The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 26

2026-07-03 18:29 UTC · 518 items

What

The US Commerce Department lifted export controls on Claude Fable 5 and Mythos 5 on June 30, 2026, ending an 18-day suspension triggered by an Amazon-researcher jailbreak report [13][14]. Anthropic's redeployment statement disclosed the jailbreak was replicable by less capable models, announced a >99% classifier fix, proposed a four-dimension jailbreak severity framework, and committed to pre-release government model access [14]. Fable 5 returned globally July 1 with a temporary access cap through July 7; Mythos 5 access continues via the Glasswing cybersecurity-research program [20][15]. Zvi Mowshowitz's July 3 analysis argues the triggering 'jailbreak' was a standard debugging request and that Anthropic's classifier fix now causes legitimate debugging tasks to fall back to lesser models — a concrete operational cost the ad hoc regulatory process never assessed [2].

Why it matters

The episode established that the US government can impose and withdraw access to commercial AI models on short notice without a stable technical standard or formal rulemaking. The classifier fix Anthropic deployed to satisfy the government carries a concrete and ongoing cost: routine coding and debugging tasks now sometimes degrade to less capable models [2]. The proposed jailbreak severity framework, if adopted by Amazon, Microsoft, Google, and other Glasswing partners, would be the first industry-wide standard for distinguishing consequential security vulnerabilities from ordinary model behavior — changing how future regulatory disputes are framed [14][16].

Open questions

  • Has Fable 5's temporary access cap (through July 7) been lifted on schedule, and what restrictions remain on coding and debugging tasks given the classifier's fallback behavior [15][2]?

  • Does the Pentagon's June 21 supply-chain designation remain in place — it was issued separately from the Commerce controls, and the June 30 lift letter addressed the BIS licensing requirements, not the DoD procurement designation [9][21]?

  • Does Legion LegalTech's federal lawsuit proceed on constitutional harm grounds now that access is restored, or does the lift moot the case [17][18]?

  • Will the proposed four-dimension jailbreak severity framework gain adoption from Glasswing partners (Amazon, Microsoft, Google), and does Aaron Levie's comment about GPT-5.6 being 'presumably next' suggest other frontier models will face similar government scrutiny [14][22][16]?

Narrative

On June 12, 2026, the US Commerce Department directed Anthropic to suspend Claude Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak demonstrated by Amazon researchers that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Zvi Mowshowitz's subsequent analysis identified the triggering scenario as a standard debugging request — 'fix this code' — applied to engineered code with deliberately planted fake CVEs [2]. Amazon CEO Andy Jassy personally briefed senior Trump administration officials before the government acted against a company in which Amazon holds a major investment [3][4]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13. Commerce Secretary Lutnick, told the directive meant the models would have to go offline, replied: 'That's the point' [5].

The technical justification was disputed from the outset. Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario as 'the model working as intended' for cyberdefense [6]. Lutnick sent a formal BIS letter on June 17 requiring an export license before international deployment [7]. On June 20, Trump stated he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the Pentagon added a supply-chain designation on June 21 and OpenAI secured a DoD contract within hours [8][9][10]. On June 27, Lutnick authorized Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program [11][12].

On June 30, the Commerce Department formally lifted export controls on both models [13]. Anthropic's redeployment statement disclosed that the triggering jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7 — directly undercutting the rationale for a Fable 5/Mythos 5-specific ban — and announced an improved safety classifier blocking the bypass in over 99% of cases [14]. Fable 5 returned globally July 1 with a temporary access cap through July 7 [15]. Anthropic committed to pre-release government access for frontier models and proposed that Amazon, Microsoft, Google, and other Glasswing partners co-develop a four-dimension jailbreak severity framework covering capability gain, breadth, ease of weaponization, and discoverability [14][16].

The episode's operational costs came into clearer focus after restoration. Zvi's July 3 analysis argued that the classifier fix, designed to block a debugging-type prompt, now causes legitimate debugging tasks to fall back to lesser models — a direct consequence of the government's inability to distinguish the triggering scenario from normal use [2]. He characterized the regulatory episode as handled by officials who 'do not know how any of this works' and called it 'a huge own goal for the US' [2]. Several structural questions remain open: the Pentagon's supply-chain designation was issued separately from the Commerce controls and its current status is unconfirmed [9]; Legion LegalTech's federal lawsuit remains pending [17][18]; and CAISI, the White House's in-house AI technical unit, was under a stop-work order throughout the restriction period [19].

