At 5:21pm Eastern on Friday 12 June, Anthropic received a letter from the US Department of Commerce. Before most of its customers in Asia were awake, it had switched off Claude Fable 5 and Claude Mythos 5 for every customer in every country. The directive ordered it to suspend access to both models by any foreign national, inside or outside the United States, including Anthropic’s own foreign-national employees. An API key does not carry a passport. Neither does an AWS account, a Google Cloud project or a seat on a Team plan. The only way to comply for foreign nationals was to comply for everyone. Fable 5 had launched on Tuesday 9 June as the first Mythos-class model the public could buy. It lasted three days. As I write on Saturday 13 June, nobody outside Anthropic and the Commerce Department knows when it comes back, or in what form.
I run the AI and data platform for a large industrial group, and I spent Saturday morning reading our router’s ledger rather than the news. It told me which classes had been on Fable 5, which had fallen back, and what that would cost over a month. That is the argument of this post: a frontier model is now a dependency that a government, a lab or a court can switch off with, at best, a day’s notice, and most enterprise architectures are built as if the model were a library they had compiled in. The facts first, because the decisions live in the details.
What happened, and what is known
The lineage matters. On 7 April Anthropic announced Project Glasswing and Claude Mythos Preview, a model it said it would not make generally available until it had built stronger safeguards; access went to eleven named launch partners and some forty organisations that maintain critical software. On 9 June the safeguards arrived. Fable 5 is, in Anthropic’s words, a Mythos-class model “made safe for general use”; Mythos 5 is the same model with some safeguards removed, for organisations verified through its cyber and life-sciences programmes. Both cost $10 per million input tokens and $50 per million output, double Claude Opus 4.8, with a million-token context window and 128,000 tokens of output.
The safeguards are classifiers, and they change what a model call means. Requests that trip the cybersecurity, biology and chemistry, or distillation classifiers are answered by Opus 4.8 instead, which Anthropic says happens in fewer than five percent of sessions. So from the first day a Fable 5 customer was already, some of the time, an Opus 4.8 customer without being told on which calls. The model requires 30-day data retention and is not offered under zero data retention. It shipped on the Claude API, Amazon Bedrock, Claude Platform on AWS, Google Cloud and Microsoft Foundry. Pro, Max, Team and seat-based Enterprise subscribers had it included from 9 to 22 June; from 23 June it was to draw on usage credits.
Then the letter. Anthropic’s Friday statement is short and unusually blunt. The government, it says, had given verbal evidence of “a narrow, non-universal jailbreak”, which amounted to asking the model to read a specific codebase and fix the flaws it found; the capability on show is widely available from other models; Anthropic disagrees that a narrow jailbreak should be grounds for recalling a commercial model; it is working to restore access as soon as possible; no other Anthropic model is affected. The practical result it states without euphemism: it must disable both models for all customers to ensure compliance.
What is not known is the longer list. The letter has not been published, so its legal basis is inference. There is no restoration date and no description of what a compliant Fable 5 would look like, since a nationality check on API traffic exists on no platform I know of. Nobody knows whether the 23 June credit switch still means anything, or whether this is a one-off or the first use of a tool the US government now considers available to it. The honest planning assumption is that Fable 5 is gone for an unknown period, and that the next model could go the same way.
Three warnings we had already been given
The suspension is new in kind, but the idea that access to a model is conditional was not. Three warnings arrived before Friday; filing them as administrative detail missed the pattern.
Rationing. The launch post itself announced that Fable 5’s inclusion on subscription plans would end on 22 June and that from 23 June it would draw on usage credits: fourteen days’ notice that the cost structure for a class of users would change, written into the announcement of the model. The signal is not the price. It is that a lab now budgets the capacity of its flagship and allocates it, and an allocation is a lever that can be pulled again.
Gated tiers. Mythos Preview was invitation-only from April. Mythos 5 is for verified organisations only. And Fable 5 carries a gate inside the model: classifiers that route a request to Opus 4.8 without telling the application which model answered. Three layers of the same idea, that capability is granted by identity and purpose rather than sold by the token. If identity can grant access, identity can withdraw it, and on Friday it did, for a category of identity, foreign nationals, that no access-control system models.
Deprecation. This is the warning with the best paperwork. Anthropic’s policy gives customers with active deployments “at least 60 days’ notice” before a publicly released model is retired, and it has kept to it: Claude Opus 4 and Sonnet 4 were notified on 14 April for retirement on 15 June, 62 days; Opus 4.1 on 5 June for 5 August, 61 days; Mythos Preview was marked deprecated on 9 June, the day its successor shipped, retirement date to be announced. The partner platforms run longer calendars of their own. Amazon Bedrock’s lifecycle page commits that a model stays on the platform for at least twelve months after launch and sits in a Legacy state “at least 6 months before the EOL date”; during Legacy, new customers cannot adopt it and existing customers can lose access after fifteen days of inactivity. Bedrock lists Sonnet 4 as Legacy from 14 April with end-of-life on 14 October, four months after Anthropic’s own retirement of the same model. Google Cloud sets its own dates for Claude, which Anthropic’s documentation says can differ from its own.
