Update, June 13: More details have emerged that reinforce how thin the government’s stated basis appears, while also strengthening and potentially complicating it.
First, the jailbreak research that reportedly triggered the directive was conducted by researchers at Amazon, according to Katie Moussouris, CEO of Luta Security, who said Anthropic shared the report with her. Moussouris is among the most authoritative voices in the field: she built Microsoft’s first bug bounty program, co-authored the international standards governing vulnerability disclosure, and led the launch of the Defense Department’s Hack the Pentagon. Her assessment of the flagged behavior is unambiguous. The information the model surfaced, she said, would be more useful to people defending networks than to anyone attacking them, and she characterized the government’s response as a complete overreaction, precisely the kind of prompting a defender would run. Her question for the administration was direct: who at the White House evaluated this and judged it a threat. Amazon did not respond to requests for comment.
Her account independently corroborates what this piece argued from the public record. The capability at issue is the ordinary work of security research, it is widely available, and it does not become more dangerous because one model produced it. An expert with no stake in Anthropic’s commercial position, holding a copy of the actual report, reached the same conclusion the deemed-export framing points to: the instrument is disproportionate to anything the evidence supports. That the precipitating research came from Amazon is a further detail the government has not addressed and one whose implications it has not been asked to explain.
The second update potentially shows the picture of Fable 5’s safety record is more contested than either the government’s silence or Anthropic’s reassurances suggest. Anthropic stated that an external bug bounty found no universal jailbreaks across more than 1,000 hours of pre-launch testing. Within a day of release, the independent red-teamer known as Pliny the Liberator publicly claimed to have defeated Fable 5’s safety classifiers using a coordinated multi-agent technique, posting screenshots that, by his account, showed the model producing offensive-security exploitation steps and a controlled-substance synthesis pathway, categories well outside the defensive codebase analysis at issue in the Amazon report. He also published what he said was the model’s roughly 120,000-character system prompt. The claims were reported by cybersecurity trade press and rest on Pliny’s own demonstration; they have not been independently verified by major outlets, and Anthropic had not publicly responded at the time of writing.
Third, the export control directive was signed by Commerce Secretary Howard Lutnick, under Epstein scrutiny, and endorsed by Elon Musk during his nomination for Treasury Secretary (also courtside at Madison Square Garden for Game 3 of the NBA Finals days before the directive went out). Musk’s SpaceX, which had its record setting IPO the same day the directive was issued, owns Grok, a direct Anthropic competitor, and is also one of Anthropic’s (and Google’s) compute suppliers under a reported $45 billion contract. SpaceX’s IPO was the largest in history. A dense, fascinating cauldron of timing and personalities.
original post:
On June 2, 2026, the White House issued an executive order establishing what it called a voluntary framework for frontier AI models, one that gave the government up to 30 days of pre-release access and expressly disclaimed any mandatory licensing or preclearance; eleven days later it ordered Anthropic to cut off all foreign access to two already-released models, and the word voluntary stopped meaning anything.
On the evening of June 12, hours after the SpaceX IPO debuted on the NASDAQ, the United States government sent Anthropic a letter that did something no government had done to a deployed commercial AI model before. Citing national security authorities, it issued an export control directive ordering the company to cut off all access to Fable 5 and Mythos 5 for any foreign national, anywhere in the world, including foreign nationals on Anthropic’s own payroll. The directive arrived at 5:21pm Eastern. The order targeted foreign nationals specifically; because Anthropic could not enforce a nationality test across tens of millions of accounts in real time, it disabled both models for every customer to stay compliant. The narrow order produced a total blackout.
What the government issued is a deemed export control. In US trade law, a deemed export is the release of controlled technology to a foreign national, treated as if the technology had been shipped to that person’s home country, the access itself counts as the export. That framework exists to govern things the government has classified as dual-use: technology with civilian value and military applicability, the kind of item whose spread is restricted because it could be turned to a weapon. You do not reach for this instrument unless you have already decided the thing in your hands belongs in that category. The directive does not say in plain words that Fable 5 is a security threat. It does not have to. The legal mechanism it chose says it for them. To control a model this way is to classify it, by implication, as a controllable dual-use capability, something closer to a weapon than to software.
Anthropic says it disagrees with the order, is complying with it, and believes the whole thing is a misunderstanding it can resolve within hours. Maybe it can. In the meantime, new sessions across Claude’s products fall back to a user’s selected default or to Opus 4.8, and the two models are simply gone for the people the order reached. But the mechanism the government reached for, and the speed with which a commercial model serving hundreds of millions went dark, are worth examining on their own terms regardless of how the next 24 hours resolve. The logic here was built for missile components and chip fabrication equipment, and it has been pointed at the question of who is allowed to query a chatbot. That is new, and the gaps in the public record are as instructive as the facts.
When the news first broke, I asked the following questions on Twitter and this post attempts to answer what we can with the information we have:
- Define “foreign national”
- What could possibly be the rationale for this?
- Did some kind of incident provoke this?
- Is Anthropic being restrained because of a legitimate threat or as punishment?
- Who was consulted before this decision?
- If there is a security threat,what is the severity of that threat? How immediate?
- Is the US government aware the tech has likely already been accessed by “foreign nationals”, a reality Anthropic forecast months ago?
What “foreign national” means here, and why the word matters
In US export control practice, a foreign national is anyone who is not a US citizen, lawful permanent resident, or member of a small set of protected categories. The category is built around the concept of a “deemed export,” the idea that handing controlled technology to a foreign national standing inside the United States counts, legally, as exporting it to their home country. A German engineer reading a controlled schematic in an office in California is treated as if the schematic were shipped to Berlin.
That framework is decades old and uncontroversial when applied to blueprints, source code for encryption, or the design of a centrifuge. What is novel is applying it to interactive access to a deployed commercial model. The directive does not restrict the model’s weights, or its training data, or a research artifact. It restricts the act of querying a running service, and it draws the line by the passport of the person doing the querying. Anthropic’s own statement makes the reach explicit: the suspension covers foreign nationals whether inside or outside the United States, and reaches the company’s own foreign-national staff. A Canadian working at Anthropic in San Francisco is, under this order, on the wrong side of the line. For U.S. allies, the lesson is especially uncomfortable: friendly status does not create procedural standing when the controlling jurisdiction decides the model is a national-security object.
The closest precedent is instructive because it does not quite fit. The deemed-export concept has been stretched to cover cloud and software-as-a-service access before, and current export regulations do contemplate that allowing a foreign national to reach controlled technology on a cloud network can count as an export. But in every established version of that doctrine, the restricted thing is controlled technology or source code, the underlying technical material, not the act of using a finished consumer product that the same company has made available to hundreds of millions of people. A foreign national inside the United States may freely use encryption source code and object code; the deemed-export trip wire historically attaches to technical data and to a US person providing technical assistance, not to the end use of a deployed service. The directive negates the distinction. It treats querying a live commercial chatbot the way the older regime treats handing someone a schematic.
The deeper historical rhyme is the Crypto Wars of the 1990s, when the US government classified strong encryption as a munition and restricted its export, until the regime collapsed under the weight of the obvious: the technology was already everywhere, the controls mostly burdened legitimate commerce, and a 1996 executive order moved commercial encryption off the munitions list. The throughline is a government reaching for export authority to contain a dual-use software capability it considered dangerous, and discovering that the capability had already diffused past the point where a control on one provider could matter. Anthropic’s central factual claim, that the flagged capability is matched by OpenAI’s GPT-5.5 and used daily by defenders, is a Crypto Wars argument in everything but name. If a capability is widely available, restricting one provider’s access by nationality does not remove the capability from the world. It removes one company’s customers from the capability.
The order itself was narrow in target: foreign nationals. The effect was not, because Anthropic could not surgically apply a nationality test across hundreds of millions of accounts in real time, so it did the only thing available and suspended both models for its entire customer base. The blunt enforcement produced a blunt outcome. That gap is itself a finding: when an export control regime designed around discrete, identifiable transfers meets a service consumed by an undifferentiated global user base, the only compliant move is total shutdown, and the narrow rule swallows everyone.
The stated rationale, and the distance between the government’s claim and Anthropic’s
The government’s letter, by Anthropic’s account, did not spell out its national security concern. The company’s stated understanding is that officials believe they have learned of a method for jailbreaking Fable 5, bypassing the safeguards that block the model from helping with high-risk tasks.
Anthropic’s rebuttal is specific and technical. It says the demonstration it was shown used a known technique to surface a handful of previously identified, minor vulnerabilities, the kind of flaws that other publicly available models will also find without any bypass at all. The company points to OpenAI’s GPT-5.5 as a model with comparable capability in the same domain, and frames the flagged behavior as something defenders use daily to keep systems secure. In Anthropic’s telling, the specific jailbreak the government appears to be reacting to amounts to asking the model to read a codebase and fix software flaws in it.
