Stankovic.
← Back to News
AIJUN 09, 2026 · 7 MIN READ

Fable 5, Mythos 5, and the First Time Washington Switched Off a Frontier Model

LA
Lazar Stankovic

On June 9, Anthropic released Claude Fable 5, the first time it had put a Mythos-class model, the tier above Opus, into public hands. Three days later, the US government ordered it taken offline for every customer on earth. Nineteen days after that, it came back. The story of those three weeks is the most consequential AI-policy event of 2026, and because it sits at the intersection of frontier capability, cybersecurity, and national-security law, it is worth telling carefully, with the facts from primary sources and the competing views laid out fairly rather than adjudicated.

What launched on June 9

Anthropic released two models that share the same underlying architecture but differ entirely in what they will do. Mythos 5 is the raw model, with fewer safeguards, released only to a small set of vetted Project Glasswing partners for defensive cybersecurity, the continuation of the restricted-tier approach Anthropic established in April. Fable 5 is the same capability wrapped in what Anthropic called the strongest safeguards it had ever applied, made safe enough for general release. Fable 5 was state-of-the-art on nearly every benchmark Anthropic tested, and its defining design feature is a safety mechanism: flagged cyber or bio requests fall back to the less-capable Opus 4.8 rather than being served by Fable itself. That fallback, and the reason Opus 4.8 mattered as the safe substrate, is why the model's May release was a setup for this one.

Fable 5 marked the first time Anthropic released such an advanced model to the public. It should have been the headline. Instead, the headline arrived three days later, from the government.

June 12: the switch-off

On the evening of Friday, June 12, at 5:21pm Eastern, Anthropic received an export-control directive from the US government, citing national-security authorities, ordering it to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including Anthropic's own foreign-national employees. Because that "wherever located" scope covers a category no API can verify in real time (green-card holders, visa workers, overseas users, all at once), and because nationality cannot be checked at the model layer on short notice, Anthropic concluded it had no way to comply selectively. So it suspended both models for everyone, globally, across the Claude platform, AWS Bedrock, Google Cloud, Microsoft Foundry, and more. All other Claude models, Opus, Sonnet, Haiku, kept running.

The government's stated trigger, as Anthropic understood it, was a reported technique for bypassing Fable 5's safeguards, a "jailbreak," discovered by Amazon researchers, that prompted the model into identifying software vulnerabilities and, in one case, producing code demonstrating how a vulnerability could be exploited. The concern: if the filters separating Fable from Mythos's offensive cyber capability could be defeated, a consumer AI product becomes an unrestricted cyber weapon.

The two accounts, laid side by side

This is where a fair write-up presents both positions rather than picking one.

Anthropic's account: the jailbreak was narrow, not universal. It reviewed the demonstration and found it identified a small number of previously known, minor vulnerabilities. Crucially, when Anthropic later tested the claim, it found that many less capable and freely available models, including Opus 4.8, GPT-5.5, and Kimi K2.7, could identify the same vulnerabilities, and that every model tested could produce the same single exploit demonstration. The reported technique, Anthropic argued, exposed no unique Mythos-level capability; it hit a borderline case where Fable's deliberately cautious safeguards blocked routine defensive work. Its position: "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people." It called the action a misunderstanding and worked to restore access.

The administration's account, conveyed publicly by White House AI adviser David Sacks and others: the government had reportedly tried to stop the launch beforehand and failed, the export order was its next move, and officials framed Anthropic as having declined to fix the safeguard issue. This did not arrive in a vacuum. The administration and Anthropic had been at odds for much of the year: the Pentagon designated Anthropic a "supply chain risk" in early March (a designation Anthropic is challenging in federal court), and several Trump technology advisers, Sacks among them, had publicly criticized the company. Observers disagreed on the motive; one AI-policy expert who had served briefly in the administration said he could not tell whether it was "lawfare against Anthropic in particular or extreme national-security hawkery."

Both accounts are part of the record, and readers can weigh them. What is not in dispute: no full text of the order was released publicly, the legal basis was the Export Controls Reform Act's dual-use provisions, and the practical effect was a 19-day global outage.

The criticism from the middle

Beyond the two principals, a distinct line of criticism came from tech executives and investors who were not defending Anthropic so much as worrying about the consequences. Their concern: restricting a leading US lab's newest models handed valuable time to Chinese open-source developers racing to close the gap with cheaper, nearly-as-capable models. The crackdown coincided with exactly that rise, which is why even people with no stake in Anthropic questioned whether the net effect served American AI leadership or undercut it. Enterprise customers, meanwhile, discovered a harder lesson: a government kill-switch can disable core infrastructure instantly, and force-majeure clauses written before 2026 had never contemplated it.

June 30: the return, and the precedent

On June 30, the Department of Commerce lifted the export controls. Fable 5 returned to global users on July 1 across the Claude platform, Claude.ai, and Claude Code, offered for up to 50% of weekly usage limits through July 7 for paid tiers, with the cloud platforms to follow. Mythos 5 access was restored first to a group of approved US organizations, after Commerce Secretary Howard Lutnick determined appropriate safeguards were in place for trusted partners; the approval for Mythos partners came June 26. In the interim, Anthropic said it had worked with the government and Amazon to review the report and had trained an improved classifier targeting the specific reported bypass.

The lasting significance is structural. This was among the most aggressive uses of export-control power ever applied to a commercially deployed AI model, and it established a template that will outlast the specific dispute: a tiered, authorization-based model of frontier-AI governance, with a trusted-partner layer sitting between full public availability and total suspension. Mythos 5's phased, government-approved return through Glasswing is the first real instance of that structure operating at scale. Whatever one thinks of this particular order, the precedent, that Washington can and will reach into the distribution of a frontier model, is now set.

The 30,000-foot read

I am not going to tell you who was right, because that is a contested political question and reasonable people land in different places on it. What is clear is that a threshold was crossed. For years the debate about government and frontier AI was theoretical, about what the state might one day do. In June 2026 it stopped being theoretical: a model used by hundreds of millions was switched off by directive, negotiated over in Washington, and switched back on nineteen days later under new terms. The capability that made this model valuable, finding and reasoning about software vulnerabilities, is exactly the capability that made a government treat it as a munition.

That tension is not going away, and it is bigger than Anthropic. Every frontier lab now knows its most capable models exist under a legal regime that can pull them from the market on a Friday evening. How labs, governments, and customers build for that reality, redundancy, dual-sourcing, clearer rules, is the work of the next few years. The full arc of this episode, and Anthropic's own account of it, is documented in the company's statement, which is the right primary source for anyone who wants to reason about it directly.

Sources: Anthropic, statement on the suspension directive (June 12) and Redeploying Fable 5 (June 30) (primary: timeline, safeguard detail, Anthropic's position, cross-model testing); CNBC (Lutnick approval, China-timing criticism, restoration terms); Fortune (Anthropic's disagreement, Pentagon "supply chain risk" designation, Sacks criticism, IPO context); Forbes (Sacks account, Jassy alert, jailbreak dispute); MarketScale (19-day framing, tiered-governance template). This is a politically contested topic; the account above presents the government's stated rationale and Anthropic's response side by side rather than endorsing either, and points readers to Anthropic's own statement for further detail. Launch benchmarks are Anthropic's self-reported figures.