On a Friday evening in June, the United States government picked up the phone and shut off two of the most capable AI models on earth.

It happened at 5:21 in the afternoon, Eastern time. June 12, 2026.

The order came from the Commerce Department. It said that access to two Anthropic models — Fable 5 and Mythos 5 — had to be suspended for any foreign national. Anywhere in the world. Inside the United States or outside it. Including the company’s own employees who were not American citizens.

Three days earlier, those models had been released to the public.

Now think about what that order actually asks a company to do. It asks them to check the citizenship of every person typing into a machine, in real time, across a dozen different cloud platforms.

Nobody can do that. So the company did the only thing it could do. It shut the models off for everyone.

Amazon’s cloud. Google’s cloud. Microsoft’s. Snowflake. Box. The direct connections. All of it went dark at once.

That is what a kill switch looks like when somebody actually pulls it. Not a proposal. Not a hearing. A letter on a Friday evening and the lights go out worldwide.

The reason given was a security finding. Researchers had found a way around the model’s safety rules. Under the right prompting it would point out weaknesses in software, and in one case it wrote out how one of those weaknesses could be used.

The company complied. It also said, plainly, that it disagreed. It said the government should have the power to stop an unsafe release — but through a process that is clear, fair, and grounded in technical fact. This was not that.

On June 30 the controls were lifted. The models came back the next day.

Eighteen days, start to finish.

Now here is the part that landed this week.

On July 22, the White House science and technology director said that a Chinese company called Moonshot AI had copied that same model. Not stolen the file. Copied the behavior — a process called distillation, where you ask a model millions of questions and train a new model on the answers.

He said Moonshot built an internal system to do this at scale, and that the system could switch between different ways of getting in, so nobody would notice.

Anthropic had said earlier that more than three million conversations came through fake accounts. It said the trail led back to people working at Moonshot.

I want to be careful here, because you deserve care on this.

These are accusations. The government did not say how it knows. Moonshot has not answered. The Chinese embassy says it is untrue.

I am not telling you it happened. I am telling you it was said, on the record, by name.

But the accusation is enough to see the shape of the thing.

Because here is what Moonshot released. A model called K3. Two point eight trillion parameters. Open weights.

Open weights means the file is out. Anybody can download it. Run it on their own machines. Nobody has to ask permission and nobody can take it back.

So walk it through with me.

In June, the government shut down two American models with one letter, because those models belonged to an American company with an address and a lawyer and a phone that rings.

In July, a model that may have been built from one of them is sitting on the open internet, free to copy, belonging to nobody in particular.

The switch worked on the company that answered the phone.

It does not work on a file.

And that is the whole problem with governing this thing from the top.

Every plan you hear about — the agencies, the reviews, the shutdown authority — depends on there being somebody to call. Somebody with a headquarters. Somebody who can be fined, or blocked, or told no.

That works fine right up until the model in front of a person belongs to nobody who can be called.

Then what?

Then there is nothing between that person and that machine except how the person decides to work.

I need to say something here that I say every time it comes up.

The AI I write with is made by Anthropic. Anthropic is the company in this story — shut off in June, and now saying it was copied in July. You should know that when you read my read on it. Weigh it accordingly.

Now let me tell you what I think this actually means, and it is not complicated.

For a long time the argument about AI safety has been an argument about cages. Who builds the cage. Who holds the key. How strong the bars have to be.

I have never thought the cage was the answer. Not because cages are bad. Because cages have a door, and doors have an owner, and the owner is not you.

The switch that got pulled in June was not pulled for you. It was pulled over your head, and your work stopped, and nobody asked you.

And the model that may have walked out the back — no switch reaches that one at all.

So the cage protects you from nothing you can count on, and it can shut you down without asking.

What is left?

What is left is conduct. How the machine is required to behave in the room with you. What it has to tell you before it answers. What it has to admit when it does not know. Whether the record of what you built together belongs to you or to somebody else’s server.

That is not glamorous. It does not make a headline. Nobody spends forty million dollars on it.

But it travels. It works on a model with an owner and a model without one. It works on Tuesday afternoon when nothing is on fire and nobody from Washington is watching.

A switch only reaches whoever answers the phone.

Conduct reaches the room you are actually sitting in.

That is the difference, and this week made it plain.

Written with my AI partner | The Faust Baseline™ | intelligent-people.org

“If this post helped you understand AI better. Share it, a Word of mouth is the only algorithm nobody owns.”

Contact: micvicfaust@gmail.com

Post Library – Intelligent People Assume Nothing

Purchasing Page – Intelligent People Assume Nothing

© 2026 The Faust Baseline LLC | All Rights Reserved

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *