AIPolitics 21: The Week Washington Found the Off-Switch on Mythos and Fable
The government just shut down the most powerful AI in the world with a letter. It tried this once before, with a different piece of software, and lost.
On Friday, at 5:21 in the evening, Anthropic got a letter from the Commerce Secretary. By the time most people had finished dinner, the company had switched off its two most capable models for every customer on the planet.
Not a hearing. Not legislation. Not a court order anybody got to argue in front of.
A letter, on a Friday, and the most powerful AI available to the public went dark.
I’ve spent twenty installments of this series circling a question: what happens to American politics when a technology this big arrives faster than our institutions can metabolize it? For most of that time the answer has been some version of (too-)slow-motion adaptation: coalitions drifting, parties re-sorting, the cleavage rotating a few degrees at a time.
This past week wasn’t slow-motion. This past week the state stopped studying the labs and started handling them. Both ends. At once.
So let me try to put the week back together here, because it has scrambled, at least a bit, where I thought this was going.
The carrot and the stick, same seven days
Start with what we covered last time. The “AI dividend” really went mainstream: Trump floating a government equity stake in the big labs, Sanders pushing a mandatory one, Altman talking up “universal basic wealth,” everyone suddenly agreeing the public deserves a cut. I argued the agreement was hiding a fight: cash versus ownership versus jobs, and underneath that, the older question of whether a thing handed down from above can ever feel like a thing you won.
That was the carrot. Then we got the stick.
The Commerce Department, citing national security, put export controls on Anthropic’s Fable 5 and Mythos 5, barring access by any foreign national, anywhere, including Anthropic’s own foreign-national employees. Because you can’t cleanly wall off “foreign” from “domestic” inside a product hundreds of millions of people use, the practical effect was a full shutdown. It’s a licensing regime, with the teeth that implies: a license now required to export, re-export, or even domestically transfer the models, and civil penalties for getting it wrong.
Tyler Cowen, writing the next morning, said something with Cowen-stickiness: AI nationalism, he said, is “rising in status.” He meant it as an observation about which ideas are gaining ground. But Cowen was describing a cultural mood. The Commerce letter was the thing itself, already on the ground, signed and delivered. The carrot and the stick arrived in one week, from one government, aimed at the same handful of companies. Not from the same hand, exactly; we’ll get to how ridiculously uncoordinated this all was. But both of them reaching in one direction: toward control.
The off-switch play has a history, though. We should talk about the last time Washington tried this.
We have called software a weapon before
In the 1990s, the United States government decided that strong encryption was a very problematic, uncontrollable munition.
I mean that literally. Cryptography above a certain strength sat on the U.S. Munitions List, governed by the arms-export rules that covered actual weapons. When Phil Zimmermann wrote Pretty Good Privacy in 1991 (the first encryption tool ordinary people could actually use) and it spread overseas the way software does, the Justice Department opened a three-year criminal investigation into him for, in effect, exporting arms.
The fight that followed was more than a little bit absurd and completely clarifying. To prove the absurdity, MIT Press printed PGP’s source code as a hardcover book. A book you could legally buy, legally carry across a border, legally read aloud, containing the exact same code that, on a floppy disk, made you an arms trafficker. A mathematician named Daniel Bernstein sued, and in 1996 a federal judge ruled for the first time that source code is protected speech under the First Amendment. The Ninth Circuit agreed in 1999. The criminal case against Zimmermann was quietly dropped. And the controls themselves were moved, by executive order, off the Munitions List and over to a different agency for a lighter touch.
That agency was the Commerce Department’s Bureau of Industry and Security. The same bureau whose letter went out Friday at 5:21pm.
I don’t think that rhyme is a coincidence. When the government decides a capability is too dangerous to let loose, it reaches for the export-control machinery, because that’s the machinery it has. The trouble is that the machinery was built for things: centrifuges, missile guidance, fissile material. It works on things because things are scarce and heavy and hard to copy. Math is none of those. Neither, it turns out, is a model.
I have to wonder if the playbook is in the same dusty binder it was so many years ago, right?
The warning that became the warrant
Now what was maybe the real story of the week.
The stated reason for the shutdown was a jailbreak. The government said it had become aware of a way to get past Fable’s safeguards. Anthropic’s account, which it published in unusual detail, is that the “jailbreak” amounts to asking the model to read a codebase and point out the security flaws, a thing other models including OpenAI’s do every day, and a thing the people who defend computer systems do for a living. By Anthropic’s own telling, the capability that got its model embargoed is, in its words, “widely available from other models.”
You must remember here that Anthropic is the lab that built its entire identity around caution. It’s the one that restricted Mythos to about fifty vetted organizations because it was too dangerous to release. It’s the one that, just two days before the shutdown, published a long manifesto asking the government, please, to take on the power to block unsafe AI deployments, as part of “a statutory process that is transparent, fair, clear, and grounded in technical facts.”
Forty-eight hours later the government used exactly that power. Just not the transparent, statutory, grounded-in-technical-facts version. The verbal-evidence, Friday-night, no-process version.
Nobody at Commerce was reading Dario’s essay and deciding to teach him a lesson. The timing is coincidence. The shape of the coincidence is...well…something.
The incentive logic here runs through this whole series, and it’s not really about Anthropic. It’s about what happens when you make yourself legible to power. The lab spent years telling Washington its product was uniquely dangerous, building the vocabulary, asking again and again to be regulated. It made itself the most readable company in the industry, the easiest one to understand as a national-security object.
Now, the thing that actually tripped the letter was the model’s capability, not the company’s rhetoric. The jailbreak that did it was demoed by Amazon, Anthropic’s single largest investor, which phoned the White House to report that its researchers had coaxed Fable into handing over the restricted vulnerability information it’s built to refuse. Your biggest backer, holding the knife. Legibility didn’t pull the trigger. But it loaded the chamber: of all the labs shipping cyber-capable models, Anthropic had spent more breath than anyone telling Washington why its model was the one to fear. When the moment came to single somebody out, it had volunteered to be the most legible target in the room. You don’t get to ask the state to hold a lever and then specify which hand it uses.
The administration’s own account, which David Sacks laid out over the weekend, is less cloak-and-dagger and more exasperated. A trusted partner found the jailbreak. The government asked Anthropic to patch it or pull the model, and Dario refused. So they fell back on the export control, “reluctantly,” and the restriction lifts the moment the hole gets fixed. The ball, Sacks says, is in Anthropic’s court. Anthropic’s reply is that the jailbreak is narrow and minor, that the trick works just as well on models nobody is export-controlling, and that it’s being singled out. Both things can be true, and that’s exactly the bind. The government had a real finding and a reasonable ask. It just chose to enforce that ask with the bluntest instrument in the drawer: a sudden kill order, aimed at one company, lifted only when that company complies.
One more detail from the whirlwind 24 hours: when the White House went looking for Amodei in the crucial window, it reportedly had trouble finding him. He was away at a wellness retreat. Make of that what you will.
Sam Altman saw the edge of this back in April, when he called Anthropic’s Mythos rollout “fear-based marketing.” His line was that it’s awfully convenient to announce you’ve built a bomb and then sell everyone the bomb shelter. I thought that was mostly a competitive jab at the time. It reads differently now. When you spend a year telling the government your model is a weapon, you shouldn’t be shocked when the government’s weapons people take you at your word.
The won-versus-granted problem from the last few posts has turned inside out here. Anthropic didn’t want power handed to it; it wanted to hand power up, to a rules-bound state, on the theory that rules would protect everyone including itself. What it got instead was power exercised on it, by the same state, with no rules in sight. The thing you build to constrain authority becomes the handle authority grabs you by.
The colder reading came from Adam Thierer and Neil Chilson, who argued over the weekend that maybe Anthropic didn’t lose at all. The government has now established, in public, that it can force a model off the market and demand a license to bring it back. Strip away the chaos and that is the pre-clearance regime Anthropic has spent a year asking for, arrived at by the ugliest possible route. When the export controls prove unsustainable and fall away, the precedent they set does not. The company that begged to be regulated may walk out of this holding the exact lever it wanted, handed to it by an administration that thought it was delivering a punishment.
