Fables and Fumbles: Why Anthropic just switched off its best AI model
One week the company was being attacked for being too careful. Days later, its own government forced it to be more careful still. Here is the throughline, for anyone who has found the headlines confusing.
If you have been half-watching the news about Anthropic this past week and come away baffled, that is fair. On the evening of Friday 12 June, the company behind the Claude chatbot abruptly turned off its two most powerful AI models for every customer on the planet. Days earlier it had been taking a public beating for the opposite reason, for being too restrictive with one of those same models. Between the two moments sit a US government letter, a national security claim, and a word you have probably seen without being told what it means: Mythos.
What Mythos is, and why it rattled people

The story starts in late March, when drafts of an unpublished Anthropic blog post leaked. They named a model the company had not announced, Claude Mythos, and on 7 April Anthropic presented it formally. Mythos was not notable for writing better emails. It was exceptionally good at one narrow, sensitive skill: reading through software and finding the flaws that hackers use to break in. In its own tests, Anthropic said the model uncovered weaknesses in every major operating system and web browser it was given, and in one case a flaw that had gone unnoticed for nearly thirty years. The company called it a "watershed moment" for cybersecurity.
The unease follows once you see the catch. The ability to find a security hole so it can be fixed is the same ability needed to find it so it can be exploited. A model that helps defenders patch the world's software is, mechanically, the model that would help an attacker plan the break-in. That worried people beyond Anthropic. Britain's AI Security Institute, a government body that evaluates these systems, reported a marked jump in cybersecurity capability over earlier models.
Locked away: a sales pitch or a real danger?

Here is the fair question to sit with, and the honest answer is that both can be true. The capability was real and corroborated by outsiders, not just by Anthropic's marketing. Yet declaring your own product too dangerous to sell is also extraordinary advertising. It signals raw power, it flatters the buyer, and it arrived as the company prepared a stock-market listing that could value it in the hundreds of billions. A safety story and a sales story are not mutually exclusive, and from outside there is no clean way to weigh how much of the caution was conviction and how much was positioning.
What is clear is the decision it led to. Rather than sell Mythos, Anthropic set up a programme called Project Glasswing and handed the model only to organisations that defend critical systems, on the logic that a dangerous skill is best pointed at fixing vulnerabilities before criminals or hostile states find them. The early group included Google, Microsoft, Apple and JPMorgan Chase, and Anthropic says those partners used it to identify more than ten thousand serious flaws in important software. For about two months, the most capable model the company had ever built went to a vetted few and nobody else.
Why release Fable 5 at all?

That changed on 9 June, when Anthropic released Claude Fable 5: by its own description the same underlying model as Mythos with safeguards bolted on, so that questions about high-risk areas like cybersecurity or biology get handed to a weaker model instead of answered. The reasoning it offered was that perfect safety is impossible, and that strong barriers plus a public release beat hiding a capable model forever, especially with rivals closing in and a listing approaching. By independent accounts the model is formidable; Wharton's Ethan Mollick, who has tested most frontier systems, wrote that it "outperformed basically every other public model I have used by a considerable margin." The launch still went badly. Within a day, researchers found the safeguards were heavier and more hidden than advertised, blocking legitimate work without telling users, and Anthropic conceded it had got the balance wrong. That was Friday. The government letter arrived the same evening.
Why the government switched it off, and how it can

At 5:21pm Eastern on Friday, according to Anthropic, the Commerce Department delivered an export control directive signed by Secretary Howard Lutnick, ordering the company to cut off Fable 5 and Mythos 5 for any foreign national, inside the United States or out, including its own foreign staff. A rule that broad left one practical option, so Anthropic disabled both models for everyone. Its other models still work. The stated reason was national security: the administration told Axios it acted after another firm claimed it had found a way around Mythos's safety barriers, and that officials had already tried and failed to get the launch delayed. Anthropic counters that it examined the demonstration and found it exposed only a few minor, already-known flaws that other public models, including one from OpenAI, can find without any trick.
How can the government simply order a company to break its own product? Through export control law, which is not special to Anthropic. The United States has long restricted sensitive exports, and in early 2025 Commerce extended that to the most advanced AI models directly. The key wrinkle is an old idea called a deemed export: giving a foreign citizen access to controlled technology counts, in law, as exporting it to their country, even if they are sitting at a desk in California. That is why an order aimed at foreigners switched the models off for Americans too. The irony is sharp, since Anthropic spent the past year lobbying for tougher export controls on advanced AI, and this week watched the same machinery turn on its flagship.
What it means for Anthropic, and for the rest of us

For Anthropic the immediate damage is a flagship it cannot sell and customers whose access vanished overnight, framed by a reputation now caught in a vice: too cautious for its users on Tuesday, too dangerous for its government by Friday. The deeper trouble is the relationship. Anthropic was already at odds with the administration, having refused to let its technology be used for autonomous weapons or mass surveillance, walked away from Pentagon talks, and then been labelled a supply chain risk, a tag usually reserved for foreign adversaries. It sued and won a temporary order restoring federal access. A rival, OpenAI, signed a Pentagon deal in the same stretch. All of this lands as Anthropic moves toward a stock-market listing, and the government has signalled it does not care about the timing; the Pentagon's technology chief wrote that "some things are simply more important than revenue cycles, clickbait, and pre-IPO valuation."
Whether this is bigger than one company is the open question. One reading is precedent: the law used here applies to any lab nearing this capability, and Friday was just the first time the rules met a product powerful enough to trip them. The other reading is that it looks personal, since the company being squeezed is the one that refused military work and sued, while the competitor that cooperated is signing contracts, and Anthropic says a rival model can do the same risky things untouched. The letter gave no specifics, so we do not know which it is.
For readers outside the United States the effect is blunt: Anthropic's two best models are, for now, off limits, and South Africa sits squarely inside that net, not as collateral but as the explicit target of the order. The longer pattern is the one to carry away. The most capable AI is starting to be treated less like software you can buy and more like controlled strategic technology, gated by nationality and by a government's relationship with Washington as much as by price. Anthropic and the administration agree that someone should be able to halt a truly dangerous release; they disagree sharply over who that someone is and what process they must follow. Mythos and Fable 5 are the first models to force that fight into the open. They will not be the last.