US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history
Version 19
2026-06-25 08:16 UTC · 352 items
What
Thirteen days after the US Commerce Department suspended Fable 5 and Mythos 5 for foreign nationals, the formal legal posture remains unchanged — BIS export licensing and Pentagon supply chain risk designation both in place — but two new developments have complicated the picture. Legion LegalTech, a US AI-native litigation company whose workflows the shutdown immediately disrupted, filed a federal lawsuit on June 24 challenging the shutdown order, the first formal judicial challenge to the directive [12]. Zvi Mowshowitz separately reports the NSA itself lost access to Mythos as a collateral effect of the export control, and that NSA red-team results widely cited in the government's justification involved authorized insider tests on air-gapped systems, not external attacker scenarios [11].
Why it matters
The Legion LegalTech lawsuit opens a judicial track that could require the government to defend its technical justification on the record. The NSA losing access to its own classified-use Mythos instance illustrates the practical incoherence of the implementation. Zvi reports a newer, more capable Anthropic model has already completed training [11], confirming the suspension has not affected underlying AI development — only its commercial deployment.
Open questions
Will the Legion LegalTech lawsuit force a public legal defense of the government's technical justification, and are other affected companies likely to join? [12]
Zvi reports NSA red-team results were mischaracterized — the tests involved authorized insider access to air-gapped systems, not external attack [11] — will this be contested in legal proceedings or on the public record?
Trump stated on June 20 he no longer views Anthropic as a national security threat [14], but Lutnick's BIS letter and the Pentagon supply chain designation remain formally in force — does Trump's statement translate into policy action, or does it remain a public signal without follow-through?
A single-sourced report suggested a reinstatement path via benchmark failure-rate tests rather than jailbreak elimination [19] — has this been corroborated as a formal administration position?
Narrative
On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations that directly preceded the government action — against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13 [1]. Commerce Secretary Lutnick told Amodei, when Amodei said the directive meant the models must go offline: 'That's the point' [4]. On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [5].
The technical and political basis for the directive is contested from multiple directions. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities — as 'the model working as intended' for cyberdefense [6][4]. Zvi Mowshowitz argues the stated reinstatement path of fixing the jailbreak is technically impossible, since vulnerability identification and secure coding cannot be separated [7], and research confirms perfect jailbreak immunity is unachievable for any LLM [8]. An administration source framed reinstatement as requiring an 'attitude adjustment' rather than a specific technical fix [9], and multiple sources attribute the action partly to political hostility toward Anthropic's leadership and Amodei's refusal to allow Claude for lethal applications [4][10]. NSA red-team results widely cited as justification — that the model 'broke into classified systems in hours' — involved authorized analysts with physical access to air-gapped systems, not an external attacker scenario [11].
As of June 24, two new fronts have opened. Legion LegalTech, a US-based AI-native litigation company whose core workflows the shutdown immediately disrupted, filed a federal lawsuit against the government over the shutdown order — the first formal judicial challenge to the directive [12]. Separately, Zvi reports the NSA itself lost access to Mythos as a collateral effect of the export controls [11], a consequence that cuts against the government's national security framing. The Pentagon labeled Anthropic a 'supply chain risk' on June 21 [13], adding a DoD procurement designation alongside the BIS controls on a distinct legal track, even as President Trump stated on June 20 he no longer views Anthropic as a national security threat [14] — a public softening with no announced policy follow-through.
Commercial consequences have accumulated through thirteen days of suspension. Companies signed backup contracts with non-US AI providers and deployed open-weight models [4]; international teams received no advance warning before access was cut [15]; the refund window for API usage credits has closed [16]. A Financial Times analysis argues Anthropic's safety rhetoric — measured at 5 per 1,000 words versus 0.6 for OpenAI — contributed to government scrutiny [17], while the Chinese open-weight model GLM-5.2 emerged as a credible coding-agent alternative during the outage [18]. Zvi notes a newer, more capable Anthropic model has already completed training [11], confirming the public-access restriction has not slowed underlying development — while businesses that migrated to alternatives are making structural choices that are difficult to reverse.
