The Call at 5:21 p.m.
On the evening of June 12, 2026, Anthropic received a letter from the U.S. Department of Commerce. At 5:21 p.m. Eastern Time, according to the company’s own timeline, the letter ordered Anthropic to block access to its two most powerful models — Claude Fable 5 and Claude Mythos 5 — for every foreign person, inside and outside the United States, explicitly including its own employees without a U.S. passport. 1 A few hours later, developers around the world began receiving 404 errors on their API calls; the homepage stated that Fable 5 was “temporarily unavailable.” 2
Two things are remarkable. First, the speed: Fable 5 had only been publicly launched on June 9, with significant attention and with the claim that it was the company’s most capable generally available model ever. 3 Three days later, it was gone again. Second, the scope: according to several media assessments, this is the first time a leading AI lab has taken an already publicly deployed model offline following intervention by the federal government. 24
According to Bloomberg and NBC News, among others, the letter came from Commerce Secretary Howard Lutnick and was drafted with the involvement of the Bureau of Industry and Security (BIS), the agency responsible for export controls. 42 Anthropic stated that it would comply with the legal order, but considered it disproportionate. All other models, including Claude Opus 4.8, remained unaffected. 1
This text puts the event into context: what Fable 5 and Mythos 5 are, what the backstory is, what the technical issue was, how the legal lever works — and why the case above all shows one thing: artificial intelligence has become a strategic asset whose distribution is no longer governed by product logic alone.
What Fable 5 and Mythos 5 Are
To understand the conflict, one needs to understand the architecture of the models. Anthropic places Fable 5 and Mythos 5 in a new “Mythos class,” positioned above the previous top tier, Opus. 3 Both share the same base model. The difference does not lie in capability, but in the safeguards: Mythos 5 is the unrestricted version and is available only to a small circle of vetted partners; Fable 5 is the same machine with built-in safety mechanisms, released for broad use. 35
The performance data Anthropic presented at launch is substantial: top scores across almost all tested benchmarks, especially in software development, knowledge work, image understanding, and scientific research; the longer and more complex the task, the clearer the lead. 3 On the widely followed coding benchmark SWE-Bench Pro, Fable 5 solved around 80 percent of tasks according to one analysis, compared with nearly 69 percent for Opus 4.8 and just over 58 percent for GPT-5.5. 6 The price was ten dollars per million input tokens — less than half of what the earlier Mythos preview had cost. 7
Fable 5 moved from product launch to access-control problem within days.
From a safety perspective, Fable 5 follows an unusual approach that observers call “graceful degradation,” or a fallback strategy: instead of simply refusing a sensitive request, the model routes requests from high-risk areas — cybersecurity, biology, chemistry, and attempts at “distillation,” meaning the extraction of capabilities to train competing models — to the weaker, safeguarded Opus 4.8. 58 According to one analysis, this mechanism is triggered in fewer than five percent of sessions. 9
Model access is now entangled with distillation risk, export controls, and strategic competition.
The name itself tells the safety story. “Fable” goes back to the Latin fabula, “that which is told” — related to the Greek mythos. 10 Behind the friendly etymology lies a hard trade-off, which Anthropic openly acknowledges: releasing such a capable model carries risks; without safeguards, capabilities in areas such as cybersecurity could cause significant harm. 3
The Backstory: Why This Shutdown Is Not an Isolated Case
Anyone who reads the June 12 letter as an isolated event misses a months-long confrontation. It began after a meeting between Defense Secretary Pete Hegseth and Anthropic CEO Dario Amodei in February 2026. 11 At its core was the question of how the U.S. military may use Claude. Anthropic drew two red lines: no mass surveillance of American citizens, and no fully autonomous weapons without human control over targeting and fire decisions. 1211
The Pentagon saw things differently. Its position, repeatedly stated publicly: a private company cannot tell the state how it may use technology in wartime or operational contexts; it claims the right to use it for “all lawful purposes.” 1213 That view is not absurd — governments have always argued that sovereign functions should not be limited by suppliers. It is a serious, legitimate tension between corporate self-restraint and the state’s claim to act.
When the negotiations failed, the Department of Defense classified Anthropic as a “supply chain risk” — a label that security experts say is usually reserved for suppliers from adversarial states and is highly unusual when applied to a U.S. company. 1114 As a result, President Trump instructed all federal agencies to stop using the company’s tools; the General Services Administration terminated the government-wide “OneGov” contract. 14 On March 9, 2026, Anthropic sued in two courts — in the Northern District of California and before the appeals court in Washington, D.C. — invoking the First Amendment and due process; the action, it argued, was unprecedented and unlawful. 1215 The case is ongoing.
Against this backdrop, the Fable 5 directive is the latest stage of a longer escalation. Two details bring it into focus: according to information that a government official gave to Axios, the agency acted after another company claimed to have “cracked” Mythos. 16 The same source also reports that the government had previously tried unsuccessfully to delay the model’s launch. 16
The Technical Core: What Was the “Jailbreak”?
The trigger, according to Anthropic, was a narrowly defined, non-universal “jailbreak.” In essence, it involved having the model read a specific piece of code and fix software bugs in it. 1 Anthropic emphasizes that it examined a demonstration of the technique; it revealed a few already known, minor vulnerabilities — weaknesses that other publicly available models would also find without any circumvention trick. 1
A distinction is worth making here, because it sits at the center of the dispute: a universal jailbreak would be a method that broadly bypasses safeguards and unlocks a wide range of dangerous capabilities. A non-universal jailbreak extracts something from the model only in a specific individual case. Anthropic states that in more than a thousand hours of external and internal testing — with participation from the U.S. government, the U.K. AI Safety Institute, and several third parties — no universal jailbreak was found; so far, it has not even received a report of a concerning non-universal jailbreak that led to a harmful result. 1 The disclosed potential circumventions were either completely harmless or minor and provided no Mythos-specific advantage.
This is the basis of Anthropic’s core argument: the capability in question — reading code and fixing bugs — is broadly available, including through OpenAI’s GPT-5.5, which is not subject to comparable export controls, and is used every day by defenders who secure systems. 71 The company also defends its “defense in depth” strategy: because perfect jailbreak resistance does not currently seem achievable for any provider, the aim is to keep circumventions either narrow or very expensive, and to combine this with monitoring in order to detect and stop successful attacks quickly. This also includes the costly 30-day retention of customer data for Fable so that jailbreaks can be researched and contained. 1
It is important to take both sides seriously. From the perspective of a security agency, even a narrow circumvention path to a Mythos-class model can be sensitive because the underlying capabilities are so large. The difference lies less in the facts than in proportionality: does the discovery of a narrow, non-universal jailbreak justify the recall of a commercial model delivered to hundreds of millions of people? Anthropic says no and warns that if such a criterion became the industry standard, it would effectively bring every new model launch by every leading provider to a halt. 1
The Mechanism: Why You Have to Shut It Down for Everyone in Order to Exclude Foreign Nationals
At first glance, the event is confusing: the order concerns “foreign nationals” — so why does Anthropic shut it down for everyone, including U.S. citizens? The answer lies in export control law and in the concept of a “deemed export.”
Since January 2025, the weights of the most advanced closed AI models have been subject to U.S. export controls. As part of the “Framework for Artificial Intelligence Diffusion,” BIS created a dedicated control number for this purpose, ECCN 4E091, and generally requires a license for the export of such model weights. 1718 Covered are closed, unpublished weights above a compute threshold of more than 10^26 operations during training. 18
The decisive term is “deemed export”: the release of controlled technology to a foreign person is legally treated as an export — even if that person is located inside the United States. 19 A person working in the United States without U.S. citizenship who uses a controlled model is, from the perspective of the regulation, an export event. Because a commercial AI service cannot reliably verify the citizenship of its users in real time for every request, there is only one way to comply fully with the requirement: shut the model down for everyone. 9 That is exactly what Anthropic did — while also asking its cloud partners to block access; Amazon, for example, removed access to Fable 5 and Mythos 5 on Bedrock. 20
This lever is legally elegant and practically brutal at the same time. It turns a restriction aimed at foreigners into a de facto full shutdown — without the agency having to order that explicitly.
