The Information Machine

US Government Export Control Directive Suspends Fable 5 and Mythos 5 for Foreign Nationals · history

Version 28

2026-07-07 08:23 UTC · 529 items

What

The US Commerce Department lifted export controls on Claude Fable 5 and Mythos 5 on June 30, 2026, ending an 18-day suspension triggered by an Amazon-researcher jailbreak report [14][15]. Fable 5 returned globally July 1 under a temporary access cap set to expire July 7; Mythos 5 access continues through the Glasswing cybersecurity-research program [16][17]. Anthropic has since published detailed technical documentation naming its proposed jailbreak-severity system the CJS framework, defining four cybersecurity use tiers, and acknowledging an intentional 'safety margin' that blocks some benign uses [18]. A federal lawsuit (Legion LegalTech v. United States, 1:26-cv-02225 D.D.C.) remains pending, and the Pentagon's separate supply-chain designation has not been confirmed withdrawn [8][12].

Why it matters

The episode showed that US commercial AI models can be taken offline by informal government directive without rulemaking or stable technical standards. Anthropic's post-restoration disclosures — that the triggering capability was replicable by less capable models [15] and that its classifier fix intentionally blocks some benign tasks as a deliberate design choice [18] — document both why the specific ban was technically thin and what ongoing operational costs it imposed on users.

Open questions

  • Has the Fable 5 temporary access cap, set to expire July 7, been lifted on schedule, and are any restrictions on coding and debugging tasks still in effect [17][5]?

  • Does the Pentagon's June 21 supply-chain designation remain in place — the June 30 Commerce lift addressed BIS export licensing, not the DoD procurement designation [8][19]?

  • Does Legion LegalTech's federal lawsuit (1:26-cv-02225 D.D.C.) proceed on constitutional harm grounds now that access is restored, or does the lift moot the case [12][13]?

  • Will the CJS jailbreak-severity framework gain adoption from Glasswing partners (Amazon, Microsoft, Google), and what threshold scores would distinguish a classification-worthy security event from routine model behavior [18][15]?

Narrative

On June 12, 2026, the US Commerce Department directed Anthropic to suspend Claude Fable 5 and Mythos 5 for all foreign nationals, citing a jailbreak demonstrated by Amazon researchers that bypassed classifier-based safeguards for cybersecurity, chemistry, and biology prompts [1]. Amazon CEO Andy Jassy personally briefed senior Trump administration officials before the government acted against a company in which Amazon holds a major investment [2][3]. Unable to restrict access by nationality on short notice, Anthropic disabled both models globally on June 13. The technical justification was disputed from the outset: Katie Moussouris, the only outside expert given access to the government's report, assessed the triggering scenario — later characterized by analyst Zvi Mowshowitz as a standard 'fix this code' debugging request applied to engineered code with deliberately planted fake CVEs — as 'the model working as intended' for cyberdefense [4][5].

The restriction produced several escalating government actions. Commerce Secretary Lutnick sent a formal BIS letter on June 17 requiring an export license before international deployment [6]. Trump stated publicly on June 20 he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the Pentagon added a supply-chain designation on June 21 and OpenAI secured a DoD contract within hours [7][8][9]. On June 27, Lutnick authorized Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program [10][11]. Legion LegalTech filed a federal lawsuit (1:26-cv-02225 D.D.C.) on June 24, arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5 [12][13].

On June 30, the Commerce Department formally lifted export controls on both models [14]. Anthropic's redeployment statement disclosed that the triggering jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7 — directly undercutting the rationale for a Fable 5/Mythos 5-specific ban — and announced an improved safety classifier blocking the bypass in over 99% of cases [15]. Fable 5 returned globally July 1 with a temporary access cap through July 7; Glasswing was confirmed as the ongoing channel for Mythos 5 [16][17]. On July 2, Anthropic published a detailed follow-up specifying its cybersecurity classification system: four tiers (prohibited, high-risk dual use, low-risk dual use, and benign), with classifiers targeting the first two [18]. The post named the proposed framework the CJS (Cyber Jailbreak Severity) system, scoring jailbreaks 0–10 across four axes on a logarithmic scale mapping to five severity levels, and announced a HackerOne bug-bounty program for Fable 5 cyber jailbreak submissions. Notably, Anthropic acknowledged a deliberate 'safety margin' that intentionally blocks some low-risk and benign uses to reduce the chance that high-risk prompts slip through undetected [18].

