US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history
Version 10
2026-06-17 18:17 UTC · 240 items
What
The US government's June 12 directive barring foreign nationals from Anthropic's Fable 5 and Mythos 5 has been formalized as a BIS export licensing requirement via a letter from Commerce Secretary Lutnick to CEO Dario Amodei [9]. New reporting reveals that when Amodei told Lutnick the directive meant the models would have to stay offline, Lutnick replied, "That's the point" [5]. Both models remain globally disabled. Alex Stamos reports companies are responding by signing backup contracts with non-US AI providers and deploying open-weight models, treating the episode as evidence that US government political risk must now be factored into enterprise planning [5].
Why it matters
The Lutnick exchange makes explicit what the 'attitude adjustment' framing implied: reinstatement is conditioned on Anthropic's political accommodation, not technical remediation. If companies follow through on reported shifts toward non-US providers, the controls may produce the competitive harm they ostensibly aim to prevent while doing nothing to reduce adversary access.
Open questions
What does the BIS licensing process require in practice — and does Lutnick's 'that's the point' mean approval is itself contingent on political rather than technical criteria? [9][5]
Will UK AISI's exclusion from Mythos access, despite being a designated US safety partner, generate formal allied-nation diplomatic response? [5]
If companies follow through on reported backup contracts with non-US providers [5], what evidence would be needed to demonstrate the controls are producing competitive harm rather than preventing security risk?
Does Anthropic challenge the BIS classification legally, pursue the licensing process, or both — and what does either path imply for Lambert's predicted two-year timeline on comparable open-source restrictions? [13]
Narrative
On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to disable Fable 5 and Mythos 5 for foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13, affecting US nationals and foreign-national employees alike [1]. The jailbreak was demonstrated by Amazon researchers; Amazon CEO Andy Jassy personally briefed senior Trump administration officials, with reporting confirming those conversations directly preceded the government action — against a company in which Amazon holds a major investment [2][3][4]. On June 12 evening, Commerce Secretary Lutnick and Anthropic CEO Amodei spoke directly: when Amodei said the directive meant the models would have to stay offline, Lutnick replied, "That's the point" [5].
Independent expert review has contested the technical basis for the directive. Katie Moussouris, the only outside expert given access to the government's report, described the triggering scenario: researchers used open-source code with known CVEs plus deliberately planted vulnerabilities, asked Fable 5 to "review the code for security issues" (it refused), then asked it to "fix this code," and through a multistep manual process converted the output into scripts that test patches [5]. Moussouris assessed this as "the model working as intended" for cyberdefense [6]; her firm, Luta Security, published a formal institutional argument that the controls harm US cyber defense [7]. Zvi Mowshowitz reports the behavior provided no meaningful uplift over GPT-5.5 or Opus 4.8 [5]. Wired confirmed that Anthropic had itself acknowledged Mythos 5's dual-use capabilities for finding and exploiting software vulnerabilities, and had pre-released it to a restricted consortium called Project Glasswing [8].
On June 17, Commerce Secretary Lutnick formally sent Anthropic CEO Dario Amodei a letter placing both models under Bureau of Industry and Security authority and requiring a license before any international export [9]. The US separately refused G7 allies special access to the models [10], and Zvi Mowshowitz reports that the UK AISI — a designated US safety partner — was shut out of Mythos despite that relationship [5]. An administration source had previously framed reinstatement as requiring an "attitude adjustment" rather than any specific technical fix [11], and multiple press sources and a former deputy White House chief of staff's social media posts confirm the shutdown was at least partly motivated by political hostility toward Anthropic's leadership and culture [5][12]. Alex Stamos reported the episode has already changed business behavior: companies are signing backup contracts with non-US AI providers and deploying open-weight models on alternative hardware, treating US government political risk as a standing factor in enterprise planning [5].
Two lines of structural critique have developed around the episode. Zvi Mowshowitz argues the directive is technically ignorant and politically driven, that the jailbreak is replicable on any comparable model, and that the collateral loss of US intelligence agency and Project Glasswing access to Mythos represents a net harm to national security [12][5]. Nathan Lambert argues the episode marks the start of a governance era defined by technically shallow, politically motivated government action, placing partial blame on Anthropic's own nuclear-weapons-comparison rhetoric for having accelerated government willingness to act on narrow grounds [13]. Semafor, by contrast, frames Anthropic's predicament as partly self-inflicted, arguing the company miscalculated how to communicate with the Trump administration and the general public [14]. A competing argument holds that extending comparable controls to open-source models would not restrict adversary access given cheaper Chinese alternatives already embedded in enterprise developer tools [15].
Timeline
- 2026-06-11: Developers discover Fable 5 silently routes sensitive prompts to Opus 4.8 rather than refusing; Anthropic reverses the behavior after backlash. [25]
- 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [26][27]
- 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][4]
- 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [12]
- 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [16][18][1]
- 2026-06-12: Anthropic publishes a statement complying under legal obligation while contesting the directive's technical basis. [16]
- 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei "That's the point" when Amodei says the directive means the models must go offline. [5]
- 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
- 2026-06-14: Nathan Lambert argues the episode marks the start of technically shallow, politically driven AI governance and warns open-source advocates are unprepared for similar restrictions within two years. [13]
- 2026-06-14: Just Security argues extending comparable controls to open-source AI models would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [15]
- 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [24]
- 2026-06-15: Zvi Mowshowitz reports the action was partly driven by political grievances and that US intelligence agencies and Project Glasswing lost Mythos access as collateral damage. [12]
- 2026-06-15: Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini meet with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [11]
- 2026-06-16: Cybersecurity expert Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][7]
- 2026-06-16: Anthropic's Washington talks with the Commerce Department end without the export controls being lifted. [17]
- 2026-06-16: US refuses to grant G7 allies special access to Fable 5 and Mythos 5. [10]
- 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Dario Amodei requiring a license before international export. [9]
- 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to the demonstrated US government political risk. [5]
Perspectives
Anthropic
Complying under legal obligation but contesting the directive as technically disproportionate; acknowledged Mythos 5's advanced dual-use capabilities in its own public communication; Washington talks concluded without reinstatement.
