The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 22

2026-06-28 08:17 UTC · 393 items

What

Two weeks after the US Commerce Department suspended Fable 5 and Mythos 5 for foreign nationals, the controls are partially unwinding: Commerce Secretary Lutnick authorized more than 100 approved institutions to access Mythos 5 on June 27 [17], Fable 5 reappeared in Amazon Bedrock on June 25 [18], and Axios reported Fable 5 may return broadly within the week [19]. The BIS export license requirement and Pentagon supply chain designation remain formally in force, as does Legion LegalTech's federal lawsuit filed June 24 [16]. NBC News reported Trump ordered government agencies to stop using Anthropic entirely, and OpenAI moved to fill the resulting gap with a Pentagon deal [14].

Why it matters

The partial reinstatement through a curated approved-institution list — not a blanket restoration — sets a template for tiered government control of frontier AI access. If Trump simultaneously ordered agencies off Anthropic while Lutnick separately authorized 100+ institutions for Mythos access [17][14], the administration is running contradictory policies in parallel, and the shape of any resolution will define precedent for how the US government exerts control over commercial AI models going forward.

Open questions

  • Is the 100-institution Mythos access list [17] a stepping stone to full reinstatement, or will this tiered model become the permanent structure — and who decides which institutions qualify?

  • Does Trump's reported order for government agencies to stop using Anthropic [14] create new legal standing for Legion LegalTech's suit, or does it complicate Anthropic's negotiating position with the administration?

  • Fable 5's broader return may come within days [19], but under what conditions — given that the stated technical bar (fixing the jailbreak) is considered impossible by multiple experts [9][10], and the actual standard appears to be political accommodation [11]?

  • Does Anthropic's Alibaba cloning disclosure [15] strengthen or weaken its negotiating position — supporting the government's China-threat framing while contesting the specific jailbreak justification that triggered the shutdown?

Narrative

On June 12, 2026, the US Commerce Department ordered Anthropic to suspend Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. The jailbreak was demonstrated by Amazon researchers, and Amazon CEO Andy Jassy personally briefed senior Trump administration officials in conversations that directly preceded the government action — against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality, Anthropic disabled both models globally on June 13. Commerce Secretary Lutnick, when told the directive meant the models would have to go offline, replied: 'That's the point' [4]. By June 17, Lutnick had sent a formal BIS letter placing both models under export licensing requirements [5]; on June 21, the Pentagon separately labeled Anthropic a 'supply chain risk' [6]. Throughout the outage, 'Claude for Government' remained operational while standard service tiers went dark [7].

The technical and political basis for the directive is contested across multiple dimensions. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities — as 'the model working as intended' for cyberdefense [8][4]. Zvi Mowshowitz argues the stated reinstatement path is technically impossible, since vulnerability identification and secure coding cannot be separated [9], and research confirms perfect jailbreak immunity is unachievable for any LLM [10]. An administration source framed reinstatement as requiring an 'attitude adjustment' rather than a technical fix [11]. NSA red-team results cited as justification involved authorized analysts with physical access to air-gapped systems, not external attackers — and the NSA itself lost access to Mythos as a collateral consequence [12]. President Trump stated on June 20 he no longer views Anthropic as a national security threat [13], yet NBC News reported he also ordered government agencies to stop using Anthropic entirely, with OpenAI moving quickly to fill the resulting gap with a Pentagon deal [14].

A complicating factor: Anthropic disclosed that Alibaba and Alibaba Qwen generated more than 28.8 million exchanges with Claude through approximately 25,000 fraudulent accounts between April 22 and June 5, targeting agentic reasoning, software engineering, and long-horizon tasks [15]. Anthropic called it the largest model-cloning campaign it has ever measured and is calling publicly for Alibaba to be punished. This places Anthropic in a structurally awkward position: contesting the government's jailbreak-based justification for the shutdown while simultaneously providing evidence that Chinese operators extracted Claude's capabilities at scale — evidence that supports the government's broader China-threat framing even if not the specific triggering incident. Legion LegalTech, a US AI-native litigation firm whose core workflows the shutdown disrupted, filed a federal lawsuit on June 24, the first formal judicial challenge to the directive [16].

