I. Introduction
… [I]f you describe your product as a munition in every press release, eventually a government takes you at your word …
Peter Girnus, quoted in Fortune
That line captures the paradox at the heart of a recent dispute in artificial intelligence (“AI”) governance. On 12 June 2026, the United States of America (“US”) government, citing national security authorities, issued an export control directive suspending all access to Anthropic’s Fable 5 and Mythos 5 models (“the Models”), by any foreign national, whether inside or outside the US, including Anthropic’s own foreign national employees. Anthropic set the episode out in a public statement (the “Official Statement”). To comply, it disabled the Models for every customer worldwide. Its other models kept running.
No file was leaked, no source code shared and no foreign buyer involved. Anthropic’s understanding is that the government had learned of a way to “jailbreak” Fable 5 to surface minor software flaws. The company calls those flaws minor and easily found by rival public models without any bypass.
This article asks one question. Why did the US government reach for the export control law, a regime built to decide who may receive a technology, to address what was really a worry about whether a model is safe? Export control turns on nationality and destination. Safety regulation turns on the product itself. I argue that the government used the wrong instrument, that the law may not even authorise what it did, and that it reached for this tool only because no proper statute exists to restrict an unsafe model.
II. The Law Behind the Directive
Let’s start with how US export control works. The Export Control Reform Act of 2018 (“ECRA”) is the governing statute. The Commerce Department runs it through the Bureau of Industry and Security (“BIS”), which applies a rulebook called the Export Administration Regulations (“EAR”). Section 1758 of ECRA lets the government control “emerging and foundational technologies” important to national security. The whole system exists to stop strategic items from crossing borders into the wrong hands. It asks who may hold a technology, and where.
One feature explains the worldwide situation. The EAR treats the release of controlled technology to a foreign national, even inside the US, as an export to that person’s home country. This is the “deemed export” rule. A directive aimed at foreign nationals therefore captures non-citizen staff and overseas users alike.
That breadth also showcases a mismatch. A jailbreak that unlocks a dangerous capability is just as usable by an American as by anyone else. Blocking access by nationality does nothing about misuse at home. If the real concern is the capability, the user’s passport is beside the point. The directive polices identity while the stated risk lives in the product.
One might object that this was a question of who gets access to the technology from the start. The directive named foreign nationals, and keeping a sensitive capability from foreign adversaries is the classic work of export control. The objection however, fails on the facts. Export control only bites when restriction works, when the adversary cannot simply obtain the thing elsewhere. The Official Statement concedes the capability is available from other public models, such as OpenAI’s GPT 5.5, and the Models already serve hundreds of millions. Blocking one firm’s foreign users denies no one anything. And the harm the government described lives in the model, not in the passport of the person prompting it. A domestic actor running the same jailbreak gets the same result, so the restriction leaves the danger untouched at home. Export control here is futile as strategic denial and mismatched as safety regulation. That is what it means to say the tool sorts by who, while the issue is whether.
III. Does Export Law Even Reach a Public Model?
There is a deeper difficulty. Export law may not cover a model like this at all. The EAR carries a long-standing exception for “published” material. Software and technology made available to the public without restriction, including anything posted openly on the internet, falls outside the EAR entirely. A model offered to hundreds of millions of users, with open sign-up, sits uneasily inside a regime built for secrets.
The fit is awkward in both directions. Anthropic keeps the Models’ weights private and wraps access in safeguards and usage terms, so a regulator could argue the core technology was never published without restriction. Anthropic had flagged the danger itself. At launch it acknowledged that the Models could cause serious harm if their cyber capabilities were misused, and it released them only after building in safeguards. Yet users never receive those weights. They reach the Models only through an application programming interface (“API”), which streams output from servers inside the US. Nothing crosses a border in the ordinary sense.
The US Congress is currently trying to close this grey gap. The Remote Access Security Act would extend export controls to cover remote access to US-controlled items through the cloud, and the House passed it in January 2026 (HR 2683). A statute written to create this power suggests the power is not clearly there yet. Commentators agree the old frameworks fit badly, noting that rules built for “discrete transfers of static information between known parties” cannot easily govern systems that generate fresh output on demand.
IV. A Power Congress Never Clearly Gave
Suppose the EAR does reach the Models. A second problem follows. When an agency uses an old statute to make a decision of vast economic and political importance, courts now demand clear authorisation from Congress. This is the major questions doctrine, applied in West Virginia v. EPA and later cases.
Months before the directive, the Supreme Court used the same logic to strike down a different emergency measure. In Learning Resources, Inc. v. Trump, decided in February 2026, the Court held by six to three that the International Emergency Economic Powers Act (“IEEPA”), which lets the President “regulate” imports, did not authorise sweeping tariffs. The statute never mentioned tariffs. Such an extraordinary power, the Court said, must be granted expressly. No President had stretched IEEPA that way before.
