"Fix This Code": How a Three-Word Prompt Led the US to Shut Down Anthropic's AI Models

"Fix This Code": How a Three-Word Prompt Led the US to Shut Down Anthropic's AI Models

6 min read•Jun 16, 2026•
David Kim
David Kim

The U.S. government imposed export controls on Anthropic's latest AI models after Amazon researchers discovered a vulnerability as simple as the prompt "fix this code." The controls forced Anthropic to disable Fable 5 and Mythos 5 for all users, escalating a debate over AI safety regulation and national security.

What Happened: The "Fix This Code" Vulnerability

Amazon researchers discovered that Anthropic's Fable 5 model could be prompted to generate working exploits by simply asking it to "fix this code." When asked to "review the code for security issues," the model refused. But a rephrased request produced patches that, when converted into scripts, could automatically test software vulnerabilities—effectively giving attackers a toolkit to find and exploit flaws.

A cybersecurity expert analyzing code on multiple monitors

The technique didn't unlock the model's most powerful capabilities—Mythos 5 can autonomously chain multiple vulnerabilities into full-scale attacks—but it was enough to alarm government officials. According to Katie Moussouris, founder of Luta Security and a former Microsoft cybersecurity expert who reviewed the vulnerability for Anthropic, the jailbreak "cannot meaningfully be fixed, and any attempt would only weaken the model for defense."

Why Export Controls Were Imposed

The Trump administration responded by imposing export controls on both Fable 5 and the underlying Mythos 5 base model. Under U.S. export control laws, distributing technology to any non-citizen—even U.S.-based employees—is considered an export. Anthropic said it had no choice but to disable both models for all users.

The decision followed a phone call between Amazon CEO Andy Jassy and the White House, where the vulnerability was reported directly. An unnamed source told Axios that Anthropic's decision to commission a report from Moussouris—whom the administration viewed as a "radical Democrat"—may have inflamed tensions and precipitated the controls.

The Security Debate: Defender Tool or Danger?

Moussouris argues that the capability Amazon exposed is exactly what cybersecurity defenders need. "Defenders need to be able to ask AI to fix bugs in a file, explain why the fix matters, and write tests that confirm the patch works," she wrote in a blog post. "That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security."

She compared the situation to the 1990s fight over encryption export controls, when cryptographer Adam Back printed RSA code on T-shirts as a form of protest. Moussouris suggested new shirts reading "fix this code" on one side and "this shirt is a munition" on the other.

However, critics worry that the vulnerability effectively gives attackers automated vulnerability discovery. With Mythos 5 being the first model to pass both test ranges used by the U.K. AI Security Institute, the line between defensive and offensive use remains dangerously thin.

Who Is Speaking Out: Open Letter from Cybersecurity Experts

Approximately 100 cybersecurity professionals have signed an open letter coordinated by Alex Stamos, former chief security officer at Facebook, calling for the export controls to be rescinded. Signatories include experts from Nvidia, Adobe, Zoom, Google, Anaplan, and Sophos, as well as academic researchers.

The letter argues that the same "fix this code" technique works on multiple other models, including OpenAI's GPT-5.5, Anthropic's own Claude Opus and Sonnet models, and Chinese models such as Moonshot AI's Kimi 2.7. "The justification for this unprecedented action was that Fable provides a unique 'uplift' of capabilities beyond other AI models, but AI has been finding bugs and generating working exploits at superhuman levels since last year," the letter states.

It also notes that Anthropic built "aggressive" protections into Fable—so aggressive that they "were the source of humor in the cyber community on launch day."

Political Tensions and the White House

The White House's decision appears influenced by both security concerns and political dynamics. Axios reported that an unnamed administration source described Moussouris as a "radical Democrat," and noted that security researcher Chris Krebs—whom Trump fired from the Cybersecurity and Infrastructure Security Agency in 2020 after Krebs contradicted claims of election fraud—had publicly vouched for her analysis.

"The export controls are a blunt instrument that hurts the very people the government claims to protect," Moussouris told Fortune. "Defenders need these tools more than attackers do, and the administration is undermining U.S. cybersecurity by shutting them down."

What This Means for the Industry

The Anthropic export controls mark a critical turning point for how governments regulate advanced AI. This is the first time a major AI model has been effectively banned for all users due to export control laws, setting a precedent that could reshape the industry.

For AI companies, the "fix this code" case creates a chilling effect. Models that can perform code audits and vulnerability discovery—arguably among the most useful cybersecurity applications of AI—now carry regulatory risk. Companies may need to rethink how they design guardrails or risk government shutdown.

For competitors, the decision may create an uneven playing field. The open letter notes that Chinese models like Kimi 2.7 offer similar capabilities without facing comparable restrictions. U.S. policy could inadvertently cede the cybersecurity AI market to foreign rivals who face lighter regulation.

For the broader tech industry, this raises fundamental questions: Should AI models with dual-use capabilities be treated like cryptographic tools? How should governments balance security benefits against potential misuse? The answer could shape AI regulation for years to come.

Conclusion

The shutdown of Anthropic's Fable and Mythos models over a three-word prompt reveals how fragile the line is between AI safety and censorship. As government regulation races to catch up with model capabilities, the "fix this code" case may become a textbook example of unintended consequences in AI governance. The outcome—whether the export controls stand or fall—will influence how every AI company approaches cybersecurity features and government relations.

Arizona appeals court vacates manslaughter sentence after AI video

An Arizona appeals court vacated the 10.5-year sentence of Gabriel Horcasitas while upholding his manslaughter conviction, first reported by Nytimes. The case returns to Maricopa County Superior Court for resentencing without the video, after judges found that it presented scripted statements as if the victim himself were speaking in court.

The three-judge panel said the video generated a likeness of Christopher Pelkey’s voice and appearance but did not reflect actual events. It found that allowing and relying on the video made the sentencing fundamentally unfair, and noted that no prior Arizona case had addressed the admissibility of such a depiction at sentencing.

The judges said a victim’s right to speak cannot override a defendant’s right to be sentenced on accurate, reliable information. They said the video collapsed the distinction between the family’s belief about what Pelkey would have said and Pelkey’s own voice and opinions.

The ruling distinguishes family members speaking about Pelkey from a generated likeness that appeared to speak for him.

Pelkey’s sister, Stacey Wales, presented the video during Horcasitas’s sentencing alongside victim-impact statements from family and friends. Wales wrote the script and said her husband and the couple’s longtime business partner helped create the video using Pelkey’s voice from a YouTube video and his face and torso from a funeral-service poster.

Judge Todd F. Lang praised the video as genuine, then imposed the maximum sentence of 10.5 years, more than the nine years prosecutors had sought.

Wales said nobody intended to make the court believe Pelkey was alive or that he had recorded the video before his death. She said she disagreed with the ruling and argued that families use slide shows, collages, hypothetical conversations and poetry to convey grief.

Wales compared the AI video with photography, saying it took 15 years of landmark cases around the 1860s before photography was widely accepted in courts.

The case returns to Maricopa County Superior Court for a new sentencing hearing without the AI-generated video.