The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 17

2026-06-22 18:33 UTC · 328 items

What

Ten days after the US Commerce Department directed Anthropic to suspend Fable 5 and Mythos 5 for foreign nationals, both models remain offline [20][21]. The BIS export licensing requirement from Commerce Secretary Lutnick [5] and the Pentagon's 'supply chain risk' designation [15] remain formally in place, while President Trump's June 20 statement that he no longer views Anthropic as a national security threat [22] has produced no policy reversal. A Financial Times analysis published June 22 argues Anthropic's own safety rhetoric — measured at 8x the volume of OpenAI's — may have contributed to triggering the ban [13], and Chinese open-weight model GLM-5.2 has emerged as a credible coding-agent alternative during the outage, adding competitive pressure on Anthropic's core revenue base [14].

Why it matters

The formal legal posture is unchanged while the economic consequences compound on two fronts: companies that migrated to non-US AI providers or open-weight models during the outage are making structural decisions that are difficult to reverse, and GLM-5.2's arrival offers the first open-weight model with credible coding-agent performance precisely when Anthropic's flagship models are offline. The FT's self-inflicted framing adds a dimension that complicates Anthropic's reinstatement negotiations.

Open questions

  • Trump stated on June 20 he no longer views Anthropic as a national security threat [22] — does this translate into formal action lifting the BIS licensing requirement and the Pentagon supply chain risk designation [15], or does it remain a public signal without policy follow-through?

  • The FT analysis argues Anthropic's safety rhetoric volume was self-defeating [13] — does Anthropic treat this as a communications lesson that shapes how it engages in reinstatement talks, or does it contest the framing?

  • GLM-5.2 is the first open-weight model Nathan Lambert considers a credible general coding agent, now competitive with Opus 4.5-class models [14] — does its emergence during the outage materially accelerate enterprise migration away from Anthropic, making commercial damage harder to reverse even if reinstatement occurs?

  • A single-sourced report suggests a reinstatement path via benchmark failure-rate tests rather than jailbreak elimination [23] — has this been corroborated, and does it represent a formal administration position or informal signaling?

Narrative

On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations that directly preceded the government action — against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13 [1]. Commerce Secretary Lutnick told Amodei, when Amodei said the directive meant the models must go offline: 'That's the point' [4]. On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [5].

The technical basis for the directive is contested. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities to extract patch-testing scripts through a multistep manual process — as 'the model working as intended' for cyberdefense [6][4]. Luta Security published a formal argument that the controls harm US cyber defense [7]. Zvi Mowshowitz argues the stated reinstatement path of fixing the jailbreak is technically impossible, since vulnerability identification and secure coding cannot be separated [8], and research confirms perfect jailbreak immunity is not achievable for any LLM [9]. An administration source framed reinstatement as requiring an 'attitude adjustment' rather than a specific technical fix [10], multiple sources confirm political hostility toward Anthropic's leadership was a factor [4][11], and Milk Road AI attributes the conflict to Amodei's consistent refusal to allow Claude for lethal applications [12].

A Financial Times analysis published June 22 adds a distinct framing: Anthropic's own sustained safety rhetoric may have contributed to bringing government scrutiny on itself. The FT measured five risk- or restriction-related words per 1,000 in Anthropic's 2026 publications, compared to 0.6 per 1,000 for OpenAI — an 8x disparity — and cited technologists who attribute the ban directly to Anthropic's repeated public warnings about AI's societal risks [13]. Separately, Nathan Lambert's June 22 analysis of GLM-5.2 — a Chinese open-weight model now competitive with Opus 4.5-class models in coding agent workflows — argues that Anthropic's Claude Code revenue, which had driven record growth, faces its first credible open-weight competition precisely during the models' suspension [14]. Lambert warns that if open models face comparable government restrictions, the result would be dangerous concentration of AI capability in a small number of closed providers.

Ten days into the outage, the formal legal posture is unchanged. The Pentagon has labeled Anthropic a 'supply chain risk' effective immediately [15], adding a DoD procurement designation alongside the BIS controls on a distinct legal track. Washington talks concluded June 16 without controls lifted; the US refused G7 allies and UK AISI special access [16][17]. Companies have signed backup contracts with non-US AI providers and deployed open-weight models in response to demonstrated government political risk [4], international teams received no advance warning before access was cut [18], and the refund window for API usage credits has closed [19].

Timeline

  • 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [32][33]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][26]
  • 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [11]
  • 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [24][25][1]
  • 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei 'That's the point' when Amodei says the directive means the models must go offline. [4]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-14: Nathan Lambert argues the episode opens a governance era of technically shallow, politically motivated AI restrictions and warns open-source advocates are unprepared for similar controls within two years. [28]
  • 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [30]
  • 2026-06-15: Anthropic meets with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [10]
  • 2026-06-16: Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][7]
  • 2026-06-16: Anthropic's Washington talks conclude without controls lifted; US refuses G7 allies and UK AISI special access. [16][17]
  • 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Amodei requiring a license before international export. [5]
  • 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [4]
  • 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure coding are inseparable. [8]
  • 2026-06-19: Research confirms perfect jailbreak immunity is not achievable for any LLM, deepening expert consensus that the government's stated fix path has no solution. [9]
  • 2026-06-20: In an Axios interview, President Trump states he no longer views Anthropic as a national security threat, while acknowledging he had held that view 'a week ago.' [22][12]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk' effective immediately, adding a DoD designation alongside the BIS export licensing controls. [15]
  • 2026-06-21: Fable 5 and Mythos 5 remain offline on Day 9; the refund window for API usage credits has closed and international teams received no advance warning when access was cut. [20][21][19][18]
  • 2026-06-22: Financial Times analysis argues Anthropic's safety rhetoric — 5 per 1,000 words vs. 0.6 for OpenAI — may have contributed to triggering the export ban. [13]
  • 2026-06-22: GLM-5.2, a Chinese open-weight model, reaches Opus 4.5-class capability in coding agent workflows, offering the first credible open alternative to Claude Code during the Anthropic outage. [14]

Perspectives

Anthropic

Complying under legal obligation while contesting the directive as technically disproportionate; Washington talks concluded June 16 without reinstatement and the formal BIS letter remains in place.

