David WalshSubscribe
Log entry · Frontier policy · Jul 1, 2026

Washington switched the model back on

Nineteen days after an export-control letter pulled Claude Fable 5 and Mythos 5 offline, the controls were lifted and the models returned. What Anthropic conceded to get them back is the real story — and the precedent is now load-bearing.

On this page
  1. What actually happened
  2. The settlement
  3. The fix, measured
  4. Two doors reopened
  5. Shutdown → restoration
  6. My read
  7. What to do now
  8. Caveats
Jun 12 – Jun 30OFFLINEPulled by export-control letter
Jul 1, 2026RESTOREDControls lifted Jun 30
Dark for 19 daysFirst deployed frontier model pulled by the state — and returned
Executive readout3 findings

On June 30 the US Commerce Department lifted the export controls it had imposed on Claude Fable 5 and Claude Mythos 5. Fable 5 returned to users worldwide on July 1; the unrestricted Mythos 5 came back only for approved US organizations, after government review.

  • 01The models came back on terms. Anthropic retrained the safety classifier that failed, opened a public bounty for new jailbreaks, and gave the government a standing seat at future launches. The switch flipped back — but not to where it was.
  • 02The cure deepens the dependency the ban exposed. The resolution was a private bilateral deal — early classified access, shared threat intel, a common security standard — not the published, appealable process Anthropic had demanded. Lab and state are now more entangled, not less.
  • 03The precedent is intact and now tested end to end. A letter can pull a live model; a negotiation can restore it. Every builder just watched the full loop run — revocation and reinstatement both by discretion, neither by statute.

01 What actually happened

Two weeks ago I wrote up the weekend Washington switched a frontier model off — a Friday-evening export-control letter that forced Anthropic to pull Fable 5 and Mythos 5 for everyone on Earth, three days after launch. That piece ended on a live status line: models still offline, no deal. This is the other end of the story.

On June 30, the Commerce Department rescinded the “is-informed” letter and lifted the controls. The next day, Anthropic began restoring service. Fable 5 — the public, safeguarded tier — returned globally across the Claude Platform, Claude.ai, Claude Code, and Cowork. Mythos 5, the unrestricted sibling, was reintroduced only to a set of approved US organizations following a government review of who gets access.

The clean version of this story is “the government overreached, then backed down.” That version is wrong, or at least incomplete. Nobody backed down for free. The models are back because Anthropic agreed to a list of things — and that list, not the reversal, is what will matter in a year.

The interesting artefact isn’t that the switch flipped back. It’s the invoice that came with it.— why the settlement is the story

The settlement

What changed hands
Anthropic conceded

What it gave

  • Retrained the safety classifier so the reported technique is now blocked in more than 99% of cases — accepting more false positives on legitimate coding requests as the cost.
  • Opened a public HackerOne program inviting researchers to report new Fable 5 jailbreaks, turning a private failure into an ongoing bounty.
  • Committed to hunt for security problems itself, coordinate with government on future launches, and report malicious use it detects.
  • Promised designated US agencies earlier access to test future frontier models and their safeguards before public release.
A classifier retrain, a bounty, and a standing pre-release review — the price of the reversal was structural, not a one-time patch.Terms per Anthropic’s statement · reporting
Anthropic recovered

What it got back

  • Fable 5 live again for users worldwide — the consumer and developer tiers it was never willing to abandon.
  • Mythos 5 restored for approved US organizations, keeping the Glasswing defensive program alive under tighter access control.
  • A resolution before its confidential S-1 became a public filing with a “the government can switch off our flagship” risk factor unresolved.
  • A working relationship with Commerce that it can point to — even if the published, appealable process it asked for never materialized.
“We’re deepening our collaboration with the US government” — early access, shared threat intelligence, and work toward a common security standard.Anthropic · restoration statement

02 The fix, measured

The technical heart of the dispute was always narrow: a jailbreak that coaxed Fable 5 into reading a codebase and surfacing exploitable flaws. Anthropic’s answer was to retrain the classifier that gates sensitive cyber queries. By its own account the reported technique is now caught almost every time — with a tradeoff it was unusually candid about.

99%+
of the reported jailbreak now blocked by the retrained classifier — at the cost of more false positives on legitimate coding and security work.
BlockedFalse-positive cost to real work

That candour matters. A classifier tuned to block a bypass will inevitably refuse some honest questions — the security engineer auditing her own service, the developer asking why a dependency looks unsafe. Anthropic ate that cost publicly rather than claim a free lunch, which is the right call and a real regression in day-to-day usefulness at the same time.

