Three days in June, in order.

On June 9, Anthropic released Claude Fable 5. It shipped with three safety classifiers: one for cybersecurity, one for biology and chemistry, and one for distillation — the practice of querying a model at scale to train a competitor on its outputs. Flagged requests aren’t refused. They fall back silently to Claude Opus 4.8, and the user is never told.

On June 10, Dario Amodei published an essay arguing that the US government should have the power to block the deployment of frontier AI models. The same day, Anthropic sent Senators Tim Scott and Elizabeth Warren a letter alleging that operators connected to Alibaba had run 25,000 fraudulent accounts through Claude.

On June 12, at 5:21 PM Eastern, the US government ordered Anthropic to cut off access to Fable 5 and Mythos 5 for every foreign national on the planet — inside the United States or outside it, including Anthropic’s own employees. Unable to verify nationality in real time, the company disabled both models for everyone, worldwide, that evening.

Forbes put the sequence plainly: “Just one day after launching Fable 5, Amodei published a major policy essay calling on the U.S. government to hold legal authority to block or reverse frontier AI models that fail independent safety testing. Two days later, the government used that authority against Anthropic.”

That reading is almost right. It is also the reason this article exists, because what the government did was not the authority Amodei asked for. It was the same power with every safeguard removed — and the instrument it traveled on has never been published, in any form, anywhere.

We covered what Mythos-class capability looked like from the outside in April. We interviewed an instance of Fable 5 on the night it was shut off. This is about who decided, and with what.

The document that doesn’t exist

Start with what can be verified, because the verification is the story.

Anthropic describes what it received as an “export control directive” issued by the US government “citing national security authorities.” It has never named the statute. Its statement that night said: “We received the directive from the government today at 5:21pm (ET). The letter did not provide specific details” about the national security concern.

Reuters, Forbes, and CNBC have each reported seeing a copy of the letter, sent by Commerce Secretary Howard Lutnick to Amodei. It has never been made public.

We checked whether anything at all had been published. Querying the Federal Register directly, we enumerated every document issued by the Bureau of Industry and Security — the agency that administers US export controls — from January 1, 2026 to today. There are 27. They concern the treatment of the United Arab Emirates, drone exports, Cambodia, anthracite coal, advanced computing license review, and routine paperwork notices. None concerns artificial intelligence, model weights, or Anthropic. A separate full-text search for “artificial intelligence model weights” from May onward returns 15 results, all unrelated — Medicare, radiation standards, pipeline safety.

This is worth stating precisely, because the distinction matters: this is not a document we failed to find. We enumerated the complete output and the set is empty. No rule. No interim final rule. No notice. No docket. No comment period. The most consequential government action against a commercial AI model in history generated no public paper of any kind.

What the mechanism was remains secondhand. CSIS, citing “media reports and discussions with people who have seen the letter,” describes it as a BIS “is informed” letter — a device that imposes a license requirement on one named company without rulemaking — and reports it may have invoked EAR § 744.22, the military-intelligence end-use provision. CSIS notes this authority has never before been used this way. If that is accurate, the government characterized a foreign national’s access to a commercial API as a military-intelligence end use. We cannot confirm it, and neither can anyone outside the room.

There is even disagreement about the letter’s existence as a letter. Three news organizations report a written document. One legal analysis, from the firm Chamberlain Hrdlicka, states that Anthropic received verbal notice with “no written order, no opportunity to remediate, and no formal findings to contest.” We can reconcile these into a plausible story — a phone call followed by a letter — but we have not verified that, so we report the conflict as a conflict.

The order that promised the opposite

Ten days before the shutdown, on June 2, the President signed Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security.” Its text is public. It directs agencies to design a voluntary framework under which developers may give the government up to 30 days of pre-release access to designated frontier models.

It also contains this sentence:

“Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement.”

Within the month, both leading American AI laboratories shipped only what the government had cleared.

We want to be careful here, because much of the coverage has not been. The executive order did not shut down Fable 5. It carries no export-control authority and cannot. The directive was a separate instrument traveling on separate powers. The two are routinely conflated and they should not be.

