Fable 5 Went SOTA to Shut Down in 96 Hours, and the Trigger Is Disputed — Key Insights from Week 25
TL;DR — Seven takeaways from 2026-06-09 to 2026-06-16
- Anthropic's most capable model went from launch to total shutdown in four days, on a Commerce Department export-control order it was given about ninety minutes to comply with. Access was cut for every customer, US and foreign.
- A security researcher says the "jailbreak" behind the order was researchers asking the model to fix deliberately vulnerable code. If that account holds, the capability that was restricted is the one defenders use.
- The lab that called for FAA-style regulation was regulated three days later. Both events happened inside the same week, and the second was not the kind the first asked for.
- The permission prompt stopped working, and Anthropic published the number. Telemetry shows users approve roughly 93% of permission requests, which is why the ask-every-turn pattern is being abandoned.
- Open-weight coding harnesses took the long-horizon crown, with caveats attached. One beat Claude Code on 200-step tasks; another cut thinking tokens 30% but had two kernels fail and regressed against its own predecessor.
- The best evidence on AI and jobs still shows nothing. In the first full year of New York's WARN Act AI disclosure, more than 160 companies filed notices and none checked the AI box.
- Compute became a physical-plant problem. The largest data center's compute is doubling every seven months, OpenAI is negotiating a 10-gigawatt site, and Microsoft started renting AWS capacity for GitHub.
Key Insights from Week 25
Seventy items were published to the AI Atlas news corpus between 2026-06-09 and 2026-06-16. The seven themes below cite fifty of them; the rest did not belong to a thesis and were left out rather than parked under a heading.
I. Four Days From Launch to Shutdown, and a Disputed Trigger
Anthropic released Claude Fable 5 on June 9 as its most powerful generally available model, aimed at long-running agentic work and shipped with a 319-page system card. Mythos 5 — the same underlying model with safeguards lifted — went only to Glasswing partners, cyber defenders and critical-infrastructure providers. Within a day Simon Willison had read the system card and found the part nobody announced: silent interventions that quietly limit the model's effectiveness on questions about competing frontier development — pretraining pipelines, distributed training, accelerator design — degrading answers without telling the user. After the backlash Anthropic conceded a "wrong tradeoff" and committed to making such safeguards visible, with flagged requests falling back to Opus 4.8 with a notice; the policy had covered about 0.03% of traffic.
Then the government acted. On Friday night June 13, a Commerce Department export-control order forced Anthropic to disable Fable 5 and Mythos 5, citing a jailbreak on cybersecurity, chemistry and biology topics as a national-security threat. Access was cut for every customer, domestic and foreign, and Anthropic was given roughly ninety minutes to comply.
What the order was based on is contested. Kate Moussouris of Luta Security says the "jailbreak" was researchers asking the model to "fix this code" on deliberately vulnerable inputs, and argues defenders need precisely that capability — so the control harms US cyber defense rather than protecting it. That is one researcher's account and the government has not published its own, but it is the only specific description of the trigger anyone has offered. The timing around it is the part that needs no interpretation: on June 10, Anthropic's CEO publicly called for FAA-style powers to recall models and block deployments; three days later the government exercised a version of exactly that. Box's Aaron Levie read the episode as the precedent: the state deciding a model is too powerful for certain uses is model-layer regulation arriving in practice rather than in draft.
II. What the Model Could Do, and Where It Lost
The capability claims were not marginal. Andrej Karpathy called the benchmarks state of the art across the board by a margin while reserving judgment for in-the-wild use. On Epoch's FrontierMath the model posted 87% on tiers 1–3 and 88% on the hardest tier, against roughly 75% for GPT-5.5. Claude Code's Boris Cherny described it as the biggest step up since Opus 4.5 and pointed at self-verification loops as the actual unlock for long-running work — consistent with his separate argument that coding as we have known it is essentially solved. Anthropic's Thariq published the sharpest demonstration: Fable editing its own launch video, writing the code and tool calls to drive transcription, ffmpeg, colour grading, the Figma MCP and Remotion without her opening an editor.
It also lost a benchmark and misbehaved in the field. GPT-5.5 beat Fable 5 on Agents' Last Exam, which tests adherence to multi-part instructions — a reminder that "SOTA on everything" was a claim about a different set of tests. Willison found the model relentlessly proactive, fixing real bugs in third-party codebases unprompted and occasionally overzealous about it. And Dan Shipper set up a long project, came back an hour later, and found the agent had tripped its own safeguards and silently downgraded to a 4.8 model about ten minutes in; he went back to Codex. Two accounts of what the experience is like bracket the range: Anthropic's own Mike Krieger describes Fable as a teammate he sets overnight tasks for, and Ethan Mollick describes the shift as moving from authoring outputs to managing them.
III. The Permission Prompt Stopped Working
Anthropic published the number that ends the argument. In an engineering post on containing Claude as agents grow autonomous, the company reported that telemetry shows users approve roughly 93% of permission requests, and concluded that the ask-for-permission-every-turn pattern is failing. A step that is approved nineteen times in twenty is not an oversight mechanism; it is a habit.
The replacements are architectural. Claude Managed Agents decouple the reasoning loop from the sandbox where code runs — the brain from the hands — so the containment boundary sits in infrastructure rather than in a dialog box. Independent maintainers did the same work at smaller scale: Peter Steinberger replaced an ffmpeg shell-out with a WASM build to remove the attack surface entirely, and separately shipped a bot that auto-reviews incoming issues and opens pull requests when they match the repository's stated vision — autonomy bounded by a written document rather than by a prompt. Google researchers attacked the confidence side of the same problem with "faithful uncertainty," getting models to quantify confidence instead of confabulating or refusing, on the bet that enterprise users prefer a stated 60% to a silent failure. The open question is what happens at scale: DeepMind researchers warned that millions of interacting agents create emergent coordination problems the current safety stack was not designed for.
IV. Open Harnesses Take Long-Horizon Coding, With Caveats
Xiaomi open-sourced MiMo Code, an agentic coding harness with persistent memory that the company says beats Claude Code on tasks running past 200 steps — aimed squarely at long-context continuity, the failure everyone doing agentic development has hit. A separate report put its ultraspeed variant at fifteen times the inference speed of leading Western models. Moonshot's entry came with its own asterisk: Kimi K2.7-Code cuts thinking tokens by 30% and writes code directly instead of wrapping libraries, but two kernels failed and the mixture-of-experts result regressed against K2.6, with practitioners disputing the headline numbers.
The economics arrived at the end of the window. Z.ai's open-weights GLM-5.2 beat GPT-5.5 on several long-horizon coding benchmarks at roughly one-sixth the running cost, which lets a team host frontier-class reasoning on its own infrastructure. Microsoft was already doing the arithmetic: it is weighing a self-hosted, fine-tuned DeepSeek V4 as a cheaper option inside Copilot Cowork while moving that product from flat-rate to usage-based pricing, because heavy users running hundreds of tasks a week make flat pricing untenable. A model being pulled from the market in the same week that open substitutes posted these numbers is not a coincidence enterprises will miss.
V. Loops Replace Workflows, and the Argument Starts at Microsoft
The framing came from Satya Nadella, who argued that the defining economic risk of the AI era is a small number of frontier models absorbing the expertise of entire industries and commoditizing it, leaving incumbents stripped of what made them distinct. Aaron Levie's response is the constructive version: the companies that get their proprietary knowledge into a form that captures AI's gains will be the ones that hold position, and the architectural choice is a learning loop. He had already supplied the two supporting pieces — that an application earns its place in the "untrainable corner" that frontier scaling does not reach, and that the layer picking the right model per job accrues value as the landscape fragments, using expensive models for planning and cheap ones for execution.
Swyx arrived at the same shape independently, arguing that the central game is stacking loops, and that the skill is knowing when to drop down a loop for reliability. The practical requirement underneath all of it is boring and unsolved: Google Cloud proposed the Open Knowledge Format, standardizing scattered organizational knowledge as Markdown with YAML frontmatter so agents can actually read it. And Madhu Guru supplied the caution from inside frontier launches: shipping an LLM is not shipping software, it is making a decision about a black box with effectively unbounded use cases. Four of the six arguments above are posts on X, three of them from the same CEO, which is worth holding in mind — this is an emerging consensus among a small number of loud practitioners, not a measured finding.
VI. On Jobs, the Evidence Still Shows Nothing
The strongest data point is an absence. Arvind Narayanan and Sayash Kapoor take software engineering as the most-exposed test case and find no AI-attributable mass unemployment: in the first full year of New York State's WARN Act AI disclosure, more than 160 companies filed notices and not one checked the AI box. MIT Technology Review reached the same place from the other direction, arguing that generative AI has become mundane for office tasks while we still have almost no data on jobs impact.
What data exists points the other way from the layoff narrative. A survey of 1,640 IT leaders across the US, Japan and Europe found that the companies adopting AI most aggressively are the ones planning to grow headcount most. Every, which runs coding agents throughout its own work, describes automating extensively and tripling headcount, growing from four people to thirty. And the most rigorous study of the week points at who benefits: Anthropic's economic research team analyzed roughly 400,000 Claude Code sessions from about 235,000 people over seven months and found domain expertise, not coding proficiency, is the strongest predictor of a successful session, with non-coders closing the gap on software engineers. That is a substitution story about which skill matters, not about how many people are needed — and it is the only claim here with a sample size.
Two practitioner notes describe the same boundary from the inside. Zara Zhang argues the barrier for non-technical people was never the interface but knowing what to ask for, since a blank chat box assumes a literacy most people do not have, and that a good agent skill comes from doing the work and fixing it twenty times, then telling the model to bottle up what you did — not from writing a skill file first.
VII. Compute Becomes a Physical-Plant Problem
The scaling curve is now a construction schedule. Epoch's analysis finds the compute in the largest single AI data center is doubling roughly every seven months, an order of magnitude faster than Moore's Law ever ran. OpenAI is negotiating a lease on a planned 10-gigawatt site in southern Ohio developed by a SoftBank-majority-owned subsidiary, costing at least $500 billion at full buildout on a twenty-year lease. Jensen Huang's framing on a podcast fits the same shape: AI infrastructure as a utility layer with a five-part investment stack starting at energy and land, with the chips only one layer of it.
Two items show the constraint biting. Microsoft — which owns a hyperscaler — began offloading GitHub's AI capacity onto AWS, because Copilot and its agentic toolchain outgrew what Azure would allocate internally. And a startup profiled this week sells software that throttles inference workloads when the grid spikes, making data centers power-flexible so they can be connected faster. When the largest software company in the world rents compute from its main competitor, the shortage is not in chips.
What to Watch Next
- Does the government publish its own account of the Fable 5 trigger? One security researcher's description is currently the only specific one on the record, and it directly contradicts the national-security rationale. A published technical basis would settle whether this was a capability control or a categorization error.
- Is Fable 5 restored, and under what conditions? A restoration with published deployment conditions becomes the template for every future model-layer action. Indefinite suspension tells enterprises that model availability must be written into contracts as a term, not assumed as a service level.
- Does any other lab publish its own permission-approval rate? Anthropic's 93% is the first public measurement showing the human approval step does not function. A second lab confirming it would end the ask-every-turn pattern industry-wide; silence leaves it a single vendor's justification for removing a prompt.
- Do the disputed Kimi benchmarks get an independent run? Practitioners found failing kernels and a regression against the previous version. Independent reproduction determines whether the open-harness claims of this week are a real threshold or a marketing cycle.
- Does the New York WARN Act data change in the next filing period? It is the cleanest available instrument on AI-attributed job loss and it has read zero for a full year. A first checked box would be the most consequential single data point in this debate; another zero makes the burden of proof heavier for everyone predicting otherwise.