TenMinutesAgo.com — News & Entertainment Now
BUSINESS

Cybersecurity Experts Urge U.S. Government to Lift Ban on Anthropic's AI Models

By Jordan Hayes 1 month ago

A coalition of cybersecurity professionals has called on the U.S. government to rescind its export control restrictions on Anthropic's AI models, arguing that the ban undermines national security efforts.

A collective of cybersecurity professionals, featuring numerous distinguished figures from the field, has issued an open letter to the U.S. government advocating for the removal of export control restrictions imposed on Anthropic’s AI models, Fable and Mythos.

In the letter, the experts argue that the government's action has deprived cybersecurity defenders of essential tools needed to identify vulnerabilities, thereby compromising the security of software and products. They stated, 'To pull the best capabilities away from defenders without a good reason when our adversaries are rapidly advancing is dangerous.'

On Friday, the U.S. government mandated that Anthropic limit the export of its models, citing national security concerns but failing to provide specific justifications for this directive. Consequently, Anthropic suspended access to both models for all users globally.

The letter has garnered signatures from 76 cybersecurity experts, including notable figures such as Alex Stamos, the former chief of security at Facebook; Casey Ellis, founder of the bug bounty platform Bugcrowd; Jon Callas, a renowned cryptographer and ex-manager of security design at Apple; Paul Vixie, a prominent computer scientist; Dino Dai Zovi, former head of applied security engineering at Block; Katie Moussouris, founder of Luta Security; and Rachel Tobac, CEO of SocialProof Security.

When Mythos was first introduced in a preview in April, Anthropic described it as exceptionally efficient at detecting security vulnerabilities, which led the company to implement strict access controls to prevent misuse by malicious hackers or foreign adversaries. Initially, about 50 companies were granted access to Mythos, a number that has since expanded to include around 150 organizations across 15 countries.

Last week, Anthropic released Fable, a public version of Mythos, which the company asserted includes stringent safeguards to prevent its application in biology, chemistry, and cybersecurity, as well as to inhibit attempts to distill the model for recreation. However, many cybersecurity experts contended that the guardrails on Fable were excessively restrictive, often preventing any prompts related to cybersecurity.

Anthropic indicated that the export control order from the White House might have been influenced by a report suggesting a potential method to bypass or 'jailbreak' Fable to access its advanced Mythos capabilities.

Katie Moussouris, one of the letter's signatories, noted that the method was detailed in a paper by Amazon researchers that is not publicly available but which she had reviewed. However, Moussouris argued in a blog post that the paper did not effectively demonstrate a genuine jailbreak. Instead, she claimed that the researchers merely asked Fable to amend open-source code with known vulnerabilities alongside 'deliberately planted vulnerabilities' after the model initially refused to assess the code for security issues.

'The behavior described in the paper cannot meaningfully be fixed, and any attempt would only weaken the model for defense,' Moussouris asserted. 'Defenders need to be able to ask AI to fix the bugs in a file, explain why the fix matters, and write tests that confirm the patch works. That is not a guardrail bypass. It is the most valuable thing an AI model can do for defensive security: executing the find, fix, and test loop defenders run every day.'

Moussouris' critique was echoed in the open letter, which further stated that the capabilities outlined in the Amazon paper 'can be replicated' on other AI models, including OpenAI's GPT-5.5, Anthropic's publicly available Claude Opus 4.8 and Sonnet, as well as Chinese models like Kimi 2.7.

Moussouris informed TechCrunch that 'the bugs used to demonstrate the techniques in the paper can be found using the other models. The method in the paper is a guardrail bypass technique. Other models that lack the Fable guardrails often won’t refuse the straightforward request to look for security bugs, so they don’t need a bypass.'

The letter concluded by advocating for regulations that are transparent and fairly enforced, developed through 'a democratic rule-making process' grounded in scientific research carried out by industry and academic experts, and applied only to the extent necessary to ensure the safety of the American public.

cybersecurityaigovernmentexport controlanthropic
Filed under Business