The Real Issue: AI Has Become a Weapon
This is the point that reaches beyond the individual case. The government is treating a language model not like an app, but like a strategic asset. That only makes sense if one acknowledges what these models can now do — and that the same capabilities can both defend and attack.
Anthropic itself provided the proof. In April 2026, the company introduced Claude Mythos Preview — a model that, according to Anthropic’s own description, can autonomously find previously unknown security vulnerabilities, known as zero-days, and build exploits for them. 2122 In the associated defense program “Project Glasswing,” Anthropic and its partners, according to company statements, identified more than 10,000 serious to critical vulnerabilities in core software — including every major operating system and every major web browser. 2223 According to reports, the partners included companies and institutions such as Okta, Samsung, SK Hynix, SK Telecom, NATO, and the EU cybersecurity agency ENISA. 24
The logic behind this is that of dual-use technology: what finds vulnerabilities in order to close them can find the same vulnerabilities in order to exploit them. Anthropic itself puts it this way — the capabilities that make a model dangerous in the wrong hands also make it invaluable for finding and fixing bugs. 22 This dual nature is precisely why export controls apply in the first place: already in 2025, BIS explicitly justified the AI rules with the “dual-use nature” of the technology. 25
The context makes the stakes tangible. Security experts describe 2026 as a year of an AI-driven arms race in cyberspace: attackers automate reconnaissance, social engineering, and exploitation of vulnerabilities at machine speed, while defenders must respond with equally fast systems. 26 In the DARPA AI Cyber Challenge, autonomous systems found 18 zero-days and patched a large share of them within 45 minutes without human intervention. 27 What once took months is now considered possible in hours. On top of that comes the spread of “uncensored” model variants: when Google released open weights, Gemma 4, in April, uncensored versions appeared in public repositories within days. 23 And the competition is not standing still — OpenAI released GPT-5.5-Cyber, its own cybersecurity-focused model, to a larger circle of partners. 24
This makes clear where things are heading: if a government can pressure a company over such capabilities — or shut down a model — then that is an enormous lever and evidence of how high the stakes have become. AI is no longer merely a productivity tool; it has become an instrument of state power. Whoever controls it controls a capability that matters for the economy, public safety, and national defense alike. Anthropic itself has warned precisely of this: such capabilities would soon also become available beyond the actors committed to safe deployment — with potentially serious consequences for economies, public safety, and national security. 22
The Historical Mirror: The Crypto Wars
This pattern is not new. In the 1990s, the U.S. government classified strong encryption as “munitions” — regulated under the International Traffic in Arms Regulations, ITAR, in the same category as grenades and tanks. 2829 When developer Phil Zimmermann released his encryption program PGP in 1991 and it spread worldwide over the internet, the U.S. Department of Justice opened a multi-year criminal investigation against him — over the alleged “export of weapons.” 3029
The legal counterarguments also sound familiar. In Bernstein v. United States, courts held that source code was a form of speech and therefore protected by the First Amendment. 29 In 1996, President Clinton removed commercial encryption from the munitions list by Executive Order 13026 and transferred it to the civilian Commerce Control List. 28 The “Crypto Wars” ended with a clear victory for strong encryption; controls were relaxed because the technology was already globally available and the internet does not recognize borders — today, SSL/TLS encrypts almost every connection as a matter of course. 31
The parallels are striking: a piece of software considered security-relevant because of its dual-use nature; a trigger in the form of global availability; a dispute over the First Amendment; and the argument that controls become ineffective as long as comparable capabilities are freely available elsewhere. Export control law already knows this exact argument of “foreign availability”: it allows the agency to loosen controls if comparable goods are available from abroad. 32
The difference, however, is just as important as the similarity. Encryption is a clearly defined mathematical procedure; a frontier AI model is an open-ended capability that continues to improve and whose risks are harder to define. What history nevertheless teaches was summarized succinctly by security researcher Ross Anderson with regard to the Crypto Wars: conflicts of this kind can be resolved as long as lawmakers make the effort to understand a technology before regulating it. 33
Why This Is a Dangerous Game
The question remains: what is actually risky about this event, beyond the concrete inconvenience for customers? Several structural points deserve attention; they are intended as sober observations, not as a verdict.
