Less than a week after Anthropic unveiled the most capable AI models it has ever built, the U.S. government forced the company to switch them off for nearly everyone on Earth. On June 13, the San Francisco lab disabled global access to its new frontier-class systems, Fable 5 and Mythos 5, to comply with what it described as a federal export-control directive barring any foreign national — inside or outside the United States, including Anthropic's own overseas employees — from using the models. Because nationality is nearly impossible to police user-by-user, the company concluded it had no choice but to pull the plug for everyone.

The order lands at the intersection of two of the year's biggest AI-policy stories: Anthropic's own escalating warnings about the security risks of frontier systems, and the White House's June 2 executive order, "Promoting Advanced Artificial Intelligence Innovation and Security," which reframed advanced AI as a national-security domain governed in part by classified benchmarking and export authorities.

What the government ordered, and why

The mechanism, according to reporting from SiliconANGLE and others, was a sweeping U.S. Commerce Department export-control order citing urgent security concerns. It explicitly barred "foreign nationals" — including citizens of allied nations — from accessing Fable 5 and Mythos 5. Anthropic confirmed the substance in a public statement, saying the government "has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees."

The trigger, by most accounts, was a jailbreak. Anthropic said officials gave it only "verbal evidence of a potential narrow, non-universal jailbreak." Reporting points to two parallel red-team findings: the U.K.'s AI Safety Institute said it had made "substantial progress" toward a universal jailbreak of Fable 5, with researcher Xander Davies writing that "within a few hours of access, we developed a jailbreak that extracted malicious responses to single-turn question-answering." Separately, The Wall Street Journal reported that Amazon — an Anthropic investor with model access — alarmed officials after CEO Andy Jassy personally called Treasury Secretary Scott Bessent to relay that company researchers had used Fable 5 to obtain "information that could be used in cyberattacks." Semafor reported the directive was also tied to suspicions that a China-linked group had accessed the new model, though that claim has not been independently confirmed.

David Sacks, co-chair of the President's Council of Advisors on Science and Technology, said on X that the White House had asked Anthropic CEO Dario Amodei last week to patch or de-deploy Fable 5 and that he declined. The Pentagon's chief information officer, Kirsten Davies, framed the stakes bluntly: "Some things are simply more important than revenue cycles, clickbait, and pre-IPO valuation. America First. Always."

Anthropic pushes back

Anthropic disputes both the severity of the flaw and the proportionality of the response. It characterized the underlying problem as a "misunderstanding" by national-security authorities and argued that recalling a model "deployed to hundreds of millions of people" over "a narrow potential jailbreak" was unwarranted. The company also noted that comparable vulnerabilities exist in rival systems, including OpenAI's GPT-5.5, and warned that the standard being applied would "essentially halt all new model deployments" across the frontier AI industry. It said it was working to restore access "as soon as possible."

The clash deepens an already adversarial relationship. Anthropic is suing the federal government after the Pentagon placed it on a supply-chain blacklist over the company's refusal to let the U.S. military use its models for domestic surveillance and fully autonomous weapons. The timing is also financially fraught: the order arrived days after Anthropic filed confidentially for an IPO reportedly chasing a roughly $1 trillion valuation, and the loss of foreign enterprise revenue could complicate that path.

The national-security turn for frontier AI

What makes this episode consequential is less the single jailbreak than the legal architecture now visible behind it. The June 2 executive order directed agencies to build a classified benchmarking process to designate "covered frontier models" and assess their "advanced cyber capabilities," and to create a voluntary channel for developers to give the government early access — up to 30 days before release. Notably, that order explicitly disavowed any mandatory "licensing, preclearance, or permitting requirement." Yet within two weeks, the government had used export-control authority to achieve something close to a hard off-switch on a commercial model — a reminder that export law can deliver outcomes a domestic licensing regime was designed to avoid.

That is the precedent worth weighing. Treating a general-purpose chatbot like a controlled munition extends the logic Washington has applied to advanced chips from Nvidia and AMD into the software layer itself. Supporters argue that a model capable of accelerating sophisticated cyberattacks against banks and critical infrastructure is a legitimate dual-use concern, and that allies benefit when the most dangerous capabilities are contained. Critics counter that "foreign national" is an unworkable and easily circumvented criterion, and that the move risks accelerating exactly the outcome the U.S. fears — a global pivot toward non-American AI.

Europe reacted sharply. European Commission spokesperson Thomas Regnier said the bloc was assessing the "practical consequences," adding that "contingency measures taken in this light should not be discriminatory against partners." French politicians Jordan Bardella and Bruno Retailleau called the ban a "wake-up call," urging support for homegrown firms like Mistral so that essential infrastructure "cannot be switched off on a whim by Washington."

What to watch next

Three things will determine how large this story becomes. First, restoration: whether Anthropic and the government negotiate a fix — a patch, a carve-out for allied users, or a narrower control — and how quickly. Second, scope creep: whether Commerce applies the same export logic to OpenAI, Google, and other labs, or whether Anthropic's existing feud with the administration made it a singular target. Third, the IPO and the allies. A prolonged ban would test investor appetite for a company whose flagship products can be disabled by federal order, and could harden European and Asian resolve to build sovereign alternatives. For now, the world's most powerful publicly available models are, for most of the world, unavailable — and the rules that put them off-limits are still being written.

"We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people."
— Anthropic, company statement