There is an analytical claim buried in the company’s launch posture. Anthropic argues that perfect jailbreak resistance is not currently achievable by anyone, that every safeguard in the industry is vulnerable to narrow jailbreaks in specific circumstances, and that no tester has yet found a universal jailbreak against Fable 5 that broadly unlocks the model’s restricted capabilities. Its strategy, by its own description, was never zero vulnerabilities. It was to keep jailbreaks either narrow or expensive, pair them with monitoring, and shut down attacks quickly, the reason it imposed 30-day data retention on this model class despite the commercial cost.
So the two parties are not disagreeing about the same fact. The government appears to treat the existence of a working bypass as disqualifying. Anthropic treats the existence of narrow bypasses as the unavoidable baseline condition of every deployed model, and argues the relevant question is whether the bypass delivers capability that is both dangerous and unavailable elsewhere. On the public record so far, the company says it does not.
Whether an incident provoked this, which remains the central unknown
Anthropic says the government provided only verbal evidence of a narrow jailbreak and that the company has not received disclosure of any concerning bypass that produced a harmful result. If a real-world security event had occurred, a breach, an attack traced to the model, a specific harm, the natural place for the government to anchor a directive of this severity would be that event. The absence of a cited incident does not prove none exists; classified material does not appear in press statements, but it shifts the weight of the available evidence toward a directive issued on the basis of demonstrated capability rather than demonstrated harm, a meaningful distinction. A government acting on a capability it considers latent and dangerous is operating in a very different posture from one responding to an attack already underway, and the two justify very different responses.
The current answer to whether an incident provoked this is that nothing in the public record indicates one, and Anthropic’s account actively suggests the opposite.
Legitimate threat or punishment, which is the wrong binary
Read against Anthropic’s own technical account, a straightforward safety rationale is hard to sustain. An order that suspends access to a model deployed to tens if not hundreds of millions, over a narrow bypass the company says is matched by capabilities freely available in competing models, is not proportionate to the threat as Anthropic has described it. The company says as much, and warns that applying this standard across the industry would effectively halt all frontier model deployment, because every provider ships models with exactly the kind of narrow vulnerabilities at issue here.
But “punishment” imports an intent the evidence does not establish. What the record does support is something more structural: a government testing the limits of its export control authority against a new class of product, choosing a maximal interpretation, and reaching for the most severe available remedy in response to a category of risk it has decided it does not want to tolerate, even at the deployed-commercial-model stage. Whether that reflects a coherent security judgment, a precedent-setting exercise of authority, internal pressure inside the executive branch, or some interaction of all three is not knowable from the outside today. Watch what the government discloses, rather than try to resolve it prematurely in either direction.
Who was consulted, and the process question underneath it
Anthropic does not say who inside the government issued the directive, which agency, or under which specific statutory authority. It describes a letter citing national security authorities, without naming them. Nor does it indicate that it was consulted before the order issued. The sequence it describes is a letter arriving at a specific minute on a Friday evening, followed by immediate compliance.
This is where the directive collides with Anthropic’s own stated policy position, and the collision is the part of the story with the longest tail. The company has argued publicly, in its Policy on the AI Exponential and in Dario Amodei’s writing, that the government should be able to block unsafe deployments through a statutory process that is transparent, fair, clear, and grounded in technical facts. Its closing line on this directive is that the action does not adhere to those principles. The complaint is not that the government acted. It is that the government acted without the process Anthropic believes such authority requires, no disclosed evidentiary basis, no apparent pre-decisional consultation, no clear statutory citation, and immediate effect.
That procedural objection will matter more than the specific dispute over Fable 5 if it sets a precedent. A directive that can pull a deployed commercial model on verbal evidence, with the legal basis unstated and the affected company informed by letter rather than consulted, establishes a posture. Every frontier provider is now on notice that this is a move the government is willing to make.
What it is like to actually work in the model that got pulled
There is a dimension the directive does not touch, and it is the one I am positioned to speak to directly. I serve as an expert witness on the failure modes of large language models, and the argument I am about to make is one I have been developing across roughly eight months of testing successive frontier releases. I no longer have access to Fable 5 as a Canadian working in Cambodia. The model is, in my sustained assessment, the least reliable reasoning model Anthropic has shipped in that window. Not the least capable in a benchmark sense, the least reliable in use: coherence that degrades as a session extends, factual material from earlier context surfacing where it does not belong, and hallucination at rates I had not previously seen from this company’s models. I have already written about this on Twitter/X as have others, and want to be careful about cause, but the observation itself is a professional judgment, not an impression.


Caption: (1) Fable 5 hallucinating a paper, and (2) conflating two topics, thereby misunderstanding the relatively simple premise of an argument
The reason this matters for the directive is that it exposes the axis the government’s logic ignored entirely. The order is indexed on a single dimension, a narrow cyber capability that can be elicited under specific conditions. Capability and reliability are different things, and they do not move together. A model can be elicitable into one narrow task that alarms a regulator while being unreliable enough at sustained reasoning to frustrate the people using it every day. Those two facts are not in tension. They describe different properties of the same system. This is close to the load-bearing distinction in the verification work I have argued elsewhere: the cost of verifying a model’s output is what governs whether the output is usable, and a model that is impressive on a capability axis can still impose verification costs that make its reasoning output expensive to trust. The directive treats capability as the whole risk surface. In practice it is one axis of several, and arguably not the one that determines whether the model is safe to rely on for ordinary work.
On cause, two readings fit the symptoms and I am not going to pretend the evidence settles which. The first is genuine degradation, that this model’s reasoning reliability is simply worse than its predecessors for architectural or training reasons. The second is that the safeguards are doing it. Anthropic states plainly that Fable’s safeguards are aggressive enough that users have complained they are overbroad, and heavy safeguard interference presents, from the user’s side, very much like incoherence: hedging that reads as confusion, dropped threads where the model has silently routed around something, context that gets mangled in the course of being filtered. A model being throttled by its own guardrails and a model that is genuinely degraded can feel nearly identical from the outside. I lean toward thinking both are present to some degree, and I hold the question open because the data to close it is not public.
Either way, the irony is hard to miss and worth stating without overclaiming it. The government identified this specific model as dangerous enough to control like a weapon and to bar a class of users from on national security grounds, and it did so within hours of a letter. It is, by my assessment, also the model whose ordinary reasoning I trusted least. A governance apparatus that can move this fast and this hard on one narrow axis of capability, while the axis that actually determines whether a model is dependable for real work goes entirely unexamined, is not measuring the thing that matters most to the people who use these systems. That gap, between what the directive measured and what reliability in use actually consists of, is the part of this episode I expect to be arguing about for a while.
The sixth question, what the specific security threat actually is, returns to the same void as the third. Anthropic’s position is that it has been shown a narrow, non-universal jailbreak and nothing more, and that the capability involved is neither novel nor confined to its models. The government has not publicly articulated a specific threat beyond the national security framing. Anthropic has committed to sharing more over the following 24 hours, so the record may fill in.
What can be said now is that the load-bearing facts are not in public view. The legal authority is unnamed. The evidentiary basis is, by the company’s account, verbal and narrow. No precipitating incident is cited. The decision process is undescribed. The affected models were deployed to hundreds of millions and then withdrawn within hours of a letter.
This is what the sovereignty problem looks like when it stops being theoretical. The argument is usually made in the abstract: that depending on a foreign-controlled technology stack means accepting that access can be revoked by a government that is not yours, for reasons you cannot see, through a process you have no standing in.
Tonight it is not abstract. A model that was running inside companies, products, and workflows across dozens of countries was switched off for every non-American who touched it, on the authority of a letter those users will never read, issued by a government most of them did not elect, enforced by a company that was given no choice but to comply. Hosting the infrastructure elsewhere would not have helped. Signing a different contract would not have helped. The control did not live in the data center or the terms of service. It lived in the jurisdiction that governs the company that controls the model, and that jurisdiction reached every user at once. Sovereignty is not a question of where a system is hosted or who pays for it. It is a question of who can turn it off, and whether the people who depend on it have any say when that happens. The answer arrived tonight, and for everyone outside the United States the answer was none.
The mechanism here is opacity at the point of enforcement: a consequential action taken with the reasoning withheld and the process unclear, against technology whose own behavior neither the public nor, on its account, the company can fully see into. The export control framework gave the government a lever built for a different kind of object, and it pulled it. Whether the misunderstanding Anthropic describes gets resolved tomorrow or evolves into precedent, the demonstration has already happened. The capacity to switch off a frontier model by nationality, on national security authority, with the basis undisclosed, is now a known quantity. That does not get un-demonstrated by a restoration of access. The voluntary EO (despite its use as written being restricted to pre-release models) now has some demonstrably very sharp teeth. It also appears to settle some online discussions that the slew of model warnings were nothing more than a marketing exercise, one Brian Merchant called the most effective pre-IPO comms in history.
This is a developing story; check back for updates to this post.