That reading is too tidy to fully trust. It asks us to credit more strategic foresight than this messy week actually showed, and the simpler story, that a safety-obsessed company got burned by its own alarms, fits the facts just as well. Still, it belongs on the table next to the sympathy, and it’s the reading I’d watch hardest as the export controls wobble.
Two screens, one Friday
Then there’s the image that honestly just strikes one as the cheapest kind of irony, the kind history just hands you.
On the same Friday afternoon Anthropic went dark, the SpaceX IPO (xAI now folded inside it) rang the bell on the largest public offering in history. Something like a $1.77 trillion valuation. Elon Musk became, on paper, the world’s first trillionaire.
Run those two screens side by side in your head. On one, the AI company that aligned itself with the administration mints the richest man who has ever lived. On the other, the AI company that spent its reputation warning about AI gets its flagship switched off by that administration. Same news cycle. Two postures toward power: stand close to it, or stand up and warn it. Their Friday-afternoon payouts landed side by side, for anyone keeping score.
Cowen had a good line about this too, in that same Saturday post. Rising in status, he wrote, are the “reticent, quiet CEOs.” Falling, by implication, is the one who wrote the 10,000-word warning. The market and the state reached the same verdict that day about which kind of executive does well in the age of AI nationalism, and it wasn’t the one raising his hand.
The dividend’s dark mirror
A twist hiding inside that IPO bell bears on the dividend fight directly.
The dividend pitch, in all its flavors, is some version of: the public should own a piece of the AI boom. Trump says it’ll make people “very rich.” Sanders wants the public to hold actual shares. The premise everyone shares is that ordinary Americans currently don’t have a stake, and ought to.
Except ordinary Americans are getting a stake right now, through the side door. In the very week we debated how to give the public an AI stake, the largest AI offering in history dropped into the public markets. Not straight into your 401(k) at the opening bell; index inclusion has rules and lag, and the float small investors can buy on day one is thin. But that’s where this paper is headed, the way big listings always end up: into the index funds, pension funds, and retirement accounts sitting quietly in the background of most working lives. OpenAI, reportedly losing more than a dollar for every dollar it earns and not expecting profit until 2030, is filing to follow. Anthropic behind it. Somewhere north of three trillion dollars in AI valuation, much of it deeply unprofitable, sliding onto the public’s balance sheet whether the public asked for it or not.
So the public already owns a piece of AI. The question the dividend debate skips is which piece. The upside everyone’s promising, or the bag — the overvalued, cash-hemorrhaging piece that, if the AI trade ever turns, working people tend to be the last ones still holding. “Americans should share in AI” turns out to be a sentence that’s already true. It just doesn’t say whether sharing means the bonanza or the downside, and right now the honest answer is both, and nobody’s choosing.
Quick intermission. This whole series runs on word of mouth and free subscriptions, not a paywall. If the first half earned the second, the buttons below are how you keep the lights on around here. So, share and subscribe!
The map nobody’s party drew
Now to the politics, of course.
Last post I said AI was scrambling the partisan cleavage. This week it stopped being a forecast and started naming names.
Watch Josh Hawley, who is the cleanest illustration I’ve got. Hawley looked at Trump’s proposal for the government to take equity in the labs and said no: “I’m not a huge fan of the government owning industry, and I think with this you’d combine the worst of the big bureaucrats with the Big Tech monopolist.” That’s a populist-right rejection of the carrot. But Hawley is also a China hawk who sponsors bills to restrict AI’s collaboration with Beijing, and he’s left the door open to taxing the labs to make sure they benefit ordinary workers. So he rejects the state owning AI, supports the state taxing AI, and his whole nationalist-security lane is the natural home for the state shutting down AI. One senator holds the no-carrot, yes-tax, yes-kill-switch combination, and there’s no party label that predicts it.
Hawley isn’t alone in scrambling things. At least a dozen Republican offices have already come out against Trump’s equity idea, some because they hate government ownership, some because they hate handing Washington more power over industry: opposite reasons landing on the same no. Democrats are split too; the rush to regulate has them fighting among themselves about how. The dividend doesn’t unite either coalition. The kill-switch doesn’t either.
AI isn’t sorting people by party. It’s sorting them by their posture toward concentrated power, and both parties are full of both postures. There’s a faction in each that wants to break the labs and a faction in each that wants to ride them, and the old red-blue map has almost nothing to say about which is which.
One senator is an anecdote, not a sort. Maybe this is just what an issue looks like before the parties whip it into line: pre-sorting noise that hardens into ordinary partisanship the moment AI becomes a base-mobilizing fight. That’s the boring possibility, and I can’t rule it out. What makes me think it’s more than noise is that the cross-pressure isn’t random. It runs along a consistent seam, how far you trust concentrated power in anyone’s hands, and that seam cuts straight across the party label. That’s why the week feels chaotic. We may be watching a cleavage that hasn’t found its language yet, playing out on a board still painted in the old teams’ colors.
Adam Thierer, who spent the spring calling the AI dividend a “profit-sharing extortion racket,” didn’t have to change lanes to be alarmed by the stick. Anthropic, he allowed, had “relentlessly raised the regulatory temperature” itself. But the shutdown was still, in his read, “a significant escalation in the politicization of AI and centralization of control over advanced computation in this country.” The free-market right recoils from the carrot and the stick alike, because both are the state reaching into the same place.
The administration’s own incoherence makes the point. Two weeks ago the White House issued an executive order on AI testing that was deliberately voluntary, with no licensing regime, a design David Sacks reportedly fought for specifically to prevent the “regulatory capture” he thinks binding rules invite. Then Commerce turned around and imposed a licensing regime on one specific lab’s models. The carrot and the stick aren’t even being held by hands that are talking to each other.
The lesson Washington already learned and forgot
The 1990s really shoulda kinda settled this part already.
Cowen’s analysis of the shutdown is basically a list of reasons it can’t hold. “U.S. citizens only” is unenforceable. You can hire a willing American, you can fake a credential, the market routes around the rule. The labs run on foreign talent they now can’t fully employ on their own best models. China’s open models keep improving regardless of what Commerce does to Anthropic. And the government can’t simply nationalize these companies and run them itself, because running a frontier lab is not a thing the federal personnel system knows how to do. His forecast is that we’ll replay this scene again and again, each time with both the companies and the government a little weaker and a little more exposed.
That’s the Crypto Wars lesson, almost verbatim. You can ban the export of the math. You cannot un-teach it. The capability is already loose, and Anthropic said so itself in its own defense, which is the strangest part: the company argued its way out of the embargo by insisting the dangerous thing isn’t actually rare. The state can switch off one company’s model on a Friday night. It cannot switch off the underlying capability, any more than it could un-publish a book of source code in 1996.
The analogy isn’t clean, and it frays in a few places. A model’s weights aren’t a book of source code; no court has called them protected speech; and unlike encryption, which is worthless unless it’s everywhere, a cyber-capable model is dangerous precisely because the capability stays concentrated. The state may have a better case for bottling this than it ever had for bottling PGP. But the part that decides the outcome isn’t the legal theory; it’s the physics of information. You can refuse to export a capability and still not stop the world from learning it.
The government’s deeper worry is the one that makes the whole exercise feel futile. It suspected that a China-linked group had already used the same jailbreak Amazon found. How it reached that conclusion is murky, and Anthropic says the White House never raised China with the company at all, and that it already blocks access from inside China. Take the suspicion at face value, though, and the lesson only sharpens. The fear isn’t that Beijing steals the weights; it’s that it distills them. Distillation is the cheap trick of the trade: you point your own model at the target, ask it millions of questions, and train a student to imitate the teacher until the capability is yours, no original required. If that’s the worry, the off-switch got flipped after the horse was already out of the barn. You can’t export-control a capability a rival may already have copied. You can only confirm, at top volume, that it was worth copying.
