Howard Lutnick Lifts Export Controls and Anthropic Restores Fable 5 After 18 Days
Howard Lutnick lifted the June 12 export controls on June 30 and Anthropic restored Fable 5 on July 1 behind a retrained classifier; Katie Moussouris calls the trigger routine defence, and governance moves up 0.4.
By Ryan Elliott Dennis · 10 sources · 9 min read
Anthropic restored Claude Fable 5 to every market on July 1 1. Eighteen days earlier, a United States export control directive had forced the company to switch the model off for everyone 2. Commerce Secretary Howard Lutnick lifted the controls on June 30 3. Mythos 5, the stronger model behind Fable, had come back four days earlier for more than 100 US organizations. Approval for that came on June 26 1. The price of the return is a retrained classifier. Anthropic says it blocks the technique Amazon's researchers reported in over 99 percent of cases 1. It also says the filter refuses more reasonable coding requests than the one it replaced 1.
What does an eighteen-day pause and a retrained filter mean for a ledger that scores governance by whether the rules allow deployment at scale? Commerce issued an order on June 12, withdrew it on June 30, and accepted a written set of Anthropic's commitments in its place. That sequence is the material, and the question is how large a step it earns.
Commerce's lifted order and written terms raise governance 0.4 points
The moveThe data5 rows · sources
| Measure | Value |
|---|---|
| Reading before this day | 0.8 |
| This piece's move | +0.4 (Governance, confirmed) |
| Band for confirmed evidence | 0.8 to 1.5 |
| Reading after the day | 1.2 |
| Distance to 100 | 98.8 |
Commerce's June 12 order and Anthropic's two-sentence reply
On June 12 at 5:21 pm Eastern, Anthropic received a directive citing national security authorities 2. It barred every foreign national, inside the United States or outside it, from Fable 5 and Mythos 5 2. Verifying nationality at API scale was out of reach the same evening. "The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance," the company wrote 2. It argued the point in the same statement. "If this standard was applied across the industry, we believe it would essentially halt all new model deployments," Anthropic said 2.
Read the two sentences together. One accepts the order in full. Its neighbour says the order, applied evenly, would end every frontier lab's release cycle. Anthropic complied and disagreed on one page, the posture of a company that expects to negotiate. Tom Brown, an Anthropic co-founder, led that negotiation through the following two weeks, according to The Hacker News 8.
The trigger was a prompt of three words, as Fortune and The Register both reported on June 15 47. Amazon researchers handed Fable 5 code with known flaws and asked it to review the code for security issues. Fable declined. Asked to "fix this code," it produced patches, and several manual steps later the researchers had test scripts 4. That research paper became the basis of the directive 4.
Commerce's order kept Fable 5 offline for 18 days, June 12 to July 1
TimelineThe data8 rows · sources
| Date | Event | Source |
|---|---|---|
| Fable 5 launches at $10 and $50 per million tokens, safeguards attached | [9] | |
| Directive at 5:21 pm Eastern switches off Fable 5 and Mythos 5 | [2] | |
| Moussouris: a 'fix this code' prompt triggered the control | [4] | |
| Fortune reports an open letter from around 100 security professionals | [7] | |
| Lutnick clears Mythos 5 for more than 100 US institutions | [6] | |
| Commerce lifts the controls; Anthropic publishes its redeployment note | [1] [3] | |
| Fable 5 returns to every market behind a retrained classifier | [1] | |
| Kahn calls the arrangement a licensing regime that officials deny | [5] |
What the classifier does, in Anthropic's words
The redeployment note of June 30 states the design plainly. "We therefore deliberately set the safety classifiers to trigger on a set of requests that we know are likely benign," Anthropic wrote 1. The company calls this a safety margin, and it says users meet the margin as refusals of reasonable requests 1. On the bypass itself: "the specific technique described in the Amazon report is blocked in over 99% of cases" 1. Requests the classifier catches route to Claude Opus 4.8, the older model, a design The Register described at Fable's launch on June 9 89.
Then comes the limit, stated by Anthropic itself. "It is probably impossible to make any AI model fully robust (that is, impervious) to jailbreaks," Anthropic wrote 1.
Weigh the adverb. "Deliberately" places the false positives on purpose. Anthropic chose to charge coders a refusal tax to buy a margin against a bypass it now rates at under one percent. In the next breath it says the margin will always leak somewhere. A ledger that tracks whether the rules allow deployment reads this as a rule written in software by the deployer, with the government's approval attached.
