US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history
Version 27
2026-07-05 02:10 UTC · 523 items
What
The US Commerce Department lifted export controls on Claude Fable 5 and Mythos 5 on June 30, 2026, ending an 18-day suspension triggered by an Amazon-researcher jailbreak report [14][15]. Fable 5 returned globally July 1 with a temporary access cap through July 7; Mythos 5 access continues via the Glasswing cybersecurity-research program [19][17]. Anthropic's redeployment statement disclosed the jailbreak was replicable by less capable models, announced a >99% classifier fix, and proposed a four-dimension jailbreak severity framework [15]. A federal lawsuit (Legion LegalTech v. United States, 1:26-cv-02225 D.D.C.) remains pending [12][13], and the Pentagon's separate supply-chain designation has not been confirmed withdrawn [8].
Why it matters
The episode established that the US government can impose and lift access to commercial AI models without formal rulemaking or stable technical standards. The classifier fix Anthropic deployed to satisfy the government carries a concrete ongoing cost: routine debugging tasks now sometimes degrade to less capable models [5]. The proposed jailbreak severity framework, if adopted by Glasswing partners, would be the first industry-wide standard for distinguishing consequential security vulnerabilities from ordinary model behavior [15].
Open questions
Has Fable 5's temporary access cap (through July 7) been lifted on schedule, and what restrictions remain on coding and debugging tasks given the classifier's fallback behavior [17][5]?
Does the Pentagon's June 21 supply-chain designation remain in place — the June 30 Commerce lift addressed BIS export licensing requirements, not the DoD procurement designation [8][20]?
Does Legion LegalTech's federal lawsuit (1:26-cv-02225 D.D.C.) proceed on constitutional harm grounds now that access is restored, or does the lift moot the case [12][13]?
Will the four-dimension jailbreak severity framework gain adoption from Glasswing partners (Amazon, Microsoft, Google), and does Aaron Levie's comment about GPT-5.6 being 'presumably next' suggest other frontier models face similar scrutiny [15][21][16]?
Narrative
On June 12, 2026, the US Commerce Department directed Anthropic to suspend Claude Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak demonstrated by Amazon researchers that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon CEO Andy Jassy personally briefed senior Trump administration officials before the government acted against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13. The technical justification was disputed from the outset: Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — later characterized by analyst Zvi Mowshowitz as a standard 'fix this code' debugging request applied to engineered code with deliberately planted fake CVEs — as 'the model working as intended' for cyberdefense [4][5].
The restriction escalated through several separate government actions. Commerce Secretary Lutnick sent a formal BIS letter on June 17 requiring an export license before international deployment [6]. Trump stated publicly on June 20 he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the Pentagon added a supply-chain designation on June 21 and OpenAI secured a DoD contract within hours [7][8][9]. On June 27, Lutnick authorized Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program [10][11]. Legion LegalTech filed a federal lawsuit (1:26-cv-02225 D.D.C.) on June 24, arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5 [12][13].
On June 30, the Commerce Department formally lifted export controls on both models [14]. Anthropic's redeployment statement disclosed that the triggering jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7 — directly undercutting the rationale for a Fable 5/Mythos 5-specific ban — and announced an improved safety classifier blocking the bypass in over 99% of cases [15]. Anthropic committed to pre-release government access for frontier models and proposed that Glasswing partners co-develop a four-dimension jailbreak severity framework covering capability gain, breadth, ease of weaponization, and discoverability [15][16]. Fable 5 returned globally July 1 with a temporary access cap through July 7 [17].
The episode's operational costs came into clearer focus after restoration. Zvi's July 3 analysis argued that the classifier fix — designed to block a debugging-type prompt — now causes legitimate debugging tasks to fall back to lesser models, a direct consequence of the government's inability to distinguish the triggering scenario from normal use [5]. He characterized the episode as handled ad hoc by officials who 'do not know how any of this works' and called it 'a huge own goal for the US' [5]. Several structural questions remain open: the Pentagon's supply-chain designation was a separate action from the Commerce controls and its current status is unconfirmed [8]; the Legion LegalTech lawsuit has not been withdrawn; and CAISI, the White House's in-house AI technical unit, was under a stop-work order throughout the restriction period [18].
