Skip to main content
AI & Machine Learning

US Orders Anthropic to Curtail AI Model Access

Technology company's office interior with laptop and computer servers.

"We will abruptly disable our most advanced models," Anthropic said, after receiving an order from the U.S. government to suspend access to Claude Fable 5 and Mythos 5 by foreign nationals.

The U.S. order and immediate effects

Anthropic said it received a directive at 5:21 p.m. ET instructing the company to "suspend all access to the models by foreign nationals," whether those users are inside or outside the United States. The company said the order applied specifically to its two newest models, Claude Fable 5 and Mythos 5, and that it would "abruptly disable" them for all users while it complies. Anthropic added that access to its other models would not be affected by the export control directive.

Anthropic's assessment: a narrow jailbreak, known vulnerabilities, and safety classifiers

Anthropic described the government's concern as centered on what it called a "method of bypassing, or 'jailbreaking' Fable 5." The company said it reviewed a demonstration of that technique and found it identified "a small number of previously known, minor vulnerabilities." Anthropic characterized those vulnerabilities as "relatively simple" and said other publicly available models can discover them without requiring a bypass.

To prevent misuse, Anthropic emphasized a layered defense: "strong" guardrails backed by safety classifiers that detect potential misuse, including jailbreak attempts, and prohibit the main model from responding. The company said its cybersecurity classifier is designed to block harmful single-turn requests relating to planning a cyber attack, exploit development, or defense evasion, and that Mythos-class models are particularly skilled at finding and exploiting software vulnerabilities—capabilities the company argues could give attackers a strategic advantage.

Mythos-class capability: converting N-days into N-hours

Anthropic's own Red Team disclosed that the Mythos-class model can transform newly disclosed software vulnerabilities into working exploits in hours, or even minutes in some cases, instead of weeks—"converting N-days into N-hours." In a stark assessment, the Red Team wrote: "A lone operator can now turn a month's worth of patches into working exploits in a single afternoon - for a few thousand dollars and with no specialized expertise." That finding underpinned Anthropic's decision to offer Mythos 5, described by the company as having the "strongest cybersecurity capabilities of any model in the world," only to a vetted group of cyber defenders and critical infrastructure operators.

For Fable 5 specifically, Anthropic says cybersecurity-related queries are routed instead to Claude Opus 4.8, the company's "next capable model," as part of Fable's built-in protections.

Legal and procedural tensions: export control, evidence, and prior disputes

Anthropic told the government it believes there has been a "misunderstanding" and that it's working to restore access as soon as possible. The company said the government has provided only "verbal evidence of a potential narrow, non-universal jailbreak," which Anthropic summarized as essentially asking the model to read a specific codebase and fix any software flaws. Anthropic said it reviewed a report it believes is the basis for the government's directive and "validated that the level of capability displayed there is widely available from other models (including OpenAI's GPT-5.5), and is used every day by the defenders who keep systems safe."

Anthropic argued that discovering a narrow potential jailbreak "shouldn't be the reason for recalling a commercial model that's deployed widely," and urged that any statutory process be "transparent, fair, clear, and grounded in technical facts." The company also noted a separate recent dispute with the U.S. Department of Defense: earlier this year the DoD labeled Anthropic a "supply chain risk," a designation the company has sought to block in two lawsuits it filed.

What this means for cyber defenders, critical infrastructure operators, and policymakers

  • Cyber defenders and vetted critical infrastructure operators: Those groups currently retain access to Mythos-class capabilities, per Anthropic, but the episode highlights how rapidly evolving model capabilities and sudden export-control moves can change operational tools and threat models overnight. They will watch both model availability and classifier performance closely.
  • Enterprise software teams and patch managers: Anthropic's Red Team claim—that frontier models can speed exploit development from weeks to hours—directly challenges traditional patching cadences and staged rollouts. Software teams will have to reassess timelines and threat assumptions against this asserted shift from N-days to N-hours.
  • Policymakers and regulators: The government's order, described by Anthropic as based on a narrow, verbal report, raises questions about the procedural mechanics of export-control directives and the evidentiary standards applied when restricting commercial model access. Anthropic's call for a "transparent, fair, clear, and grounded in technical facts" process frames what it sees as the necessary corrective.

Anthropic's abrupt suspension of Fable 5 and Mythos 5 access for foreign nationals crystallizes a tension: models that can materially accelerate both defensive work and offensive exploitation sit at the center of export-control and legal fights. The company's request to restore access, its claim that similar capabilities exist in other models, and the DoD's earlier "supply chain risk" designation together leave a compact, urgent policy and defensive question—how to balance rapid technical progress, targeted protective measures for critical systems, and transparent, evidence-based controls.

Original story