Anthropic has disabled Claude Fable 5 and Claude Mythos 5 for every customer worldwide after the U.S. Commerce Department ordered the company to prevent access by foreign nationals without an export license. The directive, received June 12, applies to foreign persons inside and outside the United States, including Anthropic employees who are foreign nationals. [1]
The immediate effect is the removal of Anthropic’s newest and most capable broadly available model from APIs and major cloud platforms. The larger consequence may be a new and uncertain precedent: U.S. export-control authorities are being applied not to chips, model weights or source code, but to access to a cloud-hosted AI model’s outputs. As of June 20, the administration has not publicly provided a detailed technical account of the national-security risk it believes the models present. [1][7]
A nationality-based order produced a global shutdown
Commerce Secretary Howard Lutnick’s letter to Anthropic CEO Dario Amodei reportedly required a Bureau of Industry and Security license before Fable 5 or Mythos 5 could be made available to a foreign person. The requirement covered exports, reexports, in-country transfers and deemed exports, the legal concept under which releasing controlled technology to a foreign national in the United States can be treated as an export to that person’s home country. [7]
Anthropic said it could not reliably apply that restriction in real time across shared consumer, API and cloud infrastructure. Rather than risk violations that could carry civil or criminal penalties, it withdrew both models from all users, regardless of nationality or location. Other Anthropic models remain available. [1]
The order is operationally significant because cloud services usually identify account holders, organizations and payment relationships, not necessarily a user’s nationality for each inference request. A company serving global enterprise teams would also need to account for employees, contractors, API users and downstream applications. University of Minnesota AI-law scholar Alan Rozenshtein characterized the nationality-based restriction as so difficult to implement that it effectively forced the worldwide shutdown. [7]

What Fable 5 and Mythos 5 offered
Anthropic launched Fable 5 and Mythos 5 on June 9. They share the same underlying model, but differ in access rules and safety controls. Fable 5 was the general-availability version, with classifiers intended to block or limit high-risk cybersecurity requests such as vulnerability discovery and exploit development. Mythos 5 was a less restricted version made available only to approved defensive-security partners through Anthropic’s Project Glasswing program. [2][3]
The company positioned the systems as frontier models for long-horizon software engineering, autonomous tool use, research, vision tasks and complex knowledge work. Launch documentation listed a one-million-token context window and outputs of up to 128,000 tokens per request. They supported code execution, memory, programmatic tool calling and vision, while using 30-day data retention for safety monitoring and jailbreak investigation. [2][3]
Fable 5 had been offered through Anthropic’s API as well as Amazon Bedrock, Google Cloud and Microsoft Foundry. Its removal therefore affects not only direct Claude users, but developers and businesses that had begun testing it in production workflows. Anthropic’s claimed performance results, including a Stripe code-migration test, were company-reported rather than independently audited. [2][3]
Mythos 5’s disruption is particularly consequential for cyber-defense groups. Anthropic had expanded Project Glasswing to more than 150 infrastructure and cybersecurity organizations shortly before the shutdown. Those users were expected to employ the model for activities including finding and remediating vulnerabilities before they could be exploited by attackers. [6]

The disputed jailbreak and the government’s rationale
Anthropic said the directive appeared to follow a demonstration in which Fable was prompted to examine a specific codebase for vulnerabilities and, in one reported instance, generated code that showed how a flaw could be exploited. The company described this as a narrow, non-universal jailbreak involving a small number of previously known and relatively minor vulnerabilities, rather than evidence that Fable’s cybersecurity restrictions could be broadly defeated. [1]
The company also said its testing found that publicly available models including Claude Opus 4.8, OpenAI GPT-5.5 and Kimi K2.7 could identify the same vulnerabilities, sometimes without bypassing their own safeguards. That is Anthropic’s assessment, not an independent comparison, but it goes to the central dispute: whether Fable and Mythos pose a distinct enough risk to justify a model-specific export action. [1]
The Commerce letter reportedly invoked military-intelligence and national-security authorities, but public reporting has not identified a particular adversary operation, harmful deployment or detailed technical evidence behind the action. White House officials had sought outside feedback on Fable 5’s safety before the order, according to reporting, yet the administration has not released a public technical explanation. [4][8]
The distinction matters because vulnerability identification is not the same as reliable weaponization or a successful intrusion. Josh Kamdjou, CEO of Sublime Security, said the gap between finding a weakness and carrying out an operation remains substantial. At the same time, Anthropic itself had treated Mythos’s cyber capabilities as sufficiently powerful to warrant controlled access, which underscores the genuine policy challenge around systems that can help defenders and attackers alike. [6]
