The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 25

2026-07-02 08:36 UTC · 472 items

What

The US Commerce Department lifted export controls on Claude Fable 5 and Mythos 5 on June 30, 2026, ending an 18-day suspension that followed a June 12 directive triggered by an Amazon-researcher jailbreak report [12][13][14]. Anthropic's official redeployment statement disclosed that the triggering jailbreak was replicable by less capable models including Claude Opus 4.8, GPT-5.5, and Kimi K2.7, and announced a >99% effective classifier fix, a proposed industry jailbreak severity framework, and commitments to pre-release government model access [13]. Fable 5 returned globally July 1 with a temporary access cap through July 7; Mythos 5 access continues through the Glasswing cybersecurity-research program [14][15]. SemiAnalysis called this the first frontier model taken offline and restored by government policy, predicting recurrence [18].

Why it matters

The episode showed that the US government can impose and withdraw access to commercial AI models without a stable technical standard or formal rulemaking process. Anthropic's own post-mortem argues the specific jailbreak didn't justify a frontier-model-specific ban since the capability was replicable by much less capable models. The forward commitments — pre-release government access, a proposed jailbreak severity framework — indicate both parties expect this kind of regulatory engagement to continue.

Open questions

  • Does the Pentagon's June 21 supply-chain designation remain in place, or did the Commerce lift also rescind the DoD procurement designation — and does OpenAI's Pentagon deal remain active [10][11][19]?

  • Does Legion LegalTech's federal lawsuit proceed on constitutional harm grounds now that the controls are lifted, or does restoration moot the action [16][20][21][22]?

  • Will the proposed four-dimension jailbreak severity framework (capability gain, breadth, ease of weaponization, discoverability) gain adoption from frontier developers beyond the Glasswing partners [13]?

  • Fable 5 carried a temporary access cap through July 7 [15] — has full unrestricted access been restored on schedule?

Narrative

On June 12, 2026, the US Commerce Department directed Anthropic to suspend Claude Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak demonstrated by Amazon researchers that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon CEO Andy Jassy personally briefed senior Trump administration officials before the government action — against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13. Commerce Secretary Lutnick, told the directive meant the models would have to go offline, replied: 'That's the point' [4]. By June 17 he had sent a formal BIS letter placing both models under export licensing requirements [5].

The technical justification was disputed from the outset. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — researchers used engineered code with deliberately planted fake vulnerabilities — as 'the model working as intended' for cyberdefense [6]. Zvi Mowshowitz argued the stated reinstatement path was technically impossible because vulnerability identification and secure coding cannot be separated, and that NSA red-team results cited as justification involved authorized analysts on air-gapped systems, not external attackers [7][8]. On June 20, Trump stated he no longer views Anthropic as a national security threat, yet the administration simultaneously ordered military contractors and federal agencies to cease business with Anthropic, with the Pentagon adding a supply-chain designation on June 21 and OpenAI securing a DoD contract within hours [9][10][11].

On June 30, the Commerce Department formally lifted export controls on both models, and Anthropic published its official redeployment statement [12][13]. That statement disclosed a detail the government had not addressed: Anthropic's own testing found that less capable models — including Claude Opus 4.8, GPT-5.5, and Kimi K2.7 — could identify the same vulnerabilities as Fable 5 in the original report, and that every model tested could produce the same exploit demonstration [13]. Anthropic also confirmed it deployed an improved safety classifier blocking the specific bypass in over 99% of cases, at the cost of increased false positives on benign coding and debugging tasks [13]. Lutnick credited Anthropic's 'close coordination with the US government' [14], and Anthropic committed to pre-release government access for frontier models with national security relevance and rapid jailbreak information sharing [13].

Fable 5 returned globally July 1 with a temporary access cap through July 7; Mythos 5 access expanded through the Glasswing cybersecurity-research program [14][15]. Anthropic proposed that Amazon, Microsoft, Google, and other Glasswing partners co-develop a consensus industry framework for assessing jailbreak severity across four dimensions: capability gain, breadth, ease of weaponization, and discoverability [13]. Several structural issues remain unresolved: the Pentagon's supply-chain designation was issued separately from the Commerce controls and its status is unconfirmed [10]; Legion LegalTech's federal lawsuit filed June 24 remains pending [16]; and CAISI, the White House's in-house AI technical unit, was under a stop-work order throughout the entire restriction period — leaving the administration without internal AI expertise at the critical moment [17].

