This article is compiled and organized by BlockWeeks.
In the conflict with Anthropic, Washington actually holds veto power over which AI models American citizens can use. Galaxy Research believes this is a wrong decision and the government should change course.
At 5:21 PM Eastern Time on Friday, June 12, the Department of Commerce issued an export control directive to Anthropic, requiring it to cut off Fable 5 and Mythos 5 services to all foreigners globally, including non-citizen employees within the company. The government claimed that someone had discovered a method to bypass Fable 5's security protections and access the cybersecurity capabilities of the underlying Mythos model. The AI company could not segment users by nationality within the government's required timeline, so it immediately shut down both models within hours, globally. Other Claude models remained online. But two of the most powerful large language models in history disappeared due to a mere private letter from the government—no court order, no public document, and no disclosure of any findings. Last Wednesday, Reddit users pointed out that Fable 5 had been added to the AWS Bedrock catalog, and the cloud service seemed to be restored. But regardless, this incident poses significant risks to AI, innovation, and the U.S. market.
The U.S. government has effectively declared that it can arbitrarily withdraw commercial models from the market through administrative action. Although this mechanism is export control, its market effect is a recall. The federal government has crossed the Rubicon of AI, shifting from rule-making to having discretionary power over which models enter the public market and when. Establishing such power usually does not self-restrict: if the government does not change direction, the next directive may be issued even more easily than this one.
The only external expert who read the underlying research, Katie Moussouris (Luta Security), described the alleged jailbreak attempt in simple terms. Amazon researchers provided the model with open-source code containing known and implanted vulnerabilities and asked them to review the security issues. The model refused. The researchers then asked the model to fix the code, and the model did so.
Moussouris called this request a defensive prompt, not a bypass, and said it was the most valuable thing AI can do for security teams. As far as she knows, the most powerful cyber defense model on the market was brought down by three words—"fix this code".
The Department of Commerce did not issue the directive to Anthropic or its underlying rationale. It was not published on the department's website, the Federal Register, or anywhere else. The directive was conveyed as a private letter from the department's Bureau of Industry and Security, which also did not make it public. The authority on which the Commerce Department relied is also not entirely clear. The Center for Strategic and International Studies (CSIS) suggested that the department may have relied on the Export Control Reform Act of 2018 (ECRA), using so-called "information-based" authority to privately inform companies that a license is required. Such requirements are enforced through the Export Administration Regulations (EAR). However, there is no regulatory framework within the EAR that supports this statutory authority, so it has never been used as a basis for control, and the Commerce Department has not issued regulations to implement this power.
The standard implied by the government cannot withstand the above reality. If deployment requires ensuring that there is no method to induce dangerous capabilities, then this standard itself is unachievable. Anthropic's own engineers stated that negative certification is impossible, and their own engineers cannot prove it for anyone. According to Anthropic's logic, applying this standard to the entire industry would completely halt the deployment of frontier AI models. This is an impossible threshold, not a safety threshold—it is just a discretionary veto power wearing a white coat.
Suppose Anthropic wanted to satisfy the literal meaning of the directive—excluding foreigners while serving Americans—this could only be achieved through full identity verification of every user. Anthropic could implement a full Know Your Customer (KYC) registration process, requiring proof of citizenship and residency, just like opening a brokerage account. With this, Anthropic could restrict access by nationality (although its own employees might still be locked out). But without this, it cannot prevent "foreign" people...
Reportedly, the U.S. government does have reason to worry. Senate testimony that emerged in late June (conveyed by Sen. Mark Warner (D-VA) and attributed to NSA Director Joshua Rudd) described Mythos breaking into almost all of the intelligence community's classified systems within hours during an authorized red team exercise (although The Economist's reporter slightly refuted the report). Mythos was the first model to pass the UK AI Safety Institute's cybersecurity test environment. This is a serious capability and an important data point. It calls for a serious process, not a letter on a Friday night without accompanying findings.
Furthermore, Mythos was supposed to be limited to vetted partners. The models taken offline were Fable (consumer version), whose safeguards routed sensitive cyber and biological requests to the older Opus 4.8. The global recall of a protected product, while the truly dangerous version was not public in the first place, reflects a process that confuses capability with deployment.






