10DispatchAIPolicyIndustry

In June the US government did something it had never done: ordered a deployed AI model taken offline. What actually happened — and what July 12 doesn't mean.

By Tomiwa FolorunsoPublished JULY 30, 2026Read 8 min

At 5:21pm Eastern on June 12 — the same day, as it happens, that the SpaceX IPO was minting the first trillionaire — a letter from Commerce Secretary Howard Lutnick arrived at Anthropic. It cited national security authorities and directed the company to suspend all access to its newest models, Claude Fable 5 and Claude Mythos 5, by any foreign national, anywhere in the world, including Anthropic's own foreign-national employees.

There is no practical way to verify the citizenship of a few hundred million users in real time. So within about ninety minutes, Anthropic switched both models off for everyone on Earth.

I felt this one personally, because I am the foreign national the letter was about. I had spent three days routing my hardest work through Fable 5 — the first public model of the Mythos class, noticeably past Opus — and then it was simply gone from the picker, everywhere, for reasons a government on another continent declined to fully specify. It was, by most accounts, the first time the US government has ever ordered a commercially deployed AI model recalled.

What actually happened

The models launched June 9. Fable 5 and Mythos 5 share the same underlying model; Fable ships with heavy safeguards for general use, while Mythos, with fewer restrictions, went only to vetted partners in a defensive-security program called Glasswing. The class is genuinely strong at one dual-use thing in particular: finding software vulnerabilities. Mozilla reportedly used Mythos to find over 270 Firefox flaws. That capability defends systems in one pair of hands and attacks them in another.

Three days after launch, per multiple reports, researchers at Amazon found a way of prompting Fable 5 past its safeguards — asking it to read a codebase and identify flaws, in one case producing demonstration exploit code. Amazon's CEO reportedly raised it directly with senior officials. There were also reports that the White House suspected a China-linked group had accessed Mythos, raising fears the model could be distilled by an adversary. Days later, the directive landed. A White House adviser claimed Anthropic had refused to fix the issue; Anthropic disputed that characterization entirely.

The detail that makes the story rich: Amazon is Anthropic's largest investor and cloud provider. The reported instigator of the shutdown was the patron.

The rebuttal, and why it matters

Anthropic complied and objected in the same breath. Its position: the jailbreak was narrow and non-universal, the vulnerabilities it surfaced were minor and previously known, and — this is the part that should have gotten more attention — its own testing confirmed that other available models, including OpenAI's GPT-5.5 and China's Kimi K2.7, could find the same flaws. The capability that triggered the recall was already on the open market, and in the Chinese case, beyond any American directive's reach.

Sit with that. A US company's model was switched off worldwide for a capability its American competitor kept selling that same afternoon, and that a Chinese open-weight model offers to anyone with a download link. Whatever this was, it was not containment.

If the standard is that a demonstrated narrow jailbreak justifies a recall, Anthropic argued, then no frontier model in the industry could legally remain deployed. Nobody in government contradicted the logic. They just kept the order in place.

The backdrop matters too. Anthropic and the administration had been fighting all year — the Pentagon designated the company a supply-chain risk in March after it sued over surveillance and autonomous-weapons assurances. The company that had asked for the most guardrails got the guardrails applied to it first. There is a lesson in there that every lab has certainly absorbed, and it is probably not the lesson regulators intended to teach.

How it ended — and what July 12 is actually about

The government cleared the models on June 30, eighteen days after the shutdown; Lutnick withdrew the export-control requirement, Mythos returned to approved US critical-infrastructure organizations, and Fable came back to the public on July 1. Anthropic shipped hardened safeguards and a jailbreak bounty program alongside it.

Then came a second cliff that people keep confusing with the first. Fable 5 returned inside paid subscriptions only through a limited window — first July 7, then extended to July 12 — after which the model moves to usage-credit billing at ten dollars per million input tokens and fifty per million output. So, to answer the question directly: the public did not lose Fable after July 12. The government question was settled June 30. July 12 was a pricing event, not a policy one — Anthropic rationing a model whose demand outruns its data centers, with a stated intention to fold it back into subscriptions when capacity allows. The ban made headlines; the invoice is what most users will actually remember.

The precedent

Here is the part I keep turning over. A researcher put it as the only question that matters: does the US government now need to approve every frontier model release? Because the aftermath suggests the industry has already answered yes on its own. OpenAI rolled out its next release to a small circle of trusted partners first, under visible government pressure. Voluntary pre-clearance, adopted preemptively, without a statute — which means without transparency, without appeal, and without any definition of what triggers a recall beyond a phone call to the right official.

Anthropic said it plainly in its own statement: it believes government should be able to block unsafe deployments through a process that is transparent, fair, and grounded in technical facts, and that this action was none of those. Both halves of that sentence are the story. The most safety-forward lab in the industry endorsed the power and condemned the process. I think they are right on both counts, and I think the gap between the two is where the next five years of AI policy will be fought.

From Lagos, one line of that letter stays with me: any foreign national. Not adversaries. Not sanctioned states. Everyone who is not American — which is to say, almost everyone the technology is supposed to be for. For eighteen days, the most capable reasoning system available to the public was a domestic good. It came back. The category it created did not go away.

— Filed under
AIPolicyIndustry