Timeline
- 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, generating 28.8 million exchanges via approximately 25,000 fraudulent accounts through June 5. [24]
- 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5 using engineered code with planted fake CVEs; Jassy personally briefs senior Trump administration officials. [2][3][5]
- 2026-06-12: Commerce Department issues export control directive for all foreign nationals; Lutnick tells Amodei 'That's the point' when informed both models would have to go offline. [22][1][23]
- 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
- 2026-06-16: Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [4][27]
- 2026-06-17: Lutnick sends a formal BIS letter to Amodei requiring an export license before international deployment. [6][23]
- 2026-06-20: Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [7]
- 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation; OpenAI secures a Pentagon contract within hours. [8][9][26]
- 2026-06-24: Legion LegalTech files federal lawsuit (1:26-cv-02225 D.D.C.) challenging the directive; Zvi reports NSA lost its own Mythos access as collateral consequence. [12][32][30][13]
- 2026-06-25: Anthropic publicly discloses the Alibaba model-cloning campaign and calls for punishment. [24]
- 2026-06-26: Trump orders military contractors and federal agencies to cease business with Anthropic. [25]
- 2026-06-27: Lutnick authorizes Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program. [10][11]
- 2026-06-30: Commerce Department formally lifts export controls on both models; Lutnick's letter credits Anthropic's 'close coordination with the US government.' [14][20][40]
- 2026-06-30: Anthropic publishes 'Redeploying Fable 5,' disclosing the jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7; announces a >99% classifier fix; proposes a four-dimension jailbreak severity framework; commits to pre-release government model access. [15]
- 2026-07-01: Fable 5 returns globally with a temporary access cap through July 7; Glasswing confirmed as the ongoing channel for Mythos 5 cybersecurity access. [19][17]
- 2026-07-02: SemiAnalysis calls Fable 5's restoration the first frontier model taken offline and brought back by government policy, predicting the pattern will recur; The Neuron frames government AI interventions as a new operational risk category. [38][39]
- 2026-07-03: Zvi argues the triggering scenario was standard debugging code, the classifier fix now causes debugging tasks to fall back to lesser models, and the episode was handled ad hoc by officials who 'do not know how any of this works.' [5]
Perspectives
Anthropic
Complied under legal obligation, contested the directive as technically disproportionate, deployed a >99% classifier fix, and disclosed the jailbreak's capabilities were replicable by much less capable models; proposed an industry jailbreak severity framework and committed to pre-release government model access.
Evolution: Shifted from crisis management to constructive co-regulatory framing, positioning itself as an advocate for consistent, transparent rules applied equally across all frontier developers.
Commerce Department / Secretary Lutnick
Drove each stage of both the restriction and the unwinding — informal directive, formal BIS letter, selective Mythos restoration, and full lift — each by letter or statement rather than formal rulemaking; credited Anthropic's cooperation at the close.
Evolution: Consistent throughout as primary decision-maker; the June 30 lift letter completes the arc he initiated.
Trump / White House
Trump stated June 20 he no longer views Anthropic as a national security threat, yet subsequently ordered agencies and contractors to stop using Anthropic; the June 30 Commerce lift partially resolves that contradiction without any public explanation.
Evolution: The formal lift narrows the gap between Trump's stated view and the government's actions, but no administration statement has explained why controls were imposed, extended, or lifted.
Pentagon / Department of Defense
Labeled Anthropic a 'supply chain risk' on June 21 and routed procurement to OpenAI; whether the DoD designation has been withdrawn alongside the Commerce lift is unconfirmed.
Evolution: The Pentagon's designation was a separate action from the Commerce controls; its current status is the main unresolved structural question from this episode.
Luta Security / Katie Moussouris
The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harmed US cyber defense.
Evolution: Consistent; Anthropic's redeployment statement independently corroborated her assessment by showing the capability was not unique to frontier models.
Zvi Mowshowitz
The triggering 'jailbreak' was a standard debugging request ('fix this code'); the classifier fix imposes an ongoing operational cost as legitimate debugging tasks fall back to lesser models; the episode was handled ad hoc by officials who don't understand the technology and constitutes 'a huge own goal for the US.'
Evolution: Sharpened materially: names Lutnick and Bessent as lacking technical competence and identifies the specific operational cost of the classifier fix — more pointed than prior critiques of the directive's procedural failures.
Legion LegalTech
Filed federal lawsuit (1:26-cv-02225 D.D.C.) June 24, arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5; the suit may continue on constitutional harm grounds even with controls lifted.
Evolution: No government response on record; the lift may affect standing or mootness arguments but the case has not been withdrawn.
