The Doyen Brief
Trade & Export Development

Washington Pulled Two Anthropic Models and Reached Its Own Foreign Staff

At 5:21pm ET on Friday, Anthropic received a letter from Commerce Secretary Howard Lutnick, drafted with the Bureau of Industry and Security, ordering it to suspend all access to its two most capable models (Fable 5 and Mythos 5) “by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.” Because you cannot reliably check nationality at the edge of a public API, the company complied the only way it could: it switched both models off for everyone, including US customers. The proximate trigger appears to be a single, disputed “jailbreak” of a cyber-capable model, and through the export-control “deemed export” rule, the off-switch reaches inside the lab and sorts its own workforce by passport.

Industry signals

What changed across the profession.

01

A Friday-night letter pulls Fable 5 and Mythos 5 for everyone

Anthropic disabled its Fable 5 and Mythos 5 models for all customers on June 12, after a 5:21pm ET export-control letter from Commerce Secretary Howard Lutnick, written with BIS officials, citing unspecified “national security authorities.” The order required suspending access for “any foreign national, whether inside or outside the United States, including foreign national Anthropic employees”; with no way to nationality-gate a public API, Anthropic pulled both models entirely. Its other models were unaffected.

Anthropic: statement on the directive
02

The trigger: a single, disputed “jailbreak” of a cyber-capable model

Anthropic says its understanding is that the government became aware of a method of “jailbreaking” Fable 5, and that the demonstration it reviewed amounted to asking the model to read a codebase and fix its flaws. That surfaced only “previously known, minor vulnerabilities” that other public models, including OpenAI's GPT-5.5, can already find. Separately, the well-known jailbreaker “Pliny the Liberator” publicly claimed to have broken Fable 5's safeguards; Anthropic disputes that this is a genuine jailbreak. The company calls the order a “misunderstanding.”

SecurityWeek: Anthropic disputes the Fable 5 jailbreak
03

“Deemed exports” are the legal mechanism that reaches the employees

Under the Export Administration Regulations, releasing controlled technology or source code to a foreign national inside the United States is “deemed” an export to that person's country of nationality, with exemptions only for citizens, green-card holders and protected individuals. The directive's phrase “including foreign national Anthropic employees” is that doctrine made explicit: the same rule that governs a shipment abroad now governs who at the next desk may open the model.

Bureau of Industry and Security: what is a deemed export?
04

Anthropic's real fear is the precedent

Anthropic is complying while openly disagreeing, warning that recalling a model deployed to hundreds of millions of users over a narrow, non-universal jailbreak (if applied across the industry) “would essentially halt all new model deployments for all frontier model providers.” The clash also follows an existing rupture: the Defense Department earlier labeled Anthropic a “supply-chain risk,” a tag historically reserved for foreign adversaries, and Anthropic is suing the administration to reverse it.

CNBC: Anthropic disables Fable 5 and Mythos 5
05

The exposed talent base is the one that built the frontier

By MacroPolo's count, roughly two-thirds of the top-tier AI researchers working in the United States did their undergraduate degrees abroad, and the single largest country of origin is China. A control regime that keys access to nationality therefore bites hardest on the cohort that staffs frontier research, and any lab forced to operationalize such an order has to do so against its own payroll.

MacroPolo: Global AI Talent Tracker
Lead analysis · Trade & Export Development

What Washington just demonstrated it can do to a frontier lab

Two precedents were set on Friday evening. A deployed commercial AI product can be switched off by letter overnight on national-security grounds, and the same authority reaches inside the company to reclassify its foreign-national employees as a licensing problem.

Anthropic launched Fable 5 and Mythos 5 on Tuesday as the most capable systems it had ever shipped: Fable 5 to the general public behind heavy safeguards that fall back to a weaker model in cybersecurity and biology, Mythos 5 without those guardrails to a small set of trusted cybersecurity and infrastructure partners. Three days later, at 5:21pm on a Friday, a letter arrived from the Commerce Secretary, drafted with the Bureau of Industry and Security, citing national-security authorities it did not specify, ordering the company to deny the models to every foreign national on earth, its own staff included. By Friday night both models were dark for all users. There was no rulemaking, no comment period and no published classification decision. The export-control directive functioned as an emergency kill switch for a product already in the hands of hundreds of millions of people. For any government that builds or buys frontier AI, that capability is the headline, independent of whether this particular invocation was justified.

The proximate trigger, as best the public record allows, was a single disputed jailbreak. Anthropic's account is that the government believed it had learned of a way to bypass Fable 5's safeguards, and that the demonstration it was shown consisted of asking the model to read a specific codebase and fix the software flaws in it, a narrow, non-universal technique that surfaced only previously known, minor vulnerabilities, of a kind other public models including OpenAI's GPT-5.5 will also produce and that defenders use every day. A separate, louder claim came from the jailbreaker known as Pliny the Liberator, who said he had “liberated” Fable 5; Anthropic disputes that this is a real jailbreak, arguing the core safeguards are enforced by independent classifiers that survive the model's conversational refusals being coaxed away. Whether or not the government's basis and Pliny's claim are the same artifact, the standard being applied is a recalled commercial model, industry-wide, on the strength of a contested narrow finding. Anthropic's warning that this would “essentially halt all new model deployments for all frontier model providers” describes where the precedent points.

The mechanism that makes the order bite inside the company is the deemed-export rule, which turns an export story into a labor-and-immigration story. Under the EAR, releasing controlled “technology” or source code to a foreign national located in the United States is treated (“deemed”) as an export to that person's country of nationality. Nothing has to cross a border. A screen share, an oral briefing or a granted permission on a repository is a release, and each release to a non-US person is an export. The only people exempt are US citizens, lawful permanent residents and a narrow category of protected individuals. Everyone else, the H-1B research scientist included, is for the purposes of this rule a foreign destination that happens to sit at the next desk. The directive's own language, “including foreign national Anthropic employees,” is the doctrine stated out loud. And because a public API cannot reliably verify the nationality of the person behind a key, the only compliant response to a deemed-export-style restriction on a mass-market model is to turn the model off for all, which is what happened.

By MacroPolo's tracking, around two-thirds of the elite AI researchers working in the United States completed their undergraduate education outside it, and the largest single source country is China, the country at the most restrictive end of every tier Washington has ever drawn. A nationality-keyed control regime runs through the center of a frontier lab's workforce. The structural response is the one cleared defense contractors have used for generations, now imported into an industry built on the opposite premise: segregated access, US-person-only project rooms, and an HR-and-legal apparatus that screens by citizenship before granting access to the crown-jewel model. An industry whose advantage was assembling the best researchers on earth regardless of origin now has a standing regulatory incentive to sort them by origin, and a live demonstration that the government can force the sort overnight.

The second-order effects radiate outward, and several cut against Washington's own aims. A model that can be switched off by letter is a different commercial proposition for an enterprise buyer, who now has to price regulatory availability alongside uptime; expect procurement teams to ask frontier vendors what their continuity plan is when the next directive lands. The deemed-export logic gives the most mobile foreign talent a sharper reason to take the job in London or Toronto rather than wait out a license. The discretion on display, an unspecified authority invoked on a Friday night against a company already suing the administration, will not be lost on allied governments weighing how much of their AI stack to anchor in a single jurisdiction; it strengthens every sovereign-AI and “trusted compute” pitch already in motion. And there is a chilling edge for the open security research that Anthropic's own safeguards depend on: if demonstrating a narrow jailbreak can trigger a national-security recall, the incentives around disclosure get more complicated for everyone.

For the practitioner community Doyen serves, the reframing is clean. Frontier AI has just been shown to be an export-controlled, politically contingent industry, and it should be modeled like aerospace, nuclear and advanced semiconductors rather than like software-as-a-service. That changes the locational calculus in concrete ways. Nationality becomes a workforce variable that AI investors must weigh when they site research, advantaging jurisdictions with deep US-person-equivalent talent pools or trusted-partner arrangements and penalizing those whose pitch was cheap global talent with no security overlay. Jurisdiction itself becomes a product feature: “trusted cloud” status, allied-tier designation and a credible continuity story are now things a serious AI-investment proposition has to offer, ahead of the tax abatement. The open question every economic-security team should be asking is procedural: under what authority, on what evidentiary standard, and with what notice can a deployed model be pulled. Friday's answer was, in effect, “a letter, a contested finding, and none.”

Top-tier US AI researchers by where they did their undergraduate degree
0%10%20%30%40%34%27%22%8%9%United StatesChinaEurope / otherIndiaOther

Indicative composition from MacroPolo's Global AI Talent Tracker, which finds roughly two-thirds of elite AI researchers working in the US trained abroad, with China the largest single source. Figures illustrate composition rather than exact shares, and underline the workforce most exposed to a nationality-keyed control directive.

Practice implications

  • A deployed frontier model can now be switched off overnight. The state has demonstrated a fast, discretionary export-control off-switch for a live commercial product, with no rulemaking and no notice. Enterprise buyers and economic-security teams should treat regulatory availability as a first-order risk and ask frontier vendors for a continuity plan.
  • Deemed exports make nationality a workforce variable. Because releasing controlled technology to a non-US person (even at the next desk) can be an export, and because a public API can't verify nationality, a nationality restriction becomes a total recall. Labs siting R&D will weigh US-person availability and visa friction directly; jurisdictions offering trusted-partner status or deep US-person-equivalent talent gain.
  • Watch the standard. The contested point is whether a narrow, non-universal jailbreak justifies pulling a mass-market model. If that standard hardens, it reaches every frontier provider, and the reform question is procedural: what authority, what evidence, what notice.
  • Jurisdiction has become a product feature. Allied-tier status and a credible continuity story now sit ahead of incentives in any serious AI-investment pitch, and Friday's events will accelerate the sovereign-AI and trusted-compute programs that allied governments had already begun.

Sources

Previous issue · Saturday, June 13, 2026America's Record FDI Year Was Almost All Acquisitions

Get the Brief in your inbox

Each issue is free and arrives the day it publishes.

You may unsubscribe at any time. We do not sell or share your details. Privacy policy.