

The Trump administration’s abrupt pivot toward frontier AI controls signals a new regulatory era, but critical gaps in rationale and scope leave security leaders without a stable planning horizon.

AI-generated illustration depicting incident for the story: US AI Regulation Finds Its Footing, but the Ground Keeps Shifting

The Trump administration’s abrupt pivot toward frontier AI controls signals a new regulatory era, but critical gaps in rationale and scope leave security leaders without a stable planning horizon.

Summary

  • The Trump administration reversed its hands-off AI stance, applying export controls to Anthropic’s Fable 5 and Mythos 5 models after private sector threat intelligence reporting.
  • Officials at the Office of the National Cyber Director cite accelerating threat actor speed across all stages of the cyber operations lifecycle as a key driver of concern.
  • Practitioners report genuine defensive value from models like GPT 5.5, alongside real friction: high token consumption, guardrail limitations, and interoperability constraints.
  • The UK’s AI Security Institute estimates open-source and foreign models trail leading US frontier models by only four to seven months, limiting the strategic window that export controls can buy.
  • Former officials acknowledge the administration’s regulatory line is unclear, and is likely to shift again as capabilities and threat intelligence evolve.

A sharp reversal, with little explanation

After spending the better part of 18 months dismantling Biden-era AI safety rules and arguing against industry constraints, the Trump administration applied export controls to Anthropic’s Fable 5 and Mythos 5 models — a move that effectively opened a regulatory era for US commercial AI. The controls followed private sector threat intelligence reporting, but the administration has offered little public explanation of where it drew the line or how it will redraw it. For CISOs trying to build AI governance frameworks with any durability, that ambiguity is itself a risk.

Why officials shifted their view

Will Loucks, senior director of intelligence at the Office of the National Cyber Director, described the underlying dynamic at a Washington event in July. Over the past two years, the number of known and exposed vulnerabilities has climbed sharply. Threat actors are moving through each stage of the cyber operations lifecycle — initial access, lateral movement, impact — more quickly than before. Speaking specifically about AI, Loucks noted that speed and volume can be threatening in their own right, even without a corresponding jump in sophistication, because they compress the time defenders have to triage and respond.

An administration learning on the job

Jordan Rae Kelly, former director for cyber and incident response on the National Security Council during Trump’s first term, described the administration’s early posture as a deliberate rejection of anything that looked like the Biden approach. That produced a permissive environment by instinct rather than analysis. She characterised the subsequent 19 months as an education, as White House officials came to grips with the genuine national security implications of frontier model capabilities. Michael Daniel, former White House cyber coordinator and now head of the Cyber Threat Alliance, puts it more plainly: his members report AI is being used to operate faster and at somewhat larger scale, but the anticipated flood of AI-enabled exploitation has not yet arrived. The question occupying policymakers now is when and how the step changes will occur.

What practitioners are actually seeing

CyberScoop spoke with users of GPT 5.5 and Fable 5 to ground the policy debate in operational experience. Eyal Webber Zvik, chief strategy officer at Cato Networks, said GPT 5.5 is now embedded in the company’s development environment, helping scan codebases for vulnerabilities and prioritising which bugs to patch based on exploitability. John Hopper, vice president of engineering at SpecterOps, tracks how long an AI agent can work autonomously before it fails or goes off task — a metric that directly affects how many agents a single operator can run in parallel. He cautioned against assuming offensive actors automatically benefit more than defenders, noting that AI lowers barriers that have always existed rather than creating fundamentally new threats.

Real friction in the tools

Eran Kinsbruner, vice president of product marketing at Checkmarx, offered a more mixed assessment. GPT 5.5 burns through tokens at a high rate — he described a 26-minute scan of a medium-sized, multi-language code repository that exhausted his token allocation before returning substantive results. He also flagged guardrails that restrict users to scanning local files rather than remote repositories like GitHub, which he said creates practical problems for enterprise-scale development environments. OpenAI did not respond to CyberScoop’s interview request regarding GPT 5.5, though the company has since released GPT 5.6, which it says is more efficient with token use.

The window is narrow

The restricted Mythos and Daybreak models remain unavailable to the general public, but that containment has a shelf life. The UK’s AI Security Institute estimates that open-source and foreign large language models are running roughly four to seven months behind the leading US frontier models. Daniel noted that export controls in this environment are unlikely to buy strategic time measured in years. Limiting access for law-abiding domestic users while causing only a minor delay for adversaries is a trade-off the administration will need to keep reassessing. Kelly acknowledged the administration’s position has merit but conceded that clarity on where the line sits and why has not been achieved.

Why it matters

CISOs now operate in an environment where the regulatory framework governing the AI tools their teams use — and that adversaries exploit — can shift without much notice or clear rationale. The administration’s pivot validates the threat model that frontier AI accelerates offensive operations, but the absence of a stable, explained policy boundary makes vendor risk assessment, procurement planning, and board-level AI governance harder to anchor. At the same time, practitioner accounts confirm that current-generation models deliver genuine defensive value alongside real limitations in token efficiency and interoperability, meaning the case for adopting these tools thoughtfully remains sound even as the policy environment settles.

What to do now

  • Assess which AI tools your organisation uses that may fall within or near current or future export control boundaries, and monitor regulatory developments from the administration closely given the stated likelihood of further shifts.
  • When evaluating frontier AI for security operations, test token consumption at realistic enterprise scale — not just in controlled demonstrations — before committing to production deployment.
  • Review AI agent autonomy settings and operator-to-agent ratios in your environment; the longer an agent runs without human oversight, the greater the operational leverage but also the risk of undetected errors or drift.
  • Document and periodically challenge guardrail configurations in AI security tooling, particularly those that restrict access to remote code repositories, to ensure they reflect actual risk rather than default vendor settings.
  • Engage with threat intelligence sharing groups, such as the Cyber Threat Alliance, to track early signals of AI-enabled exploitation before those capabilities reach mainstream threat actors.

Sources