The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 21

2026-06-27 02:30 UTC · 369 items

What

Two weeks after the US Commerce Department suspended Fable 5 and Mythos 5 for foreign nationals, the formal legal posture — BIS export licensing and a Pentagon supply chain designation — remains unchanged. The story expanded on June 25 when Anthropic disclosed that Alibaba ran the largest model-cloning campaign it has ever detected against Claude, generating more than 28.8 million exchanges via ~25,000 fraudulent accounts between April and June [16]. Legion LegalTech's federal lawsuit, filed June 24, remains the only formal judicial challenge to the directive [14]. Economist Dean W. Ball separately argues that US export restrictions shrink the AI services market below what $100B-scale data center investments require [17].

Why it matters

The Alibaba cloning disclosure places Anthropic in a structurally complex position: it is contesting the government's jailbreak-based justification for the shutdown while simultaneously providing evidence that Chinese operators extracted Claude's capabilities at scale — which partially supports the government's broader China-threat framing. If export restrictions extend or harden, Ball's economic argument suggests the commercial math for frontier AI infrastructure breaks down at the national level [17].

Open questions

  • Will Anthropic's Alibaba cloning evidence shift Congressional or administration framing — vindicating China-threat concerns while potentially separating them from the specific jailbreak justification for the shutdown? [16]

  • Will the Legion LegalTech lawsuit require the government to defend its technical justification on the record, and are other affected companies likely to join? [14]

  • Trump stated on June 20 he no longer views Anthropic as a national security threat [7], but Lutnick's BIS letter and the Pentagon's supply chain designation remain in force — does that statement translate into formal policy action?

  • Is the actual reinstatement standard a technical bar (fixing the jailbreak, which multiple experts say is impossible [9][10]) or political accommodation ('attitude adjustment' [11])?

Narrative

On June 12, 2026, the US Commerce Department issued a directive requiring Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon researchers demonstrated the jailbreak, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations that directly preceded the government action — against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13. When CEO Dario Amodei told Commerce Secretary Howard Lutnick the directive meant the models would have to go offline, Lutnick replied: 'That's the point' [4]. On June 17, Lutnick formally sent Amodei a BIS letter placing both models under export licensing requirements [5]. On June 21, the Pentagon separately labeled Anthropic a 'supply chain risk' [6] — even as President Trump stated the day before that he no longer views Anthropic as a national security threat [7], a public softening with no formal policy follow-through.

The technical and political basis for the directive is contested from multiple directions. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities — as 'the model working as intended' for cyberdefense [8][4]. Zvi Mowshowitz argues the stated reinstatement path of fixing the jailbreak is technically impossible, since vulnerability identification and secure coding cannot be separated [9], and research confirms perfect jailbreak immunity is unachievable for any LLM [10]. An administration source framed reinstatement as requiring an 'attitude adjustment' rather than a specific technical fix [11], and multiple sources attribute the action partly to political hostility toward Anthropic's leadership and Amodei's refusal to allow Claude for lethal applications [4][12]. NSA red-team results widely cited as justification involved authorized analysts with physical access to air-gapped systems, not an external attacker scenario — and the NSA itself lost access to Mythos as a collateral effect of the controls [13].

Legion LegalTech, a US-based AI-native litigation company whose core workflows the shutdown disrupted, filed a federal lawsuit against the government on June 24 — the first formal judicial challenge to the directive [14]. Commercial consequences have accumulated through the suspension: companies signed backup contracts with non-US AI providers and deployed open-weight models [4]; the Chinese open-weight model GLM-5.2 reached Opus 4.5-class capability in coding agent workflows during the outage [15]; and businesses that migrated to alternatives are making structural choices that are difficult to reverse.

A separate development has complicated the political picture. Anthropic disclosed in a confidential letter to Senators Tim Scott and Elizabeth Warren on June 10 — the day before a Senate hearing on AI — that Alibaba and Alibaba Qwen generated more than 28.8 million exchanges with Claude through nearly 25,000 fraudulent accounts between April 22 and June 5, targeting capabilities including agentic reasoning, software engineering, and long-horizon tasks [16]. Anthropic calls it the largest model-cloning campaign it has ever measured and is calling publicly for Alibaba to be punished. This places Anthropic in an awkward position: contesting the government's jailbreak-based justification for the shutdown while providing evidence that Chinese operators were extracting Claude's capabilities at scale — which partially supports the government's broader China-threat framing even if the specific triggering incident remains disputed. Economist Dean W. Ball separately argues that US export restrictions shrink the total addressable market for AI services below what is needed to justify $100B-scale data center investments, framing the controls as a structural threat to the US frontier AI buildout [17].