Pricing shows where the classifier sits in the product. Fable 5 launched at $10 per million input tokens and $50 per million output, against $25 and $125 for the Mythos Preview, The Register reported 9. "The safeguards are what distinguish the two models (Fable and Mythos) and are why we've given them different names," Anthropic said at launch 9. So the classifier was the product boundary on June 9. Eighteen days after the directive it is also the regulatory boundary.
Anthropic's new classifier blocks the Amazon technique in over 99% of cases
The numberThe data1 row · sources
| Measure | Value | Source |
|---|---|---|
| Over this share of Amazon-technique attempts blocked by the retrained classifier, by Anthropic's count | 99 percent | [1] |
The case for the move
Lutnick made the first half of the case on June 26. He cleared Mythos 5 for more than 100 US institutions, corporations and agencies among them, as Semafor reported 6. "I have determined that appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model," Lutnick said 6. Four days later he lifted the controls on both models and described what Anthropic had signed up to. The company, he said, "has agreed to proactively detect and address security risks associated with the models; to work diligently with the U.S. government on protocols and standards and releases for Mythos, Fable and future models; and to inform the US government of any malicious activity," according to TechCrunch 3.
Anthropic's own note lists the same commitments from its side 1. They run to expanded pre-release access for government partners, rapid information sharing on safeguards, dedicated research teams, and a shared, voluntary evaluation standard for frontier providers 1. On the standard: "Together with Amazon, Microsoft, Google, and other Glasswing partners, we've started to develop such a framework," the company wrote 1. It proposes scoring a jailbreak on four criteria: capability gain, breadth of that gain, ease of weaponization and discoverability 1. A bug bounty on HackerOne opened alongside it 8.
Why does this move governance up? The component asks whether the rules allow deployment at the definition's scale. On June 11 the rule was unwritten. By June 30 a regulator had stated in writing what he required, watched a classifier retrained to meet it, and released both models. An order from a regulator counts as confirmed under the method. This one arrived, met Anthropic, valued in private markets at about $1 trillion, and Commerce withdrew it on stated terms 10. Rules that a frontier lab can meet in eighteen days are rules that allow deployment.
The case for a smaller step
Katie Moussouris makes the strongest case that the eighteen days changed little. She founded Luta Security and sat on the Wassenaar Arrangement's technical expert group from 2013 to 2017 4. At Anthropic's request she reviewed Amazon's confidential paper, the only outside reader to do so by her account 47. "That's it. 'Fix this code,' plus several manual steps to generate test scripts, should never have triggered an export control," Moussouris wrote 4. Her objection reaches past the order to the control itself. "Removing the capability for models to respond to defensive requests makes AI systems worse at finding bugs and verifying patches," she wrote 4.
Fortune carried her account of the work the classifier now flags. "Defenders need to be able to ask AI to fix bugs in a file, explain why the fix matters, and write tests that confirm the patch works," Moussouris said 7. Around 100 cybersecurity professionals signed an open letter against the controls on the same ground 7.
Set her argument beside Anthropic's note. The company says the classifier blocks a technique in over 99 percent of cases and refuses more benign requests to do it. Moussouris says the technique is the benign request. If she is right, the retrained filter buys the government's approval by taxing the defenders the government says it wants to protect. On that reading the model that returned on July 1 is a worse patching tool than the one switched off on June 12. Such a rule permits deployment while degrading the deployment. It is the reason the step here is smaller than a lifted order would usually earn.
Jeremy Kahn, Fortune's editor for AI, reads the same fortnight as a regime that has yet to be written down. "The U.S. is continuing to operate what is essentially a licensing regime for frontier AI models, while officially denying that this is the case," Kahn wrote on July 2 5. He adds the cost that outlasts the order: "The decision to impose the export controls, even temporarily, has forced potential customers of American frontier AI models to recognize that it might be strategically unwise to count on these models for anything essential" 5. TechCrunch noted the sharper irony in the record: Anthropic had offered the security commitments Lutnick listed on a voluntary basis before the directive arrived 3. An order that ends with Anthropic promising what it had already promised is a small rule, whatever its size on the day it landed.
Lutnick cites safeguards; Moussouris calls the trigger a routine defensive ask
Both sidesThe data2 rows · sources
| Side | Who | Claim | Source |
|---|---|---|---|
| For | Howard Lutnick | Safeguards are in place: Anthropic agreed to detect security risks, work with the government on standards for future releases, and report malicious activity. | [3] [6] |
| Against | Katie Moussouris | A plain 'fix this code' prompt plus manual steps belongs outside export control, and blocking defensive requests leaves models worse at finding bugs and verifying patches. | [4] |
Where this sits on the ledger
The reading measures four clauses: unsupervised expert work across occupations, ten gigawatts acting as one machine, measured self-improvement, and third-party proof of execution. This episode touches the fourth clause and the governance component under it. Compute, energy and fabric stay where they were. Capability moves on measured results, and an eighteen-day outage of a public model is a deployment fact, so it stays put too.
Governance carries a weight of 0.05, the smallest on the ledger, and the method sizes a confirmed step by scale against the definition's thresholds. A written rule from Commerce, tested and withdrawn, is a confirmed event. It binds Anthropic alone, and it arrived as a letter. The framework meant to generalise it is a proposal among four Glasswing partners, with four criteria and a bug bounty. Kahn's licensing regime and Moussouris's defensive prompt both describe a rule that exists in practice and is unwritten in law. So the reading moves 0.4, in governance, at confirmed confidence. It stays under the band's floor because the thing confirmed is an arrangement, and the arrangement covers one lab.
What Commerce and Anthropic put in writing, and what remains a proposal
The recordThe data10 rows · sources
| Column | Item | Source |
|---|---|---|
| Written and in force | Commerce lifted the controls on both models on June 30 | [3] |
| Written and in force | Lutnick listed Anthropic's commitments on detection, standards and reporting | [3] |
| Written and in force | Classifier blocks the Amazon technique in over 99 percent of cases | [1] |
| Written and in force | Mythos 5 cleared for more than 100 US institutions | [6] |
| Written and in force | HackerOne bug bounty opened beside the redeployment | [8] |
| Proposed or unwritten | Severity framework remains a proposal among Glasswing partners | [1] |
| Proposed or unwritten | Four scoring criteria: capability gain, breadth, weaponization ease, discoverability | [1] |
| Proposed or unwritten | Commitments offered voluntarily before the directive, per TechCrunch | [3] |
| Proposed or unwritten | Kahn: a licensing regime officials deny exists | [5] |
| Proposed or unwritten | Refusals of reasonable coding requests rise, at a rate still unpublished | [1] |
By the numbers
- 18 days between the June 12 directive and the July 1 restoration of Fable 5 1
- 5:21 pm Eastern on June 12, the time Anthropic received the directive 2
- Over 99 percent of attempts using the Amazon technique are blocked by the retrained classifier, by Anthropic's count 1
- More than 100 US institutions cleared for Mythos 5 on June 26 6
- Around 100 cybersecurity professionals signed the open letter opposing the controls 7
- $10 per million input tokens and $50 per million output for Fable 5 at launch, against $25 and $125 for the Mythos Preview 9
- About $1 trillion in private-market valuation for Anthropic as Fortune reported it on July 1 10
- Four criteria in the proposed jailbreak severity framework: capability gain, breadth, ease of weaponization, discoverability 1
What to watch
A published severity framework, adopted by a second lab and applied to a second release, would turn a bilateral arrangement into an industry rule and earn a larger governance step. Commerce writing its licensing conditions into a public document would do the same. Measured false-positive rates on routine coding, from Anthropic or an outside tester, would settle whether Moussouris or the redeployment note describes the classifier correctly. A second directive against any frontier model would reverse this move on the day it arrives.
Sources
- 1Redeploying Claude Fable 5, Anthropic, June 30, 2026
- 2Statement on the directive to suspend Fable 5 access, Anthropic, June 12, 2026
- 3Trump drops restrictions on Anthropic's Mythos and Fable models, TechCrunch, Tim Fernholz, June 30, 2026
- 4Feds freaked over Fable 5 after simple 'fix this code' prompt, not jailbreak, says researcher, The Register, Jessica Lyons, June 15, 2026
- 5Anthropic's Fable and Mythos models are back. But U.S. AI policy is still a mess., Fortune, Jeremy Kahn, July 2, 2026
- 6Exclusive: US releases powerful Anthropic model Mythos to some US companies, Semafor, Reed Albergotti and Ben Smith, June 26, 2026
- 7'Fix this code.' The three little words behind the U.S. government decision that shut down Anthropic's Fable and Mythos AI models, Fortune, Jeremy Kahn, June 15, 2026
- 8Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls, The Hacker News, Swati Khandelwal, July 1, 2026
- 9Anthropic spins a Fable of a tamer, safer Mythos, The Register, Thomas Claburn, June 9, 2026
- 10Anthropic restoring access to its most powerful AI models signals a necessary truce with the U.S. government, Fortune, Tristan Bove, July 1, 2026