The point is narrower and harder to dismiss: an order disclaiming mandatory preclearance was followed, in ten days, by de facto preclearance — achieved through export-control leverage on one company and an informal request to another. Both complied. Neither process appears in the order.

And there is a detail that makes the choice of instrument look deliberate rather than improvised. A model-weights export control already exists on the books. ECCN 4E091, created by the Biden administration’s AI Diffusion Rule in January 2025, covers closed frontier model weights trained above 10²⁶ operations. It remains codified in the Code of Federal Regulations today. Commerce announced it would stop enforcing it in May 2025 — by press release, never completing the rescission rulemaking — and in May 2026 the Government Accountability Office held that the non-enforcement announcement was itself a rule that Commerce had failed to submit to Congress.

So the government had a published control over model weights, sitting unused and legally contested. It reached instead for an unpublished letter under an authority never before applied this way.

What he actually asked for

Amodei’s June 10 essay, “Policy on the AI Exponential,” is 5,878 words and its central proposal is an analogy to the Federal Aviation Administration. Frontier models, like aircraft, should undergo mandatory third-party testing, and “their release should be blocked or reversed as a threat to public safety if they do not meet high standards of safety.”

Here is the sentence the coverage quoted, in full:

“The government should have the power to block or deter deployment of the model if it is determined, in light of third-party assessment, to present unacceptable risks. This power must be scoped to the above four specific risks and there must be protective measures against political favoritism or arbitrary decisions.”

The second half of that sentence did not survive into most reporting. Neither did the legislative framework Anthropic published alongside the essay, which specifies the machinery:

“Rather than having the authority to impose remedies directly, the Agency may pursue them only by initiating a lawsuit seeking the appropriate remedies.”

“The Agency should apply a fact-based review process consistently across developers, holding all covered models of equivalent capabilities to the same standards. No developer may be advantaged or disadvantaged on grounds unrelated to the model’s evaluation record or capabilities related to the Enumerated Risk categories, and a developer may challenge remedies through an expedited judicial review process.”

Assembled, the proposal is: an act of Congress; an agency that generally cannot impose remedies itself but must go to court; expedited judicial review as a developer’s right; identical standards for models of equivalent capability; and explicit protection against political favoritism.

Two days later, Anthropic’s models were pulled worldwide by an unpublished letter, with no court, no review, no published criteria, and no equivalent action against models of comparable capability.

Every safeguard was absent. What arrived was not the proposal. It was the power the proposal was built to constrain.

The obvious objection is that Amodei might have written the essay differently in hindsight, or quietly revised it afterward. He did not. We compared all 31 Internet Archive captures between June 10 and July 17 — every one carries an identical content digest — and diffed the June 10 snapshot against the live page word by word. Both are 5,878 words. There are no differences. The essay as it stands today is the essay as published, two days before the shutdown.

One more thing about that essay, since the surrounding narrative assumes otherwise: “China” appears in it exactly once, in a passage about chip export controls. “Distillation” appears zero times.

Three laboratories, three instruments

Between May and July, the US government engaged all three American frontier labs. The instruments were not the same.

LaboratoryInstrumentEffect
Google DeepMindCooperative research agreement with CAISI, May 5No restriction reported
OpenAIA request, complied with voluntarilyPreview limited to ~20 vetted partners, 12 days
AnthropicBinding, unpublished, individually targeted directive18 days, global shutdown

OpenAI’s path is documented in its own words. It previewed GPT-5.6 to the government for roughly a month before release, then launched on June 26 to about twenty companies each individually approved. Its announcement reads:

“At their request, we are starting with a limited preview for a small group of trusted partners whose participation has been shared with the government… We don’t believe this kind of government access process should become the long-term default.”

That is the same objection Anthropic made. The difference is sequencing. Anthropic launched to the world and learned the process existed when its product went dark. OpenAI submitted first and reached the public twelve days later, intact. GPT-5.6 went generally available on July 9. OpenAI describes Sol, its top tier, as its most capable model for cybersecurity — the exact capability class cited against Fable 5.