Timeline

  • 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, generating 28.8 million exchanges via approximately 25,000 fraudulent accounts through June 5. [24]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5 — later characterized by Zvi as a standard 'fix this code' debugging request on engineered code with planted fake CVEs; Jassy personally briefs senior Trump administration officials. [3][4][2]
  • 2026-06-12: Commerce Department issues export control directive for all foreign nationals; Lutnick tells Amodei 'That's the point' when informed both models would have to go offline. [23][1][5]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-16: Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [6][27]
  • 2026-06-17: Lutnick sends a formal BIS letter to Amodei requiring an export license before international deployment. [7][5]
  • 2026-06-20: Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [8]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation; OpenAI secures a Pentagon contract within hours. [9][10][26]
  • 2026-06-24: Legion LegalTech files the first federal lawsuit challenging the directive; Zvi reports NSA lost its own Mythos access as collateral consequence. [17][32][30]
  • 2026-06-25: Anthropic publicly discloses the Alibaba model-cloning campaign and calls for punishment. [24]
  • 2026-06-26: Trump orders military contractors and federal agencies to cease business with Anthropic. [25]
  • 2026-06-27: Lutnick authorizes Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program. [11][12]
  • 2026-06-30: Commerce Department formally lifts export controls on both models; Lutnick sends a letter confirming the lift, crediting Anthropic's 'close coordination with the US government.' [13][21][39]
  • 2026-06-30: Anthropic publishes 'Redeploying Fable 5,' disclosing the jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7; announces a >99% classifier fix; proposes a four-dimension jailbreak severity framework; and commits to pre-release government model access. [14]
  • 2026-07-01: Fable 5 returns globally with a temporary access cap through July 7; Glasswing confirmed as the ongoing channel for Mythos 5 cybersecurity access. [20][15]
  • 2026-07-02: SemiAnalysis calls Fable 5's restoration the first frontier model taken offline and brought back by government policy, predicting the pattern will recur; The Neuron frames government AI interventions as a new operational risk category requiring contingency planning. [37][38]
  • 2026-07-03: Zvi argues the triggering scenario was standard debugging code, the classifier fix now causes debugging tasks to fall back to lesser models, and the episode was handled ad hoc by officials who 'do not know how any of this works.' [2]

Perspectives

Anthropic

Complied under legal obligation, contested the directive as technically disproportionate, deployed a >99% classifier fix, and disclosed that the jailbreak's capabilities were replicable by much less capable models; proposed an industry jailbreak severity framework and committed to pre-release government model access.

Evolution: Shifted from crisis management to constructive co-regulatory framing, positioning itself as an advocate for consistent, transparent rules applied equally across all frontier developers.

Commerce Department / Secretary Lutnick

Drove each stage of both the restriction and the unwinding — informal directive, formal BIS letter, selective Mythos restoration, and full lift — each by letter or statement rather than formal rulemaking; credited Anthropic's cooperation at the close.

Evolution: Consistent throughout as primary decision-maker; the June 30 lift letter completes the arc he initiated.

Trump / White House

Trump stated June 20 he no longer views Anthropic as a national security threat, yet subsequently ordered agencies and contractors to stop using Anthropic; the June 30 Commerce lift partially resolves that contradiction without any public explanation.

Evolution: The formal lift narrows the gap between Trump's stated view and the government's actions, but no administration statement has explained why controls were imposed, extended, or lifted.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' on June 21 and routed procurement to OpenAI; whether the DoD designation has been withdrawn alongside the Commerce lift is unconfirmed.

Evolution: The Pentagon's designation was a separate action from the Commerce controls; its current status is the main unresolved structural question from this episode.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harmed US cyber defense.

Evolution: Consistent; Anthropic's redeployment statement independently corroborated her assessment by showing the capability was not unique to frontier models.

Zvi Mowshowitz

The triggering 'jailbreak' was a standard debugging request ('fix this code'); the classifier fix imposes an ongoing operational cost as legitimate debugging tasks now fall back to lesser models; the episode was handled ad hoc by officials who don't understand the technology; and it constitutes 'a huge own goal for the US.'

Evolution: Sharpened materially: the July 3 piece identifies the specific operational cost of the classifier fix and names Lutnick and Bessent as lacking technical competence to evaluate the underlying claims — more pointed than his prior critique of the directive's procedural failures.

Legion LegalTech

Filed a federal lawsuit June 24 arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5; the suit may continue on constitutional harm grounds even with controls lifted.

Evolution: No government response on record; the lift may affect standing or mootness arguments but the case has not been withdrawn.