Timeline
- 2026-06-12: Anthropic publicly releases Fable 5 and Mythos 5. [30][31]
- 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][24]
- 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [27]
- 2026-06-12: US Commerce Department issues an export control directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [20][22][1]
- 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei 'That's the point' when Amodei says the directive means the models must go offline. [4]
- 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
- 2026-06-15: Anthropic meets with the Commerce Department; an administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [9]
- 2026-06-15: Semafor reports a China-linked group had accessed Mythos before the directive, raising model distillation concerns as a distinct driver of the government's action. [29]
- 2026-06-16: Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][25]
- 2026-06-16: Anthropic's Washington talks conclude without controls lifted; US refuses G7 allies and UK AISI special access. [21][23]
- 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Amodei requiring a license before international export. [5]
- 2026-06-17: Alex Stamos reports companies are signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [4]
- 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure coding are inseparable. [7]
- 2026-06-20: President Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [14][10]
- 2026-06-21: Pentagon labels Anthropic a 'supply chain risk' effective immediately, adding a DoD procurement designation alongside the BIS export licensing controls. [13]
- 2026-06-21: Fable 5 and Mythos 5 remain offline on Day 9; the refund window for API usage credits closes and international teams confirm they received no advance warning when access was cut. [32][33][16][15]
- 2026-06-22: Financial Times analysis argues Anthropic's safety rhetoric — 5 per 1,000 words vs. 0.6 for OpenAI — contributed to triggering the export ban. [17]
- 2026-06-22: GLM-5.2, a Chinese open-weight model, reaches Opus 4.5-class capability in coding agent workflows, offering the first credible open-weight alternative to Claude Code during the outage. [18]
- 2026-06-24: Legion LegalTech files a federal lawsuit against the US government over the Fable 5/Mythos 5 shutdown order, the first formal judicial challenge to the directive. [12]
- 2026-06-24: Zvi Mowshowitz reports the NSA lost its own access to Mythos as a collateral effect of the export control, and that NSA red-team results cited as justification involved authorized insider access to air-gapped systems, not external attack scenarios. [11]
Perspectives
Anthropic
Complying under legal obligation while contesting the directive as technically disproportionate; Washington talks concluded June 16 without reinstatement and the formal BIS letter remains in place.
Evolution: Consistent on technical contest; any reinstatement path involves political accommodation. A single-sourced report of a benchmark-based reinstatement path remains unconfirmed.
Trump / White House
Trump stated on June 20 he no longer views Anthropic as a national security threat; no formal policy change has followed.
Evolution: Publicly softened from the June 12 national security threat framing, but Trump's statement diverges from Lutnick's formal BIS action and the Pentagon's supply chain designation, with the gap unresolved.
Commerce Department / Secretary Lutnick
Escalated from informal directive to formal BIS licensing requirement; 'that's the point' exchange confirms model suspension was the intended outcome; refused G7 allies and UK AISI access.
Evolution: Consistent on enforcement; formal actions remain in place even as Trump's public statements have softened.
Pentagon / Department of Defense
Labeled Anthropic a 'supply chain risk' effective immediately, adding a DoD procurement designation alongside the BIS controls on a distinct legal track.
Evolution: Entered as a new institutional actor on June 21; acts independently of the Commerce BIS controls.
Amazon / Andy Jassy
Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations that directly preceded the government action against a company in which Amazon holds a major investment.
Evolution: Consistent; proximate causal role confirmed.
Luta Security / Katie Moussouris
The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; published a formal argument that the controls harm US cyber defense.
Evolution: Consistent.
Zvi Mowshowitz
The directive was improvised rather than calibrated to specific intelligence, the stated reinstatement path is technically impossible, the NSA lost its own Mythos access as a consequence, and NSA red-team results were mischaracterized as external attack scenarios when they were authorized insider tests on air-gapped systems.
