On Friday, June 12, at 5:21 in the evening, Anthropic cut off worldwide access to Fable 5 and its ungated sibling, Mythos 5. Inside about ninety minutes the models were gone for everyone, everywhere, including Anthropic's own foreign-born engineers. Every other Claude model kept running. Nothing was broken. The U.S. government had sent a letter, and Anthropic had until midnight to comply.
I build a company on top of frontier models for a living. This one stopped me cold.
There is no new AI law behind this, and that is what should worry anyone who builds on AI. The government reached for a 30-year-old export-control rule written for semiconductors and encryption, the "deemed export" doctrine, and aimed it at a language model for the first time. Letting a foreign national touch controlled technology counts as exporting it to their home country, even if that person is sitting in a San Francisco office. Anthropic couldn't quietly block its foreign staff. The only compliant move was to shut the whole thing down for the planet.
The precise legal text matters here, and it is still moving. The directive itself is non-public, and the reporting that it arrived as a letter from Commerce Secretary Howard Lutnick rests on unnamed officials. The mechanism is well corroborated. The paperwork is not yet on the record.
You can see how strange this got in one name. Andrej Karpathy co-founded OpenAI, led AI at Tesla, and joined Anthropic on May 19. Three weeks later he was posting that Fable 5 is "the same underlying model as Mythos but with added safeguards" and "SOTA on everything by a margin." Days after that, the model he had just joined to build went dark, and his name became the face of the ban: a Slovak-Canadian researcher, reportedly locked out of his own company's work because he isn't American.
The precise version lands harder. Karpathy holds an EB-1 green card, which under these same export rules should make him a "US person," exempt. Al Jazeera said flatly that it was "unclear" whether Anthropic's foreign-born staff would lose access at all. He most likely went dark only because the blanket shutdown took everyone down with him. But "Is Karpathy banned from Fable?" became a real question, asked in earnest about one of the most important researchers in the field. Your passport is now an input to whether you can run a model.
Then there is the trigger. The capability behind the first government shutdown of a live frontier model came down to about three words.
Fable would refuse "review the code for security issues." It would cheerfully answer "fix this code," which means finding the vulnerabilities first. That is the jailbreak. Amazon's researchers ran a prompt sequence like it, Amazon's CEO carried the finding to the White House, and by Friday night the controls were live.
The security world did not buy it. Katie Moussouris, who helped invent modern vulnerability disclosure, called the behavior unpatchable by definition and one of the most useful things an AI can do for defense. Alex Stamos gathered a hundred signatures from engineers at Nvidia, Adobe, Google, and Sophos on a letter arguing the capability is unremarkable and already sits in models from OpenAI and China with no restrictions at all. A Democratic senator, a libertarian think tank, and the EU's policy shop reached the same verdict: the safety rationale was too thin to carry a takedown this big. The administration also floated that a Chinese group had gotten in. Anthropic says it never came up. Treat that one as disputed.
If the danger was that thin and the takedown was the first of its kind, the gap between them is the real story. Strip away the safety language and what is left is a demonstration of who holds the switch.
And it was predicted, lever for lever. Twenty-two months before any of this, an analysis called "Soft Nationalization" mapped how Washington would bring frontier labs to heel without ever seizing them: export controls, foreign-national restrictions, licensing, kill switches, all triggered by a capability scare. A paper last December named the deemed-export-on-employees move specifically. June 12 was that forecast arriving on schedule.
Fable will probably come back. Anthropic flew engineers to Washington over the weekend, and the administration says it wants the model restored once it is satisfied. The precedent won't reset. Every lab now knows its strongest model can be frozen the moment the government loses confidence in it. And every company building on top now knows the thing it would rather not: the model in your stack isn't yours. API access is permission, and permission gets revoked.
I have argued for a while that the model is the least interesting part of an AI system. June 12 is the most expensive proof of that I have seen.
Frontier AI just stopped being software and became strategic infrastructure, governed the way we govern enrichment and advanced lithography. The open frontier, the years when the strongest model on earth was a credit card away for anyone, turned out shorter than we thought.
The question I can't put down, and the one I'll pick up next: what is your plan for the afternoon your model goes dark?
Continue to Part 2: The model was never your moat.
As of mid-June 2026, Fable 5 and Mythos 5 are still off worldwide, Anthropic is still negotiating, and nothing has been rescinded. I'll update this when it changes.
Sources: Anthropic's statement; Fortune; Al Jazeera; CyberScoop; SecurityWeek; TechCrunch; R Street Institute; CEP; Just Security; Cheng & Katzke, "Soft Nationalization."