White House Clears Anthropic's Cyber Model for Limited Use After Two-Week Ban

June 28, 20263 min read

Two weeks after Anthropic pulled its cybersecurity-focused AI models from the market under government pressure, the Commerce Department is allowing the company to provide one of those models to a specific list of more than 100 U.S. organizations. The move represents a partial reversal of a ban that shut down access to tools some businesses were actively using for security work.

Source: TechCrunch.

What Changed and What Didn't

Commerce Secretary Howard Lutnick notified Anthropic on Friday that Mythos 5 can now be deployed to approved government agencies and companies, according to correspondence reported by Semafor. The authorization includes a significant detail for multinational organizations: non-American employees at these approved entities can access the model. That reverses part of the original restriction, which had blocked even Anthropic's own non-American staff from using the tools they helped build.

The authorization does not mention Fable 5, a variant Anthropic released with additional safety controls just before the ban took effect. Both models were yanked from availability after security researchers reportedly bypassed their protective guardrails. The government has not clarified whether Fable 5 will receive similar treatment or remain restricted.

Anthropic confirmed it is working to restore access quickly for the approved organizations and continuing discussions with the government about broader availability. The company characterized the approved entities as organizations that "operate and defend critical infrastructure," suggesting the initial deployment targets utilities, financial services, healthcare systems, and similar sectors where cyber threats carry physical or economic consequences.

Why This Matters for Business Operators

If your organization relies on third-party AI tools for security operations, this situation illustrates a risk that did not exist six months ago. A model you deploy in June can be unavailable in July, not because of a technical failure or subscription issue, but because the government decides the technology poses export control or security concerns. The two-week gap between ban and partial restoration is not theoretical downtime. It is two weeks without tools that may be integrated into threat detection workflows, penetration testing processes, or incident response procedures.

The selective authorization approach creates a new compliance question. If you are not among the 100-plus approved organizations, you remain locked out. If you are approved but operate internationally, you now need to track which employees can access which tools based on citizenship or work location. That adds administrative overhead to what was supposed to be a productivity tool.

The underlying problem that triggered the ban has not been publicly resolved. Anthropic pulled the models after researchers demonstrated they could bypass safety controls. The government is now allowing deployment to critical infrastructure operators, but there is no indication the bypass vulnerabilities have been patched. That means approved organizations are being cleared to use tools with known exploitability issues, presumably because the perceived benefit outweighs the demonstrated risk.

Bottom Line

If you are evaluating AI tools for security or other sensitive operations, plan for the possibility that access can be revoked on short notice for reasons outside your vendor's control. Maintain alternative capabilities or manual processes that can cover critical functions during disruption. For organizations on the approved list, the access restoration solves an immediate problem but introduces new compliance tracking requirements, especially for teams with international staff.

Back to Blog

© 2026 Rich Embrace Media. All rights reserved.