Published June 16, 2026 by CSIS as a Critical Questions piece by Kate Koren, Kevin Kurland, and Aalok Mehta.
What happened
"Late Friday, June 12, the Department of Commerce sent a letter to Anthropic informing the AI developer that it was imposing export controls on its latest models, Fable 5 and Mythos 5. An approved export license from the Bureau of Industry and Security (BIS)… is now required for any foreign persons, whether inside or outside of the United States, to access the models. The requirement includes Anthropic's foreign national employees."
Anthropic's stated consequence: "The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance."
The reported precipitating cause: the White House sought other companies' views on Fable 5's safety, and "Amazon's researchers reportedly identified methods that could bypass the guardrails, an attack known as 'jailbreaking,' prompting fears that Fable 5 users could identify and exploit cyber vulnerabilities." The letter itself "has not been made public."
The authority problem
The analysis is primarily a legal one, and its findings are the reason it is cited by name. Three separate defects are identified in the authorities reportedly invoked.
The ECRA emerging-technology authority. Reports and "discussions with people who have seen the letter" indicate it cites ECRA's authority to establish interim controls on emerging and foundational technologies through an "is informed" notice. CSIS's finding: "there is no regulatory framework in the EAR for this statutory authority, which is why it has never been used before as the basis for issuing a control." The statute "does not explicitly allow for a worldwide 'is informed' control but does not exclude it either," because "by design, the statutory language is brief and nonspecific, as the details are intended to be developed in a more fulsome regulation through the federal rulemaking process. Commerce has yet to develop a regulation laying out the details."
Section 744.22. The letter reportedly also cites the military-intelligence "is informed" provision, but "this section of the EAR only allows Commerce to impose license requirements on a small group of adversarial countries, not a worldwide control." More generally, the EAR's worldwide "is informed" authority "currently only applies to exports, reexports, or in-country transfers for WMD activities, U.S. persons activities related to chemical or biological weapons, or exports to a party involved in activities contrary to U.S. national security or foreign policy interests" — a list that excludes military-intelligence end uses.
Section 734.13 and remote access. The sharpest finding is that Commerce has previously taken the opposite position: the letter reportedly cites § 734.13 as the basis for treating model access as within EAR scope, but "this exact section was used by Commerce in three previous Advisory Opinions as the reason why remote access transactions are not subject to the EAR."
The analysis adds a structural point about what an export is: "It is unclear how user access to models equates to a release of EAR software or technology to any foreign nationals except those working at Anthropic. The models or model weights are not being exported. Foreign nationals are instead accessing those models on servers operated by Anthropic." Its legislative evidence is the House's passage of the Remote Access Security Act — "precisely" because "ECRA does not authorize regulating remote access."
On the U.S.-persons route, service controls are within EAR scope for WMD or military-intelligence end uses, but "the EAR only allows Commerce to impose a worldwide license requirement on U.S. persons' activities when support enables chemical and biological weapons end uses."
The analysis also notes that the AI diffusion rule, published January 2025, does control model weights including through the foreign direct product rule, but "is not currently being enforced pursuant to a May 2025 announcement by BIS, and therefore license requirements on AI model weights are not in effect."
Paths to restoration
Three options are set out. Negotiated retraction "based upon negotiations demonstrating that the identified vulnerability has been resolved" is described as "the most likely path," with Anthropic having "reportedly already met with White House officials." Legal action would contest "either (1) the basis for action or (2) the scope of countries covered," on the ground that while "Commerce has wide latitude to impose license requirements on individual companies… the basis for such action is tied to rationale that can constrain the scope of countries impacted." Compliance within the order's terms would require identity and citizenship verification for all users, with "the real difficulty" being "obtaining deemed export licenses for Anthropic's foreign national staff and for global end users."
Consequences
For industry generally. "While the export control at issue only applies to Anthropic, the confusion over BIS's authority to impose it raises uncertainty for all of U.S. industry. Underlying assumptions on what BIS can and will control are now in question." The analysis quotes a senior White House official in Politico saying "export controls were a last resort," and draws the inference: "now that export controls have been used to control model access, every company must consider the possibility of such controls being used again."
For adoption of U.S. models. The jailbreak driving the action "is not restricted to Fable and is inherent to all modern language models." Near term, the action "is likely to drive some portion of Anthropic's customers to other AI labs"; longer term, "the uncertainty over durable access to any specific U.S. AI model is likely to drive potential foreign customers to consider options they deem more reliable, including use of small, open-weight models that can run on locally owned and operated hardware." European politicians "have cited the controls as further evidence of the need for sovereign AI, with dependency on U.S. AI seen as a supply chain vulnerability," and China gains "an opportunity… to make inroads on international adoption of its models, which lag the U.S. by 7 months on average."
The standards objection is stated as a boundary problem: "The lack of process and standards for U.S. companies risks creating an impossible bar—that the U.S. government will only allow the public release of models that cannot be jailbroken, even in theory."
Alternatives
CSIS's positive recommendation separates two uses of the instrument: "Export controls have a role to play in controlling access to certain physical components in the AI supply chain, most notably the computing capacity needed to train and operate advanced models. But export controls, at least on their own, are not a clear fit for resolving national security concerns for how models are being accessed and used." It points to new legislation, "expanded roles for other agencies or even creation of a new body with entirely new authorities."
It situates the action against the prevailing approach: the June 2, 2026 executive order "Promoting Advanced Artificial Intelligence Innovation and Security," itself "largely a response to the fears raised by Mythos for U.S. cybersecurity," established "a strictly voluntary framework for AI developers to collaborate with the government prior to releasing new models, which largely mirrors a practice that U.S. AI developers had already agreed to." The analysis notes that a licensing agency — proposed by Sam Altman at a 2023 congressional hearing and "largely dormant since then" — was "briefly reconsidered" by the administration in drafting that order "before ultimately scrapping it."
Relationships
- supports: Export Controls (AI) — analyses whether hosted-model access falls within EAR scope at all
- related: Legion v. United States (Anthropic export-directive challenge) — the complaint pleads substantially the same statutory defects
- related: Anthropic, Bureau of Industry and Security (BIS), Center for Strategic and International Studies (CSIS), EO — Promoting Advanced AI Innovation and Security (Trump, signed June 2, 2026), AI Sovereignty, Claude Mythos 5