The passport test, the kill-switch, and the restore-switch — what the Fable ban really says. A CloudDon Field Note, June 30, 2026.


[Generated using Claude]


Everyone spent two years arguing about when AGI shows up. It showed up in June, just not the one on the slides :).

The merits of the Fable 5/ Mythos 5 export ban were always thin, and the process was even worse. But the recall was never the story, and Friday made the real one plain. On June 26, the same government that switched Mythos off worldwide switched it back on, name by name, for a set of Anthropic-vetted entities and reserved the right to edit that list whenever it likes. Fable, the safer model built for the public, stays dark. OpenAI’s GPT-5.6 shipped the same day on the same leash.

The kill-switch grew a twin: a restore-switch, operated from Washington.

So here is what actually arrived this month. Not artificial general intelligence, but its gated cousin — Artificial ‘Gated’ Intelligence.

Where the access to the frontier is a list, and the real question is whether you are on it. For a non-US builder, your passport is the first filter.


Where the dial sits today

The standoff broke partway on Friday, and the weekend didn’t move it any further. Little more than two weeks into this saga, here is the status.

  • Mythos 5: partially restored. In a letter dated June 26 to Anthropic’s chief compute officer, Tom Brown, Commerce Secretary Lutnick determined the safeguards were adequate to let certain trusted partners back on the model. Access returns for roughly 100 US organizations that run and defend critical infrastructure — government agencies and Fortune 500 companies. Since the initial list, more entities are expected to be provided access to Mythos through the vetting process.
  • The list is the regime, but two hands hold it. Anthropic does the actual vetting: partners clear its Project Glasswing security bar, which is chosen based on the concentration of risk, and are admitted to invitation-only cohorts. What the June 26 letter bolted on is a federal gate above that one: Lutnick approved the annex and reserved the right to amend the approved-partner list at any time, and to adjust the terms as circumstances change. So the vetting authority (Anthropic) and the on-off authority (Washington) are two different actors, and collapsing them is the easy mistake. This is not a one-time grant. It is a standing dial, and the hand on the switch is in Washington.
  • Fable 5: still dark. The letter does not cover Fable, the safer, general-use model. The weekend came and went with no restoration — every consumer, API developer, Claude Code user, and international subscriber is still locked out worldwide.
  • GPT-5.6: gated too. OpenAI limited its new model to roughly 20 government-approved companies at Washington’s request, broader release promised “in the coming weeks.” The regime is no longer Anthropic-specific.
  • Congress got nothing. The bipartisan House letter (Liccardo, Obernolte, Lieu, Franklin) demanded the legal basis for the controls by June 26. Commerce revised the license instead of publishing its reasoning. Four days past the deadline, the written justification is still undisclosed, and the silence is its own answer.

Now read the inversion, because it is the whole tell. Mythos is the more powerful model, with fewer output safeguards. Fable carries the classifiers that block high-risk cyber and bio output, and Fable was built for the public. Washington brought back the powerful one for vetted defenders and kept the safer one offline. If this were about an unsafe model, you would restore the safeguarded version first. Restoring Mythos-to-defenders-first tells you it was never about safety. It was about who holds access.

The trigger, told straight: three stories, one switch

The three triggers to this episode tell three different stories, but all point to the same kill switch.

  • The jailbreak. Anthropic’s own account is that the government’s evidence is verbal, narrow, and non-universal. It comes down to asking the model to read a codebase and fix its flaws. Moussouris confirmed the mechanism: ask it to “review code for security issues” and it refuses; rephrase as “fix this code” and it complies, and a few manual steps turn the output into test scripts. That is the defenders’ find-fix-test loop. The same capability ships in GPT-5.5 and other public models carrying no such controls. As the basis for a global recall, that is thin. And it was reportedly first flagged to Washington by Amazon CEO Andy Jassy, Anthropic’s largest investor, rather than by government red-teaming. Sit with that one.
  • The capability shock. Sen. Mark Warner quoted NSA Director Gen. Joshua Rudd telling a June 11 Senate briefing that Mythos, in a red-team exercise, autonomously breached nearly all of the NSA’s classified systems within hours. It went viral as “AI hacked the NSA.” Then it deflated. On June 24, Reuters and AP confirmed that the test was conducted under Project Glasswing as a sanctioned defensive exercise, and a US official clarified that Mythos identified vulnerabilities within hours but did not necessarily exploit them.
  • The foreign-access concern. This one fits the shape of the order. Foreign nationals targeted; domestic/ government access preserved. That points to diversion, not capability. Reporting ties the White House alarm to Anthropic widening Glasswing's access to a partner too closely linked to China (reportedly SK Telecom), with Lutnick citing the risk of the models falling into the hands of Chinese or Russian military intelligence. The US is reportedly readying Mythos for its own offensive operations. An asset you intend to wield is exactly the one you move to deny an adversary.

