In June 2026, the most capable AI model ever offered to the public went dark for nineteen days by order of the US Commerce Department — three days after launch. It came back with government-reviewed filters, government-accepted conditions, and a settlement whose full terms have never been published. The pauses and silent model switches Claude users see today are that settlement operating.
If you use Claude Fable 5, you have probably seen it: a conversation stalls, or a notice appears saying your request was answered by a different model. Anthropic's help documentation describes the mechanism plainly enough — automated checks run on every request, and flagged ones either pause or fall back to Claude Opus 4.8[1]. What the documentation does not convey is how those checks came to exist in their current form. That story runs through the Pentagon, the White House, an active air war against Iran, a rival cloud giant's security researchers, and an export-control directive of a kind never before aimed at an American software product.
This article assembles the documented record. Where the record supports a claim, it is stated without hedging. Where the record ends and inference begins, that boundary is labeled explicitly. Both disciplines are the point.
The Timeline
FEB 24, 2026
Defense Secretary Pete Hegseth meets Anthropic CEO Dario Amodei and, per reporting cited by the Center for American Progress, demands a
signed document granting the military full access to Anthropic's models for "all lawful uses" — including uses Anthropic restricts: mass domestic surveillance and autonomous weapons without human oversight
[2].
FEB 26, 2026
Amodei publishes a statement confirming the government threatened to remove Anthropic from its systems and to designate it a
"supply chain risk" — his statement calls this a label reserved for US adversaries, never before applied to an American company
[3]. The same day, a House AI Commission co-chair publicly warns about reports that Anthropic is revising safety commitments under pressure
[4].
FEB 27, 2026
President Trump directs federal agencies to
"IMMEDIATELY CEASE all use of Anthropic's technology," with a six-month phase-out for the Department of War
[5]. The DoD moves toward the supply-chain-risk designation. Anthropic says publicly that no intimidation will change its position
[6].
FEB 28, 2026
One day after the cease-use order, Operation Epic Fury begins — coordinated US and Israeli strikes on more than 2,000 Iranian sites. Washington Post reporting, cited across defense press, describes Claude integrated with Palantir's Maven Smart System producing roughly 1,000 prioritized targets in the first 24 hours
[18]. Claude had been embedded in Maven since late 2024 via Palantir and AWS
[19].
MAR 2026
Agencies comply: GSA removes Anthropic from USAi.gov and its award schedules; the State Department and HHS reportedly stop using Claude; OPM drops Claude from its AI use-case list while adding competitors
[5]. Simultaneously, the government acknowledges Claude is
still being used for the Iran war despite the ban — embedded systems in accredited classified environments cannot simply be removed
[20].
APR 2026
Anthropic discloses
Mythos — a model it says is capable enough at code to pose a global cybersecurity threat — and grants access only to a small group of vetted security experts
[7].
JUN 9, 2026
Claude Fable 5 launches publicly — a version of Mythos with added safeguards, deployed across Anthropic's consumer and developer surfaces.
JUN 12, 2026
Amazon researchers have reported to US officials a technique that bypassed Fable 5's safeguards, prompting it to identify software vulnerabilities and, in one instance, write exploit code
[8]. At 5:21pm ET, Anthropic receives an export-control directive from Commerce Secretary Howard Lutnick citing national-security authorities. The directive bans non-US nationals from accessing Fable 5 and Mythos 5 — including foreign employees of US companies.
Anthropic pulls both models within hours[9].
JUN 15–18, 2026
Negotiations move to the White House; Anthropic works to get the directive lifted
[10]. On June 15, a DOJ court filing defending xAI's data centers discloses sworn testimony from the Pentagon's AI chief:
Grok is now operating inside Project Maven, credited with enabling over 2,000 munitions against 2,000 distinct targets within 96 hours during Epic Fury
[21].
JUN 26, 2026
The government approves restoring Mythos 5 access for a set of US organizations
[11].
JUN 30 – JUL 1, 2026
Commerce lifts the export controls. Anthropic publishes its redeployment post and
Fable 5 returns globally July 1 — with a new classifier layer trained, in the company's words, in close work with the government, and reviewed by Commerce's Center for AI Standards and Innovation (CAISI) before controls came off
[11][12].
JUL 7, 2026
Mumbai-based Fractal Analytics — already an OpenAI solutions partner — is named a Preferred Services Partner in Anthropic's Claude Partner Network, extending enterprise distribution into international markets
[13].
3
Days from public launch to export-control directive
19
Days the models stayed dark
>99%
Claimed block rate of the reported bypass, per Anthropic & CAISI testing
$30B+
Anthropic run-rate revenue by April 2026, up from $14B in February
Two Fights, Opposite Directions
The single most clarifying fact in this record is that the government pressured Anthropic in both directions within four months. In February, the Pentagon's demand was for fewer safeguards — unrestricted military use, with the specific sticking points being Anthropic's prohibitions on mass domestic surveillance and on autonomous weapons without human oversight[2]. In June, a different arm of the same government shut the model down for having safeguards that could be bypassed[9].
The February episode bears the structure of a loyalty test rather than a procurement dispute: the military already had Claude deployed on classified networks — Anthropic was the first frontier lab to put it there[3] — so the demand for a personally signed, unrestricted grant was about submission, not capability. The June episode, by contrast, ran through institutional machinery: a researcher-reported bypass, official channels, a technical review body, and a negotiated fix. Observers including Chatham House have characterized the government's overall posture as flip-flopping that serves neither security nor predictability[14] — and noted that OpenAI's newest models have come under parallel pressure, launching only to trusted partners[14].
"a label reserved for US adversaries, never before applied to an American company" — Dario Amodei, on the threatened supply-chain-risk designation, Feb 26, 2026
The War Running Underneath
The February confrontation reads differently once the operational context is restored. Claude was not a hypothetical military asset: it had been integrated into Palantir's Maven Smart System — the Pentagon's AI targeting platform, evolved from 2017's Project Maven — since late 2024, was the first AI system cleared for the government's most sensitive classification tier, and sat inside a July 2025 contract structure that paid up to $200 million each to Anthropic, OpenAI, Google, and xAI[19]. When Hegseth demanded unrestricted "all lawful uses" access on February 24, the strikes on Iran began four days later. The demand was not doctrine; it was pre-war logistics. Anthropic's refusal to permit fully autonomous strikes and mass domestic surveillance was, from the Pentagon's vantage, an obstruction sitting directly in an imminent operational timeline[2][18].
The incoherence that followed is documented at every step. The government designated Claude's maker a supply-chain risk while using Claude to prosecute the war — a contradiction it was forced to acknowledge in March, since models embedded in accredited classified workflows cannot be removed by decree[20]. The Pentagon's own CTO conceded the deeper problem: a single primary AI provider on classified networks had become an unacceptable dependency[22]. The succession was completed quietly and surfaced accidentally: sworn testimony in a June 15 environmental-lawsuit filing — arguing that power disruptions to xAI's data centers would threaten national security — confirmed Grok's operational role inside Maven[21]. The war continues on a different vendor's model. Inside the industry, the shift has not gone unresisted: more than 600 Google employees petitioned against supplying AI for classified military operations, echoing the 2018 revolt that pulled Google out of the original Project Maven[21].
A sourcing note in keeping with this article's discipline: the Grok testimony is sworn and on the court record — the strongest evidence tier in this story. The first-24-hours targeting figures are attributed to Washington Post reporting but reach this article through secondary defense press, and specific numbers vary across accounts. More sensational claims circulating about the campaign's later phases appear only in low-credibility sources and are excluded here.
The Iran campaign is also not where AI-assisted warfare began — it is where American frontier models entered it directly. In Gaza, the documented targeting systems were Israeli-built: "The Gospel," which recommends buildings and structures for strikes; "Lavender," which reportedly marked as many as 37,000 people with minimal human review; and "Where's Daddy?," which tracked listed individuals and signaled when they entered their family homes[23]. The documented American role there ran through the commercial layer rather than embedded targeting: the Israeli military purchased OpenAI's GPT-4 via Microsoft's Azure platform beginning August 2023[24], an AP investigation found military use of AI models through Azure surged nearly 200-fold after October 7 — processing mass-surveillance intelligence that was cross-checked with the in-house targeting systems[25] — and Microsoft, after first acknowledging the sales while denying evidence of harm, disabled services to a Unit 8200-linked unit in September 2025 over mass-surveillance findings[26]. Anthropic does not appear in that theater's documented record. The through-line is not any one company; it is that by 2026, commercial American AI — whether embedded in Maven or rented through Azure — had become load-bearing infrastructure for active military operations on multiple fronts, governed by each company's private terms of service rather than any public framework.