Timeline

  • 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, ultimately generating 28.8 million exchanges via ~25,000 fraudulent accounts through June 5. [16]
  • 2026-06-10: Anthropic sends a confidential letter to Senators Tim Scott and Elizabeth Warren disclosing the Alibaba cloning campaign, the day before a Senate AI hearing. [16]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials whose conversations directly preceded the government action. [2][3][22]
  • 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [25]
  • 2026-06-12: US Commerce Department issues an export control directive requiring suspension of Fable 5 and Mythos 5 for all foreign nationals, citing the classifier-based jailbreak. [18][20][1]
  • 2026-06-12: Commerce Secretary Lutnick tells Anthropic CEO Amodei 'That's the point' when Amodei says the directive means the models must go offline. [4]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-15: An administration source says reinstatement requires an 'attitude adjustment' rather than a specific technical fix. [11]
  • 2026-06-16: Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [8][23]
  • 2026-06-16: Anthropic's Washington talks conclude without controls lifted; US refuses G7 allies and UK AISI special access. [19][21]
  • 2026-06-17: Commerce Secretary Lutnick sends a formal BIS letter to Anthropic CEO Amodei requiring a license before international export. [5]
  • 2026-06-17: Companies begin signing backup contracts with non-US AI providers and deploying open-weight models in response to demonstrated US government political risk. [4]
  • 2026-06-18: Zvi Mowshowitz argues the government's stated reinstatement path — fixing the jailbreak — is technically impossible, since vulnerability identification and secure coding are inseparable. [9]
  • 2026-06-20: President Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [7][12]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation alongside the BIS export licensing controls. [6]
  • 2026-06-22: GLM-5.2, a Chinese open-weight model, reaches Opus 4.5-class capability in coding agent workflows, offering the first credible open-weight alternative to Claude Code during the outage. [15]
  • 2026-06-24: Legion LegalTech files a federal lawsuit against the US government over the shutdown order, the first formal judicial challenge to the directive. [14][26][27]
  • 2026-06-24: Zvi Mowshowitz reports the NSA lost its own Mythos access as a collateral effect of the export control, and that NSA red-team results cited as justification involved authorized insider access to air-gapped systems, not external attack. [13]
  • 2026-06-25: Anthropic publicly calls for punishment of Alibaba, describing the 28.8-million-exchange cloning campaign as the largest capability-extraction operation it has ever measured. [16]
  • 2026-06-26: Economist Dean W. Ball argues US export restrictions shrink the AI services market below what $100B-scale data center investments require, framing the controls as a structural commercial threat. [17]

Perspectives

Anthropic

Complying under legal obligation while contesting the directive as technically disproportionate; separately calling for punishment of Alibaba for the largest model-cloning campaign Anthropic has ever measured.

Evolution: The Alibaba disclosure adds an advocacy dimension that partially reinforces the government's China-threat framing even as Anthropic disputes the specific jailbreak justification — a structural tension in its own public position.

Trump / White House

Trump stated on June 20 he no longer views Anthropic as a national security threat; no formal policy change has followed.

Evolution: Publicly softened from the June 12 national security threat framing, but that statement diverges from Lutnick's formal BIS action and the Pentagon's supply chain designation, with the gap unresolved.

Commerce Department / Secretary Lutnick

Escalated from informal directive to formal BIS licensing requirement; 'that's the point' exchange confirms model suspension was the intended outcome; refused G7 allies and UK AISI access.

Evolution: Consistent on enforcement; formal actions remain in place even as Trump's public statements have softened.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' effective immediately, adding a DoD procurement designation alongside the BIS controls on a distinct legal track.

Evolution: Entered as a new institutional actor on June 21; acts independently of the Commerce BIS controls.

Amazon / Andy Jassy

Amazon researchers identified and demonstrated the jailbreak; Jassy personally briefed administration officials in conversations that directly preceded the government action against a company in which Amazon holds a major investment.

Evolution: Consistent; proximate causal role confirmed.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harm US cyber defense.

Evolution: Consistent.

Zvi Mowshowitz

The directive was improvised rather than calibrated to specific intelligence; the stated reinstatement path is technically impossible; the NSA lost its own Mythos access as a consequence; NSA red-team results were mischaracterized as external attack scenarios when they were authorized insider tests on air-gapped systems.

Evolution: Deepened across multiple installments; maintains tail-risk logic can justify precautions without a specific identified threat while calling the chosen implementation a policy fiasco.

Dean W. Ball

US export restrictions shrink the total addressable market for AI services below what $100B-scale data center investments require; every week of delay destroys commercial value by eating into the finite post-release window for margin capture.

Evolution: New voice this pass; adds a structural economic critique distinct from the technical and political objections already on record.

Tensions

  • Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [8][23][4][18][5]
  • Trump publicly stated he no longer views Anthropic as a national security threat; Lutnick's formal BIS letter remains in force and the Pentagon separately labeled Anthropic a supply chain risk, leaving Trump's public statement and the active legal posture unreconciled. [7][5][12][6]
  • The government's stated reinstatement path requires fixing the jailbreak; Zvi argues this is technically impossible and research confirms perfect jailbreak immunity is unachievable; Lutnick's 'that's the point' exchange and the 'attitude adjustment' framing indicate the actual standard is political accommodation, not a technical bar. [24][4][11][5][9][10]
  • The government cited NSA red-team results as evidence of the model's danger to classified systems; Zvi argues those tests involved authorized analysts with physical access to air-gapped systems — a materially different threat model — and the NSA itself lost access to Mythos as a collateral consequence of the same controls. [13]
  • Anthropic contests the export controls as technically disproportionate while simultaneously providing evidence that Alibaba extracted Claude's capabilities at scale via 28.8 million fraudulent exchanges — evidence that supports the government's broader China-threat framing even if not the specific jailbreak justification. [16][18][8][5]
  • Dean W. Ball argues export restrictions are commercially incoherent at $100B infrastructure scale; the government has not publicly addressed the economic cost of sustained restrictions on the US frontier AI buildout. [17]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  5. [5] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  6. [6] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  7. [7] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  8. [8] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  9. [9] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  10. [10] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
  11. [11] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
  12. [12] Trump just told the world that a week ago he considered Anthropic a national security threat (Save this). — Milk Road AI Twitter (2026-06-19)
  13. [13] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
  14. [14] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
  15. [15] GLM-5.2 is the step change for open agents — Interconnects (2026-06-22)
  16. [16] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
  17. [17] Quoting Dean W. Ball — Simon Willison (2026-06-26)
  18. [18] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  19. [19] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
  20. [20] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
  21. [21] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)
  22. [22] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
  23. [23] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  24. [24] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  25. [25] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
  26. [26] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
  27. [27] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control