News

Fable 5 is back: inside the 18 days the US government kept Anthropic's best model offline

For 18 days, the most capable AI model ever released to the public sat behind a government lock. On June 30, the US Commerce Department lifted the export controls it had imposed on Anthropic’s Claude Fable 5 and its restricted sibling Mythos 5, and by July 1 Fable 5 was live again for users worldwide — across claude.ai, the Claude Platform, Claude Code and Claude Cowork.

It’s the first time a frontier AI model has been pulled from the market by government order and then returned. Whatever your read on the merits, the episode just wrote the playbook — and set the precedent — for how Washington handles model releases it considers a national-security question.

Editorial illustration: a three-stage timeline — a glowing model sphere connected to users at launch; the same sphere dimmed behind government bars, its connections severed; then restored to gold with the gates open and an even wider network reconnected.

The timeline

DateWhat happened
Jun 2US executive order creates a voluntary pre-release review path for frontier models
Jun 9Anthropic launches Fable 5 (general access) and Mythos 5 (restricted, Project Glasswing)
Jun 12Export-control directive bars foreign-national access; Anthropic takes both models offline globally
Jun 26Commerce approves restored Mythos 5 access for ~100 US critical-infrastructure organizations
Jun 30Export controls lifted; Anthropic publishes its redeployment plan
Jul 1Fable 5 returns worldwide with an improved safety classifier
Jul 7Included Fable 5 access ends for subscription plans; usage credits take over

What triggered the shutdown

The directive traced back to a cybersecurity finding: Amazon researchers reported a jailbreak that bypassed Fable 5’s safeguards, prompting the model to identify software vulnerabilities and, in at least one case, produce working exploit code. Fable 5 had launched three days earlier as the first Mythos-class model available to the general public — state-of-the-art on nearly every benchmark Anthropic tested, including an 80.3% on SWE-bench Pro that leads GPT-5.5 by 22 points.

On June 12, the government — citing national-security authorities — ordered access suspended for any foreign national, inside or outside the United States, including Anthropic’s own foreign-national employees. Because the order took effect immediately and Anthropic had no way to verify user nationality in real time, the company switched both models off for everyone rather than risk noncompliance.

Anthropic complied but pushed back publicly, arguing the reported technique surfaced only “previously known, minor vulnerabilities” that other publicly available models could also find, and warning that if a narrow jailbreak were grounds for recalling a deployed commercial model, “it would essentially halt all new model deployments for all frontier model providers.”

The deal that brought it back

Commerce Secretary Howard Lutnick framed the June 30 reversal as the product of two weeks of joint review: “we have worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government.” Per Reuters and CoinDesk reporting, Anthropic agreed to:

  • proactively detect and address security risks in its models,
  • coordinate with the US government on protocols, standards and releases for Mythos, Fable and future models,
  • report malicious use it observes.

Anthropic also opened a HackerOne program for jailbreak reports and proposed an industry-wide framework for scoring jailbreak severity, developed with Amazon, Microsoft, Google and other Project Glasswing partners — an attempt to ensure the next dispute is argued over a shared rubric rather than a single demo.

The redeployed Fable 5 ships with an improved safety classifier targeting the reported bypass technique. Anthropic acknowledged a trade-off: the hardened classifier may flag more harmless requests in everyday coding and debugging. Mythos 5 — the same model with fewer safeguards — returned on a narrower track: roughly 100 approved US organizations that operate and defend critical infrastructure, cleared by the government on June 26.

Why it matters

  • A precedent now exists. Export controls — a tool built for physical goods and semiconductors — were applied to a deployed commercial AI model, and the resolution ran through a government review, not a court. The June 2 executive order’s “voluntary” pre-release review now has visible teeth: GPT-5.6’s government-coordinated limited preview, announced June 26, suddenly looks less like caution and more like the new normal.
  • The nationality mechanism is blunt. Because no lab can verify user nationality in real time, a foreign-national restriction is functionally a global shutdown. That asymmetry — one directive, total outage — is now priced into every frontier lab’s deployment risk.
  • Anthropic’s classifier architecture survived its first stress test. The Fable/Mythos split — one model, safeguards as the product boundary — is intact, now with government sign-off and a tightened classifier. Users pay the cost in false positives.
  • The competitive window mattered. For 18 days, the clear benchmark leader was off the market while Claude Sonnet 5 launched and rivals shipped. Regulatory downtime is now a real variable in model selection — worth weighing alongside price and capability in our models directory.

A note on sourcing: the timeline and the terms of the resolution are drawn from Anthropic’s statements and reporting by CoinDesk, Reuters (via Times Now), Infosecurity Magazine and others; the government’s specific national-security rationale beyond the jailbreak finding has not been published in detail.

Sources

← All news