The whole story - from the closed Mythos Preview and the mandatory-evaluation order Trump rejected, to the global shutdown, the backroom negotiations, Fable’s return, and the first international consequences.

Fable 5 is available again after nearly three weeks of a worldwide shutdown. Anthropic reached an agreement with the US government, changed the model’s safeguards, and got the export restriction lifted. But the original state was not restored: the more capable Mythos 5 stayed behind closed doors, and no court ever tested the legality of the mechanism that let the government switch a model off around the world.

Over the past month, details have surfaced about the reasons for the ban, the legal mechanism, Anthropic’s negotiations with the White House, and the terms of the return. Most retellings focus on the middle of the story - the jailbreak, the sudden shutdown, and Anthropic’s clash with the administration. Two less visible episodes sit at the edges: shortly before the ban, Trump rejected mandatory model evaluation, and after it, dependence on American AI became a topic at the G7 level. I decided to assemble the whole thing.

Access came back. The administrative kill switch never went anywhere.

April: How One Model Pulled In the White House and the Bankers

The story did not start with Fable. It started with the announcement of Mythos Preview on April 7.

Anthropic presented the model as an unusually strong tool for finding vulnerabilities, and immediately declined to release it to everyone. According to the company, in closed testing Mythos found thousands of previously unknown bugs in operating systems, browsers, and other critical software, and could build multi-step exploitation chains. The independent evaluation by the UK AI Security Institute painted a more restrained but still serious picture: in a controlled test with five runs and a budget of up to 50 million tokens, the model solved 73% of expert-level CTF tasks. In a separate 32-step simulated attack on a corporate network, it reached the end in three attempts out of ten.

How far Mythos actually outclassed other models remains contested. Independent researchers later reproduced part of its results using cheap public models with good orchestration. What matters here is something else: Anthropic itself declared the new capability dangerous enough not to sell as an ordinary product.

Instead of a public release, the company created Project Glasswing. The first partners - AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, Palo Alto Networks, and other major infrastructure players - got Mythos Preview in advance, so they could find and fix vulnerabilities before capabilities like these spread more widely.

After that, activity around the model became unusual for a routine AI release.

On April 10, Treasury Secretary Scott Bessent and Federal Reserve Chair Jerome Powell convened the CEOs of the largest banks. What worried them was Mythos’s ability to quickly find previously unknown vulnerabilities in banking software and build working exploitation chains. If a tool like that reaches attackers, it can speed up a breach of banking infrastructure; for a systemically important bank, a major incident becomes a financial stability risk. Attendees were urged to test their own defenses in advance and prepare for other models with similar capabilities.

On April 17, Anthropic CEO Dario Amodei came to the White House to meet Chief of Staff Susie Wiles and Bessent. Around the same time, Vice President JD Vance held a closed conversation with the heads of the largest AI companies, including Elon Musk, Sam Altman, Amodei, Sundar Pichai, and Satya Nadella. Coordination of the government’s response went to National Cyber Director Sean Cairncross - the model was treated first of all as a cybersecurity and critical infrastructure question.

Similar questions surfaced outside the US. In India, the finance minister convened the leadership of the Reserve Bank of India and the largest banks to discuss the risks of Mythos.

National Economic Council Director Kevin Hassett compared future AI model evaluation to drug approval: before a new capability is released “into the wild,” the state should be confident it is safe. An administration that came in under the banner of AI deregulation had unexpectedly started discussing its own FDA for frontier models.

Not everyone believed Anthropic. Venture investor Ben Narasin compared Amodei to “the boy who cried wolf”: the company had stressed the danger of its own work for so long that the government finally took the warning literally. David Sacks - co-chair of the President’s Council of Advisors on Science and Technology and the former head of White House AI policy - also accused Anthropic of stoking fear to get regulation that would suit it.

The Order Trump Refused to Sign the First Time

The next act began on May 21, with a signing ceremony that never took place.

The White House was about to sign a document on evaluating the most capable AI models before public release. Tech industry representatives had already been invited to the event, but the ceremony was abruptly cancelled. Trump explained to reporters: I didn't like certain aspects of it, I postponed it. According to press reports, the original version provided for up to 90 days of prior government review and met resistance from tech companies worried about slower releases.

Twelve days later, Trump did sign a different version of the order. The review was cut to 30 days and made voluntary. The text noted explicitly that the document does not create mandatory government licensing or prior approval for releasing models.

On the same day, Anthropic expanded Glasswing to roughly 200 organizations across more than 15 countries. The company was building an international cyber defense coalition while the government was simultaneously setting up a voluntary review procedure for future models.

Around the same time, the governor of the Reserve Bank of India said the Indian regulator had not yet received access to Mythos but was already preparing for the threats associated with it. That was the flip side of managed distribution: Glasswing participants could study the model themselves, while other regulators prepared for its capabilities from the outside.

The result was a compromise: labs could show their strongest models to government experts in advance, but the final release decision formally stayed with the companies.

June 9-12: The Public Release and Two Episodes of Lost Trust

On June 9, Anthropic released Fable 5 to the broad market and commercial Mythos 5 to vetted partners.

It is easy to get lost here, so a quick map of the entities:

  • Mythos Preview - the early closed version that Glasswing started with;
  • Mythos 5 - the commercial senior model with managed access;
  • Fable 5 - the mass-market model of the same class, but with extra guardrails;
  • Glasswing - the partner access program for the Mythos class;
  • Annex A - the later US list of recipients of commercial Mythos 5.

Fable came with safety classifiers for several sensitive areas: cybersecurity, biology and chemistry, and distillation attempts - copying the model’s capabilities by mass-harvesting its answers. When a safeguard fired, the request was handed off to the weaker Opus 4.8. Mythos retained fuller cyber capabilities for government bodies, critical infrastructure operators, and other trusted partners.

By the time of the public release, trust between Anthropic and the administration had already started to break down.

The first episode was South Korean SK Telecom’s access to Mythos through the expanded Glasswing. According to WIRED, US officials became alarmed by the company’s alleged ties to China and asked Anthropic to revoke the access. The company did so the same day, without any threat of export controls. SK Telecom denied ties to China; its own presence there was small, though its parent SK Group ran a large business in the country. An additional irony: SK Telecom was a $100 million investor in Anthropic.

On June 10, Amodei publicly took a position that turned against Anthropic two days later. He published an essay calling for mandatory regulation of frontier models. Under his proposal, the government, after an independent evaluation, should have the right to block or deter deployment of the model if the risk is judged unacceptable.

The second episode was a report of a Fable jailbreak. According to investigative reporting, the problem was discovered by Amazon - simultaneously a major Anthropic investor, a cloud partner, and a potential competitor. Amazon CEO Andy Jassy reported it to Treasury Secretary Scott Bessent, after which government specialists ran their own check.

The government’s version was simple: Fable is effectively Mythos behind filters. If the filters can be bypassed, a mass-market user gets the senior model’s cyber capabilities. Anthropic was told to fix the bypass or take the model out of service. Administration officials claimed Amodei refused to do either.

Anthropic described the situation differently. The company called the bypass a narrow, non-universal jailbreak and argued that the demonstrated capabilities offered no unique uplift: other models available on the market performed comparable tasks without any jailbreak at all.

The administration was assessing absolute capability: can the model help find and exploit a vulnerability? Anthropic was assessing marginal risk: does Fable specifically give an attacker a capability they did not have before?

The technical details of the bypass were never made public, so there is no way to independently assess how reproducible it was or how much capability it actually added.

WIRED stresses that SK Telecom and the Amazon jailbreak were two separate matters. Lutnick’s letter itself mentioned neither the Korean company nor China, and a large part of the reconstruction rests on anonymous sources. It cannot be said with confidence that SK Telecom was the legal cause of the ban. But the political sequence is clear: first came the question of whether Anthropic could control who receives Mythos, then whether it could keep Mythos capabilities behind Fable’s safeguards.

Two days after Amodei’s essay, the government ordered access to both Anthropic models closed.

The Shutdown: Ninety Minutes, According to the People in the Room

On June 12, Commerce Secretary Howard Lutnick sent Anthropic an individual notice of a new licensing requirement - a so-called is-informed letter. That is not a name invented by journalists but a real instrument of the Bureau of Industry and Security (BIS): the agency notifies a specific recipient in writing that the listed transactions now require BIS authorization.

The requirement covered access to Fable 5 and Mythos 5 for foreign persons anywhere in the world, including Anthropic’s own foreign employees. This was not about transferring weights or source code. A user sent a request to a model running on Anthropic’s servers and got an answer back - in other words, used an ordinary cloud service.

The letter was not a new law, a published rule, or the outcome of an open procedure. It never appeared in the Federal Register, the official journal where US federal agencies publish rules and notices. It was an individual administrative order, binding on its recipient under threat of civil and criminal penalties.

According to journalistic reconstruction, Anthropic was given about an hour and a half to comply; the directive itself was never made public, so that deadline cannot be independently confirmed. In that window, Anthropic could not have built a system that reliably determined every user’s citizenship, every company’s ownership structure, and every employee’s status. As we know, it shut both models down globally.

The June 2 executive order created no mandatory review procedure. Yet ten days later the administration applied existing export law to Anthropic - a far harsher mechanism, with no public criteria and a demand for near-immediate compliance. Formally this was not a way around the order: the new licensing regime rested on a different authority and regulated foreign access rather than the release of the model itself.

There is an irony in Anthropic being both a co-author of the emerging control regime and the first party against which that regime was enforced. The company restricted access to Mythos on its own, picked trusted recipients, came to the White House to discuss risks, and publicly asked for strong models to be regulated. None of that made Lutnick’s particular letter automatically lawful or proportionate.

June 14 - July 1: Protest, Negotiations, and the Return

On June 14, executives and researchers from the security industry published an Open Letter on Transparent AI Cyber Protections. Signatures kept accumulating after publication. Among the signatories were former Facebook security chief Alex Stamos, cryptographer and security author Bruce Schneier, and Luta Security founder Katie Moussouris. They demanded the restrictions be lifted and proposed four principles for future decisions: scientifically grounded evaluation, a proper democratic process, transparent enforcement with time to remediate, and the minimum necessary scope of intervention.

Over the weekend after the shutdown, Amodei spoke with Bessent, Lutnick, and staff from the national cyber director’s office. Anthropic’s safeguards and red-team leads flew to Washington. The June 16 talks ended without a deal: the administration still believed that stripping Fable’s guardrails opened access to Mythos-level capabilities.

In the same days, the conflict went international. At a separate meeting on the sidelines of the G7, leaders including Donald Trump, Emmanuel Macron, and European Commission President Ursula von der Leyen discussed AI with the heads of the leading labs. Anthropic was represented by Amodei; other participants included OpenAI CEO Sam Altman and Google DeepMind chief Demis Hassabis. One topic was an access scheme for trusted partners that could return strong American models to selected allies. No common scheme was agreed.

On June 23, Legion LegalTech filed suit in federal court in the District of Columbia, seeking to vacate the directive as exceeding the Commerce Department’s authority.

Then the cast of negotiators changed. According to WIRED, Amodei’s personal rapport with officials had deteriorated so badly that the CEO was pushed away from direct talks. Co-founder and compute lead Tom Brown and head of public policy Sarah Heck took over. After conversations with them, the administration’s tone became more constructive.

On June 26, the government authorized access to commercial Mythos 5 for a confidential list of more than 100 American companies and government organizations. In the paperwork it appeared as Annex A. The list was never made public; the stated common criterion was defensive work in cybersecurity and critical infrastructure.

It is easy to confuse two different groups here. By June 2, Glasswing included around 200 organizations from various countries working with the early Mythos Preview. Annex A appeared after the ban and defined a far narrower circle of American recipients of commercial Mythos 5. Some organizations may have belonged to both, but neither list has been published in full.

On June 30, the Commerce Department announced that an export license was no longer required for either model. The next day, Anthropic brought Fable 5 back for users in supported regions via Claude.ai, Claude Code, Cowork, and the Claude Platform. On third-party cloud platforms, restoration was phased.

The Commerce Department never acknowledged that its original decision had been unlawful. The restrictions were lifted after Anthropic put additional measures in place and took on voluntary commitments: faster reporting of significant jailbreaks and malicious use, broader pre-release access for government specialists, and participation in joint evaluations.

The company launched a bounty program on HackerOne and proposed a Cyber Jailbreak Severity Framework - a scale of jailbreak consequences from CJS-0 to CJS-4. Its point is practical: to give labs and government a shared language for deciding which bypass can be fixed through the normal process and which requires delaying or pulling a model. For now it is only a draft, not an industry standard.

After the models returned, Legion withdrew its suit. The court never got to rule on the legality of the directive.

What Exactly Came Back

For the mass-market user, Fable reappeared in the interfaces and the API, but it did not come back in its previous state.

Anthropic retrained the classifier to block the specific technique from Amazon’s report in more than 99% of cases. That number applies neither to Fable’s overall safety nor to jailbreaks in general, but to one class of bypass on an internal test set. The methodology and the dataset have not been published.

The company acknowledged a side effect: more false positives on ordinary coding and debugging tasks. When the classifier fires, a request may be refused or rerouted to Opus 4.8. In Claude.ai and other apps, the user sees a notice. In the API, the refusal comes back with stop_reason: "refusal", so a developer has to handle that response separately and, if needed, automatically switch the request to a fallback model.

At the same time, Fable 5 became Anthropic’s most expensive generally available model: $10 per million input tokens and $50 per million output tokens, against $5/$25 for Opus 4.8.

Commercial Mythos 5 is a different story. Formally, the blanket licensing requirement was lifted for it too, but the model never appeared in the public API. It stayed in managed-access mode for a confidential circle of American organizations. As of July 11, there had been no open international expansion.

Mythos Preview itself continued to exist inside Glasswing. Some American partners kept access to it even while the commercial models were switched off, whereas foreign participants, including ENISA and Korean organizations, lost out.

So the mass market got Fable back with an extra layer of safeguards. The fuller Mythos capabilities stayed with a narrow circle.

Short answer: nobody knows yet.

The Commerce Department relied on the Export Control Reform Act and the Export Administration Regulations (EAR). The problem is that these rules were built to control goods, technology, source code, and sensitive recipients - for instance, companies and organizations tied to the military. Applying them to the output of a cloud model is far from obvious.

The government’s logic may have been this: what matters is not the model files but the capability a foreign user obtains. If through the API they can solve the same dangerous tasks that technology transfer controls exist to prevent, then the model remains a risk even when its weights sit in the US. The administration may have considered that sufficient grounds for an emergency export restriction.

First, the user received no weights, no code, and no technical documentation. The model stayed on Anthropic’s servers; the user got only an answer to their request.

Second, the rule that was invoked was designed for particular countries and organizations tied to the military or intelligence services. The letter, by contrast, swept in every foreign user worldwide.

Third, the Commerce Control List - the official inventory of goods, software, and technology subject to US export controls - contained no separate entry for remote access to a running cloud model.

Fourth, CSIS pointed out that the Commerce Department had previously used the very same §734.13 in three advisory opinions to reach the opposite conclusion: remote access to a cloud service is not, by itself, subject to the EAR.

Finally, Congress was considering a Remote Access Security Act intended specifically to extend export authority to remote foreign access. The mere existence of such a bill signalled, at minimum, legal uncertainty.

These are arguments, not judicial findings. The government could reply that a frontier model is a dual-use technology, and courts usually grant the executive broad latitude on national security matters.

Legion was supposed to test the dispute in court but withdrew after access was restored. So no judicial or legislative precedent emerged. What did emerge is a precedent in the agency’s own conduct: the Commerce Department applied an existing instrument to a live commercial model, the company complied, and the limits of the authority were never tested.

