Commerce Takes Anthropic's Fable 5 Offline After a Narrow Jailbreak
Commerce ordered Anthropic on June 12 to bar foreign nationals from Fable 5 and Mythos 5, and Anthropic shut both off for everyone; Peter Girnus says Anthropic wrote the predicate itself, and governance moves down 0.8.
By Ryan Elliott Dennis · 5 sources · 8 min read
The US Commerce Department handed Anthropic an export control directive at 5:21 pm Eastern on Friday, June 12 2. By the time Anthropic published its statement that evening, Fable 5 and Mythos 5 were dark for every customer it has. That order, issued under national security authorities, told Anthropic to suspend all access to the two models by any foreign national, inside or outside the United States, including the company's own employees on visas 1. Anthropic said it had received only verbal evidence of the problem and called the finding a narrow jailbreak 1. It turned both models off for everyone, since an API key identifies an account and an account carries a billing address at most. Claude Opus 4.8 and the older models stayed up 2. Commerce's directive is the first government order to withdraw a frontier model from the market. The ledger's governance component moves down on it.
Commerce's order pulls the governance reading down 0.8 points
The moveThe data5 rows · sources
| Measure | Value |
|---|---|
| Reading before this day | 1.6 |
| This piece's move | −0.8 (Governance, confirmed) |
| Band for confirmed evidence | 0.8 to 1.5 |
| Reading after the day | 0.8 |
| Distance to 100 | 99.2 |
What the directive said, and what Anthropic did
Anthropic's statement describes the government's evidence in one sentence. The government believes it has found a method of bypassing Fable 5, and the company writes that "the government has only given us verbal evidence of a potential narrow, non-universal jailbreak" 1. Cybersecurity Dive reported the technique came from Amazon researchers, who prompted the model to read a codebase and fix its software flaws 3. The vulnerabilities it surfaced "appear relatively simple" in Anthropic's account 3. Fable 5's safeguards, in Anthropic's telling, sit between the public and Mythos 5's cyber capabilities. The technique got around them for that one task 2.
Read the company's own description of the wider problem. "We suspect that perfect jailbreak resistance is not currently possible for any model provider," Anthropic wrote 1. It went further in the next line: "Every safeguard used in the industry is vulnerable to non-universal jailbreaks" 1. Those two sentences carry the whole dispute. Anthropic is saying the flaw the government found is a property of the entire industry. The government is saying that property, on this model, is a national security matter.
Why turn the model off for Americans when the order named foreign nationals? Because an API screens accounts, and a passport is a different document. Joseph Hoefer, a government relations strategist writing in TechPolicy.Press, put the mechanical problem plainly: "When the controlled thing is a service that anyone can call from anywhere at any time, the familiar questions get harder" 5. Export control rules date from an era of crates and code on disks. A directive aimed at a service becomes a directive aimed at the service's existence. That is what happened on June 12.
Commerce's 5:21 pm directive took both models offline worldwide that evening
TimelineThe data7 rows · sources
| Date | Event | Source |
|---|---|---|
| Commerce delivers the export control directive at 5:21 pm Eastern | [2] | |
| Anthropic switches off Fable 5 and Mythos 5 for every customer | [1] | |
| Claude Opus 4.8 and the older models stay online | [2] | |
| Fortune carries Girnus, Ball and Marcus on the order | [2] | |
| Open letter to Lutnick and Cairncross reaches 76 signatures | [3] | |
| Carchidi calls the directive ad hoc, ahead of any agreed threshold | [4] | |
| Hoefer sets out two rival theories of model export control | [5] |
The case for the directive
Peter Girnus, a cybersecurity researcher, made the sharpest argument that Anthropic earned the order. "If you describe your product as a munition in every press release, eventually a government takes you at your word," Girnus said 2. He added a second line: "They wrote the legal predicate themselves and called it a brand" 2. His point rests on the record. Anthropic has marketed Mythos 5 as a system that finds and exploits software flaws well enough to be held back for defenders. Commerce, reading those releases, has a capability description in Anthropic's own words. It also has a report that the safeguard around it gave way.
Vincent Carchidi, a defense industry analyst at Forecast International, traced the same argument through export control history. He reached a measured version of it. "If the U.S. government's reason for action is indeed cybersecurity, however, then there is cause for adjusting one's sensitivities to this domain, where LLMs are proving more impactful than many others," Carchidi wrote 4. He also noted the directive arrived on an ad hoc basis, ahead of any formal testing process or agreed threshold for what makes a model too dangerous 4.