You really don’t have to theorize about any of this. Look at what the rest of the world did with the news. By one widely-watched tracker’s measure, the public intelligence frontier moved backward for the first time ever the day Fable went dark, the most capable model the public could touch simply subtracted from the board. And within a day, China’s Zhipu fully open-sourced GLM-5.2, a million-token model it shoved out the door under the banner “Frontier Intelligence Belongs to Everyone.” Europe called the shutdown a sovereign-AI “wake-up call.” India reopened its case for homegrown open models. The American move to bottle one capability became, in a single news cycle, the best advertising the open-source competition has ever run. PGP-as-a-book, except this time the book published itself in Mandarin before the ink on the letter was dry.
Dean Ball, who worked in this administration and is no reflexive critic of it, looked at the shutdown and said he honestly couldn’t tell “if this is lawfare against Anthropic in particular or extreme national-security hawkery.” He kept going, marveling that the same administration whose posture is that we should sell advanced chips to China now wants to bar Britain, and every other non-American on Earth, from using our best models. He called the whole thing “simply cartoonish.” I’d flag his confusion as the most important reaction of the week. When a sympathetic insider can’t read whether an action is principled security policy or a hit on a specific company, that unreadability is itself the cost of exercising this kind of power without the transparent process Anthropic was, with exquisite timing, asking for two days earlier.
Where we actually stand
So here’s my read, cart upright again.
AI nationalism didn’t arrive in a white paper or a campaign speech. It arrived in a Commerce letter and an IPO bell, one Friday afternoon, pointing in opposite directions. The state picked up the carrot and the stick in one week, and it may not be able to hold either one for long. The carrot it can’t fund without the labs’ cooperation. The stick it can’t enforce without un-shipping math that’s already in the wild. And it’s swinging both inside a coalition that can’t agree on why it’s doing either, because the coalitions themselves are coming apart along a seam that predates all of our current party fights.
Notice which of the two was real, though. The stick was a signed letter with penalties attached, carried out in hours. The carrot is still mostly a thing the President says at podiums. That asymmetry is important. This state is far better at coercion than at distribution: it can switch a company off by Friday night, and it has no comparable machinery for actually handing the public a share of anything. A government that can kill a model but can’t cut a check is going to keep reaching for the off-switch, because the off-switch is the tool that works.
And if Fable and Mythos quietly come back this or next week, don’t read that as the story falling apart. Anthropic has already flown technical staff to Washington to patch things up, and both sides say they’re eager to resolve it. Read the return as the back half proving itself: the state reached for a tool it couldn’t hold for ten days.
The question under all of this has no clean answer, and that’s probably the most honest place to end: Is this the moment the American state finally figured out how to govern artificial intelligence? Or is it the moment it discovered, in public, that it can’t — that it has the tools of a 20th-century arms regime and a 21st-century technology that laughs at them?
I can’t tell you whether the next letter will look like strength or like flailing, and I’m not sure Washington or anyone else can either.
Art of the what again?
If this was worth your time
No paywall here, just the series and your attention. Two ways to help it travel: subscribe so the next one lands in your inbox, and forward this to the one friend who’ll fight you about it. And tell me in the comments which reading you buy: the lab that got burned by its own alarms, or the lab that just got the precedent it wanted.
Caught up on the thread(s)?
Part 20 — Everyone Agrees the AI Dividend Should Happen…and That’s Kinda the Problem: the carrot, one week before the stick.
Part 19 — Comments on Arnold Kling’s Comments: where the won-versus-granted problem got its name.
Part 18 — The Political Cleavage Rotated and AI Has Bisected It: the map this week kept redrawing.
Part 17 — Anthropic Wrote the Papal Encyclical: the lab learning to speak in institutions.
Part 14 — What Just Got Built: when the security state’s AI architecture went vertical.



“AI isn’t sorting people by party. It’s sorting them by their posture toward concentrated power, and both parties are full of both postures.”
This is a terrific way to explain what appears to be partisan scrambling. It may reveal more about actual political ideology than the letter next to someone’s name on a marquee.
Also, nice to see Dean Ball mentioned here, although I think he’s a bit more critical than you assume. He didn’t work for the administration for very long and he has strong opinions about its haphazard approach to AI governance (just see his latest post!).