US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history
Version 11
2026-06-18 08:27 UTC · 263 items
What
The US Commerce Department has formally placed Anthropic's Fable 5 and Mythos 5 under Bureau of Industry and Security authority, requiring an export license before any international deployment [9]. Both models remain globally disabled. Commerce Secretary Lutnick told Anthropic CEO Dario Amodei "That's the point" when Amodei said the directive meant the models must stay offline [5], and Washington talks concluded without reinstatement [12]. Independent security experts contest the technical basis for the controls; companies are signing backup contracts with non-US AI providers in response [5].
Why it matters
The Lutnick exchange and the concluded talks together establish that reinstatement depends on political accommodation rather than any technical fix. If enterprise customers follow through on reported shifts toward non-US providers, the controls may generate the competitive harm they ostensibly aim to prevent while doing nothing to restrict adversary access to comparable capabilities.
Open questions
What does the BIS licensing process require in practice, and does Lutnick's 'that's the point' mean approval is itself contingent on political rather than technical criteria? [9][5]
Will UK AISI's exclusion from Mythos access, despite its designated US safety-partner status, produce a formal allied-nation diplomatic response? [5][10]
If companies follow through on backup contracts with non-US AI providers [5], what evidence would demonstrate the controls are producing competitive harm rather than preventing security risk?
Does Anthropic challenge the BIS classification legally, pursue the licensing process, or both — and what does either path imply for Nathan Lambert's predicted two-year timeline on comparable open-source restrictions? [14]
Narrative
On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13, affecting US nationals and foreign-national employees alike [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials — conversations that reporting confirms directly preceded the government action, against a company in which Amazon holds a major investment [2][3][4]. That same evening, Lutnick and Amodei spoke directly: when Amodei said the directive meant the models must go offline, Lutnick replied, "That's the point" [5].
Independent expert review has contested the technical basis for the directive. Katie Moussouris, the only outside expert given access to the government's report, described the triggering scenario: researchers used open-source code with known CVEs plus deliberately planted fake vulnerabilities, asked Fable 5 to review the code for security issues (it refused), then asked it to fix the code, and through a multistep manual process converted the output into patch-testing scripts [5]. Moussouris assessed this as "the model working as intended" for cyberdefense [6]; her firm Luta Security published a formal institutional argument that the controls harm US cyber defense [7]. Zvi Mowshowitz reports the behavior provided no meaningful uplift over GPT-5.5 or Opus 4.8 [5]. Wired confirmed that Anthropic had itself acknowledged Mythos 5's dual-use capabilities and had pre-released it to a restricted consortium called Project Glasswing [8].
On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [9]. The US separately refused G7 allies special access [10], and the UK AISI — a designated US safety partner — was shut out of Mythos despite that relationship [5]. Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini met with the Commerce Department on June 15; an administration source framed reinstatement as requiring an "attitude adjustment" rather than any specific technical fix [11]. Washington talks concluded June 16 without the controls being lifted [12]. Multiple press sources and a former deputy White House chief of staff's social media posts confirm the shutdown was at least partly motivated by political hostility toward Anthropic's leadership and culture [5][13].
Two structural critiques have developed around the episode. Zvi Mowshowitz argues the directive is technically ignorant and politically driven, that the jailbreak is replicable on any comparable model, and that US intelligence agencies and Project Glasswing losing Mythos access represents a net harm to national security [13][5]. Nathan Lambert argues the episode opens a governance era defined by technically shallow, politically motivated government action, placing partial blame on Anthropic's nuclear-weapons-comparison rhetoric for accelerating government willingness to act on narrow grounds [14]. Semafor frames Anthropic's predicament as partly self-inflicted, arguing the company miscalculated how to communicate with the Trump administration [15]. Alex Stamos reports companies are already signing backup contracts with non-US AI providers and deploying open-weight models on alternative hardware, treating US government political risk as a standing factor in enterprise planning [5].
