Table of Contents
1. The New Model That Stopped After Three Days
In June 2026, the debate around artificial intelligence entered a new phase. The central issue was no longer only whether AI would take jobs, weaken human thinking, or reduce opportunities for junior workers to grow. A deeper question appeared: can intelligence itself be bordered?
The immediate trigger was Anthropic's announcement of Claude Fable 5 and Claude Mythos 5. Anthropic introduced the two models on June 9, 2026. Fable 5 was presented as the company's most capable model available broadly to ordinary users, while Mythos 5 was positioned as a special model offered to a more limited set of customers. In Anthropic's launch materials, the two models were described as sharing the same underlying capability, with the difference lying in some safety classifiers. Pricing was set at 10 dollars per million input tokens and 50 dollars per million output tokens. The context window was 1 million tokens, and maximum output was up to 128,000 tokens. This was no longer received as a conventional chatbot. It looked closer to a long-running researcher or agent. [1]
Only three days later, the situation changed abruptly. On June 12, 2026, Anthropic announced that it had received an export-control directive from the U.S. government and would suspend access to Fable 5 and Mythos 5. The issue was not merely an outage at one company's service. The directive reached not only foreign nationals outside the United States, but also foreign nationals inside the United States and even foreign-national employees within Anthropic. Because it was technically difficult to separate access by nationality immediately and reliably, Anthropic disabled access for all customers in order to comply. [2]
According to Anthropic, the government's concern was the possibility of a jailbreak that could bypass safeguards in Fable 5. Anthropic also said the government did not provide specific national-security details, and that what it received was an oral explanation of a narrow, non-universal technique. The company said it had spent thousands of hours over several weeks conducting safety testing with the U.S. government, the United Kingdom's AI safety research institute, several private organizations, and its own internal teams. It also argued that complete jailbreak resistance may not be achievable by any AI company today, and that the important goal is layered defense: detecting, limiting, and monitoring dangerous outputs. [2]
The important point is not to rush into deciding which side was right. What matters is the structure revealed by the event. AI models are no longer merely convenient applications. They have become strategic resources that states may stop. After oil, uranium, semiconductors, and cryptography, trained intelligence has entered the domain of export controls and national security.
For Pochang Lab, this subject is interesting because it does not end as a story about AI performance competition. It sits at the intersection of technological history, cyber defense, state sovereignty, the free circulation of knowledge, and the ancient philosophical problem of who should manage dangerous wisdom.
The core issue was not a server failure. It was the moment access rights became a national-security question.
2. The Difference Between Fable and Mythos
The relationship between Fable 5 and Mythos 5 is the key to understanding this incident. In Anthropic's official explanation, Mythos 5 has the same underlying capabilities as Fable 5, but some safety classifiers are removed. Fable 5 was released with stronger safeguards so it could be delivered to a broad user base. In other words, the distinction is not simply a performance gap. It is a difference in how capability and control are combined.
In traditional software, the difference between a product version and a research version was often understood as a matter of feature switches or pricing. With AI models, however, functional restrictions can carry national-security meaning. If a model can find software vulnerabilities, it becomes a valuable instrument for defenders. It can analyze old codebases, identify dangerous bugs, and suggest candidate fixes. The same capability can also be used by attackers. Defense and offense often require overlapping knowledge; what changes is the direction in which that knowledge is applied.
Anthropic's Project Glasswing, announced in April 2026, was built on this dual nature. It gave a model called Mythos Preview to a limited set of cyber-defense organizations and infrastructure providers so they could use it to defend critical software. Anthropic said the model had already found many serious vulnerabilities, including issues related to major operating systems and web browsers. The company also said it had expanded access to more than 40 organizations and committed up to 100 million dollars in usage credits, along with 4 million dollars in direct support for open-source security organizations. [3]
Those numbers matter because cyber defense has long been constrained by human labor. It is difficult for humans alone to inspect millions or tens of millions of lines of code. Large financial systems, airports, power grids, communications networks, medical systems, and government systems often contain decades of accumulated legacy code. If AI can enter that environment and automate vulnerability discovery, defensive capacity can increase significantly. But if the same technology reaches malicious actors, the speed of attack can also increase.
