U.S. Order Forces Anthropic to Block Fable 5 and Mythos 5 Access for Foreign Nationals
Anthropic has announced that it will immediately take its newest AI systems, Claude Fable 5 and Mythos 5, offline for users after receiving a U.S. government directive to cut off access for foreign nationals, whether they are located inside or outside the United States. The company said the order arrived at 5:21 p.m. ET and instructed it to suspend any usage of those models by non-U.S. persons. Anthropic called the move abrupt and said it believes the requirement stems from a misunderstanding; engineers are attempting to reinstate service as quickly as practicable. The company also noted that the export-control measure does not affect its other AI models.
According to Anthropic, regulators told the company they had been made aware of a possible technique for bypassing safeguards - often referred to as “jailbreaking” - in Fable 5. Anthropic said it examined a demonstration of that method and found it exposed a handful of previously identified, minor vulnerabilities. The firm characterized those issues as relatively simple and said other publicly available models can surface them as well without needing a special bypass.
The sudden restriction follows the recent public rollout of Claude Fable 5 and its sibling Mythos 5. Both systems are built on the same core model, but Mythos 5 has had some protective limits relaxed in certain domains such as cybersecurity. Anthropic has described Mythos 5 as having the most advanced cybersecurity analysis capabilities of any model to date; access to it is currently limited to a vetted set of cyber defenders and operators of critical infrastructure.
Anthropic emphasized that it has implemented robust safety measures to reduce the risk that its models could be misused for offensive cyber tasks. Central to that effort are safety classifiers designed to detect potential misuse - including jailbreak attempts - and prevent the primary model from returning dangerous answers.
The company explained that its cybersecurity classifier is configured to block single-turn requests that would assist with planning cyberattacks, creating exploits, or evading defenses. Anthropic said Mythos-class models are particularly adept at locating and exploiting software weaknesses, a capability that could give malicious actors a significant edge if left unchecked.
Last week, Anthropic disclosed research showing Mythos-class systems can convert newly disclosed software vulnerabilities into functioning exploits in a matter of hours - and in some cases minutes - rather than the days or weeks that would previously have been required. The company’s red team warned that these frontier models can rapidly weaponize publicly disclosed defects, shortening the window between disclosure and exploit dramatically.
Anthropic’s red team analysis warned that a single operator, with modest expense and no specialist training, could turn what used to be a month’s worth of patches into a set of working exploits in an afternoon. That assessment argues the conventional patch-management cadence - monthly releases, multi-week staged rollouts, and the lag between pre-release and stable channels - may no longer be an effective defense strategy.
To reduce risk, Fable 5 includes protections that cause cybersecurity-related queries to be answered by Claude Opus 4.8, Anthropic’s next-tier capable model, rather than by the more permissive Fable 5. The company also stated that, to date, it is not aware of any universal jailbreak technique that compromises its newest models. External red teams and internal adversarial testing, Anthropic said, have found the current safeguards to be markedly stronger than those in previously deployed systems.
At the same time, Anthropic conceded that perfect immunity to jailbreaks is unattainable: every defensive approach can be circumvented in narrowly defined contexts or requires tailored effort to adapt. The firm added that the government has so far provided only verbal evidence pointing to a possible narrow, non-general jailbreak - essentially a scenario where the model is instructed to read a particular codebase and repair software flaws.
Anthropic said it reviewed a report it believes underpins the government’s order and determined the capability shown there is already widely accessible from other models - including OpenAI’s GPT-5.5 - and is regularly used by security teams that defend systems. The company argued that, while it supports government action to prevent unsafe AI deployments, finding a limited potential jailbreak should not automatically trigger a recall of a commercially deployed model used broadly.
Finally, Anthropic urged that any statutory process for restricting AI products be transparent, equitable, technically grounded, and clear. The policy clash comes amid earlier friction with U.S. defense authorities: earlier this year the Department of Defense labeled Anthropic a “supply chain risk” after the company tried to restrict military applications of its technology. Anthropic has responded by filing two legal challenges seeking to overturn that designation.