The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 12

2026-06-19 02:33 UTC · 272 items

What

The US Commerce Department has placed Anthropic's Fable 5 and Mythos 5 under BIS export licensing requirements, keeping both models globally disabled [9]. The government's stated reinstatement path — that Anthropic should 'fix' the triggering jailbreak — is assessed by independent security experts as technically impossible, since the ability to identify vulnerabilities cannot be separated from the ability to write secure code [8]. Washington talks concluded without reinstatement [12], and Commerce Secretary Lutnick's exchange with Anthropic CEO Dario Amodei confirms model suspension was the intended outcome from the start [5].

Why it matters

The government has offered a reinstatement path that security experts say has no technical solution, meaning compliance effectively requires political accommodation rather than any remediable fix. If enterprises continue building backup contracts with non-US providers in response to demonstrated US government risk, the controls may produce the competitive harm they ostensibly aim to prevent.

Open questions

  • The government says Fable can return when Anthropic 'fixes' the jailbreak; Zvi Mowshowitz argues this is technically impossible [8]. Does the administration have a specific technical standard in mind, or is 'fix the jailbreak' a placeholder for political accommodation?

  • Will UK AISI's exclusion from Mythos access, despite its designated US safety-partner status, produce a formal allied-nation diplomatic response? [5][10]

  • Does Anthropic challenge the BIS classification legally, pursue the licensing process, or both — and what does either path imply for Nathan Lambert's predicted two-year timeline on comparable open-source restrictions? [14]

  • If companies follow through on backup contracts with non-US AI providers [5], at what point does the competitive harm from the controls become visible enough to shift the policy calculus?

Narrative

On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13, affecting US nationals and foreign-national employees alike [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials — conversations that reporting confirms directly preceded the government action, against a company in which Amazon holds a major investment [2][3][4]. That same evening, Lutnick and Amodei spoke directly: when Amodei said the directive meant the models must go offline, Lutnick replied, "That's the point" [5].

Independent expert review has contested the technical basis for the directive. Katie Moussouris, the only outside expert given access to the government's report, described the triggering scenario: researchers used open-source code with deliberately planted fake vulnerabilities, asked Fable 5 to review the code for security issues (it refused), then asked it to fix the code, and through a multistep manual process converted the output into patch-testing scripts [5]. Moussouris assessed this as "the model working as intended" for cyberdefense [6]; her firm Luta Security published a formal institutional argument that the controls harm US cyber defense [7]. Zvi Mowshowitz goes further: the government has said Fable can return when Anthropic fixes the jailbreak, but Mowshowitz argues this path has no technical solution — the ability to identify security vulnerabilities is inseparable from the ability to write secure code — and characterizes the restrictions as "a naked demonstration of power to show who is in control" [8].

On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [9]. The US separately refused G7 allies special access [10], and the UK AISI — a designated US safety partner — was shut out of Mythos despite that relationship [5]. Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini met with the Commerce Department on June 15; an administration source framed reinstatement as requiring an "attitude adjustment" rather than any specific technical fix [11]. Washington talks concluded June 16 without the controls being lifted [12]. Multiple press sources and a former deputy White House chief of staff's social media posts confirm the shutdown was at least partly motivated by political hostility toward Anthropic's leadership and culture [5][13].

Two structural critiques have developed around the episode. Zvi Mowshowitz argues the directive is technically incoherent and politically driven, that the jailbreak is replicable on any comparable model, and that US intelligence agencies and Project Glasswing losing Mythos access — along with companies' shift to backup contracts with non-US AI providers — represents a net harm to national security and US competitiveness [13][5][8]. Nathan Lambert and Semafor approach from a different angle: Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for comparable controls within two years [14]; Semafor frames Anthropic's predicament as partly self-inflicted poor communication strategy, and separately reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct government driver [15][16].