As of June 27, the picture is shifting toward partial restoration. Lutnick authorized more than 100 companies and institutions to access Mythos 5 in a letter to Anthropic's chief compute officer Tom Brown, prioritizing cloud providers, chip companies, security firms, banks, and federal agencies — with an Annex A list of approved entities not made public [17]. Fable 5 reappeared in Amazon Bedrock on June 25 [18], and Axios reported on June 27 that a broader Fable 5 return may come within the week, with government agencies signaling progress on safety controls and trusted-user access protocols [19]. The BIS licensing requirement and Pentagon supply chain designation remain formally in force alongside these developments.

Timeline

  • 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, ultimately generating 28.8 million exchanges via ~25,000 fraudulent accounts through June 5. [15]
  • 2026-06-10: Anthropic sends a confidential letter to Senators Tim Scott and Elizabeth Warren disclosing the Alibaba cloning campaign, the day before a Senate AI hearing. [15]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Amazon CEO Andy Jassy briefs senior Trump administration officials in conversations that directly preceded the government action. [2][3][23]
  • 2026-06-12: White House issues Anthropic a 90-minute takedown ultimatum with no stated details on the actual threat. [28]
  • 2026-06-12: Commerce Department issues export control directive for all foreign nationals; Lutnick tells Amodei 'That's the point' when informed both models would have to go offline. [20][29][1][4]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-16: Katie Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [8][24]
  • 2026-06-16: Anthropic's Washington talks conclude without controls lifted; US refuses G7 allies and UK AISI special access. [21][30]
  • 2026-06-17: Lutnick sends a formal BIS letter to Amodei requiring an export license before international deployment; companies begin signing backup contracts with non-US AI providers. [5][4]
  • 2026-06-20: President Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [13][22]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation alongside the BIS export licensing controls. [6]
  • 2026-06-23: 'Claude for Government' remains operational during the ongoing global outage affecting standard service tiers. [7]
  • 2026-06-24: Legion LegalTech files a federal lawsuit against the US government over the shutdown order, the first formal judicial challenge to the directive. [16][26][27]
  • 2026-06-24: Zvi Mowshowitz reports the NSA lost its own Mythos access as a collateral effect, and that NSA red-team results cited as justification involved authorized insider access to air-gapped systems, not external attack. [12]
  • 2026-06-25: Anthropic publicly calls for punishment of Alibaba for the 28.8-million-exchange cloning campaign; Fable 5 reappears in Amazon Bedrock. [15][18]
  • 2026-06-26: Trump reportedly orders government agencies to stop using Anthropic entirely; OpenAI moves to fill the resulting gap with a Pentagon deal. [14]
  • 2026-06-27: Lutnick authorizes Mythos 5 for more than 100 approved institutions in a letter to Anthropic chief compute officer Tom Brown; the Annex A list of approved entities is not made public. [17]
  • 2026-06-27: Axios reports Fable 5 may return broadly within the week, with government agencies signaling progress on safety controls and trusted-user access protocols. [19]

Perspectives

Anthropic

Complying under legal obligation, contesting the directive as technically disproportionate, calling for punishment of Alibaba for the largest model-cloning campaign it has ever measured, and negotiating toward reinstatement.

Evolution: The Alibaba disclosure adds an advocacy dimension that partially reinforces the government's China-threat framing even as Anthropic disputes the specific jailbreak justification. Partial reinstatement of Mythos access suggests negotiations are producing results.

Trump / White House

Trump stated June 20 he no longer views Anthropic as a national security threat, yet NBC News reports he also ordered government agencies to stop using Anthropic entirely; no formal policy has aligned these two positions.

Evolution: The reported agency ban on Anthropic use contradicts Trump's public softening, deepening the gap between his statements and the administration's actual posture.

Commerce Department / Secretary Lutnick

Escalated from informal directive to formal BIS licensing; refused G7 allies access; now selectively authorizing Mythos 5 for 100+ approved institutions while the licensing requirement formally remains in force.

Evolution: Consistent on enforcement; the approved-institution path for Mythos represents a partial policy shift without formally lifting the BIS controls.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' on June 21 on an independent legal track; OpenAI moved quickly to secure a Pentagon deal after Trump's reported ban on government use of Anthropic.

Evolution: Entered as a new actor June 21; OpenAI's Pentagon deal is a direct structural consequence of the government's posture toward Anthropic.