Evolution: Consistent on technical contest; any reinstatement path involves political accommodation. A single-sourced report of a benchmark-based reinstatement path remains unconfirmed.

Trump / White House

Trump stated on June 20 he no longer views Anthropic as a national security threat; an administration source separately framed reinstatement as requiring an 'attitude adjustment.'

Evolution: Publicly softened from the June 12 national security threat framing, but Trump's statement diverges from Lutnick's formal BIS action and the Pentagon's supply chain designation, with no announced policy change.

Commerce Department / Secretary Lutnick

Escalated from informal directive to formal BIS licensing requirement; 'that's the point' exchange confirms model suspension was the intended outcome; refused G7 allies and UK AISI access.

Evolution: Consistent on enforcement; formal actions remain in place even as Trump's public statements have softened.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' effective immediately, adding a DoD procurement designation alongside the BIS export licensing controls on a distinct legal track.

Evolution: Entered as a new institutional actor on June 21; acts independently of the Commerce BIS controls.

Amazon / Andy Jassy

Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations that directly preceded the government action against a company in which Amazon holds a major investment.

Evolution: Consistent; proximate causal role confirmed.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; published a formal argument that the controls harm US cyber defense.

Evolution: Consistent.

Zvi Mowshowitz

Directive is technically incoherent and politically driven; the stated reinstatement path is technically impossible since vulnerability identification and secure coding are inseparable.

Evolution: Consistent; June 18–19 work sharpened the technical impossibility argument without changing the core critique.

Nathan Lambert / Financial Times / technology and national security observers

Lambert argues the episode opens a governance era of politically motivated AI restrictions and warns GLM-5.2's arrival creates real competitive pressure on Anthropic's Claude Code revenue during the outage; the FT argues Anthropic's own 8x-higher safety rhetoric volume contributed to triggering the ban.

Evolution: Lambert's analysis deepened from a governance-era warning to include specific competitive economic analysis; the FT's self-inflicted framing is new and cuts against Anthropic's posture of disproportionate government overreach.

Tensions

  • Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [6][7][4][24][5]
  • Trump publicly stated he no longer views Anthropic as a national security threat; Lutnick's formal BIS letter of June 17 remains in force and the Pentagon has separately labeled Anthropic a supply chain risk, leaving Trump's public softening and the formal legal posture in divergence. [22][5][12][15]
  • The government's stated reinstatement path requires fixing the jailbreak; Zvi argues this is technically impossible and research confirms perfect jailbreak immunity is unachievable; Lutnick's 'that's the point' exchange and the 'attitude adjustment' framing indicate the actual standard is political accommodation, not a technical bar. [27][4][10][5][8][9]
  • The FT attributes the export ban partly to Anthropic's own safety rhetoric — quantitatively 8x heavier than OpenAI's — framing Anthropic as having contributed to its own predicament; Anthropic and Moussouris frame the directive as disproportionate government overreach with no legitimate technical basis. [13][6][7][24]
  • Zvi and multiple sources argue political hostility toward Anthropic's leadership drove the action; Milk Road AI attributes it to Amodei's refusal on lethal use; the government's public framing emphasizes the jailbreak and Chinese model distillation risk. [4][11][12][24][30]
  • Lambert predicts open-source AI models will face comparable government restrictions within two years and warns this would dangerously concentrate AI power; Just Security argues such extensions would not advance US competitive interests given cheaper Chinese alternatives already in enterprise use. [28][31][14]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  5. [5] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  6. [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  7. [7] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  8. [8] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  9. [9] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
  10. [10] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
  11. [11] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
  12. [12] Trump just told the world that a week ago he considered Anthropic a national security threat (Save this). — Milk Road AI Twitter (2026-06-19)
  13. [13] How Anthropic may have talked itself into an AI export ban — Ars Technica AI (2026-06-22)
  14. [14] GLM-5.2 is the step change for open agents — Interconnects (2026-06-22)
  15. [15] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  16. [16] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
  17. [17] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
  18. [18] RT @PsudoMike: US export control order pulled Fable 5 and Mythos 5 from Canadian teams on hours notice. No warning. No m... — reactive:fable-mythos-export-control (2026-06-20)
  19. [19] Claude Fable 5 + Mythos 5 are STILL offline. Day 9 of the export control ban. The refund window for usage credits closed... — reactive:fable-mythos-export-control (2026-06-21)
  20. [20] JUST IN: Anthropic's Fable 5 and Mythos 5 are still down globally after a US export-control directive — reactive:fable-mythos-export-control (2026-06-21)
  21. [21] 🚨 Day 9 of the CLAUDE FABLE 5 BAN! — reactive:fable-mythos-export-control (2026-06-21)
  22. [22] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  23. [23] The White House and Anthropic may have found the first serious path to restore Mythos and Fable access without pretendin… — Rohan Paul Twitter (2026-06-19)
  24. [24] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  25. [25] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
  26. [26] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
  27. [27] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  28. [28] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
  29. [29] Technology, National Security Leaders Say Anthropic and Trump’s ‘Messy Public Breakup’ Will Harm Both — reactive:fable-mythos-export-control
  30. [30] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
  31. [31] Export Controls on Open-Source Models Will Not Win the AI Race — reactive:fable-mythos-export-control
  32. [32] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
  33. [33] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch