The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 13

2026-06-19 18:42 UTC · 282 items

What

The US Commerce Department has placed Anthropic's Fable 5 and Mythos 5 under BIS export licensing requirements, keeping both models globally disabled [6]. The government's prior stated reinstatement condition — that Anthropic 'fix' the jailbreak — remains contested by experts who assess perfect jailbreak immunity as technically impossible for any LLM [9][10]. A single unconfirmed report suggests the White House and Anthropic may have identified a reinstatement path based on benchmark failure-rate tests rather than jailbreak elimination [15]. Washington talks concluded without reinstatement [11], and Zvi Mowshowitz's capabilities review confirms Fable 5 as state-of-the-art across benchmarks while noting classifier false-positive problems on benign queries [16].

Why it matters

If the reported benchmark-based approach is genuine, it would replace an impossible technical standard with a measurable one — shifting from 'eliminate jailbreaks' to 'demonstrate acceptable failure rates.' Whether the administration formalizes this or the demand remains political accommodation in technical dress is the central unresolved question. Companies building backup contracts with non-US AI providers in response to demonstrated US government risk are making a structural decision that is difficult to reverse [5].

Open questions

  • Rohan Paul reports a possible reinstatement path via benchmark-based failure-rate tests rather than jailbreak elimination [15] — is this confirmed beyond a single tweet, and does it represent a formal administration position or informal signaling?

  • The government says Fable can return when Anthropic 'fixes' the jailbreak; Zvi argues this is technically impossible [9] and research confirms perfect jailbreak immunity is unachievable for any LLM [10] — does the administration have a specific, measurable standard in mind?

  • Does Anthropic challenge the BIS classification legally, pursue the licensing process, or both — and what does either path imply for Nathan Lambert's predicted two-year timeline on comparable open-source restrictions? [17]

  • If companies follow through on backup contracts with non-US AI providers [5], at what point does the competitive harm become visible enough to affect the policy calculus?

Narrative

On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13, affecting US nationals and foreign-national employees alike [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations reporting confirms directly preceded the government action — against a company in which Amazon holds a major investment [2][3][4]. That evening, Commerce Secretary Lutnick told Anthropic CEO Dario Amodei, when Amodei said the directive meant the models must go offline: "That's the point" [5]. On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [6].

The government's technical basis for the directive has been contested by independent experts. Katie Moussouris, the only outside expert given access to the government's report, described the triggering scenario: researchers used open-source code with deliberately planted fake vulnerabilities, asked Fable 5 to review the code for security issues (it refused), then asked it to fix the code, and through a multistep manual process converted the output into patch-testing scripts [5]. Moussouris assessed this as "the model working as intended" for cyberdefense [7], and her firm Luta Security published a formal argument that the controls harm US cyber defense [8]. Zvi Mowshowitz argues the government's stated reinstatement path — fix the jailbreak — has no technical solution, since the ability to identify security vulnerabilities cannot be separated from the ability to write secure code, and characterizes the directive as "a naked demonstration of power to show who is in control" [9]. Research published in June 2026 confirms the underlying principle: perfect jailbreak immunity is not achievable for any LLM, and frontier models are getting harder but not impossible to jailbreak [10].

Washington talks concluded June 16 without the controls being lifted [11]. The US refused G7 allies special access [12], and the UK AISI — a designated US safety partner — was shut out of Mythos [5]. An administration source framed reinstatement as requiring an "attitude adjustment" rather than any specific technical fix [13], and multiple sources confirm the shutdown was partly motivated by political hostility toward Anthropic's leadership [5][14]. Against this backdrop, an unconfirmed report on June 19 suggested the White House and Anthropic may have identified a reinstatement path based on benchmark-based tests of model failure rates rather than elimination of jailbreaks — a possible shift from a technically impossible standard to a measurable one [15]. This comes from a single low-attribution source and has not been corroborated by other reporting.

Zvi Mowshowitz's capabilities review of Fable 5 published June 19 establishes the technical stakes: Fable 5 achieved state-of-the-art scores on nearly all tested benchmarks, including GPQA Diamond at 94%, RiemannBench at 55%, and Cursor Bench at 72.9%, and expert users describe the capability jump as the largest since Claude Opus 4.5 [16]. The same review notes that Fable 5's content classifiers trigger excessively on benign queries — including the word "cancer" and questions about government employment — routing users to Opus 4.8 instead, a false-positive problem Zvi frames as a painful but necessary tradeoff given the regulatory environment [16].