The Anthropic directive is the export control version of those tariffs. Deciding which people across the world may use a leading commercial AI product, through a trade statute that never mentioned hosted models, is exactly the kind of unprecedented and far-reaching move the major questions doctrine flags. The Congress still legislating to add this very authority only sharpens the doubt. A court might still defer, since national-security trade powers draw wide judicial respect. Even so, the deeper point holds. A choice this large belongs to Congress, not to an agency acting alone.
V. A Directive Without Process
Even setting authority aside, the directive skipped the process a serious decision demands. Export law is built that way. By statute, the export functions exercised under ECRA sit outside the core provisions of the Administrative Procedure Act (“APA”), including notice-and-comment rulemaking and the usual route to judicial review (50 U.S.C. § 4821(a)). The notice-and-comment exemption is reinforced because export control counts as a military and foreign-affairs function (5 U.S.C. § 553(a)(1)). A company’s main recourse is an internal agency appeal as per Part 756 of the EAR, and not a court. Speed and secrecy are built in the framework.
The consequences are stark. Because Congress removed normal review, the only realistic challenge left is a constitutional one. Under Webster v. Doe, courts may still hear a “colourable constitutional claim” even where a statute blocks review, but little else survives. A company that loses a worldwide product overnight has almost no ordinary administrative remedy.
What the company received matches that thin protection. The Official Statement says the letter gave no specific reasons and “…[Anthropic]… believe[s] the government should have the ability to block unsafe deployments, as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. This action does not adhere to those principles.” There was no published standard for when a model must be withdrawn, no findings on a record, and no hearing before access vanished for everyone. Courts have warned against this. In Bernstein v. United States Department of Justice, a Ninth Circuit panel held that software code is protected speech, and that an export licensing scheme giving officials broad discretion without procedural safeguards is an unconstitutional prior restraint. That panel was later withdrawn for rehearing, but its reasoning still resonates. A standardless letter pulling a model down invites a similar objection.
VI. What Lawful Oversight Looks Like
None of this means frontier models should escape control. It means control should run through law built for the task, and two models already show a better way.
First, the European Union’s AI Act regulates general-purpose systems that carry “systemic risk”. Article 51 sets a defined trigger based on training compute, imposes duties of testing and cybersecurity, and lets the regulator restrict or withdraw a model only as a last resort. Article 93 requires a structured dialogue with the developer before any such step. The state can act, but it must give reasons and allow a response.
Second, California shows what a home-grown answer looks like. Its 2025 Transparency in Frontier Artificial Intelligence Act (“SB 53”) is the first American statute aimed squarely at AI safety. It reaches only the largest developers and works through openness rather than a sudden order. Covered firms must publish a safety framework, report serious incidents to the state within fixed deadlines, and answer to the Attorney General, who can fine them for breaches. The approach is preventive rather than punitive, built to surface dangers before they occur. It also speaks straight to this dispute. SB 53 already treats a model’s potential to enable large-scale cyberattacks, or to slip free of human control, as a catastrophic risk to be managed in the open. That is the same family of concern the government raised about Fable 5. The country had a purpose-built tool for the job and reached for a trade statute instead.
The contrast is the whole argument. Anthropic itself accepts that the government should be able to block an unsafe deployment, but only through a process that is “transparent, fair, clear and grounded in technical facts”. That is a request for law, not a rejection of oversight.
One detail makes the gap impossible to miss. Just ten days before the directive, the President signed an executive order on frontier AI. It created only a voluntary framework for developers to engage the government before release, with no enforceable rights. The proper tool was optional. Ten days later, the government used export law to force a model offline. When the lawful instrument is voluntary, the state grabs whatever hard instrument lies nearest.
VII. Conclusion
The directive to suspend all access to Fable 5 and Mythos 5 models by any foreign national is a warning, not a precedent to follow. It shows a government using a border-control trade tool to do the work of product-safety regulation, a task that tool cannot perform. The restriction missed the real risk, because a jailbreak does not care about a user’s nationality. It may have exceeded the law, because a trade statute never clearly authorised it. And it skipped fair process, because export law was built for speed and secrecy, not reasoned decisions.
The answer is not less oversight of capable models. It is a framework designed for the question these models actually pose. Until one exists, every new frontier model sits one letter away from a worldwide shutdown, ordered without standards and shielded from review.
Manraj Singh Chandpuri is a third-year B.A. LL.B. student at the University Institute of Legal Studies, Panjab University. He is the founder of www.RightSignal.co, a legal technology program on AI training and machine-readable rights reservations.

