Leadership3 publishers3 min readPublished
A Friday letter from Commerce turned frontier-model routing into an export-control problem
Commerce told Anthropic on June 12 that any foreign national, anywhere, needs a BIS license to use Fable 5 or Mythos 5. Anthropic disabled both models for every customer to comply, and the letter has not been made public.
The Board Room · Leadership desk

What happened
- Commerce wrote to Anthropic late on Friday, June 12, requiring a BIS license for any foreign person inside or outside the United States to access Fable 5 or Mythos 5, including Anthropic's own foreign national employees.
- Anthropic disabled both models for every customer to comply, and said its other models, including Claude Opus 4.8, remain available.
- Anthropic said it reviewed a demonstration of the jailbreak behind the government's concern and found it identified a small number of previously known, minor vulnerabilities.
- The National Law Review calls this the first known US use of export control authorities to regulate a particular frontier AI model on a national security basis.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- exposure A customer whose own staff are all US persons still lost the service, so the exposure ran through the vendor's compliance decision.
- precedent The obligation runs past Fable 5's fate; by the National Law Review's reading it attaches to adopting any future frontier model a regulator decides raises national security concerns.
- contradiction With the case made verbally and Anthropic saying it has no detailed written support for the government's position, there is no shared threshold for when a jailbreak justifies pulling a deployed model.
- cost The interruption lands on a product Anthropic says was deployed to hundreds of millions of people, and the remediation work sits with the companies that integrated it.
The controlled item is access. In practice that rarely means a person typing into a chat window. According to the National Law Review, compliance here cannot stop at direct logins: API calls, embedded internal tools, autonomous agents and any system that routes prompts or code to a controlled model are in scope. A deemed export can occur if foreign national employees, contractors or affiliates reach the model indirectly [9]. The two product names also point at one system. Anthropic has said Fable 5 is a Mythos-class model released broadly with safeguards, and that Mythos 5 is the same underlying model with certain safeguards lifted and narrower distribution [19]. Anthropic made no attempt to sort its user base by nationality; it switched both models off for everyone [10].
Which authority Commerce used remains unknown, and the letter has not been made public [5]. CSIS sets out the limits. Under the Export Administration Regulations, a worldwide "is informed" license requirement can currently be issued for weapons of mass destruction activities, or for US persons supporting chemical or biological weapons work. It can also be issued for exports to a party involved in activities contrary to US national security or foreign policy interests [11]. ECRA separately directs Commerce to control emerging and foundational technologies, and the "is informed" route there is not limited by country scope. But CSIS writes that this authority has not been implemented by a regulation as ECRA requires [12]. A US official confirmed that the Commerce Department had issued an export control directive suspending access to the models for foreign nationals [18].
Anthropic and the government describe different demonstrations. Anthropic said the government had given it only verbal evidence of a potential narrow, non-universal jailbreak, "which essentially consists of asking the model to read a specific codebase and fix any software flaws" [13]. The company said it validated that the level of capability displayed is widely available from other models, including OpenAI's GPT-5.5, and is used every day by the defenders who keep systems safe [14]. CSIS, citing media reports, says the White House asked other companies for feedback on Fable 5's safety and that Amazon researchers identified methods that could bypass the guardrails [21]. Anthropic said it disagreed that a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people [20]. "If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers," the company said [15].
For anyone running these models in production, the live question is version pinning. Tracking a vendor's newest release buys capability on day one. It also puts the system in the group a single letter can stop at short notice. Anthropic said it received the directive at 5:21pm ET, and that the letter did not provide specific details of its national security concern [16]. Staying on an older release costs capability. The National Law Review suggests companies identify the integrations that call Fable 5 or Mythos 5 and consider disabling, rerouting or otherwise remediating them unless and until lawful access is confirmed [23].
What to watch
- Whether BIS issues a regulation implementing ECRA's emerging and foundational technology controls, which would move this from a letter to one company to a published rule.
- Whether Commerce grants a license or withdraws the directive, and whether Fable 5 returns with access segmented by nationality.
- Whether a comparable directive reaches a second provider's frontier model.