Who Gets to Use the Model Now?

The government switched Anthropic's model back on, but only for a list of approved names. It will not say what law the list runs on.

Watercolor illustration of a nightclub entrance. Badged guests walk inside while a bouncer holds a clipboard by a velvet rope and a long public line waits outside.
Image generated with Nano Banana 2.

This piece follows our earlier coverage of Commerce’s Anthropic shutdown: Commerce Found the Kill Switch and Is an AI Answer an Export?.

Two weeks ago the U.S. government switched off Anthropic’s two most powerful models, and last Friday it switched one of them back on. Claude Mythos 5 did not come back like ordinary software, with a status page going green and every previous customer getting access again. It came back to a list.

Commerce Secretary Howard Lutnick sent Anthropic a letter saying the company could restore Mythos 5 for a defined set of approved organizations, reportedly more than a hundred companies and institutions, including many Fortune 500 companies. Anthropic described the approved group as cyber defenders and infrastructure providers. The approval also covered foreign-national employees at those organizations and Anthropic’s own foreign-national employees, the same category of workers the original directive had locked out. Fable 5, the public-facing version of the same underlying system, was not mentioned. It remains offline with no date attached.

Mythos came back to a guest list rather than to the public. The letter does more than ease one shutdown. It shows a new path for frontier AI releases: not just whether a model is good enough to ship, but whether a user is approved to touch it.

What actually crosses the border

Export control was built for things that move: a crate of chips, a hard drive of source code, a technical manual handed to a foreign engineer. You can point at the object and say it left the country. Hosted AI does not behave that neatly.

Legion LegalTech’s lawsuit, which we wrote about earlier this month, goes straight at that gap. The shutdown cut off the company’s Canadian developers, but Legion argues that its engineers only sent prompts to a service running in Virginia and received text back. They never received the weights, the source code, the object code, or the training data. The model stayed put; only an answer came back over the wire.

The same access problem shows up on the hardware side. A Carnegie Endowment analysis from May described how a Chinese firm can be blocked from buying advanced U.S. chips but still rent their computing power through a data center in a third country. Under current law, that arrangement is generally legal. The chip stays put while its computing power travels.

Mythos pushes the access problem one step further. The model sits on Anthropic’s servers, the weights never go anywhere, and the thing being granted or withheld is permission to log in. Export control was designed to govern objects crossing borders. Commerce is now reaching toward the use of a capability under conditions it sets. As UC Berkeley public-policy professor Andrew Reddie put it in Tech Policy Press, the open question is whether a system built to control things can govern capabilities.

The wording of the new permission shows the stretch. According to Reddie’s account of the letter, Commerce said a license would no longer be required to “export, reexport, or in-country transfer” Mythos 5 to the approved entities, their foreign-national employees, or Anthropic’s own foreign-national employees. That is export-control language reaching into domestic access, employment status, and hosted software. The border is being redrawn around who can touch a capability.

It is not just Anthropic anymore

One reading is that Anthropic had a bad month, fought the administration over a jailbreak, and is now negotiating its way back to normal. OpenAI made that harder to believe the same week, when it released its newest flagship through a similar access process.

OpenAI’s announcement of the GPT-5.6 family, its Sol, Terra, and Luna models, described a limited preview that begins with a small group of trusted partners. The company said it previewed the models’ capabilities with the U.S. government beforehand, is starting narrow at the government’s request, and shared the partner list with officials. OpenAI was also unusually direct about its discomfort with the arrangement. It wrote that this kind of government access process should not become the long-term default, even as it works with the administration on a cyber executive order framework and a repeatable process for future releases.

The important part is that OpenAI complied while objecting. Two of the most capable AI labs in the world spent the same week routing major model access through the government, one after a crackdown and one through a voluntary preview. Dean Ball, who runs strategic futures at OpenAI and previously advised the White House on AI, said frontier developers now need an explicit green light from the government. That sounds less like a one-off exception than an emerging release process.

Nobody will say what law this runs on

The unresolved problem is the legal authority underneath it.

The authority could be export control stretched over hosted access, the June executive order on AI security, procurement leverage, or a Commerce “is informed” letter doing work that looks more like a licensing system. Commerce has not said which theory it is using. The original June 12 directive remains in force; Friday’s letter is an exception carved into it, not a repeal. Lutnick reserved the right to reevaluate and narrow the approval again if circumstances change. The only export classification that directly covered advanced model weights was rescinded last year with nothing put in its place. There is still no published rule, stated threshold, appeal path, or equal-treatment guarantee across labs.

Anthropic had already described a cleaner version of this process. On the same morning it launched Fable 5, the company published a framework arguing that governments should be able to block dangerous models only through specific legal triggers, third-party evaluation, judicial review, and equal standards for equally capable systems. Days later, it was switched off by a mechanism with none of those features. The power to shut a model down arrived ahead of any process for using that power carefully, and the power to let one back on, conditionally, for a chosen few has arrived the same way.

There is a real argument for caution here. A hosted frontier model can help a capable user with offensive cyber work or other genuinely dangerous tasks even though no file changes hands. The labs describe their newest systems in exactly those terms, advertising major coding and cybersecurity gains and spending hundreds of thousands of GPU hours hunting for jailbreaks. If that capability is real, letting a vetted hospital or grid operator use it while the public waits may beat shutting everyone off at once. A guest list can be the humane version of a ban.

But temporary arrangements often become permanent infrastructure before anyone votes on them. Mythos is back through a side door, GPT-5.6 came in through a preview list, and Fable is still outside. Maybe this is a bridge to a real framework, with rules, thresholds, and a way to argue that you belong on the list. Or maybe the framework has already arrived, and the reason no one will name the law underneath it is that a guest list is easier to keep when you never have to say what it is printed on.