Regulation

US Government Temporarily Blocked Anthropic’s Claude Mythos AI Over Cybersecurity Risks

The advanced model’s ability to uncover critical vulnerabilities triggered a two-week export control order, reshaping AI governance and global cybersecurity dynamics.

Editorial·10 Jul 2026
US Government Temporarily Blocked Anthropic’s Claude Mythos AI Over Cybersecurity Risks

Anthropic’s most advanced AI model, Claude Mythos, was publicly announced on April 7, 2026, but its release was abruptly halted by the US government just two months later—only to be partially restored after a fortnight of high-stakes negotiations. The intervention marks a turning point in the governance of frontier AI, demonstrating how national security concerns can override corporate timelines and reshape the global cybersecurity landscape in real time.

Mythos didn’t merely outperform existing benchmarks; it redefined them. During internal testing, the model achieved a perfect score on Cybench, a rigorous evaluation of AI reasoning, and autonomously uncovered a 17-year-old remote code execution vulnerability in FreeBSD, a widely deployed open-source operating system. This capability underscored its potential to accelerate both offensive and defensive cyber operations, forcing policymakers and industry leaders to confront a new reality: AI systems can now identify critical flaws faster than human teams—and potentially faster than they can be patched.

Unprecedented capabilities meet unprecedented controls

The model’s technical prowess was matched by its immediate impact. Within weeks of its announcement, Anthropic launched Project Glasswing, a $100 million defensive initiative leveraging Mythos to proactively identify and remediate vulnerabilities. The project’s founding members included a who’s who of tech and finance: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, Microsoft, NVIDIA, Palo Alto Networks, and the Linux Foundation. The European Union Agency for Cybersecurity (ENISA) later joined, signaling the initiative’s growing international significance.

Glasswing’s results were staggering. By deploying Mythos in a controlled, collaborative environment, the project identified over 10,000 high- and critical-severity vulnerabilities in a matter of weeks—a figure that dwarfed typical disclosure rates. The scale of these findings offered a preview of what unchecked access to such a model might entail: an exponential increase in the discovery of exploitable flaws, with both defensive and offensive implications.

It was this dual-use potential that triggered the US government’s intervention. On June 12, 2026, the US Department of Commerce, led by Secretary Howard Lutnick, issued an export control order blocking access to Mythos for all foreign nationals, including non-US employees of Anthropic. The decision was rooted in fears that the model could be "jailbroken" or accessed by adversarial states, particularly China, thereby providing a strategic advantage in cyber warfare. The order also extended to Fable 5, a companion model developed alongside Mythos, further underscoring the administration’s resolve to contain perceived risks.

Anthropic, anticipating such concerns, had already taken steps to mitigate them. The company’s cofounder and Chief Compute Officer, Tom Brown, led negotiations with the US government, arguing that a controlled, phased release was necessary to prevent the model from being weaponized before defenses could be shored up. Yet even these precautions were not enough to avoid the initial block, which left Anthropic and its partners in a state of limbo.

A partial reversal and its global repercussions

After two weeks of intense discussions, the US government partially relented. On June 27, 2026, restrictions were eased for over 100 trusted US institutions, allowing their foreign employees to access Mythos without an export license. This decision, reported by outlets like Semafor and the South China Morning Post, suggested that Anthropic had agreed to implement additional safeguards, though the specifics of these measures were not publicly disclosed. By July 1, 2026, Anthropic confirmed that full access to both Mythos and Fable 5 had been restored, signaling a tentative resolution to the standoff.

The rapid reversal did little to quell the broader unease within the AI community. Francesco Bailo, a researcher at the University of Sydney, described the episode as a "dangerous, messy precedent," warning that it could embolden governments to assert greater control over AI releases in the future. Tanishq Abraham of Sophont echoed these concerns, noting that while the relationship between Anthropic and the US administration appeared to be improving, the incident exposed the fragility of trust between developers and regulators. The lack of transparency around the safeguards that secured the ban’s reversal only deepened the uncertainty for other AI labs navigating similar challenges.

Meanwhile, the fallout from Mythos’ restricted release was already being felt across the industry. Public disclosures of severe CVEs (Common Vulnerabilities and Exposures) surged to approximately 1,500 in June 2026, a 3.5× increase over the previous monthly average of around 430, according to data from Epoch AI. This spike reflected not only Mythos’ prowess in uncovering vulnerabilities but also the urgency of defensive collaboration. Yet it also raised questions about whether organizations could keep pace with the accelerating discovery of flaws, particularly as AI-driven tools became more widespread.

The US government’s unilateral action also sparked frustration among international allies and non-US companies. European officials, in particular, criticized the dependence on Washington’s decisions, arguing that such controls could hinder global cooperation on cybersecurity. The initial exclusion of non-US entities from Mythos access underscored a growing divide between US-led AI governance and the rest of the world, with many fearing that critical tools could be weaponized or withheld for geopolitical ends.

Competitive fallout and the fragmentation of AI access

Anthropic was not the only company affected by the shifting regulatory landscape. Competitor OpenAI delayed the public launch of its GPT-5.6 model after facing similar government pressure, opting instead to limit access to vetted partners. This parallel development suggested that export controls and selective deployment were becoming standard features of frontier AI releases, at least in the short term. For multinational firms, the message was clear: access to cutting-edge AI tools was increasingly contingent on geopolitical alignment and compliance with evolving—and often opaque—regulations.

The implications for global businesses are profound. Companies operating across borders must now account for the possibility of fragmented access, where employees in one country may be granted permissions that are denied to colleagues elsewhere. This fragmentation could hinder collaboration, slow innovation, and create disparities in cybersecurity capabilities between regions. Moreover, the lack of clarity around the criteria for access—or the safeguards required to obtain it—leaves many organizations in a state of uncertainty, forced to navigate a regulatory environment that is still being defined.

For AI developers, the Mythos episode serves as a cautionary tale. The rapid imposition and subsequent lifting of export controls demonstrate that frontier AI deployment is now subject to real-time geopolitical negotiation. This volatility introduces new risks for companies investing in advanced models, as the commercial viability of their products may hinge on government approvals that are difficult to predict or secure. The precedent set by Mythos suggests that future releases could face similar scrutiny, particularly in areas where national security concerns intersect with technological capability.

The new cybersecurity paradigm: Collaboration under constraint

The Mythos saga reveals a fundamental shift in the development and deployment of AI. The model’s ability to autonomously uncover vulnerabilities at scale has accelerated the cybersecurity arms race, forcing organizations to adopt AI-driven defensive measures or risk falling behind. Project Glasswing’s success—finding over 10,000 critical flaws in a matter of weeks—demonstrates that pre-release, collaborative hardening with AI is becoming a necessity for providers of critical infrastructure. The initiative’s expansion to include ENISA further highlights the growing recognition that cross-border cooperation is essential to addressing the global challenges posed by advanced AI.

Yet the episode also exposes the tensions between innovation and control. While Anthropic and its partners argued that an unrestricted release would give attackers an advantage before patches could be deployed, critics countered that the government’s intervention was an overreaction to risks that may have been exaggerated. The lack of transparency around the specific safeguards that led to the ban’s reversal only deepens the uncertainty for other AI developers navigating similar terrain. Some industry observers have questioned whether the 3.5× spike in CVE disclosures is sustainable—or whether it reflects a temporary surge driven by the novelty of Mythos’ capabilities.

Looking ahead, the precedent set by Mythos suggests that frontier AI models will face increasing scrutiny from governments, particularly in the US, where national security concerns often outweigh commercial or scientific considerations. For global professionals, the lesson is clear: the era of unfettered AI advancement is over. The future will be shaped by a delicate balance between collaboration and control, with geopolitics playing an ever-larger role in determining who gets access to critical tools—and who doesn’t.

As AI continues to reshape cybersecurity, the need for international frameworks that address both the opportunities and risks of these technologies has never been more urgent. The Mythos episode underscores the importance of dialogue between developers, policymakers, and the broader AI community to ensure that advancements in the field are harnessed for the greater good—without sacrificing the innovation that drives progress.

#AI governance #cybersecurity #export controls #frontier models

Newsletter

Get the AI news that matters

One short brief with the day's most important AI stories — written for professionals.

We send a confirmation link. No spam. Unsubscribe anytime.