Zvi Mowshowitz's July 3 analysis argued that the classifier fix — designed to block a debugging-type prompt — now causes legitimate debugging tasks to fall back to lesser models, characterizing the episode as handled ad hoc by officials who 'do not know how any of this works' and a 'huge own goal for the US' [5]. Several structural questions remain open: the Pentagon's supply-chain designation was a separate action from the Commerce controls and its current status is unconfirmed [8]; the Legion LegalTech lawsuit has not been withdrawn; and the Fable 5 temporary access cap was set to expire July 7 with no public update on its status [17].

Timeline

  • 2026-04-22: Alibaba and Alibaba Qwen begin a model-cloning campaign against Claude, generating 28.8 million exchanges via approximately 25,000 fraudulent accounts through June 5. [22]
  • 2026-06-12: Amazon researchers demonstrate a jailbreak on Fable 5 using engineered code with planted fake CVEs; Jassy personally briefs senior Trump administration officials. [2][3][5]
  • 2026-06-12: Commerce Department issues export control directive for all foreign nationals; Lutnick tells Amodei 'That's the point' when informed both models would have to go offline. [20][1][21]
  • 2026-06-13: Anthropic disables Fable 5 and Mythos 5 globally after determining nationality-based restriction was not achievable on short notice. [1]
  • 2026-06-16: Moussouris assesses the triggering behavior as 'the model working as intended' for cyberdefense; Luta Security publishes a formal argument that the controls harm US cyber defense. [4][26]
  • 2026-06-17: Lutnick sends a formal BIS letter to Amodei requiring an export license before international deployment. [6][21]
  • 2026-06-20: Trump states he no longer views Anthropic as a national security threat, with no formal policy change announced. [7]
  • 2026-06-21: Pentagon labels Anthropic a 'supply chain risk,' adding a DoD procurement designation; OpenAI secures a Pentagon contract within hours. [8][9][24]
  • 2026-06-24: Legion LegalTech files federal lawsuit (1:26-cv-02225 D.D.C.) challenging the directive; Zvi reports NSA lost its own Mythos access as collateral consequence. [12][32][29][13]
  • 2026-06-25: Anthropic publicly discloses the Alibaba model-cloning campaign and calls for punishment. [22]
  • 2026-06-27: Lutnick authorizes Mythos 5 for more than 100 approved institutions via the Glasswing cybersecurity-research program. [10][11]
  • 2026-06-30: Commerce Department formally lifts export controls on both models; Lutnick's letter credits Anthropic's 'close coordination with the US government.' [14][19][40]
  • 2026-06-30: Anthropic publishes 'Redeploying Fable 5,' disclosing the jailbreak was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7; announces a >99% classifier fix; proposes a four-dimension jailbreak severity framework; commits to pre-release government model access. [15]
  • 2026-07-01: Fable 5 returns globally with a temporary access cap through July 7; Glasswing confirmed as the ongoing channel for Mythos 5 cybersecurity access. [16][17]
  • 2026-07-02: Anthropic publishes detailed cybersecurity classifier post: names the proposed framework CJS, specifies a 0–10 logarithmic scoring scale mapping to five severity levels, defines four cybersecurity use tiers, acknowledges an intentional safety margin blocking some benign uses, and launches a HackerOne bug-bounty program. [18]
  • 2026-07-02: SemiAnalysis calls Fable 5's restoration the first frontier model taken offline and brought back by government policy, predicting the pattern will recur; The Neuron frames government AI interventions as a new operational risk category. [38][39]
  • 2026-07-03: Zvi argues the triggering scenario was standard debugging code, the classifier fix now causes debugging tasks to fall back to lesser models, and the episode was handled ad hoc by officials who 'do not know how any of this works.' [5]

Perspectives

Anthropic

Complied under legal obligation, contested the directive as technically disproportionate, deployed a >99% classifier fix, disclosed the jailbreak was replicable by less capable models, proposed the CJS jailbreak-severity framework with a four-tier cybersecurity classification system, acknowledged an intentional safety margin that blocks some benign uses, and launched a HackerOne bug-bounty program.

Evolution: Moved from crisis management to constructive co-regulatory framing; the July 2 technical post gives the proposed framework a concrete scoring methodology and candidly acknowledges classifier tradeoffs.

Commerce Department / Secretary Lutnick

Drove each stage of both the restriction and the unwinding — informal directive, formal BIS letter, selective Mythos restoration via Glasswing, and full lift — each by letter or statement rather than formal rulemaking; credited Anthropic's cooperation at the close.

Evolution: Consistent throughout as primary decision-maker; the June 30 lift letter completes the arc he initiated.

Trump / White House

Trump stated June 20 he no longer views Anthropic as a national security threat, yet subsequently ordered agencies and contractors to stop using Anthropic; the June 30 Commerce lift partially resolves that contradiction without any public explanation.

Evolution: The formal lift narrows the gap between Trump's stated view and the government's actions, but no administration statement has explained why controls were imposed, extended, or lifted.

Pentagon / Department of Defense

Labeled Anthropic a 'supply chain risk' on June 21 and routed procurement to OpenAI; whether the DoD designation has been withdrawn alongside the Commerce lift is unconfirmed.

Evolution: The Pentagon's designation was a separate action from the Commerce controls; its current status remains the main unresolved structural question from this episode.

Luta Security / Katie Moussouris

The triggering scenario used deliberately planted fake CVEs on engineered code and is 'the model working as intended' for cyberdefense; the controls harmed US cyber defense.

Evolution: Consistent; Anthropic's redeployment statement independently corroborated her assessment by showing the capability was not unique to frontier models.

Zvi Mowshowitz

The triggering 'jailbreak' was a standard debugging request ('fix this code'); the classifier fix imposes an ongoing operational cost as legitimate debugging tasks fall back to lesser models; the episode was handled ad hoc by officials who don't understand the technology and constitutes 'a huge own goal for the US.'

Evolution: Sharpened over successive posts: names Lutnick and Bessent as lacking technical competence and identifies the specific operational cost of the classifier fix — more pointed than earlier critiques of the directive's procedural failures.

Legion LegalTech

Filed federal lawsuit (1:26-cv-02225 D.D.C.) June 24, arguing the shutdown violated its rights as a US AI-native firm whose core workflows depended on Fable 5; the suit may continue on constitutional harm grounds even with controls lifted.

Evolution: No government response on record; the lift may affect standing or mootness arguments but the case has not been withdrawn.

SemiAnalysis / The Neuron

The episode establishes a new regulatory category: frontier model launches are now policy events subject to government intervention, and companies whose workflows depend on a single closed model need open-source backup strategies.

Evolution: Both framed the restoration as the end of one episode and the beginning of an ongoing operational risk category, not a one-time anomaly.

Tensions

  • Anthropic and Moussouris both assess the triggering behavior as standard defensive work on engineered fake code; Zvi characterizes it more specifically as a routine 'fix this code' debugging request — yet the government never publicly addressed any counter-assessment, even when lifting the controls. [4][21][15][19][5]
  • Anthropic's July 2 post frames its safety margin — which blocks some benign uses — as a deliberate design choice to reduce classifier leakage; Zvi argues the same effect (legitimate debugging tasks falling back to lesser models) is an operational cost the ad hoc government process never weighed. [18][5]
  • Trump publicly stated he no longer views Anthropic as a national security threat, yet the administration subsequently ordered agencies and contractors to stop using Anthropic; the June 30 Commerce lift partially closes that gap without any reconciling explanation. [7][23][24][19]
  • The Commerce lift and the Pentagon supply-chain designation were issued by separate agencies; the June 30 letter addressed BIS export licensing controls but whether it also rescinds the DoD procurement designation remains unconfirmed. [8][19][9]
  • Zvi argued the directive was technically impossible to satisfy as stated; Anthropic's resolution came through a classifier fix combined with demonstrating capability parity with less capable models — a different path than the government's original framing required. [28][15][30][5]

