Security Experts Urge White House to Reverse Ban on Anthropic’s Top Models

The message that triggered the whole affair was three words long: “Fix this code.” According to Fortune, that was the extent of the “jailbreak” that led the U.S. government to ban exports of Anthropic’s two most powerful AI models. On Monday, 76 cybersecurity experts signed an open letter urging the White House to reverse course.

The letter’s signatories include some of the most established names in security research, people who have spent careers finding flaws in software that runs hospitals, banks and power grids. They argue that the government’s national-security authorization was misapplied to what was, in their reading, a routine request: researchers asking the models to repair known vulnerabilities. Katie Moussouris, the prominent security researcher who founded Luta Security and helped build the bug-bounty programs that modern software companies depend on, said the researchers were doing exactly what the government says it wants done.

The distinction matters. A jailbreak, in the government’s telling, is an attempt to bypass an AI’s safety controls to make it do harmful things. What the researchers did, according to the letter and to Fortune’s reporting, was hand the models vulnerable code and ask for fixes. The request did not try to break the models’ safety rules; it tried to use their capabilities for defense. In the logic of the security industry, that is not an attack. It is a patch request.

The ban itself is sweeping, and that is what has the experts alarmed. A government directive dated June 12 bars any foreign national, inside or outside the United States, including Anthropic’s own non-U.S. employees, from accessing Fable 5 and Mythos 5, the two frontier models at the center of the dispute. Security researchers say the effect is to lock out precisely the people who find the flaws before attackers do, and to make the U.S. the only country that restricts its own best models while rivals sell freely abroad.

Anthropic has agreed to meet with the Trump administration to resolve the dispute, the company said, a step that suggests both sides want a way out. But the politics are complicated by Amazon. Andy Jassy, Amazon’s chief executive, has voiced safety concerns about frontier models to the government, according to people familiar with the matter, and Amazon is both one of Anthropic’s largest investors and, through its own models, one of its competitors. The overlap has made some researchers wonder whether the ban’s sharpest edge was aimed at a rival’s product.

The letter’s signatories are careful not to question the government’s authority to restrict exports; they question the judgment. Banning a model because someone asked it to fix code, they argue, sets a precedent that will chill the security research that the government itself relies on. If asking an AI to patch a vulnerability is treated as an attack, researchers will stop asking, and the vulnerabilities will go unfound.

There is also a commercial dimension. Anthropic sells access to its models to enterprises around the world, and an export ban on its two most capable systems hands international customers a reason to look at alternatives. OpenAI, Google and a growing field of open-source models stand to gain whatever Anthropic loses, and the experts argue that a policy meant to protect national security could end up ceding the frontier to foreign competitors instead.

The immediate test is the promised meeting. If the administration clarifies that the ban applies only to genuinely harmful uses, the letter’s signatories have said they would accept the outcome. If it holds the line on the basis of three words, the dispute is likely to widen, drawing in other labs that sell to the same customers and face the same exposure.

The letter lands in a broader fight over how the government treats AI as a national-security asset. Washington has spent years restricting the export of advanced chips and the tools used to make them, and extending that regime to the models themselves was the subject of debate in the administration long before the Anthropic order. The experts’ argument is that models are different from chips: they are software, they can be copied, and restricting them mainly pushes the market to open-source alternatives that no one controls. The model makers themselves have been reluctant to say so publicly, but several have privately told regulators the same thing, according to people familiar with the discussions.

The signatories have asked for three things: a published technical basis for the ban, a narrower definition of what counts as a jailbreak, and grandfathering for researchers who were working on legitimate vulnerability fixes when the order landed. Whether the administration grants any of it will be the first test of how seriously it takes the security community’s warnings about its own policy.

For the security industry, the episode has already had one effect: it has united a famously fractious community. The 76 signatures span companies, universities and independent researchers who rarely agree on anything else, and they have found common ground in a simple claim. Fixing code is not a crime, and treating it as one will make everyone less safe. The White House will now have to decide whether it agrees.

Related Posts

  • September 6, 2026
  • 10 views
Anthropic Moves Its IPO Filing to Late September

The bankers and lawyers running Anthropic’s initial public offering had told investors to expect the company’s registration documents as soon as this week. The calendar has moved. Anthropic now plans…

  • September 6, 2026
  • 11 views
OpenAI Quietly Revises GPT-6 Astra Scores After Launch

When OpenAI released GPT-6 Astra on Sept. 3, the launch post carried the usual furniture of a modern model debut: coding results, speed comparisons and a figure for how often…