SemiAnalysis / The Neuron
The episode establishes a new regulatory category: frontier model launches are now policy events subject to government intervention, and companies whose workflows depend on a single closed model need open-source backup strategies.
Evolution: Both framed the restoration as the end of one episode and the beginning of an ongoing operational risk category, not a one-time anomaly.
Tensions
- Anthropic and Moussouris both assess the triggering behavior as standard defensive work on engineered fake code; Zvi adds it was specifically a 'fix this code' debugging request — yet the government never publicly addressed any counter-assessment, even when lifting the controls. [4][23][15][20][5]
- Anthropic's classifier fix satisfies the government's requirement and blocks the bypass in >99% of cases, but Zvi argues it now causes legitimate debugging tasks to fall back to lesser models — a concrete operational cost the ad hoc process never weighed. [15][5]
- Trump publicly stated he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the June 30 lift partially closes that gap without any reconciling explanation. [7][25][26][20]
- The Commerce lift and the Pentagon supply-chain designation were issued by separate agencies; the June 30 letter addressed BIS export licensing controls but whether it also rescinds the DoD procurement designation remains unconfirmed. [8][20][9]
- Zvi argued the directive was technically impossible to satisfy as stated; Anthropic's resolution came through a classifier fix combined with demonstrating capability parity with less capable models — a different path than the government's original framing required. [29][15][18][5]
Sources
- [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
- [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
- [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
- [4] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
- [5] Fable #6: The Return of the King — Zvi's AI Roundups (2026-07-03)
- [6] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
- [7] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
- [8] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
- [9] San Francisco-based OpenAI strikes deal with Pentagon hours after President Donald Trump's administration bans Anthropic - ABC7 San Francisco — reactive:fable-mythos-export-control
- [10] The U.S. just reopened Anthropic’s Claude Mythos 5 for more than 100 approved institutions. — Rohan Paul Twitter (2026-06-27)
- [11] Anthropic just confirmed Mythos 5 is being redeployed to US organizations defending critical infrastructure. — reactive:fable-mythos-export-control (2026-06-27)
- [12] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
- [13] Legion LegalTech, Corp. v. United States Of America 1:26-cv-02225 (D.D.C.) | Civil Rights Litigation Clearinghouse — reactive:fable-mythos-export-control
- [14] Quoting Anthropic — Simon Willison (2026-06-30)
- [15] Redeploying Fable 5 — Anthropic News (2026-06-30)
- [16] Anthropic: Collaborating with Amazon, Microsoft, Google and Other Glasswing Allies to Develop Framework for Evaluating A... — reactive:fable-mythos-export-control (2026-07-01)
- [17] 😺 Fable 5 is back baby — The Neuron (2026-07-01)
- [18] The Once And Future Fable #5 — Zvi's AI Roundups (2026-06-30)
- [19] After spooking Trump into safety testing, Anthropic AI models get global release — Ars Technica AI (2026-07-01)
- [20] The letter from US Commerce Secretary Howard Lutnick about lifting the export control restriction on Anthropic Fable 5. … — Rohan Paul Twitter (2026-07-01)
- [21] Things seem to be ending up in a better spot with Fable, and presumably GPT-5.6 next. What we have now is the initial pr... — reactive:fable-mythos-export-control (2026-07-01)
- [22] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [23] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
- [24] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
- [25] OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic — reactive:fable-mythos-export-control
- [26] Trump administration orders military contractors and federal agencies to cease business with Anthropic | CNN Business — reactive:fable-mythos-export-control
- [27] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
- [28] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
- [29] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
- [30] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
- [31] AI #175: The Fable Continues — Zvi's AI Roundups (2026-07-02)
- [32] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
- [33] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
- [34] Legion LegalTech Sues US Gov Over AI Export Control Directive — reactive:fable-mythos-export-control
- [35] Legal tech firm sues US over Anthropic access curbs — reactive:fable-mythos-export-control
- [36] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
- [37] Legal tech firm sues US over order limiting foreign access to top-tier Anthropic models — reactive:fable-mythos-export-control
- [38] The return of Fable 5. — SemiAnalysis Twitter (2026-07-02)
- [39] 😺 We're LIVE now (talking Fable & GPT 5.6) — The Neuron (2026-07-02)
- [40] FINALLY.. Claude Fable 5 and Mythos 5 are coming back. 🔥 https://t.co/6VdnFSvLRP https://t.co/OFVd1hOESd — Rohan Paul Twitter (2026-06-30)