• Uncategorized

When the Government Pulls the Plug: Anthropic, Export Controls, and the Future of AI Governance

On June 12, 2026, at 5:21 p.m. ET, the U.S. government handed Anthropic a directive that forced the company to do something extraordinary: disable its two most powerful AI models—Fable 5 and Mythos 5—for every single customer worldwide, with no advance notice and no specific explanation of the national security concern that justified the action.

The directive, issued by the Commerce Department’s Bureau of Industry and Security under the signature of Commerce Secretary Howard Lutnick, ordered Anthropic to suspend all access to Fable 5 and Mythos 5 by any foreign national—whether inside or outside the United States, including Anthropic’s own foreign-national employees. Because Anthropic cannot reliably distinguish foreign nationals from U.S. persons in real time across its user base of hundreds of millions, the practical result was a hard global shutoff of both models for all customers.

This is a watershed moment—not just for Anthropic, but for the AI industry, for technology companies, and for every compliance professional and general counsel who advises clients that deploy or rely on advanced AI systems. The implications extend far beyond a single company or a single product outage.

What Actually Happened

The Commerce Department acted, according to administration officials, after another company claimed it had successfully jailbroken Mythos—a technique that would allow users to circumvent the model’s safety guardrails. Anthropic responded that it had received only verbal evidence of a narrow, non-universal jailbreak, and that it had not been provided specific details about the alleged national security concern underlying the directive.

Anthropic’s public statement was sharply critical of the government’s handling of the matter. The company stated: ‘We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people. If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers.’ Anthropic called the action a ‘misunderstanding’ and said it was working to restore access as soon as possible.

The directive did not affect Anthropic’s other models. Only Fable 5 and Mythos 5 were suspended. But the manner in which it was executed—without specific technical findings shared with the company, based on verbal reports of a narrow jailbreak, with no advance process—raises legal and policy questions that will outlast this particular episode.

The Broader Context: This Did Not Come Out of Nowhere

To understand what happened on June 12, you have to understand what has been happening to Anthropic since February 2026. This export control directive is not an isolated event. It is the latest escalation in an ongoing and deeply serious conflict between Anthropic and the Trump Administration.

In February 2026, after months of failed contract renegotiations over the military’s use of Claude, President Trump directed all federal agencies to cease using Anthropic’s AI technology. Defense Secretary Pete Hegseth designated Anthropic a ‘supply chain risk’—the first time that designation, historically reserved for foreign adversaries like Huawei and ZTE, had ever been applied to an American company. The underlying dispute: the Pentagon demanded that Anthropic waive its contractual restrictions on the use of Claude for mass domestic surveillance of Americans and for fully autonomous weapons systems without human oversight over targeting and firing decisions. Anthropic refused.

Anthropic filed lawsuits challenging the designation in two federal courts on March 9, 2026—one in the Northern District of California, one in the D.C. Circuit. A federal judge in San Francisco granted Anthropic a preliminary injunction barring the Trump Administration from enforcing the Claude use ban. The D.C. Circuit denied Anthropic’s request to temporarily block the supply chain risk designation while litigation proceeds.

Friday’s export control directive must be read against this backdrop. Anthropic has been litigating against the government for months, accusing the Administration of acting beyond its legal authority, arbitrarily, capriciously, and in retaliation for Anthropic’s refusal to let its models be used for mass surveillance and autonomous weapons. The BIS directive lands in the middle of active litigation with the same Administration.

The Export Control Legal Framework: What Authority Is Being Invoked?

The Commerce Department’s Bureau of Industry and Security administers the Export Administration Regulations, which govern the export, re-export, and transfer of items—including technology and software—that have dual-use potential. The EAR applies to items on the Commerce Control List, and in recent years BIS has increasingly applied export control concepts to advanced AI models and the technology underlying them.

The June 12 directive is reported to have been issued under ‘national security authorities’—the specific statutory basis has not been publicly identified with precision. This matters for two reasons. First, the scope of BIS authority over AI model access is not yet fully defined by statute, regulation, or court decision. Second, Anthropic’s own public challenge—that a narrow, non-universal jailbreak does not legally justify recalling a commercial model deployed to hundreds of millions of people—is implicitly a legal argument about whether the government’s invocation of national security authority was appropriate and proportionate to the alleged risk.

The compliance community should watch closely for how the government articulates the specific legal basis for this directive, because that articulation will define the scope of BIS authority over AI deployments going forward.

The Compliance Implications: What Companies Using AI Must Understand Now

For compliance officers, general counsels, and technology companies deploying or relying on advanced AI models, the June 12 directive creates immediate and serious compliance and risk management questions. Here is what your compliance program needs to address:

  • Third-party AI risk is now a government enforcement risk, not just a vendor management risk. If a government agency can order a frontier AI provider to suspend its most capable models with no advance process, no specific findings shared with the company, and no meaningful opportunity to contest the action before it takes effect, then companies that rely on those models face service disruption risk that no SLA can fully address. This belongs in your third-party AI risk assessment framework.
  • The ‘foreign national’ compliance trigger has enterprise-wide implications. The directive applied to foreign nationals ‘whether inside or outside the United States, including foreign national Anthropic employees.’ For companies with international workforces who use AI models in their operations, this raises immediate questions about access controls, workforce data, and how nationality-based restrictions can be implemented in real time at enterprise scale—questions that most companies have never had to answer for a commercial software product.
  • AI model export controls are an emerging and fast-moving regulatory category. Friday’s directive is not the end point—it is an early signal of a regulatory trajectory. BIS has been expanding its focus on advanced AI technologies. Companies building AI-dependent products and services need to incorporate export control analysis into their AI governance programs, just as they would for any other dual-use technology.
  • The legal authority question is live and contested. Anthropic has publicly disputed the legal basis for this action, just as it disputed the DOD supply chain risk designation. If litigation follows—and given the existing litigation posture, it very well might—the courts will be asked to define the limits of BIS authority over AI model access. Companies and their counsel should track this closely.
  • Process and due process matter. Anthropic’s statement specifically calls out that the government did not provide specific details of its national security concern and that the action does not adhere to principles of transparency, fairness, and technical grounding. Whether or not those concerns prevail legally, they signal a significant absence of the kind of structured process—notice, technical review, opportunity to respond—that companies have come to expect in regulatory enforcement.

The Governance Gap This Exposes

Perhaps the most important compliance and policy observation is this: there is no clear, comprehensive statutory framework governing government authority to restrict commercial AI model access on national security grounds. The Export Administration Regulations were not designed with frontier AI models in mind. BIS’s existing authorities—powerful as they are in their traditional domains—were built around discrete items with defined technical parameters, not models trained on vast datasets and deployed through API access to hundreds of millions of users worldwide.

Anthropic made exactly this point in its public statement: ‘We believe the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. This action does not adhere to those principles.’ This is not a company saying the government should have no authority. It is a company saying the authority needs a legal architecture that does not currently exist—and that ad hoc directives issued without process, based on verbal reports of narrow jailbreaks, are not an adequate substitute.

The AI governance gap is real. Congress has not enacted comprehensive AI legislation. The regulatory framework is fragmented across agencies with different authorities and different mandates. The Executive Branch is asserting novel authorities over commercial AI systems in the context of active political conflict with specific companies. And the courts have not yet drawn the lines.

For compliance professionals, that governance gap is itself a risk factor that must be addressed in your AI governance program. The question is not just whether the AI models your company uses are safe and responsible. The question is also: what happens to your operations if the government pulls the plug?

You may also like...