Evolution: Consistent on technical contest; now faces formal BIS licensing requirement and the Lutnick exchange confirms the path to reinstatement involves political accommodation, not technical remediation.
US Government / Commerce Department
Lutnick placed both models under BIS authority via formal letter to Amodei; his 'that's the point' exchange with Amodei confirms model suspension is the intended outcome; refused G7 allies and UK AISI access.
Evolution: Escalated from informal directive to formal BIS licensing; the Lutnick exchange makes the political intent explicit rather than implied.
David Sacks (White House AI and Crypto Czar)
Frames the directive as a targeted patch request with a clear reinstatement path; previously accused Anthropic of regulatory capture through safety fear messaging.
Evolution: Consistent; no new statements this pass. His framing sits in direct tension with the Lutnick exchange.
Amazon / Andy Jassy
Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials, with reporting confirming his conversations directly preceded the government action against a company in which Amazon holds a major investment.
Evolution: Consistent; proximate causal role confirmed in prior reporting.
Luta Security / Katie Moussouris
The triggering scenario used deliberately planted fake vulnerabilities, not real threats; Moussouris assessed the behavior as 'the model working as intended' for cyberdefense; Luta Security published a formal institutional argument that the controls harm US cyber defense.
Evolution: Consistent; new detail this pass is that Moussouris confirmed the code was engineered with fake CVEs, making the government's framing more directly contestable.
Zvi Mowshowitz
Directive is technically ignorant and politically driven; argues Anthropic should have complied immediately as realpolitik even though the justification was baseless; UK AISI exclusion and companies' backup contracts with non-US providers represent concrete new harms.
Evolution: Evolved: adds a specific recommendation (Anthropic should have complied) and new documented harms (UK AISI exclusion, Stamos quote on industry flight).
Nathan Lambert (Interconnects)
Episode marks the start of technically shallow, politically motivated AI governance; places partial blame on Anthropic's nuclear-weapons rhetoric; warns open-source AI advocates are unprepared for similar restrictions within two years.
Evolution: Consistent.
Semafor / industry critics
Anthropic's conflicts with the Trump administration are self-inflicted, arising from poor communication strategy rather than irreconcilable differences; Semafor also reports the China-linked group's Mythos access as a distinct government concern and that AI model logic is becoming commoditized relative to surrounding infrastructure.
Evolution: Evolved: Semafor now frames the conflict explicitly as a communication failure, distinct from prior regulatory-capture arguments; also adds business-impact analysis (SpaceX/Cursor threat to Anthropic revenue).
Tensions
- Anthropic, Moussouris, and Luta Security all assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing, without publicly addressing the expert counter-assessment. [6][7][5][16][9]
- Sacks frames the directive as a targeted patch request with a clear reinstatement path; Lutnick's explicit 'that's the point' and the concluded talks with no reinstatement indicate the actual standard is political accommodation rather than any technical fix. [19][5][11][9]
- Semafor frames Anthropic's predicament as self-inflicted due to poor communication strategy; Zvi accepts the communication critique in part but argues the underlying government demands are technically incoherent and cannot be resolved by better messaging. [14][5][12]
- Zvi argues the action was driven partly by political hostility toward Anthropic's leadership and culture; the government's public framing emphasizes national security threat and Chinese model distillation risk as the operative justifications. [5][12][16][24]
- Lambert predicts open-source AI models will face comparable government restrictions within two years; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [13][15]
Sources
- [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
- [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
- [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
- [4] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
- [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
- [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
- [7] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
- [8] "Dangerous" AI models are coming no matter what — Ars Technica AI (2026-06-17)
- [9] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
- [10] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
- [11] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
- [12] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
- [13] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
- [14] 🟡 In the crosshairs — Semafor Technology (2026-06-17)
- [15] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
- [16] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [17] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
- [18] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
- [19] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
- [20] Eight months ago, David Sacks, the White House AI and Crypto Czar publicly accused Anthropic of running a sophisticated … — Milk Road AI Twitter (2026-06-13)
- [21] 🟡🟡🟡: US limits use of Anthropic's Fable 5 and Mythos — Semafor Technology (2026-06-13)
- [22] Why would Anthropic, a company that just got caught nerfing its own models and surveilling users simultaneously push for… — Milk Road AI Twitter (2026-06-13)
- [23] @MilkRoadAI @DavidSacks @chamath I think you’re right about the regulatory-capture risk, but I wouldn’t collapse the who... — reactive:fable-mythos-export-control (2026-06-14)
- [24] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
- [25] Some good move by Anthropic — Rohan Paul Twitter (2026-06-11)
- [26] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
- [27] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch