The Precedent Was the Letter, Not the Model
Table of Contents
On Friday 12 June 2026 the US Commerce Department told Anthropic it needed an export licence before any foreign national anywhere on earth could access Claude Fable 5 or Mythos 5, including foreign nationals sitting in the company’s own offices in the United States. The formal directive arrived at 5:21 p.m. Eastern. According to the complaint later filed by one of Anthropic’s customers, a phone call earlier that afternoon had given the company ninety minutes to comply, on the basis of a national security threat whose details it was not told. Anthropic could not verify nationality at the application layer on that timescale, so it turned both models off for everybody.
Eighteen days later the order was withdrawn. Mythos 5 came back on 26 June for a named annex of approved US organisations, reported as more than a hundred. Fable 5 came back worldwide on 1 July.
The bottom line for anyone building on a frontier model: a category of control now exists that can remove a production dependency in ninety minutes, applies to your supplier rather than to you and is imposed by letter rather than by rule. It gives no advance signal of any kind. Chip export controls came with lead times and order books. This one came with a phone call.
What the instrument actually was
Almost all the coverage described the models and skipped the instrument.
The order was an is-informed letter, signed by Commerce Secretary Howard Lutnick and addressed to Dario Amodei. An is-informed letter is a notification the Bureau of Industry and Security sends to one named company telling it that a licence is now required for specified transactions. It does not go through notice-and-comment rulemaking, and it is not published in the Federal Register or entered in the Commerce Control List. There is no public standard against which anyone else can assess their own exposure, because the instrument is addressed to one recipient. Bloomberg obtained and published it on 16 June, four days after it reached Anthropic, which is the only reason its contents are public at all. Bloomberg reported that the letter threatened criminal and civil penalties for non-compliance.
The letter cited several authorities rather than one. 50 U.S.C. § 4817, the emerging and foundational technologies provision of the Export Control Reform Act of 2018. 50 U.S.C. § 4813(a)(15), which lets BIS inform a person by specific notice that a licence is required. The deemed export and reexport provisions at 15 CFR §§ 734.13 and 734.14. And 15 CFR § 744.22, under which BIS issues is-informed letters restricting exports for certain military-intelligence end uses or end users.
Section 4813(a)(15) is the licensing-by-individual-notice power, which is the whole mechanism of this episode written into statute. And § 744.22 places a commercially deployed chatbot inside the framework the United States uses for things it treats as military capability, without naming an end user or an end use.
The citations are contested, and the challenge came fast. On 23 June, Legion LegalTech Corp, a US litigation-software company whose developers include Canadian nationals working from Canada, sued the United States, the Commerce Department, Secretary Lutnick and the BIS Under Secretary in federal court in Washington, asserting violations of ECRA, the EAR, IEEPA, the Administrative Procedure Act and the Berman informational-materials exemption. Legion’s argument is that Section 4817 requires notice-and-comment rulemaking and multilateral coordination, neither of which happened. It argues too that the is-informed authority is a case-specific tool aimed at identified military-intelligence end users, not a mechanism for a worldwide ban with no end user or end use named. Its summary of the position is that Commerce cannot enforce a control that does not exist. Its warning is sharper: left standing, the directive would establish that the executive may disable any frontier AI model by unreviewed command.
There is statutory text on Commerce’s side, and it belongs next to Legion’s reading. Section 4817’s notice-and-comment requirement attaches to the interagency process that identifies a technology. Section 4817(b)(1) then tells the Secretary to establish controls on what that process identifies, “including through interim controls (such as by informing a person that a license is required for export)”. Section 4813(a)(15) separately authorises BIS to inform a person individually by specific notice. Individual notice is written into the statute twice, so it is not an improvised instrument. What remains contested is whether these models and these transactions could lawfully be brought inside that mechanism on the authorities Commerce actually cited.
Anthropic was not a party. The case was assigned to Judge Richard J. Leon, who ordered the government to respond to Legion’s preliminary-injunction motion by 14 July. That response never came due. Commerce withdrew the directive on 30 June, and on 3 July Legion voluntarily dismissed without prejudice.
So the first and so far only challenge to this mechanism ended without a ruling, ten days after it was filed, because the thing it challenged went away. No court ruled on any of it, so nothing here is precedent in the sense a lawyer means, and what survives is the operational fact that the instrument worked.
Is a prompt an export?
Whether a prompt to a hosted model counts as an export is unsettled, and the answer determines who else is exposed.
A deemed export under the EAR is the release of controlled technology to a foreign person. The directive expressly invoked it. Both the 26 June letter narrowing the controls and Lutnick’s 30 June announcement withdrawing them use the phrase “deemed export and deemed reexport”.