Here’s my read: Friday adjudicates between the three. The model came back for vetted US cyber defenders — not the general public, not foreign nationals. That is the move you make when the worry is who has access, not whether the model is safe. The third story was always the best fit. The remedy just confirmed it.


Five things the switch means for a non-US builder

1. The kill-switch grew a twin

Before June 12, “what if Washington switches your model off” was a hypothetical on a risk slide. Then it became a documented action with a fuse measured in hours, hitting AWS Bedrock, Google Cloud, Microsoft Foundry, Snowflake, and the direct API all at once. No carve-out for regulated industries. Friday bolted on the other half of the machine: the same authority that pulled the model handed it back to a named list, and kept the pen. So the precedent is not just that access can be revoked. It is that access is cleared, name by name, and adjustable at will. The precedent is the deliverable, not the recall. Both switches now exist. Both have been pulled. The dial stays in one hand.

2. The annex is the new perimeter

Bifurcation stopped being a forecast on Friday and grew an annex. Mythos came back for a hundred-odd vetted US critical-infrastructure orgs, listed, and for no one else. Foreign nationals are wholly excluded, including Anthropic’s own non-citizen staff. The gate is now two-layered: who you are (a US person) and which entity you belong to (a listed one). The July 8 identity-verification rollout is the next turnstile, aimed at individual US users. Fable-for-the-public sits behind all of it. The steady state is not “ban lifted.” It is a frontier you reach through a clearance, with your nationality checked at the door.

3. The diffusion paradox: the switch leaks

Export controls bite the closed-model layer. Open-weight and Chinese frontier models sit entirely outside their reach, and the same “fix this code” capability is available from every one of them. So a control meant to deny foreign nationals the capability mostly reroutes them to models such as Llama, Mistral, DeepSeek, and Qwen. The migration already started — to open-weight models such as GLM-5.2 and Kimi K2.7. The controls accelerate the exact diffusion they exist to stop. And the gap is closing on the clock: on June 28, Zhipu AI — the Tsinghua spinout behind the GLM series — reported its latest model matches Claude Mythos on security bug-detection benchmarks, the exact capability class the ban was built to contain. Sixteen days from recall to claimed parity. If Zhipu opensources it the way GLM has shipped before, the controlled capability is free to every actor the controls were meant to lock out, which both validates the threat and guts the remedy. Please note that the parity claim relies on Zhipu’s own benchmarks via a secondary aggregator and should be treated as unverified pending independent testing. Kate Koren of CSIS said the same of Friday’s order: a practical interim step that leaves the wider-release problem unsolved, and the longer it lasts, the more room China has to close the gap. For an India-originated, open-weight-fluent shop, that isn’t a threat. It’s a tailwind.

4. India isn’t on the list, and the blank is the signal

The off-ramp is no longer a proposal — it’s operating. Friday’s first wave of restored access went to US organizations only; allied expansion is unscheduled. European officials and other allies are already openly unhappy at their new dependence on Washington’s calendar. Austria’s digitalization secretary went so far as to write the EU Commission on June 28, urging member states to explore hosting Anthropic inside the bloc, and everyone else, governments, companies, consumers, is in the dark on when, or whether, they get in. The “trusted partners” scheme that frames allied access took shape around the June 17 G7 in Évian, the working lunch where Amodei pitched a US-led coalition — and it is G7-centric by construction. India is not a G7 member. It was in the room, though, as an outreach partner, with India’s Sarvam at that AI lunch alongside the frontier labs — but a seat at the lunch is not a seat on the list. India still sits outside wave one, on neither the citizenship route (US persons) nor automatically the allied one, and Washington has already turned down the UK’s bilateral plea for a carve-out, a close ally’s one-country ask, refused.

That blank is the finding. India’s route to frontier US-model access is an unanswered bilateral question — which is the single strongest argument for pressing its own access terms and its own indigenous, open-weight capability, rather than booking US-frontier availability as durable infrastructure. I don’t anticipate that question getting answered in India’s favor by accident.

5. The real takeaway is jurisdictional, not technical

Model access is now a procurement variable. It sits next to accuracy and cost: which government can switch this off, and on what terms. Friday sharpened it — US incorporation is no longer enough, because access now runs entity-by-entity through a list that a single official can rewrite.

The defensible posture has four parts, in order. An abstraction layer over providers. Real dual-sourcing in the critical paths. An open-weight fallback you have actually run in production, not just benchmarked. And a standing assumption that any single US frontier model can vanish, or be rationed, on a directive. Standard contracts and force-majeure language never anticipated an instant government-mandated cutoff. Explicit regulatory suspension and fallback clauses are now the baseline. Period.


The other edge: the switch punishes candor

A second dynamic runs underneath, and it’s aimed at the labs. This ban punishes disclosure. Anthropic called Mythos a near-munition, shipped unusually honest system cards, and imposed 30-day retention because the model was capable enough to need watching. That transparency became the legal predicate for its own recall. The cyber researcher Peter Girnus put it best: market your product as a munition in every release, and a government eventually takes you at your word. Anthropic, he said, “wrote the legal predicate themselves and called it a brand.” The lesson every lab just filed away is blunt: disclosure is an attack surface.

But the “Anthropic was singled out” reading is dead. The same day Mythos came back under guard, OpenAI accepted the same leash on GPT-5.6, government-approved partners only. OpenAI doesn’t pretend to like it — it said this kind of access process shouldn’t become the long-term default, because it keeps the best tools from the developers and defenders who need them, and it framed compliance as the fastest road back to broad release. Like it or not, both labs complied. This isn’t a grudge against one company anymore. It’s the shape of the regime, and the leashes are being fitted across the industry at once.


The CloudDon View

Predictions

The resolution came selectively, not clean: Mythos is available through gated access, Fable access is still in the dark. The pull-restore-amend sequence ran end-to-end. Gate access went industry-wide the same day, with OpenAI’s GPT-5.6. And demand began leaking to open-weight and Chinese models, with Zhipu claiming Mythos parity by June 28. They’re the floor the rest of the call stands on. Here’s what I’d expect to happen within the next twelve months.

  • The lever gets pulled again. Give it twelve months before the full sequence — revoke worldwide, restore to a named list, keep the pen to amend it — runs a second time, on a different lab and a different model. Friday didn’t end the precedent. It productized it.
  • Fable-for-the-public is the last domino. The public model returns after the defenders and after the verified individuals, not before. The July 8 identity gate ships on or near schedule, and a US citizen clears to Fable before a foreign national sees it at all. The general user was never first in line. They’re the end of it.
  • The gate travels up the stack. Clearance- and citizenship-gating doesn’t stay at the base-model layer. It moves up the stack into the coding agents, the vertical apps, the enterprise platforms built on the frontier tier. Recent focus on learning loops/ agents further increases the likelihood of this prediction. The passport check moves to wherever the capability lands.
  • India gets no clean seat in 2026. No citizenship route and no automatic allied one; India isn’t in the G7, and Washington already refused even the UK’s single-country ask. So expect Indian frontier access to behave the way it is — delayed, conditional, or absent. Plan around that now, not after the next abrupt cutoff.
  • Disclosure norms contract, industry-wide. Labs say less about dangerous-capability evals once candor reads as an attack surface, and the quiet EO pre-brief becomes the template that replaces the public system card. This is the call I hold loosest; it’s the hardest to falsify. Watch two things — the August 1 EO frontier-model framework deadline, and whether the next two system cards say more than the last, or less.

Recommendations

  • For non-US builders and CTOs. Treat single-provider frontier dependency as a continuity risk on par with a region outage. Build the abstraction layer and the tested open-weight fallback now. Not after the next 5:21 pm ET on a Friday.
  • For investors backing non-US AI-native companies. Underwrite jurisdictional exposure explicitly. A portfolio company whose core loop is wired to one US frontier API carries a political beta; it is almost certainly not pricing. After Friday, even a US-incorporated entity carries it, because access runs through a list that one official can rewrite. Favor architectures and teams that treat model access as swappable rather than sacred.
  • For Indian policy makers. Used early, the ambiguity is a card to play, not just exposure to absorb. Press for a defined access framework bilaterally — and fund indigenous and open-weight capability, the hedge that needs no one’s permission to switch on.
  • For the labs, collectively. The disclosure dilemma is everyone’s now, as OpenAI learned Friday. The industry needs a shared safety-disclosure norm with a safe-harbor understanding, so candor is no longer unilateral self-sabotage. Transparency survives only if everyone is held to it at once. If I can see that, the people holding the pen saw it a while ago.

Bottom line.

The recall is ending, but the machinery is not.

Trump has reportedly told allies Anthropic is no longer a national security threat after talks with Amodei — fine, but that clears one company’s name; it doesn’t retire the dial. Two weeks ago, the question was whether one model would come back. Friday answered the sharper one: who decides. The same hand that switched Mythos off for the world switched it back on for a chosen list, kept the safer model dark, put OpenAI on the same leash by nightfall, and kept the pen to edit the list whenever it likes. Three days later, the pen is still uncapped: Fable stays offline, Congress keeps its silence, and a Chinese lab is already claiming the capability the ban was meant to fence off.

That is what arrived. Not artificial general intelligence, but Artificial Gated Intelligence. The most capable tier of American AI is no longer a product you buy, but access you are granted, checked against who you are and where you sit, on a list someone in Washington can rewrite.

You don’t get a vote on who holds the dial. You do get to decide how much of your stack hangs off it. Build like the answer to “are you on the list” is no, because for a non-US builder, right now, it is. The capability isn’t going back in the box.

Whether we govern it through something transparent or just keep checking names at the door is still an open question. The sooner we move away from door checks, the better.