US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history
Version 14
2026-06-20 08:15 UTC · 295 items
What
The US Commerce Department placed Anthropic's Fable 5 and Mythos 5 under BIS export licensing requirements on June 17, and both models remain globally disabled [6]. In an Axios interview on June 20, President Trump stated he no longer views Anthropic as a national security threat, walking back a position he acknowledged holding 'a week ago' [16]. An unconfirmed report suggests the White House and Anthropic may have identified a reinstatement path based on benchmark failure-rate tests rather than jailbreak elimination [17]. The government's stated technical rationale — that Anthropic must 'fix' a jailbreak — remains contested by independent experts who assess perfect jailbreak immunity as technically impossible [9][10].
Why it matters
Trump's public statement that he no longer views Anthropic as a national security threat, combined with an unconfirmed reinstatement path via benchmarks, suggests the political impasse may be softening. Whether this translates into formal lifting of BIS controls or remains a public statement without policy follow-through is unresolved. Companies that have already signed backup contracts with non-US AI providers in response to this episode are making structural decisions that are difficult to reverse [5].
Open questions
Trump said in an Axios interview he no longer views Anthropic as a national security threat [16] — does this translate into formal action to lift the BIS licensing requirement, or is it public softening without policy follow-through?
Rohan Paul reported a possible reinstatement path via benchmark-based failure-rate tests [17] — has this been corroborated beyond a single source, and does it represent a formal administration position or informal signaling?
Milk Road AI attributes the core conflict to Amodei's non-negotiable refusal to allow Claude for lethal applications [15] — is the dispute about the jailbreak specifically, about Anthropic's broader use-case restrictions, or both, and which issue must be resolved for reinstatement?
If the export controls are lifted, do companies that signed backup contracts with non-US AI providers reverse those decisions, or has this episode durably shifted enterprise AI procurement strategy [5]?
Narrative
On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations reporting confirms directly preceded the government action — against a company in which Amazon holds a major investment [2][3][4]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13 [1]. Commerce Secretary Lutnick told Anthropic CEO Dario Amodei, when Amodei said the directive meant the models must go offline: 'That's the point' [5]. On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [6].
The technical basis for the directive has been contested by independent experts. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities to extract patch-testing scripts through a multistep manual process — as 'the model working as intended' for cyberdefense [7][5]. Her firm Luta Security published a formal argument that the controls harm US cyber defense [8]. Zvi Mowshowitz argues the government's stated reinstatement path — fix the jailbreak — is technically impossible, since vulnerability identification and secure coding cannot be separated [9]. Research published in June 2026 confirms this: perfect jailbreak immunity is not achievable for any LLM [10]. Washington talks concluded June 16 without the controls being lifted; the US refused G7 allies and the UK AISI special access [11][12].
The political dimension of the dispute is now more explicit. An administration source framed reinstatement as requiring an 'attitude adjustment' rather than any specific technical fix [13], and multiple sources confirm the shutdown was partly motivated by political hostility toward Anthropic's leadership [5][14]. Milk Road AI frames the underlying conflict as Amodei's consistent, non-negotiable refusal to allow Claude to be used for lethal applications [15]. On June 20, in an Axios interview in which reporter Marc Caputo directly asked whether he views Anthropic and Dario Amodei as threats to national security, President Trump said 'Well, not now, but a week ago, maybe' [16] — publicly acknowledging both that he had held that view and that it had changed. An unconfirmed report from June 19 suggested the White House and Anthropic may have identified a reinstatement path based on benchmark failure-rate tests rather than jailbreak elimination [17], potentially material if accurate but sourced only from a single low-attribution tweet. Trump's public softening and the BIS letter Lutnick signed June 17 currently coexist without formal resolution.
Zvi Mowshowitz's capabilities review of Fable 5 (June 19) establishes the technical stakes: Fable 5 achieved state-of-the-art scores on nearly all tested benchmarks, including GPQA Diamond at 94%, and expert users describe the capability jump as the largest since Claude Opus 4.5 [18]. Alex Stamos reported that companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk [5]. Nathan Lambert warned that the episode opens a governance era of technically shallow, politically motivated AI restrictions and that open-source advocates are unprepared for comparable controls within two years [19].
Timeline
- 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [27][28]
- 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][4]
- 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [14]
- 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [20][21][1]
- 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei 'That's the point' when Amodei says the directive means the models must go offline. [5]
- 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
- 2026-06-14: Nathan Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for similar controls within two years. [19]
- 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [24]
- 2026-06-15: Anthropic meets with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [13]
- 2026-06-15: Zvi Mowshowitz reports the action was partly driven by political grievances and that US intelligence agencies and Project Glasswing lost Mythos access as collateral damage. [14]
- 2026-06-16: Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [7][8]
- 2026-06-16: Anthropic's Washington talks conclude without controls lifted; US refuses G7 allies and UK AISI special access. [11][12]
- 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Dario Amodei requiring a license before international export. [6]
- 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [5]
- 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure coding cannot be separated. [9]
- 2026-06-19: Research confirms perfect jailbreak immunity is not achievable for any LLM, deepening expert consensus that the government's stated fix path has no solution. [10]
- 2026-06-19: Zvi Mowshowitz's capabilities review confirms Fable 5 as state-of-the-art across benchmarks and documents classifier false-positive problems on benign queries. [18]
- 2026-06-19: Unconfirmed report suggests the White House and Anthropic may have identified a reinstatement path based on benchmark failure-rate tests rather than jailbreak elimination. [17]
- 2026-06-20: In an Axios interview, President Trump states he no longer views Anthropic as a national security threat, while acknowledging he had held that view 'a week ago.' [16][15]
Perspectives
Anthropic
Complying under legal obligation while contesting the directive as technically disproportionate; Washington talks concluded without reinstatement.
