
Kate Koren joins to discuss Trump administration's export controls on Fable and Mythos 5, and AI industry executives at the G7 Summit.
Loading summary
A
Foreign.
B
Welcome back to the AI Policy Podcast. I'm Alok Mehta, director of the Wadhwani AI Center.
A
And I'm Matt Mand, a researcher with the Center. Today we'll start with the Trump administration's decision to impose export controls on Anthropic's most advanced model, and wrap up by discussing how AI took center stage at the G7 summit. And for the first of those two topics, I'm excited to welcome our colleague Kate Coren, who co authored a recent article with Alok, unpacking the administration's decision. Kate is the deputy director for the Economics program here at CSIS and previously spent three years at the Bureau of Industry and Security, the agency within the Commerce Department that manages some of the government's export control programs and whose authority was used to limit access to Anthropic's best models. Kate, thanks so much for joining us.
C
Thanks so much for having me.
A
So on June 12, the Department of Commerce sent a letter to Anthropic informing it that a license would now be required for any foreign person to access Claude Fable 5 and Mythos 5, its two most advanced publicly available models at the time. Aluc, before we dive into the details of that policy, could you walk us through the events that caused the administration to take this action?
B
Yeah, so happy to do that. I'll try to cover the highlights, but a lot happened in the space of just a few days, and details are still emerging. So this is, I think, a partial picture of what happened, and we'll just have to see how things continue to develop. So this all starts back with Mythos, which is a really powerful model that Anthropic developed and released in a limited form sometime around April. It excels at sort of cyber capabilities finding and detecting vulnerabilities, and also detecting sort of ways to chain those vulnerabilities together to penetrate various IT systems. And so their initial decision was that they would release that model only to a set of trusted partners. And so they had a very limited release. It wasn't available publicly. They had something called Project Glasswing that they used to facilitate access to those trusted partners. And then they also, during that time, sort of started figuring out how they could make a version of this model available to the public by developing various guardrails related to its cyber capabilities. I think the intent was always to release a version of this model publicly because it is very powerful, and that's the business model of the the company. But they wanted to take the time to implement a variety of guardrails related to those Cyber capabilities. And those cyber capabilities, by the way, there was a lot of clamor, both from companies and government, to get access to them. And we've seen some testing from places like the UK Security Institute that validated that, indeed, the model is very power powerful and had advanced capabilities in detecting vulnerabilities that we'd never seen in a model of this type before. And so, you know, that was several months ago. And finally, on June 9th, Anthropic finally released a public version of a Mythos class model. They called it Fable 5. And when they released it, they said that this is their very best model, state of the art, you know, excels on a number of benchmarks of AI capability and cited its use in things like software engineering knowledge work and scientific research. And they also released sort of a improved version of mythos called mythos 5. Similar underlying model, but with different kinds of safeguards, particularly lighter safeguards, so that it could be used by government and corporate clients to do some of their cybersecurity work. What we know or what we think happened, based on the copious amounts of reporting that we've seen, is that on Thursday, June 11, so this is two days after the model's public release, the CEO of Amazon, Andy Jassy, raised concern to the White House about the ability for Fable 5, about the ability to bypass some of the guardrails that were in place on Fable 5. And so they flagged this to the White House, and this really raised the administration's attention. In particular, they developed a sort of method of getting around these safeguards, known as a jailbreak. And so this is the ability to use sort of a set of specific prompts that allow you to basically bypass the guardrails that were put in place and get information about cybersecurity vulnerabilities that Anthropic did not intend. And then what we understand happened after that is that the White House had a conversation with Anthropic, in particular with the CEO of Anthropic, Dario Amadei, and that during those calls, there was a discussion about how to proceed from this path forward. Our understanding is that those conversations were pretty contentious, that the administration pushed for Anthropic to voluntarily pull back the model so that they could improve their guardrails. And that Anthropic sort of pushed back and said that these are a very specific type of jailbreak, and it's not something that poses the. The kind of risk you would see with a broader jailbreaking capability. And so that kind of action wasn't Warranted. And then shortly thereafter, what we saw is that the Trump administration imposed its export controls, citing some national security authorities and saying that Fable 5 couldn't be used by foreign nationals, supposedly as a last resort, because they were hoping that they could work it out in these conversations with Anthropic. And so that's the status that they issued this proclamation in response, Anthropic, due to difficulties implementing that provision, including the fact that they employ foreign nationals. And so under this directive, their employees couldn't. Those types of employees couldn't use their model. They pulled down the model completely, and public access to the model is still restricted.