Dario Amodei's own policy writing supplies the third voice for the order. Carchidi quotes the Anthropic chief executive's June blog post: "The government should have the power to block or deter deployment of the model if it is determined, in light of third-party assessment, to present unacceptable risks" 4. The sentence asks for exactly the power the Commerce Department used. Its hedge sits in the middle clause, on third-party assessment, and that is where Anthropic's objection lives.
Amazon found the bypass, Commerce issued the order, Anthropic shut the models
Who connectsThe data10 rows · sources
| From | Link | To | Source |
|---|---|---|---|
| Amazon researchers | prompted it to fix a codebase's flaws | Claude Fable 5 | [3] |
| Commerce Department | directive at 5:21 pm Eastern, June 12 | Anthropic | [2] |
| Anthropic | switched off for every customer | Claude Fable 5 | [1] |
| Anthropic | dark worldwide by that evening | Claude Mythos 5 | [1] |
| Anthropic | kept online | Claude Opus 4.8 | [2] |
| Dario Amodei | asked that government hold power to block deployment | Commerce Department | [4] |
| Peter Girnus | wrote the legal predicate itself | Anthropic | [2] |
| Howard Lutnick | serves as Commerce Secretary | Commerce Department | [3] |
| Open letter, 76 signatures | the order took the best models from defenders | Howard Lutnick | [3] |
| Open letter, 76 signatures | addressed to the National Cyber Director | Sean Cairncross | [3] |
The case against it
Anthropic's statement makes the case against the recall in its own words. "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people," the company wrote 1. It then stated the consequence for every frontier lab: "If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers" 1. The company apologized to customers, called the order a misunderstanding, and said it was working to restore access 2.
Dean Ball, an AI policy analyst who served briefly in the Trump administration, said the same thing with less patience. "I can't tell if this is lawfare against Anthropic in particular or extreme national-security hawkery. Regardless, it is simply cartoonish," Ball said 2. Gary Marcus, a longtime critic of the AI labs, argued in a social media post that the order ran against the government's stated aim of staying ahead of China, and that it would push Chinese-born researchers at American labs to go home 2.
Seventy-six signatures had gathered on an open letter to Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross by Monday morning 3. Chief executives, security chiefs, venture investors and researchers signed it 3. The letter's argument is availability. Its signatories wrote that the directive "has taken the best models away from defenders, created market uncertainty, and risked America's AI leadership without any real risk to justify it" 3. They also conceded the capability: "Anthropic's Mythos-class models are quite good at finding flaws and weaponizing exploits. However, they are not uniquely good at these tasks, and many of the undersigned individuals regularly use other foundation and open-source models for security audits and red-teaming every day" 3.
Set the two sides beside each other and the disagreement narrows to one question. Does a capability that other public models already hold become a national security matter when it appears on the strongest model? The letter says availability decides it, so the order denies defenders and leaves attackers untouched. Girnus says the label Anthropic chose decides it, so the order took the company at its word. Both readings agree on the facts of the jailbreak.
Girnus says Anthropic invited the order; Anthropic disputes the recall
Both sidesThe data2 rows · sources
| Side | Who | Claim | Source |
|---|---|---|---|
| For | Peter Girnus | Anthropic called its product a munition in every press release, so Commerce took Anthropic at its word; Anthropic wrote the legal predicate and called it a brand. | [2] |
| Against | Anthropic | A narrow potential jailbreak is poor cause to recall a model serving hundreds of millions; applied industry-wide, the standard would halt every new frontier deployment. | [1] |
Why the step is smaller than it looks
The ledger's governance component asks one question: do the rules allow deployment at the definition's scale? On June 12 the Commerce Department answered that question in the negative for Anthropic, the company closest to the scale. It acted on evidence delivered verbally. That earns a confirmed move down. A regulator's order is the top tier of evidence in the method, and the model is off.
Three things hold the step at the bottom of the confirmed band. A suspension is reversible. Anthropic said it was working to restore access, the Trump administration has a stated interest in American AI leadership, and the letter campaign was already running at 76 names by June 15 3. A revoked order would restore the June 11 reading. Some later piece would carry that move on the day it happens.
