T1#regulation#security#market#military
Commerce Puts Two Anthropic Models Under Export Control — Nineteen Days Dark

Metadata
- Date
- Decade
- 2020s
- Tier
- T1
- Timelines
- A General History of Information Technology · A History of Artificial Intelligence · A History of Cybersecurity
- Sources
- 12
- Connections
- 02
- Tags
- #regulation#security#market#military
On 9 June 2026 Anthropic released Claude Fable 5 and Claude Mythos 5. Fable 5 went to enterprise customers and paid subscribers; Mythos 5 went only to vetted partners through Project Glasswing, a cybersecurity consortium.
Three days later, on Friday 12 June, the Bureau of Industry and Security sent Anthropic a letter over Commerce Secretary Howard Lutnick's signature directing the company to suspend all access to both models by any foreign national — not merely foreign nationals abroad, but the company's own foreign-national employees working inside the United States. Anthropic's statement the same day said the net effect was that it had to disable Fable 5 and Mythos 5 for all its customers to comply, and that access to its other models was unaffected.
The letter has never been published. No Federal Register notice accompanied it. Writing in Tech Policy Press on 15 June, Joseph Hoefer noted that because the directive arrived by letter and was not made public, its precise scope and rationale were known mostly secondhand.
The Trigger, and the Dispute About It
The precipitating event was a report by Amazon researchers describing a way past Fable 5's safeguards — by Anthropic's own account, prompting the model to read a specific codebase and fix any software flaws. Those safeguards exist to prevent users reaching the cybersecurity capabilities that Mythos 5 carries.
Anthropic disputed the severity, not the finding. It called the bypass narrow, said the level of capability displayed was widely available from other models including OpenAI's GPT-5.5, and argued that recalling a commercial model over a narrow jailbreak would set a standard that halts essentially all new model deployment. The administration's account came the next day from White House AI adviser David Sacks, who wrote on X that a trusted partner testing Fable had come forward with the jailbreak, that the administration had first asked Anthropic to fix it or de-deploy the model, and that Dario Amodei declined. The two accounts do not reconcile, and with the underlying letter unpublished there is no way to adjudicate between them from outside.
There is a tangle of interest here worth stating plainly. Forbes reports that Amazon "is one of Anthropic's largest investors and provides much of its cloud infrastructure." It was Amazon's researchers who found the flaw. According to the Wall Street Journal, followed by TechCrunch and others, Amazon CEO Andy Jassy raised the finding with Treasury Secretary Scott Bessent and other officials, and that is what set the export action in motion. Every outlet hedges this with reportedly. An Amazon spokesperson was quoted saying it is not uncommon for governments to seek the company's counsel on potential security risks. The commercial timing was awkward in a further respect: Forbes notes that Anthropic had filed a confidential IPO prospectus with the SEC earlier the same month, disclosing a US$47 billion revenue run rate and a US$965 billion valuation.
This Was Not the First Export Control on Model Weights
The episode is usually narrated as the moment export controls jumped from chips to model weights. That framing fails twice over, and it is worth being precise about why.
First, controls on model weights already existed. The Biden administration's interim final rule Framework for Artificial Intelligence Diffusion, published 15 January 2025, created a new ECCN 4E091 covering the model weights of any closed-weight model trained on more than 10²⁶ computational operations. Model weights were, on paper, already a controlled item. But the rule set its compliance date at 15 May 2025, and BIS announced its rescission on 13 May — two days short. It expired before it ever bit. The CSIS analysis of the Anthropic action (Kate Koren, Kevin Kurland and Aalok Mehta, 16 June 2026) puts it exactly: the diffusion rule controls AI model weights but "is not currently being enforced pursuant to a May 2025 announcement by BIS, and therefore license requirements on AI model weights are not in effect."
Second, the June 2026 action was not about weights at all. The same CSIS piece is blunt: "The models or model weights are not being exported. Foreign nationals are instead accessing those models on servers operated by Anthropic." Nothing was transferred. That is precisely why the legal construction was contested. The authorities reportedly cited in the letter were ECRA's "is informed" mechanism for emerging and foundational technologies, EAR §744.22 on military-intelligence end uses, and EAR §734.13, which defines when remote access counts as an export at all.
So what was new? Hoefer identifies it correctly. That software, source code, and electronic transmission of non-public technical data can be export-controlled is old law, settled in the encryption export litigation of the 1990s. The novelty is applying that authority to a continuously available frontier model reached by API — and doing it not through a rule of general application but through a letter naming one company and two of its products. The accurate claim is not the first export controls on model weights. It is the first time export-control authority was aimed at a live commercial AI service, company and model by name.
The Withdrawal, and What It Cost
On 26 June, with government approval, Mythos 5 access was restored to a set of US organisations. On Tuesday 30 June Lutnick wrote again, notifying Anthropic that BIS had evaluated the diversion risks the two models now presented and was withdrawing the controls imposed in his 12 June letter. The Record reports that this second letter was addressed to co-founder Tom Brown rather than to chief executive Dario Amodei.
What Anthropic gave in exchange, per its own 30 June post:
- For models that materially advance the capability frontier in areas relevant to national security, expanded early access for designated government partners
- Rapid investigation, triage, and notification to government counterparts when significant jailbreaks or misuse patterns are identified
- Dedicated internal teams working on shared government priorities
- Work with government and industry peers toward a shared, voluntary security and evaluation standard
Technically, the company said it had trained a new classifier such that "the specific technique described in the Amazon report is blocked in over 99% of cases." It also proposed a consensus framework — with Amazon, Microsoft, Google and others — for grading jailbreak severity along four axes: capability gain, breadth, ease of weaponisation, and discoverability.
Fable 5 came back on Wednesday 1 July, to users globally on the Claude Platform, Claude.ai, Claude Code and Claude Cowork. Nineteen days from the 12 June letter. Mythos 5 was free of export controls but remained limited to vetted US organisations under Project Glasswing — a distribution choice of Anthropic's, not a regulatory constraint.
Two Instruments, Ten Days Apart
All of this happened ten days after the signing of Executive Order 14409, which directed agencies to design a voluntary framework for pre-release government access to covered frontier models and stated that nothing in that section authorises the creation of mandatory licensing, preclearance, or permitting. The instrument used on 12 June was not that framework. It was the Export Administration Regulations — a parallel authority that requires neither negotiation nor consent.
The Congressional Research Service set the two beside each other in its 9 July In Focus, suggesting Congress might weigh the order's assessment machinery against "the Administration's other approaches, such as requiring Anthropic to suspend access to a frontier AI model showing advanced cyber capabilities, in the context of the E.O.'s broader policy and its effects on industry compliance and future policymaking."
The precedent left behind is uncomfortable in both directions. The government demonstrated that a single unpublished letter, carrying no stated reason beyond national security, can remove a commercial product from every customer on earth for nineteen days. The company shipped a model whose safeguards were defeated within three days, argued publicly with the government about how much that mattered, and eighteen days later accepted a package of commitments including expanded pre-release government access. Anyone trying to judge how voluntary a voluntary framework really is will be looking at these nineteen days for some time.
Sources
Last updated: