The US government ban on Anthropic's Fable 5 model
- https://www.youtube.com/watch?v=cOxC0t8DqYk
- Original title: Is it ever coming back?
Theo walks through the 11-day-and-counting saga of the US government banning Anthropic's frontier models (Fable 5 and Mythos 5) from access by any foreign national worldwide. He traces the alleged origin (SK Telecom reselling access to China, an Amazon-reported "jailbreak"), explains why the ban is technically and legally unprecedented, and argues the whole episode sets a dangerous precedent: the most capable models become entirely inaccessible while only slightly-dumber open-weight models (like China's GLM 5-2) remain freely downloadable. He's frustrated, scared about the long-term chilling effect on AI development, and reluctantly defends Anthropic while also blaming their own fear-mongering for the situation.
The ban and its timeline
- Fable 5 and Mythos 5 launched June 9th and were, in Theo's view, incredible. He was running two $200 plans to maximize Fable usage and was live-streaming the models when the ban hit on June 12th, three days after launch.
- Anthropic's official press release promised more details within 24 hours; that never came. It has now been 11 days (two Mondays passed) with no model and no timeline for return.
- The international managing director of Anthropic said six days prior that they were "very confident" the models would return "in the coming days." Still nothing.
Alleged origin of the drama
- It did not start with the jailbreak reports. It started with SK Telecom, a South Korean internet company and heavy Anthropic user that invested over $100M into Anthropic in 2023 (a meaningful percentage of the company at the time), partly for a commercial telecom partnership.
- SK Telecom was alleged to be reselling Fable/Mythos access to customers in China, who are banned from access.
- Shortly after Anthropic announced an expansion of "Project Last Wing," the White House asked Anthropic to revoke SK Telecom's access to Mythos. Anthropic immediately complied. No export controls were threatened at that point.
- Cutting off a $100M investor this readily signaled to the government how willing Anthropic was to follow orders, but it wasn't enough. Reports of a jailbreak originating from Amazon then reached the government and triggered the ban. Amazon reportedly tried to contact Anthropic about it; Anthropic refused to respond.
The "jailbreak" that wasn't
- Per Anthropic's announcement, the government gave only verbal evidence of a "narrow, non-universal jailbreak," which essentially consisted of asking the model to read a code base and fix software flaws.
- Anthropic reviewed the report it believes underlies the directive and validated that this capability is widely available from other models, including OpenAI's GPT-5.5, and is used daily by defenders keeping systems safe.
- The core tension: fixing a bug also gives a model a guide to the exploit. A dumb model handed a patch diff can be asked to recreate the exploit. With open-weight models like GLM 5.2 approaching GPT-5.5, the pipeline of using the smartest models to find fixes and open-weight models to exploit them is real.
- Theo argues the best fix is to secure software, find and patch exploits, and ship patches fast before the capability spreads, which is what Anthropic's Project Last Wing was doing.
- Anthropic, immersed in the AI world, saw a model that fixes code bases as intended behavior, not a jailbreak, hence the dissonance. The word "jailbreak" has been "absolutely destroyed": the government sees a jailbreak, Anthropic sees intended behavior, the world sees confusion.
Why we can't just get it back
- This is not a formal sale/use ban. The restriction bars any foreign national (non-US citizen, regardless of location) from using the models, even Anthropic's own employees. People like Karpathy have been cut off.
- Anthropic can't simply ship a "know your customer / verify identity" gate. The model is exposed over API, so an integrator like Theo would have to verify their own users' citizenship and forward that data to Anthropic, an unviable data-privacy chain.
- They could theoretically gate it behind auth in Claude Code and aggressively ban misuse, but that isn't reliable enough. So they've kept it on hold until the ban is lifted, which requires "fixing the jailbreak."
Negotiations and politics
- Initially Anthropic didn't seem to know how to talk to the White House. After sending employees in person, negotiations improved. In an interview Trump said he no longer sees Anthropic as a national security threat (he did before).
