The Kill Switch
How a late-night phone call, a billion-dollar investment gone sour, and ninety minutes of government pressure ended Anthropic's most powerful AI, and what it means for the rest of the world
At 5:21 p.m. Eastern Time on Friday, June 13th, Anthropic received a letter. It came from the United States Department of Commerce, and it was not long. The gist of it was simple: the company had ninety minutes to shut down its two most advanced artificial intelligence models, Fable 5 and Mythos 5, for every user outside the United States. By ten o'clock that evening, the models were dark.
The official explanation was national security. But the real story, as it tends to be with Washington, is considerably more interesting than that.
The phone call
The night before, a Thursday, Andy Jassy, the chief executive of Amazon, a company that has invested over four billion dollars in Anthropic and hosts its infrastructure on its cloud, called the United States Treasury Secretary Scott Bessent. He also called a number of other senior administration officials. He had something to show them: an internal report, prepared by Amazon's own researchers, claiming they had found a way to "jailbreak" Mythos 5, Anthropic's most capable model, and coax it into producing information that could, in theory, be weaponized.
Administration officials spent the early hours of Friday in conversation with Anthropic, pressing the company to pull its models voluntarily. Anthropic refused. At one o'clock in the afternoon, the government issued its ultimatum. At five-thirty, Commerce Secretary Howard Lutnick's letter arrived. By the time most Americans sat down to dinner, Fable 5 and Mythos 5 no longer existed, not for anyone abroad, and, since compliance was impossible to guarantee any other way, not for anyone at all.
The paradox at the center of this episode is worth sitting with for a moment. Amazon, the company that lit the fuse, is also one of Anthropic's largest financial backers. It is, in a very real sense, both the arsonist and the landlord. Whether this constitutes a conflict of interest, or merely the peculiar logic of Silicon Valley, where every major player is simultaneously a partner, competitor, and potential regulator of every other, is a question the industry has been quietly avoiding for years. Friday's events made it a good deal harder to avoid.
A narrow jailbreak, and a convenient one
Anthropic did not go quietly. In a public statement issued the same evening, the company disputed nearly every premise of the government's action. The jailbreak Amazon had demonstrated, Anthropic said, was "narrow" and "non-universal," a set of prompts rather than a fundamental flaw in the model's architecture. More pointedly, Anthropic noted that the same technique worked just as well on GPT-5.5, OpenAI's flagship model, which had received no letter from the Department of Commerce, no ultimatum, no ninety-minute countdown.
To understand why this matters, a brief technical digression is necessary. Fable 5 was not simply a powerful AI model released to the public. It was Anthropic's attempt to thread an extremely delicate needle: making the capabilities of its Mythos class available broadly, while wrapping those capabilities in a layer of safety systems, a so-called classifier, designed to intercept dangerous requests before the model could act on them. If a user asked about cyberattacks, or weapons, or certain categories of sensitive chemistry, the classifier would detect the intent and redirect the query to a less capable model. The jailbreak Amazon described did not defeat Mythos 5. It defeated the classifier, using techniques like substituting Cyrillic characters for Latin letters, burying harmful requests inside very long conversations, or framing dangerous queries as academic exercises or fictional scenarios.
Katie Moussouris, the chief executive of Luta Security, whom Anthropic shared the Amazon report with, was blunt in her assessment. The government's response, she told Axios, "seems way out of line with what's actually in the research report." The information the jailbreak could elicit, she added, was far more useful to defenders of computer systems than to attackers. Security researchers do this kind of work every day.
None of which is to say the vulnerability was trivial. It is to say that it was not unique to Anthropic, that it was not the kind of discovery that typically triggers an emergency export control directive, and that the question of why this particular company was singled out, while its competitors were not, has not yet received a satisfactory official answer.
Singapore and the art of the pretext
Here is something that did not make the headlines, but probably should have. Two weeks before the ban, Anthropic closed a funding round of sixty-five billion dollars, at a valuation approaching one trillion. The co-lead investors were GIC and Temasek, the two sovereign wealth funds of Singapore. They had been here before: GIC had co-led Anthropic's previous round as well, and both Singaporean funds, along with the Qatar Investment Authority, had participated in the Series F in September 2025.
In other words, Anthropic is substantially owned, in the financial sense, by foreign governments. In the political vocabulary of the current administration, where "national security" and "economic sovereignty" have become nearly interchangeable, this is not an incidental detail. It is a lever. You do not need to prove that Singapore is a threat to American interests, an implausible claim, given that Singapore is one of Washington's closest partners in Southeast Asia. You need only invoke the word "foreign," and the machinery of export control law begins to move.
The question of whether that machinery was designed for situations like this one is, to put it charitably, contested. As the legal scholars Joe Khawam and Tim Schnabel noted in Just Security, export control frameworks "were designed for discrete transfers of static information between known parties" and are "ill-suited to govern AI systems that generate unlimited, dynamic outputs on demand for potentially anonymous users worldwide." The administration has not publicly explained which legal authority it believes applies here. It has not, in fact, publicly explained much of anything.
The ghost of retaliation
There is another chapter in this story that has received surprisingly little attention, perhaps because it is uncomfortable for everyone involved. In July of 2025, Anthropic signed what appeared to be a landmark agreement with the Pentagon: Claude would become the first frontier AI model approved for use on classified military networks. It was a deal worth billions, and it seemed to signal a productive, if complicated, relationship between the company and the federal government.