Put the three together and the pattern is a spectrum of notice: six to twelve months on a partner platform, sixty days on the first-party API, fourteen days for a rationing change, and on Friday, none. Every control a platform team has for the first three, a registry of retirement dates, a bench run on the replacement, a cost line for the change, is the control that absorbs the fourth. The difference is only whether it fires on a calendar or on an error.
Blast radius: four days in production
Who was running Fable 5 in production on Friday evening? More organisations than a three-day-old model would normally have, for three reasons. It had been in partners’ hands as Mythos Preview since April, so the companies quoted on launch day, Stripe describing a fifty-million-line Ruby migration among them, were not starting from zero. It was included on every paid plan, so every Claude Code user on a Max or Team seat had it from Tuesday. And the free window ended on 22 June, a deadline that moves work quickly rather than carefully. I will not guess which launch customers had production traffic on it by Friday. I know what our own ledger showed: Fable 5 on the allowed list for two flagship task classes, behind a value threshold, and nowhere else.
What broke is easier to describe than who. Any call to claude-fable-5 on any platform fails. Any workflow with that string in its code is down until someone edits the code. Any agent mid-run at 5:21pm Eastern stopped at its next model call, which for a long-horizon agent is the expensive kind of stop. Any prompt tuned to Fable 5’s effort levels and refusal behaviour now runs, if it runs at all, on a model that reads it differently. Prompt caches are per model, so a team that switched cleanly to Opus 4.8 started cold, paying write rates before its first hit. And any team that spent the week migrating from Opus 4.8 to Fable 5 now migrates back, without the week. The quieter damage is to plans: product decisions taken on Tuesday on the assumption that the model would exist have, on Saturday, no model under them.
The architecture that survives it
None of what follows is novel. It is the design that turns a price change into a configuration change, applied to the case where the change is a government letter. Five properties, in build order.
Model names are configuration, not code. No application should contain the string claude-fable-5, or any other provider model identifier. The application declares a task class, the router resolves the class to a model, and the mapping lives in one versioned registry. The test is mechanical: a search of the repositories for any provider’s model identifiers should return hits only in the router’s configuration. On Friday night, the organisations that recovered in an hour were the ones for whom that search returned nothing.
Every task class has a bench-qualified fallback chain. A fallback is not the next model down. It is a model that has passed the class’s bar on the same task set, with its score and cost per task recorded next to the primary’s, so that when the route moves the quality delta is known rather than discovered. Opus 4.8 was the natural fallback for Fable 5: Anthropic was already routing some Fable 5 traffic to it, and for most teams it had been the primary until Tuesday. But the chain should not stop at one provider. A second provider’s model qualified for the same class is the only fallback that survives a directive aimed at one lab, and the device and on-premises tier I wrote about on Thursday in Twenty billion parameters in your pocket is the floor for classes that handle restricted data and cannot leave the building whichever cloud is up.
Prompts and tool schemas are provider-neutral. What makes a prompt hard to move is rarely the instructions. It is the provider-specific mechanics around them: an effort parameter whose levels mean different things on each model, an assumption about how refusals come back, a tool definition that leans on one provider’s schema extensions. The router owns those mappings per model; the application owns the task, the reference material and the tool contracts in plain JSON Schema. A prompt that can be sent unchanged to two providers and graded on the same bench is a prompt that can fall back.
Cache and context assumptions do not depend on one tokeniser. Anthropic documents that Claude 4.7 and later models use a newer tokeniser that produces roughly 30 percent more tokens for the same text than Sonnet 4.6 and earlier. A chunker sized in Fable 5 tokens is wrong on an older Claude model and wrong again on another provider; a pipeline that assumes a million-token window overflows a model with 200,000; and the cache is per model, with writes at 1.25 times the input rate on the five-minute tier, so every fallback begins cold with a write bill. Size chunks to the smallest window in the chain, keep the cacheable prefix stable across providers, and carry the cache-write cost of a fallback in the ledger as a known event.
Contracts carry substitution rights. The commercial layer should mirror the technical one: the right to substitute any bench-qualified model, including another vendor’s, without penalty or re-approval; a named substitute from the vendor when it withdraws a model, as Anthropic named Opus 4.8 on Friday; immediate notice and public status reporting when withdrawal is involuntary; and credits for prepaid commitments and unused usage credits during a suspension. None of this stops a directive. It stops the directive becoming a dispute.
Export control is a vendor-risk category now
Vendor risk reviews ask about financial failure, breaches, outages and price. Friday added a category that behaves differently from the others. The trigger is outside the vendor’s control. The vendor cannot comply at customer granularity, so the action is global even when the concern is specific. It flows through every reseller: Bedrock, Google Cloud and Foundry customers lost the model at the same moment as API customers. And nothing in the directive distinguishes an ally from an adversary. Every one of my colleagues is a foreign national under its terms, and so is every employee of every bank in London, Frankfurt, Singapore or Mumbai that had the model in production.
The legal foundation is not mine to assess, and I notice that the lab affected says it disagrees with it. What I can assess is what a buyer should ask before the next model, and the list fits on a questionnaire.
- Under what legal regimes can you be compelled to suspend our access, and can you comply for our organisation alone, or only globally? A vendor that must switch off the world to satisfy an order about one country is a different risk from one that can fence a tenant.
- What notice do we get for each kind of withdrawal? Deprecation, rationing, tier changes and involuntary suspension each need a stated minimum, and the involuntary case an obligation of immediate disclosure.
- What is the named substitute, and is it covered by the same terms? Opus 4.8 was the de facto substitute on Friday. The contract should say so in advance.
- Do our cloud-platform contracts carry independent obligations? If a vendor-level directive flows through a reseller unchanged, the reseller’s availability commitments need to say what happens to the bill.
- What happens to retained data during a suspension? Fable 5 required 30 days of retention. A model that is switched off still holds a month of our traffic somewhere.
- Which of our task classes have no fallback outside this vendor, and which none outside this jurisdiction? That question is for us, not the vendor, and it matters most.
A worked example: the Friday review queue
Consider a bank that reviews loan documentation overnight, each document run through a model that extracts covenants, flags inconsistencies and drafts a reviewer’s note. Four thousand documents a night, submitted as a batch at 6pm Eastern so the results are waiting for the desk in the morning. Say each document is about 25,000 tokens of fresh input, with a 6,000-token block of instructions and reference material that caches, and 2,500 tokens of structured output. The token counts are my estimates for a plausible workload; the prices are Anthropic’s list rates.
On Thursday 11 June the batch ran on Fable 5: about $0.38 a document at standard rates, or $0.19 on the Batch API at half price, so about $762 a night and $16,800 for a month of 22 nights. The desk had moved to Fable 5 on Tuesday because the launch-week bench showed a real gain on covenant extraction over Opus 4.8, which had held the class since late May.
Friday’s batch was submitted at 6pm Eastern, thirty-nine minutes after the letter. Without a fallback chain, here is Friday. The first calls return errors. Nobody watches a nightly batch, so the failure is found by the desk on Saturday morning, or by an on-call engineer if the bank is lucky. The model identifier is in the workflow code, so the fix is a code change, and under the bank’s model-risk policy a change of model needs approval from someone who is not at work on Saturday. The prompt carries Fable-specific effort settings, and the last bench result for Opus 4.8 is three weeks old and on the previous prompt. By Monday there are two nights of documents in the queue, eight thousand of them, and a desk that must either review them by hand or trust a model nobody has signed off for this task. That is not a model failure. It is a design that assumed the model would be there.
With a fallback chain, here is the same Friday. The router’s circuit breaker on the Fable 5 route opens after a burst of consecutive failures, and the class falls back to Opus 4.8, next in the chain because it passed the class bar in May and has been benched on every prompt change since. The first calls pay cache-write rates on the 6,000-token reference block; after that, hits. The batch completes. Every call is written to the ledger as a fallback event with its reason, so Saturday’s review takes an hour: four thousand fallback events, a night that cost about $381 on batch instead of $762 because Opus 4.8 is half Fable 5’s price, and a quality delta known from the bench rather than guessed. The desk widens its human-review sample for the week, the model-risk owner signs a one-line note that the substitute was already qualified, and nobody is paged. On Monday the question is whether to wait for Fable 5 or stay, and the ledger answers it: about $8,400 a month saved against a measured loss of accuracy on one task. That is a decision, not an incident.
The difference between the two Fridays is a few thousand lines of router, a registry file, a bench that runs on prompt changes, and a contract clause. All of it existed before 9 June. What changed on Friday is that the cost of not having it became visible.
What to do this week
- Search the code. Find every provider model identifier in every application repository. Each hit is a workflow that goes down with its model. Move them into the router’s configuration; the search should return nothing by the end of the quarter.
- Qualify the chain, not the model. For every task class that was on Fable 5, record the bench result for the fallback on the current prompt; if there is none, run it now, while the fallback is the primary. Then add a second-provider entry to every class that handles non-restricted data.
- Add the six questions to vendor due diligence. Every frontier contract renewal should answer them, and the answer to the first, whether the vendor can comply at tenant granularity, should drive how much of the portfolio sits with that vendor.
- Keep the device and on-premises tier benched. For restricted task classes it is the only fallback that no directive, deprecation or outage reaches. It does not need to win the bench; it needs to pass the bar.
- Do not migrate back on day one when access returns. If and when Fable 5 returns, it will return with new terms and probably new controls. Bench it again, read the terms, and let the registry decide. No production migration within a month of a release applies to a re-release too.
- Write down what Saturday morning looked like. Which classes moved, how long it took to know, what it cost, who was woken. That is the postmortem for an incident that was not your fault, and the document that justifies the router to the people who asked why you needed one.
Ten years ago the question a platform team asked of a model was whether it was good enough. Then it was what it cost. This week it is whether you are allowed to use it, and the answer changed on a Friday evening without anyone asking you. A frontier model is a dependency with the failure modes of a dependency. Build for the day it is not there.