Timeline

  • 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [23][24]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][4]
  • 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [13]
  • 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [17][19][1]
  • 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei "That's the point" when Amodei says the directive means the models must go offline. [5]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-14: Nathan Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for similar controls within two years. [14]
  • 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [16]
  • 2026-06-15: Zvi Mowshowitz reports the action was partly driven by political grievances and that US intelligence agencies and Project Glasswing lost Mythos access as collateral damage. [13]
  • 2026-06-15: Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini meet with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [11]
  • 2026-06-16: Cybersecurity expert Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][7]
  • 2026-06-16: Anthropic's Washington talks with the Commerce Department conclude without the export controls being lifted. [12]
  • 2026-06-16: US refuses to grant G7 allies special access to Fable 5 and Mythos 5. [10]
  • 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Dario Amodei requiring a license before international export. [9]
  • 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [5]
  • 2026-06-17: Wired confirms Anthropic had acknowledged Mythos 5's dual-use capabilities and pre-released it to restricted consortium Project Glasswing before the directive. [18]
  • 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure code writing cannot be separated. [8]

Perspectives

Anthropic

Complying under legal obligation while contesting the directive as technically disproportionate; acknowledged Mythos 5's advanced dual-use capabilities; Washington talks concluded without reinstatement.

Evolution: Consistent on technical contest; the concluded talks and formal BIS letter confirm the path to reinstatement involves political accommodation, not technical remediation.

US Government / Commerce Department

Lutnick placed both models under BIS authority via formal letter; his 'that's the point' exchange confirms model suspension was the intended outcome; the government says Fable can return when Anthropic fixes the jailbreak; refused G7 allies and UK AISI access.

Evolution: Escalated from informal directive to formal BIS licensing requirement; Lutnick's exchange and the stated fix-the-jailbreak reinstatement path both on record.

David Sacks (White House AI and Crypto Czar)

Frames the directive as a targeted patch request with a clear reinstatement path; previously accused Anthropic of regulatory capture through safety fear messaging.

Evolution: Consistent; no new statements. His framing sits in direct tension with Lutnick's exchange and Zvi's technical assessment that the jailbreak cannot be fixed.

Amazon / Andy Jassy

Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations reporting confirms directly preceded the government action against a company in which Amazon holds a major investment.

Evolution: Consistent; proximate causal role confirmed in prior reporting.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs, not real threats; assessed the behavior as 'the model working as intended' for cyberdefense; published a formal institutional argument that the controls harm US cyber defense.

Evolution: Consistent; the fake-CVE detail makes the government's technical framing directly contestable.

Zvi Mowshowitz

Directive is technically incoherent and politically driven; the government's stated reinstatement path (fix the jailbreak) is technically impossible since vulnerability identification and secure coding are inseparable; the restrictions are 'a naked demonstration of power to show who is in control'; collateral losses — UK AISI, US intelligence agencies, enterprise flight to non-US providers — represent net national security harm.

Evolution: Sharpened: adds explicit argument that the fix path has no technical solution and toughens his characterization of the directive's political nature.

Nathan Lambert / Semafor

Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for comparable controls within two years; Semafor frames Anthropic's predicament as self-inflicted poor communication strategy and reports China-linked Mythos access as a distinct government concern.

Evolution: Consistent; Semafor explicitly frames the conflict as a communication failure.

Tensions

  • Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [6][7][5][17][9]
  • Sacks frames the directive as a targeted patch request with a clear reinstatement path; Zvi argues the stated fix is technically impossible since vulnerability identification cannot be separated from secure coding; and Lutnick's 'that's the point' and the concluded talks with no reinstatement indicate the actual standard is political accommodation. [20][5][11][9][8]
  • Semafor argues Anthropic's predicament is self-inflicted due to poor communication strategy; Zvi accepts the communication critique in part but argues the underlying government demands are technically incoherent and cannot be resolved by better messaging. [15][5][13][8]
  • Zvi argues the action was driven partly by political hostility toward Anthropic's leadership and culture; the government's public framing emphasizes national security threat and Chinese model distillation risk as the operative justifications. [5][13][17][16]
  • Lambert predicts open-source AI models will face comparable government restrictions within two years; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [14][22]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
  5. [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  6. [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  7. [7] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  8. [8] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  9. [9] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  10. [10] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
  11. [11] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
  12. [12] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
  13. [13] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
  14. [14] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
  15. [15] 🟡 In the crosshairs — Semafor Technology (2026-06-17)
  16. [16] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
  17. [17] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  18. [18] "Dangerous" AI models are coming no matter what — Ars Technica AI (2026-06-17)
  19. [19] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
  20. [20] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  21. [21] Eight months ago, David Sacks, the White House AI and Crypto Czar publicly accused Anthropic of running a sophisticated … — Milk Road AI Twitter (2026-06-13)
  22. [22] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
  23. [23] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
  24. [24] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch