When the Government Pulls the Plug on AI

By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer

TL;DR: Chuck Gallagher, AI ethics speaker and author, examines the June 2026 federal export-control directive that forced Anthropic to shut down its Fable 5 and Mythos 5 AI models for every user on Earth — and argues that governing cutting-edge technology by emergency memo creates what he calls a ‘compliance blast radius’ that punishes the innocent while doing little to address the actual risk.

A Friday Afternoon. A Phone Call. Everything Goes Dark.

Picture this: your team shows up for work on a Monday morning and the AI tool your entire platform is built on no longer exists. Not glitching. Not slow. Gone. That is exactly what happened to the developers, attorneys, and entrepreneurs who had woven Anthropic’s Fable 5 and Mythos 5 into their products and workflows.

On June 12, 2026, the Commerce Department’s Bureau of Industry and Security issued a directive citing national security: Anthropic must immediately disable both models for any foreign national, including its own foreign-national employees. Anthropic received the order at 5:21 p.m. Eastern time. By end of day, Fable 5 and Mythos 5 were off — not just for foreign users, but for everyone. Every customer. Worldwide. Access to all other Anthropic models was unaffected, but Fable 5 had been publicly available for exactly three days.

Now, the way I see it, that is not a policy. That is a fire drill with no exit map.

What Did the Government Actually Find?

The government’s stated justification: someone discovered a method to bypass, or ‘jailbreak,’ Fable 5 — a technique that, if exploited, could unlock dangerous cyber capabilities. Anthropic’s statement did not identify the source of the tip; multiple outlets reported that researchers found workarounds and shared them with the White House, which then treated it as a national security concern and moved through export-control channels.

Anthropic pushed back hard in its public statement. The company said the disclosed technique amounted to asking the model to read a specific codebase and fix software flaws — and that the same capability is available from publicly deployed models, including OpenAI’s GPT-5.5. The vulnerabilities surfaced were, by Anthropic’s account, minor and already known. No one had demonstrated a universal jailbreak — a method capable of broadly bypassing the model’s safeguards across a wide range of harmful uses. Anthropic’s letter from the government contained no specific details of the national security concern.

As an AI ethics speaker and author, I have watched this pattern before: a risk assessment, real or overstated, drives a decision that is faster than the evidence. And the people who pay for that speed are rarely the ones who created the risk.

What Is the ‘Compliance Blast Radius’ — and Why Does It Matter?

Here is the part that should keep every business leader up at night. The directive targeted foreign nationals. But Anthropic could not implement a nationality verification system for hundreds of millions of users overnight. So the company did the only thing it could do in the time given: it shut off access for everybody.

That is what I mean by a compliance blast radius — a term I use for what happens when the enforcement mechanism is blunt and the target is precise. The legal instrument does not distinguish between a Canadian software developer building legal drafting tools in San Jose and a state-sponsored threat actor in an adversary nation. The blast catches them both — and a great many other people who had nothing to do with the underlying concern.

Legion LegalTech, a San Jose company that builds AI-powered drafting tools for attorneys, filed suit in federal court in Washington, D.C., on June 23, 2026. Its complaint calls the harm ‘immediate, irreparable, and existential.’ Legion’s Canadian development team lost access overnight — not because they posed a threat, but because they happened to be standing in the blast radius. Legion CEO Arthur Rothrock asked the question plainly: ‘Who’s to say they can’t do this any other time against another company, like OpenAI?’ That is the right question. And we do not yet have a good answer.

This is also the first known customer lawsuit challenging an AI model access ban — a legal precedent that will shape how export controls on AI services are interpreted and enforced for years.

The Rationalization That Creates the Next Risk

In my work on ethics and consequences, I have watched this pattern play out in boardrooms, courtrooms, and now in the policy space. It usually does not happen all at once. It happens in increments, each one rationalized. ‘We’ll sort out the details later.’ ‘The urgency justifies the shortcut.’ ‘A fast, private directive beats a slow, public process.’

Anthropic said as much in its public statement: it disagreed that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people, and noted that if this standard were applied across the industry, it would essentially halt all new model deployments for all frontier model providers. The company was complying with a legal directive it believed was disproportionate.

The collateral damage reached beyond Legion. The UK’s AI Security Institute — one of the leading international bodies for testing frontier AI models — lost access too. Allied partners. Paying customers. Researchers doing the work of making AI safer. The very people you would want evaluating these systems in an emergency were cut off in the emergency.

Frankly, that is not national security. That is an own goal.

What Does Responsible AI Governance Actually Look Like?

Anthropic itself has publicly called for something better. The company has said the government should have the ability to block unsafe deployments — but as part of a statutory process that is transparent, fair, clear, and grounded in technical facts. That is not a radical ask. That is basic rule of law applied to a new domain.