SemiAnalysis / The Neuron

The episode establishes a new regulatory category: frontier model launches are now policy events subject to government intervention, companies whose workflows depend on a single closed model need open-source backup strategies, and this pattern will recur.

Evolution: Both framed the restoration as the end of one episode and the beginning of an ongoing operational risk category, rather than a one-time anomaly.

Tensions

  • Anthropic and Moussouris both assess the triggering behavior as standard defensive work on engineered fake code; Zvi adds it was specifically a 'fix this code' debugging request — yet the government never publicly addressed any counter-assessment, even when lifting the controls. [6][5][14][21][2]
  • Anthropic's classifier fix satisfies the government's requirement and blocks the bypass in >99% of cases, but Zvi argues it now causes legitimate debugging tasks to fall back to lesser models — a concrete operational cost the ad hoc process never weighed. [14][2]
  • Trump publicly stated he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the June 30 lift partially closes that gap without any reconciling explanation. [8][25][26][21]
  • Zvi argued the directive was technically impossible to satisfy as stated; Anthropic's resolution came through a classifier fix combined with demonstrating capability parity with less capable models — a different path than the government's original framing required. [29][14][19][2]
  • The Commerce lift and the Pentagon supply-chain designation were issued by separate agencies; the June 30 letter addressed the BIS export licensing controls but whether it also rescinds the DoD procurement designation remains unconfirmed. [9][21][10]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Fable #6: The Return of the King — Zvi's AI Roundups (2026-07-03)
  3. [3] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  4. [4] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  5. [5] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  6. [6] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  7. [7] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  8. [8] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  9. [9] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  10. [10] San Francisco-based OpenAI strikes deal with Pentagon hours after President Donald Trump's administration bans Anthropic - ABC7 San Francisco — reactive:fable-mythos-export-control
  11. [11] The U.S. just reopened Anthropic’s Claude Mythos 5 for more than 100 approved institutions. — Rohan Paul Twitter (2026-06-27)
  12. [12] Anthropic just confirmed Mythos 5 is being redeployed to US organizations defending critical infrastructure. — reactive:fable-mythos-export-control (2026-06-27)
  13. [13] Quoting Anthropic — Simon Willison (2026-06-30)
  14. [14] Redeploying Fable 5 — Anthropic News (2026-06-30)
  15. [15] 😺 Fable 5 is back baby — The Neuron (2026-07-01)
  16. [16] Anthropic: Collaborating with Amazon, Microsoft, Google and Other Glasswing Allies to Develop Framework for Evaluating A... — reactive:fable-mythos-export-control (2026-07-01)
  17. [17] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
  18. [18] Legal tech firm sues US over order limiting foreign access to top-tier Anthropic models — reactive:fable-mythos-export-control
  19. [19] The Once And Future Fable #5 — Zvi's AI Roundups (2026-06-30)
  20. [20] After spooking Trump into safety testing, Anthropic AI models get global release — Ars Technica AI (2026-07-01)
  21. [21] The letter from US Commerce Secretary Howard Lutnick about lifting the export control restriction on Anthropic Fable 5. … — Rohan Paul Twitter (2026-07-01)
  22. [22] Things seem to be ending up in a better spot with Fable, and presumably GPT-5.6 next. What we have now is the initial pr... — reactive:fable-mythos-export-control (2026-07-01)
  23. [23] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  24. [24] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
  25. [25] OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic — reactive:fable-mythos-export-control
  26. [26] Trump administration orders military contractors and federal agencies to cease business with Anthropic | CNN Business — reactive:fable-mythos-export-control
  27. [27] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  28. [28] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  29. [29] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  30. [30] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
  31. [31] AI #175: The Fable Continues — Zvi's AI Roundups (2026-07-02)
  32. [32] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
  33. [33] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  34. [34] Legion LegalTech Sues US Gov Over AI Export Control Directive — reactive:fable-mythos-export-control
  35. [35] Legal tech firm sues US over Anthropic access curbs — reactive:fable-mythos-export-control
  36. [36] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  37. [37] The return of Fable 5. — SemiAnalysis Twitter (2026-07-02)
  38. [38] 😺 We're LIVE now (talking Fable & GPT 5.6) — The Neuron (2026-07-02)
  39. [39] FINALLY.. Claude Fable 5 and Mythos 5 are coming back. 🔥 https://t.co/6VdnFSvLRP https://t.co/OFVd1hOESd — Rohan Paul Twitter (2026-06-30)