A
Great. Yeah. So now that we have all that context, I want to turn to you, Kate. Could you walk us through exactly how these export controls work? What do they do precisely, and what authorities do they rely upon?
C
Sure. So, contextually, I think it's probably best to start with why this is so sort of novel and new and why this is still there's a lot of uncertainty about these controls. So previously, and sort of the standing sort of understanding of the regulations and how they would apply to AI models, you know, before this event, was that accessing a model wouldn't be considered an export, you know, subject to the ear, the Export Administration regulations. Those are. Everything is very clearly defined in the ear. And an export is defined and an export for, you know, software is defined as actually releasing that software. So if you were releasing, you know, the model itself, the model weights, or your source code, object code, those are clearly exports and there could be subject to export regulations. But a user accessing the model is not or was not. That falls into a category called remote access, which covers additional types of transactions as well, which, based on past advisory opinions that the Bureau of Security has published, it is determined are not subject to its authorities based on the current ear. So what Commerce did in this letter, which is known as an IS informed letter, it's informing, in this case, Anthropic, but one particular company or, you know, person that a license is required. It cited, you know, these authorities that have been there, but that were previously interpreted kind of to mean something else. So Commerce's authority, well, BIS's authority for the stems from ECRA, the Export Control Reform act of 2018. That's the statutory authority. And the letter actually cites a provision in ECRA that has not been implemented in the Earth. I'm not a lawyer, I know this is very weedy and lawyer esque, but basically, the statute, the ECRA is very broad, high level, sort of giving the authority and then that gets implemented in the ear in very detailed drawn out things that put parameters and those are federal rules that go through the rulemaking process, go through intergency review, get lots of feedback. All to say the particular part of ECHRA that was cited in this is informed letter has not been encoded in the ear. So therefore has not been used before in this way. Generally the interpretation is until you put it into the ear, can't use it. They did they cited in the letters the authority to do this under the emerging technology authority. So that's. And parts of that have been enshrined in the ear, just not this particular part. So that there's a part NECRA that says directs really BIS to impose controls emerging technology. And there's a specific line in there about using the is informed mechanism. It's that specific aspect using the is informed mechanism to say this new emerging technology, you know, you particular one company, not everybody, but you are informed. There's a license requirement. That was the first authority they cited. And as I kind of worked through there, it's a little murky generally. That was not understood to be, you know, something you could do. The second part they cited is section 744.22. I want to say I make sure I got it letter has now been fully published by Bloomberg copy of it. So we do have that now. But that is a part that allows commerce to control items that have a risk of military intelligence end use. The issue there is. Well, there's two issues. Military intelligence, end user, end user. The first part is that only applies to an export subject to the ar. So as we discussed, it's still a little murky the ability to say this is. And the second part is that particular authority to do is informed control that only goes to one company or one user under 744.22 for military intelligence. That is not supposed to be a worldwide is informed letter. It's restricted to certain adversarial countries. And the reason for that is, you know, there's a lot of kind of, you know, its own type of guardrails in the ear to avoid unnecessary harms for industry. And because these informed letters only apply to one company, you want to be pretty careful about how they're used and the scope of them. So it is unusual, to say the least that it was used in this way to put this worldwide control. Let's see there's anything else in the letter. Those are the two statutes in the letter. And then it goes on to define about access to the models it actually cites these kind of definitions in the ear about this act, saying this makes it subject to the, er. But those are the exact same parts of the ear that were in those previous advisory opinions, basically saying that remote access is not an export in the earth. Very messy.
A
Got it. Yeah. So you're describing a sort of. You described it as unusual, I guess unprecedented is also probably a good way to describe this, Right?
C
Yes.
A
And so Anthropic received this letter. They're being the subject of unprecedented legal action by this administration. What options did they have when they received this letter, and which does it look like they're pursuing now?
C
Yeah, so they had a couple options, the first being to, you know, I guess protest it. You know, they could. And they still could, you know, they could choose to, you know, take this up, you know, in the court system and say that, you know, this is not out, it's out of scope.
A
Yeah. They can add to their already increasing volume of legal problems with the administration.
C
Yes, I, I would expect the first thing they did is try to, you know, make sense of it and understand the letter and make sure they were interpreted correctly. And, you know, from what it sounds like from reporting, you know, media reporting about how these meetings went, you know, they basically were told like, yes, this means you need to cut off access. That was the intent. You know, when I first saw this and heard this, I first thought was, there's no way to comply with this, which means they're going to have to take it down. It's like, okay, that was the intent. They could technically try to comply with it. That is still an option open to them. They could try to work within this framework, but it would be extremely difficult one. It would mean they would need to do basically really in depth, know your customer on any account that was, you know, provisioned to have access to fable with a citizenship, you know, know your customer baked into there. That's not impossible, of course, but it's difficult and you could be limited only to US citizens. The more difficult part that would be the real deal breaker here, is their own foreign national employees. For them, they would need a deemed access license from BIS for everyone who had access to this. And that just seems pretty much impossible to attain for them, certainly in a timely fashion and not in a workable way. So the third option, and what it seems that they are doing, what they're going with here, is working with the government on resolving the concerns to get to a place where the government revokes this requirement, you know, is informed licenses, because they license Requirements as informed letters, because they are done by this one to one letter, they can be rescinded in the same way. So it doesn't go through the rulemaking process, doesn't need to get published anywhere. So yeah, I'm sure they're, they're anxiously hoping, they're getting quickly to the point where they're going to get a letter saying that this is now revoked.
A
Yeah. And I think I saw a separate letter, this time to the Commerce Department, not from it, coming from a bipartisan group of representatives that expressed concerns about the approach that the administration has taken here, potentially the singling out of Anthropic and not other AI companies. So it'll be interesting to see as well how other parts of the government weigh in on this debate.
C
Absolutely.
A
But I want to finish up this section by zooming out a little bit and talking about what it means for the broader conversations in AI policy. So for example, I've been seeing a lot of talk about how this impacts frontier innovation, what it means for AI sovereignty for other nations now that they don't have access to the most advanced AI models coming out of the US So could you both just talk a little bit about what you see as the most important implications of the administration's actions here? And although maybe you can start.
B
Yeah, I think there are lots of interesting and far reaching implications from this decision. I'll start with this idea. We often hear this idea that in the US AI is not regulated. What this shows is that there are lots of tools that the government can't use to regulate AI. And the problem here is that this is a untested, unprecedented use of a tool. And so none of the processes that we have put in place to sort of provide our regularity and assurances about how these tools will be applied to companies are in place. And so this creates a lot of uncertainty. On top of that, you know, the type of jailbreaking exploit that we're talking about that Amazon flagged, it is an inherent flaw that we see in all existing models. Certainly the models have gotten better at sort of resisting these kinds of attempts over time, but it is still inherent to this type of technology. And so if the thought is that this is specific to Anthropic, which has had a strained relationship with the administration for a while, that's not the case. Right. And I think all other AI companies are going to be thinking about how this could be applied to them in the case of something similar being found in one of their systems. And it's almost certain that these Kinds of exploits to some extent can be found in all of their systems. I think the second thing is that one of our long term goals in the US is to spread US AI technology all around the world. And this is harming that goal. This is the most powerful model that US companies have developed and right now other countries can access them and so they will be thinking about where they can get the capabilities that they're looking for. And this applies to all of our allied countries, all the countries we want to build deep partnerships with, including in part to, you know, support our access to key components of the AI supply chain. And then the third thing I'll mention is that is related to that, which is now this is. We've already seen moves by other countries to sort of, you know, concerns about over reliance on American technology. And now we're in a situation where I think it is even harder for them to think about making investments in U.S. technology. Right. Like developing the infrastructure you need around the AI model to make it work well for you. If there's a concern that'll be arbitrarily pulled and some of those investments will be stranded. And so I think this feeds into the narrative we've seen of other countries of sort of divesting away from American technology, thinking about alternatives, thinking about their sovereignty.
A
Nice. Kate, over to you.
C
Yeah, I'll start with, I think one main takeaway very much echoes aloks with really what this means for all other companies and the rest of the industry of just sort of that the ground has shifted under their feet. These sort of established ideas of what wasn't subject to export controls. It's all unstable now. And where this goes from here, it'll be really interesting to see. Unless or until this is challenged by someone, you have to assume that it's, this is now the standing interpretation and it can and will be used again. There's something called the Remote Access Security act, which has been waiting for houseboat for a while now that would sort of fix this issue in the ear. It would amend ECHRA and specifically give BIS the ability to regulate Interesting. Remote access. Yeah. And it's, I think it's, you know, it's a really important kind of common sense measure of adding to the toolkit. And that would resolve some, but not all of these issues because it would still leave open issues about the ability to use this as informed mechanism and others. But I'm kind of hopeful that this will accelerate that and some other more sort of formalized, regularized processes to give some stability to the regulatory picture here. So I think that's really helpful for. It's helpful for everybody. Right. It's helpful for the government and it's helpful for industry too. Have a well thought through, understand and solid regulatory system that everyone understands and can follow and knows what's happening there, what's going on. The other issue, again, just echoing a look here about this, just driving the push for sovereign AI. We've already seen some reactions to that in media, but it just makes sense. And I think those go together where if the US can kind of get its house in order, but here on the regulatory side, make that more public and coherent and understandable and solid, that can help ease some of those concerns.
A
Yeah, well, we'll be watching to see how things develop over the coming weeks and months in this situation. But Kate, thank you so much for joining us. It was great having you on the podcast and you really appreciate your expertise. I know Alok and I were not looking forward to having to explain what's going on in these laws ourselves, and I think we would have done a much worse job. So thanks again.
C
Thanks so much for having me.
A
Great. Well, look, let's move on and talk about our next topic, which is last week's G7 summit. This is actually related to what Kate was just talking about and you were just talking about for AI sovereignty. Because at the G7 summit, AI really dominated the agenda. And in an unprecedented move that the heads of major AI companies literally joined the world leaders at the table at the G7 summit. So you can see photos where Sam Altman and Demis Hassabis are flanking President Trump and Dario Amadei and Marc Benioff are sitting next to President Macron. What do you make, first of all, of AI CEOs having a physical seat at the table with heads of state at the G7 summit?
B
I think in a lot of ways this is a bad look. Um, and it's a bad look from the perspective of, you know, we've seen increasing concerns that started well before sort of the modern AI era that was started with ChatGPT about the level of concentration in tech markets and the amount of power that technology companies have over people's lives and the amount of wealth that's been concentrated to a handful of people in the technology industry. And treating the heads of these companies like they are elected representatives of nation states, I think just feeds into this narrative in really problematic ways. I think in problematic ways that even executives at these companies might acknowledge. And so I think we should really think hard about whether we want to send the message that, you know, these kinds of AI CEOs are going to have influence over the development of society in the same way as world leaders who have had to campaign and convince people that they should be in that kind of position.
A
Yeah, I feel like it's a clear symbol of how power is distributed in AI policymaking right now. And another relevant point here is that what we were just talking about, the Trump administration's AI export restrictions, were on the mind of everyone who is attending this G7 summit. What do we know about how any conversations related to the export controls and their impact on our allies, what those conversations included at the summit?
B
Yeah, I mean, I think, you know, it was a closed door summit and so we don't know exactly what was talked about, but I think that we have indications and I would expect that the leaders there would talk about, even if there's no public access to anthropics models, how they can get access to those capabilities. Because for the same reason that the US Government is interested in having access these models, it wants to be able to shore up its defenses, detect vulnerabilities, and patch them before bad actors have the ability to leverage AI tools to hack these systems. Every other country around the world, including the people at the G7 table and other US allies, will want to have that kind of access as well. And so figuring out, even in the case where we're restricting public access to these models, can we figure out how to provide access to a trusted set of governments and a trusted set of companies and institutions situated within those countries so that they can do this kind of testing? Because I think it's important to remember that it's undisputedly true that Chinese models are less powerful than the most powerful American models. But that gap is somewhere between six and 12 months. And so this is the window we have to act. Within six or nine months, there will be models made by Chinese developers, a lot of which are available to freely download and use on your own infrastructure, that will have probably similar capabilities to all these capabilities that are raising so many concerns around Mythos and Fable. And so this is the window we have to sort of figure out how to take action in this space.
A
Yeah, I think in the words of Demis Hasidis, according to reporting, he said at this meeting, we are, quote, in the foothills of the Singularity, end quote. So, I mean, that's the sort of language we've heard AI CEOs use for some time. But at the very least, it points to the fact that this is the moment to get it right. Yeah. Anything else?
B
Yeah. I think one other thing we should see is that this situation with Mythos I think is driving more interest at the global level, at the multilateral level, around more seriously considering whether we need a global governance approach to AI. We saw some thawing in US China relations around this issue. So AI came up in the summit that the US and China had recently. There wasn't a lot of substantive discussion there, but there was an agreement to have that substantive discussion soon, later this year at a follow up summit. And so I think these are positive signs that maybe we're re entering an era where we can have sort of more multilateral discussions about what it might mean to set guardrails around AI in a way that allows competition in providing services and allows the creation of sort of robust AI industries, but also puts in place certain protections both on the national security side and on making sure that AI works to make society better.
A
Yeah. And I do recall at the UN Global Dialogue on AI Governance back in 2025, OSCP director Michael Kratio said something along the lines of, you know, the US is opposed to any global governance regime, if memory serves you, says something along those lines. I might not be getting that exactly right. But do you think that the models that have come out in the months since and the risks that they seem to pose may have changed how the Trump administration will approach global governance?
B
I mean, all signs seem to indicate that they're taking this issue more seriously, that they've been spooked in ways that I think would not have been true six months ago or nine months ago or at the start of the administration, and that this is softening their stance. I think you're not going to see a 180 shift where they move from a sort of deregulatory model to something like the EU approach. But I think there's an increasing recognition that maybe there is some very light framework that we can implement on a global or multilateral level that can set some base expectations for this technology that would help protect the world and help protect society, but not necessarily stifle competition. And I think the hard work will be finding exactly where that line is, what we can agree to that is light enough to work for places like the US but also robust enough to provide assurances to some other countries who are concerned and to lots of people around the world who are concerned about what powerful AI technologies, how, how they might impact the world, how might they impact the labor market, how to shape that technology to do more, provide more benefit than harm.
A
Yeah. Well, I think that's a good note to end today's podcast on. Thanks to our audience as always for tuning in and thank you a look for joining me.
B
Thanks. Thanks for listening to this episode of the AI Policy Podcast. If you like what you heard, there's an easy way for you to help us. Please give us a five star review on your favorite podcast platform. Subscribe and tell your friends. It really helps when you spread the word. This podcast was produced by Sarah Baker and Matt Mand. See you next time.
White House Imposes Export Controls on Anthropic's Fable and Tech CEOs Join Heads of State at G7 Summit
Center for Strategic and International Studies (CSIS) – June 25, 2026
This episode of the AI Policy Podcast, hosted by Aalok Mehta (Director, Wadhwani AI Center at CSIS) and Matt Mand (CSIS researcher), takes a deep dive into two urgent developments in AI policy:
Aalok and Matt are joined by Kate Coren, Deputy Director for Economics at CSIS and former Bureau of Industry and Security (BIS) official, to unpack these fast-moving events and their national and international implications.
Context
Chain of Events
“The administration pushed for Anthropic to voluntarily pull back the model… Anthropic sort of pushed back… and then shortly thereafter, the Trump administration imposed its export controls, citing some national security authorities… as a last resort.”
—Aalok Mehta, 06:10
Kate Coren Dissects the Legal Mechanics
“Previously… accessing a model wouldn’t be considered an export… What Commerce did in this letter… cited these authorities that have been there, but that were previously interpreted kind of to mean something else.”
—Kate Coren, 07:14
Options for Anthropic
“When I first saw this and heard this, my first thought was, there’s no way to comply with this, which means they’re going to have to take it down.”
—Kate Coren, 13:19
Political Fallout
Regulatory Uncertainty
—Kate Coren, 19:11
AI Sovereignty & Global Partnerships
“One of our long-term goals in the US is to spread US AI technology around the world… this is harming that goal… countries can’t access them and so they will be thinking about where they can get the capabilities they’re looking for.”
—Aalok Mehta, 18:00
Need for Regulatory Clarity
AI Leaders Join Heads of State
“Treating the heads of these companies like they are elected representatives of nation states, I think just feeds into this narrative in really problematic ways.”
—Aalok Mehta, 22:23
Export Controls & Allied Tensions
“Even if there’s no public access to Anthropic’s models, [allies want to know] how can they get access to those capabilities? …this is the window we have to act.”
—Aalok Mehta, 24:08
Global AI Governance Momentum
“All signs seem to indicate that [the administration is] taking this issue more seriously, that they've been spooked in ways… this is softening their stance… maybe there is some very light framework we can implement on a global or multilateral level…”
—Aalok Mehta, 28:10
Memorable Quote
—Demis Hassabis, at the G7 summit (as cited by Aalok Mehta, 26:03)
For listeners who missed the episode, this summary maps the landscape of AI regulation in 2026: uncertain, high-stakes, and increasingly intertwined with national and international governance.