On Friday evening, the U.S. Commerce Department instructed Anthropic to prevent any foreign national from accessing Fable 5 and Mythos 5, the company's two newest and most capable AI models. The directive cited national security authorities. To comply, Anthropic had to take both models offline entirely — there was no practical way to enforce the restriction on foreign nationals without disabling access for everyone.

Anthropic complied. And then, in a public statement, the company said something worth paying attention to: it disagreed with the decision, believed the directive stemmed from a misunderstanding, and noted that it had received only verbal evidence of the vulnerability the government claimed to have identified.

Anthropic also said something I agree with directly: governments should have the ability to block unsafe AI deployments. The question worth examining is not whether that authority is legitimate. It is what that authority requires to be exercised responsibly.

What "Verbal Evidence" Actually Means

The government identified what it described as a narrow jailbreak — a technique that could allow users to circumvent some safety restrictions in Fable 5. Based on that finding, it directed Anthropic to suspend access for all foreign nationals, which cascaded into a full takedown.

Anthropic says the evidence provided was verbal. No documented reproduction steps. No demonstrated exploit. No technical specifics shared with the team responsible for the system.

I spent years in software engineering and quality assurance before moving into research. One of the most basic things you learn in that environment — whether you are filing a bug report or receiving one — is that a report without reproduction steps is not actionable. It is not that you disbelieve the person reporting it. It is that you cannot confirm, isolate, or fix something you cannot reproduce. The problem does not go away because the system went offline. It goes underground.

"You cannot fix what you cannot reproduce. The problem does not go away when the system goes offline. It goes underground."

This is not a procedural complaint. It is a safety argument. If Fable 5 has a genuine vulnerability — and it may — then the only path to actually resolving it runs through Anthropic's engineering team having enough information to understand and address it. Removing the model without sharing the specifics means the issue remains unresolved, unpatched, and unknown to the people best positioned to fix it.

Anthropic noted that the jailbreak, if real, likely exists in other companies' systems as well. That is almost certainly true of any vulnerability discovered in a widely deployed model class. Which means the intervention, as structured, did not address the underlying problem. It addressed one company's deployment of it.

The Difference Between Oversight and Reaction

There is a version of government intervention in AI that I think is not only legitimate but necessary. It looks like: clearly identified risk, technically grounded evidence, shared with the responsible party in sufficient detail to act on, through a process that is transparent enough to be audited and repeated. That is oversight. It is what responsible deployment governance looks like in any complex technical domain.

What happened Friday does not quite fit that description. A directive arrived with verbal evidence, no documented reproduction path, and a compliance mechanism — removing access — that does not actually resolve the underlying concern. The people who could fix the problem were not given what they needed to fix it.

Anthropic's statement put it clearly: they believe the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. They said this action did not adhere to those principles. I think that is right. And I think it is important to say so plainly, separate from any judgment about the actors involved.

"The people who could fix the problem were not given what they needed to fix it. That is not safety. That is the appearance of safety."

Why Process Is Not Bureaucracy

There is a tendency, when security concerns feel urgent, to treat process as friction — as the thing that slows down the people trying to protect us. I understand that instinct. But in technical domains, process is not administrative overhead. It is the mechanism by which evidence becomes action.

A jailbreak reported without documentation cannot be patched. A vulnerability identified verbally cannot be verified. An intervention built on unshared evidence cannot be evaluated, challenged, or improved. And in a domain moving as fast as AI, where the same capability gaps exist across multiple systems from multiple organizations, that matters. The goal should not be to take one model offline. It should be to understand and address the class of vulnerability — which requires precisely the kind of technical transparency that this process lacked.

This is not unique to AI. It is how responsible disclosure works in cybersecurity. It is why aviation safety investigations share findings publicly. It is why pharmaceutical adverse event reporting exists. The value of the process is not just procedural fairness. It is that evidence shared rigorously is evidence that can actually be used.

What This Adds to the Pattern

I have been writing in this series about the structural failure modes of AI adoption: the pressure to deploy fast, the tendency to trust AI outputs beyond what comprehension warrants, the organizational dynamics that make careful evaluation least likely exactly when it matters most. This case fits a related pattern.

When intervention — like adoption — is driven by urgency rather than grounded in deliberate process, it tends to produce reactions rather than solutions. The model is offline. The vulnerability, if real, is still there. The organizations best positioned to address it have less information than they need. And the framework for future interventions is, if anything, less clear than it was before.

AI should happen with us, not to us — and that applies to governance just as much as it applies to deployment. Pulling a system offline is something that happens to a system. Fixing a vulnerability is something that happens with the people who built it. Those are different things, and only one of them makes anyone safer.

Series Context

This essay is part of an ongoing series on AI adoption failures — structural patterns in how organizations and institutions relate to AI that reliably produce bad outcomes. Earlier entries examine the Crisis Adoption Problem, the Bandwagon Problem, and other failure modes in organizational AI adoption.

Source

Jared Perlo, "Anthropic suspends new AI models after government directive," NBC News, June 12, 2026. Read the full article →

DH

Debra Hogue, PhD

Computer Scientist · Human-AI Collaboration Researcher · Oklahoma