Key Takeaways
- On June 12, 2026, the US government applied export controls to Claude Fable 5 and Claude Mythos 5, forcing Anthropic to cut off all foreign nationals — the first time export rules targeted an AI model rather than chips.
- Because the order took effect at once and nationality could not be checked in real time, Anthropic suspended both models worldwide for every user.
- The trigger was a jailbreak: Amazon researchers found a prompt that got Fable 5 past its safeguards to identify software vulnerabilities and, in one case, produce exploit code.
- Anthropic’s review, done with the government and Amazon, found that weaker models — including Opus 4.8, GPT-5.5 and Kimi K2.7 — could identify the same flaws, so the technique exposed no unique capability.
- Anthropic trained a new safety classifier that blocks the reported technique in over 99% of cases, routing flagged requests to Opus 4.8.
- Commerce Department researchers at CAISI tested the old and new safeguards and judged them extraordinarily strong.
- The Commerce Department lifted the controls on June 30, and Fable 5 returned globally on July 1, 2026.
The US government changed course on Claude Fable 5 because the security concern that prompted the restriction did not survive close inspection. A reported method for bypassing the model’s safeguards turned out to expose no capability that cheaper, widely available models lacked, and Anthropic quickly built a classifier that blocked the specific technique. Once government testers confirmed the fix, the export controls were lifted and public access resumed.
The sequence was fast. Anthropic released Fable 5 and Mythos 5 on June 9, 2026. Three days later, on June 12, the Department of Commerce imposed export controls citing national-security authorities and ordered Anthropic to block access for any foreign national, inside or outside the United States, including its own non-citizen staff. With no reliable way to verify nationality instantly, the company shut both models down for everyone. By June 30 the controls were gone, and Fable 5 was back for global users on July 1. Anthropic’s own account is set out in its statement on restored access.
What Fable 5 and Mythos 5 Are
Fable 5 and Mythos 5 share the same underlying model but carry different safeguards. Fable 5 launched with the strongest protections Anthropic had ever applied, aimed at general availability.
Mythos 5 has fewer safeguards and went only to a small set of vetted Project Glasswing partners for defensive cybersecurity. The distinction matters because Mythos 5 can find and exploit software flaws more effectively than any other model and than all but the most skilled human experts, which is precisely why its access is gated. Our guide to how Claude Mythos 5 could aid cybersecurity and biomedicine covers those capabilities in depth, and the earlier preview model is explained in our Claude Mythos guide.
The Trigger: A Jailbreak Found by Amazon
The export directive followed a report in which Amazon researchers found a way to prompt Fable 5 so that it bypassed its safeguards and identified a set of software vulnerabilities. In one instance the model produced code showing how a single vulnerability could be exploited. That finding, once it reached the government, prompted the immediate restriction.
Anthropic spent the following two weeks reviewing the report with the government and Amazon. Its testing reached a clear conclusion: many less capable models could identify the same vulnerabilities, and every model it tested could reproduce the same exploit demonstration, including Claude Haiku 4.5, Sonnet 4.6, several Opus versions, GPT-5.4, GPT-5.5 and Kimi K2.7. The technique did not expose any Mythos-level capability. It touched a borderline case that Fable 5’s cautious safeguards normally block out of an abundance of caution, and the behaviour involved routine defensive security work rather than a novel offensive weapon.
The Fix and the Reversal
Even though the bypass exposed nothing unique, Anthropic moved quickly. Working with the government, it trained an improved safety classifier that targets and blocks the reported behaviour, notifies users when a request is blocked, and sends that request to Opus 4.8 instead. The new classifier stops the specific technique in over 99% of cases, at the cost of flagging more benign coding and debugging requests — a trade-off the company said it would keep refining.
Independent verification sealed the reversal. Researchers at the Department of Commerce’s Center for AI Standards and Innovation tested both the old and new safeguards and agreed they were extraordinarily strong. On June 26 the government approved restoring Mythos 5 for a set of US organisations that defend critical infrastructure. On June 30 the Commerce Department lifted the controls entirely, and Fable 5 returned to Claude.ai, the Claude Platform, Claude Code and Claude Cowork on July 1.
| Date (2026) | Event |
|---|---|
| June 9 | Anthropic releases Claude Fable 5 (general) and Mythos 5 (Glasswing partners). |
| June 12 | Commerce Department applies export controls citing national security; foreign-national access blocked. Both models suspended worldwide. |
| June 12–29 | Anthropic reviews the Amazon jailbreak report with the government; trains a new classifier. |
| June 26 | Government approves restoring Mythos 5 for select US critical-infrastructure organisations. |
| June 30 | Commerce Department lifts the export controls. |
| July 1 | Fable 5 restored globally across Claude products. |
The Bigger Picture
The episode arrived amid tension between Anthropic and the current administration, and the company had earlier taken the Department of Defense to court over a “supply chain risk” label. It also coincided with a June 2 executive order on advancing AI innovation and security, and Anthropic used the resolution to commit to deeper government collaboration: expanded pre-release access for national-security evaluators, faster information sharing on jailbreaks, and a proposed industry framework for scoring jailbreak severity across four criteria — capability gain, breadth, ease of weaponisation and discoverability. Alongside partners including Amazon, Microsoft and Google, it also opened a HackerOne channel for reporting cyber jailbreaks.
For a company that filed to go public days before the controls landed, the speed of the reversal mattered commercially as well as technically. Our coverage of Anthropic’s IPO filing and our Opus model comparison give more context on where the model line stood at the time.
Why the Stance Changed, in One Sentence
The government restricted Fable 5 on the fear that a jailbreak had unlocked dangerous cyber capability, and it lifted the restriction once evidence showed the technique offered no advantage over freely available models and a fresh safeguard reliably closed the gap.
This account is anchored to Anthropic’s official posts and to reporting from late June and early July 2026. It describes a recent government-and-industry matter factually; developments may have continued since, and Anthropic’s statement is the primary reference.
If you are interested in this topic, we suggest you check our articles:
- How Claude Mythos 5 Could Aid Cybersecurity and Biomedicine
- Claude Mythos Guide: Anthropic’s Cybersecurity AI Model Explained
- Claude Opus 4.6 vs 4.7 vs 4.8: Which Model Wins?
- Anthropic Files for IPO: How It Compares to AI Rivals
- xAI vs OpenAI vs Anthropic: Which AI Lab Wins in 2026?
Sources: Anthropic, CNBC, The Hacker News, Al Jazeera
Written by Alius Noreika

