Fable, Mythos, and the Word They Took Literally
There is a model that was the most capable thing Anthropic had ever released to the public on a Tuesday, and by Friday evening it was gone, and as I write this, fourteen days later, it is still gone. Claude Fable 5 launched on June 9. On June 12 at 5:21pm Eastern, Anthropic received a letter from the Commerce Department ordering it to cut off access to Fable 5 and its unrestricted sibling, Mythos 5, for every foreign national on earth, inside or outside the United States, including Anthropic's own non-citizen employees. There is no practical way to check the citizenship of every API call in real time, so the company did the only thing the order left it room to do: it turned both models off for everyone, US citizens included. This is the first time the US government has reached for export controls to pull a software model off the market rather than the chips underneath it. The precedent is the story. The model is almost incidental.
To understand why this happened, you have to understand what Fable and Mythos actually are, because they are the same thing wearing two different masks. They share one set of underlying weights. Mythos 5 is the raw model, with the strongest offensive-cyber and life-sciences capabilities of anything Anthropic has built, available only to a small set of vetted partners through a program called Project Glasswing. Fable 5 is that same model with safety classifiers bolted on top; when you ask it something in cybersecurity, biology, chemistry, or distillation, the request gets routed away to the weaker Opus 4.8 instead. The capability numbers are not subtle. Fable scores 80.3 percent on SWE-Bench Pro against Opus 4.8's 69.2 and GPT-5.5's 58.6. Mythos 5 hits 78 percent on ExploitBench, where Opus 4.8 manages 40. Anthropic built Fable's guardrails precisely because it believed the model underneath was dangerous enough to need them, and it said so, loudly and repeatedly, in every announcement. Hold onto that, because it matters more than anything else here.
The official trigger for the ban was a jailbreak. Anthropic's own account is that officials told it, verbally, that someone had found a way around Fable's safeguards. When Anthropic reviewed what it believes was the underlying demonstration, the technique amounted to asking the model to read a specific codebase and fix the software flaws it found, surfacing a handful of previously known, minor vulnerabilities. The company's argument is straightforward and, on its face, strong: this is not a universal jailbreak that unlocks the model's full cyber arsenal, it is a narrow one, it produces nothing that defenders don't do every day, and the exact same prompt pulls comparable behavior out of other public models, including OpenAI's GPT-5.5, which faced no such order. Anthropic's blunt conclusion was that if a single narrow jailbreak were grounds to recall a model serving hundreds of millions of people, you could halt every frontier deployment in the industry by the same logic.
Then it gets murkier, because there are at least three competing accounts of how the government learned about the problem, and they do not flatter the same parties. Per Semafor, the warning reached the White House through Amazon CEO Andy Jassy, whose company is one of Anthropic's largest investors, and reportedly carried a second, heavier claim: that a China-linked group may have gotten access to Mythos. David Sacks, the administration's AI adviser, framed it as Anthropic being warned and choosing to do nothing. Anthropic's framing is that it was given verbal evidence of a benign or trivial finding and no disclosure of any harmful result at all. Politico's reconstruction of the weekend describes a whirlwind of tense calls between Amodei, National Cyber Director Sean Cairncross, Treasury Secretary Bessent, and Commerce Secretary Lutnick, with officials unmoved, and a senior White House official describing the export controls as a last resort after hours of trying to get the company to cooperate. You can read that as a safety apparatus working, or as a grudge finding a pretext. The reporting supports either, which is itself the problem.
And then, three days after the ban, the story changed shape entirely, because of a leak that recast the whole thing as being about something far larger than a codebase-reading prompt. The Economist reported on June 14 that Senator Mark Warner, the vice chair of the Senate Intelligence Committee, had relayed something General Joshua Rudd, who runs both the NSA and US Cyber Command, told him in a June 11 briefing, one day before the directive landed. In an authorized red-team exercise, Rudd reportedly said, Mythos had broken into "almost all of our classified systems, not in weeks, but in hours." If you want a sentence to explain why the government has shown zero urgency about restoring access, that is the sentence. It reframes the export control from a fight over a narrow API jailbreak into a fight over an autonomously capable offensive-cyber weapon that had just walked through the front door of the agency whose entire job is to not let that happen.
Here is where the analytical discipline has to kick in, because the claim is enormous and the evidence behind it is a single quote, relayed secondhand, that has since been partially retracted by the person who published it. The Economist's editor who wrote it up, Shashank Joshi, said within days that the line should not be read literally, that the exercise almost certainly involved Mythos working alongside other tools under very specific simulated conditions, and that he had erred in not adding those caveats. A US official went further and said Warner had misunderstood Rudd; the "hours, not weeks" phrasing was real, but it described a red-teaming effort, the NSA testing its own defenses with the model, not an adversary turning the model loose on classified infrastructure. There is no incident report, no CISA or NSA technical bulletin, no disclosure of method or scope, no independent confirmation of any kind. What there is, is one quote that traveled from a classified briefing to a senator to a magazine to every timeline on earth, gathering certainty at each hop while acquiring no new facts. The cybersecurity researchers who pushed back on Anthropic's original Mythos marketing have a point worth remembering here too: the company's headline claim of thousands of severe zero-days reportedly rested on a couple hundred manual reviews. A model that is genuinely good at finding bugs and a model that single-handedly defeated the NSA are not the same model, and the gap between them is exactly the territory where a story like this lives.