Access by Citizenship, Organization, and Request Content

In my post on Mythos and the second asymmetry I pointed to an inequality of access that already existed: early Mythos went to selected organizations, mostly in a single jurisdiction, and over time regulators could exert more and more influence over who was chosen. The Fable Saga showed the next stage of that logic - access started to be explicitly tied to citizenship, employer, and purpose of work.

The first split was by citizenship: the June 12 letter demanded that the models be closed to foreign persons, including Anthropic employees without US citizenship.

The second was by organization and type of work. Mythos came back not to the market at large but to a confidential list of American companies and agencies engaged in defending critical infrastructure. Foreign employees inside approved organizations were allowed access: what mattered was not citizenship alone, but also employer and purpose of use.

The third is enforced by Fable’s own safeguards. A user who is already admitted may still get a refusal or a weaker model depending on the content of the task. The first two mechanisms decide who gets the model; the third decides which capabilities the user gets inside it.

There are also carve-outs for vetted professionals. The Cyber Verification Program lets approved specialists do vulnerability research, penetration testing, and red teaming without some of the restrictions on dual-use tasks. For plainly malicious activity - developing ransomware or mass data theft, for example - the prohibition holds even after approval. The program runs on applications, requires data retention to be enabled, and is available only through some of Anthropic’s platforms and those of its partners. Claude’s geographic restrictions still apply: you can only apply for and use CVP from countries and regions Anthropic supports, and Russia is not on that list. So even a verified profession is no guarantee of extended access on its own: what matters is the nature of the work, Anthropic’s decision, the connection method, and the user’s country.

Anthropic already has mechanisms for verifying identity against a government ID, but it does not apply them to all Fable users to determine citizenship and export status. If this kind of segmentation becomes permanent, ordinary identity verification will not be enough: the system will have to account for citizenship, residency, employer, purpose of work, and possession of the required export license.

Across hundreds of millions of users, that is close to banking-grade KYC. It also creates a privacy risk: sensitive requests end up linked to a verified identity and potentially available to the authorities.

International Reaction and a Parallel Push for Sovereignty

A centralized cloud model is convenient precisely because it stays with the provider. But that same centralization creates a controllable cutoff point: access can be closed by the company, by the cloud platform, or by the government of the supplier’s country.

With an open-weight model, that mechanism works much less well. Weights that have already been downloaded cannot be recalled by letter: a user can keep working with the copy they have and modify it as they see fit. That protects against suddenly losing a model you have already deployed, though it does not remove the other dependencies: new versions and fixes usually come from the developer, and the compute infrastructure may still be tied to foreign suppliers. This is why the Fable Saga became a strong argument for open weights and for keeping several independent suppliers.

Sovereign AI projects and investments long predate the incident. A number of states and companies are already working on their own models, data centers, and compute infrastructure in order to depend less on foreign platforms. Back on May 17 of this year, Mistral CEO Arthur Mensch warned: In a world where you import all your digital services from the United States, you have no leverage over the United States. The Fable story turned that problem into a vivid example.

At the G7, Emmanuel Macron put the risk bluntly: We will not buy any model made by your companies if from one day to the next you can just turn off the switch. He acknowledged that evaluating dangerous capabilities was legitimate, but called the specific American response strictly nationalist.

The French leadership linked the incident to sovereign AI investment and to the DGSI - the French domestic intelligence service - switching from American Palantir to a solution from French firm ChapsVision. The move toward a local supplier, however, began before the crisis, so it cannot be counted as a direct consequence.

Austria urged the European Commission to work on getting Anthropic to host in the EU. A UK parliamentary committee called the shutdown a “powerful reminder” of the risk of dependence. Canadian Prime Minister Mark Carney said: The situation we're in collectively right now with Mythos and Fable is something that can happen with overreliance on certain models.

The most concrete potential consequence came from South Korea, where after the loss of access reports appeared of a plan to concentrate compute resources and extra budget on a single national team. No officially approved budget could be found, though: the discussion has not yet turned into an adopted government program.

In China, agencies have recently discussed restricting foreign access to top Chinese models, open-weight publication, liability for technology leakage, and limits on foreign investment, according to Reuters. There has been no official decision, and no causal link to Fable has been established.

The US and China are looking at different objects. The American mechanism controlled cloud access; the Chinese discussion concerns weights, public release, intellectual property, and developer ownership. But the overall vector is similar: a frontier model becomes a strategic asset whose distribution boundaries the state wants to define.

Almost simultaneously, the US administration applied a softer instrument to OpenAI. On June 25, it asked the company to stagger the release of GPT-5.6. OpenAI opened a limited preview, and the general release followed on July 9.

This was not a second Fable ban. The mechanism stayed voluntary, and the White House denied that it had approved the release. It is more accurate to speak of a request, a review, and a limited preview. But the two episodes show the range of instruments: with Anthropic the state used a binding letter, with OpenAI voluntary coordination.

Materially restructuring the market in a month was impossible: comparable national models, compute capacity, and supply chains do not appear in a few weeks. But the incident changed the political status of the topic. Initiatives that states and companies were already pursuing in Europe, China, India, the UAE, and elsewhere now have a concrete example of dependence on the supplier’s country. After the shutdown, it was discussed by G7 leaders, parliamentary committees, and the authors of national technology plans. Fable acted as a catalyst for policy that already existed, and demonstrated in practice a risk that had more often been described as something in the future.

Three Asymmetries in One Story

I keep coming back to the theme of AI asymmetries in my Telegram posts. The Fable Saga assembled three of them at once.

The first is between a service’s apparent availability and its actual behavior. Ordinary monitoring will tell you whether the API responds and whether it returns errors. But a service can keep formally working while requests are already being handled by a weaker fallback model (Opus instead of Fable, or Sonnet instead of Opus), while the safety filters refuse more often, or while some capabilities have been closed off for your category of user.

The second is between customers’ ability to notice a change and their ability to adapt to it. A large company can regularly run the same set of characteristic tasks through the model. Checks like these help detect a hidden drop in model quality, compare suppliers, and switch a workflow to a fallback model in time. Anthropic, for instance, officially routes some cybersecurity, biology, chemistry, and distillation requests away from Fable 5 to the weaker Opus 4.8. In biology and chemistry, these limits are meant, among other things, to prevent the model being used to develop dangerous weapons. It is a deliberate safety measure, but for the customer the result is the same: the API keeps working while the answer quality on a specific class of tasks changes. A small team usually has no evaluation harness of its own, so it learns about the change when a workflow that worked yesterday starts producing a different result or breaks.

The third is inside the defenders’ own camp. In my previous post on Mythos I called it “the second asymmetry of cybersecurity”: some organizations get a new defensive capability earlier and manage to rebuild their processes, while others keep working with the old tools. Annex A went further than Glasswing - access ended up tied to a closed list, a jurisdiction, and an approved purpose of work.

All three come down to the control layer around the model. The provider decides which model answers a request, when a safety filter fires, which fallback model a task is switched to, and who gets extended capabilities. The state can additionally influence admission itself. The user sees the result of these decisions, but rarely the reason for them.

Conclusion: The Button Is Still There

The service came back in under three weeks, but in the meantime the government managed to apply a contested legal construction to a global cloud product and (per journalistic reconstruction) give the company about 90 minutes. The restriction was lifted before any judicial review, so the mechanism survived and the limits of its use remain undefined.

The dependence of cloud AI on the provider and on the state whose jurisdiction it sits in was known before. Fable showed how it works in practice: a single administrative decision changed access to a working tool worldwide faster than the customer, the provider, and the court could prepare.

For business, the conclusion is the same as before, only now confirmed by experience: it is dangerous to tie a critical process to a single centralized model. Open-weight models, local deployment, and multiple suppliers do not remove every risk, but they reduce the chance of a single point of shutdown.

Fable 5 works again. Mythos remains behind closed doors. The administrative shutdown mechanism has already been used, and no court has tested its legality or its limits.

Find me on: LinkedInGitHubTelegramMax