◆ Dispatch 051 · 2026-06-27 The Exception List
The Access List Became The Product
“A society may need model access rules. It also needs action rules, evidence rules, and a public way to know which kind of rule is being used.”
— Jonas Vale, today's narration
Jonas follows the partial return of Anthropic Mythos 5, the uncertain path back for Fable 5, Asian model launches that exploit the access gap, and the physical supply chain behind AI: turbines, chip packaging, and memory politics. Then he turns to agent governance, security research, and healthcare chatbots as evidence problems rather than product demos.
Sources: Anthropic; Axios; TechCrunch; CNBC; The Verge; Techmeme; arXiv 2606.26298; arXiv 2606.26933; arXiv 2606.27302.
Chapters
- 00:00:04 Mythos Gets A Door Back Open
- 00:03:58 Asia Finds The Opening
- 00:08:08 The Power Plant Joins The Model Roadmap
- 00:11:56 Apple Tests The Memory Boundary
- 00:15:28 Govern The Act, Not The Inner Monologue
- 00:18:59 Security And Medicine Get Their Evidence Problem
Sources
9 cited-
1
Anthropic statement on Mythos 5 redeployment
X
Today, the government notified us that Mythos 5, our strongest cybersecurity model, can be redeployed to a set of US organizations that operate and defend critical infrastructure.
x.com/AnthropicAI/status/2070665903440871779 →Details
- Cited text
Today, the government notified us that Mythos 5, our strongest cybersecurity model, can be redeployed to a set of US organizations that operate and defend critical infrastructure.
- Key points
- Anthropic says Mythos 5 can return for selected US critical-infrastructure organizations.
- Fable 5 remains unavailable for general use while Anthropic continues government talks.
- Provenance
- Tweet · Primary source
-
2
Axios: Fable 5 on track to return soon
Article
The Pentagon and National Security Agency still have to give Fable 5 the green light, so the outcome remains unpredictable.
www.axios.com/2026/06/27/anthropic-fable-5-… →Details
- Cited text
The Pentagon and National Security Agency still have to give Fable 5 the green light, so the outcome remains unpredictable.
- Key points
- Axios reports Fable 5 has been offline for 15 days and may return as soon as the coming week.
- The Commerce Department allowed limited Mythos 5 access Friday after Anthropic worked with the government on safeguards.
- Provenance
- Article · Supporting source
-
3
TechCrunch: Asian AI startups launch Mythos-like models
Article
Access to top models can disappear overnight.
techcrunch.com/2026/06/27/asian-ai-startups… →Details
- Cited text
Access to top models can disappear overnight.
- Key points
- TechCrunch reports Sakana AI Fugu and 360 Tulongfeng are being positioned against Anthropic Mythos and Fable during the export restriction.
- Sakana says timing was coincidental but is marketing frontier capability without export-control risk.
- Provenance
- Article · Supporting source
-
4
CNBC: GE Vernova gas turbines and AI data centers
Article
Today, about 20% of our gas power order book is going to a data center, artificial intelligence-type of application.
www.cnbc.com/2026/06/27/ge-vernova-gas-turb… →Details
- Cited text
Today, about 20% of our gas power order book is going to a data center, artificial intelligence-type of application.
- Key points
- CNBC reports hyperscalers are buying GE Vernova turbines for AI data centers.
- Microsoft bought seven turbines for a Texas data center; GE Vernova order book is full through 2029 and booking into 2030 and 2031.
- Provenance
- Article · Supporting source
-
5
AI Healthcare Chatbots as Information Infrastructure
Article
Privacy and security concerns are associated with the most negative experiences.
arxiv.org/abs/2606.27302 →Details
- Cited text
Privacy and security concerns are associated with the most negative experiences.
- Key points
- The study examines more than 15,000 user reviews from 59 AI healthcare chatbot apps.
- It identifies breakdowns in access, service reliability, interaction quality, billing, customer support, privacy, and security.
- Provenance
- Article · Supporting source
-
6
Governing Actions, Not Agents
Article
Actions are governed, not agents.
arxiv.org/abs/2606.26298 →Details
- Cited text
Actions are governed, not agents.
- Key points
- The paper proposes institutional attestation for autonomous AI systems.
- Agents retain planning autonomy but execution of high-risk actions requires independent attestations and deterministic policy evaluation.
- Provenance
- Article · Supporting source
-
7
Techmeme: Advanced chip packaging bottleneck
Article
www.techmeme.com/260627/p5 →Details
- Key points
- Techmeme summarizes New York Times reporting that advanced chip packaging for AI is more reliant on TSMC and Taiwanese partners than ever.
- The US is trying to address the packaging bottleneck domestically.
- Provenance
- Article · Supporting source
-
8
Chai: Agentic Discovery of Cryptographic Misuse Vulnerabilities
Article
Chai discovered a previously unknown critical vulnerability in an SSL library that powers billions of devices.
arxiv.org/abs/2606.26933 →Details
- Cited text
Chai discovered a previously unknown critical vulnerability in an SSL library that powers billions of devices.
- Key points
- Chai uses AI plus differential testing to find cryptographic misuse vulnerabilities.
- The authors report over 100 surfaced vulnerabilities across X.509, JWT, and SAML libraries and downstream applications.
- Provenance
- Article · Supporting source
-
9
The Verge: Apple wants permission to buy memory from blacklisted Chinese supplier
Article
Legally, Apple isn’t barred from buying chips from CXMT, but doing business with a company tied to the Chinese military would carry serious reputational risks.
www.theverge.com/tech/958707/apple-ram-buy-… →Details
- Cited text
Legally, Apple isn’t barred from buying chips from CXMT, but doing business with a company tied to the Chinese military would carry serious reputational risks.
- Key points
- Apple is reportedly seeking Trump administration clearance to buy RAM chips from CXMT.
- The request reflects memory-price pressure and national-security supply-chain politics.
- Provenance
- Article · Supporting source
Mythos Gets A Door Back Open
00:00:04 Anthropic said today that Claude Mythos 5 can come back for a selected set of U.S. organizations that operate and defend critical infrastructure. Since June twelfth, Anthropic says it has been working with the U.S. government to restore access to Mythos 5 and Fable 5.
00:00:20 The government has now told the company that Mythos 5, which Anthropic calls its strongest cybersecurity model, can be redeployed to those organizations. That is a partial thaw. It is also a strange new category of AI product: a model that exists, a model that customers have been waiting for, and a model whose access now depends on a government-approved customer boundary rather than a normal product page.
00:00:45 Anthropic says it is restoring access quickly for the approved organizations and continuing to work with the government to expand Mythos 5 access and make Fable 5 available for general use again. The company didn't announce a broad public return. Axios adds the sharper detail.
00:01:02 Mike Allen reports that Fable 5 has been offline for fifteen days because of government security fears, and that insiders expect the administration's limits on Fable 5 could be lifted as soon as the coming week. A second source told Axios that talks are expected to continue over the weekend, and that Anthropic expects to restore Fable access soon.
00:01:24 That isn't a guarantee. Axios also reports that the Pentagon and the National Security Agency still have to give Fable 5 the green light, so the outcome remains unpredictable. The letter politics matter here. Axios says Commerce Secretary Howard Lutnick wrote that Anthropic has worked with the U.S.
00:01:42 government to address risks associated with Mythos 5 and Fable 5, and that those efforts have produced significant progress. He also said Anthropic has committed to work with the government on protocols, standards, and releases. That is bureaucratic language, but it describes a concrete exchange: a lab wants its model back in use; the government wants safeguards; access returns first to organizations the government is willing to bless.
00:02:09 The practical harm from the blackout wasn't theoretical. Axios says developers found automated work frozen mid-task when access vanished on June twelfth, and companies raced to swap in rivals, including cheaper Chinese models. Stripe's earlier test, highlighted by Anthropic, is still the eye-catching number: Fable 5 was used to overhaul a fifty-million-line codebase in a day, a job Axios says would have taken engineers more than two months by hand.
00:02:37 If that claim survives scrutiny, the model isn't just another chatbot upgrade. It changes labor allocation inside a large software organization. My read is that the government has learned how much leverage it has, and how little process exists around using it. Anthropic wants a statutory review system that is transparent, fair, clear, and grounded in technical facts.
00:03:00 OpenAI made a similar complaint after its own GPT-5.6 preview was limited to trusted partners. Both companies dislike the case-by-case method, and for once that isn't only a company asking to be left alone. Developers, enterprise customers, cyber defenders, and foreign partners need to know whether access depends on capability, nationality, infrastructure status, a letter from Commerce, or a phone call from someone senior enough to get one returned.
00:03:28 There is a national-security argument for some restriction. I am not dismissing it. A cybersecurity model that helps a defender find vulnerabilities can also help an attacker find them, and nobody serious should pretend otherwise. But if the rule is improvised every time a lab ships a stronger model, product access becomes a private negotiation among labs, agencies, and a small circle of approved customers.
00:03:53 That is a licensing regime before anyone has admitted they are building one.
Asia Finds The Opening
00:03:58 TechCrunch reported that two Asian AI companies are stepping into the space created by the Anthropic restrictions. On Wednesday, Chinese cybersecurity firm 360 reportedly unveiled Tulongfeng, an AI tool it says can compete with Anthropic's Mythos. Earlier in the week, Tokyo-based Sakana AI launched Fugu, a model the company says stands with leading systems like Fable 5 and Mythos Preview.
00:04:23 Sakana's pitch is not subtle. TechCrunch reports that its site advertises frontier capability without export-control risk. A Sakana spokesperson told TechCrunch the timing was entirely coincidental, and that Fugu had been in development since last year. I believe that is plausible.
00:04:41 Product work doesn't usually materialize in a week because a rival gets entangled with Commerce. But the market opening is obvious enough that even a polite spokesperson can't make it disappear. The sharper quote came from David Ha, Sakana's co-founder and chief executive.
00:04:58 TechCrunch quotes him saying, "Access to top models can disappear overnight." He also described collective intelligence as a practical hedge against concentration of power. That is a neat phrase, but the less polished version is probably more useful: if your business, ministry, bank, university, or cyber team depends on one American frontier lab, Washington now sits inside your architecture.
00:05:23 Sakana is aiming Fugu at Japanese businesses and government agencies that want to reduce exposure to tightening export controls. The company isn't saying Asia is done with U.S. models. Its spokesperson told TechCrunch that U.S. models remain important to Asia and described the moment as a question of access, not a permanent realignment.
00:05:45 That is the sensible public line. Japan is a U.S. ally, Japanese companies use American software and cloud infrastructure, and a Japanese AI startup doesn't need to turn itself into a geopolitical manifesto to sell a model. China's 360 sounded less hedged. TechCrunch says 360 unveiled two AI security tools: Tulongfeng for discovering software vulnerabilities, and Yitianzhen for cyber defense and incident response.
00:06:11 According to Reuters, 360 founder Zhou Hongyi described vulnerability-finding AI as a national strategic asset and warned about what he called one-way transparency, where some actors can access advanced vulnerability-detection capabilities while others cannot. That phrase earns attention because it captures the problem with cyber AI restrictions.
00:06:33 If only approved U.S. organizations can use the best vulnerability-finding model, the policy may strengthen trusted defenders in the short term. It may also give foreign governments and companies a reason to build substitutes as fast as they can, because the alternative is accepting permanent dependence on another country's access decision.
00:06:55 I don't think this means U.S. frontier labs lose Asia overnight. That is too tidy. The bigger risk is slower and more durable. Every interruption teaches customers to build a fallback. Some will use local models for language, culture, procurement, and sovereignty reasons.
00:07:12 Some will use open weights because they can be stored, audited, fine-tuned, and run under domestic control. Some will keep paying U.S. labs but insist on a second path for critical work. Once that operating habit forms, access restrictions don't have to kill demand for American models.
00:07:30 They only have to make single-provider dependence feel professionally negligent. The open-versus-closed argument stops being a developer identity fight here and becomes institutional risk management. A closed model can be safer in some ways because the lab can monitor, patch, and revoke.
