AI & Models
Cybersecurity experts protest US ban on Anthropic models
Cybersecurity experts are protesting a US government export ban on Anthropic’s Fable and Mythos models, arguing the restriction may be based on flawed security assumptions.
A group of 76 cybersecurity experts has published an open letter asking the US government to lift its export control order on Anthropic’s Fable and Mythos models. The signatories, who include cybersecurity expert Katie Moussouris, argue that the government’s action has taken the best models away from cybersecurity defenders. They assert that pulling these capabilities away from defenders without a good reason while adversaries are rapidly advancing is “dangerous.” The open letter argues that the ban hinders the ability of security professionals to find vulnerabilities and secure software.
The US government issued the export control order on Friday, directing Anthropic to limit the export of Fable and Mythos due to national security concerns. In response, Anthropic suspended access to the models for all users worldwide, affecting organizations across 15 countries. The restriction interrupted a planned rollout for Mythos, which launched as a preview in April. Anthropic had initially given access to around 50 companies, later expanding that group to around 150 organizations before the export ban was imposed. Last week, Anthropic released Fable, a version of the model equipped with strict guardrails—which are safety restrictions built into AI models—designed to block its use in cybersecurity.
Anthropic stated that the export control order may have been based on a report concerning a method to bypass Fable’s guardrails. However, cybersecurity experts argue that the underlying research, authored by Amazon researchers, does not demonstrate a true jailbreak, which is a technique to bypass AI safety guardrails. Instead, the method described in the Amazon paper simply involved asking the model to fix code with known or deliberately planted vulnerabilities. According to the group of experts, this method can be replicated on other AI models, including OpenAI’s GPT-5.5, Anthropic’s Claude Opus 4.8 and Sonnet, and Kimi 2.7.
Moussouris, a signatory of the letter, pointed out that the behavior described in the Amazon paper cannot meaningfully be fixed, and attempting to do so would only weaken the model for defensive purposes. She explained: “Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.” The letter also called for transparent regulations created through a democratic rule-making process, designed to ensure the safety of the American public.
Why it matters
The US government’s export control order on Anthropic’s Fable and Mythos models has removed critical tools from cybersecurity defenders, prompting an outcry from industry experts who argue the ban hinders their ability to secure software.