Evolution: Consistent on technical contest; the concluded talks and formal BIS letter confirm any reinstatement path involves political accommodation. Reports of a possible benchmark-based path remain unconfirmed.
Trump / White House
Trump stated in a June 20 Axios interview that he no longer views Anthropic as a national security threat, while acknowledging he had done so 'a week ago'; an administration source separately framed reinstatement as requiring an 'attitude adjustment.'
Evolution: Publicly softened from the June 12 national security threat framing; Trump's statement diverges from the formal BIS licensing action Lutnick signed on June 17, with no announced policy change.
Commerce Department / Secretary Lutnick
Escalated from informal directive to formal BIS licensing requirement; 'that's the point' exchange confirms model suspension was the intended outcome; refused G7 allies and UK AISI access.
Evolution: Consistent on enforcement; his formal actions remain in place even as Trump's public statements have softened.
David Sacks (White House AI and Crypto Czar)
Frames the directive as a targeted patch request with a clear reinstatement path; previously accused Anthropic of regulatory capture through safety fear messaging.
Evolution: Consistent; his framing sits in tension with Lutnick's actions and Zvi's technical assessment that the jailbreak cannot be fixed.
Amazon / Andy Jassy
Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations reporting confirms directly preceded the government action against a company in which Amazon holds a major investment.
Evolution: Consistent; proximate causal role confirmed.
Luta Security / Katie Moussouris
The triggering scenario used deliberately planted fake CVEs on engineered code; assessed the behavior as 'the model working as intended' for cyberdefense; published a formal argument that the controls harm US cyber defense.
Evolution: Consistent.
Zvi Mowshowitz
Directive is technically incoherent and politically driven; the stated reinstatement path is technically impossible since vulnerability identification and secure coding are inseparable; collateral losses represent net national security harm. Fable 5 is the largest capability jump since Opus 4.5, with classifier false-positives on benign queries as a painful but necessary tradeoff.
Evolution: Consistent; June 18–19 work sharpened the technical impossibility argument and added capabilities context without changing the core critique.
Nathan Lambert / Semafor
Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions, with open-source advocates unprepared for comparable controls within two years; Semafor frames Anthropic's predicament as partly self-inflicted and reports China-linked Mythos access as a distinct government concern.
Evolution: Consistent.
Tensions
- Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [7][8][5][20][6]
- Trump publicly stated he no longer views Anthropic as a national security threat; Lutnick's formal BIS letter of June 17 remains in force with no announced reversal, leaving Trump's public softening and the formal legal posture in divergence. [16][6][15]
- Sacks frames the directive as a targeted patch request with a clear reinstatement path; Zvi argues the stated fix is technically impossible and research confirms perfect jailbreak immunity is unachievable for any LLM; Lutnick's 'that's the point' exchange and the administration source's 'attitude adjustment' framing indicate the actual standard is political accommodation, not a technical bar. [22][5][13][6][9][10]
- Zvi argues the action was driven partly by political hostility toward Anthropic's leadership; Milk Road AI attributes it to Amodei's non-negotiable refusal to allow lethal Claude use; the government's public framing emphasizes the jailbreak and Chinese model distillation risk. [5][14][15][20][24]
- Lambert predicts open-source AI models will face comparable government restrictions within two years; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [19][26]
Sources
- [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
- [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
- [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
- [4] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
- [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
- [6] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
- [7] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
- [8] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
- [9] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
- [10] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
- [11] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
- [12] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
- [13] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
- [14] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
- [15] Trump just told the world that a week ago he considered Anthropic a national security threat (Save this). — Milk Road AI Twitter (2026-06-19)
- [16] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
- [17] The White House and Anthropic may have found the first serious path to restore Mythos and Fable access without pretendin… — Rohan Paul Twitter (2026-06-19)
- [18] Claude Fable 5 and Mythos 5: Capabilities — Zvi's AI Roundups (2026-06-19)
- [19] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
- [20] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [21] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
- [22] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
- [23] Eight months ago, David Sacks, the White House AI and Crypto Czar publicly accused Anthropic of running a sophisticated … — Milk Road AI Twitter (2026-06-13)
- [24] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
- [25] 🟡 In the crosshairs — Semafor Technology (2026-06-17)
- [26] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
- [27] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
- [28] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch