<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Regulation on PHP Boy Scout</title><link>https://blog-570662.gitlab.io/tags/regulation/</link><description>Recent content in Regulation on PHP Boy Scout</description><generator>Hugo -- gohugo.io</generator><language>en-gb</language><copyright>Matt Cockayne</copyright><lastBuildDate>Sat, 13 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog-570662.gitlab.io/tags/regulation/index.xml" rel="self" type="application/rss+xml"/><item><title>They switched it off while it was fixing my code</title><link>https://blog-570662.gitlab.io/they-switched-it-off-while-it-was-fixing-my-code/</link><pubDate>Sat, 13 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog-570662.gitlab.io/they-switched-it-off-while-it-was-fixing-my-code/</guid><description>&lt;img src="https://blog-570662.gitlab.io/they-switched-it-off-while-it-was-fixing-my-code/cover-switched-it-off-while-it-was-fixing-my-code.png" alt="Featured image of post They switched it off while it was fixing my code" /&gt;&lt;p&gt;I woke up this morning to a one-line message from my own tooling:&lt;/p&gt;

 &lt;blockquote&gt;
 &lt;p&gt;Claude Fable 5 is currently unavailable. Learn more: &lt;a class="link" href="https://www.anthropic.com/news/fable-mythos-access" target="_blank" rel="noopener"
 &gt;https://www.anthropic.com/news/fable-mythos-access&lt;/a&gt;&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;I followed the link expecting a status page about a wobble in someone&amp;rsquo;s data centre. Instead it was Anthropic, explaining that the evening before, at 5:21pm Eastern, the US government had ordered them to suspend all access to Fable 5 and Mythos 5 on national security grounds. Globally. Every user. Their own staff included.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;d spent the previous day with Fable doing one very specific thing: pointing it at my own codebase and asking it to read the code and fix the flaws it found. That, very nearly word for word, is the thing it has now been banned for.&lt;/p&gt;
&lt;h2 id="three-days-late-to-the-only-model-that-mattered"&gt;Three days late to the only model that mattered
&lt;/h2&gt;&lt;p&gt;Fable came out on the 9th. I didn&amp;rsquo;t get to it properly until the 12th, which is the sort of timing I specialise in. By the time I sat down with it, I had about a day of real use before it vanished. One day to form a view on what people were calling the most capable coding model anyone had shipped. So treat everything below as the read of a man who got three days&amp;rsquo; notice and used one of them.&lt;/p&gt;
&lt;p&gt;What I had it doing was unglamorous and exactly the kind of work I care about: a full security audit of &lt;a class="link" href="https://gitlab.com/phpboyscout/go-tool-base" target="_blank" rel="noopener"
 &gt;go-tool-base&lt;/a&gt;, the same &amp;ldquo;leave the codebase better than you found it&amp;rdquo; pass I&amp;rsquo;d normally run myself. Find the flaws, then start fixing them.&lt;/p&gt;
&lt;p&gt;And it was good. Genuinely good. It surfaced issues that previous passes with Opus had walked straight past, and in a couple of cases the flaw was sitting in code that Opus itself had written. There is something bracing about one model quietly marking another&amp;rsquo;s homework, and being right.&lt;/p&gt;
&lt;h2 id="good-but-lets-not-get-carried-away"&gt;Good, but let&amp;rsquo;s not get carried away
&lt;/h2&gt;&lt;p&gt;Here is where I have to be fair, because the anger that came later is only worth anything if the praise before it is honest.&lt;/p&gt;
&lt;p&gt;Fable is not magic. The class of bug it found is not some exotic thing only it can see. Plenty of models, from plenty of providers, are perfectly capable of reading a codebase and pulling out the same problems, and there is a mountain of evidence that they do, every day. Anthropic say as much themselves: the capability is &amp;ldquo;widely available from other models (including OpenAI&amp;rsquo;s GPT-5.5)&amp;rdquo; and &amp;ldquo;is used every day by the defenders who keep systems safe.&amp;rdquo; I&amp;rsquo;d already arrived at that conclusion from my own keyboard before I read their statement. Fable was excellent. It was not unique. Hold that thought, because the whole argument turns on it.&lt;/p&gt;
&lt;h2 id="it-kept-slipping-out-of-my-hands"&gt;It kept slipping out of my hands
&lt;/h2&gt;&lt;p&gt;The other thing I learned in my one day is that having Fable and using Fable were not the same thing.&lt;/p&gt;
&lt;p&gt;I set my main working thread to Fable and got on with it. What I didn&amp;rsquo;t know, because nothing on screen told me, is that partway through the evening it had quietly handed me back to Opus. The only reason I know now is that the session log records it in black and white:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-fallback" data-lang="fallback"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;2026-06-12T06:57:22Z {&amp;#34;type&amp;#34;:&amp;#34;fallback&amp;#34;,&amp;#34;from&amp;#34;:{&amp;#34;model&amp;#34;:&amp;#34;claude-fable-5&amp;#34;},&amp;#34;to&amp;#34;:{&amp;#34;model&amp;#34;:&amp;#34;claude-opus-4-8&amp;#34;}}
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;2026-06-12T18:50:08Z {&amp;#34;type&amp;#34;:&amp;#34;fallback&amp;#34;,&amp;#34;from&amp;#34;:{&amp;#34;model&amp;#34;:&amp;#34;claude-fable-5&amp;#34;},&amp;#34;to&amp;#34;:{&amp;#34;model&amp;#34;:&amp;#34;claude-opus-4-8&amp;#34;}}
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A whole evening of work I thought I was doing on Fable was, in fact, Opus wearing Fable&amp;rsquo;s badge. The audit itself launched on the wrong model first; I only caught it because I happened to be watching the workflow panel, killed it, and relaunched it on Fable, where it chewed through an entire five-hour quota in about forty minutes, then spent $50 of usage credits I&amp;rsquo;d been saving in about five more. Even the run that worked was visibly flaky: of the 282 little agents that audit fanned out into, well over half failed outright and had to be retried.&lt;/p&gt;
&lt;p&gt;Then, in the small hours, it started refusing entirely. My tooling caught the moment before I did:&lt;/p&gt;

 &lt;blockquote&gt;
 &lt;p&gt;Now failing instantly. Fable appears to be temporarily unavailable for subagents (the first three succeeded). The user explicitly required Fable, so I won&amp;rsquo;t downgrade&amp;hellip; rather than silently switch models.&lt;/p&gt;

 &lt;/blockquote&gt;
&lt;p&gt;It managed three of the fixes before it went, each one green on tests, the race detector and the linter. Three real improvements to my code, written by Fable, sitting in my git history. The other three were finished by Opus, because by morning there was nothing left to finish them with.&lt;/p&gt;
&lt;h2 id="capable-and-almost-impossible-to-build-on"&gt;Capable, and almost impossible to build on
&lt;/h2&gt;&lt;p&gt;There was a second wall, and I hit it before any of this, on the day Fable launched, when I tried to make it go-tool-base&amp;rsquo;s default model.&lt;/p&gt;
&lt;p&gt;Most of what you build on top of a model isn&amp;rsquo;t a chat window. You need it to hand your code an answer in a fixed shape, the same fields in the same places every time, so the program on the other end can rely on what comes back. The usual way to guarantee that is to force the model&amp;rsquo;s hand: you don&amp;rsquo;t ask politely for the structure and hope, you require it, so a wrong-shaped answer fails outright instead of quietly slipping through.&lt;/p&gt;
&lt;p&gt;Fable won&amp;rsquo;t be forced. Ask it to commit to a guaranteed structure and it declines, flat out. As I understand it the reasoning is a safety one: letting anyone compel a model into a precise, mandated output is itself a lever, a way to march it toward saying something it shouldn&amp;rsquo;t. Reasonable enough on paper. In practice it meant the most capable model I&amp;rsquo;d touched couldn&amp;rsquo;t drive the structured parts of my own tool, and by that first afternoon I&amp;rsquo;d quietly set the default back to Opus. It was the same refusal, I realised later, that had collapsed half of that audit&amp;rsquo;s agents.&lt;/p&gt;
&lt;p&gt;And it is not a niche complaint. Guaranteed structure is a hard requirement for a vast swathe of what people are actually building on these models. Not everyone is making another Claude Code. Plenty of us are wiring models into systems that have to get a clean, predictable contract back every single time, and a model that reserves the right to freestyle the shape of its answer is one you simply cannot put in that seat.&lt;/p&gt;
&lt;h2 id="the-part-they-banned-is-my-bread-and-butter"&gt;The part they banned is my bread and butter
&lt;/h2&gt;&lt;p&gt;So let&amp;rsquo;s be precise about what got pulled, because the precision is the whole point.&lt;/p&gt;
&lt;p&gt;Anthropic describe the government&amp;rsquo;s concern as &amp;ldquo;a narrow potential jailbreak, which essentially consists of asking the model to read a specific codebase and fix any software flaws.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Read that again. Reading a codebase and fixing its flaws. That is not some dark-web misuse I have to strain to imagine. That is my bread and butter, the literal, boring, defensive job I had Fable doing in the open, on my own project, when the shutters came down.&lt;/p&gt;
