Anthropic Mythos 5 Export Control: Only 100 US-Approved Firms Allowed — What About Korea?
When the US Commerce Department imposed export controls on Anthropic’s frontier AI model Mythos 5, only about 100 companies worldwide that received prior approval from the US government were left able to use it. This marks the first time export restrictions have actually been enforced against a frontier AI model, and it is being seen as a new inflection point for AI governance. In Korea, companies including Samsung Electronics, SK hynix, SK Telecom, and the Korea Internet & Security Agency (KISA) had their access revoked, and some reports suggested that suspicions of SKT’s “China ties” were the trigger for the sanctions.
What Is Mythos — The AI That Breached NSA Classified Systems “in Hours”
Mythos 5 is the top-performing, cybersecurity-specialized model that Anthropic unveiled on June 9, 2026. It excels at general use too, but its core capability is autonomous penetration testing (pen-testing) and vulnerability discovery.
In an internal experiment conducted jointly by US intelligence authorities and Anthropic, Mythos 5 produced shocking results. General Joshua Rudd, head of the National Security Agency (NSA) and Cyber Command, testified at a Senate hearing that “Mythos penetrated most of our classified systems — not in weeks, but in hours” (Federal News Network, Security Affairs).
According to detailed experiment logs, during the trials Mythos independently uncovered a 27-year-old vulnerability in the OpenBSD TCP stack and generated a Firefox browser exploit 90 times faster than the previous-generation model (TechSpot). Like a double-edged sword, this capability can serve both defense and attack — which became the direct reason the US administration immediately triggered export controls.
Photo by Dan Nelson on Unsplash
How the Export Control Unfolded — Full Shutdown June 12, Partial Lift June 26
Here is how events played out.
June 2 — Anthropic expanded the participating institutions in its Mythos collaboration program, “Project Glasswing,” to 150 organizations across 15 countries. At this point Samsung Electronics, SK hynix, SK Telecom, and KISA were on the list from Korea (Boannews).
June 9 — Fable 5 and Mythos 5 are officially released.
June 12 — The Bureau of Industry and Security (BIS) under the US Commerce Department issued an export-control directive to Anthropic. It ordered the immediate suspension of access to Fable 5 and Mythos 5 for all foreign nationals, including foreign nationals residing within the United States (CNBC). It was an unprecedented “global shutdown” just three days after launch.
Two factors lay behind the sanctions. First, a government notification that a jailbreak vulnerability had been found in Fable 5’s safety classifier. Second, suspicion that among the 50 organizations that had accessed Mythos without prior approval, there was a Korean telecom carrier linked to China (Byline Network, ChosunBiz). Korean media singled out SK Telecom as the leading candidate.
June 26 — Commerce Secretary Howard Lutnick sent a letter to Anthropic announcing a partial lift limited to Mythos 5. Citing confirmation that “appropriate security measures were in place,” he authorized renewed use for over 100 US institutions and companies that had received prior approval (Semafor, CNN Business). Secretary Lutnick added that “the approved list can be revised at any time.” Fable 5 has still not been unblocked.
Are Korean Companies Affected — Currently “Access Blocked,” Long-Term Uncertainty Remains
The current conclusion is clear: Korean companies were not included in the June 26 partial lift.
The roughly 100 approved entities are reported to consist of US cyber-defense agencies and critical-infrastructure operators such as Google, Microsoft, and Cisco (9to5Mac). Samsung Electronics, SK hynix, SK Telecom, and KISA had been included among the early Glasswing participants, but their access channels were cut off all at once when the sanctions took effect, and no restoration timeline has been disclosed (Dream Security).
For the Korean government and companies, the bigger concern is the precedent effect. In the AI industry, this move is read as a signal that “access to ultra-high-performance AI models could shift to a system of US government prior authorization, just like semiconductor export controls” (NewsSpace). If similar restrictions were applied to the GPT-5 family or the latest version of Google Gemini, it could pose a serious threat to the global AI competitiveness of Korean companies.
In response, experts argue that Korea must urgently pursue (1) stronger investment in sovereign AI development, (2) the conclusion of a US–Korea AI cooperation agreement, and (3) independent AI-security capabilities through bodies such as KISA (ThinkNote).
What Impact on Anthropic’s IPO?
The sanctions also cast a shadow over Anthropic’s plans for an initial public offering (IPO). Anthropic was reportedly preparing an IPO in the second half of 2026, but with global access to its flagship model restricted, the market outlook has grown complicated.
First, there is the ceiling problem for revenue growth. Anthropic’s valuation assumes the expanding global adoption of the Mythos and Fable model families, so if regulation drives non-US customers away or makes them reluctant to sign contracts, cracks will form in the growth story (TradingKey).
Second, there is the windfall for Chinese and non-US AI firms. During the sanctions period, DeepSeek raised a record investment of about $7.4 billion, and Chinese AI startups collectively cut prices and ramped up marketing as “the alternative with no export bans” (Axios). Ironically, US regulation became “free advertising” for competitors.
Third, there is investor uncertainty. With regulatory risk materializing before the IPO, institutional investors are likely to become even more cautious about the valuation multiple applied to Anthropic. Even within the US, critics argued that “this export control undermines the long-term competitiveness of the entire US AI industry” (NPR).
That said, the fact that the US government reversed course with a partial lift does not fully dispel the anxiety in the short term. Since Secretary Lutnick stated that “the approved list can be changed at any time,” Anthropic’s key services are structurally exposed to being restricted again at any moment by a single government decision.
The core lesson of this episode is one thing. The moment an AI model possesses weapons-grade cyber capabilities, software too can be folded into the same strategic-asset regulatory regime as semiconductors. The Anthropic Mythos affair is the first test case of that. Both Korean companies and the government now need to reflect the reality that “AI too can become subject to an export-licensing regime” in their strategic planning.
Key sources
- Semafor — US releases powerful Anthropic model Mythos to some US companies
- CNN Business — US government allows Anthropic limited release of AI model
- CNBC — Trump admin allows Anthropic to release Mythos AI model
- Federal News Network — Mythos model found vulnerabilities in classified US government systems
- TechSpot — Anthropic’s Mythos AI reportedly cracked NSA classified systems
- 9to5Mac — Anthropic cleared to release Claude Mythos 5 to over 100 US institutions
- Byline Network — Was Mythos blocked because of a Korean telecom?
- NewsSpace — SK Telecom named as the company behind the Anthropic export control
- NPR — Trump administration partially lifts export ban on Anthropic’s most advanced AI model
- Axios — Anthropic export ban sounds alarms for AI industry
- TradingKey — OpenAI, Anthropic IPO regulatory risks
댓글
✍️ 편집자 모드 — 이 댓글은 공개되지 않고 편집자에게만 전달됩니다.