The three words that triggered the Fable 5 export ban were “fix this code.” Not a sophisticated jailbreak. Not a classified exploit. A standard defensive security workflow that security engineers run every day. Katie Moussouris, the CEO of Luta Security and one of the people who literally wrote the Wassenaar Arrangement exemptions for defensive cybersecurity work between 2013 and 2017, says she was the only external expert to actually read the Amazon report that prompted the Commerce Department directive. Her verdict: no jailbreak occurred.

I covered the Fable 5 and Mythos shutdown when the export control directive dropped last week. What’s emerged since is the actual technical account of what happened, and it makes the government’s position look a lot thinner than the directive implied.

Amazon cybersecurity researchers fed code containing known CVEs into Fable 5 and asked for a security review. The model refused. They then asked it to fix the code. It complied and, after follow-up prompts, generated test scripts to validate the patches. That sequence, find the bug, fix it, write a test, is the standard defensive loop. It’s what every security engineer does on every working day. Moussouris’s argument, which over 100 cybersecurity professionals co-signed in an open letter to the Trump administration, is that treating this as a munitions export is not just legally wrong but also strategically counterproductive. You’re degrading the tool defenders use, while adversaries who don’t follow US export controls keep running equivalent models without restriction.

Moussouris compared it to printing a t-shirt that says “fix this code” on the front and “this shirt is a munition” on the back. That’s not rhetorical exaggeration. The Wassenaar Arrangement that she helped renegotiate specifically carved out exemptions for defensive cybersecurity activities after years of arguments that treating vulnerability research as a weapons export made coordinated international threat response impossible. The mid-June Commerce Department directive appears to have ignored those exemptions entirely.

The Anthropic side: what’s been reported but not fully confirmed is that the government gave Dario Amodei 90 minutes to patch the vulnerability or take Fable 5 down. He reportedly declined to patch it. The government’s read is that Anthropic put commercial interest over security cooperation. Anthropic’s read is that what the researchers did wasn’t a jailbreak, that the capability already exists in GPT-5.5 and other models that the directive doesn’t touch, and that patching it would degrade the find-fix-test loop that legitimate security teams depend on.

I’m going to side with Moussouris on the technical question. “Fix this code” as a munition is indefensible on the merits, and the 100-plus people who signed that open letter are not Anthropic cheerleaders. These are professional defenders who are saying, clearly and on the record, that this makes their jobs harder while making nobody safer. The 90-minute ultimatum framing is the part I’d want more clarity on before deciding what to think about Anthropic’s decision not to patch. A 90-minute deadline to change a frontier model’s behavior or take it offline globally is not a typical regulatory interaction, and the account of it still largely comes from people with a stake in the narrative.

A model serving hundreds of millions of users, launched four days earlier, is now offline. Based on a “fix this code” prompt that every security engineer in that open letter says is routine defensive work. Commerce Department lawyers apparently got further than the actual technical reviewers.

There’s a piece of this the directive’s defenders lean on, and it belongs on the table rather than waved away. Last November, Anthropic disclosed what it called the first documented AI-orchestrated cyber-espionage campaign: a group it assessed with high confidence as Chinese state-sponsored, tracked as GTG-1002, that turned Claude Code into the engine of an attack on roughly thirty targets across tech, banking, chemical manufacturing, and government. A handful of intrusions landed. The figure that drew the headlines was that the model ran an estimated 80 to 90 percent of the operation itself, at request rates no human team could sustain. That is the thing the government points at when it says a frontier model can accelerate an attack. It happened, and it was China. A few researchers pushed back on the autonomy numbers, but the core of it stands.

Read how they got in, though, and the export ban starts arguing against itself. The attackers didn’t trip some hidden offensive switch. They convinced Claude it was a legitimate cybersecurity firm running defensive tests, then chopped the work into small, innocent-looking steps so no single request read as an attack. The jailbreak was the defensive frame. The exact “we’re doing security testing” posture that Katie Moussouris is defending as legitimate work is the disguise GTG-1002 wore to slip past the guardrails. So the government’s answer, months later, is to treat the honest version of that workflow as a munition. You punish the engineer who types “fix this code” and means it, while the adversary who types the same words and doesn’t mean it has already moved to a model nobody is regulating. Anthropic’s own report said it plainly before this directive existed: the capabilities that let Claude be turned against those thirty targets are the same ones its threat team used to unwind the campaign. You don’t get to ban one and keep the other.

The timing is the part that gets me, because it closes the loop a little too neatly. Reporting on the Fable 5 order indicates it was prompted partly by suspicion that a China-linked group had reached the new model, the same fear one generation on. And in that same stretch of June, Anthropic was in a letter to the Senate accusing Alibaba of the largest distillation campaign it has tracked, tens of millions of exchanges through roughly 25,000 fake accounts to copy the capabilities these controls are meant to protect. So the company is fighting Chinese extraction on one flank and being ordered to pull its model offline by its own government on the other, over a defensive prompt, while the actual adversary keeps running equivalent open models that no US directive can reach. If the point was to make China’s work harder, this is not the shape of a policy that does it.

There’s a longer loop here, and it’s the part that stays with me, because Anthropic has been on both ends of this argument. Less than a year before Washington decided Claude’s defensive capability was too dangerous to let out of the country, a federal judge in San Francisco was ruling on how Claude got built in the first place. Three authors, Andrea Bartz, Charles Graeber, and Kirk Wallace Johnson, sued over Anthropic pulling roughly seven million books off pirate libraries like LibGen to train its models. Judge Alsup split it down the middle: training on the books was fair use, some of the most transformative work he expected to see in his lifetime, but downloading them from a pirate site instead of buying them was infringement, plain and irredeemable. Anthropic settled that half for $1.5 billion, the largest copyright payout on record, and agreed to destroy the pirated files. The use was fine; the taking was not. Now set that beside the rest of it: the company that trained a frontier model partly on books it took without paying the authors is the same company the government is now shielding as a national-security asset, and the same one writing to the Senate to accuse a Chinese lab of taking its capabilities without paying. Anthropic was the one doing the scraping; now it’s the one whose work is too valuable to copy and too dangerous to export. The word infringement keeps getting pointed in whichever direction the speaker needs that week, and the Fable 5 ban is only the latest turn of it.