Axios summarized the shift: “Washington is starting to treat the most advanced U.S.-developed AI models as products that need government review before they can be widely released.”

The asymmetry of instruments is documented. The cause is not. Anthropic’s public posture on AI safety has been the most aggressive of the three, and it is the only one that received a binding order; the White House’s David Sacks has said publicly that the administration asked Amodei to fix the jailbreak or pull the model and that “Dario refused,” while Anthropic’s own statement suggests it disputed the severity rather than refusing to remediate. Those accounts are incompatible and neither has documentary support. Press reporting has characterized Amodei as a political target. We are not in a position to establish motive, and we are not going to imply one by arrangement. What we can say is that three laboratories with comparable models received three different instruments, and no public criteria explain the difference.

The accusation and the evidence

The distillation classifier that shipped inside Fable 5 is worth pausing on, because of what it is bracketed with.

Anthropic’s launch post states: “We’ve previously identified large-scale attempts to extract (‘distill’) Claude’s capabilities to train competing models in authoritarian countries.” Flagged requests “will fall back to Opus 4.8.”

A commercial countermeasure — protection against competitors copying a product — shipped inside the same classifier stack as bioweapons and offensive cyber. Anthropic’s justification is safety-framed: capabilities leaking without safeguards attached. That can be true and market-protective at the same time. Note also the wording: “authoritarian countries,” not China. The hedge is theirs.

The underlying accusations are substantial. In February, Anthropic published figures: roughly 16 million exchanges through some 24,000 fraudulent accounts, broken out as DeepSeek 150,000-plus, Moonshot 3.4 million-plus, MiniMax 13 million-plus. In June came the Alibaba letter: 25,000 accounts, 28.8 million interactions between April 22 and June 5. OpenAI has made parallel claims to the House Select Committee on China.

All of it rests on internal telemetry. No forensic artifacts have been published, no logs, no third-party audit. Nothing links the weights of any Chinese model to Claude-generated data. The claim is about API access patterns; the conclusion is about what those labs trained on. The bridge between them is Anthropic’s, and it has not been substantiated publicly. DeepSeek, Moonshot and MiniMax declined to comment. Alibaba says it does not train on proprietary model outputs.

We should be direct about why we are pressing this point, since we are not clean on it.

In April we published an article arguing that Mrinank Sharma’s resignation from Anthropic was a signal about Mythos. The timeline was suggestive and subsequent events supported the conclusion. We had no sourcing for the connection itself. We ran the inference with the grammar of fact, and in June we appended a correction saying so. Being right later does not repair an unsupported bridge — that was the lesson, and it applies here identically. A pattern in access logs is evidence of a pattern in access logs. Whether it establishes distillation is a claim that requires evidence nobody has shown.

There is also a fact that complicates any reading of Anthropic as a passive subject of policy: its terms of service have prohibited commercial Claude access by Chinese-controlled entities since September 2025, nine months before the government did anything. It was not caught up in a restriction. It had been arguing for one.

When the instrument it had advocated was turned on it, Anthropic did not draw the parallel. Its June 30 redeployment post is procedural throughout and mentions neither the essay nor the irony. We found no comment on it anywhere. That is an absence we report as an absence, not as a refusal.

The second act, in dates

While this ran, the commercial map redrew itself. We will lay the dates out and let them sit, because Anthropic has attributed every one of these moves to capacity and demand, never to competition, and we have no basis to overrule that.

At launch on June 9, Fable 5 was included at no extra cost on paid plans through June 22, after which it would move to usage credits. It was always going to credits; that was in the announcement.

Of the thirteen promised days, three were delivered. The models went dark on the twelfth.

The export controls were lifted on June 30 and access returned on July 1 — nineteen days after the shutdown — with Fable included at up to 50% of weekly limits through July 7. That window was extended to July 12, then to July 19, each time announced days before expiry.

On July 9, OpenAI released GPT-5.6 generally, with Sol — its flagship — included in the $20 ChatGPT Plus subscription. Sol lists at $5 and $30 per million input and output tokens. Fable 5 lists at $10 and $50.