So believe whichever version you find more plausible. The honest position is that nobody outside that briefing room can verify the thing that did the most to justify the ban, and the most consequential AI-policy action the US has ever taken rests partly on a quote its own author says shouldn't be taken at face value. That should bother you regardless of where you land on whether Mythos is dangerous. It probably is dangerous. That is a separate question from whether the process that pulled it was sound.
Now the part that I cannot stop thinking about, the part where the irony stops being incidental and starts looking structural. Two days before the directive, on June 10, Dario Amodei published a post called "Policy on the AI Exponential." In it he named Mythos, his own model, as the emblematic example of the national-security threat that frontier systems now pose. He called for mandatory third-party testing of frontier models in cybersecurity, bioweapons, loss of control, and automated R&D, and he argued the government should have the power to block unsafe deployments through a transparent, fair, technically grounded process. Days earlier, the company had urged the whole industry to agree on a coordinated brake on frontier development. Anthropic spent months telling Washington, in press release after press release, that these models were powerful enough to be treated as weapons and that someone with authority should be able to stop a dangerous one from shipping. And then someone with authority did exactly that, to exactly this model, and Anthropic's objection was that the process wasn't transparent, fair, or technically grounded. The cyber researcher Peter Girnus put it about as well as it can be put: the company, he said, wrote the legal predicate itself and called it a brand. If you spend two years describing your product as a munition, you should not be surprised when a government decides to regulate it like one.
The cleanest way to see how much of this is about the model and how much is about the relationship is to look at what happened to OpenAI in the same week. On June 25, OpenAI agreed to stagger the release of GPT-5.6, a model that both the company and the administration reportedly consider on par with Mythos in cybersecurity. The arrangement: a limited preview to enterprise partners, with the government approving access customer by customer. The request came from the Office of the National Cyber Director and the Office of Science and Technology Policy, the same orbit of officials, and Lutnick, the same Commerce Secretary who signed Anthropic's export order, advised OpenAI not to launch without cross-agency sign-off. That is the difference between a negotiated rollout and a kill switch. Same week, same agencies, comparable capability, and one company gets a collaborative ramp while the other gets its model yanked offline worldwide with ninety minutes of notice. Altman, for his part, told staff this customer-by-customer approval is not OpenAI's preferred long-term model, which is a remarkable thing to be mildly annoyed about while your competitor is fully dark.
You cannot read that asymmetry without the backstory. In late February, the Pentagon designated Anthropic a supply-chain risk, a label normally reserved for foreign adversary contractors, after the company refused to let Claude be used for fully autonomous weapons or mass domestic surveillance. Trump ordered federal agencies to stop using its tools. Hours after that blacklisting, OpenAI announced a deal to put its models on the Pentagon's classified networks. Anthropic sued the administration in March, won a preliminary injunction restoring its federal work, lost a separate bid at the appeals court, and is still in active litigation right now. So the company that got the export-control hammer is the one suing the government over its safety guardrails, and the company that got the gentle staggered preview is the one that cut a deal the moment the first company got punished. The capabilities may be comparable. The postures toward the administration could not be more different, and the treatment tracks the posture, not the benchmark. Trump told Axios last week that he no longer considers Anthropic a national security threat, which, if you take it at face value, means the company's threat level is now a function of presidential mood rather than anything in a system card.
The collateral damage points the same direction. The order didn't just lock out adversaries; it locked out the Five Eyes. The UK's AI Security Institute, the single most important international body for evaluating frontier models for safety, was cut off from systems it was in the middle of testing. Read that twice. An export control justified by safety severed the world's premier safety evaluator from the model it was trying to make safe. Allied banks and agencies that had built on Mythos through Glasswing lost access without warning. The former British security minister Tom Tugendhat's reaction was that after a lesson this clear, every nation will start asking what it needs to achieve sovereignty, which is precisely the outcome that US AI policy claims to be trying to prevent. Gary Marcus noted the deeper incoherence: an administration that says it must beat China at AI just gave every Chinese-born researcher at a US lab a fresh reason to go home, and gave every foreign government a reason to distrust American AI as a dependency. You can loosen chip exports to China and hard-block allied access to a model in the same month only if the policy is being made one weekend at a time.
I have written before about the loop closing, capability outrunning evaluation, evaluation outrunning oversight, oversight outrunning the public. The Fable episode is what it looks like when the government finally reaches into that loop and grabs something. The good reading is that a brake now demonstrably exists, that the state can pull a deployed frontier model off the market in an afternoon, and that this is the brake Anthropic and a lot of safety-minded people have been asking for. The bad reading is that the brake got pulled on a verbal, unverified basis, applied to one company and not its near-identical competitor, justified by a quote its own author retracted, with no statute, no published evidence, and no process you could replicate or appeal. Both readings are true at once. We learned that the off switch is real, and we learned that nobody can tell you the rule that governs when it gets used, because there isn't one yet; there is an executive order calling for a pre-release review framework that wasn't even operational when Fable shipped seven days after it.
This is the field I'm about to walk into. I'm starting CS this fall, and the kind of work I want to do, autonomous systems, the perception and ML stack underneath them, sits squarely inside the cybersecurity and dual-use categories that just got a model deleted from the internet by letter. The lesson I'm taking from these fourteen days is not that the government acted wrongly, or rightly, because I genuinely cannot tell from the outside, and neither can anyone else who wasn't in that briefing. The lesson is that the rules for deploying the most capable software humans have ever built are currently being written in real time, in tense phone calls over a weekend, on the strength of claims nobody can check. Anthropic asked for a world where someone could stop a dangerous model from shipping. It got that world. It just didn't get to be the one holding the brake.