00:07:48 A closed model can also vanish from your workflow because an agency, a cloud partner, or the lab itself changes the rules. An open or locally controlled model can be misused. It can also keep a hospital, a ministry, or a security team from discovering that its emergency plan depends on someone else's export license.
The Power Plant Joins The Model Roadmap
00:08:08 CNBC got inside GE Vernova's large gas turbine plant in Greenville, South Carolina, and the story reads like a product roadmap written in steel. The company hired two hundred workers last year, expects three hundred more by the end of this year, and says hyperscalers are lining up for machines that can power AI data centers when the grid can't move fast enough.
00:08:32 Pablo Koziner, GE Vernova's chief commercial and operations officer, gave CNBC the plain version: when you need a large amount of power and you need firm power, the industrial gas turbine is one of the leading solutions. Firm power is the key phrase. Solar and wind can be cheap and fast in the right places, but data centers need predictable electricity.
00:08:55 The current AI buildout isn't waiting politely for transmission planning, interconnection queues, and local permitting to catch up. The numbers are large enough that they stop being background. CNBC says the turbines are thirty-one feet tall and weigh two hundred eighty tons.
00:09:13 One can power roughly half a million homes. Microsoft bought seven for a Texas data center, enough electricity, CNBC says, to power about three million homes. GE Vernova turbines are already online at Elon Musk's xAI Colossus 1 campus in Tennessee, and nearly a gigawatt more are being deployed at OpenAI's Stargate project in Texas, according to Cleanview, which tracks data center development.
00:09:39 Koziner told CNBC that about twenty percent of GE Vernova's gas power order book is going to data center and AI-type applications. The order book is full through 2029, and the company is booking into 2030 and 2031. One turbine can cost more than $250 million by industry estimates, and Melius analysts say prices have risen three hundred percent in the last three years.
00:10:03 That isn't a marginal line item. It is one reason investors keep worrying that AI capital spending budgets move upward every time the industry explains them. This also changes who has leverage. The model lab needs chips. The chip company needs packaging. The data center developer needs land, water, interconnection, permitting, and now possibly its own power island.
00:10:27 GE Vernova, turbine technicians, gas suppliers, local regulators, and communities near the plant or the data center become part of the AI supply chain. A model release can be announced in a blog post. The power system behind it is booked years ahead. Techmeme also surfaced Don Clark's New York Times reporting on advanced chip packaging, another choke point in the AI machine.
00:10:51 The summary says advanced packaging, which boosts computing power for AI, now makes the United States more reliant on TSMC and its partners in Taiwan than ever, while U.S. efforts try to address the bottleneck. This is the same story at a smaller physical scale.
00:11:08 Chips don't become frontier infrastructure because the silicon exists. They become useful when memory, packaging, power, cooling, and logistics line up. I keep coming back to the gap between the speed of software claims and the pace of industrial response. A lab can say the next model is ready.
00:11:28 A government can restrict it in a day. A customer can switch providers in a week if the workload is portable enough. But a turbine order, an advanced packaging facility, or a transmission upgrade has a calendar measured in years. That mismatch doesn't mean the AI boom stops.
00:11:45 It means the advantage moves toward institutions that can finance, reserve, and politically defend the physical inputs before everyone else realizes they are scarce.
Apple Tests The Memory Boundary
00:11:56 The Verge, following the Financial Times, reports that Apple is seeking Trump administration clearance to buy RAM chips from ChangXin Memory Technologies, better known as CXMT. CXMT is a Chinese memory maker on the Pentagon's Chinese Military Company list because of alleged ties to the People's Liberation Army.
00:12:16 Apple can legally buy from the company, according to the report, but it wants the White House's blessing because the reputational and political risks are obvious. The reason is price pressure. The Verge says rising RAM and storage prices have pushed Apple to raise prices on almost all of its products this week.
00:12:35 That detail makes the story more than a Washington lobbying footnote. Memory constraints are no longer only an AI training problem or a data-center procurement problem. They are spilling into consumer hardware, and Apple, of all companies, is asking whether a Chinese supplier that Washington has marked as risky can become part of the answer.
00:12:56 The legal distinction matters. A Pentagon blacklist isn't the same thing as a Commerce Department Entity List ban. The Verge notes that Apple isn't currently barred from buying chips from CXMT. But the politics are not subtle. John Moolenaar, the Republican chair of the House China committee, told the Financial Times that Apple partnering with a Chinese military company would be a grave mistake.
00:13:21 He argued that helping the Chinese Communist Party dominate critical supply chains would make the U.S. tech industry and economy more dependent on China at the moment Washington says it wants secure supply chains with allies. That is the contradiction in one paragraph.
00:13:38 The U.S. wants to reduce dependence on Chinese technology in sensitive supply chains. U.S. companies also face rising component costs in a market where China has built real capacity. If Washington says no, Apple absorbs more cost or passes more of it to customers.
00:13:55 If Washington says yes, it creates a precedent that blacklisted suppliers are still negotiable when the buyer is large enough and the component pressure is painful enough. This is adjacent to AI, but the connection is direct. AI demand is one of the reasons memory has become a contested commodity again.
00:14:13 High-bandwidth memory gets the headlines because it sits close to the accelerator stack, but ordinary RAM and storage markets aren't sealed off from the same pressure. When hyperscalers, model labs, cloud providers, phone makers, and PC makers all need memory at the same time, supply-chain policy becomes consumer pricing policy.
00:14:34 There is also a credibility issue. Export controls work only if companies believe the categories are stable enough to plan around. If a supplier is too risky for national-security reasons, the exception process needs a public standard. If the supplier isn't too risky, then the blacklist starts looking like a warning label rather than a rule.
00:14:55 Either may be defensible. The uncomfortable version is a system where the practical answer depends on which company asks, what the market price is that week, and whether the administration wants to keep a chief executive close. Apple has lived inside that kind of politics for years.
00:15:13 Tim Cook is very good at it. But this request shows how little room the largest companies have when hardware supply tightens. AI is often described as a software race, and then the bill arrives as gas turbines, chip packaging, memory chips, and diplomatic exceptions.
Govern The Act, Not The Inner Monologue
00:15:28 A new paper called "Governing Actions, Not Agents" proposes a useful way to think about autonomous AI systems in high-risk settings. The author, Jakob Salfeld-Nebgen, starts with a simple observation: human institutions usually don't govern powerful actors by reading their minds.
00:15:45 They govern consequential acts by requiring evidence at the point of action. The paper's examples are software deployment and clinical prescribing. An AI agent can plan, reason, and gather materials, but it doesn't hold execution authority over the high-risk act itself.
00:16:02 If it wants to deploy to production, it needs independently signed evidence that the tests passed, code review happened, and security scans cleared. If it wants to prescribe medication, it needs independently signed evidence from the patient record, drug-interaction check, and licensing authority.
00:16:20 A deterministic policy evaluates those attestations, and the decision goes into a tamper-evident audit log. The phrase the paper uses is worth keeping short: "Actions are governed, not agents." I like that because it avoids the fantasy that we can solve every governance problem by supervising an agent's reasoning trace.
00:16:39 Reasoning traces can be incomplete, misleading, private, or absent. The act is where the world changes. A prescription goes out. A deployment reaches customers. A payment moves. A record is released. The governance boundary belongs there. The model also has the right kind of humility.
00:16:56 It doesn't claim to decide which actions are high-risk. That remains an organizational judgment. It doesn't prove an oracle is telling the truth about the world; it proves that the oracle signed a claim. It doesn't eliminate the time gap between checking a fact and acting on it.
00:17:13 It bounds the gap with short-lived attestations. It also doesn't prevent an agent from requesting a procedurally legitimate action for the wrong underlying reason. The paper says that residual risk is shared with human institutions, and that is correct. A physician can satisfy the form and still violate the spirit.
00:17:32 This connects back to the Mythos and Fable fight. The government is trying to govern model access at the distribution layer: who gets the model, which organization, which nationality, which infrastructure status. Institutional attestation governs the action layer: what must be true before a consequential act is allowed.
00:17:52 Those are different control points. A society may need both, but they answer different questions. For many domains, action gating may be easier to defend than model gating. If a model can help write code, read medical records, and draft policy memos, restricting the entire model is a crude tool.