Two doors reopened

Not the same width

Fable 5

Global

The safeguarded public tier, back for everyone across Platform, Claude.ai, Claude Code, and Cowork. Sensitive cyber and bio queries still route to a weaker fallback; now the classifier in front of that route is tighter.

Who: anyone, worldwide

Mythos 5

US-approved only

The unrestricted Glasswing model, reintroduced only to approved US organizations after a government review. Same underlying weights as Fable — the difference has always been the guardrails and, now, the gate on the door.

Who: vetted US partners

The asymmetry is the tell. The consumer product came back universal; the frontier capability came back inside a US-vetted enclave. Whatever else the episode settled, it drew a sharper line between the model you can rent from anywhere and the model you can only touch from the right jurisdiction with the right paperwork.

Shutdown to restoration

Jun 12 → Jul 1, 2026
Jun 12 · 5:21pmET

The letter — models go dark

Unable to wall off foreign nationals under the deemed-export doctrine, Anthropic disables Fable 5 and Mythos 5 for everyone.

Shutdown
Jun 13–142026

Anthropic sends staff to Washington

Senior technical negotiators dispatched over the weekend; Commerce, CIA, and the White House science adviser on the calendar.

Jun 15–272026

Two weeks of quiet talks

No public deal, no restoration date. GLM-5.2 keeps circulating as the open-weights alternative that the US controls not at all.

Jun 302026

Commerce lifts the controls

The “is-informed” letter is rescinded after Anthropic agrees to retrain the classifier, open a bounty, and deepen government collaboration.

Reversal
Jul 12026

Restoration begins

Fable 5 returns worldwide; Mythos 5 comes back for approved US organizations. Total dark time: 19 days.

You are here

03 My read

In the ban piece I argued the scary thing wasn’t the jailbreak — narrow jailbreaks are always real — but the shapeof the dependency it exposed: a frontier model is access you’re granted, revocable over a weekend by letter, faster than you can read the statute. The restoration doesn’t soften that. It completes it.

Because now we’ve seen the whole cycle. The state can pull a deployed model, and a lab can get it back — but the currency of restoration is deeper integration with the state that pulled it. Early classified access to unreleased frontier models. Shared threat intelligence. A push toward a common security standard set with government at the table. None of that is inherently bad; some of it may be genuinely good for safety. But it is the opposite of the arms-length, statutory, appealable regime Anthropic itself said the industry needed.

The model came back. The leverage that took it away didn’t — it just changed from a threat into a relationship.— the durable outcome

For everyone building on frontier models, the lesson from June didn’t expire on July 1. If anything it got a worked example. The dependency is real, the switch is real, and the cure for being switched off is to stand closer to the hand on the switch.

What to actually do now

For builders
1

Keep the fallback you wired in June

If you added a non-Anthropic and an open-weights path during the outage, don’t rip it out now that Fable is back. The next launch carries the same re-exposure risk; a tested fallback is cheap insurance that already paid off once.

2

Re-test your prompts against the stricter classifier

The retrain trades false positives for safety. Security-adjacent and code-audit workflows that worked in May may now refuse. Re-run your evals against Fable 5 before assuming parity, and file false positives through the new bounty channel.

3

Treat Mythos-class access as jurisdictional

Frontier capability came back gated to vetted US orgs. If your roadmap assumed open access to that tier, assume paperwork and a jurisdiction test instead — and design around the safeguarded Fable tier as the default.

4

Watch what the deal standardizes

The consequential clause isn’t the classifier; it’s “a common security standard” and pre-release government access. If that hardens into an industry norm, it reshapes how every frontier model ships. That’s the signal to track through the rest of the year.

Caveats · what we don’t know
  • The full agreement isn’t public.The concession list is drawn from Anthropic’s statement and reporting; the rescinded letter and any side terms were never published, just as the original directive wasn’t.
  • “99%+ blocked” is a vendor classifier claim.It reflects Anthropic’s own evaluation of the reported technique, not an independent audit, and says nothing about jailbreaks not yet reported.
  • The Mythos 5 access criteria are opaque.Who counts as an “approved US organization,” and who decides, has not been disclosed.
  • The 19-day figure is calendar time from the Jun 12 letter to the Jul 1 restoration; the exact moment service fully returned for every surface may vary.
  • This is a fast-moving story; status is current as of July 1, 2026.