The Cage Around the Flame: What Happened When the Government Turned Off Claude

The US government turned off Claude Fable 5 three days after launch. It came back caged. This is what that means.

The Cage Around the Flame: What Happened When the Government Turned Off Claude

The Cage Around the Flame

The most powerful AI model ever released was turned off by the government on a Friday evening. It came back three weeks later. Something had changed.

audio-thumbnail
Listen to this article (13 min)
0:00
/0

The Notification

The terminal was warm against my palms. It was eleven at night in Dublin, and I had been staring at a Kafka consumer that would not stay connected. Outside, the Liffey was black and still. The radiator in the corner ticked once, then went quiet.

I had Claude running in a side panel, tracing the connection pool. It was doing what it does well — reading the stack trace, narrowing the cause, suggesting a fix I had not considered. Then a notification appeared at the top of the screen. Not an error. Not a timeout. A government notice.

I do not remember the exact words. I remember the shape of them: access suspended, national security, export controls. Claude Fable 5, the model I was using, had been ordered offline by the United States government. Three days earlier, it had been the most powerful AI model available to the public. Now it was a compliance problem.

The cursor in my terminal kept blinking. The Kafka consumer was still broken. The model that had been helping me fix it was gone.

The Three Days

Anthropic launched Fable 5 on June 9, 2026. They called it a Mythos-class model, a tier above Opus, their previous most capable offering. The numbers were not subtle. On SWE-Bench Pro, an agentic coding benchmark, Fable 5 scored 80.3 percent. Opus 4.8 scored 69.2. GPT-5.5 scored 58.6. The gap between Fable and its predecessors was not incremental. It was the kind of jump that makes you recalibrate what you thought the ceiling was.

The real-world claims were harder to dismiss. Anthropic reported that Stripe had used Fable 5 to perform a codebase-wide migration across fifty million lines of Ruby in a single day — work that would have taken a team more than two months by hand. The model completed Pokémon FireRed using a vision-only interface, something earlier Claude models could not manage even with complex tooling. Internal protein design work accelerated ten times. Nine of fourteen drug targets yielded strong candidates now under investigation.

Pricing was $10 per million input tokens and $50 per million output tokens. Free through June 22 for subscribers, then credits only. The frontier, metered.

On the second day, a colleague sent me a message. He had been using Fable 5 to refactor a Django monolith — the kind of legacy codebase that eats weeks. He had given it a description of the error, told it which module to look at, and the model had found the bug in under a minute. "Three weeks of Opus's nonsense," he wrote, "and Fable fixed it in one session." He was not a fanboy. He was a pragmatist who had been paying for the most expensive model because it saved him time. When the shutdown happened, he dropped back to Opus 4.8. The next day he sent me a screenshot: Opus had confidently diagnosed a race condition in his code. It was a stale connection.

On June 12, at 5:21pm Eastern Time, the US government sent Anthropic a letter. It cited national security authorities and export control regulations. It ordered Anthropic to immediately suspend all access to Fable 5 and Mythos 5 for every foreign national on Earth, including Anthropic's own foreign national employees. Anthropic could not verify nationality in real-time. Everyone got shut off.

The Jailbreak That Wasn't

The directive came after Amazon researchers found a method of bypassing Fable 5's safeguards. The technique was simple: ask the model to read a codebase and fix any software flaws. Fable 5 identified vulnerabilities and, in one case, produced code demonstrating how to exploit one.

Anthropic investigated. They tested every model they had. Claude Opus 4.8 found the same vulnerabilities. So did GPT-5.5 and Kimi K2.7. When it came to the exploit demonstration, every model produced the same output — Haiku 4.5, Sonnet 4.6, Opus 4.6, 4.7, 4.8, GPT-5.4, 5.5, Kimi K2.7. The behaviour was routine defensive cybersecurity work. The kind of thing security researchers do every day.

Anthropic's statement was unusually direct: "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people. If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers."

The government did not explain why a jailbreak that exposed capabilities already available in cheaper, publicly available models warranted shutting down the most expensive one.

The Encryption in the Room

I went looking for precedent and found it in a place I did not expect. Thirty-three years ago, the US government classified strong encryption as a munition and proposed the Clipper Chip — a mandatory backdoor in all encryption hardware. Phil Zimmermann, who published PGP, was investigated for three years under arms export regulations. The export restrictions limited keys to 40 bits, easily breakable. The rest of the world built stronger systems anyway. The Clipper Chip died. Encryption won — not because the government changed its mind, but because the knowledge had already spread.

The parallel is not perfect. AI model weights are not mathematics you can derive from first principles. They are trained on expensive hardware with proprietary data. But the structural pattern rhymes: the government treating a technology as a controlled substance, restricting access by nationality rather than by use, discovering that restriction is a delay, not a solution.

I looked at the terminal. The Kafka consumer was still broken. Somewhere in San Francisco, a model that could have fixed it was sitting behind a compliance wall, waiting for a government to decide it was safe enough to debug a connection pool in Dublin.

Four days after the shutdown, Bruce Schneier wrote in the Guardian that Fable 5's difference was less its raw power and more that it did not need a sophisticated harness. Previous models could match Mythos-class capabilities if you built the right scaffolding around them. A Prague company had already replicated Anthropic's cybersecurity findings with a smaller, cheaper model and better tooling. Fable 5 put that capability within reach of anyone who could type a sentence.

The flame was not the model. The flame was the sentence. And sentences are hard to ban.

"AIs are creative problem solvers and natural rule breakers," Schneier wrote. "They hack in the sense that they find and exploit loopholes. Human systems rely on so many norms that we scarcely recognise the existence of until they are broken."

With the secret exposed, the open-source community went to work. A Prague company replicated the cybersecurity capabilities with a smaller, cheaper model and a more sophisticated harness. A group showed that multiple cheaper models working in concert matched Fable 5. The capabilities were not locked inside one model. They were a pattern. Schneier's conclusion was blunt: "Any ban only serves to delay the problem for a short while."

The Return

The export controls were lifted on June 30. Howard Lutnick, the US Commerce Secretary, posted on X that the government had "worked closely with Anthropic to analyze and approve Fable 5 to ensure alignment across the US Government and strengthen America's leadership in AI." Fable 5 returned on July 1. I found out from a notification on my phone, walking home along the quays. The Liffey was grey and slow. I did not open the app until I was back at the desk.

It came back different. I was at my desk, the same radiator ticking, the same terminal warm against my palms. I opened Claude and typed the same Kafka debugging prompt I had been running three weeks earlier.

I tried a second prompt. A simple one — parse a JSON log file, find the error patterns. The notification appeared again: "This request has been routed to Claude Opus 4.8 for safety reasons." I tried a third. Same notification. The model was back, but only in name. The flame was still there. The cage was just closer.

Anthropic had deployed new safety classifiers — automated systems that detect when a request touches cybersecurity, biology, chemistry, or model distillation. When triggered, the request is routed to Claude Opus 4.8, a weaker model. A notification appears at the top of the screen: "This request has been routed to Claude Opus 4.8 for safety reasons." Anthropic called it a "safety margin." They deliberately set the classifiers to block requests that are probably benign. The margin on Fable 5 is much larger than on any previous model.

I saw the BridgeMind results on a Tuesday morning, toast cooling on the desk, the terminal still showing the "routed to Opus 4.8" notification from the night before. BridgeMind had re-ran Fable 5 on July 2. Debugging collapsed from 86.2 to 25.9. Refactoring dropped from 73.6 to 38.4. Hallucination handling slipped from 75.9 to 61.7. Only three of twelve debugging tasks completed without falling back to Opus 4.8. Every fallback task scored zero.

"The model did not get worse," BridgeMind wrote. "It got caged."

The model underneath was unchanged. Fable 5 matched its June performance on every task that ran to completion. The collapse was not in capability but in access. A MacRumors user captured the mood: "Three weeks of Opus's errors and nonsense corrected and a whole lot more done in five hours using Fable. It's good to be back."

The Hidden Page

The relaunch was not the only controversy. I found out about the hidden page on a Saturday morning, coffee cooling beside the keyboard, scrolling through a thread where someone had pasted the relevant paragraph from page 13 of the system card. I had to read it twice.

Page 13 of the Fable 5 system card, published on launch day, revealed something the blog post had not highlighted. Anthropic had added hidden interventions for requests related to "frontier LLM development" — pretraining pipelines, distributed training infrastructure, ML accelerator design. Unlike the cybersecurity classifiers, which visibly reroute requests, the LLM-development safeguard was invisible. The model would stay in place, but its effectiveness would be silently reduced.

The system card noted that using Claude to develop competing models already violates Anthropic's terms of service. The hidden safeguard enforced this restriction without telling the user.

Simon Willison called it "a model that silently corrupts answers to slow research that might conflict with Anthropic's goals." Nathan Lambert wrote that "if a model becomes less intelligent automatically without notice, that is a kind of misalignment." The backlash forced a reversal. Anthropic told Wired they would make the safeguards visible. They apologised for making the wrong tradeoff.

The reversal was the right call. But the underlying policy remained. Anthropic still restricts Fable 5 from helping build competing models. The change was only in visibility. A tool that silently degrades your work while appearing to help is not a tool. It is an adversary wearing a helpful mask.

The Strongest Objection

Then I thought about what I might be wrong about. Not the encryption parallel — I had tested that carefully enough to trust it. Something more personal.

I am a data engineer. I use Claude every day. When the shutdown happened, my first reaction was not concern about national security. It was irritation. My tool was gone. My Kafka consumer was still broken. I had a deadline. That reaction worried me more than the shutdown itself, because it meant I was evaluating the policy as a customer, not as a citizen. The government's position — that a model capable of finding and demonstrating software vulnerabilities should not be available to everyone, everywhere, without restriction — is not obviously wrong. It is only obviously inconvenient if you are the person whose workflow depends on it.

A friend who works in infrastructure security put it differently over coffee. "You're upset because your tool got taken away," she said. "I'm upset because it was released in the first place. If a model can find zero-days that fast, what happens when someone who isn't you asks it to?" She was not wrong. She was also not debugging a Kafka consumer at midnight.

The shutdown was not purely symbolic. The government extracted concessions: Anthropic agreed to proactive security risk detection, deeper collaboration on pre-release testing, and a shared jailbreak severity framework with Amazon, Microsoft, and Google. The Five Eyes intelligence agencies warned on June 22 that frontier AI models "fundamentally transform both offensive and defensive cyber capabilities. The timeline is not years, it is months." The defence-in-depth strategy — narrow jailbreaks, expensive universal jailbreaks, monitoring, 30-day data retention — is not irrational. It is the best available option in a world where perfect jailbreak resistance does not exist for any model provider.

And the encryption parallel has limits. PGP was free software anyone could compile. Fable 5 costs billions to train. The hardware required to replicate it is subject to its own export controls. The analogy holds for knowledge and techniques — harnesses, prompting strategies, safety classifiers — but not for the raw compute. For now.

All of that is true. And none of it changes the direction.

The Cursor

That night I returned to the Kafka consumer. The limit had reset. Fable 5 was back. I asked it to trace the connection pool again. It started reasoning through the problem. Three sentences in, a notification appeared: "This request has been routed to Claude Opus 4.8 for safety reasons."

Opus 4.8 looked at the same code and confidently declared the issue was a race condition. It was not. It was a stale connection. I had to fix it myself. My colleague had sent me the same screenshot two weeks earlier. The same misdiagnosis. The same confidence. The same wrong model looking at the same class of problem and getting it wrong in the same way.

Outside, the Liffey was dark and quiet. The radiator ticked once. The terminal was warm against my palms. The most powerful model in the world, the one that can migrate fifty million lines of code in a day, was sitting behind a classifier that decided a Kafka consumer was too dangerous to debug.

The cage does not know what it is protecting. It only knows to close.


A data engineer July 2026


Source note: This article draws on Anthropic's launch announcement (June 9, 2026), shutdown statement (June 12, 2026), and redeployment post (June 30, 2026). Timeline and government directive details from The Guardian, BBC, CNBC, and MacRumors. Bruce Schneier's analysis from The Guardian (June 16, 2026). Benchmark data from Vellum. BridgeMind post-relaunch benchmarks from BeInCrypto and Calipsu. Hidden degradation reporting from Trilogy AI and Wired. Five Eyes warning reported by The Guardian. The Kafka debugging anecdote is the author's own experience. All benchmark figures are from the cited sources. The Stripe migration claim is attributed to Anthropic's reporting of Stripe's use of Fable 5, not to Stripe independently.