Timeline

  • 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [25][26]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][4]
  • 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [14]
  • 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [18][19][1]
  • 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei 'That's the point' when Amodei says the directive means the models must go offline. [5]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-14: Nathan Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for similar controls within two years. [17]
  • 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [22]
  • 2026-06-15: Anthropic's Logan Graham, Dave Orr, and Nicholas Carlini meet with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [13]
  • 2026-06-15: Zvi Mowshowitz reports the action was partly driven by political grievances and that US intelligence agencies and Project Glasswing lost Mythos access as collateral damage. [14]
  • 2026-06-16: Cybersecurity expert Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [7][8]
  • 2026-06-16: Anthropic's Washington talks with the Commerce Department conclude without the export controls being lifted. [11]
  • 2026-06-16: US refuses to grant G7 allies special access to Fable 5 and Mythos 5. [12]
  • 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Dario Amodei requiring a license before international export. [6]
  • 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [5]
  • 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure coding cannot be separated. [9]
  • 2026-06-19: Zvi Mowshowitz's capabilities review confirms Fable 5 as state-of-the-art across benchmarks and documents classifier false-positive problems on benign queries. [16]
  • 2026-06-19: Unconfirmed report suggests the White House and Anthropic may have identified a reinstatement path based on benchmark failure-rate tests rather than jailbreak elimination. [15]

Perspectives

Anthropic

Complying under legal obligation while contesting the directive as technically disproportionate; Washington talks concluded without reinstatement.

Evolution: Consistent on technical contest; the concluded talks and formal BIS letter confirm any reinstatement path involves political accommodation. Reports of a possible benchmark-based path are unconfirmed.

US Government / Commerce Department

Lutnick placed both models under BIS authority via formal letter; his 'that's the point' exchange confirms model suspension was the intended outcome; reinstatement framed as requiring an 'attitude adjustment'; refused G7 allies and UK AISI access.

Evolution: Escalated from informal directive to formal BIS licensing requirement. Unconfirmed reports suggest the administration may be open to benchmark-based failure-rate standards rather than jailbreak elimination.

David Sacks (White House AI and Crypto Czar)

Frames the directive as a targeted patch request with a clear reinstatement path; previously accused Anthropic of regulatory capture through safety fear messaging.

Evolution: Consistent; his framing sits in direct tension with Lutnick's exchange and Zvi's technical assessment that the jailbreak cannot be fixed.

Amazon / Andy Jassy

Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations reporting confirms directly preceded the government action against a company in which Amazon holds a major investment.

Evolution: Consistent; proximate causal role confirmed.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code; assessed the behavior as 'the model working as intended' for cyberdefense; published a formal argument that the controls harm US cyber defense.

Evolution: Consistent.

Zvi Mowshowitz

Directive is technically incoherent and politically driven; the stated reinstatement path is technically impossible since vulnerability identification and secure coding are inseparable; collateral losses represent net national security harm. Separately assesses Fable 5 as the largest capability jump since Opus 4.5, with classifier false-positives on benign queries as a painful but necessary tradeoff.

Evolution: Sharpened with June 18 technical argument that the fix path has no solution; June 19 capabilities review adds context on the model at stake without changing his critique of the directive.

Nathan Lambert / Semafor

Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for comparable controls within two years; Semafor frames Anthropic's predicament as self-inflicted poor communication strategy and reports China-linked Mythos access as a distinct government concern.

Evolution: Consistent.

Tensions

  • Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [7][8][5][18][6]
  • Sacks frames the directive as a targeted patch request with a clear reinstatement path; Zvi argues the stated fix is technically impossible and research confirms perfect jailbreak immunity is unachievable for any LLM; Lutnick's exchange and the concluded talks indicate the actual standard is political accommodation. [20][5][13][6][9][10]
  • Semafor argues Anthropic's predicament is self-inflicted due to poor communication strategy; Zvi accepts the communication critique in part but argues the underlying government demands are technically incoherent and cannot be resolved by better messaging. [23][5][14][9]
  • Zvi argues the action was driven partly by political hostility toward Anthropic's leadership and culture; the government's public framing emphasizes national security threat and Chinese model distillation risk as the operative justifications. [5][14][18][22]
  • Lambert predicts open-source AI models will face comparable government restrictions within two years; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [17][24]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
  5. [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  6. [6] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  7. [7] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  8. [8] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  9. [9] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  10. [10] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
  11. [11] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
  12. [12] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
  13. [13] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
  14. [14] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
  15. [15] The White House and Anthropic may have found the first serious path to restore Mythos and Fable access without pretendin… — Rohan Paul Twitter (2026-06-19)
  16. [16] Claude Fable 5 and Mythos 5: Capabilities — Zvi's AI Roundups (2026-06-19)
  17. [17] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
  18. [18] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  19. [19] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
  20. [20] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  21. [21] Eight months ago, David Sacks, the White House AI and Crypto Czar publicly accused Anthropic of running a sophisticated … — Milk Road AI Twitter (2026-06-13)
  22. [22] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
  23. [23] 🟡 In the crosshairs — Semafor Technology (2026-06-17)
  24. [24] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
  25. [25] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
  26. [26] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch