How an Export Control Rule Reaches an AI Model Running in a US Data Center
What the directive on Fable 5 and Mythos 5 says, how deemed-export law works, and the 1991 precedent. Sourced to primary documents.
How an Export Control Rule Reaches an AI Model Running in a US Data Center
What the US export control directive on Fable 5 and Mythos 5 says, the 1991 precedent, and the AI laws now taking effect. Sourced to primary documents.

Frederick, Maryland
A note on sourcing: this account relies only on primary documents, the companies’ and governments’ own published texts. Where a fact is known only from press reporting attributed to unnamed officials, it is left out.
What happened
On Friday, June 12, 2026, Anthropic disabled public access to its two most capable AI models, Claude Fable 5 and Claude Mythos 5. In its statement, the company said it received an export control directive from the US government at 5:21pm Eastern that day, citing national security authorities. Fable 5 had launched three days earlier, on June 9. Anthropic said access to its other models, including Opus 4.8, was unaffected. The directive and the letter conveying it have not been published; the account that follows is drawn from Anthropic’s own statement and its model pages.
What the directive does
The directive covers any foreign national, whether outside the United States or inside it. Under US export law, releasing controlled technology to a foreign national counts as an export even when it happens entirely within the country, a category known as a deemed export. Anthropic said the order reached foreign nationals everywhere, including its own foreign national employees, and that the only way to comply at the scale of its user base was to disable both models for every customer.
The stated trigger
Anthropic said the letter gave no specific details of the national security concern, and that its understanding was that the government believed someone had found a way to jailbreak Fable 5. The company said it reviewed a demonstration of the technique, found that it surfaced a small number of previously known, minor vulnerabilities, and that other publicly available models could find the same issues without any bypass. Anthropic described the technique as asking the model to read a specific codebase and fix software flaws. It said the only evidence it had received was verbal, and it identified OpenAI’s GPT-5.5 as a publicly available model with the same documented capability. Anthropic said it disagreed that a narrow potential jailbreak justified recalling a model in wide deployment, and that the same standard applied across the industry would, in its view, halt new model releases by all frontier providers.
In its launch post for the two models, Anthropic had stated that perfect jailbreak resistance is not currently possible for any provider, that no tester had found a universal jailbreak for Fable during pre-launch testing, and that it required 30-day retention of Fable data specifically to detect and respond to jailbreak attempts.
A precedent from 1991
The treatment of software as an export-controlled item has a direct antecedent. In 1991 a programmer named Phil Zimmermann wrote an email encryption program called Pretty Good Privacy, or PGP. In testimony to the US Senate in 1996, Zimmermann said he wrote and released PGP in part because of Senate Bill 266, a 1991 measure that included a non-binding resolution stating that providers of secure communications equipment should ensure the government could read the plaintext of encrypted messages. He said he released PGP as freeware in June 1991 because he wanted cryptography available to the public before it could be restricted, and that it then spread internationally.
For readers who were not online then, the legal context is the key fact. Strong cryptography was classified as a munition. Encryption above a certain strength sat on the United States Munitions List, and exporting it required a license under the regime that governs weapons. There was no app store and no GitHub; software moved on floppy disks and over university networks.
In 1993 a federal grand jury opened an investigation into whether Zimmermann had violated the Arms Export Control Act by allowing PGP to travel abroad. During the investigation, MIT Press published the complete PGP source code as a printed book, PGP: Source Code and Internals (1995). Printed matter could be exported where software on a disk could not, so the book could be carried out of the country legally and, abroad, scanned and compiled back into working software.
A separate case addressed the constitutional question. Daniel Bernstein, a mathematics graduate student at Berkeley, wanted to publish a cipher he had written along with a paper and its source code, and was told he would first need to register as an arms dealer. With the Electronic Frontier Foundation as counsel, Bernstein sued. In Bernstein v. United States Department of State, 922 F. Supp. 1426 (N.D. Cal. 1996), Judge Marilyn Hall Patel held that source code is a form of expression protected by the First Amendment.
The investigation into Zimmermann closed in January 1996 with no charges. In his own announcement of the outcome, Zimmermann quoted the Assistant US Attorney’s letter stating that he would not be prosecuted and that the investigation was closed. Later that year President Clinton signed Executive Order 13026, moving commercial encryption from the Munitions List to the Commerce Control List, a less restrictive regime administered by the Commerce Department.
The closest AI-specific precedent
A more recent rule, built for AI, controls model weights rather than deployed services. In January 2025 the Commerce Department’s Bureau of Industry and Security issued the Framework for Artificial Intelligence Diffusion. It created a control category, ECCN 4E091, for the weights of advanced closed-weight models trained above a compute threshold of 10²⁶ operations, and set licensing requirements for exporting those weights. The rule included a carve-out: deemed exports to permanent regular employees of companies headquartered in the United States or other top-tier countries did not require a license. The June 12, 2026 directive differs in scope. It names foreign national employees, applies to two models already released to the public, and operates as a one-off order rather than through that standing weights-licensing framework.
California SB 53 and the reports filed under it
California’s SB 53, the Transparency in Frontier Artificial Intelligence Act, took effect January 1, 2026. It applies to developers of frontier models, defined as foundation models trained using more than 10²⁶ operations, and imposes the heaviest obligations on large frontier developers. Under the statute, a large frontier developer must publish a frontier AI framework on its website describing how it assesses and mitigates catastrophic risks; must publish a transparency report when it deploys a new or substantially modified frontier model; and must report critical safety incidents, which under the Act are submitted to the California Office of Emergency Services. The Act adds whistleblower protections and civil penalties enforced by the Attorney General.
The frameworks published in connection with the law are available directly:
- Anthropic, Frontier Compliance Framework, announced December 19, 2025 in a post describing it as the company’s SB 53 compliance framework.
- OpenAI, Frontier Governance Framework (PDF), published May 2026, which OpenAI states maps its practices to California’s Transparency in Frontier AI Act and the EU AI Act’s Code of Practice.
- Google DeepMind, Frontier Safety Framework, the company’s frontier AI framework, most recently updated in April 2026.
Transparency reports under SB 53 take the form of the model documentation, often called system cards, that developers publish when a frontier model is deployed. Critical safety incident reports go to the state rather than to a public repository, so those filings are not generally available to read.
Other AI laws now in effect or arriving
In the European Union, the AI Act is phasing in. Per the European Commission’s implementation timeline, obligations for general-purpose AI models began applying in August 2025, the bulk of the Act including obligations for high-risk systems applies from August 2, 2026, and providers of general-purpose AI models already on the market before August 2025 have until August 2, 2027 to come into full compliance. The Act sets maximum penalties of 35 million euros or seven percent of global annual turnover.
Among US states, New York’s RAISE Act, amended in early 2026 to align with SB 53, takes effect January 1, 2027. Texas’s Responsible Artificial Intelligence Governance Act took effect in January 2026. Colorado’s AI Act is set to take effect June 30, 2026. (Primary text for each is available from the respective state legislature.)
At the federal level, on December 11, 2025 the White House issued the executive order Ensuring a National Policy Framework for Artificial Intelligence, which directs federal agencies to identify and challenge state AI laws, creates an AI Litigation Task Force, directs the FTC to issue a policy statement on preemption, and conditions certain federal funding on states not enforcing conflicting AI laws. On June 2, 2026 the White House issued Promoting Advanced Artificial Intelligence Innovation and Security, which directs agencies to create a voluntary process for developers to submit covered frontier models to the government for cybersecurity review up to 30 days before release (fact sheet). A separate bipartisan House discussion draft, the Great American Artificial Intelligence Act, released in June 2026, proposes a three-year preemption of state laws regulating AI model development; it is a discussion draft and has not been enacted.
Sources (primary documents)
The directive and the models
- Anthropic, “Statement on the US government directive to suspend access to Fable 5 and Mythos 5”: https://www.anthropic.com/news/fable-mythos-access
- Anthropic, “Claude Fable 5 and Claude Mythos 5” (launch and status page): https://www.anthropic.com/news/claude-fable-5-mythos-5
1991 cryptography precedent
- Philip Zimmermann, testimony to the US Senate, June 26, 1996: https://www.mit.edu/~prz/EN/essays/Testimony.html
- Philip Zimmermann, announcement that the case was dropped, January 12, 1996 (quoting the US Attorney’s letter): https://www.mit.edu/~prz/EN/news/PRZ_case_dropped.html
- Philip Zimmermann, PGP: Source Code and Internals, MIT Press, 1995 (printed source code)
- Bernstein v. United States Department of State, 922 F. Supp. 1426 (N.D. Cal. 1996) (source code as protected speech)
- Executive Order 13026, Federal Register, November 19, 1996 (moving commercial encryption to the Commerce Control List): https://www.govinfo.gov/content/pkg/FR-1996-11-19/pdf/96-29692.pdf
2025 BIS export-control rule
- Bureau of Industry and Security, “Framework for Artificial Intelligence Diffusion,” Federal Register, January 15, 2025: https://www.federalregister.gov/documents/2025/01/15/2025-00636/framework-for-artificial-intelligence-diffusion
California SB 53 (statute and published reports)
- SB 53 statute, California Legislature: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260SB53
- Anthropic, Frontier Compliance Framework: https://trust.anthropic.com/resources?s=eorilovp4wxk38nxbi7k3&name=anthropic-frontier-compliance-framework
- Anthropic, “Sharing our compliance framework for California’s Transparency in Frontier AI Act,” December 19, 2025: https://www.anthropic.com/news/compliance-framework-SB53
- OpenAI, “OpenAI’s Frontier Governance Framework,” May 2026: https://openai.com/index/openai-frontier-governance-framework/ (PDF: https://cdn.openai.com/pdf/e37d949b-8c9f-4d76-b99e-4272f4631a7e/openai-frontier-governance-framework.pdf)
- Google DeepMind, “Frontier Safety Framework” (updated April 2026): https://deepmind.google/blog/strengthening-our-frontier-safety-framework/
EU AI Act
- European Commission, AI Act regulatory framework: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- European Commission AI Act Service Desk, implementation timeline: https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act
US federal executive orders
- “Ensuring a National Policy Framework for Artificial Intelligence,” December 11, 2025: https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/
- “Promoting Advanced Artificial Intelligence Innovation and Security,” June 2, 2026: https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/ (fact sheet: https://www.whitehouse.gov/fact-sheets/2026/06/fact-sheet-president-donald-j-trump-promotes-advanced-artificial-intelligence-innovation-and-security/)
Items deliberately omitted: claims that appeared only in press reports citing unnamed officials. The full primary text of the New York, Texas, and Colorado statutes is available from each state legislature; the Great American Artificial Intelligence Act is a House discussion draft, not enacted law.
By Joshua McDonald on June 14, 2026.
Exported from Medium on August 26, 2026.
Reader discussion