First, the concentration of power. The fact that a tool used by hundreds of millions of people can be shut down within hours shows how much control lies in very few places — with the provider that flips the switch, and with the authority that can compel it to do so. A single point of control is efficient and dangerous at the same time.
Second, the precedent. If the discovery of a narrow jailbreak is enough to recall a model, then — according to Anthropic’s argument — all frontier launches come under reservation. 1 If models are treated like munitions requiring an export license, the logic of the entire industry shifts: away from product release and toward state-approved diffusion. Several observers interpret the move as a signal that the United States is prepared to treat frontier models like semiconductors or defense goods. 34
Third, a safety paradox. The very lab that, according to both its own and independent accounts, had built in particularly strong safeguards was shut down — while the unrestricted Mythos version remains available to vetted partners. 15 This raises an uncomfortable incentive question: do labs that speak openly about the capabilities and risks of their models thereby become more vulnerable? Transparency should be rewarded, not punished.
Fourth, the asymmetry. Defenders are bound by safety, law, and compliance; attackers and uncensored, open-weight models are not. 26 Taking a safeguarded model off the market does not remove the underlying capability from the world — it continues to exist in uncontrolled variants and in models from other countries. Control in one place is not the same as control everywhere.
What is notable is that both sides, in principle, want the same thing. Anthropic has publicly stated that the state should be able to block unsafe launches — but within a process that is transparent, fair, clear, and based on technical facts; in this case, Anthropic says those standards were not met. 1 The conflict is therefore less about whether there should be government oversight, and more about how that oversight should work. That is a comparatively hopeful reading: it is about process, not principle.
For everyone building on or depending on frontier models — developers, founders, entire industries — this has a practical consequence: anyone who ties their business to the most capable model tier now carries geopolitical and regulatory risk. Availability can change overnight; the sober answer is diversification and resilience, not alarmism.
What Remains
The episode around Fable 5 will probably be resolved; Anthropic describes the event as a misunderstanding and is working to restore access. 1 More important than the outcome of this individual case is what it marks: the moment when frontier AI turned from a product into a strategic asset. The questions therefore shift. They are no longer only about what a model can do, but also: who decides how it is distributed, according to what process, and with how much transparency?
The Crypto Wars suggest that controls over globally available software erode over time — but the transition can be costly and chaotic. The real task is therefore less about shutting things down than about building: institutions, norms, and infrastructure for a world of faster, cheaper cyber capabilities before those capabilities spread unchecked. Programs such as Glasswing are one attempt in that direction; whether they will take effect quickly enough remains open.
Until then, the conclusion remains uncomfortable and clear at the same time: the kill switch exists, it works, and the hand on the switch has become a matter of strategic weight. Anyone watching this game should take it seriously for what it is — not a product dispute, but an early chapter in the geopolitics of artificial intelligence.
Sources & Notes
Research status: June 13, 2026. The following sources were evaluated for this article; the primary source is Anthropic’s official statement from June 12, 2026.
