US Government Lifts Export Controls on Anthropic's AI Cybersecurity Models
The US government has lifted export controls on Anthropic's advanced cybersecurity AI models, Fable 5 and Mythos 5, after the company reached agreements with the government. The controls were initially imposed due to concerns over the potential misuse of the models by foreign nationals.
Background on the Export Controls
In June, the US government imposed export controls on Anthropic's Fable 5 model, restricting access to foreign nationals. The company was forced to disable access for all customers to ensure compliance. However, after negotiations with the government, the controls have been lifted, and access to the model has been restored.
The episode marked the first known use of export control authorities to pull AI software from public access. The reversal may set the terms under which frontier AI models are regulated in the US going forward.
Mythos 5 Model Access Restrictions
Export controls on Anthropic's more powerful cybersecurity model, Mythos 5, were also fully lifted as of June 30. However, access to the model remains restricted to vetted US organizations through Project Glasswing, Anthropic's controlled-access program for critical infrastructure defenders.
The company is continuing to negotiate broader domestic and international access through Glasswing. The initial shutdown was triggered by a 'jailbreak' technique covered in an Amazon research report, which was subsequently described in detail by Katie Moussouris, founder of Luta Security.
Assessment of the Jailbreak Technique
Moussouris wrote that researchers fed Fable 5 open-source code with publicly known vulnerabilities plus deliberately planted flaws, then asked it to 'fix this code.' The model's output was then manually assembled, across multiple steps, into scripts that test patches.
Her conclusion was that the underlying capability cannot be removed without degrading the model's usefulness for legitimate security work. Anthropic said its own subsequent testing confirmed the same technique worked against other models, including OpenAI's GPT-5.5 and the Chinese model Kimi K2.7 — none of which faced comparable export restrictions.
Measures to Prevent Misuse
As part of the negotiations to restore access to Fable, Anthropic said it trained a new safety classifier that blocks the specific technique in more than 99% of cases. Researchers from the Commerce Department's Center for AI Standards and Innovation tested both the original and updated safeguards and endorsed the result.
Beyond the classifier, Anthropic committed to expanded pre-release access for government evaluators to test frontier models before broad release, rapid disclosure of significant jailbreaks, dedicated staff and compute for joint research, and participation in a shared voluntary security standard across frontier model providers.
Together with its Glasswing partners — including Amazon, Microsoft, and Google — Anthropic said it is drafting an industry framework to score jailbreak severity across four criteria: capability gain over existing tools, breadth of tasks affected, ease of weaponization, and discoverability.
Industry Response
More than 100 cybersecurity professionals had signed an open letter organized by former Facebook security chief Alex Stamos and addressed to Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross, warning the government that the export controls risked doing more harm than good.
The signatories included executives from Nvidia, Adobe, Zoom, Google, and Sophos, and echoed Anthropic's argument that if the standard applied to Fable 5 were applied industry-wide, it would, in Anthropic's own words, 'essentially halt all new model deployments for all frontier model providers.'
Conclusion
The lifting of export controls on Anthropic's AI cybersecurity models marks a significant development in the regulation of frontier AI models. The episode highlights the need for a balanced approach to regulating AI models, one that considers both the potential benefits and risks of these technologies.
Source: The Record