Semafor: China-Linked Group Had Already Accessed Mythos Before the Export Order Landed
A Semafor report published June 13 adds a concrete intelligence finding to the White House’s decision to restrict Anthropic’s Fable 5 and Mythos globally: a China-linked group had already obtained access to Mythos, raising concerns about capability transfer through distillation.
The export control directive arrived Friday from Commerce Secretary Howard Lutnick, ordering Anthropic to disable both models for all non-US customers and foreign persons within the United States. Anthropic took both models down the same day. The company has been in ongoing dispute with the government over the severity of the underlying jailbreak, but the distillation concern is a separate and distinct reason for the action.
Why Distillation Changes the Risk Model
Access to a frontier model — even through a narrow jailbreak — enables a specific class of exfiltration that does not require the model’s weights. A foreign actor who can query Mythos at scale can generate a synthetic training dataset from those responses, then use that dataset to train a local model that approximates Mythos’s behavior without needing the underlying system.
The technique is not hypothetical. Distillation from proprietary models has been documented across multiple open-weight models released by competitors. The concern is that Mythos’s documented performance on cybersecurity tasks — 93.9% SWE-bench Verified, completion of two AISI cyberattack ranges end-to-end — is precisely the capability profile that transfers through this mechanism.
A distilled model would not replicate Mythos exactly, but could capture enough of its offensive security reasoning to be operationally useful.
Anthropic’s Position Has Not Changed
Anthropic has consistently disputed the framing of the export action as a cybersecurity response. The company said the technique shown to it was narrow, found a small number of already-known vulnerabilities, and produced capability that other public models can also provide. Anthropic further noted that “perfect jailbreak resistance is not currently possible for any model provider” and that universal jailbreaks will eventually be found across the industry.
That argument addresses the jailbreak. It does not directly address the intelligence claim that a China-linked group had already accessed the system before controls were put in place.
The Distinction That Matters
Earlier coverage focused on the government’s jailbreak finding and Anthropic’s response to it. The Semafor report reframes the action: the primary driver may not have been the jailbreak’s severity, but the fact that access had already occurred and that distillation of frontier cyber capabilities represented an ongoing transfer risk.
This is a counterintelligence rationale, not just a vulnerability response. The policy instrument — export controls rather than a security patch request — is consistent with treating the access event itself as the trigger rather than the technical flaw.
What Comes Next
Anthropic and the government have been in talks on conditions for bringing models back online. The original timeline cited “a few weeks.” Whether those talks address the distillation concern separately from the jailbreak — and whether Anthropic can offer any technical control that prevents systematic model querying — is not yet public.
The White House had already blocked Anthropic’s attempt to expand Mythos access from 50 to 120 organizations before the export controls were issued, suggesting officials were tracking access scope as a risk variable before the Friday directive.