Evolution: Deepened with two specific new claims in his fourth installment: NSA self-harm from the controls and the mischaracterization of red-team evidence; maintains that tail-risk logic can justify precautions without a specific identified threat, while calling the chosen implementation a policy fiasco.
Nathan Lambert / Financial Times
Lambert argues GLM-5.2's emergence creates real competitive pressure on Anthropic's Claude Code revenue during the outage; the FT argues Anthropic's 8x-higher safety rhetoric volume contributed to triggering the ban.
Evolution: Consistent; Lambert's competitive analysis and the FT's self-inflicted framing remain relevant given models are still offline.
Tensions
- Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [6][25][4][20][5]
- Trump publicly stated he no longer views Anthropic as a national security threat; Lutnick's formal BIS letter remains in force and the Pentagon separately labeled Anthropic a supply chain risk, leaving Trump's public statement and the active legal posture unreconciled. [14][5][10][13]
- The government's stated reinstatement path requires fixing the jailbreak; Zvi argues this is technically impossible and research confirms perfect jailbreak immunity is unachievable; Lutnick's 'that's the point' exchange and the 'attitude adjustment' framing indicate the actual standard is political accommodation, not a technical bar. [26][4][9][5][7][8]
- The FT attributes the export ban partly to Anthropic's own safety rhetoric — quantitatively 8x heavier than OpenAI's — framing Anthropic as having contributed to its own predicament; Anthropic and Moussouris frame the directive as disproportionate government overreach with no legitimate technical basis. [17][6][25][20]
- Zvi and multiple sources argue political hostility toward Anthropic's leadership and Amodei's refusal on lethal use drove the action; the government's public framing emphasizes the jailbreak and Chinese model distillation risk. [4][27][10][20][29]
- The government cited NSA red-team results as evidence of the model's danger to classified systems; Zvi argues those tests involved authorized analysts with physical access to air-gapped systems — a materially different threat model — and the NSA itself lost access to Mythos as a collateral consequence of the same controls. [11]
Sources
- [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
- [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
- [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
- [4] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
- [5] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
- [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
- [7] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
- [8] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
- [9] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
- [10] Trump just told the world that a week ago he considered Anthropic a national security threat (Save this). — Milk Road AI Twitter (2026-06-19)
- [11] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
- [12] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
- [13] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
- [14] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
- [15] RT @PsudoMike: US export control order pulled Fable 5 and Mythos 5 from Canadian teams on hours notice. No warning. No m... — reactive:fable-mythos-export-control (2026-06-20)
- [16] Claude Fable 5 + Mythos 5 are STILL offline. Day 9 of the export control ban. The refund window for usage credits closed... — reactive:fable-mythos-export-control (2026-06-21)
- [17] How Anthropic may have talked itself into an AI export ban — Ars Technica AI (2026-06-22)
- [18] GLM-5.2 is the step change for open agents — Interconnects (2026-06-22)
- [19] The White House and Anthropic may have found the first serious path to restore Mythos and Fable access without pretendin… — Rohan Paul Twitter (2026-06-19)
- [20] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [21] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
- [22] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
- [23] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
- [24] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
- [25] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
- [26] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
- [27] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
- [28] Welcome to the AGI era of AI governance — Interconnects (2026-06-14)
- [29] A new Semafor report says the White House partly decided to place export restrictions on Anthropic’s Mythos over concern… — Rohan Paul Twitter (2026-06-15)
- [30] Anthropic releases Claude Fable 5, its most powerful public AI model — reactive:fable-mythos-export-control
- [31] Introducing Claude Fable 5 and Claude Mythos 5 - Claude API Docs — reactive:claude-fable-5-mythos-launch
- [32] JUST IN: Anthropic's Fable 5 and Mythos 5 are still down globally after a US export-control directive — reactive:fable-mythos-export-control (2026-06-21)
- [33] 🚨 Day 9 of the CLAUDE FABLE 5 BAN! — reactive:fable-mythos-export-control (2026-06-21)