TL;DR
- The government's side of the Fable 5 shutdown went public, and it's a control story, not an export-paperwork story: White House AI czar David Sacks says Anthropic was warned of a jailbreak, called it "not serious," and refused to fix it; the suspension is now reported to have been triggered by fears a China-linked group already accessed Mythos. T3
- Agentic-evals crux: a single trusted-partner red-team demo (Amazon researchers prompting Fable 5 to surface Mythos-class cyber/code capabilities) became the de-facto control trigger that overrode the lab's own red-teaming: the clearest live test yet of whose evaluation counts when an off-switch is pulled. T3
- Regulatory: there is still no statutory framework for a frontier-model kill-switch; the dispute now routes to a scheduled June 22 Anthropic–White House meeting rather than any due-process channel, even as Colorado's algorithmic-discrimination duties go live June 30. T3
Thread of the day: Yesterday this library led with Anthropic's account of the Fable 5 / Mythos 5 shutdown. Today the other account arrived, and it inverts the framing from "export control with no evidence" to "a safety dispute the lab lost." White House AI czar David Sacks put the government's reading on the record: a "highly credible, trusted partner" (reported to be Amazon, with CEO Andy Jassy phoning the administration) demonstrated a jailbreak of Fable 5's guardrails that surfaced the cyber/code-vulnerability capabilities of the underlying Mythos model; when notified, Anthropic's leadership allegedly judged it "not a serious risk" and declined to fix it, after which the government "reluctantly issued the export controls", and, per Semafor, did so amid fears a China-linked group had already accessed Mythos and could distill or reverse-engineer it. Anthropic disputes nearly all of this: it says it got 90 minutes, no prior national-security warning, that the jailbreak is narrow and non-universal, and that the White House never raised Chinese access to it directly. Strip the politics and the agentic-control lesson sharpens from yesterday's: the off-switch was pulled not on a statute or a FLOP threshold but on one partner's red-team demonstration of an agentic cyber capability, making eval validity (whose test counts, and how a single demo becomes a kill trigger) the actual governance question. The two sides now meet June 22; until then, every "fact" below is a contested claim in a live dispute.
What's new
The government's counter-narrative goes on the record: a partner jailbreak demo, a refusal-to-fix claim, and a suspected China access to Mythos
Tier: T3 T3 (mainstream reporting, Semafor, Fortune, Axios, Tom's Hardware, Business Today, carrying on-record statements from White House AI czar David Sacks for the government's position and an Anthropic source for the rebuttal; this is a live, contested dispute and the underlying facts, the China access, the "refused to fix" characterization, Amazon's exact role, are NOT independently verified) Pillar: Policy × Safety (agentic lane ⚙️: cyber/code capability of an agentic model as the trigger; eval validity, a single partner red-team demo vs. the lab's own evaluation; loss of oversight/control: an externally-pulled off-switch on a ~90-minute clock; foreign-adversary access claim) What happened: Over June 13–16, the administration's account of the Friday June 12 shutdown became public and shifted the story. White House AI czar David Sacks wrote that a "highly credible, trusted partner of both Anthropic and the USG" identified "a jailbreak in Fable 5's guardrails" that let users bypass consumer safeguards to reach the cyber capabilities of the underlying Mythos model: getting it to "provide information about cyberattacks that should have been restricted." Per Sacks, when the administration notified Anthropic, leadership (he named CEO Dario Amodei) "said the jailbreak was not a serious risk and refused to fix it," and the company "prioritized the continued offering of the consumer model over safety"; the administration then "reluctantly issued the export controls," and "the ball is in Anthropic's court." Reporting (Fortune, June 14) identifies the partner as Amazon, researchers used a prompt sequence to expose the vulnerability and CEO Andy Jassy raised it with senior officials, with Politico reporting the government had requested Amazon's feedback. Separately, Semafor reported the suspension was motivated by fears that a China-linked group had already accessed Mythos, raising concern that the model, which finds flaws in code, could be distilled or reverse-engineered; Semafor cautioned it was "unclear how the government had arrived at this suspicion or what evidence they had." Anthropic's rebuttal: a source says the company "was given 90 minutes to pull its newest model and was given no previous communication of a national security threat," maintains the jailbreak is narrow and non-universal, and denies the White House raised Chinese access concerns to it directly. The two sides are reported to be meeting in Washington on June 22. Why it matters in practice: Yesterday the framing was procedural overreach: a national-security export control with no statute, no written evidence, and an all-customer blast radius. Today's disclosures don't erase that, but they relocate the center of gravity into the agentic-evals lane, where this library has been pointing all month. Three reads. First, eval validity is now the load-bearing question: the operative trigger was one partner's red-team demonstration of an agentic cyber capability, set against the lab's contrary assessment, so the dispute is literally "whose evaluation counts, and is a single non-universal jailbreak demo sufficient to justify recalling a model used by hundreds of millions?" That is the eval-validity and red-team-affordance problem (the AISI/Apollo/Redwood control-evals line of work) playing out as live policy, not a benchmark. Second, loss of oversight/control in the institutional sense deepened: a ~90-minute external ultimatum, with the lab itself executing the off-switch under duress, is the cleanest real-world instance yet of an external actor holding control over a deployed frontier model, and the China-access claim adds the failure mode the agentic-security literature keeps flagging (a capable code/cyber model reaching an adversary). Third, keep hard epistemic discipline: this is now a two-narrator dispute and both narrators are interested. Sacks is making the government's case; the Anthropic source is making the lab's; the China-access suspicion is explicitly unverified even by the outlet that reported it; and "refused to fix" vs. "narrow, non-universal, no national-security warning" cannot both be fully true. The watch items are concrete: what surfaces from the June 22 meeting, any written rationale or evidence of the China access, whether the "trusted partner" and its test methodology are disclosed, and whether the directive's logic gets extended to other labs' models. Source: White House move to limit Anthropic linked to concerns about Chinese access to Mythos (Semafor, 2026-06-13) · How a warning from Amazon led the White House to shut down Anthropic's Mythos model (Fortune, 2026-06-14) · Trump adviser David Sacks says Anthropic refused to fix Fable 5 jailbreak before US export controls (Tom's Hardware, 2026-06-15) · Anthropic had 90 minutes to restrict Claude Fable 5 as White House feared Chinese access (Business Today, 2026-06-16)
Still no statutory floor for the kill-switch: the dispute routes to a meeting, not a process
Tier: T3 T3 (press analysis of a live, litigated dispute; the structural/legal reads are commentary, not primary documents) Pillar: Policy (which branch and which statute governs a frontier-model off-switch; due process as the missing layer) What happened: The new disclosures don't change the structural gap this library flagged yesterday: the only fast, legally-tested lever the executive reached for was an export control built for goods, now applied to model access, and the resolution mechanism that has materialized is a negotiation (the June 22 meeting) plus litigation, not a statutory review with notice, evidence standards, and appeal. What today adds is that the government now has a public safety rationale ("a partner found a jailbreak; the lab wouldn't fix it; an adversary may have had access") rather than only a classified one, which strengthens the administration's narrative but still leaves the same due-process void: a ~90-minute ultimatum, a contested factual record, and no neutral adjudicator before the switch was thrown. Why it matters in practice: Every governance framework tracked this month (the June 2 EO, OpenAI's blueprint, the Great American AI Act, Anthropic's own Advanced AI Framework) assumes blocking authority arrives with process. This episode is the counterexample that should reshape those proposals: the question is no longer "should there be an off-switch" but "what evidentiary standard and what review must precede pulling one." A partner's red-team demo triggering an instant, all-customer recall, with the factual basis disputed days later in the press, is precisely the scenario a due-process layer exists to prevent (or to legitimize). Watch whether Congress responds with an actual statutory standard, and whether the June 22 talks produce anything resembling a repeatable procedure rather than a one-off settlement. Source: US asks Anthropic to block global access to top AI models: Why it matters (Al Jazeera, 2026-06-14) · Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (Anthropic, 2026-06-12)
Worth watching
- Colorado AI Act becomes enforceable June 30. The CAIA's core duty: developers and deployers of high-risk AI must use reasonable care to prevent algorithmic discrimination in employment, housing, credit, healthcare, and other consequential decisions, goes live at month's end. It's the nearest-term concrete US fairness/enterprise compliance milestone, and a reminder that while the frontier-control fight dominates headlines, the deployed-system discrimination regime is the one most enterprises will actually feel first. (Colorado AI Act overview)
- Illinois SB 315: signature watch (carryover). Gov. Pritzker has committed to signing the AI Safety Measures Act (first US state mandate for annual independent third-party safety audits of large frontier developers; 72-hour critical-incident reporting; whistleblower protections; effective Jan 1, 2027) but, as of this briefing, has not yet signed the enrolled bill. Key Passages stub stays
needs_verificationuntil the Public Act text is available. (Transparency Coalition) - Agentic carryover: control-evals methodology is the lens for the lead. The AISI / Apollo / Redwood line of work on how to evaluate control measures for LLM agents (red-team affordances scaled to capability) is the right framework for reading the Fable 5 fight: the dispute is exactly about red-team affordances and whether one demonstration validly establishes risk. Already ledgered; no new artifact in the window, but newly load-bearing. (AISI blog)
- EU AI Act: formal adoption of the "Digital Omnibus" amendments expected July. The Parliament/Council vote that confirms the high-risk deadline slip (to Dec 2027) and the new transparency/prohibition provisions is the next datable EU step. Long-running thread; resurface on the adoption vote. (Global Policy Watch)
Evidence: today's lead rests on Tier-3 reporting of a live, two-narrator dispute (Semafor, Fortune, Axios, Tom's Hardware, Business Today) carrying on-record statements from both the White House AI czar and an Anthropic source, the underlying facts (suspected China access, "refused to fix," Amazon's exact role) are explicitly unverified and flagged provisional. The structural/legal read is T3 commentary. Worth-watching items are a T1 statute going live (Colorado), a T1 legislative-status note (Illinois), an already-ledgered T2 agentic-control methodology, and a T1 EU legislative step.