FROM THE DESK OF THE EDITOR

August 3, 2026 | Jonathan Brown


There is a peculiar irony that only government can manufacture — the kind where a company builds its entire identity around responsible AI, proposes a framework for the very regulatory oversight that could restrain it, and then gets hit with that authority harder and faster than any of its less conscientious competitors ever will. That is the story of Anthropic in the summer of 2026. It is also a story about what happens when export control law — a framework designed for centrifuges and semiconductor lithography machines — gets applied to something that lives in server weights and API responses. And it is a story about the gap between the governance frameworks we have and the governance frameworks we need, written in real time by people who do not appear to know what they are doing. But before we get into the specifics, let us set the stage.

The Company That Wanted to Be Regulated
Anthropic has never been a typical AI lab. Founded by Dario and Daniela Amodei after they split from OpenAI, the company has staked its identity on a simple proposition: that AI development should proceed with genuine restraint, not merely the appearance of it. Their constitutional AI approach, their responsible scaling policies, their willingness to publish safety frameworks — all unusual in an industry where most players treat
safety disclosures merely as marketing collateral.
On June 10, 2026, CEO Dario Amodei published a sweeping policy essay titled “Policy on the AI Exponential.” It was, by any measure, the most aggressive regulatory proposal ever published by a major AI lab. Amodei argued that AI was advancing at a pace that “our policymaking institutions were never built for,” and that transparency-based regulations were no longer sufficient. He proposed an FAA-style regulatory framework in
which frontier AI models would undergo mandatory third-party testing before deployment, and in which the government would have explicit legal authority to “block or deter deployment” of models deemed to present unacceptable risks across four categories: cybersecurity, biological weapons, loss of AI system control, and automated research and development that could accelerate the other three.
The proposal was concrete: it would apply only to models trained above a specific compute threshold by companies with significant AI revenue or R&D spending, and it included civil penalties tied to global annual revenue and safeguards against political favoritism. It was, in short, a serious attempt to build a rules-based framework for governing the most powerful technology humans have ever created. Two days later, the government used that kind of authority against Anthropic itself.


The Shutdown
On June 12, 2026, Anthropic publicly launched its two most capable AI models: Claude Fable 5 and Claude Mythos 5. Fable 5 was the headline release — the first general-availability version of Anthropic’s Mythos model family, which the company had previously described as too powerful in cybersecurity to release publicly. Mythos 5 had fewer restrictions and was available only to vetted organizations through Anthropic’s Project Glasswing program, a trusted-access initiative for cyber defenders and critical infrastructure operators. That same evening, Commerce Secretary Howard Lutnick sent a letter to Amodei directing Anthropic to suspend access to both models by any foreign national, anywhere in the world — including foreign nationals working inside the United States, and including Anthropic’s own noncitizen employees. The directive cited
national security authorities and constituted an export-control order under the Export Control Reform Act of 2018.
Because Anthropic had no way to immediately collect and validate every user’s nationality in real time, the practical result was a global shutoff. Both models went dark for everyone. Not just foreign adversaries. Not just suspicious accounts. Everyone.
The trigger, according to reporting by Axios, was a claim by another company that it had “jailbroken” Mythos — finding a way to bypass Fable 5’s safety guardrails and access the unrestricted cybersecurity capabilities of the underlying Mythos architecture. Reporting by Semafor and The Wall Street Journal pointed to Amazon as the source of the report. Amazon, notably, is one of Anthropic’s largest investors and provides much of its
cloud infrastructure. White House AI adviser David Sacks said the administration had asked Amodei to either fix the jailbreak or take the model out of deployment, and that Amodei had refused — though Anthropic disputed this characterization, saying it was never presented with details of the alleged jailbreak and never refused to fix any issues.
Anthropic countered that the capability demonstrated in the alleged jailbreak was available from other publicly deployed models, including OpenAI’s GPT-5.5, and was routinely used by cybersecurity defenders. The company argued that a narrow potential jailbreak should not justify recalling a commercial model deployed to hundreds of millions of people, and that if this standard were applied across the industry, it would essentially halt all new model deployments for all frontier providers.
The two accounts — the government’s and Anthropic’s — have not been reconciled as of this writing. But one thing is clear: the U.S. government has, for the first time, used export-control law to shut down a widely deployed AI model.


The Supply Chain Risk Designation
The export-control order did not come out of nowhere. It was the latest escalation in a conflict between Anthropic and the Trump administration that had been building since early 2025. The root of the conflict was Anthropic’s refusal to allow its products to be used for domestic surveillance of Americans and for autonomous lethal weaponry without human oversight over targeting and firing decisions. That refusal contributed to the collapse of talks between Anthropic and the Department of Defense, which led
to Defense Secretary Pete Hegseth designating Anthropic as a “supply chain risk” — the first time that designation, historically reserved for foreign adversaries like Huawei and ZTE, had ever been applied to an American company.
President Trump then ordered federal agencies to stop all use of Anthropic’s products. A federal judge issued a temporary injunction against both actions on March 27, 2026, pausing the supply-chain-risk designation and the federal-agency ban. But the legal fight continued. Anthropic filed lawsuits challenging the designation in two federal courts. In June, Hegseth rejected Anthropic’s appeal to reassess the classification, maintaining
that the pre-deployment risks and erosion of trust justified the determination.
Hegseth reinforced the message on social media, declaring that the Department of Defense had kicked Anthropic out of its building and that every passing day proved it was the right move. The DOD’s chief information officer, Kirsten Davies, was even more pointed. She wrote that the department fully supported President Trump and Secretary Hegseth in prioritizing national security, adding: “Some things are simply more important than revenue cycles, clickbait, and pre-IPO valuation. America First. Always.”
Read that again. A senior defense official, in an official capacity, publicly taunted a private company about its pre-IPO valuation while justifying a government action that would directly harm that valuation. Whatever one thinks of Anthropic’s products or its safety posture, that statement should disturb anyone who believes in the separation of commercial enterprise and state power.

The IPO Irony
The timing of all of this is what elevates the story from concerning to something closer to alarming. On June 1, 2026 — less than two weeks before the export-control order — Anthropic confidentially filed a draft S-1 registration statement with the SEC, formally beginning the process of going public. The filing came days after a $65 billion Series H funding round that valued the company at $965 billion, with a reported $47 billion
revenue run rate.6 This placed Anthropic in a three-way IPO race with OpenAI and SpaceX, with combined potential public valuations approaching $3 trillion.
Then, eleven days later, the government effectively switched off its two most advanced products.
For institutional investors pricing the offering, the regulatory risk was no longer hypothetical. It was not a footnote in a risk disclosure document. It was a demonstrated capability of the U.S. government to shut down a company’s flagship products with almost no notice, based on a security assessment the company said was inaccurate, using a legal framework designed for physical hardware. Any underwriter building a discounted
cash flow model for Anthropic now had to incorporate a new line item: the possibility that the Commerce Department could, at any time, for reasons that may or may not withstand legal scrutiny, disable the company’s primary commercial offerings.
Davies’s crack about “pre-IPO valuation” was not just undiplomatic. It was a signal that the government understood the financial damage it was inflicting and was choosing to inflict it anyway — or, worse, was inflicting it partly because of it.

The Resolution and Its Cost
On June 30, 2026, less than three weeks after the shutdown, the Commerce Department lifted the export controls. Secretary Lutnick, in a letter to Anthropic, said the export controls were withdrawn and that a license was no longer required for the export of the Mythos or Fable models. The government had allowed Anthropic to release Mythos 5 to some “trusted” U.S. organizations, partially reversing the order, before the full lifting of
restrictions.
But the resolution came at a cost that has received far less attention than the shutdown itself. To get the restrictions lifted, Anthropic significantly strengthened the models’ safety guardrails. According to legal scholar João Marinotti, those guardrails resulted in a “collapse” of the models’ benchmark scores, demonstrating lower overall intelligence and capacity. The models were reportedly hobbled to the point that many benign queries triggered the new guardrails. In one experiment, the new Fable 5 completed only 3 of 12
tasks that would have been routine before the controls were imposed.
Let us be precise about what happened here. The government’s intervention did not just restrict access to the models. It demonstrably degraded the product. The company was forced to make its AI worse in order to be allowed to sell it. That is not security policy. That is coercion with collateral damage to the very thing being protected.


