(updated on August 9, 2026)

Washington Pulled the Plug on Fable 5: The 18 Days That Redefined AI Sovereignty

June 2026: Washington ordered Anthropic to cut off Fable 5 and Mythos 5 for foreign nationals. A sourced timeline of the first state kill switch.

Anthropic Claude sovereignty Fable 5 regulation Europe

On June 12, 2026, the US Department of Commerce ordered Anthropic to suspend access to Claude Fable 5 and Mythos 5 for every foreign national, anywhere in the world, including foreign nationals working on US soil. Anthropic disabled both models for everyone that same evening, three days after launch. It is the first documented case of a government cutting off access to an already deployed frontier model.

Eighteen days later, the restrictions were lifted. In between: a federal lawsuit, a bipartisan letter from Congress, and a French presidential campaign that seized on the story. Here is what actually happened, sourced line by line, and what it means if your stack depends on Claude.

Timeline

DateEventSource
June 9, 2026Claude Fable 5 and Mythos 5 launchAnthropic
June 11Andy Jassy (Amazon) raises a jailbreak found by his researchers with White House officials, then with Scott BessentFortune
June 12Commerce directive signed by Howard Lutnick, 90 minutes' notice, models disabled around 10pmBloomberg
June 13-15Gabriel Attal: "Anthropic is their Strait of Hormuz". The story enters the French presidential raceLCP
June 16Anthropic's public response, aimed at the directiveForbes
June 16European Parliament votes the Digital Omnibus (423 for, 57 against, 174 abstentions)European Parliament
June 18Bipartisan letter from four members of Congress to LutnickOfficial PDF
June 23Legion LegalTech Corp sues the federal governmentBloomberg
June 26Lutnick authorizes partial Mythos 5 redeployment to 100+ US organizationsAxios
June 29EU Council gives final green light to the Digital OmnibusCouncil of the EU
June 30Export controls on Fable 5 and Mythos 5 fully liftedCNBC
July 1Fable 5 restored to users globallyAnthropic
July 8Biometric identity verification goes live on flagged accountsTechCrunch
July 17Moonshot ships Kimi K3, 2.8 trillion parameters, open weightsForbes
July 19End of no-extra-cost Fable 5 inclusion in paid plansBleepingComputer
July 23A White House official accuses Moonshot of evading the Nvidia chip embargoCNBC
Early AugustDeadline for the pre-release review framework mandated by executive order 14409, kept secretTech Policy Press

A phone call that was never about this

The trigger was not a lobbying operation. On June 11, Amazon CEO Andy Jassy was on a pre-scheduled call with White House officials about an entirely different topic. Amazon researchers testing Fable 5 had found a jailbreak. Officials encouraged him to raise it with Scott Bessent at Treasury. He did so the same day, according to Fortune.

One detail gets consistently flattened in the retellings: Jassy said he was concerned about the cyber capabilities of all frontier models, not just Anthropic's. This was not a targeted complaint against a competitor. What turned a general remark into a company-specific directive was the administration's response to it.

On the morning of June 12, a White House call brought together Michael Cairncross, Scott Bessent and Susie Wiles. Shortly after, a Commerce Department directive signed by Howard Lutnick landed on Dario Amodei's desk. The demand: suspend access for every foreign national, everywhere, including foreign nationals employed in the United States. Commerce gave Anthropic 90 minutes to comply.

Anthropic had no reliable way to verify user nationality in real time. Facing an immediately effective directive with an unverifiable scope, the company did the only technically available thing: it cut everyone off. Around 10pm on June 12, Fable 5 and Mythos 5 went dark.

Anthropic's response targeted the directive, not Amazon

This is the nuance that suffered most in the coverage. Anthropic did not hit back at Amazon. Its public response targeted the government directive and the standard it establishes.

Three arguments, reported by Forbes. First, the vulnerabilities in question are "relatively simple" and discoverable with other public models, including GPT-5.5. Second, Anthropic said it had only verbal evidence of a narrow, non-universal jailbreak. Third, the company stated it had received no details whatsoever about the national security risk invoked to justify the shutdown.

The line that captures the stakes:

"If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers."

Unpack the argument: if a narrow, verbally reported jailbreak is enough to trigger a worldwide shutdown in 90 minutes, no lab can ship anything. Every frontier model has known jailbreaks at launch. That is the normal state of the art, not a Fable 5 anomaly.

Europe found out it is a user, not a player

In Europe, the shock was not technical. It was political, and it was instant.

In mid-June, Gabriel Attal, a leading French presidential contender, delivered the line that framed the entire French debate: "Anthropic is their Strait of Hormuz". He added that "AI must be treated like energy or raw materials" and warned of the "total vassalization of France" (LCP, France 24).

The analogy works because it is precise on one point. The Strait of Hormuz is not the resource, it is the chokepoint. Nobody needs to take your oil away if they can close the valve. What June 12 demonstrated is that API access is not infrastructure: it is a revocable right of passage, and the party holding the right is not you.

The reactions across Europe were parallel, not coordinated. Jordan Bardella called for accelerating support for "the gem that is Mistral AI". In the Netherlands, Geert Wilders tweeted "I want my #Anthropic Claude Fable 5 back!" and "AI is more and more national sovereignty". Bruno Retailleau, Édouard Philippe, Jean-Luc Mélenchon and Benjamin Haddad each weighed in. A technical infrastructure story became a presidential campaign marker in forty-eight hours.

The timing had an ironic twist. While Paris was talking sovereignty, Brussels was moving the other way. On June 16, the European Parliament passed the Digital Omnibus by 423 votes to 57 with 174 abstentions, confirmed by the Council on June 29. That text pushes back AI Act deadlines: standalone high-risk systems move to December 2, 2027, embedded systems to August 2, 2028 (European Parliament). Europe demanded digital sovereignty in the same week it delayed its own AI regulation timeline by two years.

In the US, pushback came from Congress and the courts

On June 18, four lawmakers signed a bipartisan letter to Lutnick: Sam Liccardo (D-CA), Jay Obernolte (R-CA), Ted Lieu (D-CA) and Scott Franklin (R-FL). They did not contest the principle of control. They asked two very concrete questions: which legal authorities the directive rests on, and by what criteria access can be restored (letter PDF).

On June 23, a customer sued. Legion LegalTech Corp filed against the federal government with a head-on argument: no existing export control covers hosted AI models or their outputs. The company described a Canadian development team cut off overnight, and harm that was "immediate, irreparable, and existential" (Bloomberg). The first legal challenge came not from the provider, but from a user.

That point is worth holding onto. The real damage was not borne by Anthropic, which has lawyers and a direct line to the administration. It was borne by ten-person teams that had built a product on an API.

How it ended: a two-step lift

The restrictions were not lifted in one move, and the distinction matters.

On June 26, Lutnick notified Anthropic that Mythos 5 could be redeployed to more than 100 US organizations named in an annex to the letter, including Fortune 500 companies and federal agencies. No export license would be required for those entities and their foreign national employees (Axios). A partial return, reserved for "trusted partners".

On June 30, Commerce fully lifted export controls on both models. Lutnick said no license would be required going forward, as Anthropic had agreed to proactively detect and address security risks associated with the models, to work with the government on standards for upcoming models, and to report malicious activity (CNBC).

On July 1, Fable 5 came back for users globally on the Claude Platform, Claude.ai, Claude Code and Claude Cowork. Anthropic laid out its commitments in Redeploying Claude Fable 5: early government access to models advancing national security capabilities, rapid sharing of discovered jailbreaks, dedicated teams for joint security research, and work toward a shared voluntary security and evaluation standard for frontier model providers.

Total blackout: 18 days. But the exit came through a bilateral agreement between a company and a government, not through a court ruling or a clarification of legal authority. The question the four members of Congress asked on June 18 never received a public answer. The precedent, however, now exists.

How to read this story without getting played

Everything above is sourced. That does not mean all of it carries equal weight, and I would rather hand you the framework than a ready-made narrative.

Three tiers of certainty are worth keeping apart, because everywhere else they get blended together.

What is established. The directive existed, and Bloomberg published the letter. The models did go dark on June 12 and returned on July 1. The European Parliament vote, the Legion LegalTech suit, the letter from the four members of Congress: those are documents. On these points you can build.

What is narrated by interested parties. The entire causal chain, by contrast, rests on storytelling: Jassy's call, the route through Bessent, the June 12 morning meeting. That comes from reporting built on anonymous sources, meaning people who chose to talk and had a reason to. It is not therefore false, but it is not the same kind of object as a signed letter.

What nobody knows, and nobody will. The actual severity of the jailbreak. Anthropic says it never received details of the risk invoked. Congress asked, and got no answer. And the testing apparatus stood up since is explicitly classified. The information that would settle the debate is not merely missing: it is designed to stay that way.

Here is the habit of mind I think is healthiest, and it generalizes to most announcements in this industry.

How public the affair became is itself information about how serious it was. If a capability were genuinely catastrophic, the expected behavior from a state is silence and classification. Not a letter leaking to Bloomberg within four days, not an "inside the room" account handed to a magazine, not a resolution announced by press release. What we observe looks far more like a negotiation conducted partly through the press, with each side briefing journalists to improve its position.

Look at who gained what. The administration demonstrated it could unplug a frontier lab in 90 minutes. Anthropic emerged as the responsible actor that pushed back, then won concessions and a seat at the table for writing future norms. Amazon came across as the vigilant researcher. Nobody was publicly damaged. A crisis every protagonist walks away from taller deserves at least a raised eyebrow.

The opposite error is just as lazy. Saying "it was all PR" would be as unearned as swallowing the heroic version. Teams really did lose access overnight, the Legion LegalTech complaint describes concrete harm, and the legal precedent is real regardless of anyone's intent. The right posture is not cynicism, it is ranking your evidence.

A fresh example, straight out of updating this article. While researching this section, several online summaries claimed Kimi K3 "surpasses" Fable 5 and GPT-5.6 Sol. Going back to the Forbes piece those write-ups cite, you read the opposite: K3 trails both overall, and only matches them on some coding and agent benchmarks. Two clicks separated the viral claim from the original text. That is precisely the mechanism that distorted the June story, and it is still running.

What happened since: the precedent becomes a system

Since the restrictions lifted, three developments have confirmed that June was not a one-off.

It was never Anthropic-specific. OpenAI's GPT-5.6 went through its own government-gated rollout in July, roughly two weeks of access restricted to vetted partners, again with no published threshold or process. June read like a score being settled with one particular lab. In hindsight it was the first application of a practice that is spreading.

The mechanism is being institutionalized, and it is secret. Executive order 14409, signed in June 2026, tasks an NSA-led group with building a pre-release review framework, including government access to models for up to thirty days before launch. Its deadline fell in early August. Nothing requires publishing what that group does with the models it evaluates, and the White House has said the framework will stay secret. So we move from an improvised 90-minute shutdown to a permanent process whose criteria are no better known than they were in June.

A Chinese lab answered with open weights. On July 17, Moonshot shipped Kimi K3, 2.8 trillion parameters, downloadable and modifiable. Forbes puts its overall performance below Fable 5 and GPT-5.6 Sol, but level with Fable 5 on coding and agent benchmarks and well ahead of Opus 4.8. Six days later, a White House official accused Moonshot of evading the Nvidia chip embargo (CNBC): an accusation, made by an interested party, belonging squarely in tier two of the framework above.

The uncomfortable part for the European debate: while Paris talked about vassalization and Brussels pushed back its own timetable, the only concrete answer to the valve problem came from elsewhere. A model you download and host yourself cannot be cut off by directive. No campaign slogan delivers that property. It may be the real lesson of the summer, and it is not a flattering one.

What this changes if you build on Claude

Down to specifics. If your product calls a Claude API in production, here is what June 2026 teaches you.

Your dependency is not contractual, it is geopolitical. Your SLA does not protect you from a government directive with 90 minutes' notice. No clause in your contract covers that scenario. Frontier model availability is now a political variable, on par with a technical one. If you are outside the US, you are not a party to the decision. You are its object.

Multi-model is no longer cost optimization, it is business continuity. The classic reasoning routes each task to the cheapest capable model. The June 2026 reasoning makes sure a second provider can take over. Concretely: abstract your calls behind your own interface instead of calling the Anthropic SDK directly all over your codebase. An llm.complete() layer that hides the provider costs half a day now and is worth your survival the day the valve closes.

Actually test your plan B. A fallback that never runs is a fallback that does not work. Run your system on the backup provider for a full day. You will discover that your prompts are tuned for Claude, that your output parsers break, that your tool calls use a different schema. Better to find out on a quiet Tuesday than at 10pm on June 12.

Watch your dependency on bleeding-edge models. The irony of this whole affair is that the models that got cut were the newest ones. Previous generations were never touched. If your product only works with the model that shipped last week, you built on the most exposed layer of the stack. Check what your system produces on an n-1 generation: if quality holds up, you have a free shock absorber.

Pricing is moving too. No-extra-cost Fable 5 inclusion in paid plans (Pro, Max, Team, Enterprise premium), capped at 50% of weekly limits, ends July 19, 2026 at 11:59:59pm PT. This was never "free access": Free-tier users were always excluded. After that, prepaid credits kick in at $10 per million input tokens and $50 per million output tokens. That is the third extension in five weeks (BleepingComputer). If you sized your costs against the inclusion window, redo the math before the 19th.

And there is an identity layer now. Since July 8, Anthropic runs biometric identity verification: government ID, live selfie with liveness detection, facial geometry template, via Persona Identities. Scope covers Free, Pro and Max; Team, Enterprise and API are exempt. It only targets flagged accounts, not the whole user base. Anthropic acknowledges these templates "may be considered biometric data in some jurisdictions" (TechCrunch). If you are in the EU and have GDPR questions, you are not alone.

The takeaway

The June 2026 kill switch lasted only 18 days and ended in a full lift. You could conclude the system worked. That would miss the point: the shutdown happened with no risk details shared with the provider, no legal basis clarified before Congress, and no court ruling on the merits. What worked was private negotiation. What was never established was the rule.

Two months on, it is that absence of a rule that got institutionalized. The review framework mandated by executive order 14409 makes the power to intervene permanent without making the transparency permanent: the criteria stay classified, and the mechanism now applies to OpenAI as readily as to Anthropic. June was not the crisis. It was the demonstration.

For anyone building outside the United States, the lesson is simple and uncomfortable: you build on infrastructure whose valve sits somewhere else, operable in 90 minutes, on criteria nobody disclosed to you. That is not a reason to stop using Claude, which remains excellent. It is a reason to stop treating API access as a given, and to keep at least one fallback path nobody else can close on your behalf.

And keep the reading framework for next time, because there will be a next time. Separate what is documented from what is narrated, ask who benefits from the version you are handed, and be especially wary of affairs everyone walks away from taller. On this subject, the most important information is almost always the piece nobody has an interest in giving you.

Pierre Rondeau

Pierre Rondeau

Developer and indie builder. I build products and automations with AI. Creator of Claude Hub.

LinkedIn