Locked Out by Passport: Frontier Model Access Can Depend on Who Is at the Keyboard
This week a second Commerce Department letter restored Mythos 5 to more than 100 named US organisations while Fable 5 stayed dark for everyone and all non-US organisations stayed locked out. What the legal basis actually is, what Europe can still run, and what nationality-gated access adds to an EU risk register.
This week a second letter from the US Commerce Department put Claude Mythos 5 back in the hands of more than a hundred named American organisations. Claude Fable 5 stayed off for every customer on earth, and every organisation outside the United States stayed locked out of both. Ten days earlier Anthropic had switched both models off for everyone, because it had no way to check the nationality of the person behind an API key. This week turned an outage into a question about who you are.
This follows The 72-hour model from 18 June. Everything below is sourced. Where we rely on someone else's reading of a document we have not seen ourselves, we say so.
Two letters and a lawsuit
The starting point is Friday 12 June. Anthropic received a Commerce Department directive at 5:21pm ET ordering it to "suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States", a group that included "foreign national Anthropic employees". It disabled both models for all customers the same evening. Trade-press reporting on the court filing says the company was given 90 minutes.
On Tuesday 23 June the first legal challenge arrived, and it did not come from Anthropic. Legion LegalTech, a US maker of drafting and case-management software for lawyers, asked the U.S. District Court for the District of Columbia to vacate the directive. The defendants were the President, Commerce Secretary Howard Lutnick and BIS Under Secretary Jeffrey Kessler. Legion's standing rests on a detail any European engineering lead will recognise: its developers include "Canadian nationals working remotely from Canada". No ruling has been reported.
On Friday 26 June, Lutnick wrote to Anthropic's Tom Brown: "I have determined that appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model." TechCrunch reported more than 100 specific US government agencies and companies on the list, with their non-American employees and Anthropic's own non-American staff covered. The letter did not mention Fable 5. Anthropic said it was "continuing to work with the government to expand access to Mythos 5 and make Fable 5 available for general use again". European organisations are still outside the arrangement.
The bottom lane of that chart matters as much as the top two. Anthropic's 12 June statement said "Access to all other Anthropic models will not be affected", and that has held. Opus 4.8, Sonnet 4.6 and Haiku 4.5 have kept answering for EU customers on the Claude API, on claude.ai, and through Amazon Bedrock, Google Cloud and Microsoft Foundry, from the first hour. What Europe has lost is the newest tier, not its access to Claude.
The legal basis, read from the outside
A caveat first. We have not read the Lutnick letter. Bloomberg published it on 16 June behind a paywall, and what follows rests on two secondary readings: the CSIS analysis by Kate Koren, Kevin Kurland and Aalok Mehta from the same day, and Export Compliance Daily's account of the Legion complaint. They agree on the mechanism and differ in the details.
- CSIS, 16 JuneThe letter invokes the Export Control Reform Act and the Export Administration Regulations: §734.13, which defines what counts as an export, and §744.22, the military-intelligence end-use control, applied through an "is informed" letter from the Bureau of Industry and Security. CSIS notes that this route has "never been used before as the basis for issuing a control" of this kind.
- The Legion complaint, as reported 25 JuneCites ECCN 4E091, a classification from the earlier AI Diffusion Rule that BIS said in May 2025 it would not enforce, plus 50 U.S.C. §4817 and 15 CFR 744.22(b). Legion argues the order exceeds the statute, turns a targeted military-intelligence authority into a blanket worldwide ban, is arbitrary under the Administrative Procedure Act, and is selective, because GPT-5.5 was left alone.
- The 2 June Executive Order"Promoting Advanced Artificial Intelligence Innovation and Security" contains no export-control provision and nothing on foreign access. Sec. 2(d) sets up a vulnerability clearinghouse under Treasury. Sec. 3 creates a voluntary framework under which a developer may give government up to 30 days of pre-release access.
So the order that had people worried at the start of June is not the instrument that was used. Its Sec. 3(c) says the opposite of what happened: "Nothing in this section shall be construed to authorize the creation of a mandatory governmental licensing, preclearance, or permitting requirement for the development, publication, release, or distribution of new AI models." Ten days after that sentence was signed, a letter under a different statute had the practical effect of a licence requirement for one company's two newest models.
CSIS listed three ways out for Anthropic: negotiate a retraction, which it called "most likely"; challenge the action in court; or verify identities and apply for deemed-export licences for users and staff. The third option is worth a moment. It describes what selective compliance would have required, and no API provider is built to do it.
What Europe said
The political reaction this week came from capitals and parties, not from the Commission. France's minister delegate for Europe, Benjamin Haddad, said "Europe cannot settle for being an open market dependent on technologies designed, funded, and controlled elsewhere." Volt Europa published a statement on 24 June calling for a faster Cloud and AI Development Act and uniform enforcement of the AI Act.
The most concrete move came on Sunday 28 June. Austria's State Secretary for Digitalisation, Alexander Pröll, wrote to Commission Executive Vice-President Henna Virkkunen: "Let us jointly explore the strategic establishment and participation of Anthropic within the European Union. With legal certainty, market access, capital and a set of values that suits this company." He added: "If we want to act, we must act now." There is a tension in it. Hosting an American lab puts guaranteed access ahead of the home-grown-champion strategy built around companies such as Mistral. Virkkunen's office has not answered publicly, and we found no Commission position this week.
There was a dissenting voice too. MEP Aura Salla argued that "Europe is better off without these models", on cybersecurity grounds.
Here is the counter-argument to our own alarm, and it deserves its weight. The practical damage in the EU is narrow. Two models are off. Everything a European production system was running a month ago is still up, at the same prices, on the same endpoints. If the lesson were only "you lose the top tier for a couple of weeks", most risk committees would shrug. The lesson is the mechanism. The control was keyed to the person and not to the place, so an EU Bedrock region, an EU data-residency clause or a Frankfurt data centre would have changed nothing.
Since 26 June the same underlying model has been running for a government-approved list and switched off for everyone else. Availability now has a third answer besides yes and no.
Our read
Access to a frontier model can be made conditional on the passport of the person at the keyboard, by letter, within days, and then made conditional on a named list. It happened once, and a second letter partly undid it, both times without a rule, a consultation or a notice to customers. We would put nationality-gated access into an EU buyer's risk register as its own line, next to outage, price change and deprecation, with its own owner.
The mitigation is a routing policy with a tested second route. Switching vendor does not do it. Moving from one American lab to another keeps you under the same statute, and Legion's own complaint makes the point that GPT-5.5 was simply not chosen this time. A second route means a named model for each task class, already run through your own eval set, wired in behind the same contract, so that the day a model ID starts returning errors is a logged configuration change. For the prompts that cannot leave the building, a model under Apache-2.0 or MIT on hardware you control is the one route a letter to a vendor cannot reach.
One honest limit on that last sentence. ECCN 4E091 was written with model weights in mind, and we do not know whether the same legal theory could be pointed at weight distribution. Nobody has tried. We flag it as open and would not build a guarantee on it.
Two smaller things are worth doing this quarter. Read what your master agreement says about government-ordered suspension: notice, service credits, termination rights. And when a vendor says a model is available, ask to whom.
This is the kind of work Sebrona does for EU teams: a written routing policy, a second route that has passed your evals before you need it, and a log that shows which model answered each call. If that is a gap in your stack, write to info@sebrona.com.
Reading
Where the dates, quotes and legal citations in this post come from. We cite so you can check us, and we mark what we read second-hand.
- Anthropic, statement on the directiveWording of the directive, the 5:21pm ET receipt, the all-customer shutdown, "Access to all other Anthropic models will not be affected", and the "previously known, minor vulnerabilities" description.
- Executive Order, "Promoting Advanced Artificial Intelligence Innovation and Security"Sec. 2(d), Sec. 3 and the Sec. 3(c) sentence quoted above; the absence of any export-control provision.
- CSIS analysisECRA and EAR basis, §734.13 and §744.22, the "is informed" mechanism, and Anthropic's three options.
- Export Compliance Daily on the Legion suitPlaintiff, court, defendants, filing date, the claims, ECCN 4E091, 50 U.S.C. §4817, 15 CFR 744.22(b), the Canadian developers and the 90-minute window.
- TechCrunch on the second letterLutnick's sentence to Tom Brown, the more-than-100 organisations, coverage of non-American staff, and Fable 5's absence from the letter.
- European reactionHaddad's quote (Euronews, 27 Jun); Volt Europa's statement (24 Jun); Pröll's letter to Virkkunen (28 Jun); Aura Salla's dissent (AI Frontiers).
- Not read directlyThe Lutnick letters themselves. Bloomberg published the first on 16 June behind a paywall. The Legion case number and any ruling: not found.