The Export Control Fallacy
The deeper problem is that export controls are the wrong tool for this job. They are a category error masquerading as policy. Export controls were designed for physical goods — uranium-enrichment centrifuges, semiconductor lithography machines, dual-use chemicals — things that must be physically shipped across borders and can be intercepted at ports of entry. The Export Control Reform Act of 2018, which the Commerce Department used here, was written with hardware in mind.
But an AI model is not a centrifuge. When a user sends a prompt to Claude and receives a response, the only thing that crosses a border is the reply. The model itself remains on Anthropic’s servers. Previous Commerce Department guidance had treated remote access to software running on U.S. servers as outside the scope of export controls.
Legal scholar João Marinotti identified two fundamental questions: whether access to the models constitutes an “export” at all, and whether the Commerce Department followed lawful procedures. The “is informed” mechanism used here is normally for narrow, company-specific notifications, not global shutdowns of widely deployed commercial products.
Beyond the legal questions, there is a practical one that should embarrass the policymakers responsible, (and conceivably would, if the particular policymakers had a sense of civic responsibility that extended beyond political loyalty.) If Mythos can genuinely exploit cybersecurity vulnerabilities at an unprecedented pace — and experts believe it can — then restricting it to government-approved American entities does not eliminate the threat. It simply removes American defensive researchers, independent security teams, and allied partners from the pool of operators who can use the capability to protect systems. Meanwhile, adversaries build equivalent capability independently, or through other means, or through other API providers in jurisdictions that do not recognize U.S. export-control orders.
Export controls work on physical hardware because physics constrains replication. They work poorly — perhaps not at all — on a capability that exists in model weights that can be copied, fine-tuned, distilled, or independently developed. The administration’s own concern about a China-linked group accessing Mythos proves the point: the capability cannot be contained by nationality-based access controls on a single company’s API.

The Strategic Paradox for Anthropic There is a cruel strategic paradox at the center of this story, and it is one that Amodei himself flagged. Two days before the export-control order, Amodei published his essay calling for the government to have the power to “block or deter deployment” of frontier AI models. The framework he proposed was careful — it included protections against political favoritism, it was scoped to specific risk categories, it required
third-party testing, it called for transparency. It was, in short, a rules-based process.
The government’s response ignored every one of those safeguards. There was no third-party testing. There was no transparency. There was no clear, rules-based process. As Brad Carson, president of Americans for Responsible Innovation, put it: the decision “appeared inconsistent with a clear, rules-based process and risked America’s lead in AI innovation.” The government, Carson said, should be able to evaluate and block advanced AI models in extraordinary situations, “but such decisions required protection from impulse and
political favoritism.”
Anthropic found itself in an impossible position. It had advocated for the very kind of government authority now being wielded against it. Challenging the order in court could undercut its own policy position. So Anthropic complied, called the episode a "misunderstanding,” and accepted a degraded product to get back to market.
The message this sends to every other AI company is unmistakable: if you build safety into your products, if you refuse to enable surveillance and autonomous weapons, if you advocate for regulation, you will be punished — not by the market, but by the state. And the punishment will come using the very regulatory framework you asked for.


The Tiered Access Problem
The resolution also created a structure that should worry anyone who cares about the future of AI access. After Anthropic strengthened its guardrails, the government allowed it to release Mythos 5 to “trusted” U.S. organizations — effectively a tiered access system in which the government controls the keys. Marinotti warned that this creates “a two-tiered AI order” in which governments condition export privileges on secret access to frontier models more powerful than anything publicly available.
It also concentrates capability in the hands of government-approved entities, excluding independent researchers, academic institutions without clearance, foreign allies, and the broader cybersecurity community that actually defends networks. The government’s own agencies had been struggling to access and understand how to implement Mythos. The solution was not to restrict access further.


The Market Verdict
The current AI landscape does not correctly price honesty. Anthropic’s safety-first positioning reads to many investors as either naive or a competitive moat, depending on who is looking. The market rewards aggression. OpenAI, less restrained in its deployment philosophy, was not subject to the same export-control action, even though Anthropic noted that the capability in the alleged jailbreak was available from other publicly deployed models, including OpenAI’s GPT-5.5. The administration’s order did not mention GPT-5.5 Cyber, another advanced vulnerability-focused model. OpenAI also jumped at and acquired lucrative defense contracts in the absence of any competition from Anthropic, who were effectively barred from bidding for federal contracts by their supply-chain-risk designation.
Indeed, OpenAI benefited substantially from Anthropic's exclusion. Hours after Hegseth's February 27, 2026 "supply-chain risk" designation, OpenAI announced its own Pentagon deal for classified-network deployment — timing Sam Altman himself later admitted "looked opportunistic and sloppy." Then in May 2026, the Pentagon finalized classified-network (Impact Level 6/7) deals with seven-to-eight vendors — including OpenAI, Google, SpaceX, and Microsoft — with Anthropic explicitly excluded amid the ongoing dispute. By July 2026, the Pentagon's own R&E chief said more than two-thirds of classified AI work had already shifted away from Anthropic to these alternative providers. This is selective enforcement and selective bidding policy wearing the clothes of national security. It reveals a tension Anthropic has been forced to embody more explicitly than any competitor: the tension between being taken seriously as a safety organization, which requires genuine restraint, and being taken seriously as a commercial enterprise, which the market rewards for aggression. Whether that is admirable or a slow strategic error depends on whether
the regulatory environment eventually rewards the bet. Right now, the verdict is genuinely uncertain.


