On Friday evening, Dario Amodei received a letter that brought down his company’s two most powerful models within hours. Commerce Secretary Howard Lutnick wrote to the head of Anthropic that the Mythos 5 and Fable 5 models were subject to export controls for anyone outside the United States as well as every foreign national within the country. Anthropic had no way to distinguish foreign nationals from American users in real time. So it shut down both models entirely for everyone. Only three days passed between the models’ launch and their shutdown.
The most advanced models yet
On June 9, the company unveiled two models. Fable 5 was the public version, which anyone with a paid plan could enable. Mythos 5 was the same model, but without performance and safety restrictions, and was made available only to a handful of vetted security partners and selected biologists through Project Glasswing.
The difference between them was not intelligence, but safeguards. Fable routed sensitive queries in cybersecurity, biology, and chemistry to the weaker Opus 4.8 model, and users pointed this out. Anthropic was concerned that Mythos’s ability to find flaws in code was simply too good. The company itself stated that the model had found thousands of previously unknown vulnerabilities in all major operating systems and browsers. Some of them had survived decades of human review. It was precisely this effectiveness that came back to haunt the company.
The trigger came from outside. According to media reports, the Department of Commerce sprang into action after another company claimed it had cracked Mythos. This is known as a jailbreak—a way to bypass built-in safeguards and get answers from a model that it would otherwise refuse to provide. Officials were alarmed enough to take action. The administration reportedly first tried to persuade Anthropic to delay the models’ launch. The company refused, and the letter followed.
Anthropic responded quickly and forcefully. It claims that the government provided only “verbal evidence of a possible breach of the model’s defenses.” The company examined the technique and said it revealed only a few long-known and relatively minor vulnerabilities. It says the same flaws can also be found by other publicly available models without bypassing any safeguards. Anthropic explicitly named OpenAI’s GPT-5.5 as a comparable example.
“We disagree that the discovery of a narrow potential jailbreak should be grounds for withdrawing a commercial model deployed to hundreds of millions of people,” the company wrote. It also issued a warning. According to Anthropic, if this standard were applied across the industry, it would effectively halt the release of virtually all new models.
Accounts of the events differ depending on whom you listen to. David Sacks, a former White House AI adviser, portrayed it differently. He claimed that the government had received a warning that Fable 5 could be breached, and that when Amodei was notified, the company did nothing about it.
Export controls imposed on a model itself for the first time
This brings us to the heart of why this event is so exceptional. The United States has previously blocked exports of chips and supercomputers—the hardware that powers artificial intelligence. Both the Trump and Biden administrations did so with semiconductors. But the software itself, the model itself, had never been targeted before.
The Department of Commerce letter introduced a licensing regime. A permit is now required to export, re-export, or even transfer these models domestically. And because the restrictions also apply to foreign nationals living in the United States, they affected Anthropic’s own employees who are not U.S. citizens. The company had no choice. To comply with the regulations, it had to shut down the models for absolutely everyone. Access to Anthropic’s other models remained unchanged.
There is something almost absurd about this situation. Anthropic has long positioned itself as a company sounding the alarm about the risks of artificial intelligence. And now that very caution has turned against it.
Consider the contradiction. The Pentagon previously designated Anthropic a “supply-chain risk” and cut ties with the company because it refused to give the government access to its models for mass domestic surveillance and autonomous weapons. So Anthropic is considered too dangerous for the military’s own purposes. And now the Department of Commerce considers it too dangerous for foreign nationals as well.
Meanwhile, other parts of the government are practically fighting over Mythos. The NSA sent roughly half a dozen engineers to Anthropic to help the agency deploy the model for cyber operations. The Treasury Department sought access. Federal IT chiefs complained that the White House was leaving them in the lurch and failing to provide clear instructions on how to use Mythos to scan government networks.
A dispute over who decides
Anthropic complied with the ban, but it certainly has not accepted it. “We believe this is a misunderstanding, and we are working to restore access as soon as possible,” the company stated, apologizing to its customers.
An administration official revealed that the model is to remain locked down until the government’s security apparatus has been strengthened. This could reportedly take a few weeks.
The question arises of who actually decides who gets access to the most powerful AI. The European Commission had already been told that it must apply to the U.S. administration for access to Mythos. The only non-American entity with access to the model was the United Kingdom’s AI Security Institute. Washington thus retains the keys to the door behind which lie capabilities that public models do not yet offer.
And Anthropic? It has found itself in a position where it built something so powerful that it no longer gets to decide who may use it.
Sources: reuters.com, theguardian.com and cnn.com