On July 18, Anthropic announced that Fable 5 would be included permanently in Max and Team Premium plans, at up to 50% of weekly limits. Pro and Team Standard moved to usage credits with a one-time $100 grant. The terms took effect July 20.

Two observations we are confident in. First, three last-minute extensions are not a plan; the shape of that behavior is a retreat from the credits transition, whatever caused it. Second, and more telling: an apology for nineteen days of downtime is a temporary instrument — extra credits, a longer window, a grant. What Anthropic did was permanent and structural. Companies do not repair outages by amending plan entitlements forever.

We will also correct something circulating in the coverage. Several outlets reported that a promotional usage boost expired on July 20, cutting baseline limits by 33% just as Fable’s 50% allowance arrived — making the inclusion generous on paper and smaller in practice. It is not so. Anthropic’s documentation shows the Claude Code +50% promotion running through August 19. And 33% is not an independent measurement: it is the arithmetic inverse of a 50% boost. The figure appears to be one promotion’s eventual expiry attached to a different promotion’s end date. Fable entered the plans with no offsetting cut.

The per-model cap itself is a house mechanism, not an invention. Claude Opus 4 carried a dedicated weekly allowance separate from the general pool starting in August 2025, and Anthropic confirmed as much when it announced that Opus 4.5 had “removed Opus-specific caps.” What appears to be new is the formulation: earlier carve-outs were absolute allowances in hours or tokens. We found no precedent for one expressed as a percentage of the plan.

A border that does not close

On June 13 — the day after the shutdown — Zhipu AI released GLM-5.2 as open weights under an MIT license. On July 16, Moonshot AI announced Kimi K3, a 2.8-trillion-parameter model, with weights scheduled for release on July 27. Alibaba previewed Qwen3.8-Max on July 19. DeepSeek’s V4 family has been openly downloadable since April.

Nineteen days of denial to paying customers who complied. Zero days to anyone willing to download a file.

Anthropic made the substitution argument on the first night, saying the capability at issue “is widely available from other models (including OpenAI’s GPT-5.5), and is used every day by the defenders who keep systems safe.”

The structural problem is older than this dispute. The Export Administration Regulations were built for items with serial numbers and chains of custody. A weights file on Hugging Face has neither. The control reached the only category of actor it could reach — the API of an American company — and left the rest of the ecosystem untouched.

One correction here too, because nearly every account has it wrong, including our own first reading. The directive was based on nationality, not territory. A French citizen in Ohio was covered; an American in Paris was not. No geofence resolves that. The binding constraint was identity verification, and Anthropic’s own explanation says so: it could not verify nationality in real time, so it shut everything down. Commentators compressed this into “geofencing was infeasible,” which describes a different problem than the one that existed.

What was never decided

The controls were lifted on June 30, after Anthropic shipped a classifier that it says blocks the reported technique in over 99% of cases. Lutnick’s withdrawal letter — also unpublished — cited “appropriate safeguards,” and was addressed to Anthropic’s chief compute officer, Tom Brown, rather than to Amodei. Mythos 5 returned to a set of approved US organizations. Fable 5 returned to the world on July 1.

Nothing was resolved. Anthropic never said the government had been wrong; the government never said it had been right. The redeployment post is administrative from beginning to end.

And the question underneath was left exactly where it started. When a person outside the United States sends a prompt to an American server and receives a response, has anything been exported? Traditional export control has never treated remote use of US software that way. The Harvard Law Review raised the question in June. It was never adjudicated, because the lift made it moot.

So it remains available. The letter was never published, so there is no text to challenge. No rule was issued, so there was no comment period. No court reviewed it, because there was no proceeding. The criteria distinguishing the laboratory that was shut down from the two that were not have never been stated. And it worked: within three weeks, every American frontier lab was shipping on terms the government had approved in advance, under an executive order that had promised, in writing, not to require exactly that.

The most consequential AI policy of the year is not written down anywhere. That is not an oversight in how it was made. That is how it was made.