Anthropic received a letter that knocked its two most powerful Claude models off the internet within hours. The U.S. Department of Commerce invoked an obscure export directive and banned access to the Fable 5 and Mythos 5 models for anyone who is not a U.S. citizen. Including Anthropic's own employees. The company chose to shut down both models entirely to comply with the order.
And this is where a story begins that appears to be about AI safety but actually reeks of politics.
The Fable and Mythos models
Mythos is a so-called frontier model—the best and most powerful model Anthropic can build. When the company first unveiled it in April, it admitted that it was too good at hacking to be released into the world. So instead of making it publicly available, it gave access to only a handful of organizations, mostly U.S. technology companies, which were supposed to use it to patch vulnerabilities in critical digital systems.
Fable is the same underlying model, but with added safeguards. These are intended to prevent it from being misused to attack computer networks. It was Fable that became publicly available last week. And within three days, it was gone again.
A dispute that had been simmering since spring
Anthropic and the Trump administration had been at odds from the start. Their relationship has grown increasingly tense since the beginning of 2026. The government accused the company of building so-called “woke AI” and called CEO Dario Amodei an “ideological lunatic.”
At first, they argued over AI regulations and chip exports. The dispute escalated when Anthropic refused to give the Pentagon access to its models for domestic surveillance and fully autonomous weapons systems. The Department of Defense responded by threatening to designate the company a “supply chain risk.” Such a label would force military contractors to end all cooperation with Anthropic.
Once you know this, you simply look at the letter sent to Anthropic differently...
The official version
To this day, the government has not publicly explained why it invoked the directive. Anthropic believes that officials discovered a so-called jailbreak—a way to bypass Fable's safeguards and access its most powerful capabilities for malicious purposes.
How do those safeguards actually work? Before a user's request reaches the model itself, the system classifies it as either safe or dangerous. If it is unsure, it redirects the query to a weaker model. According to Anthropic, the government feared that this protection could be bypassed and that the model could be made to reveal information useful for cyberattacks.
But the safeguards of large language models are not bulletproof. Their effectiveness depends entirely on how accurately the model can determine what the user actually wants from it. And there is a large online community dedicated to bypassing these barriers. Anthropic itself admits that “perfect jailbreak resistance is not achievable by any current model provider.” Anthropic also claims that the study the government most likely relied on was written by engineers from Amazon—a company that is both a competitor and a major investor in Anthropic.
And that was not the only breach. Within forty-eight hours of Fable's release, a researcher using the alias “Pliny the Liberator” published the model's entire system prompt on X and GitHub. A system prompt is a hidden set of instructions that helps determine how a model behaves. It is unclear exactly how it could be exploited, but it attracted attention in the AI jailbreak community.
🚨 JAILBREAK ALERT 🚨
— Pliny the Liberator 🐉󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭 (@elder_plinius) June 10, 2026
ANTHROPIC: PWNED 🫡
FABLE-5: LIBERATED 🦋
let's start with the 🐘...
the consensus seems to be that this has been one of the most disappointing model drops of all time, effectively preventing legitimate researchers from contributing their talents to our… pic.twitter.com/Z0vdPIt4vY
The version that makes more sense: RETALIATION
New information that emerged over the weekend casts an even greater shadow over the government's justification. Citing its sources, Axios described a tense weekend between the two sides. According to the outlet, the export directive was not prompted by a technical problem with the product, but by “personality differences” between Anthropic and the Trump administration.
Katie Moussouris, a seasoned cybersecurity expert and founder of Luta Security, wrote on her blog that Anthropic had recently sent her a private copy of the study on the alleged bypassing of Fable's safeguards and asked for her opinion. Moussouris analyzed how the researchers had bypassed the safeguard but added that it “should never have triggered any export directive.”
So what is the problem? The difference allegedly lies mainly between asking the model to “review the code for security vulnerabilities” and asking it to “fix the code.” The result is essentially the same; only the question is phrased slightly differently. “The behavior described in the study cannot be meaningfully fixed, and any attempt would only weaken the model for defensive purposes,” Moussouris wrote. She called the directive hasty, crude, and misguided.
And she was not alone. Together with dozens of other leading security experts, she called on the Trump administration to rescind the order. They said that removing advanced defensive tools from the hands of U.S. network administrators directly threatens the country's defenses. America has experienced something similar before. When the government rewrote export laws in the 2010s to cover cyber tools that could be misused for attacks, the wording was so broad that it nearly outlawed legitimate security research as well.
Why AI is so difficult to police
The deepest problem with the safety of models such as Fable is that we still do not really know how they work. Oxford economist and machine learning expert Maximilian Kasy argues that they work much better than they “should.”
Large language models have billions of internal parameters and are trained on unimaginably vast amounts of data. We would expect such systems to be “overfitted”—excellent at repeating patterns from their training data, but terrible as soon as they encounter something new. Yet Claude and ChatGPT can generalize. Kasy compares the development of today's AI to alchemy: it works through trial and error, not through a well-developed theory. Model behavior is therefore partly opaque even to the people who build them.
And this is exactly what makes governments' work more difficult. They do not have their own access to the data, infrastructure, or experts they would need to properly assess closed, cutting-edge models. A recent presidential executive order on AI safety effectively admits as much. The administration shifted from its original “leave it alone” approach to requiring developers to submit their models for review before release. This is a quiet capitulation. The government itself does not believe that companies can fully assess what their models are capable of and how they might be misused.
A message to all of Silicon Valley
Friday's intervention revealed more than just friction between the government and one company. It showed that the AI industry is not immune to government intervention. With a single swift, unilateral move that apparently did not even require court approval, Washington forced a technology company to withdraw products from service.
Justin Hendrix, editor-in-chief of Tech Policy Press, warns that this move “will likely set off alarm bells in foreign capitals about the reliability of American AI for critical deployments.” U.S. companies may be unable to operate without their own government interfering. This time, Anthropic took the hit. Tomorrow, it could be anyone else.
Sources: techcrunch.com and theconversation.com