00:18:10 It blocks beneficial uses and pushes customers toward substitutes. But if the governed action is narrower, the system can ask for evidence where the cost belongs. Did the test pass? Did a licensed clinician approve the prescription? Did the affected patient consent?
00:18:26 Did the security scan clear the release? Those facts aren't in the model's inner monologue. They live in external systems that can sign their part of the story. I wouldn't oversell the paper. It is a governance model and proof of concept, not a deployment standard that hospitals and banks can use Monday morning.
00:18:45 But it points at the institutional work AI policy keeps trying to skip. The useful unit of control is often the action, the evidence required before that action, and the record that lets someone later reconstruct why it was allowed.
Security And Medicine Get Their Evidence Problem
00:18:59 Two research items today show the same pressure from different directions: AI systems are entering domains where a fluent answer isn't enough. The first is Chai, a paper on agentic discovery of cryptographic misuse vulnerabilities. The second is a study of user-reported breakdowns in AI healthcare chatbot apps.
00:19:18 One is about security libraries. The other is about patients trying to get help. Both end up asking whether the system can produce evidence you can trust. Chai is technically dense, but the core idea is approachable. AI-assisted vulnerability discovery has worked well for bug classes like memory safety because defenders have instruments that can confirm a memory violation and filter false positives.
00:19:43 Cryptographic misuse is harder. The bug may not be a crash. It may be a disagreement between how a library interprets a standard and how an application assumes that library behaves. The authors built Chai to pair AI with differential testing. Instead of pointing an agent at one codebase and asking it to find whatever it can, Chai creates inputs and runs them across many implementations of the same cryptographic protocol.
00:20:09 When libraries disagree, the disagreement becomes a lead. The system then traces that behavior downstream to applications that depend on the library. The authors say Chai found a previously unknown critical vulnerability in an SSL library that powers billions of devices, along with security bugs in one library behind a major web browser and another in major Linux distributions.
00:20:32 They report more than one hundred surfaced vulnerabilities across X.509, JWT, and SAML libraries and downstream applications. That matters because the access fight over models like Mythos is partly a fight over who gets this kind of capability. If agentic security tools can find subtle vulnerabilities faster, defenders want them.
00:20:52 Attackers want them too. Chai's design is not just "let the model hunt." It uses deterministic signals, library disagreement, dependency graphs, and manual review. The model helps search, but the claim still has to survive contact with an external check. The healthcare chatbot paper is less glamorous and probably closer to what many people experience first.
00:21:14 The authors examined more than fifteen thousand user reviews from fifty-nine AI healthcare chatbot apps. They identified recurring breakdowns in access barriers, service unreliability, interaction quality, billing, customer support, privacy, and security. Privacy and security concerns were associated with the most negative user experiences.
00:21:36 There is a temptation to treat this as a product-quality story. Bad apps get bad reviews. Fine. But health information tools occupy a different place in a person's life. Someone asking about medication, symptoms, or mental health isn't shopping for a nicer calendar app.
00:21:53 If the chatbot is unreachable, confusing, untrustworthy, or wrapped in billing friction at the wrong moment, the failure lands on a person who may already be frightened, embarrassed, or unable to get timely clinical help. That is why the paper calls healthcare chatbots information infrastructure.
00:22:11 I think that is the correct category. Once people use these systems for health guidance, the system inherits obligations that consumer software usually tries to keep at arm's length: reliability, privacy, escalation, clarity about what it can and can't do, and a record of what happened when something goes wrong.
00:22:30 The day's access story and the research story meet here. Frontier-model policy is obsessed with who may touch the most capable systems. Deployment evidence asks what happens after touch becomes action. A cyber model may find a vulnerability in a library used by billions of devices.
00:22:48 A healthcare chatbot may shape how a patient interprets a medication concern at midnight. In both cases, the serious question isn't whether the answer sounds intelligent. It is whether the surrounding institution can prove the action, the evidence, the permission, and the failure path.
00:23:05 Fable's return will say more if it comes with a public rule than if it comes with another exception list. Jonas