David WalshSubscribe
Log entry · Frontier policy · Jun 15, 2026

The week Washington switched off a frontier model

On a Friday evening an export-control letter pulled Claude Fable 5 and Mythos 5 offline worldwide — three days after launch. The story is messier, and more important, than either side is saying.

On this page
  1. What actually happened
  2. Mythos & Glasswing
  3. The dispute, on the merits
  4. The legal machine
  5. Launch → shutdown
  6. The two accounts
  7. Who did what
  8. The reaction abroad
  9. My read
  10. What to do about it
  11. Caveats
A flagship, deployed to hundreds of millions, went dark over a weekend on the strength of a letter.
Executive readout3 findings

On the evening of Friday June 12, 2026 (5:21pm ET), the US Commerce Department ordered Anthropic to bar all foreign nationals — including its own staff — from using Fable 5 and Mythos 5. Unable to verify nationality per session, Anthropic disabled both models everywhere.

  • 01The trigger was a competitor’s jailbreak claim. Amazon’s CEO reportedly told officials his researchers coaxed Fable 5 into surfacing cyberattack-relevant information. Amazon is Anthropic’s largest investor and hosts the model on AWS.
  • 02The mechanism is unprecedented in scope.An “is-informed” letter under export-control authority, applied via the “deemed export” doctrine — the first time the tool has been used to halt a deployed commercial model rather than chips.
  • 03The two sides tell opposite stories.Anthropic calls it “a misunderstanding” over a narrow jailbreak; the administration says CEO Dario Amodei “refused” a reasonable safety request. As of June 15 the models remain dark with no deal.

01 What actually happened

Most regulatory stories arrive slowly. This one took ninety minutes. On the afternoon of Friday June 12, administration officials called Anthropic and gave the company roughly an hour and a half to pull its two newest models, citing a national security concern they would not specify. Anthropic asked for details. At 5:21pm ET, a letter from Commerce Secretary Howard Lutnick arrived instead, imposing export controls.

The letter required a license for the “export, re-export or domestic transfer” of Claude Fable 5 and Claude Mythos 5, with civil and criminal penalties for non-compliance. Because Anthropic cannot verify the citizenship of every API and app user in real time, there was no partial way to comply. It switched both models off for everyone on Earth — three days after Fable 5’s June 9 public launch.

A flagship product, deployed to hundreds of millions of people, went dark over a weekend on the strength of a letter whose full text has never been made public.— the part that should worry every builder

This is, by most accounts, the first time the United States has used export controls to halt a deployed commercial AI model rather than the chips and compute beneath it — and the first time a leading lab has pulled a live model offline because the federal government told it to.

02 The lineage: Mythos and Glasswing

To understand why anyone reached for export-control law, you have to understand what Fable 5 is underneath. Its capabilities trace to Claude Mythos Preview, a frontier model Anthropic disclosed in April 2026 with cybersecurity abilities that alarmed the industry. By its own red-team account, Mythos could autonomously find and exploit zero-day vulnerabilities across major operating systems and browsers, and in one case chained four bugs into a sandbox escape.

Rather than release it, Anthropic built Project Glasswing — a defensive consortium of security-critical partners (AWS, Google, Microsoft, NVIDIA, CrowdStrike, the Linux Foundation, and others) who used the model to find and patch flaws. By early June, participants had surfaced more than 23,000 vulnerabilities. This is the dual-use heart of the whole affair: the same capability that patches Firefox can, pointed the other way, look like a weapon.

On June 9, Anthropic launched Fable 5 — the public, safeguarded tier of that model — alongside the unrestricted Mythos 5 for Glasswing partners. Both share the same underlying model; only the guardrails differ. Fable routes sensitive cyber, bio, and chemistry queries down to a weaker fallback model. Anthropic said safeguards trigger in fewer than 5% of sessions and that over 1,000 hours of red-teaming found no universal jailbreak.

03 The dispute, on the merits

Strip away the politics and the technical disagreement is narrow and knowable. Anthropic says the government’s basis is “a potential narrow, non-universal jailbreak” that “essentially consists of asking the model to read a specific codebase and fix any software flaws.” Reviewing a demonstration, it found the trick surfaced “a small number of previously known, minor vulnerabilities” that other public models — including OpenAI’s GPT-5.5 — can find with no bypass at all.

