Anthropic Restores Claude Fable 5 After U.S. Commerce Department Lifts Export Controls
Anthropic has resumed global availability of Claude Fable 5. The move follows the U.S. Commerce Department’s decision on June 30 to revoke export restrictions that had been placed on Fable and its more permissive sibling, Mythos 5, roughly two and a half weeks after the bans were imposed. Fable 5 came back online for users on Wednesday, July 1 across Claude.ai, the Claude Platform, Claude Code, and Claude Cowork.
The June 12 order had directed Anthropic to deny access to both models for any foreign national, whether inside or outside the United States, including non-citizen employees. Because the restriction was effective immediately and Anthropic lacked a reliable real-time way to verify every user’s nationality, the company took the blunt step of disabling both models for everyone.
The action was triggered by a jailbreak - a crafted prompt that causes a model to override its safety constraints - discovered by Amazon researchers in Fable 5. According to Anthropic, the exploit led the model to identify several software vulnerabilities and in one instance to generate proof-of-concept code demonstrating how a weakness might be abused. Anthropic characterized the behavior as part of routine defensive security testing rather than an emergent, secret super-capability, noting that similar prompts work on many less-restricted models including its own Claude Opus 4.8, OpenAI’s GPT-5.5, and China’s Kimi K2.7. Nevertheless, both the government and the reporting partner judged the matter serious enough to warrant emergency controls.
To address the concern, Anthropic developed and trained a new safety filter - a classifier - specifically tuned to detect the exact jailbreak technique described in the report. In a June 30 update the company said this filter now blocks that tactic in over 99% of attempts. When the classifier intervenes, requests are routed to the weaker Opus 4.8 model and the user receives a notification. Anthropic acknowledges this mitigation increases false positives on benign coding and debugging queries.
Mythos 5, which is the same base model with reduced safety constraints, has returned under tighter limits. Access was reinstated on June 26 for about 100 U.S. companies and federal agencies involved in protecting critical infrastructure, and Anthropic says it is still negotiating with the government to expand that pool.
Commerce Secretary Howard Lutnick, who approved the rollback of the controls, said his department spent two weeks reviewing the models in collaboration with Anthropic. In a letter tied to the reversal, Anthropic agreed to proactively search for security issues, coordinate with regulators on future launches, and report any observed malicious use. Negotiations were reportedly led by co-founder Tom Brown rather than CEO Dario Amodei, who has been at odds with the administration this year.
The episode was contentious from the outset. Reporting from outlets including The Wall Street Journal attributed the original enforcement action in part to Amazon’s findings and concerns expressed by CEO Andy Jassy. Former government official David Sacks criticized Anthropic for allegedly valuing continuous public access to a consumer model over safety. Others viewed the government’s initial response as excessive: Francesco Bailo, an AI governance researcher at the University of Sydney, told Al Jazeera that lifting the controls suggested an admission the prior move was overreaching, and a number of security leaders signed an open letter calling for the restrictions to be removed.
Competition concerns also played into the debate. The temporary suspension arrived just as inexpensive, capable Chinese open-source models were gaining traction, and several industry leaders warned that freezing U.S. offerings effectively handed rivals time to close the gap.
Anthropic is proposing a more standardized way to evaluate the seriousness of jailbreaks. Working with partners including Amazon, Microsoft and Google, the company wants to rate each exploit on four dimensions: capability gain (how much the trick advances a user beyond existing tools), breadth (how many distinct attacks the method enables), ease of weaponization (the skill and effort required to turn it into a usable attack), and discoverability (how easy the method is to find or replicate).
For the most severe scenarios - for example, a jailbreak that could be used to attack power grids or financial systems - Anthropic says it will roll out patches as soon as the threat level is confirmed and has created a team to monitor jailbreak reports around the clock. The company also launched a HackerOne program to collect reports of new Fable 5 jailbreaks and committed to giving the U.S. government earlier access to test future frontier models before they are released widely.
Anthropic is not alone in taking precautions. Days earlier, OpenAI limited previews of GPT-5.6 to a small group that had government clearance rather than offering public access, citing similar dual-use concerns: models capable of helping defenders find and fix bugs can also aid attackers. The risk is tangible. Earlier this year Anthropic found that a prior Mythos model could locate and exploit zero-day vulnerabilities across major operating systems and browsers on demand, including a 27-year-old flaw in OpenBSD; its red team was able to transform newly disclosed bugs into working exploits in less than a day.
The immediate operational crisis has subsided, but the larger governance question remains. A June 2 executive order created a voluntary channel for companies to have frontier models reviewed before release and established a classified benchmark for what counts as a “covered” model, while explicitly stopping short of imposing a mandatory licensing regime. Fable 5 did not go through that voluntary review, so regulators turned to export controls instead - a sign that when Washington wants to act quickly on a frontier model, it still relies on ad hoc measures rather than a firm, established process.