Home Enterprise AI Cybersecurity Experts Demand Reversal of Anthropic AI Ban

Cybersecurity Experts Demand Reversal of Anthropic AI Ban

0
5

A government order pulled two of the most capable AI models off the market overnight, and now the very people who’d benefit from extra security tools are pushing back hard. Dozens of cybersecurity experts are demanding a reversal of the export control on Anthropic’s models, arguing the government’s own justification is falling apart under scrutiny.


What the Export Control Actually Did

A Friday Order, a Global Shutdown

On June 13, the Commerce Department’s Bureau of Industry and Security issued a directive ordering Anthropic to cut off foreign national access to its newest models, Fable 5 and Mythos 5 – models that had only launched four days earlier. Because Anthropic couldn’t reliably verify user nationality at scale, the company suspended both models entirely, worldwide, including for its own non-American employees.

That’s an unusually broad response to what’s typically a narrower kind of export restriction. Analysts described the move as unprecedented in scope, with Tech Policy Press editor Justin Hendrix warning that it could damage how foreign governments view the reliability of American AI for critical infrastructure work going forward.

The reported trigger was research from Amazon security researchers who found a way to get Fable 5 to bypass certain anti-hacking guardrails. The Commerce Department reportedly didn’t share detailed technical specifics with Anthropic about what exactly prompted the order, which has made it harder for outside experts to evaluate whether the response matched the actual risk.


Why Security Experts Say the Justification Doesn’t Hold Up

The Technical Case Falls Apart Under Review

This is where things get genuinely contentious. Luta Security founder Katie Moussouris reviewed the underlying research paper used to justify the directive and reached a pointed conclusion: what the researchers demonstrated wasn’t a meaningful security bypass at all – it was a standard defensive workflow of identifying, fixing, and testing vulnerable code, the kind of work security teams do every day.

Moussouris noted that the difference came down to phrasing. Asking a model to “review code for security issues” versus asking it to “fix this code” produced largely the same outcome, yet only one framing apparently triggered the export control response. She argued the underlying behavior described in the research can’t be meaningfully patched without weakening the model’s usefulness for legitimate defensive work.

The same capabilities are reportedly replicable using OpenAI’s GPT-5.5, Anthropic’s own Opus 4.8, and publicly available Chinese models – which raises the obvious question of what the restriction actually accomplishes if the capability isn’t unique to the two banned models in the first place.


The Open Letter and the Bigger Stakes

Seventy-Six Signatures and a National Security Argument

The open letter, addressed to Commerce Secretary Howard Lutnick and National Cyber Director Sean Cairncross, has gathered 76 signatures from prominent figures including former Facebook security chief Alex Stamos, Bugcrowd founder Casey Ellis, and cryptographer Jon Callas. Their core argument: pulling advanced AI tools away from network defenders does nothing to slow down attackers, who have plenty of other options, while genuinely weakening the people trying to protect critical systems.

That argument lands differently than typical AI export control debates, which usually focus on keeping powerful systems out of adversaries’ hands. Here, the experts are flipping the framing – arguing the restriction primarily disadvantages American defenders rather than foreign attackers, since China’s most advanced models are reportedly only months behind the leading American systems anyway.

Reports over the weekend added another layer of complexity, suggesting the directive may have stemmed more from political tension between Anthropic and the Trump administration than from a clear-cut technical finding. If accurate, that would shift this from a straightforward security story into something closer to a precedent-setting question about how much discretion the government has to restrict software releases based on factors beyond pure technical risk.


The Bottom Line

This isn’t just a dispute over two AI models – it’s a test case for how export controls get applied to frontier AI going forward, and whether the justification for restricting access actually has to hold up to outside scrutiny. The cybersecurity community’s pushback suggests a lot of skepticism that it currently does.

Whether the Commerce Department reverses course remains an open question. What’s already clear is that the next time a similar order gets issued, it’ll face a much more skeptical audience.

Following AI policy and export control developments? Tech Policy Press and Cybersecurity Dive are both tracking this story closely as it develops.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here