Skip to content
Heise Online — US government forces shutdown of Anthropic Fable 5 and Mythos 5

Heise Online — US government forces shutdown of Anthropic Fable 5 and Mythos 5

www.heise.de June 16, 2026

Anthropic must shut down its AI models Fable 5 and Mythos 5 for all customers worldwide. According to the company, the trigger is a US government export control directive received on June 12, 2026, which prohibits foreign nationals from accessing both models – including foreign Anthropic employees within the USA. All other Claude models are not affected by the order. The measure is part of an escalating dispute between Anthropic and parts of the US security bureaucracy that occurred previously.

As Anthropic explains in a statement , the authority did not provide specific technical details regarding the stated national security concerns. According to the company's understanding, the government assumes that a method exists to “jailbreak” Fable 5, i.e., to bypass its protective mechanisms. Anthropic describes the measure as a “misunderstanding” and is working on restoring access.

Anthropic describes the criticized technique as a verbally transmitted, potentially non-universal jailbreak. At its core, it involves instructing the model to read a specific codebase and fix software errors. A demonstration of this technique was reviewed, revealing only a small number of already known, minor vulnerabilities that publicly available models could also detect – the company explicitly mentions OpenAI's GPT-5.5 in this context.

From Anthropic's perspective, this is an everyday capability, similar to what security professionals use daily in legitimate code reviews and bug fixing. The crucial difference lies not in the function itself, but in the context: the same process might be desirable in a security review, but could be considered potential misuse in another scenario. A universal jailbreak that fundamentally bypasses Fable 5's protective mechanisms has not been found to date.

Anthropic refers to a so-called “Defense-in-Depth strategy”: Jailbreaks are intended to be either narrowly limited or very complex, and are supplemented by monitoring designed to quickly detect successful attacks. For Fable 5, there is also a 30-day data retention requirement to analyze and contain bypass attempts. Our test of Fable 5 confirms that Anthropic places classifiers before the actual model and sometimes falls back to the model Opus 4.8 for sensitive inputs.

The previously communicated protective measures were tested over thousands of hours of red teaming in a preliminary review – together with the US government, the UK AI Safety Institute (UK AISI), private organizations, and internal teams. The results were significantly better than those of earlier models. However, a fully independent audit, for example by European research institutions, is not yet documented; a complete disclosure of the protective logic or the internal classifier architecture was not provided. While Fable 5 was equipped with additional protective mechanisms for public use, Mythos is considered a more restrictive variant .

Anthropic admits that perfect jailbreak resistance is not achievable for any model. At the same time, the company contradicts the assertion that a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people. If this standard were applied across the industry, it would amount to a halt in new frontier models.

The current order comes amidst an already strained relationship. In early March 2026, the US Department of Defense classified Anthropic as a “supply chain risk.” In a recent blog post, CEO Dario Amodei explained that they consider the classification as a “supply chain risk” legally untenable and intend to challenge it in court. The underlying US statute 10 U.S.C. § 3252 is narrowly tailored to specific supply chain risks in national security systems and requires the department to demonstrate why less intrusive measures are not reasonably available.

According to Anthropic, the conflict revolved around the refusal to release Claude for mass domestic surveillance and fully autonomous weapon systems without restrictions. Whether the current export directive is primarily a security measure or political pressure on a recalcitrant provider cannot be proven from the published sources. However, it seems plausible that the preceding dispute significantly worsened the relationship and facilitated the escalation.

For domestic providers, a directly comparable, single-model-specific intervention is not apparent in the EU. While US export control law aims at external economic access restrictions, the EU AI Act pursues a risk-based approach with market surveillance, transparency, and documentation obligations. In Germany, the Federal Network Agency is to become the central market surveillance authority; the corresponding draft law (KI-MIG) was passed by the Bundestag on June 11, 2026, with the Bundesrat's approval still pending. A global shutdown of a single model, similar to export control, is not envisioned in this logic.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Countries (1)

Domains (1)

Tools (2)