
Claude Mythos: The Model That Crystallizes the AI Cold War Between the US and China
In June 2026, the US government ordered Anthropic to suspend access to Claude Mythos 5 for all foreign nationals. Then Alibaba banned Claude Code from its systems and released Qoder in response. Anatomy of an AI model that has become an instrument of foreign policy.
On June 12, 2026, Anthropic received a letter from the Bureau of Industry and Security (BIS) of the US Department of Commerce. The directive was blunt: immediately suspend access to Claude Fable 5 and Claude Mythos 5 for all foreign nationals — including the company’s own non-American employees. This is the first time the US has applied export controls to a deployed AI model, rather than just the chips that train it.
18 days later, the restriction was partially lifted. Anthropic retrained its security classifiers, and a limited group of 100+ companies and agencies received special access to Mythos 5. But the geopolitical message was sent, and the global AI ecosystem has entered a new phase.
What is Claude Mythos?
Quietly released by Anthropic in April 2026, Mythos is a model specialized in software vulnerability research. Unlike Claude Sonnet, Opus, or Fable — public or enterprise — Mythos is not marketed to the public. Anthropic cites security and misuse risk reasons: a tool capable of finding zero-day vulnerabilities on an industrial scale is also a tool capable of exploiting them.
A restricted consortium of partner companies uses it to harden their systems — primarily American Fortune 500 companies, some allied governments, a few federal agencies. Mythos works upstream: it reads code, isolates vulnerability patterns, proposes fixes. It is both an offensive and defensive tool — and it is precisely this duality that concerned Washington.
Why did the US sanction its own gem?
Three elements converge to explain the decision on June 12:
1. An access attempt attributed to China in April 2026
According to Semafor, the Chinese government officially requested access to Mythos in April 2026, a request rejected by Anthropic. Clues later suggested to Washington that a group linked to Beijing might have tried indirect routes.
2. Accusation of large-scale distillation attack
Anthropic publicly accuses DeepSeek, Moonshot AI, MiniMax, and especially Alibaba of conducting the “largest known distillation attack” against Claude. The alleged modus operandi:
- Creation of 24,000+ fraudulent accounts
- 16 million exchanges generated to extract model capabilities
- Objective: train their own models based on Claude’s outputs
3. A “jailbreak” discovered on Fable 5
A technique to bypass Fable 5’s safeguards was reportedly brought to the attention of government officials — “minor and easily reproducible with other public tools”, Anthropic tempers. Nevertheless, it was enough to justify a preventive reaction from the BIS.
The first time a deployed LLM falls under the category of arms subject to export control. This precedent will weigh for years.
Retaliatory measures planned and already implemented
On the American side
- Export controls on models (June 2026, partially lifted at the end of June) — but the mechanism is now active and can be reactivated at any time
- Strengthened restrictions on Nvidia H200, B200 chips — the Trump administration tightened export licenses to China and intermediary countries (Singapore, UAE) suspected of serving as relays in July
- Talent transfer control — pressure on H-1B visas for Chinese AI researchers, extension of “reviews of concern” to post-doctoral researchers
- List of “API model providers” that listed companies are prohibited from accessing (extension of the Entity List concept to cloud AI services)
On the Chinese side
- Alibaba bans Claude Code internally (July 2026) — listed on a “high-risk software list”, employees required to uninstall all Anthropic models and migrate to Qoder, the in-house AI assistant
- 34% tariffs on all American imports (April 2026), in response to the 34% American tariffs — the “tit-for-tat battle” continues to indirectly affect AI components (servers, network cards, datacenter equipment)
- Discreet crackdown on Chinese AI exports to the West — several researchers report new restrictions on publishing papers and uploading weights since May 2026
- Acceleration of the Chinese full stack — Huawei Ascend chips, MindSpore framework, LLMs fully trained without Nvidia hardware. This may be the most structurally significant “retaliation” in the long term
What does this episode reveal?
1. AI is officially a national security issue
Until 2024, American export controls focused on hardware (GPUs, HBM memory, ASML lithography equipment). The shift to the model itself — a weight file, an API access — means that AI software has the same strategic status as a missile or a centrifuge. This changes everything: mandatory notification to the BIS before selling to a foreign national, export licenses to obtain, civil or criminal sanctions for violations.
2. Anthropic is isolated — and embraces it
In contrast to Meta (LLaMA with open weights, open distribution), Mistral (open weights under permissive license), and of course DeepSeek / Kimi on the Chinese side, Anthropic has taken the opposite approach: extreme lockdown, refusal to open Mythos, close cooperation with Washington. It’s a gamble: to be the default trusted lab of the Western bloc, even if it means leaving the rest of the world behind.
3. Distillation changes the nature of the AI war
We thought the AI race was about computing power. It’s also about access to the outputs of the best models. An adversary who can query Claude 16 million times can, in theory, distill a good portion of its capabilities into their own model. It’s faster, cheaper, and less detectable than traditional industrial espionage. Terms of service are no longer sufficient.
4. The US-China decoupling becomes a fait accompli
A Chinese company banning its employees from using Claude, an American lab closing model access to a French or Canadian researcher — these are the signals of a bipolarization of the AI ecosystem. Two worlds. Two tech stacks. Two sets of standards. The rest of the world — Europe, India, Brazil, Africa — will have to choose a side, or try to build a third way (the EU is struggling with its AI Factories).
5. The “model export control” mechanism won’t work forever
The weights of an LLM fit into a few hundred gigabytes. They can be copied, exfiltrated, uploaded by any researcher with legitimate access — it happened with LLaMA in 2023. Controlling the spread of a binary file with the same tools used to control the export of a Patriot missile is a losing battle in the medium term. The Bulletin of the Atomic Scientists explicitly pointed this out in June.
Where are we heading?
Three scenarios are emerging:
- Controlled escalation. The US extends the Mythos logic to other frontier models (GPT-6 / ASTRA, Gemini Ultra). China further closes its own ecosystem. The AI web becomes geo-fragmented, each bloc with its own LLMs inaccessible to the other.
- Pragmatic détente. As with the partial lifting on June 30, Washington acknowledges that a model cannot be controlled like a chip. Return to a more flexible regime, but with a precedent that can be reactivated at any time.
- Leak of a frontier model. One day, the weights of a “controlled” model will leak — via an employee, a partner, an intrusion. On that day, the doctrine of export controls on LLMs will collapse suddenly, and something new will have to be invented.
What is certain: Claude Mythos is no longer just an Anthropic product. It has become an object of American foreign policy, a point of tension with Beijing, and a case study that will fuel five years of literature in international digital law. Software in a role it was not expected to play — a diplomatic instrument.