Timeline

  • 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, generating 28.8 million exchanges via approximately 25,000 fraudulent accounts through June 5. [24]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5; Jassy personally briefs senior Trump administration officials in conversations that directly preceded the government action. [2][3]
  • 2026-06-12: Commerce Department issues export control directive for all foreign nationals; Lutnick tells Amodei 'That's the point' when informed both models would have to go offline. [23][1][4]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-16: Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][28]
  • 2026-06-17: Lutnick sends a formal BIS letter to Amodei requiring an export license before international deployment. [5][4]
  • 2026-06-20: Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [9]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation alongside the BIS export licensing controls. [10]
  • 2026-06-24: Legion LegalTech files the first federal lawsuit challenging the directive; separately, Zvi reports NSA lost its own Mythos access as collateral consequence. [16][30][8]
  • 2026-06-25: Anthropic publicly discloses the Alibaba cloning campaign and calls for punishment. [24]
  • 2026-06-26: Trump orders military contractors and federal agencies to cease business with Anthropic; OpenAI secures a Pentagon contract within hours. [25][19]
  • 2026-06-27: Lutnick authorizes Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program. [27][32]
  • 2026-06-30: Commerce Department formally lifts export controls on both models; Lutnick sends a formal letter confirming the lift; Anthropic announces access restoration begins July 1. [12][26][33]
  • 2026-06-30: Anthropic publishes 'Redeploying Fable 5,' disclosing the jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7; announces a >99% effective classifier fix; proposes a four-dimension industry jailbreak severity framework; and commits to pre-release government model access. [13]
  • 2026-07-01: Fable 5 returns globally with a temporary access cap through July 7; Ars Technica reports Lutnick credited Anthropic's 'close coordination with the government.' [14][15]
  • 2026-07-02: SemiAnalysis calls Fable 5's restoration the first frontier model taken offline and brought back by government policy, predicting the pattern will recur. [18]

Perspectives

Anthropic

Complied under legal obligation, contested the directive as technically disproportionate, deployed a >99% classifier fix, and disclosed that the jailbreak's capabilities were replicable by much less capable models — undercutting the rationale for a Fable 5/Mythos 5-specific ban; proposed an industry jailbreak severity framework and committed to pre-release government model access.

Evolution: Shifted from crisis management to constructive co-regulatory framing, positioning itself as an advocate for consistent, transparent rules applied equally across all frontier developers.

Trump / White House

Trump stated June 20 he no longer views Anthropic as a national security threat, yet subsequently ordered agencies and contractors to stop using Anthropic; the June 30 Commerce lift partially resolves that contradiction without any public explanation of the sequence.

Evolution: The formal lift narrows the gap between Trump's stated view and the government's actions, but no administration statement has explained why controls were imposed, extended, or lifted.

Commerce Department / Secretary Lutnick

Drove each stage of both the restriction and the unwinding — informal directive, formal BIS letter, selective Mythos restoration, and full lift — each by letter or statement rather than formal rulemaking; credited Anthropic's cooperation at the close.

Evolution: Consistent throughout as primary decision-maker; the June 30 lift letter completes the arc he initiated.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' on June 21 and routed procurement to OpenAI; whether the DoD designation has been withdrawn alongside the Commerce lift is unconfirmed.

Evolution: The Pentagon's designation was a separate action from the Commerce controls; its current status is the main unresolved structural question from this episode.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harmed US cyber defense.

Evolution: Consistent; Anthropic's redeployment statement independently corroborated her assessment by showing the capability was not unique to frontier models.

Zvi Mowshowitz

The directive was improvised and technically impossible to satisfy in the terms stated; NSA red-team results were mischaracterized; CAISI's stop-work order left the White House without AI expertise throughout; and the SCOTUS ruling on Humphrey's Executor forecloses independent AI regulation.

