Living outside of the US (and EU). I’m in the process of launching an agent assisted automated pentesting and authorized offensive security service. I’m using open weights models to execute the entire audit. So lets for a moment entertain the idea that the US somehow locks open weights. How are they going to stop such audits or actual attackers? A competing service in the US simple won’t be able to execute the same level of audits because many of the models refuse following penetration and offensive security testing instructions. An actual attacker is not going to limit itself to those models either. Why would anyone serious about security then limit itself too.
In the end, as a non-US entity; how would the US even stop me from providing services to US companies in private? Well I have a US LLC now, but the moment they become serious about this it takes me a few weeks to incorporate in HK or SG.
This is a common confusion I see about the law in tech circles.
Lawmakers can take into consideration how a law would be enforced (and good ones do), but they don't have to do this, and often do not. Being hard to implement or enforce is just simply not their problem to solve.
Now from a compliance standpoint -- the companies in the US who do business with you must follow what US law requires and if they don't, they can be fined or have the people responsible put into prison. And if people try to do it "in private" anyway, the law can simply require records to be produced.
Simple. If they put your company on something like the entity list that Huawei is on, nobody is going to work with you, public or private.
The US government can even force non-US banks from other countries to report oversea US citizens' income to the IRS, what makes you think they don't have the power or enforcement method to stop US-based entities from working with you?
I am a small entity, expecting less than $250k in yearly revenue. Somehow I’d be honored to be on that list. I wouldn’t expect to end up there either.
And I could just accept crypto to circumvent any actual regulation, of course that would not be the wording or advice on my service, I’d just disable bank and credit card payments for the US and allow Crypto payments only. That’s how a lot of Chinese and Russian services already operate and have so for over a decade.
Crypto would be convenient as I can even pay my inference in crypto and exchange it to cash at little to no scrutiny while still allowing it to be taxed.
If you're only accepting crypto, you're effectively not serving the US market and the policy would be considered successful.
My main market is still US. Largely US founders with startups and companies.
They can put you on an entity list as mentioned, but their general goal is not to target you or other small businesses but rather larger companies. They don't care about what you do.