Amazon / Andy Jassy

Amazon researchers demonstrated the jailbreak; Jassy personally briefed administration officials in conversations that directly preceded the government action against a company in which Amazon holds a major investment.

Evolution: Consistent; proximate causal role established and unchanged.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harm US cyber defense.

Evolution: Consistent.

Zvi Mowshowitz

The directive was improvised; the stated reinstatement path is technically impossible; the NSA itself lost Mythos access as a consequence; NSA red-team results were mischaracterized as external attack scenarios when they were authorized insider tests on air-gapped systems.

Evolution: Consistent across multiple installments; maintains tail-risk logic can justify precautions without a specific identified threat while calling the implementation a policy failure.

Legion LegalTech

Filed a federal lawsuit June 24 arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5; the first formal judicial challenger to the directive.

Evolution: New voice as of June 24; no government response on record yet.

Tensions

  • Anthropic, Moussouris, and Luta Security assess the triggering behavior as standard defensive security work on engineered fake code; the government treated it as justifying full model suspension and formal BIS licensing without publicly addressing the expert counter-assessment. [8][24][4][20][5]
  • Trump publicly stated he no longer views Anthropic as a national security threat, but reportedly ordered government agencies to stop using Anthropic entirely; Lutnick's BIS letter and the Pentagon's supply chain designation remain in force — leaving Trump's public statements and the active legal posture unreconciled. [13][14][5][6]
  • The stated reinstatement path requires fixing the jailbreak; Zvi argues this is technically impossible and research confirms perfect jailbreak immunity is unachievable; the actual standard appears to be political accommodation rather than a technical bar. [4][11][9][10]
  • The government cited NSA red-team results as evidence of the model's danger; Zvi argues those tests involved authorized analysts with physical access to air-gapped systems — a materially different threat model — and the NSA itself lost Mythos access as a collateral consequence. [12]
  • Anthropic contests the export controls as technically disproportionate while simultaneously providing evidence that Alibaba extracted Claude's capabilities at scale via 28.8 million fraudulent exchanges — evidence that partially supports the government's broader China-threat framing even if not the specific jailbreak justification. [15][20][8][5]
  • The government is simultaneously restricting Anthropic (BIS licensing, Pentagon designation, reported agency ban) and partially restoring access (Mythos for 100+ institutions, Fable 5 returning in Bedrock) — two tracks running in parallel without a coherent stated policy. [17][18][14][5][6]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  5. [5] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  6. [6] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  7. [7] Claude is still experiencing that major outage except for the "Claude for Government" https://t.co/rhOQ1mtCew — Rohan Paul Twitter (2026-06-23)
  8. [8] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  9. [9] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  10. [10] Perfect immunity from jailbreak is not possible even for the strongest of LLMs. — Rohan Paul Twitter (2026-06-19)
  11. [11] "They screwed us": Personality clashes sent Anthropic's models offline — Simon Willison (2026-06-15)
  12. [12] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
  13. [13] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  14. [14] OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic — reactive:fable-mythos-export-control
  15. [15] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
  16. [16] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
  17. [17] The U.S. just reopened Anthropic’s Claude Mythos 5 for more than 100 approved institutions. — Rohan Paul Twitter (2026-06-27)
  18. [18] 🚨 Claude Fable 5 just reappeared in Amazon Bedrock. — reactive:fable-mythos-export-control (2026-06-25)
  19. [19] Axios reports that Anthropic’s Fable 5 may soon return, as soon as this coming week. — Rohan Paul Twitter (2026-06-27)
  20. [20] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  21. [21] Anthropic Washington Talks End Without Lifting Export Controls — reactive:fable-mythos-export-control (2026-06-16)
  22. [22] Trump just told the world that a week ago he considered Anthropic a national security threat (Save this). — Milk Road AI Twitter (2026-06-19)
  23. [23] Amazon CEO reportedly raised Anthropic model concerns before ... — reactive:fable-mythos-export-control
  24. [24] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  25. [25] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  26. [26] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
  27. [27] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  28. [28] The Once And Future Fable #2 — Zvi's AI Roundups (2026-06-15)
  29. [29] Scoop: Trump admin blocks foreign access to Anthropic's most powerful AI — reactive:fable-mythos-export-control
  30. [30] The US just refused to give G7 allies special access to Anthropic’s Mythos 5 and Fable 5. — Rohan Paul Twitter (2026-06-16)