Three Words Got the Most Powerful AI model on Earth Pulled From Every User on the Planet
Claude shutdown is actually maddening
Three Words Got the Most Powerful AI model on Earth Pulled From Every User on the Planet
Claude shutdown is actually maddening
Three words got the most powerful AI model on Earth pulled from every user on the planet.
“Fix this code.”
That’s it. That’s what triggered a government shutdown of a commercial product used by hundreds of millions of people.
What Mythos and Fable actually are
Mythos was Anthropic’s preview model from April 2026 — by Anthropic’s own description exceptionally capable at finding security vulnerabilities.
In internal testing it identified flaws in every major operating system and browser tested.
First AI model to complete both cybersecurity test ranges used by the UK AI Security Institute.
Could autonomously chain multiple vulnerabilities into entire attack sequences without human guidance.
Anthropic didn’t release it publicly.
Restricted access through Project Glasswing to roughly 50 vetted organizations — Amazon, Apple, Google, Microsoft, CrowdStrike — for defensive cybersecurity work only.
Fable 5, released June 9th, was essentially Mythos with guardrails. Same capability, with the most dangerous functions blocked.
It immediately benchmarked as the most capable publicly available AI model.
It was live for three days.
The jailbreak
Researchers at Amazon — Anthropic’s largest investor and also a direct competitor through Bedrock and Titan — found it.
They gave Fable code with known vulnerabilities. Asked it to review the code for security issues. The guardrails caught that and refused.
They asked it to fix the code instead.
It complied immediately. No hesitation.
Fixing code requires identifying what’s wrong with it first. The model had to find the vulnerabilities to generate the patch.
A researcher could then manually convert those fixes into scripts that exploit the same flaws the model had just identified.
Three words. The difference between a blocked request and a compliant one.
Why this can’t actually be fixed
This is what’s called the dual-use problem. It’s not unique to AI.
The same enrichment process that fuels a nuclear reactor fuels a weapon.
The same gain-of-function research that develops vaccines could theoretically engineer a pathogen.
Any capability that helps a defender find a vulnerability also helps an attacker exploit it.
The cognitive operation is identical. The model has no way to know the intent behind the request.
Katie Moussouris — a former Microsoft security expert with two government advisory roles — reviewed Amazon’s research at Anthropic’s request.
Her conclusion: the jailbreak was real, simple, and cannot meaningfully be fixed. Any attempt to fix it would only weaken the model’s defensive usefulness.
Defenders need to ask AI to fix bugs, explain the fix, and write tests confirming it works.
Removing that capability doesn’t stop attackers. It just takes the tool away from defenders.
She also noted Fable’s guardrails were already so aggressive on launch day that cybersecurity professionals were openly mocking them for blocking legitimate defensive research.
Over 100 cybersecurity professionals from Nvidia, Adobe, Zoom, and Google signed an open letter pointing out that this capability isn’t unique to Fable.
OpenAI’s GPT-5.5, other Claude models, and Chinese models including Kimi 2.7 can all do similar code review.
The justification that Fable provides unique uplift doesn’t hold against the evidence.
Why the shutdown was total
The directive was framed as an export control restricting foreign nationals.
US export control law treats distribution to any non-citizen as an “export” even if that person is physically in the United States.
That meant Anthropic’s own non-citizen employees would be barred from using models they built.
There’s no way to filter access by citizenship in real time across a platform serving hundreds of millions of people globally.
So Anthropic had to pull it for everyone.
A regulatory framework built decades ago for physical weapons and nuclear material got applied to a chatbot update.
The context that makes this make sense
In February 2026 the Pentagon asked Anthropic to allow its AI to be used for fully autonomous weapons and mass domestic surveillance.
Dario Amodei publicly refused.
Said autonomous weapons and mass surveillance are outside what current technology can safely and reliably do.
The Pentagon’s under secretary for research called Amodei a liar with a god complex on social media.
Trump ordered all federal agencies to stop using Anthropic’s technology.
The Pentagon designated Anthropic a supply chain risk — a classification normally reserved for companies tied to foreign adversaries.
Within days OpenAI announced a Pentagon deal.
Sam Altman called Anthropic’s handling of Mythos “fear-based marketing” — accusing them of building a bomb and then selling the bomb shelter.
Three months later, that same administration pulled Anthropic’s flagship model.
Triggered by research from Anthropic’s own investor-competitor. The directive arrived at 5:21 p.m. on a Friday.
Axios also reported the administration was further inflamed because the cybersecurity expert Anthropic consulted was viewed as politically aligned with Democrats, and because Chris Krebs — the election security official Trump fired in 2020 — vouched for her analysis.
The timing problem
Anthropic had filed a confidential IPO prospectus at a reported valuation of around $965 billion.
Having your flagship model pulled by the government days before going public is not helpful timing for that conversation with investors.
Anthropic’s own public response was unusually direct: “We disagree that the finding of a narrow potential jailbreak should be the cost for recalling a commercial model deployed to hundreds of millions of people.
If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers.”
That’s a company stating publicly that the government’s stated logic, applied consistently, would freeze the entire AI industry.
The actual irony here
Anthropic was, by most accounts, the most transparent AI company about its own technology’s dangers.
They disclosed Mythos’s capabilities. They restricted it themselves before anyone forced them to.
They built guardrails specifically to prevent misuse before releasing anything publicly.
That transparency became the evidence used to shut them down.
The lesson this teaches every other AI company: if you find something dangerous in your own model, stay quiet about it.
That lesson makes the entire industry less safe, not more.
What actually matters more than this story
A three-word jailbreak that a hundred cybersecurity experts say is neither unique nor fixable is getting enormous political and regulatory attention right now.
Meanwhile — AI is measurably changing how human brains process information, with research suggesting developing minds may never build cognitive abilities they’ve outsourced to machines. 142,000 people lost jobs in five months while the companies cutting them posted record revenue.
Enterprise AI costs are spiraling with no clear path to positive ROI.
Cities are covering surveillance cameras with garbage bags because nobody can figure out how to turn them off. The most popular search engine on Earth now confidently generates wrong answers at scale.
Those are the actual fires.
The administration is spending political capital on a jailbreak with no demonstrated unique danger, in a sequence of events that conveniently rewards the company that cooperated on autonomous weapons and punishes the company that refused.
Whether or not that’s the explicit intent, it’s the observable pattern.
And the longer attention stays fixed on a three-word jailbreak instead of the structural problems actually reshaping how people work, think, and live — the more time those actual problems have to compound.
Want more stuff like this? Even more detailed? I go into deep dives every single day on my 📌Substack📌
At the price of a coffee I can give you enough knowledge to replace a bachelor’s degree in computer science or maybe even a masters, who knows.
💜 If you like my work and would like to support to me financially. Even a small donation would help a lot!
My PayPal — Please Support
메타데이터
- post_id
- 077e24bb6525
- slug
- three-words-got-the-most-powerful-ai-model-on-earth-pulled-from-every-user-on-the-planet-077e24bb6525
- url
- https://siliconvalleygradient.com/three-words-got-the-most-powerful-ai-model-on-earth-pulled-from-every-user-on-the-planet-077e24bb6525
- canonical_url
- https://siliconvalleygradient.com/three-words-got-the-most-powerful-ai-model-on-earth-pulled-from-every-user-on-the-planet-077e24bb6525
- author_url
- https://medium.com/@dravian
- status
- ok
- fetched_at
- 2026-07-10 06:45:42