Living outside of the US (and EU). I’m in the process of launching an agent assisted automated pentesting and authorized offensive security service. I’m using open weights models to execute the entire audit. So lets for a moment entertain the idea that the US somehow locks open weights. How are they going to stop such audits or actual attackers? A competing service in the US simple won’t be able to execute the same l…
Lawmakers can take into consideration how a law would be enforced (and good ones do), but they don't have to do this, and often do not. Being hard to implement or enforce is just simply not their problem to solve.
Now from a compliance standpoint -- the companies in the US who do business with you must follow what US law requires and if they don't, they can be fined or have the people responsible put into prison. And if people try to do it "in private" anyway, the law can simply require records to be produced.
Ultimately with any law, it comes down to:
* what exactly does the law require?
* how far are regulators willing to go to enforce it?