When an AI model can be pulled overnight, dependence on a single provider becomes a business risk.
The US government cites national security grounds. More specifically, the authorities believe a method was discovered to bypass the safety mechanisms of the Fable 5 model (what is known as a "jailbreak"). The method reportedly allowed the model to analyse source code and identify security vulnerabilities.
Anthropic disputes the severity of the situation. The company says it reviewed the demonstration and that the vulnerabilities identified were already known, relatively simple and accessible through other publicly available AI models, including OpenAI's GPT-5.5. Furthermore, Anthropic stresses that no universal jailbreak was demonstrated (that is, a method that could fully and broadly bypass the model's protections).
Before launching Fable 5, Anthropic worked with several partners to test the model's security: the US government, the UK AI safety agency (UK AISI), private third-party organisations and internal teams. Testing took thousands of hours.
The company implemented a strategy called "defense in depth": the protective mechanisms are designed so that any bypass attempt is either very limited in effect or very costly to produce. In addition, Anthropic introduced a 30-day data retention policy for the Mythos-class models, precisely so it can quickly detect and mitigate any jailbreak attempt.
Anthropic states that these protections are the strongest ever implemented on a commercial model.
It is the first time a government has withdrawn a commercial AI model from hundreds of millions of users on the basis of a single security report. The decision was taken without a transparent statutory process, without a public hearing and without concrete details communicated to the company.
Anthropic complies with the directive, but publicly criticised the process, arguing that if a limited jailbreak were enough to withdraw a model, no AI provider in the world would be able to launch new products.
For companies that use artificial intelligence, there are a few practical lessons:
Anthropic has promised to publish more details within the next 24 hours. The company's other models (including those in the Opus, Sonnet and Haiku ranges) are not affected.
The situation is still developing. It is worth watching what other governments do, how the European Commission reacts (it is working on implementing the AI Act) and what impact this has on companies that have built their processes on these models.
If you use AI in your company and do not yet have a governance strategy, now is the time.
It means a tool you have built into your processes can become unavailable overnight, for reasons outside your control. If workflows, products or decisions depend on a single model, suspending it may affect operational continuity. That is why it is worth assessing early how dependent the company is on a single provider and what alternatives it has ready.
It is the risk that your business is exposed when you rely on a single AI model or provider with no alternatives. If that provider raises prices, changes its terms, has an outage, or the model is withdrawn by an authority, you have no immediate plan B. A prudent approach is to be able, in principle, to switch between providers and to avoid tying critical processes to a single model.
AI governance means clear internal rules about which AI tools are used, for what purposes, with what data and with whom responsible. As regulation increases — for example through the European AI Act — companies without an internal AI usage policy risk being caught unprepared. A governance policy also helps with managing incidents and unexpected external decisions, such as a suspension.
A few useful directions: avoid dependence on a single provider, document which processes use AI and how critical they are, treat AI security as a leadership matter rather than just an IT one, and prepare continuity plans for the case where a model becomes unavailable. These are prudent, forward-looking measures, not guarantees — the regulatory situation can change quickly.
We help you bring order to your use of AI before an incident or an external decision does it for you.