Evolution: Anthropic's classifier fix partially addresses his reinstatement-path argument, but his broader critique — that the government lacked the technical capacity to evaluate or resolve the underlying claim — remains unaddressed by the government.

Legion LegalTech

Filed a federal lawsuit June 24 arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5; the suit may continue on constitutional harm grounds even with controls lifted.

Evolution: No government response on record; the lift may affect standing or mootness arguments but the case has not been withdrawn.

SemiAnalysis

Calls Fable 5's restoration the first case of a frontier AI model taken offline and brought back by government policy, and predicts similar policy-driven outages will recur.

Evolution: New voice this pass; provides the clearest statement of what the episode establishes as regulatory precedent.

Tensions

  • Anthropic and Moussouris both assess the triggering behavior as standard defensive work on engineered fake code; Anthropic's redeployment statement adds that the same capabilities were replicable by much less capable models — yet the government never publicly addressed either counter-assessment, even when lifting the controls. [6][4][13][26]
  • Trump publicly stated he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the June 30 lift partially closes that gap without any reconciling explanation. [9][25][19][26]
  • Zvi argued the stated reinstatement path was technically impossible to satisfy; Anthropic's official statement implies resolution came through a classifier fix combined with demonstrating the capability was not unique to frontier models — a different resolution than the government's original framing required. [7][13][17]
  • Anthropic contests the export controls as technically disproportionate while simultaneously providing evidence that Alibaba extracted Claude's capabilities at scale via 28.8 million fraudulent exchanges — evidence supporting the government's broader China-threat framing even if not the specific triggering incident. [24][23][6][5]
  • The Commerce lift and the Pentagon supply-chain designation were issued by separate agencies; the June 30 letter addressed the BIS export licensing controls but whether it also rescinds the DoD procurement designation remains unconfirmed. [10][26][11]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  5. [5] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  6. [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  7. [7] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  8. [8] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
  9. [9] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  10. [10] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  11. [11] San Francisco-based OpenAI strikes deal with Pentagon hours after President Donald Trump's administration bans Anthropic - ABC7 San Francisco — reactive:fable-mythos-export-control
  12. [12] Quoting Anthropic — Simon Willison (2026-06-30)
  13. [13] Redeploying Fable 5 — Anthropic News (2026-06-30)
  14. [14] After spooking Trump into safety testing, Anthropic AI models get global release — Ars Technica AI (2026-07-01)
  15. [15] 😺 Fable 5 is back baby — The Neuron (2026-07-01)
  16. [16] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
  17. [17] The Once And Future Fable #5 — Zvi's AI Roundups (2026-06-30)
  18. [18] The return of Fable 5. — SemiAnalysis Twitter (2026-07-02)
  19. [19] Trump administration orders military contractors and federal agencies to cease business with Anthropic | CNN Business — reactive:fable-mythos-export-control
  20. [20] Legion LegalTech Sues US Gov Over AI Export Control Directive — reactive:fable-mythos-export-control
  21. [21] Legal tech firm sues US over Anthropic access curbs — reactive:fable-mythos-export-control
  22. [22] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  23. [23] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  24. [24] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
  25. [25] OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic — reactive:fable-mythos-export-control
  26. [26] The letter from US Commerce Secretary Howard Lutnick about lifting the export control restriction on Anthropic Fable 5. … — Rohan Paul Twitter (2026-07-01)
  27. [27] The U.S. just reopened Anthropic’s Claude Mythos 5 for more than 100 approved institutions. — Rohan Paul Twitter (2026-06-27)
  28. [28] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  29. [29] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  30. [30] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
  31. [31] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  32. [32] Anthropic just confirmed Mythos 5 is being redeployed to US organizations defending critical infrastructure. — reactive:fable-mythos-export-control (2026-06-27)
  33. [33] FINALLY.. Claude Fable 5 and Mythos 5 are coming back. 🔥 https://t.co/6VdnFSvLRP https://t.co/OFVd1hOESd — Rohan Paul Twitter (2026-06-30)