Ban on Anthropic models sparks controversy among cybersecurity veterans
The US government's decision to ban the export of Anthropic's Fable and Mythos models is causing a stir in the cybersecurity world. A group of experts, including renowned veterans in the field, teamed up to criticize the measure. They published an open letter asking the government to reconsider the order, arguing that this ban deprives cybersecurity defenders of the best tools to identify vulnerabilities and protect systems. The letter highlights that at a time when adversaries are advancing rapidly, depriving defenders of these capabilities is dangerous.
Last Friday, Anthropic was instructed to limit the export of the models, based on national security concerns. However, the specific reasons behind this decision were not disclosed. As a result, the company suspended access to the models for all users worldwide. Among the 76 signatories of the letter are heavyweight names like Alex Stamos, former chief security officer at Facebook, and Casey Ellis, founder of Bugcrowd. Anthropic, when launching Mythos in April, stated the model was so effective at finding security flaws that it needed to be restricted to prevent malicious hackers from using it to cause havoc.
The controversy surrounding Mythos and Fable
Initially, Anthropic allowed around 50 companies to access Mythos, recently expanding to 150 organizations in 15 countries. Last week, the company launched Fable, a public version of Mythos, but with strict restrictions to prevent its use in biology, chemistry, and cybersecurity. These restrictions were so severe that many cybersecurity experts stated the model blocked virtually any prompt related to the field.
The government's decision may have been influenced by a report suggesting the possibility of bypassing Fable's restrictions to access its advanced capabilities. Katie Moussouris, one of the letter's signatories, reviewed a paper by Amazon researchers that allegedly demonstrated this technique. However, she states the paper did not show a real jailbreak. Instead, the researchers asked Fable to patch open-source code with known vulnerabilities, which the model initially refused to do.
Defending models as essential tools
Moussouris argues that the behavior described in the paper cannot be meaningfully fixed without weakening the model for defense. She highlights that defenders need AI to find and fix bugs, explain the significance of fixes, and test if they work. This is not a security breach, but rather a crucial function for defensive security. The open letter also mentions that the capabilities described in the paper can be replicated in other models, such as OpenAI's GPT-5.5 and Anthropic's own Claude 4.8 Opus.
The experts call for regulations to be created in a transparent and fair manner, based on scientific research and applied only to the extent necessary to ensure the safety of the American public. The discussion on the use and restriction of AI models in cybersecurity continues, raising questions about the balance between security and innovation. The US government's decision could have significant implications for the future of cybersecurity and AI development.





Comments (0)
Comments are moderated and if they violate our Terms and Conditions of use, the comment will be deleted. Persistence in violation will result in a ban of your account.