On Friday, June 12, 2026, at 5:21 PM East Coast time, Anthropic received a letter from the United States Department of Commerce. A few hours later, two of the most advanced artificial intelligence models in the world — Claude Fable 5 and Mythos 5 — were offline for hundreds of millions of people. Italians included. No advance notice, no detailed explanation, no appeal. This isn’t an episode of Black Mirror: it happened yesterday, and it says something uncomfortable about who really controls the digital tools we use every day.


What happened, step by step

On June 9, 2026, Anthropic had launched Fable 5 and the underlying model Mythos 5, presented as the most capable systems the company had ever released publicly. Three days later, on June 12, the letter arrived: an export control order requiring the company to immediately suspend access to the two models for “any foreign national, inside or outside the United States, including Anthropic’s own foreign employees.”

The criterion is nationality, not geographic location. A non-American engineer working in the San Francisco offices falls under the ban exactly like a user in Milan. Since Anthropic cannot verify every user’s citizenship in real time, it did the only thing that guaranteed compliance: it shut the models down for everyone, worldwide. The other models — such as Claude Opus 4.8 — remain accessible. On June 13, the company publicly confirmed the deactivation.


The technical pretext: a jailbreak that doesn’t hold up

In the letter, the government did not put the details of the “national security threat” in writing. Verbally, officials explained that they had become aware of a technique to bypass Fable 5’s safeguards and unlock its offensive cybersecurity capabilities — in practice, getting the model to analyze code in order to find its vulnerabilities.

Anthropic reviewed the demonstration and responded without mincing words: it was a narrow, non-universal jailbreak that essentially amounts to asking the model to read a codebase and flag its flaws. The vulnerabilities identified were already known and relatively trivial, and the same result — the company argues — can be obtained with freely available competing models, including OpenAI’s GPT-5.5, which is subject to no export control at all.

“We disagree that the discovery of a potential narrow jailbreak should be grounds for withdrawing a commercial model deployed to hundreds of millions of people. If this standard were applied across the industry, it would effectively block every new model for every provider.”

Hard to argue with on technical grounds. But, as so often happens, the logic behind the order does not appear to be technical.


The Axios scoop: a political order, not a security one

According to Axios’s reconstruction, the letter bears the signature of Commerce Secretary Howard Lutnick and was prepared with the Bureau of Industry and Security (BIS), the office that manages export controls on sensitive technologies. Still according to Axios, the decision reportedly took shape after another company claimed to have succeeded in jailbreaking Mythos. And one detail weighs more than all the others: the administration allegedly first tried to convince Anthropic to postpone the launch of the new models, and only after being refused did it send the export control letter.

If that’s the picture, the order looks less like a national security measure and more like a lever of regulatory pressure against a company that refused to bend. It’s how many industry observers read it: a tool created to control the export of military technologies, used in practice as an instrument of moral suasion against a commercial software provider.


The knot that touches your privacy: data retention

There’s an aspect of this affair that hits close to home for anyone concerned with data protection. To defend precisely against jailbreaks, Anthropic had imposed on Fable and Mythos a mandatory 30-day retention of user data — a policy meant to detect and mitigate abuse, but one that also means your conversations with the model are retained and analyzed for longer than usual.

It’s the classic paradox of centralized security: to make a system “more secure” against malicious use, you make it less private for everyone. The user doesn’t get to choose: either you accept data retention, or you don’t use the model. And when a government order then arrives, that very data — and those very models — become a lever in the hands of whoever holds jurisdiction.


Why it should worry even those who don’t use AI

Beyond the clash between Anthropic and Washington, the real question is a different one: on what infrastructure are we building our digital lives?

This episode demonstrated, with brutal clarity, that an American company can be forced — within hours, with a single letter — to cut off access to a service for hundreds of millions of people around the world. Without a law being voted on, without a transparent process, without notice. The mechanism used, the Export Administration Regulations (EAR), was created to control the export of chips, missile components, and nuclear materials. Today it’s being extended to AI software, treated as if it were munitions — the same logic as the restrictions on GPUs to China, now applied to a product used by private citizens.

There’s also an irony worth reflecting on: Anthropic built its brand by emphasizing how powerful and potentially dangerous its models were, to position itself as the “responsible” company in the field. That framing backfired: if you describe your product as a weapon, sooner or later a government will take you at your word.


The lesson: diversify and don’t depend

For anyone who follows privacy and digital sovereignty, the pattern is familiar. Centralized services — cloud, messaging, AI models — are always subject to the jurisdiction of whoever controls them. When that power is exercised, the end user has no say in the matter. The concrete implications for us Europeans are threefold:

  • any AI service based on US infrastructure can be shut off by an administrative act;
  • no contractual clause truly protects the user in these scenarios;
  • dependence on a single provider is always a business-continuity risk, on top of a privacy one.

The answer is not to give up AI, but to diversify: to favor, where possible, open-source and self-hostable solutions, and not to build critical processes on platforms over which you have no control. It’s the same philosophy as self-custody in Bitcoin and self-hosting your own data — whoever holds the keys, owns the service.


Conclusion

The American government has shown that it can switch off a global AI model in the time it takes to write a letter. Anthropic complied, formally dissenting but effectively obeying, and millions of users — Europeans included — found themselves staring at an error screen. In a world where artificial intelligence is increasingly woven into everyday productive infrastructure, the question “who controls the model?” stops being academic. It’s a matter of digital sovereignty. And today, for many of the tools we use, the honest answer is: not us.


Sources: