“including their non-American employees” is the part that made me sit up too. That’s basically the government saying “yeah, this can flow through your actual org chart,” not just a neat list of US-incorporated shells, and it makes the whole idea of controlling access feel kind of imaginary in day-to-day practice.
Once you allow that, enforcement turns into vibes + paperwork. Like, are we pretending people won’t just route usage through whoever has credentials and a laptop.
okay so that “authorized to use Mythos 5, including non‑American employees” line is the one that makes my eye twitch — it reads like export controls getting routed through an org chart. If the model access is “domestic” because the company is US-based, but half the people touching it aren’t, that’s… a pretty convenient definition.
I’m not sure what the enforcement even looks like here. Is it just “don’t let accounts log in from outside the US,” or are they treating this like a clearance thing where nationality matters even if you’re sitting in a US office? Because those are wildly different worlds in practice.