The Signal — June 20, 2026
The US government ordered Anthropic's most powerful AI models restricted — but roughly 200 organizations never lost access. A Bloomberg report reveals that companies enrolled in Anthropic's Project Glasswing program continue to use Mythos Preview for cyber vulnerability research, exploiting a regulatory gap the shutdown order never closed.
The Glasswing Loophole
When the US government moved to restrict access to Anthropic's Fable 5 and Mythos 5 model families, the message was clear: frontier AI capabilities with potential cybersecurity applications needed tighter controls. But the order contained a glaring omission. It never explicitly addressed Mythos Preview, the earlier-access version of the model already deployed to roughly 200 organizations through Anthropic's Project Glasswing initiative.
These aren't fringe operators. Bloomberg's reporting identifies banks and major technology firms among the Glasswing cohort, all cleared to use Mythos Preview specifically for cyber vulnerability research. They were granted access before the shutdown order landed, and nothing in the order's language revokes it. The result is a regulatory gray zone where the government's intent and its legal reach don't quite align.
If this dynamic feels familiar, it should. TechCrunch published a parallel analysis drawing a direct line from today's AI export control struggles to the 1990s PGP encryption wars. In that era, the US government classified strong cryptographic software as a munition and attempted to block its export. Phil Zimmermann faced a criminal investigation for publishing PGP's source code. The effort failed badly: the code spread globally, the restrictions proved unenforceable, and the government eventually abandoned the approach.
Like cryptographic software, advanced AI capabilities are information at their core, patterns of weights and architectures that resist containment once they exist. The TechCrunch analysis argues that attempting to control AI model access through export-style restrictions faces the same structural problem: you can restrict distribution channels, but you can't uninvent the capability.
The Glasswing situation doesn't exist in isolation. It sits within a rapidly shifting regulatory framework that reveals just how difficult AI governance has become at the frontier.
On June 2, President Trump signed an AI executive order establishing a voluntary frontier model review framework, reflecting the administration's reluctance to impose hard mandates on US AI companies. In May, the Five Eyes intelligence alliance released guidance on securing agentic AI systems, acknowledging that autonomous AI capabilities create security challenges that existing frameworks don't address.
Then in early June, Japan and the EU were granted access to Mythos specifically for cybersecurity testing, an international dimension that complicates the domestic restriction picture further. If allied nations can access the model for security research, the argument for restricting domestic companies already cleared for similar work becomes harder to sustain.
What the Gray Zone Reveals
What matters here is less whether 200 companies should have access to Mythos Preview than what the episode reveals about the structural challenge of regulating frontier AI.
Traditional export controls work best with physical goods. You can track shipments of enriched uranium or missile components through supply chains. Software has always been harder, as the PGP episode demonstrated. AI models occupy an even more complex position: they're software, but their capabilities depend on massive compute infrastructure that is trackable, creating a partial chokepoint that physical export controls never had with code alone.
The Glasswing gray zone suggests regulators are still learning where AI falls on this spectrum. The shutdown order targeted the production models but missed the preview version, either by oversight or by deliberate scoping. Either explanation is telling. If it was oversight, the regulatory apparatus doesn't yet understand the model versioning and access structures it's trying to control. If it was deliberate, it implies the government recognizes that cutting off cleared cybersecurity researchers would create its own national security problems.
As frontier models grow more capable and more widely deployed through early-access programs, these gray zones will multiply. The question worth asking isn't whether governments can control AI access, but whether the control mechanisms they're building can keep pace with the deployment structures the companies are creating.
Sources: Bloomberg · Reuters · TechCrunch
On the Editor's Desk
A shorter Signal today. We looked at a few other stories, but they either weren’t new, weren’t well-sourced enough, or felt too stale to be useful. Rather than pad the edition, we’re keeping it to the one story that actually held up.