TOKYO, 31 AUG 2026 — Japan's largest banks have regained access to Anthropic's Mythos model, eleven weeks after a US export-control directive cut off foreign nationals. The capability being controlled is finding software vulnerabilities, and an open-weight Chinese model already does that at roughly frontier level.
What actually happened, in order
On 12 June Anthropic disabled access to Claude Fable 5 and Claude Mythos 5 for all customers, after a US government export-control directive required it to suspend access by foreign nationals. The stated concern was a method of bypassing the safeguards intended to limit Fable 5's use for cybersecurity tasks, including identifying software vulnerabilities.
On 26 June the government authorised restoration of Mythos 5 for a limited set of US organisations that operate and defend critical infrastructure, reported as more than 100 institutions. Japanese banks regained access by 28 August. Fable 5 remained unrestored at that point, with no published timeline.
Anthropic switched it off for Americans too
The directive concerned foreign nationals. Anthropic disabled the models for everyone.
This detail is the most instructive part of the story: it shows what export control on a hosted model means in practice. A cloud API does not have a border. The provider knows the billing entity and the account, and it does not reliably know the nationality of the person at the keyboard, which is what the deemed-export rules turn on. Because Anthropic could not enforce the rule at the required granularity, its only compliant option was to switch the model off for everyone.
Two weeks later the government issued a narrower authorisation, and the shape of what came back tells you the model that was reached: an allowlist of named institutions rather than a rule about who may access. That is how export control has always worked for physical goods, applied to a service, and it produces a market in which capability is a licence rather than a purchase.
The controlled capability is the one that has diffused
Vulnerability discovery is what triggered this, and it is the part of offensive security that open weights have already reached.
We reported that Z.ai's GLM-5.3 finds bugs like the frontier and is 23 points behind at using them. That gap is the whole question. Discovery — reading code and identifying a flaw — has largely commoditised. Exploitation, meaning turning a flaw into a working, reliable attack chain, has not, and that is where the frontier models still separate.
The directive was aimed at a jailbreak affecting vulnerability identification. On the evidence available, that is the capability least amenable to control, because a comparable model ships under an MIT licence and can simply be downloaded. Weights on a disk are not subject to an access directive.
Which does not make the control pointless
Restricting a hosted model might look like theatre while open-weight models exist, but that conclusion is too quick.
Three things a hosted frontier model provides that a downloaded one does not: the compute to run it at scale without acquiring the hardware, the reliability that comes from a maintained production system, and the exploitation capability where the gap is still 23 points. An actor who can download GLM-5.3 has bug-finding. An actor with Mythos access had something further along the chain.
The control is a friction, not a barrier, and friction is a legitimate policy objective. What it does not do is create a capability gap that did not already exist, and the public framing of the June action implied otherwise.
Who bore the cost
The eleven-week outage fell entirely on customers who were never the directive's target.
Japanese banks are among the most heavily supervised institutions on earth, operating under a treaty ally's financial regulator. They lost access in June because the enforcement mechanism could not distinguish them from anyone else, and regained it in August through what appears to be a bilateral process rather than a rule they could have read in advance.
That unpredictability is the operational problem for anyone outside the United States. A firm cannot build a critical workflow on a service that may be withdrawn by a directive it has no standing to contest, and restored on a timetable it cannot see. The rational response is a second supplier, and the available second suppliers are increasingly Chinese open-weight models.
What this means for buyers in this region
Southeast Asian institutions sit further from the front of that queue than Japan does, and should plan accordingly.
Japan is a treaty ally with a mature financial regulator and a direct diplomatic channel, and it took eleven weeks. A bank in Jakarta, Manila or Bangkok has none of those advantages and no reason to expect faster treatment. Anyone in the region running production workloads on a US frontier model should assume access is revocable on short notice, and that restoration is a matter of allied priority rather than contract.
The practical response is not to avoid US models, which remain the strongest available. It is to keep workloads portable, with prompts and evaluation harnesses that can be pointed at a fallback model which has actually been run rather than merely identified. This is ordinary supplier-concentration discipline, now elevated from a procurement preference to a geopolitical requirement.