Cybersecurity has long used the concept of dual use. A technology can serve civilian and military purposes, defense and offense, legitimate research and abuse. Cryptography, drones, satellite imagery, genome editing, and AI all have this property. The difficulty is that if a dual-use technology is fully closed, society's defensive capacity may also decline. If it is fully open, abuse risk spreads. The suspension of Fable 5 and Mythos 5 placed this old problem directly in front of frontier AI models.
3. Model Weights as a New Strategic Material
When AI becomes subject to export control, model weights sit at the center. Model weights are the vast collection of numerical values adjusted through training. Human knowledge is stored in books, experience, and skills. In a neural network, much of what we call knowledge is stored in weights. The ability to write, read code, understand images, and reason is embedded in the arrangement of those numbers.
Semiconductors are physical objects. They pass through factories, logistics networks, and customs. Model weights, by contrast, are data. They may be enormous, but they can be copied. They can move through encrypted communications and sit in cloud storage. That is exactly why they are hard for states to handle. They are not physical goods in the ordinary sense, but their national-security value can be enormous.
In January 2025, the U.S. Bureau of Industry and Security set out a framework for managing the diffusion of advanced AI models and large advanced semiconductor clusters. The framework explicitly introduced the idea of controlling the weights of certain closed models trained above a defined compute threshold. One threshold was models trained on more than 10 to the 26th computational operations. For ordinary life, that number feels almost astronomical. In AI policy, it becomes a way to draw a line around models considered capable of national-level impact. [4]
In May 2025, the United States rescinded the Biden-era AI diffusion rule while strengthening semiconductor export-control guidance and saying a replacement rule would come later. U.S. policy is therefore not settled. It contains two motives at the same time: an economic motive to spread American AI widely enough to become the global standard, and a security motive to prevent dangerous capabilities from flowing to adversaries or high-risk actors. [5]
The U.S. executive order issued on June 2, 2026 linked advanced AI to cyber defense, critical infrastructure, and national security. It described a policy of working with private companies to modernize government and private-sector information systems and harden them against external threats. At that point, AI companies cease to look like ordinary service companies. They become part of the national-security supply chain. [6]
This structure resembles the semiconductor industry. NVIDIA GPUs, TSMC manufacturing capacity, and ASML lithography equipment became central to national strategy. Now the authority to provide access to AI models is also becoming an object of international politics. The difference is that semiconductors are manufactured objects, while AI models are often consumed as cloud services. Who is using the model, from where, under which nationality, and for which purpose? That question is becoming a national-security issue behind the login screen.
Model weights are not physical cargo. Even so, they are beginning to hold the kind of value states want to govern.
4. The Memory of the Crypto Wars
There is a historical precedent for this event: the crypto wars of the 1990s. At the time, strong encryption software in the United States was treated almost like a munition. Encryption was seen as a special technology for diplomats, militaries, and intelligence agencies. Spreading strong encryption abroad was viewed as a national-security risk.
In 1991, Phil Zimmermann released PGP, software that allowed individuals to encrypt email. It was a tool for protecting civilian privacy, but the U.S. government investigated him in connection with encryption export controls. The investigation lasted roughly three years and ended without charges. A memorable episode was the publication of PGP source code as a book. If software is printed on paper, is it a protected publication under freedom of expression, or is it a blueprint for a weapon? That question shook American society at the time.
Another famous example was the protest of printing short RSA encryption code on T-shirts. Under the export-control logic of the 1990s, a shirt bearing strong encryption code could, in theory, be treated as something like an export-controlled munition. A few lines of code on a person's back could become a problem when crossing a border. That strange image symbolized the conflict between a state trying to regulate information as a thing and software circulating as copyable knowledge.
