When the U.S. government suspended foreign access to Anthropic's most powerful AI models on June 12, the order arrived with little public explanation and a verbal warning about a "jailbreak." But the legal and bureaucratic machinery behind that abrupt action had been assembled in plain sight ten days earlier, in an executive order most of the AI industry had praised.

On June 2, 2026, President Trump signed "Promoting Advanced Artificial Intelligence Innovation and Security," an order pitched as a light-touch, innovation-friendly alternative to the prior administration's AI rules. Buried in its Section 3 is the conceptual backbone of what happened to Fable 5 and its sibling Mythos 5: a new government vocabulary for "covered frontier models," a classified process to identify them, and a framework under which developers were expected to hand the government early access before release.

Read in sequence, the order and the ban tell a single story. The EO designed a voluntary pipeline for the government to vet the most capable AI models. When Anthropic launched Fable 5 on June 9 without using that pipeline — which did not yet formally exist — the government produced the cooperation by force.

What Section 3 actually requires

Section 3, titled "Secure Frontier Model Deployment," sets an August 1 deadline. Within 60 days of June 2, the Treasury Secretary, the NSA director (acting through the Secretary of War), and the CISA director (through the Secretary of Homeland Security) must build "a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine the threshold at which an AI model should be designated a 'covered frontier model.'"

Crucially, the order assigns the designation power to one official: "Such a determination shall be made by the Director of NSA." That places the judgment of whether a commercial model is a frontier national-security concern inside the intelligence community, on a classified basis that developers see only "as appropriate."

The same section directs those agencies to "design a voluntary framework" letting developers ask the government whether a model qualifies, and then "provide the Federal Government with access to covered frontier models...for a period of up to 30 days before they plan to release such models to other trusted partners." The order is emphatic that this is not licensing: nothing in it, Section 3(c) states, authorizes "a mandatory governmental licensing, preclearance, or permitting requirement."

A fourth provision matters for enforcement. Section 4 directs the Attorney General to prioritize the computer-fraud statute (18 U.S.C. 1030) and the wire-fraud statute (18 U.S.C. 1343), among others, "against anyone who utilizes AI to illegally access or damage a computer." That language reframes AI cyber capability as an existing-law enforcement target — a legal foundation for treating a model's cyber prowess as a national security matter rather than a novel regulatory question.

How the pieces produced a ban

The timing is the tell. The EO created a 30-day pre-release briefing expectation but gave the agencies until August 1 to actually build the benchmarking process and the framework. Anthropic shipped Fable 5 on June 9 — seven days after the EO, and nearly two months before the machinery to evaluate it was due. There was, technically, no framework to pre-brief under.

Then, according to The Wall Street Journal's account, Amazon CEO Andy Jassy told the administration that Amazon researchers had used a series of prompts to coax Fable 5 into producing information useful for cyberattacks. On June 12, the government issued an export-control directive — Anthropic says it received only verbal notice of a "potential narrow, non-universal jailbreak" — barring access by any foreign national, forcing Anthropic to disable both Fable 5 and Mythos 5 for all customers.

In other words, the outcome the voluntary framework was meant to elicit — government scrutiny of a high-capability model before broad release — was instead extracted after release, through a national-security enforcement action.

Analysts caught the shift in tone. "This sure looks mandatory if there are going to be consequences for not doing what the government says," Daniel Remler, a senior fellow at the Center for a New American Security, said of the directive. Kevin Frazier, an adjunct fellow at the Cato Institute, called the EO's framework "at best, half-built."

Anthropic itself had welcomed the order. CEO Dario Amodei has long argued for exactly this kind of gatekeeping, writing that "Frontier AI models, like airplanes, should be required to go through technical testing and auditing, and their release should be blocked or reversed as a threat to public safety if they do not meet high standards of safety." The company that asked for a safety regime became the first to feel its sharpest edge — before the regime was finished.

Why It Matters

The Fable 5 episode is the first real-world test of how a "voluntary" AI framework behaves when a developer doesn't volunteer. The EO's drafters were careful to disclaim mandatory licensing, but Section 4's enforcement priorities and the government's existing export-control and national-security authorities gave officials a path to compel cooperation anyway. For AI labs, the lesson is that the gap between "voluntary" pre-briefing and de facto requirement may be narrow, and that an NSA classified designation can effectively gate a product's release. It also signals that cyber capability — not bioweapons or disinformation — is the dimension on which Washington is most prepared to act fast.

What to Watch

- August 1, 2026: the statutory deadline for NSA, Treasury, and CISA to deliver the classified benchmarking process and the voluntary framework. Whether those documents formalize the 30-day pre-release access — and what triggers a "covered frontier model" label — will define the rules of the road. - Whether Anthropic regains access for Fable 5 and Mythos 5, and on what terms, will reveal how the government negotiates after an enforcement action rather than a briefing. - Watch for other labs quietly pre-briefing future releases to avoid Anthropic's fate, which would suggest the voluntary framework is working as designed — through deterrence. - Any legal challenge to the directive could test whether national-security authorities can substitute for the licensing power the EO explicitly disavowed.

"This sure looks mandatory if there are going to be consequences for not doing what the government says."
- Daniel Remler, Senior Fellow, Center for a New American Security
60 days
Deadline for covered-model benchmarking
30 days
Pre-release government briefing window
June 2
Date the EO was signed