Anthropic–U.S. battle highlights AI power struggle

Anthropic’s decision to take its newest AI models offline worldwide after a U.S. Commerce Department directive has turned a dispute over a suspected cybersecurity jailbreak into a larger fight over who controls frontier AI deployment. The company says it was compelled to disable public-facing Claude Fable 5 and restricted Claude Mythos 5 because the order barred access by foreign nationals, including its own employees, and it could not reliably determine nationality in real time.[1]

The models remain unavailable as of June 21, despite President Donald Trump saying on June 19 that Anthropic was “not now” a national-security threat. The confrontation matters beyond one company: it is an early test of whether export-control powers can regulate cloud access to a deployed AI model, and whether emergency intervention can substitute for a clear framework for assessing AI-enabled cyber risk.[5][6]

Anthropic’s AI-cyber dispute, by the numbers>10,000high- orcritical-severity~50Glasswing partnersreporting those fin~90 mintime Anthropic wasreportedly given to$200Mreported Pentagondefense contract und
Data: Article text; company-reported Glasswing figures

An emergency order with global consequences

Anthropic released Fable 5 and Mythos 5 on June 9. The two models share an underlying system, but their availability and safeguards were sharply different. Fable 5 was the general-use product, with stronger safety filtering and routing of certain high-risk cyber and biology requests to the less capable Claude Opus 4.8. Anthropic said those restrictions were deliberately conservative but activated in fewer than 5% of sessions on average. Fable 5 was priced at $10 per million input tokens and $50 per million output tokens.[2]

Mythos 5, meanwhile, was reserved for vetted cybersecurity and research partners because of its stronger ability to locate and potentially exploit software vulnerabilities. Anthropic had already deployed an earlier Mythos preview through Project Glasswing, a program intended to give defenders controlled access to advanced software-analysis capabilities.[3]

On June 12, Commerce sent Anthropic a directive requiring the company to suspend Fable and Mythos access for all foreign nationals, whether they were inside or outside the United States. Anthropic says it received the order at 5:21 p.m. Eastern time. The directive also applied to foreign-national employees, creating an operational problem that led the company to disable both models globally rather than attempt selective enforcement. Its other models were not affected.[1]

Reporting indicates the government used an “is informed” mechanism under the Export Administration Regulations, backed by authority associated with the 2018 Export Control Reform Act. The order reportedly treated remote model access as an export or transfer requiring a license, with potential civil and criminal penalties for violations. That interpretation is consequential because export rules have historically focused more clearly on hardware, physical technology and model weights than on users remotely querying a cloud-hosted model.[5]

Herbert C. Hoover Building
Photo: Wikimedia Commons, Public domain, via Wikimedia Commons

A disputed jailbreak became a national-security issue

The administration’s move followed concerns raised by Amazon, Anthropic’s major investor and cloud partner. Amazon researchers reportedly identified a possible prompting technique that could bypass Fable’s cyber-safety controls, and CEO Andy Jassy personally raised the matter with officials. The White House and Commerce Department treated the possibility of exposing offensive cyber capabilities as a national-security concern, according to reporting by Axios and The Washington Post.[5][6]

Anthropic disputes the characterization of the finding. It says the demonstrated bypass was narrow: a user asked Fable to examine a particular codebase and identify software vulnerabilities. The company says the resulting findings were minor and already known, and argues that other public models, including OpenAI’s GPT-5.5, could produce comparable results without a jailbreak. It says no tester found a universal method for broadly unlocking Fable’s cyber capabilities.[1]

The disagreement is not merely semantic. A universal jailbreak would suggest systemic failure of a model’s safeguards. A narrow result on a particular codebase could still be important, but it calls for technical evaluation of reproducibility, severity, scalability and whether the model materially changes an attacker’s capabilities. Anthropic says it had conducted thousands of hours of red-team testing with the U.S. government, the U.K. AI Security Institute and private organizations before launch. Officials and people briefed on the dispute have offered a conflicting account, saying the company was dismissive of Amazon’s warning or did not adequately address it.[1][5]

People familiar with the discussions told The Washington Post that Anthropic was given roughly 90 minutes to take Fable offline. Anthropic has said it did not receive a detailed written explanation of the underlying national-security concern before the action. That compressed process is central to criticism of the order: the government demonstrated it could halt a commercial frontier model rapidly, while providing little public visibility into the technical evidence or legal standards used.[5][6]

data center server racks
Photo: Joël van der Loo, CC BY-SA 4.0, via Wikimedia Commons

The defensive value—and dual-use risk—of AI cyber tools

Project Glasswing illustrates why the policy question is difficult. Mythos is a general-purpose model with unusually strong agentic coding, reasoning and software-analysis abilities, not a tool trained solely for cybersecurity. Anthropic says it can identify and potentially help exploit vulnerabilities at a scale that can aid defenders but could also lower the cost of offensive cyber activity if misused.[3]

Through Glasswing, Anthropic gave selected infrastructure, cloud, software and security organizations access for defensive work. Partners included AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks. By May 22, Anthropic said roughly 50 partners had identified more than 10,000 high- or critical-severity vulnerabilities. Those are company-reported figures, and many findings were not public because vendors were still developing patches.[3][4]