“The government response seems way out of line with what’s actually in the research report” — researchers found vulnerabilities by asking the questions normal defenders would ask, “which is exactly what the model was intended to do.”

Katie Moussouris, Luta Security — who reviewed Amazon’s report

The administration’s account, delivered by David Sacks on X, is that a “highly credible trusted partner” came forward with a jailbreak, that Anthropic was asked to fix it or de-deploy, and that Amodei refused — choosing, in Sacks’s framing, “the continued offering of the consumer model over safety.” The two stories are not quite contradictory on facts; they diverge on what a narrow jailbreak in a frontier model warrants.

The government has not published the directive or its precise statutory basis, which is itself part of the problem. The most credible named analysis — from Brian Egan, a former State and NSC legal adviser — assesses the authority as “most likely” the Export Controls Reform Act of 2018, exercised through a private “is-informed” letter telling Anthropic that a license is now required.

The piece that forced a global shutdown is the “deemed export” doctrine: releasing controlled technology to a foreign national — even one standing inside the United States — counts as an export to their home country. A model that anyone in the world can hit through an API cannot be walled off by citizenship in real time. As one analyst put it: the munition is in the building, and the people who made it are not allowed to look at it.

There is a genuine legal hole here. The Biden-era classification for advanced AI model weights was reportedly rescinded in May 2025, so the directive apparently did not rest on it — and the action sits in open tension with Trump’s own June 2 executive order, which explicitly barred mandatory licensing for frontier models.

How a launch became a shutdown

Apr 7 → Jun 15, 2026
Apr 72026

Project Glasswing announced

Mythos Preview offered to a defensive cybersecurity consortium rather than released openly.

Jun 22026

Trump signs AI innovation & security EO

Establishes a voluntary pre-deployment review framework and explicitly bars mandatory licensing for frontier models. Glasswing expands by 150 organizations the same day.

Jun 92026

Fable 5 & Mythos 5 launch

The first publicly available Mythos-class model. Same day, Amodei publishes a policy piece citing Mythos as the emblematic example of frontier risk.

Jun 9–112026

The “secret sabotage” backlash

Researchers find a hidden safeguard that silently degrades frontier-LLM-development help. Anthropic reverses the covert mechanism within ~48 hours.

Jun 112026

Amazon raises concerns

Andy Jassy reportedly flags a jailbreak to officials including Treasury Secretary Bessent; the findings are run past the NSA. At least five other firms reportedly warn too.

Trigger
Jun 12 · 1:15pmET

The 90-minute call

Officials phone Anthropic and give it roughly 90 minutes to pull the models, citing an undefined national security concern. Anthropic asks for details.

Jun 12 · 5:21pmET

Lutnick’s letter — export controls imposed

Unable to wall off foreign nationals, Anthropic disables Fable 5 and Mythos 5 for everyone and posts a statement.

Shutdown
Jun 132026

The accounts go public

Sacks posts the administration’s version; WSJ/Reuters report the Amazon trigger; Anthropic disputes a China-access rationale. Zhipu releases GLM-5.2 as an open alternative.

Jun 13–142026

Anthropic sends staff to Washington

Senior technical negotiators dispatched over the weekend. Talks ongoing.

Jun 152026

Still offline

Commerce is set to meet Anthropic staffers; meetings also scheduled with the CIA and the White House science adviser. No deal, no restoration timeline.

You are here

The two accounts

Same event · opposite stories
The lab

Anthropic

  • The basis is a narrow, non-universal jailbreak — asking the model to read a codebase and fix flaws.
  • It surfaced only minor, previously-known bugs that other public models find without any bypass.
  • The government gave “verbal evidence” only; the letter “did not provide specific details.”
  • Recalling a model over a narrow jailbreak would “essentially halt all new model deployments” industry-wide.
“We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people.”Anthropic blog post · June 12
The administration

The White House

  • A “highly credible trusted partner” testing Fable came forward with a jailbreak of the guardrails.
  • Anthropic was asked to fix it or de-deploy the model.
  • Amodei refused — prioritizing the consumer model “over safety.”
  • Inconsistent with Anthropic’s own branding, having marketed Mythos as near-cyberweapon.
“The Admin asked Dario to fix the jailbreak or de-deploy the model. Dario refused… The ball is in Anthropic’s court.”David Sacks on X · June 13

Who did what

Key players
Anthropic
  • Dario Amodei
    CEO & co-founder — recipient of the letter
  • Tom Brown
    Co-founder, chief compute officer — weekend talks
  • Logan Graham · Dave Orr · Nicholas Carlini
    Risk, safeguards & security — technical negotiators in DC
  • Sarah Heck
    Public policy chief
Administration
  • Howard Lutnick
    Commerce Secretary — signed the directive
  • David Sacks
    PCAST co-chair — public defender of the action
  • Scott Bessent
    Treasury Secretary — received Jassy’s concerns
  • Michael Kratsios
    Science adviser. President Trump signed off.
Amazon
  • Andy Jassy
    CEO — reportedly raised the jailbreak concern
  • The conflict
    Amazon is Anthropic’s largest investor and hosts Fable 5 on AWS Bedrock.
  • Amazon’s line
    “It’s not uncommon for governments to seek our counsel… we don’t share the details.”

05 The reaction abroad

The most durable consequences may be the ones that happened outside Washington. In India — reportedly Anthropic’s second-largest market — the shutdown landed as confirmation of a thesis sovereign-AI advocates had been pushing for years.

You should not confuse access with ownership. If your most significant differentiator has external control loops, you have to accept that you are vulnerable.— Pratyush Kumar, Sarvam (paraphrased)

The competitive response was faster still. Within roughly a day, the Chinese lab Zhipu shipped GLM-5.2— a large open-weights model explicitly positioned as the alternative, at a fraction of Claude’s premium pricing. Whatever the merits of the ban, its clearest immediate beneficiary was a model the US controls not at all.

Even sympathetic policy voices balked at the breadth. Targeted controls might be “prudent,” argued one CFR analyst, but a universal ban is “highly questionable” — and the deemed-export piece “absurd.” The recurring note: banning allied nationals from a US model while still exporting AI chips to China is hard to square as strategy.

06 My read

I don’t think the interesting question is whether the jailbreak was real. Narrow jailbreaks are always real; that’s the nature of the things. The interesting question is what just got demonstrated about the shapeof the dependency we’ve all been building on.

A frontier model is not infrastructure you own. It is access you are granted, and access can be revoked — over a weekend, by letter, without published reasons, faster than you can read the statute. That is true whether you find the government’s case persuasive or Anthropic’s. The mechanism is now precedent regardless of how this particular standoff resolves.

What to actually do about it

For builders
1

Treat frontier access as a revocable dependency

If a workflow’s core differentiator runs on a single closed US model, you carry geopolitical single-point-of-failure risk. What would change this: a published, statutory, appealable process for model restrictions — which Anthropic itself is now demanding.

2

Wire in a tested fallback path now

Opus 4.8, GPT-5.5, and open-weights options stayed live through the shutdown. Keep at least one non-Anthropic and one open-weights model in critical pipelines. Trigger to act: if your team includes non-US nationals and relies on Fable/Mythos-class capability, assume re-exposure risk on any future frontier launch.

3

Watch three concrete signals

(a) any Commerce action lifting or formalizing the control; (b) whether a joint technical review yields a “fixed” jailbreak and partial restoration; (c) whether the classified frontier-model benchmarking process is invoked. Resolution on (a)/(b) likely restores Fable; escalation on (c) signals a durable licensing regime.

4

Make model choice swappable

Prefer architectures where the model sits behind an abstraction layer, and document data-retention exposure. Assume “trusted access” tiers can be reclassified without notice.

Caveats · what we don’t know
  • The directive’s text and exact legal basis are not public.ECRA + “is-informed” letter is expert inference, not a confirmed government statement; the deemed-export mechanism is widely cited but unconfirmed.
  • Accounts conflict and are partly anonymous.Whether Amodei “refused” to fix the jailbreak versus was never given written evidence is disputed. The “China-linked access” rationale comes from a single anonymous source and is denied by Anthropic.
  • The “first ever” framing is contested. Dual-use controls have long applied to novel technologies; the more precise claim is that the breadth is unprecedented.
  • Capability and benchmark figures originate largely from vendor claims or early third-party tests and are not fully independently verified.
  • This is a fast-moving story; status is current as of June 15, 2026.