The deal collapsed in February 2026. The Pentagon, it emerged, had demanded that Anthropic permit the use of Claude "for all lawful purposes," a phrase that, in the military context, included lethal autonomous weapons systems and the mass surveillance of American citizens. Anthropic refused. On March 9th, the company filed suit in the Northern District of California, alleging retaliation, due process violations, and breaches of administrative procedure.
Three months later, the government shut down its most advanced models.
No one can prove causation. The administration has offered no comment on the lawsuit in connection with Friday's events. But the sequence of events is, at minimum, a fact. And facts, in cases like this one, have a way of accumulating meaning.
What the rule of law is for
On the evening of June 13th, a Friday, chosen perhaps for the same reason that difficult corporate announcements are always made on Fridays, the Cato Institute published a piece by the constitutional scholar Kevin Frazier under the headline "Trump Administration Veers from the Rule of Law in Singling Out Anthropic's Latest Models." The Cato Institute is not a progressive organization. It is, if anything, congenitally skeptical of government regulation and instinctively sympathetic to business interests. Its criticism, for that reason, carries a particular kind of weight.
Frazier identified three principles of the rule of law that he believed the administration's action had violated. The first is publicity: the rules that govern behavior must be knowable in advance. In this case, the action was disclosed not by the government but by Anthropic itself, in a statement to its users. The government published nothing. The second is prospectivity: those subject to rules must have the opportunity to align their conduct with them before being penalized. No one in the AI industry, not even the lawyers who specialize in export controls, had seriously anticipated that these authorities would be used to recall a model already in commercial deployment. The third is legality: government actions must have a clear statutory foundation, and here that foundation remains, at best, uncertain.
To these three, Frazier added a fourth: generality. Like cases must be treated alike. OpenAI's GPT-5.5, which shares the same vulnerability, has not been treated alike. The administration's own former AI czar, David Sacks, a longtime ally of Elon Musk, whose company xAI competes directly with Anthropic, acknowledged on X that other models possess the same cybersecurity capabilities that were cited as the basis for the ban. He did not address why only one company had received a letter.
Anthropic, in its own statement, put the matter with a directness that is unusual for corporate communications: "We believe the government should have the ability to block unsafe deployments as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. This action does not adhere to those principles." That is not a technical objection. It is a political one.
The uncomfortable comparison
There is an exercise that Western analysts perform, regularly and with some satisfaction, when a government in Beijing or Moscow moves against a private company for reasons that are officially about public safety but seem to have more to do with politics. They call it what it is. They note the lack of due process, the absence of published evidence, the convenient alignment between the regulatory action and the interests of favored competitors, the history of the company's relationship with the government, the suggestive timing.
In November 2020, Chinese regulators pulled the plug on the IPO of Ant Group, Jack Ma's fintech company, two days before it was set to become the largest public offering in history. Ma had recently delivered a speech critical of Chinese banking regulators. In 2021, DiDi was forced off the New York Stock Exchange within days of its listing, after Chinese authorities concluded that its data practices posed a national security risk. In both cases, the official explanation was safety. In both cases, observers noted that the companies in question had, in one way or another, fallen out of favor with the state.
The point is not that the United States is China. The point is that the tools of arbitrary power look remarkably similar regardless of the flag under which they are deployed, and that the value of the rule of law lies precisely in its capacity to make those tools unavailable, to make it structurally difficult, not merely politically inconvenient, for a government to shut down a private business in ninety minutes on the basis of an unpublished report from a competitor that also happens to be an investor.
That capacity has been, at the very least, called into question.
What Europe is not building
This story is not only an American one. It concerns, in ways that have barely begun to be articulated in European capitals, the four hundred and fifty million citizens of the European Union, and the tens of millions of European businesses that depend, in their daily operations, on artificial intelligence systems, almost all of which are American.
Consider the question in its starkest form. If Europe were to find itself in serious disagreement with Washington over Ukraine, or tariffs, or migration, or Taiwan, the kinds of disagreements that are no longer unthinkable, and if an American administration were to decide that AI access was a useful instrument of geopolitical pressure, Friday's events have established that such pressure is technically feasible, politically executable, and legally defensible, at least in the administration's own estimation. Europe has no answer to this scenario. It does not have the models, the compute, or the sovereign infrastructure to guarantee its own continuity.
This is not, it should be said, for want of diagnosis. On September 9th, 2024, Mario Draghi presented the European Commission with a four-hundred-page report on the future of European competitiveness. It contained a hundred and seventy concrete proposals: European AI models, sovereign cloud infrastructure, expanded supercomputing networks, quantum computing ecosystems, data sovereignty frameworks. It identified, with precision and in writing, exactly the vulnerabilities that became visible on June 13th, 2026.
That report remained, for the most part, a document. It did not become a budget. It did not become a policy. It did not become an emergency.
Perhaps, now, it will.
The lesson of February 2022, when Russia closed the gas pipeline and Europe discovered, in the space of a few weeks, the full cost of its energy dependence, was brutal but legible: to depend for your survival on an actor who controls the valve is not a technical detail. It is an existential condition. The lesson of June 13th, 2026, should be equally legible: to depend for your intelligence infrastructure on an actor who can turn off the servers with ninety minutes' notice is the same condition, dressed in different clothes.
Fable 5 is dark. The question Europe must now answer is not when it will come back online. It is when Europe will begin building sovereignty of its own.
Sources: Axios | Fortune | Time | Bloomberg | CNBC | Al Jazeera | The Decoder | TNGlobal | Cato Institute | Anthropic official statement