Anthropic’s argument is that capable models are becoming necessary defensive infrastructure. If attackers can use comparable AI systems to find flaws, withholding tools from defenders may widen rather than close the security gap. The company has said competitors could reach Mythos-class capability within six to 12 months, potentially without the same deployment controls.[4]

Its safeguards follow a defense-in-depth model: refusals at the model layer, monitoring, restricted access for its more capable system, data retention to study jailbreaks and controlled testing with partners. Anthropic acknowledges that no provider can guarantee protection against every narrow bypass. The government’s apparent position is that a potential failure in those protections can justify intervention before broader misuse occurs.[1]

The conflict follows a Pentagon showdown

The Commerce dispute came only months after Anthropic’s clash with the Pentagon over military use of Claude. During negotiations over a reported $200 million defense contract, Anthropic refused to remove restrictions against mass domestic surveillance of Americans and fully autonomous weapons systems that can select and attack targets without meaningful human control. CEO Dario Amodei argued that current frontier models are not reliable enough for autonomous lethal decisions.[8]

Defense Secretary Pete Hegseth said those limits were unacceptable because the government, rather than a contractor, should decide lawful military use. On February 27, he directed the Pentagon to designate Anthropic a supply-chain risk, potentially cutting it off from Defense Department systems and from defense contractors.[8]

Anthropic sued, and U.S. District Judge Rita Lin issued a preliminary injunction on March 26 blocking the designation and a broader federal order to stop using the company’s technology. The General Services Administration subsequently restored Anthropic products to its schedules and government services.[8] Civil-liberties organizations argued the earlier Pentagon action could amount to retaliation against Anthropic for its public safety positions, raising First Amendment and due-process questions.[8]

That history gives the current standoff an added dimension. The companies and government agencies are not debating only technical safeguards. They are also contesting whether a model developer can set binding terms on how a government customer uses its technology, and how far the government can go in response when it considers those terms unacceptable.

A de facto licensing system without settled rules

More than 80 cybersecurity executives and experts, and more than 100 under a broader accounting reported by the Associated Press, urged Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross to lift the restrictions. Their concern was that cutting off access to advanced defensive systems could weaken U.S. security teams while malicious actors continue to use other available models. The group called for an open, scientific and transparent process to evaluate AI cyber risk.[7]

Critics across the AI-policy spectrum agree that the present arrangement is inadequate, even where they disagree about who should lead oversight. FAR.AI chief executive Adam Gleave described the environment as ad hoc. ControlAI’s Connor Leahy argued that government, not industry, should provide oversight, but that regulators need much stronger technical capacity. Georgetown’s Helen Toner and Databricks co-founder Patrick Wendell have also argued for capable, structured regulatory evaluation rather than either corporate self-policing or opaque intervention.[6]

The immediate question is whether Anthropic and the administration can reach a technical and legal resolution that restores Fable and Mythos access. Trump’s June 19 remarks suggested a less confrontational posture, though he also did not rule out use of the Defense Production Act if needed.[6] As of June 21, no permanent settlement or generally applicable regulatory regime has been announced.

The longer-term question is more fundamental. Frontier AI models are distributed through APIs and cloud services, can change through software updates, and may serve both defensive and offensive cyber functions. Applying export-control authority to that environment may be possible, but the Anthropic episode shows how much remains unsettled: what capability threshold triggers intervention, what evidence must be disclosed, how cloud access should be classified, and what review is available to a company ordered offline. Until those questions have clear answers, deployment decisions for the most capable AI systems will remain a contested exercise of corporate judgment and government power.

Editor’s Take

I think the most important practical issue is not whether one prompt bypass was alarming, but whether regulators can convert a disputed test result into an instant global shutdown of a cloud model without publishing a usable technical and legal standard. That uncertainty is a deployment tax: companies will spend more on access controls, identity verification, audit trails and legal review, yet still be unable to predict what conduct triggers intervention.

The next thing to watch is whether Commerce defines remote inference as an export in a durable, reviewable way. A narrow, evidence-led process could push providers toward better cyber evaluations while preserving defensive access. A vague nationality-based rule, however, is hard to operate in global engineering organizations and may deprive defenders of precisely the software-analysis capacity they need. The hype is in treating either safety filters or a single jailbreak as conclusive proof; the real question is measurable uplift in offensive capability, reproducibility, scale and the effectiveness of monitored, restricted deployment.

References

  1. Anthropic – https://www.anthropic.com/news/fable-mythos-access
  2. Anthropic – https://www.anthropic.com/news/claude-fable-5-mythos-5
  3. Anthropic – https://www.anthropic.com/project/glasswing
  4. Anthropic – https://www.anthropic.com/research/glasswing-initial-update
  5. The Washington Post – https://www.washingtonpost.com/technology/2026/06/15/how-90-minute-white-house-deadline-sparked-silicon-valleys-biggest-ai-fight/
  6. Axios – https://www.axios.com/2026/06/17/anthropic-fable-mythos-ai-model-government-oversight
  7. Investing.com – https://www.investing.com/news/stock-market-news/anthropic-and-us-officials-meeting-monday-to-resolve-dispute-over-export-curbs–administration-official-says-4742693
  8. Cato Institute – https://www.cato.org/legal-briefs/anthropic-v-department-war

Leave a Reply

Your email address will not be published. Required fields are marked *