In 1995, Daniel Bernstein, a mathematician at the University of California, Berkeley, sued the U.S. government over the publication of encryption software. By 1999, the legal reasoning that encryption source code could be expressive speech had gained force, and prior permission requirements were treated as unconstitutional in that context. This helped spread the idea that code is also speech. After the crypto wars, strong encryption became a foundation for online commerce, online banking, messaging apps, and cloud services.
The point is not that encryption regulation was simply foolish. Government concerns were real: if criminal organizations or adversarial states used strong encryption, investigations and intelligence work would become harder. But if strong encryption were kept away from society as a whole, banks, hospitals, companies, and individuals would also become weaker. You cannot defend a society by weakening its defenses. That was the central lesson of the crypto wars.
AI has the same structure. Opening advanced AI models can strengthen defenders. Researchers, developers, companies, local governments, medical institutions, and educational institutions can benefit. At the same time, abuse possibilities expand. Closing access may reduce some risks, but it can also slow society's defensive capacity and research velocity. In the encryption era, the question was whether citizens should be allowed to possess strong encryption. In the AI era, the question becomes who should be allowed to use strong intelligence.
5. The Philosophy of Sovereignty
The political philosopher Carl Schmitt said that the sovereign is the one who decides on the state of exception. The idea is dangerous, but it also captures something sharp about state power. In ordinary times, laws and procedures move society. In an emergency, someone decides that normal rules can no longer handle the situation. That authority to decide is the core of sovereignty.
The suspension of these AI models is, in this sense, a question of sovereignty. The government stopped a private company's latest model offering on national-security grounds. Anthropic accepted that governments should have authority to stop dangerous deployments, but argued that such authority should be transparent, fair, and based on lawful procedure grounded in technical facts. The dispute is therefore not whether government can ever intervene. It is what procedure, what evidence, and what scope should govern such intervention.
Borrowing from Michel Foucault's theory of power, modern states do not only punish people. They govern through knowledge, statistics, surveillance, and classification. Schools, hospitals, prisons, militaries, and administrative agencies classify individuals, record them, and standardize them. In the AI era, the object of this governance expands beyond people to the circulation of intelligence itself. Which model is dangerous? Which output is permitted? Which nationality may use it? Which purpose is safe? These judgments become embedded inside API access controls and cloud contracts.
Norbert Wiener, in Cybernetics in 1948, treated communication and control as problems that cut across machines, living organisms, and societies. Cybernetics studies systems that adjust themselves through informational feedback. AI safety mechanisms are exactly such feedback systems. They classify dangerous outputs, refuse them, monitor them, and retrain around them. But who designs that feedback? A company, a state, an international organization, or a research community? That question is not only a technical specification.
Friedrich Hayek argued that knowledge is dispersed throughout society and cannot be fully grasped by a center. Markets coordinate dispersed knowledge through prices and exchange. From that perspective, strict centralized management of advanced AI use has limits. Whether a given research use is beneficial or dangerous may only be visible in the field. But fully decentralized freedom also disperses abuse risk. The difficulty of AI governance lies in the fact that both centralization and distributed knowledge have limits.
Philosophically, the problem resembles Prometheus's fire. In Greek mythology, Prometheus gave fire to humanity. Fire made cooking possible, enabled metalworking, and advanced civilization. But fire could also burn cities, forge weapons, and make war more destructive. What the gods feared was not fire in itself, but the fact that humans who possessed fire could change the existing order. AI is similar. Advanced intelligence is a useful tool, but it is also a fire capable of changing existing power relations.
AI governance is not only about taking fire away. It is about building institutions that can handle fire responsibly.
6. Why Europe and Canada Reacted
This issue does not remain an American domestic story because AI is already a global infrastructure service. The European Commission said it was assessing the practical impact of Anthropic's model suspension and warned that measures should not be discriminatory against partners. It also framed the incident as another reason for Europe to strengthen technological sovereignty. [7]
Technological sovereignty means that a country or region can control critical technologies for itself. It does not mean simply building a domestic AI model. It includes cloud infrastructure, semiconductors, data centers, foundation models, standardization, legal institutions, and human-capital development. Even if a foreign AI service is convenient and high-performing, critical infrastructure cannot depend completely on it if access might disappear one day because of export controls or diplomacy.
Canadian Prime Minister Mark Carney also warned on June 14, 2026 that the incident showed the danger of overreliance on American AI models. If a country depends too heavily on one model or one provider nation, a policy change in that country can directly affect domestic research, industry, defense, and administration. This is not unique to AI. Similar problems have appeared in energy, food, medicine, and semiconductors. AI makes the dependency harder to see. The user sees only a response on a screen, while behind it sit data centers, contracts, laws, nationality checks, export controls, and diplomatic relationships. [8]
Japan is not distant from this issue. In June 2026, Mitsubishi Heavy Industries and Preferred Networks announced a partnership to jointly develop Japan-made AI technologies for mission-critical machinery and systems in social infrastructure and national-security fields. Preferred Networks has vertically integrated technologies that include AI chips, computing infrastructure, and foundation models, and it is involved with the Japanese foundation model PLaMo. This movement is not merely a domestic AI boom. It is tied to the question of how far Japan can understand and control AI embedded in critical infrastructure. [9]
After World War II, Japan developed while depending heavily on international specialization for energy, food, semiconductors, and communications infrastructure. International specialization is efficient. But the pandemic, semiconductor shortages, the war in Ukraine, and U.S.-China conflict in the 2020s showed the fragility of supply chains optimized only for efficiency. AI models have now entered the same problem space.
7. Open Intelligence and Closed Security
There are three broad directions for border management of AI models. The first is full closure. Advanced models are made available only to domestic companies, domestic research institutions, and approved users. From a security perspective, this is easy to understand. But it can slow international research, frustrate allies and private companies, and encourage migration toward other countries' models or open models.
The second direction is full openness. High-performing models are spread around the world, and American, European, or Japanese AI becomes the international standard. This is favorable for market expansion, but difficult for abuse control. Cyberattacks, fraud, automated influence operations, and dangerous research assistance may appear in areas where institutions have not yet caught up.
The third direction is trusted access. User attributes, organizations, purposes, audits, log retention, safety evaluations, and incident reporting are combined, and the most dangerous capabilities are opened in stages. This idea was visible in Anthropic's Project Glasswing. Mythos-level capability was first made available for cyber defense and critical-infrastructure protection, with lessons to be shared from that controlled use.
Trusted access, however, contains hard questions. Who is trusted? Does the government choose? Does the company choose? Does an international institution certify? What happens to startups and university researchers? Should access be divided by nationality, organizational controls, or purpose? If nationality alone is used, allied-country researchers, immigrants, students, and employees of global companies are caught in the net. If purpose alone is used, stated intent may diverge from actual use. If organization alone is used, individual researchers and small teams may be excluded.
Elinor Ostrom's work is useful here. She showed that shared resources are not limited to two options: top-down state control or market freedom. In some cases, user communities themselves can create rules, monitor use, impose sanctions, and improve governance over time. Her research focused on forests, irrigation systems, and fisheries, but the idea can be applied to knowledge resources. Advanced AI also needs layered governance by users, developers, governments, researchers, and international institutions, rather than a simple choice between state control and laissez-faire.
AI safety management is also like airport security. We cannot trust every person completely. But if every person is treated as an enemy, movement stops. So societies combine identity checks, baggage screening, monitoring, risk assessment, and international agreements to create systems that are imperfect but functional. AI models require the same kind of thinking. Perfect safety does not exist. But the absence of perfect safety is not a reason either to abandon governance or to stop everything. We need to decide how much risk is accepted, with what transparency, and by whom.
8. What May Happen Next
Several changes are likely to move forward after this incident. First, identity checks and nationality verification may become stronger. Until now, AI services often required little more than an email address, phone number, and payment method. For advanced models, providers may begin verifying nationality, residence, organization, and intended use. This resembles financial know-your-customer checks. The act of using AI may begin to require identity verification.
Second, companies will use multiple AI models. If business workflows depend deeply on one company's model, a policy change or suspension can stop operations. Cloud computing already has the concept of multi-cloud strategy. AI will move in a similar direction: companies will combine multiple models, prepare fallbacks for critical operations, and maintain internal, domestic, or open models where needed.
Third, safety evaluation standards will become more important. Which capabilities are dangerous? Which benchmarks should measure them? How should cyber capability, chemical or biological assistance, autonomous agent capability, persuasion, and long-horizon planning be evaluated? AI evaluation in the early 2020s often focused on scores in math, reading, programming, and general knowledge. From 2026 onward, evaluation for deciding which capabilities may be released will become more important.
Fourth, debate over open models will intensify. If closed corporate models can be stopped by government directive, researchers and developers will see more value in open models whose weights they can hold themselves. But once open models are released, they are difficult to recall. As with cryptography spreading across the internet, information cannot be fully taken back once it circulates. Openness increases freedom and defensive capacity, but it makes abuse control harder.
Fifth, AI alliances among states will form. The United States, Europe, Japan, Canada, the United Kingdom, Australia, South Korea, India, and others will likely seek new frameworks around AI safety standards, export controls, data centers, semiconductor supply, and researcher exchange. Semiconductor supply chains are already being reorganized among allies. AI models will likely follow: trusted countries will try to share capabilities while preventing leakage to hostile actors.
There is a trap here too. If AI alliances become too exclusionary, excluded countries will accelerate their own models and the world may divide into multiple AI blocs. The internet was originally a technology that crossed borders. AI, however, depends on cloud infrastructure, data, semiconductors, power, and security. It is therefore more deeply affected by borders. AI is becoming a more geopolitical technology than the internet.
9. The Switch That Stops Intelligence
The most striking part of this incident is that AI had a switch that could stop it. A model provided through the cloud becomes unavailable if the company disables access. This is an advantage for safety. If dangerous use is discovered, the service can be stopped. At the same time, it is also a weakness of dependency. If research, development, business operations, education, medicine, and administration depend on one model, that switch has the power to stop part of society.
Hannah Arendt divided human activity into labor, work, and action. Labor is the repeated activity that sustains life. Work creates artificial objects in the world. Action creates a public world through words and deeds among people. AI is entering all three. It handles routine operations, produces software and documents, and influences political speech and public debate. Therefore, stopping AI is not merely stopping a tool. It begins to resemble stopping part of society's capacity to act.
An AI with no stop switch is also frightening. If a released model can no longer be controlled and continues to be used for dangerous purposes, there may be no way to stop the harm. This is the fundamental dilemma of the AI era. A controllable AI is an AI that someone can stop. An unstoppable AI is freer, but also more dangerous. We do not have a simple answer between freedom and safety.
This problem will not end with one company or one administration. As AI becomes more capable, the same question will return repeatedly. A model may find software vulnerabilities faster than humans. Another may read papers, generate hypotheses, and design experiments. Another may support corporate decision-making or part of a military system. Who should be allowed to use it? Which countries should receive it? Which capabilities should be restricted? What evidence is enough to stop it?
The June 2026 suspension of Fable 5 and Mythos 5 may be remembered not as a small service interruption in AI history, but as the moment a boundary became visible. Until now, AI has moved toward becoming smarter, cheaper, and more widely available. Yet past a certain capability threshold, openness is no longer automatically good. Intelligence can be a public good, a product, and a weapon at the same time. We do not yet have much experience governing something that holds all three properties simultaneously.
There is still reason for hope. After the crypto wars, strong encryption did not become the enemy of society. It became a foundation of modern safety. Nuclear technology has both military and civilian sides, yet it produced the International Atomic Energy Agency and inspection regimes. Aircraft can be used in war, but international civil aviation rules also connect the world. Humans cannot perfectly control dangerous technologies, but we have repeatedly learned, slowly, through institutions, practices, monitoring, expertise, and international cooperation.
AI will require the same work. The impact is too large to leave to companies alone. Knowledge is too distributed to leave to states alone. Externalities are too large to leave to markets alone. Implementation moves too quickly to leave to researchers alone. We need institutions in which multiple actors monitor one another, object, leave records, and update standards.
The day AI got borders was not only the day intelligence was confined. It was the day intelligence was written onto the map of states. From here, AI debates cannot be understood by reading performance charts alone. The next decade of technology politics will be about who has access, who has authority to stop access, and who can verify that decision.
The suspension of Fable 5 and Mythos 5 was not an accidental disturbance. It was a sign that AI has moved from convenient tool to civilizational infrastructure. Whoever holds fire can warm a room or burn a city. That is why the answer is not simply to seize the fire, but to build institutions for handling it. The real issue in AI is not intelligence itself. It is which society uses that intelligence, under what responsibility, and within which boundaries.
References
- [1]Anthropic, Claude Fable 5 and Claude Mythos 5, 2026-06-09; Claude API Docs, Introducing Claude Fable 5 and Claude Mythos 5. ↩
- [2]Anthropic, Statement on the US government directive to suspend access to Fable 5 and Mythos 5, 2026-06-12. ↩
- [3]Anthropic, Project Glasswing, 2026-04-07; Anthropic, Expanding Project Glasswing, 2026-06-02. ↩
- [4]Federal Register, Framework for Artificial Intelligence Diffusion, 2025-01-15. ↩
- [5]Bureau of Industry and Security, Department of Commerce Announces Rescission of Biden-Era Artificial Intelligence Diffusion Rule, 2025-05-13. ↩
- [6]The White House, Promoting Advanced Artificial Intelligence Innovation and Security, 2026-06-02. ↩
- [7]Euronews, US export controls on Anthropic should not be discriminatory, EU Commission warns, 2026-06-14. ↩
- [8]Associated Press, Canadian Prime Minister Mark Carney says US AI restrictions underscore risks of dependence, 2026-06-14. ↩
- [9]Mitsubishi Heavy Industries, Mitsubishi Heavy Industries and Preferred Networks Form Business Alliance to Jointly Develop Japan-Made AI Technologies for Mission-Critical Applications, 2026-06-02. ↩

NEW NOVEL 2026/08/01
Clouded Glass
Polishing is not about force.
Volume two of The World Became Slightly Farther Away.Five stories that can also be read as a starting point.
View on Amazon
Jijoden.com
Your life is worth writing.
There is a truer self you can tell only to AI.Gather fragments of memory into a single story.
Take a LookRelated Articles
Claude Fable 5 vs Claude Opus 4.8: Is the Model 'Above Opus' Actually Worth Using? (As of July 8, 2026)
A thorough comparison of Claude Fable 5 — released in June 2026 and briefly suspended under US export controls — against the workhorse Claude Opus 4.8, covering pricing, benchmarks, safety classifiers, and when to use each, based on public information as of July 8, 2026.
The OpenAI Trial and the Moment a Well-Intentioned Organization Becomes a Giant Company
A governance-focused analysis of the Musk-OpenAI lawsuit, nonprofit ideals, frontier AI capital demands, Anthropic, DeepSeek, Gemini, Copilot, and the institutional contradictions of AI companies.
How Far Will AI Agents Refuse “Gray-Area Code” in 2026?
This article examines where AI agents refuse or assist gray-area automation (like social engagement bots), comparing policy intent and real behavior across OpenAI, Google, and Anthropic.
Figma × Anthropic “Code to Canvas”: A New Roundtrip from Running UI to Editable Design
A primary-source-based analysis of Figma and Anthropic’s Code to Canvas: runtime UI capture mechanics, MCP strategy, continuity with HTML-to-Figma approaches, workflow impact, security governance, and what to watch next.
Complete Guide to OpenAI Agent Builder: From Generative AI and AI Agents to the Latest Platform
A comprehensive guide to OpenAI's Agent Builder announced in October 2025, covering the fundamentals of generative AI and AI agents, no-code agent development, and comparisons with competing products.