- Trump does not appear interested in invoking the Defense Production Act, a wartime power he reportedly considered using for a hostile takeover of Anthropic. He noted he has the power but isn't sure he has to use it.
- Anthropic has been visibly placating the administration, stating gratitude for the "ongoing partnership" and shared goals of protecting critical infrastructure and US AI leadership.
- Per leaks, progress has since stalled and the government has lost interest, making unbanning harder. Anthropic is reportedly iterating on Sonnet 5 to ship a cheaper, dumber 5-era model just to give hurting customers something.
The Legion lawsuit
- A 43-page lawsuit was filed against the United States, the Department of Commerce, Howard Lutnick (who okayed and pushed the ban), Jeffrey Kessler, the Bureau of Industry and Security, the Executive Office of the President, and 10 additional defendants.
- It is not from Anthropic but from Legion, a US-based AI-native litigation-tech company building attorney tools on frontier models. Legion is a commercial Anthropic customer licensed to use Fable 5, and its dev team includes Canadian nationals working remotely from Canada (a Five Eyes partner / Group A:5 nation under the government's own export regulations).
- The June 12th letter from Commerce's BIS gave Anthropic 90 minutes to comply under threat of criminal and civil penalties on export-control authority. Within hours hundreds of millions of users, including allies' citizens and Anthropic's own employees, lost access.
- Three causes of action argue the government lacks authority. The use of the International Emergency Economic Powers Act (IEEPA) is claimed invalid because the president is barred from prohibiting the export of "information and informational materials in any format or medium," which is entirely withheld in that act.
- Theo notes the heavy use of em-dashes suggests AI helped draft the complaint ("probably not Babel, though").
Bipartisan congressional pushback
- A bipartisan group (Congressmen Sam Liccardo, Jay Obernolte, Ted Lieu, Scott Franklin; two Democrats, two Republicans) is pressing the Department of Commerce for transparency on the June 12th decision, raising concerns it sets a significant precedent for frontier AI regulation.
- They want to understand the standards, criteria, and evidentiary thresholds applied, and how they'll apply going forward, warning the action could substantially restrict distribution, deployment, and use of advanced AI even within the US. A response was requested by June 26th.
The deeper precedent and Theo's fears
- Per Artificial Analysis, Fable 5 is the best model ever on intelligence/capabilities, scoring 60 vs the next-highest Opus at 56 (and likely understated, since Fable refusals fell back to Opus, making it a blended score).
- China's GLM 5-2 is unusually high on the chart, a major jump for open-weight models, especially for code; Theo says it should have been called GLM 6. It has mostly caught up to "5-4" and is approaching GPT-5.5, though Fable was a tier above.
- The perverse structure: models above a capability line can't be sold or released publicly without crazy restrictions, but something slightly dumber can be downloaded and run locally for anything. Theo: once you have the weights, the government can't export-control what runs on your GPU.
- This incentivizes the least-restricted models (e.g. Chinese, censored by their government) to dominate, since US-government-censored models become entirely inaccessible. Theo doesn't want either, but calls the current trajectory a bad precedent.
- He partly blames Anthropic's own fear-mongering about AI's existential danger for putting people on high alert and provoking this response.
- Pete Hegseth claimed the Department of War kicked Anthropic out of its building three months ago and that each day proves it right, despite the military using Mythos in high-stakes operations days before the ban (per a community note). The feds clarified his statements aren't final agency actions, but his influence on the White House/Commerce contributes to scenarios like this.
- Other labs have gone quiet (notably few posts from OpenAI for weeks), likely fearing their own models get banned or KYC'd, possibly delaying releases like "GBD 56" to mid-July.
- Theo's broader worry: the software/tech industry has never had to deal with a powerful new tool being abruptly taken away with no promise of return. Nearly everyone he knows working on or with AI is scared about what this means long-term.
- He closes by quoting the congressmen on the economic and national-security stakes, notes the requested June 26th response, and says he'll cover it if it happens, while going back to "staring at the PRs at feable me" wishing he could ask the model more questions.