Skip to content
Ilona Golmanstudio live · updated 30 Aug
Theme
Accent

Accent colours the marks — active tab, underline, the main button. The frame, grid lines and body text stay graphite.

Blog

Ilona Golman

Notes · AI

Nobody agrees what it does

In June the US pulled Anthropic's most powerful model off the market overnight. Then 350 security experts revolted. The fight isn't really about the model — it's that no one can agree what it can do.

22 June 2026 · 7 min read · Original essay

Written with AI tools, reviewed by me on its substance — how these are made →

On June 12 2026 the US government did something it had never done: it pulled a working AI model off the market overnight. An emergency export-control order barred foreign nationals — including Anthropic's own staff — from Claude Fable 5 and Mythos 5, written so broadly that Anthropic switched both models off for every customer the same evening. (Fable 5 is the guarded model, with classifiers that refuse high-risk cyber requests; Mythos 5 is the same model with some guards removed, sold only to vetted organisations.) One day they were the most capable models many people had; the next, gone.

The trigger was surprisingly small. Amazon researchers had found a jailbreak: ask Fable to read a particular codebase and fix the insecure code, and it would surface real vulnerabilities. The government treated that as a national-security risk. Anthropic disagreed — bluntly — saying other freely available models find the same flaws with no jailbreak at all, and that recalling a model “deployed to hundreds of millions of people” over one narrow trick would, as a standard, “essentially halt all new model deployments.”

The revolt

Two days later, on June 14, a letter went up at freefable.org. Around 350 cybersecurity executives and researchers — among them Bruce Schneier, former Deputy US CTO Ed Felten, and the founders of Bugcrowd and Veracode — asked Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross to reverse the order. They weren't arguing that the model is harmless. They were arguing that the model is not special: the same vulnerability-hunting is “replicable on GPT-5.5, Opus, Sonnet, and Kimi 2.7,” so pulling the best model out of defenders' hands helps attackers, not the public.

"[The directive] has taken the best models away from defenders, created market uncertainty, and risked America's AI leadership without any real risk to justify it."
  • Controls grounded in scientific evaluations built with industry and academia — not one lab's say-so.
  • Rules made through democratic rule-making, not an emergency order.
  • Enforcement that's transparent and fair, with time to fix problems.
  • Restrictions used only to the minimal extent necessary to keep the public safe.

The contradiction

Here's the uncomfortable part. Two months earlier, an April paper from the Cloud Security Alliance had described this same class of capability as a paradigm shift — “AI-driven offense is the new baseline,” the kind of language that sells urgency, restructuring, and training seats. Some of the names on that April alarm are on the June letter that calls the capability a commodity. Storm in spring, weather in summer.

The lazy reading is hypocrisy. The useful reading is that threat assessment bends to incentive. When the danger sells consulting and conference seats, it's a paradigm shift; when a ban freezes your market, it's nothing special. I don't think most of these people are lying in either direction. I think “how dangerous is this?” has no neutral answer when everyone you can ask has money riding on the reply.

Why this belongs in the Almanac

I keep an almanac of AI and the rules; its first issue is a dashboard of the gap between what AI can do and when the rules catch up. The usual complaint is that law is slow. This episode shows something more unsettling: the ground won't hold still. The state can recall a deployed model overnight on the strength of one narrow jailbreak. Allies scramble — at the June G7 in Évian, Macron pushed a “trusted partners” workaround to get the access back. And the experts whose job is to tell us how dangerous the thing is can't agree among themselves.

When nobody agrees what a model does, every move is a bet placed in fog. Pull it and you might be disarming your own side over a parlor trick; leave it and you might be shipping the first weapon that writes its own exploits. You won't know which until afterward. That's the real lag — not that the law is late, but that it's trying to bind a thing whose size changes with who's describing it.

  • Jun 12: the US pulls Anthropic's Fable 5 and Mythos 5 overnight — the first time it's recalled a deployed frontier model.
  • The trigger was a narrow jailbreak (read a codebase, flag insecure code); Anthropic says public models do the same with no jailbreak.
  • Jun 14: ~350 security leaders (freefable.org) demand a reversal — the capability is “commodity,” replicable on other frontier models.
  • The same capability was a “paradigm shift” in an April industry paper. The threat level tracked the incentive.
  • The lag isn't only slow law — it's that no one can agree how dangerous the model is.