A Blanket Kill Switch, Not a Targeted One

On June 12, 2026, the US Commerce Department's Bureau of Industry and Security ordered Anthropic to suspend its Fable 5 and Mythos 5 models for foreign nationals worldwide, after regulators flagged a narrow jailbreak that let the models read a codebase and surface exploitable vulnerabilities faster than intended. The directive was framed as a national security measure, not a broad restriction on AI exports as such.

Anthropic said it had no reliable way to distinguish an eligible domestic user from an ineligible foreign one at the application layer, so it shut both models down for every customer on the planet, including its own non-US employees, to stay compliant. Only the National Security Agency secured an exemption, on the grounds that no other model matched Mythos's vulnerability-discovery capability.

Tokyo Just Said the Quiet Part Out Loud

On August 10, in an interview carried by Kyodo News, Yoichi Iida, Japan's National Cyber Director and Deputy National Security Advisor, confirmed publicly for the first time that the June suspension "disrupted security vulnerability scanning operations for key government systems" inside Japan itself - the first on-record admission from an allied government that Washington's export enforcement produced real operational damage, not just commercial inconvenience, on friendly soil.

Iida did not treat the incident as a reason to pull back. He called Japan's adoption of sophisticated AI technology in cyber defense "inevitable," warning that "it would be no surprise if the time between vulnerability discovery and exploitation were shortened to a fraction of a hundredth or a thousandth of what it used to be" without it.

The Timing Makes It Worse, Not Better

The disruption landed less than seven weeks before Japan's Active Cyber Defense Act, approved by Prime Minister Sanae Takaichi's cabinet in March, is due to take effect on October 1, 2026. The law authorizes the Japanese government to act preemptively against cyberattack risks - exactly the kind of proactive, AI-accelerated vulnerability scanning that Fable 5 and Mythos 5 were being used for before Washington switched them off.

Anthropic restored global access to Fable 5 on July 1 after the US restrictions lifted at the end of June, but Mythos, the more capable of the two for vulnerability discovery, came back only for a vetted set of US organizations. That means the tool Iida's own account suggests Tokyo was relying on for government scanning may still not be fully available to it, three months before the Active Cyber Defense Act goes live.

The Lesson Extends Well Past Anthropic and Japan

The mechanism that hurt Japan was not a targeted policy but an ordinary technical limit: a US vendor can be legally required to distinguish domestic from foreign users, discover it cannot do so at the application layer, and default to switching a tool off for every customer worldwide rather than risk violating an export order. That default applies to any frontier AI vendor headquartered in the US, for any future directive, regardless of who is actually implicated.

For any EU or UK organization that has built a security-critical process - vulnerability scanning, incident triage, code auditing - around a single foreign frontier model, the Japan case is the clearest evidence yet that the vendor's home government can switch that process off overnight, with no advance notice and no carve-out for allies, over an issue that has nothing to do with the customer at all. The practical answer is not to avoid US AI vendors; it is to make sure no single vendor is a single point of failure for anything that has to keep running the day an export order lands.