ai-cybersecuritytrade-pressNewsThe Broadside1 min read

Commerce lifts Anthropic Fable 5, Mythos 5 export controls

The administration backed away from a hard export block and replaced it with voluntary access, testing, and information-sharing promises.


TL;DR

Inside Cybersecurity reports that Commerce Secretary Howard Lutnick withdrew June 12 export controls on Anthropic’s Fable 5 and Mythos 5 after Anthropic agreed to detect security risks, coordinate with the U.S. government on releases and report malicious activity. Fable 5 is slated for global availability July 1; Mythos 5 access has been restored for selected U.S. organizations. The affected audience is less procurement than policy: agencies are still building a voluntary frontier-model review process while individual approvals already move.

Commerce’s reversal gives Anthropic a path to release Fable 5 globally and restore limited Mythos 5 access without waiting for the Trump administration’s frontier-model review machinery to mature. According to Inside Cybersecurity, Lutnick’s June 30 letter withdrew the controls imposed in a June 12 letter after Anthropic agreed to proactively address model security risks, work with the government on protocols and standards for Mythos, Fable and future models, and notify the government of malicious activity.

That is the operational shift. Fable 5 moves to Claude Platform, Claude.ai, Claude Code and Claude Cowork on July 1, while Mythos 5 returns only for a set of U.S. organizations cleared June 26. Anthropic says it will keep coordinating with the government to expand Mythos access to domestic and international partners in Project Glasswing.

The policy story is less tidy. The same administration that issued a voluntary June 2 executive order for government benchmarking of frontier AI models with advanced cyber capabilities first used export controls that effectively froze Anthropic’s models, then lifted them in exchange for collaboration commitments. Anthropic is now offering expanded pre-release access for designated government partners, information sharing on jailbreaks and misuse patterns, and participation in the interagency cybersecurity vulnerability clearinghouse referenced in the order.

For agencies and contractors watching AI procurement, this is not a new mandatory compliance regime yet. It is a live negotiation over who gets to inspect frontier models before release, how fast those models can reach defenders, and whether voluntary commitments will be enough when a model’s vulnerability-discovery capability makes it both a defensive tool and an export-control problem.


Published ·Deep Fathom