The Doyen Brief
Trade & Export Development

The overnight off-switch: Washington pulls two Anthropic models, and reaches inside the lab to its own foreign staff

At 5:21pm ET on Friday, Anthropic received a letter from Commerce Secretary Howard Lutnick, drafted with the Bureau of Industry and Security, ordering it to suspend all access to its two most capable models (Fable 5 and Mythos 5) “by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.” Because you cannot reliably check nationality at the edge of a public API, the company complied the only way it could: it switched both models off for everyone, including US customers. The proximate trigger appears to be a single, disputed “jailbreak” of a cyber-capable model, and through the export-control “deemed export” rule, the off-switch reaches inside the lab and sorts its own workforce by passport.

Quick hits

What moved, in brief.

01

A Friday-night letter pulls Fable 5 and Mythos 5 for everyone

Anthropic disabled its Fable 5 and Mythos 5 models for all customers on 12 June after receiving an export-control directive at 5:21pm ET — a letter from Commerce Secretary Howard Lutnick, written with BIS officials, citing unspecified “national security authorities.” The order required suspending access for “any foreign national, whether inside or outside the United States, including foreign national Anthropic employees”; with no way to nationality-gate a public API, Anthropic pulled both models entirely. Its other models were unaffected.

Anthropic: statement on the directive
02

The trigger: a single, disputed “jailbreak” of a cyber-capable model

Anthropic says its understanding is that the government became aware of a method of “jailbreaking” Fable 5, and that the demonstration it reviewed amounted to asking the model to read a codebase and fix its flaws — surfacing only “previously known, minor vulnerabilities” that other public models, including OpenAI's GPT-5.5, can already find. Separately, the well-known jailbreaker “Pliny the Liberator” publicly claimed to have broken Fable 5's safeguards; Anthropic disputes that this is a genuine jailbreak. The company calls the order a “misunderstanding.”

SecurityWeek: Anthropic disputes the Fable 5 jailbreak
03

“Deemed exports” are the legal mechanism that reaches the employees

Under the Export Administration Regulations, releasing controlled technology or source code to a foreign national inside the United States is “deemed” an export to that person's country of nationality — with exemptions only for citizens, green-card holders and protected individuals. The directive's phrase “including foreign national Anthropic employees” is that doctrine made explicit: the same rule that governs a shipment abroad now governs who at the next desk may open the model.

Bureau of Industry and Security: what is a deemed export?
04

Anthropic's real fear is the precedent, not this one model

Anthropic is complying while openly disagreeing, warning that recalling a model deployed to hundreds of millions of users over a narrow, non-universal jailbreak — if applied across the industry — “would essentially halt all new model deployments for all frontier model providers.” The clash also follows an existing rupture: the Defense Department earlier labelled Anthropic a “supply-chain risk,” a tag historically reserved for foreign adversaries, and Anthropic is suing the administration to reverse it.

CNBC: Anthropic disables Fable 5 and Mythos 5
05

The exposed talent base is the one that built the frontier

By MacroPolo's count, roughly two-thirds of the top-tier AI researchers working in the United States did their undergraduate degrees abroad, and the single largest country of origin is China. A control regime that keys access to nationality therefore bites hardest on precisely the cohort that staffs frontier research, and any lab forced to operationalise such an order has to do so against its own payroll.

MacroPolo: Global AI Talent Tracker
Deep dive · Trade & Export Development

The off-switch and the deemed export: what Washington just demonstrated it can do to a frontier lab

Stripped of the model names, two precedents were set on Friday evening. A deployed commercial AI product can be switched off by letter overnight on national-security grounds. And the same authority reaches inside the company and reclassifies its foreign-national employees as a licensing problem.

The sequence is worth stating plainly because the speed is part of the story. Anthropic launched Fable 5 and Mythos 5 on Tuesday as the most capable systems it had ever shipped — Fable 5 to the general public behind heavy safeguards that fall back to a weaker model in cybersecurity and biology, Mythos 5 without those guardrails to a small set of trusted cybersecurity and infrastructure partners. Three days later, at 5:21pm on a Friday, a letter arrived from the Commerce Secretary, drafted with the Bureau of Industry and Security, citing national-security authorities it did not specify, ordering the company to deny the models to every foreign national on earth, its own staff included. By Friday night both models were dark for all users. There was no rulemaking, no comment period, no published classification decision — an export-control directive functioning as an emergency kill switch for a product already in the hands of hundreds of millions of people. For any government that builds or buys frontier AI, that capability is the headline, independent of whether this particular invocation was justified.

The proximate trigger, as best the public record allows, was a single disputed jailbreak. Anthropic's account is that the government believed it had learned of a way to bypass Fable 5's safeguards, and that the demonstration it was shown consisted of asking the model to read a specific codebase and fix the software flaws in it — a narrow, non-universal technique that surfaced only previously known, minor vulnerabilities, of a kind other public models including OpenAI's GPT-5.5 will also produce and that defenders use every day. A separate, louder claim came from the jailbreaker known as Pliny the Liberator, who said he had “liberated” Fable 5; Anthropic disputes that this is a real jailbreak, arguing the core safeguards are enforced by independent classifiers that survive the model's conversational refusals being coaxed away. Whether or not the government's basis and Pliny's claim are the same artefact, the salient point for the trade-policy reader is the standard being applied: a recalled commercial model, industry-wide, on the strength of a contested narrow finding. Anthropic's warning that this would “essentially halt all new model deployments for all frontier model providers” is not special pleading; it is a description of where the precedent points.