What the Settlement Bought — and What It Cost
The redeployment was not a return to the June 9 status quo. Per Anthropic's own announcement and contemporaneous reporting, the price of coming back online included: a new classifier trained in close collaboration with the government, targeted at the reported bypass; CAISI review of the safeguards before controls lifted; accepted government conditions that have not been itemized publicly; and a commitment to deeper ongoing collaboration with the US government on pre-release testing, information sharing, and research[11][12].
The user-facing cost is the friction this article opened with. Anthropic acknowledges the tightened filtering can flag benign requests — including routine coding and debugging — which then fall back to Opus 4.8[12]. The company describes an intentionally enlarged "safety margin": a classifier boundary set wide enough that some legitimate dual-use and even benign requests are blocked as the price of confidence against harmful ones[15]. The checks run on everything the model reads — memory, connector data, search results, files — so a block can be triggered by content the user never typed[1]. One industry analysis summarized the post-redeployment product bluntly: a frontier model wrapped in a policy router, whose operating envelope shrank after a government-triggered shutdown[16].
📋 What Is Documented vs. What Is Not
- Documented: The current Fable 5 classifiers were developed with government involvement and reviewed by a Commerce Department body before redeployment. This is stated in Anthropic's own materials and corroborated by wire reporting.
- Documented: Anthropic accepted government conditions as part of the redeployment. The existence of conditions is public; their content is not.
- Documented: The February pressure sought to remove safeguards against domestic surveillance; Anthropic refused and absorbed the loss of its federal business.
- Documented (under oath): The Pentagon's AI-assisted targeting program, initially powered by Claude, continued the Iran campaign on xAI's Grok — per sworn Pentagon testimony surfaced in a June 15 court filing.
- Not documented: The full terms of the June resolution, the scope of "deeper collaboration," and quantified false-positive rates for the current filters.
- Not supported by the record: Claims that the standoff was driven by motives beyond the stated security rationale — including theories about protecting officials from incriminating information. No public evidence connects the dispute to such a motive, and the documented February fight points the opposite way: the pressure was to expand the government's use of the tool, not to restrict what the tool could know.
The Personalist Question
What follows is analysis of the documented record, not additional documentation. A fair reading has to hold two registers at once. The February escalation carries personal signatures: an all-caps presidential directive, a demand for a signed instrument of submission, punishment calibrated to defiance rather than to any technical event. The June episode ran through institutions that behaved like institutions — reported vulnerability, technical review, negotiated remedy — even if the chosen remedy, a national-security export order against an American software product, was without precedent. The reversal of that order within three weeks, in a letter from the Commerce Secretary, is consistent with either register: institutional correction, or volatility at the top[14].
The test that separates the readings is forward-looking and falsifiable: personalist pressure predicts further reversals uncorrelated with technical events; institutional normalization predicts that mechanisms like the industry jailbreak-severity framework Anthropic is building with Amazon, Google, and Microsoft[11], and CAISI-style review, gradually make interventions boring and predictable. The next unprovoked reversal — or a sustained absence of one — is the data point.
The Business Backdrop
Every move above occurred against extraordinary commercial stakes. Anthropic's run-rate revenue rose from $14 billion in February to over $30 billion by April[5]; the company confidentially filed for an IPO after a funding round valuing it near $965 billion[17]; and roughly 80% of its business is enterprise, which Amodei describes as stable and predictable income[17]. A company that watched its entire US federal business evaporate by presidential order has an acute education in concentration risk. Seen in that light, the July 7 Fractal partnership — enterprise distribution through a model-agnostic Indian firm serving Fortune 500 clients[13] — is at minimum ordinary commercial expansion, and plausibly also a hedge: revenue that no single government's mood can switch off. Both readings can be true simultaneously; the record does not distinguish them.
The Takeaways
- The pauses are enforcement artifacts: The model-switching behavior users experience executes terms negotiated in the June settlement — policy running in the product's foreground.
- Government involvement is documented, not conjectural: The current classifiers were co-developed with government input and reviewed by a Commerce body; conditions were accepted whose content remains unpublished.
- The pressure ran both ways: The same government demanded fewer safeguards in February and imposed a shutdown over insufficient ones in June. Any theory of the episode has to explain both.
- The transparency gap is the legitimate grievance: Users are asked to accept opaque interventions on the strength of a help-center article. The burden of demonstrating trustworthiness sits with the company and the government, not with the user.
- The record constrains speculation: The documented fight was over who may point the tool at whom — surveillance power — not over hiding knowledge from the tool. The visible story is sufficient, and darker than most hidden ones proposed.
What Would Change This Picture
This account is provisional in the way all reporting on live events is. Specific disclosures would materially revise it: publication of the accepted conditions; quantified false-positive data; evidence of filter behavior diverging across subscription tiers; or a further reversal untethered to any technical trigger. Absent those, the honest summary is this: a frontier AI company held its most consequential safeguard against unprecedented state pressure, then traded a measure of product transparency and autonomy to keep its most capable model publicly available — and the users now living inside that trade were never shown its terms.
📡 How this story was surfaced
This piece grew out of a reader-driven inquiry into Fable 5's model-switching behavior, developed through iterative research against public sources: primary company and government statements, wire reporting, congressional research, and policy analysis. Disclosure: the draft was researched and written with Claude, an Anthropic model — the subject of this article. Sourcing is footnoted throughout so that claims can be verified independently of the tool that assembled them.
Sources
- Claude Help Center — Why Claude switched models in your conversation with Fable 5
- Center for American Progress — The Trump Administration Is Trying To Make an Example of Anthropic (Mar 4, 2026)
- Anthropic — Statement from Dario Amodei on discussions with the Department of War (Feb 26, 2026)
- Rep. Valerie Foushee — Statement on Pentagon pressure and safety rollbacks (Feb 26, 2026)
- Congressional Research Service — Federal Government and Anthropic (May 2026)
- Business Insider — Trump orders federal agencies to stop using Anthropic's technology (Feb 2026)
- MIT Technology Review — Three things to watch amid Anthropic's latest feud with the government (Jun 22, 2026)
- Let's Data Science — Anthropic Restores Fable 5 With Tightened Safeguards (Jul 2026, citing Reuters/Axios/CNBC)
- Anthropic redeploys Claude Fable 5 after a 19-day suspension (Jul 1, 2026)
- Christian Science Monitor — AI giant Anthropic and government face off again (Jun 18, 2026)
- Anthropic — Redeploying Claude Fable 5 (Jun 30, 2026)
- 9to5Google — Claude Fable 5 returns with tightened safeguards (Jul 1, 2026)
- Business Standard — Fractal selected as Preferred Services Partner in Claude Partner Network (Jul 7, 2026)
- Chatham House — The US government's latest U-turn on Anthropic's Mythos (Jul 2026)
- Anthropic — More details on Fable 5's cyber safeguards and our jailbreak framework (Jul 2026)
- Clanker Cloud News — Claude Fable 5 Is Back, But The Nerf Is The Product (Jul 2026)
- Fortune — Dario Amodei on culture, IPO filing, and enterprise revenue (Jun 2026)
- The Defense News — Pentagon Used Claude AI and Palantir Maven to Identify 1,000 Targets in Iran Strikes (Mar 5, 2026, citing Washington Post)
- WION — AI in warfare is here: Pentagon used Claude in Iran strikes (Mar 2026)
- eWeek — Grok AI Helped Direct 2,000 US Strikes in Iran, Pentagon Reveals (Jun 17, 2026)
- Times of Israel — Musk's Grok AI helped guide US strikes on Iran, legal briefing shows (Jun 17, 2026)
- OpenTools — Pentagon Tests OpenAI and Google AI to Replace Claude (May 2026, citing Bloomberg / Federal News Network)
- +972 Magazine / Local Call — 'Lavender': The AI machine directing Israel's bombing spree in Gaza (Yuval Abraham, Apr 2024)
- +972 Magazine / Local Call / The Guardian — Leaked documents expose deep ties between Israeli army and Microsoft (2025)
- Associated Press — Microsoft says it provided AI to Israeli military for war but denies use to harm people in Gaza (May 2025)
- Associated Press — Microsoft reduces Israel's access to cloud and AI products over reports of mass surveillance in Gaza (Sep 2025)
Continue the investigation
Kaleido Investigates — Hidden in plain sight.