Three days after Anthropic released its Claude Fable 5 and Mythos 5 models last month, the Commerce Department ordered both offline worldwide after discovering a jailbreak that could let Fable 5 find software flaws and write exploit code, according to a new report from the Center for Data Innovation. The shutdown lasted nineteen days before Commerce lifted controls on June 30, allowing Fable 5 to return globally on July 1 while Mythos 5 came back online for roughly 100 vetted U.S. institutions. The report argues that Congress should pass clear rules for when and how the government can shut down AI systems, warning that the ad-hoc approach used in this case undermines American competitiveness and trust in U.S. technology.

The incident unfolded without public transparency or established procedure. The government presented its evidence verbally, and conflicting accounts emerged: reports claim White House adviser David Sacks said Anthropic refused to fix the jailbreak, while Anthropic said it never got disclosure of a jailbreak that produced a harmful outcome. Because Anthropic couldn't verify users' nationality in real time, complying with the export control directive meant taking both models offline for everyone, everywhere. The reinstatement came through private letters and a negotiated settlement, producing no published standard for what triggered the shutdown or what satisfied the government's concerns. British lawmakers noted that hospitals, companies, and researchers were using Fable 5 when it went dark.

According to the report's author, Michelle Lopes Maldonado, the central lesson is that "the United States should not govern frontier AI by ad-hoc ultimatum." The report finds that prudent buyers will now factor this risk into their adoption decisions, building redundancy, splitting workloads across vendors, and hesitating before integrating the most capable American models into critical operations—a real tax on productivity that falls hardest on organizations trying to deploy AI most seriously. For governments and businesses abroad, the lesson was clear: American AI is a revocable dependency that Washington can cut off without warning, which the report describes as a gift to Chinese open-weight developers whose models no U.S. authority can recall.

The report argues that the Commerce Department had narrower options available before resorting to a global shutdown. A proportionate response would have resembled the coordinated vulnerability disclosure process that already governs software security: the government discloses the jailbreak to the company under confidentiality, the company gets a defined window to patch its safeguards and verify the fix, and regulators escalate only if remediation fails. Proof that narrower options existed comes from the settlement itself—Mythos 5 returned under a tiered arrangement with access restricted to roughly 100 vetted U.S. institutions, the type of remedy the government should employ before imposing a global blackout. The report notes that cyber capability is inherently dual-use: the same vulnerability-discovery techniques exploited by malicious actors are essential for defenders to identify and fix weaknesses before they're weaponized.

Congress should codify the provisions of the June 2, 2026, Executive Order "Promoting Advanced Artificial Intelligence Innovation and Security" to create a durable statutory framework that future administrations can't easily reverse, the report recommends. Any legislation should include strong confidentiality protections to encourage responsible reporting without exposing developers' proprietary models or sensitive security vulnerabilities, and should establish a standardized Common Vulnerabilities and Exposures (CVE)-style system for rating and disclosing AI jailbreaks so "severe risk" has a consistent technical meaning. Before restricting a U.S. closed-weight model, there should be proof that the capability at issue isn't already available in open-weight or foreign systems—if Anthropic's claim that the jailbreak was replicable on other deployed models is true, then restriction delivers no security gain but pushes users toward models no U.S. authority can patch, monitor, or switch off. The dispute lasted nineteen days, but the consequences may last far longer.