What This Means for Cyber Governance
For the cybersecurity community, the lessons are specific and immediate.
First, the U.S. government has now demonstrated that it can and will use export-control law to shut down AI services in real time. This is a precedent. It will be cited. And it will shape how every frontier AI company thinks about deployment, about safety disclosures, and about cooperation with government. Second, the nationality-based access model is fundamentally broken for AI. The idea that you can restrict access to a model based on the citizenship of the user, when the model is accessed via API and the capability can be replicated or independently developed, reflects an obsolete understanding of how software capabilities propagate. Cyber governance needs a new model — one that accounts for the reality that AI capabilities do not respect borders, that model weights can be copied, and that restricting one company’s API does not eliminate the underlying capability. Third, the benchmark collapse matters. According to João Marinotti’s reporting, the guardrails required to satisfy the government resulted in a demonstrably degraded product. If accurate, the government’s intervention did not make anyone safer. It made the tool worse. A less capable defensive AI does not protect networks better. It protects them worse. The government’s own cyberdefense agencies were counting on Mythos to support federal cyberdefense operations. By forcing Anthropic to hobble the model, the government may have degraded the very capability it was simultaneously trying to secure for its own use. Fourth, the absence of due process is the real scandal. The export-control order was unilateral, secret, open-ended, and global. It bypassed the traditional process for controlling dangerous technologies — the one that involves multiple agencies, public comment, coordination with allies, and Federal Register publication. The “is informed” mechanism used here was designed for narrow, company-specific notifications, not for global shutdowns of widely deployed commercial products. Brad Carson was right: such decisions require protection from impulse and political favoritism. They did not get it.


The Road Ahead
The Anthropic affair is not over. The lawsuits challenging the supply-chain-risk designation are still working through the courts. The D.C. Circuit Court of Appeals is set to address whether the executive branch has the authority to apply a classification historically reserved for foreign adversaries to a domestic American company. During oral arguments in March, a panel including two Trump appointees suggested they were likely to grant extensive powers to the executive branch to designate domestic firms as supply-chain risks, though subsequent orders prohibiting government use of a company’s products could still be subject to legal challenge.
Meanwhile, Anthropic is heading toward an IPO with a risk profile that no financial model can fully capture. The company that asked to be regulated has been regulated, but not in the way it asked for, not through the process it proposed, and not with the safeguards it insisted on. The government did not use the careful, FAA-style framework Amodei envisioned. It used a sledgehammer designed for a different era and a different kind of technology.
Responsible AI governance requires transparent rules, due process, and reciprocal limits on state power. It requires a framework designed for the actual characteristics of AI, its replicability, its borderless propagation, its dual-use nature, rather than one designed for physical goods that can be stopped at a port. And it requires a government that understands the difference between partnering with industry to manage risk and using regulatory authority as leverage against companies that decline to enable surveillance and utonomous
weapons.
What happened to Anthropic this summer was not governance. It was coercive procurement policy wearing the clothes of national security. And if it can happen to the company that literally asked for regulation, it can happen to anyone. The question now is whether the regulatory environment will eventually reward the companies that took safety seriously, or whether the lesson the market learns from the summer of 2026 is that
restraint is a liability and cooperation with the state is a trap. The answer will shape the architecture of digital power for decades to come.
This editorial reflects the views of the editorial board of Border Cyber Group.

Sources

Anthropic, “Policy on the AI Exponential,” June 10, 2026.

Nextgov, “Anthropic suspends top AI models after U.S. export control order,” June 13, 2026.

Forbes, “Anthropic Disabled Fable 5 And Mythos 5 After A U.S. Export Control Order, Here’s What Happened,” June 16,

Forbes, “Anthropic Disabled Fable 5 And Mythos 5 After A U.S. Export Control Order, Here’s What Happened,” June 16,
2026 (citing Axios and Semafor reporting).

Politico, “Hegseth doubles down on Anthropic’s security risk designation,” June 4, 2026.

Reuters, “Anthropic moves toward IPO, stepping up race with OpenAI,” June 1, 2026.

Reuters, “US removes curbs on Anthropic’s latest Fable and Mythos AI models,” June 30, 2026.

João Marinotti, “Legally or not, the US government is controlling global access to the world’s most powerful AI,” The Conversation, July 21, 2026.