The novelty is what counts as a release. When someone sends a prompt to a hosted model and gets a reply, the weights never move. The user receives no weights, no source code and no technical data. The model remains on servers in the United States and what crosses the border is access to a capability rather than possession of an item. A Harvard Law Review analysis published on 26 June works through the problem and observes that the letter does not identify which downstream controlled items the models’ outputs would help develop; it imposes a licence requirement on the two named models directly. BIS has no established definition of an AI model, which leaves a prior question unanswered: whether what is subject to the EAR here is the weights, the algorithms, or the application layer serving them. Anthropic complied at the application layer, which suggests the last.
There is a cleaner route Commerce did not take. In January 2025 the Biden administration created ECCN 4E091, which controlled the weights of closed models trained above a compute threshold, as part of the AI Diffusion Rule. That rule was announced as rescinded in May 2025.
Legion’s complaint states flatly that 4E091 was rescinded with no replacement and that no operative classification reaches a hosted model or its outputs. The regulation says otherwise. ECCN 4E091 is still in the Commerce Control List, and 15 CFR § 742.6(a)(13) still requires a licence for the export, reexport or in-country transfer of 4E091 items to every destination worldwide, with applications reviewed under a presumption of denial for end users headquartered outside a short list of approved destinations. I checked that against the eCFR text current to 6 September 2026.
That leaves a state of affairs stranger than either party described. A worldwide licence requirement on advanced model weights is codified and in force. BIS says it has stopped enforcing the framework that created it. The rule that would formally rescind it has not been issued, so the control can be enforced again without any rulemaking at all.
One exemption may work in the opposite direction. EAR § 734.7 excludes from the regulations software that has been widely disseminated, a provision that parallels the informational-materials carve-out in US sanctions law and shares its First Amendment reasoning. Whether a commercially deployed model qualifies is untested. And as Mayer Brown’s lawyers pointed out in a footnote, the EAR’s definition of technology does contain the word “models”, but that wording dates to at least 1996 and was not written with anything like this in mind.
This produces an asymmetry. Published weights are excluded from the model-weight control by its own terms: 4E091 does not reach parameters that have been “published” as § 734.7(a) defines it, nor closed models less capable than the most advanced published one. A closed model delivered as a service was the thing that got switched off. If you were designing a policy to push global buyers toward open weights they can run on their own hardware, this is roughly what you would build, and CSIS reached the same conclusion in its assessment on 23 June. I made the weights-survive-the-buildings argument in a different context; this is the regulatory version of it.
Why the answer was to turn everything off
The order permitted continued access by US persons. Anthropic disabled the models for everyone, which reporting has occasionally treated as an act of protest. Look at what compliance would have required and the decision reads differently.
A US person under the EAR is not whoever has a US IP address. To comply, a provider would need a defensible foreign-person determination for every user of two specific models, held with enough confidence to stake criminal liability on it. Conventional implementations of that require documentary evidence of citizenship or immigration status, storage of the result, and a workflow for people who cannot produce documents. It means the same determination for every employee with internal access, and deemed-export licences for the ones who are not US persons. It means doing this for a consumer product, at scale, without notice, over a weekend.
There is no widely deployed equivalent at consumer or API scale. Age verification, which is a much easier problem with a decade of regulatory pressure behind it, is still done badly by most of the industry. Citizenship verification as an access control on an API is not a feature anyone had in the backlog.
One company’s choice is not the operative part. If nationality-based access control ever becomes a standing compliance requirement for AI services, the identity architecture required to satisfy it is not deployed at consumer or API scale anywhere today. Building it would create a database of user citizenship and immigration status at every major AI provider, which is a privacy consequence to name before it arrives rather than after.
Your exposure runs through your supplier’s supplier
Fable 5 was available through AWS Bedrock, Google Cloud and Microsoft Foundry. Customers of those platforms lost access because of a compliance obligation imposed on Anthropic, with no independent notice from the cloud provider they actually contracted with.
Work out what that means for your own vendor assessment. You performed due diligence on your cloud provider. Possibly you performed due diligence on the model provider. You almost certainly did not assess the regulatory exposure of the model provider as a distinct risk from its service reliability and its security posture, because until June 2026 there was no reason to. The failure mode here is not an outage, a security breach or a broken contract. It is a lawful order to a company two steps up your supply chain, which arrives with no notice and which your own contract gives you no standing to contest.
The practical consequence for architecture is the same one I argued in the context of adversarial pressure on infrastructure: a dependency that can be removed by a decision rather than by a failure requires a different kind of redundancy. Multi-region does nothing for you here. Multi-provider does, and only if the fallback is genuinely exercised rather than documented.
The dispute about the facts, and why the argument does not turn on it
Two accounts of the trigger exist, and both remain unreconciled.
The government’s position has not been set out in public. Reporting has attributed the concern to a jailbreak of Fable 5 that unlocked its unrestricted cyber capabilities, including identification of unknown vulnerabilities and generation of working exploit code. Forbes, citing the Wall Street Journal and Semafor, reported that Amazon chief executive Andy Jassy raised the issue with Treasury Secretary Scott Bessent and other officials, saying Amazon researchers had used Fable 5 to obtain information usable in cyberattacks. Separately, SiliconANGLE reported that the concern may relate to a statement by the red team lead at the UK’s AI Security Institute, four days before the order, that its cybersecurity team had made substantial progress toward a universal jailbreak of Fable 5. Neither line of reporting has been confirmed by Commerce.
Anthropic’s position is that it saw only a narrow technique amounting to asking the model to read a codebase and identify flaws in it. It says the vulnerabilities surfaced were minor and already publicly known, and that the models were safe throughout. The company nonetheless shipped a new safety classifier that it says blocks the reported technique in more than 99% of cases, and the controls were lifted the day after.
I am not going to adjudicate that, and the useful part is that nothing below depends on it. Suppose the government was entirely right and the jailbreak was as serious as the response implies. The instrument still gave one company ninety minutes, produced no published standard, exempted a list of named organisations by a second letter four days before withdrawing the controls entirely, and left every other frontier provider guessing at where the line is. Suppose Anthropic was entirely right and the capability was mundane. The same instrument is still available, on the same terms, to be used again on a worse-founded assessment.
A control regime that produces the same operational risk whether or not its factual premise is correct is a control regime you have to plan around rather than argue with.
What is actually in force today
Checked on 6 September 2026, and this is the part to verify again before you cite any of it.
From the June episode, nothing. The 12 June letter was withdrawn on 30 June. The model-weight controls are a separate question and the answer there is not nothing: 4E091 and its worldwide licence requirement are still on the books, unenforced. Lutnick’s letter lifting it recorded commitments from Anthropic to “proactively detect and address security risks associated with the models”, to work with the government on standards for future models, and to notify it of malicious activity. Those are commitments in a letter, not obligations in a rule, and they bind one company. The third of them creates an incident-notification duty by private arrangement, alongside the four statutory reporting regimes that already overlap on AI incidents and were negotiated in public.
When Commerce narrowed the controls on 26 June by exempting a named annex of trusted partners, Lutnick wrote that he reserved the right to reevaluate and adjust the scope of the licence requirements should circumstances change, and to alter the list of approved entities at any time. He reserved a discretion he can exercise again, and set no conditions a provider could satisfy in advance.
No replacement rule has been published. The AI Diffusion successor is on the BIS docket, carried in earlier materials under the title Redesigned Framework for Artificial Intelligence Diffusion. The draft reached OIRA in February 2026 and was withdrawn in March. Under Secretary Jeffrey Kessler told the House Foreign Affairs Committee on 14 July that regulatory action on AI and semiconductors is coming. Commerce’s regulatory plan says BIS intends to publish it before the fiscal year ends on 30 September, and describes it as another interim final rule, meaning BIS intends to issue it without a proposed rule and a comment period first. The same plan records that BIS has already stopped enforcing the 2025 framework the rule is meant to rescind.
That last detail is the one to hold. Most people took from June that a letter can move faster than a rule. The rule that replaces the letter is also built to skip the step where anyone gets to comment on it.
Set this against the European position, where the GPAI security obligations apply to a defined class of model, on published dates, with the text available to anyone who wants to read it before deciding whether it applies to them. Whatever you think of the substance, one of these regimes can be planned for and the other cannot. That difference will show up in procurement long before it shows up in policy.
What to do about it
Four things, none of which require you to have a view on export policy.
Add regulatory exposure of the model provider to your vendor assessment as a line item distinct from availability and security. You are not asking whether they will have an outage. You are asking whether a government can order them to stop serving you, and what notice your contract gives you when that happens.
Find out, in writing, what your cloud provider owes you if the model behind their service becomes unavailable through a compliance order on the model developer. Bedrock, Foundry and Vertex customers found out in June that the answer might be nothing.
Keep a tested fallback on a different provider, and ideally an open-weight model you can run yourself for the part of the workload you cannot afford to lose. This is the same conclusion the Hugging Face incident responders reached from an entirely different direction, and when two unrelated failure modes point at the same control, build it.
Stop treating nationality-based access control as a hypothetical. If the successor rule contains anything resembling a person-based restriction, the identity plumbing to satisfy it will take you longer to build than the compliance deadline will allow, and the version you ship in a hurry will be the one that ends up holding immigration status on your users.
The thing that changed in June was not that a model turned out to be dangerous. Governments have been asserting that for two years. What changed is that one of them found a lever it could pull in ninety minutes, pulled it, and then put it back without ever saying where the line was. The lever is still there.
In the early 2000s, running emerging-technology risk labs at CyberAgency, a defence client asked my team to break the AI systems they planned to put into weapons. We did. That is where my work on AI security started, two decades before the current wave of attention. I kept at it through risk labs at IBM, Accenture, PwC and KPMG. In 2016 I co-wrote a book on AI and leadership. My commercial work today is quantum, at Applied Quantum, which is why this site sells nothing.