Timeline
- 2026-06-11: Developers discover Fable 5 silently routes sensitive prompts to Opus 4.8 rather than refusing; Anthropic reverses the behavior after backlash. [22]
- 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [23][24]
- 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][4]
- 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [13]
- 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [16][17][1]
- 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei "That's the point" when Amodei says the directive means the models must go offline. [5]
- 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
- 2026-06-14: Nathan Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for similar controls within two years. [14]
- 2026-06-14: Just Security argues extending comparable controls to open-source AI models would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [21]
- 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [20]
- 2026-06-15: Zvi Mowshowitz reports the action was partly driven by political grievances and that US intelligence agencies and Project Glasswing lost Mythos access as collateral damage. [13]
- 2026-06-15: Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini meet with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [11]
- 2026-06-16: Cybersecurity expert Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][7]
- 2026-06-16: Anthropic's Washington talks with the Commerce Department conclude without the export controls being lifted. [12]
- 2026-06-16: US refuses to grant G7 allies special access to Fable 5 and Mythos 5. [10]
- 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Dario Amodei requiring a license before international export. [9]
- 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to the demonstrated US government political risk. [5]
- 2026-06-17: Wired confirms Anthropic had acknowledged Mythos 5's dual-use capabilities and pre-released it to restricted consortium Project Glasswing before the directive. [8]
Perspectives
Anthropic
Complying under legal obligation while contesting the directive as technically disproportionate; acknowledged Mythos 5's advanced dual-use capabilities; Washington talks concluded without reinstatement.
Evolution: Consistent on technical contest; the concluded talks and formal BIS letter confirm the path to reinstatement involves political accommodation, not technical remediation.
US Government / Commerce Department
Lutnick placed both models under BIS authority via formal letter to Amodei; his 'that's the point' exchange confirms model suspension is the intended outcome; refused G7 allies and UK AISI access.
Evolution: Escalated from informal directive to formal BIS licensing requirement; Lutnick's exchange makes political intent explicit.
David Sacks (White House AI and Crypto Czar)
Frames the directive as a targeted patch request with a clear reinstatement path; previously accused Anthropic of regulatory capture through safety fear messaging.
Evolution: Consistent; no new statements. His framing sits in direct tension with the Lutnick exchange.
Amazon / Andy Jassy
Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations reporting confirms directly preceded the government action against a company in which Amazon holds a major investment.
Evolution: Consistent; proximate causal role confirmed in prior reporting.
Luta Security / Katie Moussouris
The triggering scenario used deliberately planted fake CVEs, not real threats; assessed the behavior as 'the model working as intended' for cyberdefense; published a formal institutional argument that the controls harm US cyber defense.
Evolution: Consistent; confirmed the code was engineered with fake vulnerabilities, making the government's technical framing directly contestable.
Zvi Mowshowitz
Directive is technically ignorant and politically driven; the jailbreak is replicable on any comparable model; collateral loss of US intelligence agency and Project Glasswing access to Mythos represents a net national security harm; companies' backup contracts with non-US providers are a concrete new competitive harm.
Evolution: Evolved: added specific new documented harms (UK AISI exclusion, industry flight to non-US providers) and a realpolitik recommendation that Anthropic should have complied immediately regardless of the directive's validity.
Nathan Lambert / Semafor
Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for comparable controls within two years; Semafor frames Anthropic's predicament as self-inflicted poor communication strategy rather than irreconcilable differences, and reports the China-linked Mythos access as a distinct government concern.
Evolution: Semafor evolved: explicitly frames the conflict as a communication failure; Lambert consistent.
Tensions
- Anthropic, Moussouris, and Luta Security all assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [6][7][5][16][9]
- Sacks frames the directive as a targeted patch request with a clear reinstatement path; Lutnick's explicit 'that's the point' and the concluded talks with no reinstatement indicate the actual standard is political accommodation rather than any technical fix. [18][5][11][9]
- Semafor argues Anthropic's predicament is self-inflicted due to poor communication strategy; Zvi accepts the communication critique in part but argues the underlying government demands are technically incoherent and cannot be resolved by better messaging. [15][5][13]
- Zvi argues the action was driven partly by political hostility toward Anthropic's leadership and culture; the government's public framing emphasizes national security threat and Chinese model distillation risk as the operative justifications. [5][13][16][20]
- Lambert predicts open-source AI models will face comparable government restrictions within two years; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [14][21]
Sources
- [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
- [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
- [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
- [4] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
- [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
- [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
- [7] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
- [8] "Dangerous" AI models are coming no matter what — Ars Technica AI (2026-06-17)
- [9] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
- [10] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
- [11] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
- [12] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
- [13] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
- [14] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
- [15] 🟡 In the crosshairs — Semafor Technology (2026-06-17)
- [16] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [17] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
- [18] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
- [19] Eight months ago, David Sacks, the White House AI and Crypto Czar publicly accused Anthropic of running a sophisticated … — Milk Road AI Twitter (2026-06-13)
- [20] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
- [21] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
- [22] Some good move by Anthropic — Rohan Paul Twitter (2026-06-11)
- [23] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
- [24] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch