Skip to main content
Live
Main content

76 cybersecurity experts protest US export ban on Anthropic's Mythos and Fable

Alex Stamos, Katie Moussouris, and Jon Callas signed an open letter calling the White House order 'dangerous' for defenders.

Jaeden Schafer
Editor in Chief · · 5 min read
Anthropic logo

Seventy-six cybersecurity experts signed an open letter Sunday asking the US government to reverse its export control order on Anthropic's Fable and Mythos models, calling the ban dangerous for the defenders who rely on frontier models to find vulnerabilities. The letter follows Friday's White House order, which cited unspecified national security concerns and prompted Anthropic to suspend access to both models worldwide. The signatories argue the action has stripped defensive security teams of their most capable tool while leaving adversaries unaffected.

The list of signatories is unusually senior for an open letter in the security field. It includes former Facebook chief of security Alex Stamos, Bugcrowd founder Casey Ellis, former Apple security architecture manager Jon Callas, computer scientist Paul Vixie, former Block applied security engineering head Dino Dai Zovi, Luta Security founder Katie Moussouris, and SocialProof Security CEO Rachel Tobac.

To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous
Open letter signatories, 76 cybersecurity experts

Anthropic launched Mythos as a preview in April, restricting it to roughly 50 companies on the grounds that the model was powerful enough at finding vulnerabilities to cause real damage if misused. That group was later expanded to about 150 organizations across 15 countries. Last week, Anthropic released Fable, a public version of Mythos with guardrails designed to block prompts in biology, chemistry, and cybersecurity, and to prevent distillation attacks that could reconstruct the underlying model.

Key facts

  • 0176 cybersecurity experts signed an open letter asking the US to lift the export control order on Anthropic's Fable and Mythos.
  • 02Signatories include former Facebook security chief Alex Stamos, Bugcrowd founder Casey Ellis, and Luta Security founder Katie Moussouris.
  • 03Mythos launched in April with access limited to 50 companies, later expanded to 150 organizations across 15 countries.
  • 04The White House export control order issued Friday cited national security concerns without public specifics.
  • 05Signatories argue the underlying technique can be replicated on OpenAI's GPT-5.5, Claude Opus 4.8, Sonnet, and Kimi 2.7.

The Fable guardrails turned out to be aggressive enough that security researchers reported the model refusing essentially any cybersecurity-related prompt. According to Anthropic, the White House export control order may have been triggered by a non-public Amazon research paper describing a method to jailbreak Fable into producing Mythos-level output.

Moussouris, who said she has reviewed the Amazon paper, disputed that framing in a blog post. She wrote that the researchers did not demonstrate a meaningful jailbreak. They asked Fable to fix open source code containing both known public vulnerabilities and deliberately planted ones, after the model initially refused to review the code for security issues.

Her argument is that this is not a guardrail bypass but the core defensive workflow.

The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense
Katie Moussouris, Founder, Luta Security

The open letter echoes that critique and goes further, arguing that the technique described in the Amazon paper can be replicated on OpenAI's GPT-5.5, on Anthropic's own publicly available Claude Opus 4.8 and Sonnet, and on Chinese models including Kimi 2.7. If that claim holds, the export control singles out two specific Anthropic models for a behavior that is effectively industry-wide, without measurably restricting adversary access to equivalent capability.

Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.
Katie Moussouris, Founder, Luta Security

The letter also requests that any future restrictions come through a democratic rule-making process grounded in scientific research from industry and academic experts, and be used only to the minimum extent necessary to protect public safety. That language is a direct shot at the opacity of Friday's order, which Anthropic itself said came without a specific explanation of the underlying concern.

Related · from this week
White House suspects China-linked group accessed Anthropic's Mythos
Jaeden Schafer · 4 min read →

There is a counterweight worth stating. Mythos was restricted in the first place because Anthropic judged its vulnerability-finding capability dangerous enough to require a 50-company allowlist, later widened to 150. The same capability that helps defenders patch a codebase helps attackers find a zero-day in the same codebase. Reasonable people inside the security community disagree about where the offense-defense balance lands on a model this capable, and the Amazon researchers presumably believed they had identified a real risk, even if Moussouris reads their paper differently.

Still, the policy mechanism matters as much as the underlying judgment. An export control issued without public reasoning, targeting two models from one US lab while equivalent capability remains available from OpenAI, Anthropic's own deployed Claude line, and Chinese labs, is hard to defend on national security grounds. It functionally penalizes the lab that disclosed the capability rather than the capability itself.

For the AI market, the episode is a preview of what frontier-model export policy looks like when it lands on real products. Anthropic spent months staging Mythos access carefully, released Fable with what it described as strict guardrails, and still ended up with both models pulled from worldwide availability inside a week. Other labs watching this will draw a clear conclusion: disclosing a dangerous-sounding capability invites a unilateral export action, while quietly shipping the same capability inside a general-purpose model does not. That is the opposite of the incentive structure US AI safety policy should be creating, and it is the specific outcome 76 of the most credentialed defenders in the industry just signed their names against.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

White House suspects China-linked group accessed Anthropic's Mythos

Export restrictions on Anthropic's most powerful model were partly driven by suspected unauthorized access, according to a Semafor report.

Jaeden Schafer4 min read
Anthropic logo
Security

Cybersecurity researchers say Anthropic's Fable blocks even routine code reviews

Fable's keyword-triggered guardrails reject benign security work, falling back to Claude Opus 4.8 whenever 'cybersecurity' surfaces in a prompt.

Jaeden Schafer4 min read
Anthropic logo
Business

Anthropic shutdown of Fable 5 and Mythos 5 fuels sovereign AI push abroad

After the White House forced Anthropic to cut foreign access to its top models on June 13, the UK, France, and Canada are using it to argue for homegrown AI.

Jaeden Schafer5 min read