AI Ban: Jailbreak Trigger, Pentagon Fight, and Partial Restoration

The Anthropic AI export ban was a Commerce Department directive issued on June 12, 2026, that forced Anthropic to cut off access to its two most powerful models, Fable 5 and Mythos 5, for every foreign national worldwide. The order cited national security authorities and a reported jailbreak of Fable 5’s safety guardrails. Because individually validated export licenses would have been required to keep any foreign user online, Anthropic disabled both models for everyone rather than try to screen users in real time. Two weeks later, the government allowed Mythos 5 back for roughly 100 trusted partners; Fable 5, the public-facing model, stayed dark.

What the Directive Required

Commerce Secretary Howard Lutnick issued the directive on Friday, June 12, 2026. It subjected Fable 5 and Mythos 5 to export control rules and told Anthropic to suspend access for any foreign national, whether located inside or outside the United States, and including Anthropic’s own non-citizen employees. The only path to keep a foreign user connected was an individually validated export license per user.

The day moved in hours, not weeks. According to Axios, Anthropic received a government notification at roughly 1:00 p.m. ET giving the company 90 minutes to take the models down over a national security threat. The formal letter arrived at 5:30 p.m. ET. By 10:00 p.m. ET, users had lost access to Fable.1Axios. Anthropic Amazon White House Anthropic’s other models, including Claude Opus 4.8, were not affected.2Fortune. Anthropic Disables Fable Mythos Export Controls National Security Threat

Fable 5 was Anthropic’s public-facing model, built with restrictions that were supposed to block access to the deeper cybersecurity capabilities of Mythos 5, the underlying model intended only for government agencies and select corporate partners. The government’s concern was that the wall between the two had been breached.

The Jailbreak That Triggered the Ban

The trigger came from Amazon. On the evening of June 11, 2026, Amazon CEO Andy Jassy raised concerns about the Mythos-class model with senior administration officials. Amazon researchers had used a series of prompts to bypass Fable 5’s guardrails and get the model to provide information about cyberattacks that was supposed to be restricted.3Fortune. How a Warning From Amazon Led the White House to Shut Down Anthropic’s Mythos Model Whether Amazon ran that testing on its own or at the White House’s request is unclear, though an unnamed source told Politico that the government had asked Amazon for feedback on the model.

White House AI adviser David Sacks called the finding a “jailbreak in Fable 5’s guardrails.” Anthropic CEO Dario Amodei pushed back, describing the bypass as “narrow” rather than a full jailbreak. Katie Moussouris, CEO of Luta Security and one of the cybersecurity experts who reviewed the research, said the method involved asking the model questions “normal defenders would ask AI” — specifically, requests to analyze codebases and fix software flaws.1Axios. Anthropic Amazon White House

The UK government’s AI Security Institute separately evaluated Fable 5 and found it could exploit defenses and systems 73% of the time. Gina Neff, a professor of responsible AI at Queen Mary University London, called that a “step change in capability in cyber security.”4BBC. Anthropic Suspends AI Tools After US Government Order

How Anthropic Responded

Anthropic complied and objected at the same time. In a June 12 statement, the company said it was “removing access to Fable 5 and Mythos 5 for all users” and called the situation “a misunderstanding.”5Anthropic. Fable Mythos Access

The company’s arguments were pointed. It said the government’s letter “did not provide specific details” about the national security concerns and that Anthropic had received only “verbal evidence of a potential narrow, non-universal jailbreak.” Anthropic argued that the cited capability — reviewing code and correcting software errors — was “widely available from other models,” including OpenAI’s GPT-5.5, and that it was a standard defensive tool rather than a novel offensive threat.5Anthropic. Fable Mythos Access

Anthropic also pointed to thousands of hours of pre-launch red-teaming with the U.S. government, the UK AI Security Institute, and third-party organizations. Its “defense in depth” approach relied on making jailbreaks narrow and expensive, paired with mandatory 30-day customer data retention to enable monitoring. The company conceded the government has authority to block unsafe deployments, but said any such action should follow “a statutory process that is transparent, fair, clear, and grounded in technical facts.” In Anthropic’s view, this action did not.5Anthropic. Fable Mythos Access

The Partial Restoration on June 26

Two weeks after the shutdown, Commerce partially relented. On June 26, 2026, Lutnick sent a letter to Anthropic co-founder Tom Brown granting permission to release Mythos 5 to roughly 100 companies and federal agencies. Lutnick said “appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model.”6CNBC. US Government Anthropic Claude Mythos 5 AI

Fable 5 was not restored. As of late June 2026, the public-facing model remained unavailable to all users.

The Pentagon Fight Behind the Ban

The export directive did not appear out of nowhere. It followed months of open conflict between the administration and Anthropic over how the military could use the company’s technology.

In 2025, Anthropic signed a military contract worth up to $200 million that barred its tools from being used for mass surveillance of Americans or to power fully autonomous weapons. In January 2026, the Pentagon demanded unrestricted use, and Anthropic refused. Amodei said the company “cannot in good conscience accede” to those demands, arguing current frontier models were not reliable enough for autonomous weapons and that mass domestic surveillance violated fundamental rights.7Federal News Network. Anthropic Refuses to Bend to Pentagon on AI Safeguards as Dispute Nears Deadline

On February 27, 2026, President Trump ordered all federal agencies to stop using Anthropic technology. The same day, Defense Secretary Pete Hegseth designated Anthropic a “supply chain risk to national security” — the first time a domestic American company had received such a designation. The Pentagon called Anthropic’s position a “master class in arrogance and betrayal” and accused it of putting “Silicon Valley ideology above American lives.”8NPR. Trump Anthropic Pentagon OpenAI AI Weapons Ban

Anthropic sued in the U.S. District Court for the Northern District of California. On March 26, 2026, Judge Rita F. Lin granted a preliminary injunction blocking the designation and related directives. The court found Anthropic was “likely to succeed” on its First Amendment, Fifth Amendment, and Administrative Procedure Act claims, concluding that the government’s actions were not motivated by genuine national security concerns but were intended to punish the company. Judge Lin wrote that “punishing Anthropic for bringing public scrutiny to the government’s contracting position is classic illegal First Amendment retaliation.”9Terms.law. Trump AI Policy10Electronic Frontier Foundation. Anthropic DoD Conflict: Privacy Protections Shouldn’t Depend on Decisions of a Few Powerful

The government appealed. By June 2026, the case had reached the D.C. Circuit. After Hegseth denied Anthropic’s request for reconsideration on June 3, an appellate panel including two Trump appointees heard oral arguments. The judges signaled they might uphold broad executive authority to designate domestic companies as supply chain risks but suggested that follow-on directives barring use of specific products could remain open to legal challenge.11Politico. Hegseth Anthropic Designation Supply Chain Risk

That history is why several lawmakers questioned the timing of the export ban. Senator Mark Warner, chair of the Intelligence Committee, said the administration had a running “quarrel” with Anthropic and asked whether the export action was driven by security analysis or politics. Senator Angus King cited the administration’s “otherwise announced antipathy” toward the company and called the ban “pretty extreme.”12CyberScoop. Congress Reacts Anthropic AI Export Controls

Congressional Reaction

On June 18, 2026, a bipartisan group of lawmakers — Representatives Sam Liccardo (D-CA), Jay Obernolte (R-CA), Ted Lieu (D-CA), and Scott Franklin (R-FL) — sent a letter to Lutnick asking for details on the legal authorities, technical evaluations, and review process behind the decision. They wrote that the action set a “significant new precedent for frontier AI regulation” with broad implications for “developers, researchers, users, and investors throughout the AI sector.”13Sam Liccardo. Bipartisan Members of Congress Seek Transparency on Frontier AI Export Controls

Representative Bennie Thompson, the ranking Democrat on the House Homeland Security Committee, called the order evidence of an “ad hoc approach” in which political appointees dictate AI regulation. Representative Andrew Garbarino, the committee’s Republican chair, split the difference: he agreed the administration “is right to treat advanced AI cyber capabilities as a national security issue” but warned the response must not “unintentionally disadvantage American companies, allied partners, or critical infrastructure defenders.”12CyberScoop. Congress Reacts Anthropic AI Export Controls