The NIST AI Risk Management Framework — which federal agencies are expected to consult when approaching AI risk — outlines a sequence built around defining accountability structures before a crisis, establishing technical criteria for what constitutes a triggering risk, and building workable enforcement mechanisms with verification and appeal paths. None of that happened here. The directive arrived at 5:21 p.m. It cited national security. It offered no specific details. And Anthropic — to its credit — complied, even while publicly disagreeing with the proportionality of the response.

This, right here, is why AI governance matters. Not just the rules we write for AI systems, but the rules we write for ourselves in how we regulate them.

The Lesson Behind the Headline

I am not suggesting the government had no legitimate concern. National security is real. The potential misuse of frontier AI models by bad actors is real. But a legitimate concern does not automatically justify any response. The means matter. The process matters. And the people who get caught in the crossfire matter.

Every choice has a consequence. That is true for the businesses that build on third-party AI infrastructure without a contingency plan. It is true for the government agencies that reach for the fastest tool without examining its blast radius. And it is true for all of us watching this unfold and trying to understand what comes next.

The rule of law does not move at the speed of an emergency memo. That used to be the point. As AI ethics speaker and author Chuck Gallagher, I would say this: if we want governance that protects both national security and economic integrity, we need to build the processes before we need them. Not at 5:21 p.m. on a Thursday, with the whole world watching.

Frequently Asked Questions

Why did the US government shut down Anthropic’s AI models Fable 5 and Mythos 5?

The Commerce Department’s Bureau of Industry and Security issued an export-control directive on June 12, 2026, citing national security concerns. The government believed a jailbreak method had been discovered that could unlock dangerous cyber capabilities in Fable 5. Anthropic disputed the severity of the finding, noting the technique involved widely available capabilities already present in other deployed models.

Why were all Anthropic users affected if the order only targeted foreign nationals?

Anthropic could not implement nationality verification for hundreds of millions of users on the same day it received the directive, so it shut off access to Fable 5 and Mythos 5 for all customers globally. Access to all other Anthropic models was unaffected. This broad shutdown is what critics have called the ‘compliance blast radius’ of governing by emergency directive.

Who sued the US government over the Anthropic AI ban?

Legion LegalTech Corp, a San Jose legal technology company, filed suit in federal court in Washington, D.C., on June 23, 2026. Legion builds AI-powered legal drafting and case-management tools and depends on Anthropic’s models. The company’s Canadian development team lost access overnight; Legion called the harm ‘immediate, irreparable, and existential.’ Anthropic is not a party to the suit. Chuck Gallagher, AI ethics speaker and author, has noted this case as a landmark test of how export controls apply to cloud-based AI services.

What is the NIST AI Risk Management Framework and why does it matter for AI export controls?

The NIST AI RMF outlines a broadly applicable risk governance sequence — define accountability structures before a crisis, establish technical criteria for triggering restrictions, and build enforcement mechanisms with verification and appeal paths. Critics of the Fable 5 directive have argued that none of these steps preceded the order — the government acted on verbal evidence of a narrow potential jailbreak with no formal risk assessment, no public technical criteria, and no clear appeal process for affected businesses.

What does this mean for businesses that build on third-party AI infrastructure?

The Legion LegalTech case is a warning for any company that has embedded externally hosted AI models into its core product. A government directive can remove access overnight with no advance notice and no immediate recourse. Risk experts recommend contingency strategies including hybrid architectures, multi-vendor access arrangements, and contractual clauses addressing sudden access changes — though each carries its own trade-offs.

Want to Bring This Conversation to Your Organization?

The intersection of AI capability, government regulation, and business risk is not a future concern. It is happening right now, and every leader who has embedded AI into their operations needs to understand what it means for their team, their customers, and their liability. Chuck Gallagher speaks to organizations navigating exactly these questions — from AI governance frameworks to the ethics of building on systems you do not fully control. Learn more or book a conversation at ChuckGallagher.com.

Five Questions for Reflection and Discussion

1. If your organization relies on a third-party AI model, what happens to your operations if access disappears overnight? Do you have a contingency plan?

2. The government acted on verbal evidence of a narrow potential jailbreak with no public technical criteria. What standards should exist before a government can pull a commercial AI product from the market?

3. Anthropic complied with a directive it publicly disagreed with. Is compliance without agreement an ethical response? When, if ever, should a company refuse?

4. The UK’s AI Security Institute — a body working to make AI safer — lost access during the shutdown. What does it tell us about the collateral damage of blunt enforcement tools?

5. ‘Every choice has a consequence.’ Who bears the consequences here — and who should?

Leave a Reply