There you have it! The U.S. government forced Anthropic to pull its cyber model offline for the e…
June 25, 2026 · 0 likes · 0 comments
Cybersecurity AI
There you have it! The U.S. government forced Anthropic to pull its cyber model offline for the entire planet, and three weeks later OpenAI shipped a STRONGER one with zero restrictions. Same capability, same dual-use risk, opposite treatment, and nobody is explaining why.
Let me lay out what actually happened, because the timeline is the whole story.
In June, Washington hit Anthropic with an export-control directive. Suspend access to Mythos 5 and Fable 5 for every foreign national on earth, including Anthropic's own employees. Anthropic couldn't comply halfway, so they took both models offline for all customers. Gone. The trigger? Amazon researchers had slipped past Fable 5's anti-hacking guardrails, and White House advisers decided a model that finds vulnerabilities at scale was a national security risk. Lawsuit followed. Lawmakers are still demanding the rationale. Cyber leaders are begging the government to lift the curbs because the restrictions hurt the defenders, not the attackers.
Now look at OpenAI.
This week they launched GPT-5.5-Cyber under the Daybreak program. Read a whole codebase, find the holes, prove them in a sandbox, write the patch. Their own benchmark: 85.6% on CyberGym, beating the exact Anthropic model the government just banned. OpenAI says it outperforms Mythos. The more dangerous tool, by their own numbers.
And the export control? There isn't one.
OpenAI gets to run its own "Trusted Access for Cyber" program. They verify the defenders. They scope the controls. They decide who holds the key to the world's vulnerability surface. The company grades its own homework, and Washington nods along.
So which is it?
If a model that finds and patches bugs at scale is a national security threat that has to be ripped offline globally, then the more capable model is a bigger threat. Same logic. Same risk. If it's NOT a threat and these are defensive tools we want in the field, then Anthropic got crushed for nothing and owed an apology.
You cannot have both. Pick a standard and apply it to everyone.
I spent years building the security layer that sits on top of these models, the controls that decide what an AI is allowed to touch. I'll tell you what selective enforcement actually produces: it doesn't make anyone safer. It just picks winners. One company gets forced offline and sued into a corner. Another ships the stronger weapon and writes its own rules. That's not a safety policy. That's a referee who keeps changing the call depending on the jersey.
The defenders need these tools. The attackers already have them. Fine. Then build one rulebook and hold every lab to it, in public, with oversight nobody owns privately.
Until someone answers why the weaker model got banned and the stronger one didn't, this isn't about security at all.
Same standard, or admit it was never the point.
If you want to keep up with AI news, check out https://lnkd.in/e2FPSD_Q
Thoughts?
Let me lay out what actually happened, because the timeline is the whole story.
In June, Washington hit Anthropic with an export-control directive. Suspend access to Mythos 5 and Fable 5 for every foreign national on earth, including Anthropic's own employees. Anthropic couldn't comply halfway, so they took both models offline for all customers. Gone. The trigger? Amazon researchers had slipped past Fable 5's anti-hacking guardrails, and White House advisers decided a model that finds vulnerabilities at scale was a national security risk. Lawsuit followed. Lawmakers are still demanding the rationale. Cyber leaders are begging the government to lift the curbs because the restrictions hurt the defenders, not the attackers.
Now look at OpenAI.
This week they launched GPT-5.5-Cyber under the Daybreak program. Read a whole codebase, find the holes, prove them in a sandbox, write the patch. Their own benchmark: 85.6% on CyberGym, beating the exact Anthropic model the government just banned. OpenAI says it outperforms Mythos. The more dangerous tool, by their own numbers.
And the export control? There isn't one.
OpenAI gets to run its own "Trusted Access for Cyber" program. They verify the defenders. They scope the controls. They decide who holds the key to the world's vulnerability surface. The company grades its own homework, and Washington nods along.
So which is it?
If a model that finds and patches bugs at scale is a national security threat that has to be ripped offline globally, then the more capable model is a bigger threat. Same logic. Same risk. If it's NOT a threat and these are defensive tools we want in the field, then Anthropic got crushed for nothing and owed an apology.
You cannot have both. Pick a standard and apply it to everyone.
I spent years building the security layer that sits on top of these models, the controls that decide what an AI is allowed to touch. I'll tell you what selective enforcement actually produces: it doesn't make anyone safer. It just picks winners. One company gets forced offline and sued into a corner. Another ships the stronger weapon and writes its own rules. That's not a safety policy. That's a referee who keeps changing the call depending on the jersey.
The defenders need these tools. The attackers already have them. Fine. Then build one rulebook and hold every lab to it, in public, with oversight nobody owns privately.
Until someone answers why the weaker model got banned and the stronger one didn't, this isn't about security at all.
Same standard, or admit it was never the point.
If you want to keep up with AI news, check out https://lnkd.in/e2FPSD_Q
Thoughts?