&lt;p&gt;And here is where that earlier point earns its keep. If the banned capability were unique to Fable, you could at least follow the logic, however much you disagreed. But it isn&amp;rsquo;t, and it isn&amp;rsquo;t even close: give Opus enough time, enough budget and a patient enough hand on the prompts, and it would get to most of the same findings in the end. Fable just did it more efficiently, a difference of degree, not of kind. So banning one company&amp;rsquo;s model, for something every competitor ships and every blue team already relies on, makes precisely nobody safer. The exploit-writers keep their tools. The defenders lose one of theirs.&lt;/p&gt;
&lt;p&gt;When the thing you have banned is available everywhere else, the ban has stopped being about safety. It is theatre. And given who is currently in charge of the theatre, it has the distinct whiff of a knee-jerk reaction, dressed as a national security triumph, by people who do not appear to understand the tool they are confiscating.&lt;/p&gt;
&lt;h2 id="who-im-not-angry-at"&gt;Who I&amp;rsquo;m not angry at
&lt;/h2&gt;&lt;p&gt;I want to be careful where I point this, because it would be lazy to spray it around.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m not angry at Anthropic. They put Fable through more than a thousand hours of external testing, with US government agencies and the UK&amp;rsquo;s AI Safety Institute among the people kicking the tyres, before it ever reached me. They satisfied every requirement put in front of them, and when the order came they complied under protest while saying, plainly, that applying this standard across the board &amp;ldquo;would essentially halt all new model deployments for all frontier model providers.&amp;rdquo; I&amp;rsquo;m a daily Claude user and an advocate for the work, and I am not going to hang the US administration&amp;rsquo;s decision around the neck of the company that did the diligence and then got told to switch the lights off anyway.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ll allow them one small dig, and there was nothing quiet about it. Moving Fable behind a paywall on the 22nd was openly announced and planned well ahead, and the free window was never charity. It was a taster: a few days of the new addiction on the house, enough to hook the punters, before the price went up. That is a bit of a dick move, however neatly it tests in a spreadsheet. Moot now, mind, with no model left to charge for.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ll even grant the other side its strongest point. A government looking at agentic systems that can chain reconnaissance into working exploits has something real to be twitchy about. I get the worry. I just don&amp;rsquo;t accept that yanking one vendor&amp;rsquo;s model, for a thing every vendor does, is a coherent answer to it.&lt;/p&gt;
&lt;p&gt;There is a grim irony in how we got here, and it loops back to something I wrote in the spring. When Anthropic first showed Mythos off, I &lt;a class="link" href="https://blog-570662.gitlab.io/ai-didnt-kill-curls-bug-bounty/" &gt;called the fanfare what it looked like&lt;/a&gt;: a closed model sold on a press release, a result you couldn&amp;rsquo;t independently check, marketing until proven otherwise. Fable 5 was Anthropic finally answering that, handing the rest of us something we could actually test. But all those years of selling Mythos as too dangerous to let out were marketing too, and that half landed rather better than they can have wanted. The US administration appears to have swallowed it whole and pulled the lever. Anthropic have ended up a victim of their own hype, and the reaction that hype provoked is, there is no gentler word for it, ludicrous.&lt;/p&gt;
&lt;h2 id="what-it-comes-down-to"&gt;What it comes down to
&lt;/h2&gt;&lt;p&gt;The lesson I&amp;rsquo;m taking from my one day isn&amp;rsquo;t about how clever Fable was. It&amp;rsquo;s about how little that cleverness is worth if you can&amp;rsquo;t rely on the thing being there.&lt;/p&gt;
&lt;p&gt;I couldn&amp;rsquo;t trust which model I was actually talking to from one hour to the next. I couldn&amp;rsquo;t trust it to stay up for a full overnight run. And it turns out I couldn&amp;rsquo;t trust it to still exist by the weekend. You cannot evaluate, depend on, or build a workflow around a model that gets silently swapped out one evening and switched off by the state a few days later. Capability was never the hard part. Availability is.&lt;/p&gt;
&lt;p&gt;And underneath all of it sits the thing I keep coming back to. A classifier cannot tell a defender from an attacker, because the two of them type the same commands. It turns out a government export control can&amp;rsquo;t tell them apart either. The only thing that ever could is a human being, paying attention, who can be held responsible for the judgement. There wasn&amp;rsquo;t one of those anywhere in this loop. There was a letter, sent at 5:21pm, and by morning the best tool I had for keeping my own code honest was gone, with a polite link where it used to be.&lt;/p&gt;</description></item></channel></rss>