A novel test of export controls for hosted AI
Export controls have traditionally focused on tangible goods and transferable technical assets, including advanced chips, manufacturing equipment, source code and model weights. In this case, customers were not downloading Fable 5 or Mythos 5. They were submitting prompts to a service and receiving outputs through a web interface or API. Legal analysts have questioned whether that ordinary inference access is a controlled release of technology under existing export-control rules. [7][8]
The action nevertheless demonstrates that Commerce can use company-specific authority to limit access to a commercial hosted model, at least while the underlying directive remains in force. CSIS analysts warned that the lack of a generally applicable rule or transparent public process creates uncertainty for U.S. AI companies developing and deploying frontier systems. [7]
Anthropic has said it supports government intervention where there is evidence of genuinely unsafe deployment, but argues that this order is disproportionate and insufficiently explained. Its broader argument is that every current frontier model can be jailbroken in some circumstances; treating a limited jailbreak as grounds for an export restriction could make the deployment of new models untenable. [1]
More than 100 technology and cybersecurity executives, including representatives associated with Adobe, Google and Zoom, have urged Lutnick and National Cyber Director Sean Cairncross to lift the restrictions. Their open letter argued that the shutdown deprives defenders of useful tools, adds market uncertainty and risks weakening U.S. AI leadership without showing that these models are uniquely dangerous. [6]
Implications for competition, security and AI sovereignty
The order creates a difficult tradeoff. Restricting access could reduce the chance that foreign malicious actors use a powerful model for cyber operations. But it also limits access for foreign-based and multinational security teams that might use the same capabilities to find and patch flaws. Camille Stewart Gloster, a former deputy national cyber director, said the move narrows the already limited opportunity for defenders to understand frontier-model risks before attackers operationalize comparable capabilities. [6]
There is also a commercial and geopolitical risk. If foreign customers conclude that access to U.S.-hosted models can be withdrawn abruptly through a company-specific government order, they may seek local providers or open-weight systems that are harder for Washington to control. CSIS has argued that such a shift could reduce U.S. commercial influence and create an opening for Chinese AI providers internationally. [7]
For European customers, the episode has intensified concerns about AI sovereignty and dependence on U.S. cloud platforms. The Fable and Mythos shutdown shows that even a service available in Europe can be affected immediately by a unilateral U.S. export-control decision. That may strengthen the case for domestic AI infrastructure and alternatives that can be operated outside U.S. providers’ policy and legal constraints. [7]
As of June 20, Anthropic is complying with the directive while seeking to restore access. The outcome will determine more than the availability of two Claude models. It could establish whether export controls become a recurring mechanism for governing the use of advanced AI services—and whether U.S. companies can offer frontier models globally without facing sudden, model-specific restrictions. [1][7]
Editor’s Take
If this order is enforced as described, the practical lesson is stark: nationality-based access controls do not map cleanly to global SaaS infrastructure. An API can authenticate an account, but reliably determining every individual user’s nationality across enterprise teams, contractors and downstream applications is a different problem entirely. A global shutdown may be the only defensible operational response when penalties are high and the compliance standard is unclear.
What I would watch next is not just whether these particular models return, but whether Commerce publishes a durable technical and legal test for hosted-model inference. Without one, customers will treat U.S.-hosted frontier AI as a revocable dependency and accelerate multi-model, regional-cloud and open-weight contingency plans. That is commercially rational, but it could also push security-sensitive work toward providers with less visibility and weaker safeguards.
The cyber-risk concern should not be dismissed: better vulnerability research can aid attackers as well as defenders. But a reported narrow jailbreak is not, by itself, evidence that one model is uniquely weaponizable or that a worldwide cutoff improves security. The useful policy standard should distinguish vulnerability discovery from reliable operational exploitation, require evidence proportionate to the restriction, and preserve controlled access for accountable defensive teams.
References
- Anthropic – https://www.anthropic.com/news/fable-mythos-access
- Anthropic – https://www.anthropic.com/news/claude-fable-5-mythos-5
- Anthropic Platform Documentation – https://platform.claude.com/docs/en/about-claude/models/introducing-claude-fable-5-and-claude-mythos-5
- Axios – https://www.axios.com/2026/06/12/anthropic-trump-mythos-fable-national-security
- Bloomberg Law – https://news.bloomberglaw.com/in-house-counsel/anthropics-ai-model-suspension-vexes-its-cyber-tech-customers
- Center for Strategic and International Studies – https://www.csis.org/analysis/department-commerce-restricted-access-anthropics-latest-models-what-comes-next
- Harvard Law Review – https://harvardlawreview.org/blog/2026/06/is-access-to-fable-an-export/