Sources

  1. [1] Anthropic shuts down Fable, Mythos models following Trump admin directive — Ars Technica AI (2026-06-13)
  2. [2] Reuters: Amazon’s Andy Jassy was among the people who warned senior Trump officials this week about security concerns ar… — Rohan Paul Twitter (2026-06-13)
  3. [3] Amazon CEO’s Talks With U.S. Officials Triggered Crackdown on Anthropic Models - WSJ — reactive:fable-mythos-export-control
  4. [4] Quoting Matteo Wong, The Atlantic — Simon Willison (2026-06-16)
  5. [5] Fable #6: The Return of the King — Zvi's AI Roundups (2026-07-03)
  6. [6] Full Letter From Commerce Secretary Howard Lutnick to Dario Amodei — Rohan Paul Twitter (2026-06-17)
  7. [7] Not anymore: Trump on whether he sees Anthropic threatening national security — Rohan Paul Twitter (2026-06-20)
  8. [8] Pentagon says it is labeling AI company SF-based Anthropic a supply chain risk 'effective immediately' - ABC7 San Francisco — reactive:fable-mythos-export-control
  9. [9] San Francisco-based OpenAI strikes deal with Pentagon hours after President Donald Trump's administration bans Anthropic - ABC7 San Francisco — reactive:fable-mythos-export-control
  10. [10] The U.S. just reopened Anthropic’s Claude Mythos 5 for more than 100 approved institutions. — Rohan Paul Twitter (2026-06-27)
  11. [11] Anthropic just confirmed Mythos 5 is being redeployed to US organizations defending critical infrastructure. — reactive:fable-mythos-export-control (2026-06-27)
  12. [12] Reuters: A US legal tech company just sued the US federal government over the order of forced Anthropic's model shut dow… — Rohan Paul Twitter (2026-06-24)
  13. [13] Legion LegalTech, Corp. v. United States Of America 1:26-cv-02225 (D.D.C.) | Civil Rights Litigation Clearinghouse — reactive:fable-mythos-export-control
  14. [14] Quoting Anthropic — Simon Willison (2026-06-30)
  15. [15] Redeploying Fable 5 — Anthropic News (2026-06-30)
  16. [16] After spooking Trump into safety testing, Anthropic AI models get global release — Ars Technica AI (2026-07-01)
  17. [17] 😺 Fable 5 is back baby — The Neuron (2026-07-01)
  18. [18] More details on Fable 5’s cyber safeguards and our jailbreak framework — Anthropic News (2026-07-02)
  19. [19] The letter from US Commerce Secretary Howard Lutnick about lifting the export control restriction on Anthropic Fable 5. … — Rohan Paul Twitter (2026-07-01)
  20. [20] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
  21. [21] The Once And Future Fable #3: Fix This Code — Zvi's AI Roundups (2026-06-17)
  22. [22] Anthropic says Alibaba must be punished for largest Claude cloning attack — Ars Technica AI (2026-06-25)
  23. [23] OpenAI strikes deal with Pentagon after Trump orders government to stop using Anthropic — reactive:fable-mythos-export-control
  24. [24] Trump administration orders military contractors and federal agencies to cease business with Anthropic | CNN Business — reactive:fable-mythos-export-control
  25. [25] OpenAI's Pentagon deal the morning after Anthropic's ban signals how Washington now picks AI winners - Startup Fortune — reactive:fable-mythos-export-control
  26. [26] The Fable 5 Export Controls Harm US Cyber Defense - Luta Security — reactive:fable-mythos-export-control
  27. [27] American Government Takes Down Claude Fable — Zvi's AI Roundups (2026-06-13)
  28. [28] AI #173: AI Pauses — Zvi's AI Roundups (2026-06-18)
  29. [29] The Once And Future Fable #4 — Zvi's AI Roundups (2026-06-24)
  30. [30] The Once And Future Fable #5 — Zvi's AI Roundups (2026-06-30)
  31. [31] AI #175: The Fable Continues — Zvi's AI Roundups (2026-07-02)
  32. [32] Legion LegalTech sues US over Anthropic Fable 5 and Mythos 5 ... — reactive:fable-mythos-export-control
  33. [33] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  34. [34] Legion LegalTech Sues US Gov Over AI Export Control Directive — reactive:fable-mythos-export-control
  35. [35] Legal tech firm sues US over Anthropic access curbs — reactive:fable-mythos-export-control
  36. [36] Legal Tech Co. Sues US Over Anthropic AI Shutdown Order - Law360 Pulse — reactive:fable-mythos-export-control
  37. [37] Legal tech firm sues US over order limiting foreign access to top-tier Anthropic models — reactive:fable-mythos-export-control
  38. [38] The return of Fable 5. — SemiAnalysis Twitter (2026-07-02)
  39. [39] 😺 We're LIVE now (talking Fable & GPT 5.6) — The Neuron (2026-07-02)
  40. [40] FINALLY.. Claude Fable 5 and Mythos 5 are coming back. 🔥 https://t.co/6VdnFSvLRP https://t.co/OFVd1hOESd — Rohan Paul Twitter (2026-06-30)