The Cybersecurity Industry Objected

The ban drew a sharp response from cybersecurity professionals. By June 15, 2026, 76 experts had signed an open letter hosted at freefable.org calling for the restrictions to be lifted. Signatories included Alex Stamos, former Facebook chief of security; Casey Ellis, founder of Bugcrowd; and Jon Callas, a cryptographer and former Apple security manager. The list later grew past 100, with executives from companies including Adobe and Nvidia joining.14TechCrunch. Cybersecurity Vets Protest Dangerous US Government Ban on Anthropic’s Most Powerful Models15Yahoo News. Cybersecurity Executives Urge Trump Administration

Their core argument: pulling the best defensive tools away from cybersecurity professionals while adversaries advanced was itself a security risk. The signatories said the jailbreak method the government cited involved standard defensive tasks — analyzing code and fixing known vulnerabilities — and that those capabilities were already available on other models, including OpenAI’s GPT-5.5, Anthropic’s own Claude Opus 4.8, and the Chinese model Kimi 2.7. The letter said Chinese AI models were “only months behind the best American models,” making it counterproductive to hobble American defenders.14TechCrunch. Cybersecurity Vets Protest Dangerous US Government Ban on Anthropic’s Most Powerful Models

The International Reaction

The ban landed hardest in Europe. The European Commission had already been moving to reduce dependence on American technology providers, and the shutdown accelerated that work.

On June 3, 2026 — nine days before the Anthropic ban but in the same policy climate — the Commission announced the “European Technological Sovereignty Package.” Its centerpiece was the proposed Cloud and AI Development Act, which would create four tiered “assurance levels” for public-body procurement of cloud and AI services, graded by where data is stored, who controls the corporate entity, and how exposed the software supply chain is to non-EU jurisdictions.16European Commission. Strengthening Europe’s Tech Sovereignty

At the highest levels, providers would need to demonstrate EU ownership and control, and US-incorporated companies would likely need joint ventures with EU partners to qualify. The Commission acknowledged that, because of the U.S. CLOUD Act, major American cloud providers might find it “very difficult” to satisfy the top two tiers without significant restructuring.17William Fry. EU’s Data Sovereignty Response to US AI Bans

Canada also released its “National Artificial Intelligence Strategy: AI for All” during this period. The Commission described the Anthropic shutdown as a case study in the risks of relying on foreign-controlled AI providers.18IAPP. The Global Implications of the White House’s Export Controls on Anthropic

What It Means for AI Customers and Developers

For enterprise customers, the practical takeaway is that a commercially deployed American AI model can now disappear from the market within hours on national security grounds, with no advance warning to users. Legal experts at Baker McKenzie have described the Anthropic episode as part of a broader trend of geopolitical risk around AI, and have recommended that companies fold the possible “unavailability of AI models” into business continuity planning — a suggestion that would have seemed far-fetched for a domestic American software product a year earlier.18IAPP. The Global Implications of the White House’s Export Controls on Anthropic

For developers, the ban established a precedent that Commerce Department export control authority can reach a deployed AI model, not just chips or training hardware. The restoration of Mythos 5 to a small set of trusted partners, with Fable 5 still offline, signals that the government is prepared to draw the line between “gated” and “public” versions of the same model family and to keep the public version off the market indefinitely when it decides safety guardrails are insufficient.

For users outside the United States, the ban is a reminder that access to American frontier models is now tied to their nationality in a way it was not before. The license requirement written into the June 12 directive applied to foreign nationals regardless of where they physically sat, including foreign employees of Anthropic itself.

As of late June 2026, the shape of the conflict remained unsettled. The Pentagon’s separate designation of Anthropic as a supply chain risk was tied up in the D.C. Circuit. Fable 5 had not returned. And the questions Congress asked in its June 18 letter — about what legal authority, what technical evaluation, and what process produced a same-day shutdown of a commercial AI product — had not been publicly answered.