Second, the capability at issue is ordinary. Anthropic argued that the flaws the technique surfaced were minor, previously known, and findable by other public models 3. The letter's signatories said they use other models for the same work every day 3. A directive that turns off one model while equivalent tools stay online changes who has the best tool for three weeks. It changes little about what the substrate can do.
Third, this is the governance component at a weight of 0.05, the lightest on the ledger with capital. The order says something real about the rules, and the rules are one of eight things the reading tracks. Compute kept building through the weekend. Interconnect queues moved. The 421 megawatts at Abilene stayed energized. A single order on one model is a fact about deployment permission, and the reading treats it as one bounded step.
What pushed governance down, and what holds the step at 0.8
The recordThe data10 rows · sources
| Column | Item | Source |
|---|---|---|
| The order, on the record | Directive received at 5:21 pm Eastern on Friday, June 12 | [2] |
| The order, on the record | Fable 5 and Mythos 5 dark for every customer worldwide | [1] |
| The order, on the record | Scope covers every foreign national, Anthropic's own visa-holding staff included | [1] |
| The order, on the record | Government evidence reached Anthropic in verbal form only | [1] |
| The order, on the record | Claude Opus 4.8 and the older models stayed online | [2] |
| Holding the step at the floor | Anthropic says it is working to restore access | [2] |
| Holding the step at the floor | Surfaced flaws appear relatively simple and previously known, per Anthropic | [3] |
| Holding the step at the floor | Letter signatories run other models for security audits every day | [3] |
| Holding the step at the floor | Executive order gives officials 60 days to build benchmarks | [4] |
| Holding the step at the floor | Directive arrived ad hoc, ahead of any testing threshold | [4] |
Where this sits on the ledger
Hoefer's essay names the larger stake. Commerce is writing export policy for models by enforcement, one directive at a time. He argues that "each enforcement decision becomes precedent, the accumulated precedents begin to function like a rule" 5. Two theories are in contention, in his account. An incremental-risk approach controls only capabilities unavailable elsewhere; a capability-based approach restricts any model with a sensitive ability, whatever the competition offers 5. The June 12 order is a data point for the second theory. Anthropic's defense is an argument for the first.
Carchidi reads the tension against the administration's own executive order, which instructed officials to develop benchmarking processes within 60 days 4. The directive arrived before those processes existed. So the government now has a live precedent and a pending standard, in that order, which is the ad hoc basis he described.
For the ledger, the record on June 12 reads this way. The rules did allow a frontier model to deploy to hundreds of millions of people, for a short time. Then the Commerce Department withdrew that permission on a verbal report. Governance moves 0.8 points down at confirmed confidence. It moves back on the day a filing, a restored model, or a published standard says the permission is stable.
By the numbers
- 5:21 pm Eastern on Friday, June 12: the time Anthropic received the directive 2
- Two models suspended, Fable 5 and Mythos 5, for every customer worldwide 1
- Hundreds of millions of people: Anthropic's count of users on the recalled model 1
- 76 signatures on the open letter to Lutnick and Cairncross by Monday morning, June 15 3
- One task in the reported jailbreak: reading a codebase and fixing its software flaws 3
- 60 days: the window the concurrent executive order gave officials to develop benchmarking processes 4
- Zero foreign nationals, including Anthropic's own employees on visas, permitted access under the order 1
What to watch
A written finding from Commerce or a national security agency that states what the jailbreak reached would confirm the move. Any formal threshold for withdrawing a model would make it durable. Restored access, with a classifier the government has tested, would reverse most of the step on the day it happens. One more directive against another provider's model would settle whether Hoefer's capability-based theory is the rule, and a standard published inside the executive order's 60-day window would show the government choosing deliberation over precedent.
Sources
- 1Statement on the directive to suspend Fable 5 access, Anthropic, June 12, 2026
- 2Anthropic disables Fable and Mythos AI models after U.S. government bars it from giving foreigners access, Fortune, Jeremy Kahn, June 13, 2026
- 3Cybersecurity experts blast US government for restricting Anthropic's AI models, Cybersecurity Dive, Eric Geller, June 15, 2026
- 4Echoes of Export Control Past: Assessing the Anthropic "Fable" Suspension, Forecast International, Vincent Carchidi, June 15, 2026
- 5Did the US Government Just Set An AI Export Precedent by Blocking Mythos?, TechPolicy.Press, Joseph Hoefer, June 15, 2026