There’s a neat symmetry to this week. Anthropic launched Fable 5 on June 9 — its most capable model to date, positioned as a frontier-class system with expanded reasoning, tool use, and multi-step planning. Three days later, the US government ordered it offline. Fable 5 and its companion Mythos 5 were dark by the evening of June 12.

The mechanism was an export-control directive. The government’s concern: foreign nationals — including foreign Anthropic employees within the United States — could use the models to provide meaningful assistance with high-risk tasks. The apparent trigger was a post on X from a researcher who goes by Pliny the Liberator, claiming he had bypassed Fable 5’s safety systems within the model’s first 24 hours using a coordinated multi-agent technique he called a “pack hunt.” The method stacked five layers: Unicode substitution, long-context smuggling, fiction framing, document-structure framing, and request decomposition. The screenshots showed step-by-step exploitation guides for x86 Linux systems. Fable 5’s 120,000-character system prompt was also reportedly leaked on GitHub.

Anthropic called it a misunderstanding. The capabilities demonstrated, the company said, were already widely available from GPT-5.5 and other frontier models — the kind of thing defenders use every day to keep systems safe. Both claims can be simultaneously true: the jailbreak may be real and the government’s response disproportionate. What’s harder to argue is that it was precedent-free. No frontier model has ever been pulled by government directive this fast, this quietly, or with this little public explanation.

The summit begins today

Today Dario Amodei, Sam Altman, and Demis Hassabis are in France. The 52nd G7 summit opens in Évian-les-Bains, and for the first time all three major frontier labs are at the table. French President Macron personally invited Altman — his first G7 appearance. A working lunch Wednesday will focus on safe, rapid AI deployment.

The timing is hard to ignore. The same week the US government exercised what appears to be an actual kill switch on a deployed AI model, the world’s leading democracies are convening to draft the rules. Whether this reads as coordination or as the usual lag between events and policy, there is now a concrete data point for what government intervention in AI looks like in practice.

The recursive loop

There’s a stranger thread running through all of this. On June 4, Anthropic called for internationally verifiable mechanisms to pause frontier AI development — a different kind of kill switch, one labs would activate together rather than have imposed from outside. The argument wasn’t abstract. It came with a disclosure: more than 80% of the code now merged into Anthropic’s production codebase was written by Claude, not by human engineers. Engineers choose the work, review the changes, decide what ships — but the code is largely Claude’s. Output per engineer has multiplied eightfold since 2021. Co-founder Jack Clark told the BBC that 100% self-written code could arrive within two years.

The position Anthropic is occupying this week is a difficult one to hold: the company is arguing, with considerable evidence, that its AI is too capable to be left ungoverned — while also building the model the government just yanked for being too capable. There’s no clean resolution. That’s the actual situation.

The open-weight frontier

Meanwhile, the gap between what governments can control and what developers can download narrowed again. MiniMax’s M3, launched June 1, is the first open-weight model claiming frontier coding performance alongside a one-million-token context window and native multimodality. Vendor-reported numbers put it at 59.0% on SWE-Bench Pro, above GPT-5.5’s 58.6%. Open weights haven’t shipped yet and independent evals are still pending. But the direction is consistent: capability diffuses downward, and the gap that makes centralized control legible gets smaller every month.