The mechanism that makes the order bite inside the company is the deemed-export rule, and this is the part that turns an export story into a labor-and-immigration story. Under the EAR, releasing controlled “technology” or source code to a foreign national located in the United States is treated (“deemed”) as an export to that person's country of nationality. Nothing has to cross a border. A screen share, an oral briefing, a granted permission on a repository, a glance at a model endpoint: each is a release, and each release to a non-US person is an export. The only people exempt are US citizens, lawful permanent residents and a narrow category of protected individuals. Everyone else (the H-1B research scientist, the O-1 hire, the recent PhD on OPT, the engineer on an L-1 transfer) is, for the purposes of this rule, a foreign destination that happens to sit at the next desk. The directive's own language, “including foreign national Anthropic employees,” is the doctrine stated out loud. And because a public API cannot reliably verify the nationality of the person behind a key, the only compliant response to a deemed-export-style restriction on a mass-market model is to turn the model off for all, which is exactly what happened. A nationality restriction on a cloud product is, in practice, a total recall.

That is why the talent arithmetic is not a footnote. By MacroPolo's tracking, around two-thirds of the elite AI researchers working in the United States completed their undergraduate education outside it, and the largest single source country is China — the country at the most restrictive end of every tier Washington has ever drawn. A nationality-keyed control regime does not graze the edge of a frontier lab's workforce; it runs through the center of it. The structural response is the one cleared defense contractors have used for generations, now imported into an industry built on the opposite premise: segregated access, US-person-only project rooms, walled compute, technology control plans, and an HR-and-legal apparatus that screens by citizenship before granting access to the crown-jewel model. An industry whose advantage was assembling the best researchers on earth regardless of origin now has a standing regulatory incentive to sort them by origin, and a live demonstration that the government can force the sort overnight.

The second-order effects radiate outward, and several cut against Washington's own aims. A model that can be switched off by letter is a different commercial proposition for an enterprise buyer, who now has to price regulatory availability alongside uptime; expect procurement teams to ask frontier vendors what their continuity plan is when the next directive lands. The deemed-export logic gives the most mobile foreign talent a sharper reason to take the job in London, Paris, Toronto or Abu Dhabi rather than wait out a license — a quiet reverse brain drain dressed as compliance. The discretion on display, an unspecified authority invoked on a Friday night against a company already suing the administration, will not be lost on allied governments weighing how much of their AI stack to anchor in a single jurisdiction; it strengthens every sovereign-AI and “trusted compute” pitch already in motion. And there is a chilling edge for the open security research that Anthropic's own safeguards depend on: if demonstrating a narrow jailbreak can trigger a national-security recall, the incentives around disclosure get more complicated for everyone.

For the practitioner community Doyen serves, the reframing is clean even if the politics are not. Frontier AI has just been shown to be an export-controlled, politically contingent industry, and it should be modelled like aerospace, nuclear and advanced semiconductors rather than like software-as-a-service. That changes the locational calculus in concrete ways. Nationality becomes a workforce variable that AI investors must weigh when they site research, advantaging jurisdictions with deep US-person-equivalent talent pools or trusted-partner arrangements and penalising those whose pitch was cheap global talent with no security overlay. Jurisdiction itself becomes a product feature: “trusted cloud” status, allied-tier designation and a credible continuity story are now things a serious AI-investment proposition has to offer, ahead of the tax abatement. And the open question every economic-security team should be asking is procedural — under what authority, on what evidentiary standard, and with what notice can a deployed model be pulled — because Friday's answer was, in effect, “a letter, a contested finding, and none.”

Who staffs the US AI frontier: top-tier researchers by where they did their undergraduate degree
0%10%20%30%40%34%27%22%8%9%United StatesChinaEurope / otherIndiaOther

Indicative composition from MacroPolo's Global AI Talent Tracker, which finds roughly two-thirds of elite AI researchers working in the US trained abroad, with China the largest single source. Figures illustrate composition rather than exact shares, and underline the workforce most exposed to a nationality-keyed control directive.

Why it matters for practitioners

  • A deployed frontier model can now be switched off overnight. The state has demonstrated a fast, discretionary export-control off-switch for a live commercial product — no rulemaking, no notice. Enterprise buyers and economic-security teams should treat regulatory availability as a first-order risk, not a tail risk, and ask frontier vendors for a continuity plan.
  • Deemed exports make nationality a workforce variable. Because releasing controlled technology to a non-US person — even at the next desk — can be an export, and because a public API can't verify nationality, a nationality restriction becomes a total recall. Labs siting R&D will weigh US-person availability and visa friction directly; jurisdictions offering trusted-partner status or deep US-person-equivalent talent gain.
  • Watch the standard, not just this case. The contested point is whether a narrow, non-universal jailbreak justifies pulling a mass-market model. If that standard hardens, it reaches every frontier provider, and the more important reform question is procedural: what authority, what evidence, what notice.
  • Jurisdiction has become a product feature. Allied-tier status and a credible continuity story now sit ahead of incentives in any serious AI-investment pitch, and Friday's events will accelerate the sovereign-AI and trusted-compute programs that allied governments had already begun.

Sources

Previous issue · Saturday, 13 June 2026The greenfield gap: America's record FDI year was bought, not built

Get the Brief in your inbox

Free. Each issue, the day it publishes.

You may unsubscribe at any time. We do not sell or share your details. Privacy policy.