Footnotes
-
Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5,” 12.6.2026 · anthropic.com/news/fable-mythos-access ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12
-
NBC News, “Anthropic suspends new AI models after government directive,” 12.6.2026 · nbcnews.com ↩ ↩2 ↩3
-
Anthropic, “Claude Fable 5 and Claude Mythos 5,” 9.6.2026 · anthropic.com/news/claude-fable-5-mythos-5 ↩ ↩2 ↩3 ↩4 ↩5
-
Bloomberg, “Anthropic Says US Orders Halt to Foreign Access for Fable 5, Mythos 5 AI Models,” 13.6.2026 · bloomberg.com ↩ ↩2
-
Amazon Web Services, “Anthropic Claude Fable 5 on AWS …,” updated 12.6.2026 · aws.amazon.com ↩ ↩2 ↩3
-
SWE-Bench Pro values according to analysis by P. Pillitteri, 9.6.2026 · pasqualepillitteri.it ↩
-
Fortune, “Anthropic disables Fable and Mythos AI models …,” 13.6.2026 · fortune.com ↩ ↩2
-
The Decoder, “Anthropic releases Claude Fable 5 and Mythos 5 …,” June 2026 · the-decoder.com ↩
-
MarkTechPost, “Anthropic Disables Claude Fable 5 and Mythos 5 After US Government Order,” 13.6.2026 · marktechpost.com ↩ ↩2
-
Appwrite, “Anthropic just launched Claude Fable 5 and Claude Mythos 5” on the origin of the name, June 2026 · appwrite.io ↩
-
NPR, “Anthropic sues the Trump administration over ‘supply chain risk’ label,” 9.3.2026 · npr.org ↩ ↩2 ↩3
-
PBS NewsHour / AP, “Anthropic sues in federal court to reverse … ‘supply chain risk’ designation,” 9.3.2026 · pbs.org ↩ ↩2 ↩3
-
CNN Business, “Anthropic sues the Trump administration after it was designated a supply chain risk,” 9.3.2026 · cnn.com ↩
-
Pearl Cohen, “Anthropic Sues Department of Defense Over Supply Chain Risk Designation,” 26.3.2026 · pearlcohen.com ↩ ↩2
-
Al Jazeera, “Anthropic sues Trump administration to undo US ‘supply chain risk’ tag,” 9.3.2026 · aljazeera.com ↩
-
9to5Mac, citing Axios, “Anthropic pulls Claude Mythos 5 and Claude Fable 5 …,” 12.6.2026 · 9to5mac.com ↩ ↩2
-
U.S. Bureau of Industry and Security, “Framework for Responsible Diffusion of Advanced AI,” 13.1.2025 · bis.gov ↩
-
Freshfields and Sidley Austin, analyses of ECCN 4E091 and the 10^26 threshold, January 2025 · freshfields.com; sidley.com ↩ ↩2
-
RAND, “Understanding the Artificial Intelligence Diffusion Framework” on the concept of deemed export, 14.1.2026 · rand.org ↩
-
Amazon Web Services, notice on the blocking of Fable 5 and Mythos 5 on Bedrock, 12.6.2026 · aws.amazon.com ↩
-
Help Net Security, “Anthropic: Claude Mythos identified 10,000+ software flaws,” 26.5.2026 · helpnetsecurity.com ↩
-
Anthropic, “Project Glasswing: Securing critical software for the AI era,” 7.4.2026 · anthropic.com/glasswing ↩ ↩2 ↩3 ↩4
-
CETaS, Alan Turing Institute, “Claude Mythos: What Does Anthropic’s New Model Mean for the Future of Cybersecurity?,” 2026 · cetas.turing.ac.uk ↩ ↩2
-
TechCrunch, “Anthropic scales Claude Mythos to critical infrastructure in 15+ countries,” 2.6.2026 · techcrunch.com ↩ ↩2
-
U.S. Bureau of Industry and Security on the “dual-use nature” of AI, 13.1.2025 · bis.gov ↩
-
WebProNews, “The AI Arms Race …,” 30.1.2026; Dark Reading, “Cyber Predictions 2026,” 31.12.2025 · webpronews.com; darkreading.com ↩ ↩2
-
TechInformed, “Cybersecurity predictions 2026 …” on the DARPA AI Cyber Challenge, 5.1.2026 · techinformed.com ↩
-
“Crypto Wars” overview of ITAR and Executive Order 13026 · en.wikipedia.org/wiki/Crypto_Wars ↩ ↩2
-
Reason, “When Encryption Was a Crime …,” 2020; Immunity Networks, “Phil Zimmermann: PGP, the Crypto Wars …,” 17.4.2026 ↩ ↩2 ↩3
-
Vice, “How the Government Is Waging Crypto War 2.0,” 2024 · vice.com ↩
-
Immunity Networks, “Phil Zimmermann: PGP, the Crypto Wars, and the Right to Encrypted Communication,” 17.4.2026 ↩
-
Just Security, “AI Model Outputs Demand the Attention of Export Control Agencies” on foreign availability, 12.12.2025 · justsecurity.org ↩
-
Open Rights Group, “Crypto Wars” quoting Ross Anderson · wiki.openrightsgroup.org ↩
-
Crypto Briefing, “Anthropic cuts global access to Mythos models after US export controls,” June 2026 · cryptobriefing.com ↩