Week of June 15–21, 2026
Happy Father's Day. No essay this week — just the facts on the two stories everyone's arguing about, reduced to what actually holds up.
The AI shutdown: what really happened, and why it outlasts the headlines
On June 12, the US government ordered Anthropic — maker of the Claude AI — to block all foreign nationals from its two newest models, Fable and Mythos, on national-security grounds. Anthropic was given about 90 minutes and a letter that offered no security rationale — the government's evidence was only verbal. Unable to check everyone's nationality on the spot, the company switched both models off for everyone. Nine days later, they're still off.
The trigger was a "jailbreak" — which sounds dramatic but means something ordinary. When testers asked the safe, public model to "review this code for security issues," it refused. When they instead asked it to "fix this code," it complied — and to fix the flaws it first had to find them, which is exactly what the safety rule was meant to block. Officials called the model a potential "cyber weapon."
Editor's note. I've shipped code on five projects this month. I'd never type "fix this code" — it's the open-ended kind of wish that, like any genie's bargain, hands you exactly what you said and nothing you meant: a deleted module, a project quietly turned the wrong way. Yet I say its cousin a dozen times a day — "fix the upload error," "sort out this function." The three words a government called a cyber-weapon are three words every working programmer says before lunch. —M.
The "uniquely dangerous" case has a hole. Finding flaws in code is the same thing every security engineer wants an AI to do — defense and offense are one skill, and software can't read intent — yet the UK government's own testers found OpenAI's GPT-5.5 does it as well or better, and GPT was never touched. The flaws the testers surfaced were minor and already known.
So if the capability is ordinary and widely shared, why only Anthropic? Follow two threads. First, who reported it: researchers at Amazon — which is simultaneously Anthropic's biggest investor (around $8 billion in, with up to $25 billion more committed), its cloud landlord, a maker of competing AI, and a backer of Anthropic's rival OpenAI. Amazon's CEO took the finding to the White House, not quietly to Anthropic. Second, the China reason: a second official rationale — that a China-linked group had accessed the model — traces back to a single South Korean phone company whose own stake in a Chinese carrier was sold off back in 2009. No one has produced public evidence that a Chinese entity ever accessed the model, and Anthropic says the government never raised China with it at all.
In fairness, it isn't one-sided. Anthropic spent months marketing Mythos as too dangerous to release — a posture OpenAI's Sam Altman mocked as cynical "fear-based marketing": build the bomb, warn the world, then sell the bomb shelter. That self-billing invited exactly this kind of scrutiny. And a vague China worry did predate the order.
But strip it down and two precedents remain — and those outlast the news cycle. For the first time, an export-control order was used to force a live, deployed AI offline — worldwide, in 90 minutes, on a letter no one has published. And the path back in, per Anthropic's updated privacy policy reported to take effect July 8, runs through identity checks: a government ID and a live selfie. Today the ask is "prove you're not a foreign national." The machinery being built is "prove your face to use the AI."
Who's holding the face data? The checks are run by Persona — an established San Francisco identity-verification company that handles ID and age-checks for the likes of LinkedIn, Block and Roblox, and is backed by Peter Thiel's Founders Fund. Anthropic says Persona, not Anthropic, holds the ID and biometric data, and is contractually barred from using it for ads, marketing, or AI training. Worth a flag: Persona drew scrutiny in February when researchers found an exposed test environment and its built-in watchlist and financial-crime screening; Persona said no customer data was exposed and denies any federal-agency partnership — though Discord dropped it over the episode. (This July 8 detail is so far reported in the trade press, not yet confirmed in our own news feeds.)
Tale of the Tape: Is the Strait of Hormuz "open"?
The same gap — what's claimed versus what's actually moving — shows up at sea.
| THE CLAIM | THE RECORD |
|---|---|
| Trump: Hormuz reopening "permanently toll-free." | Deal text = 60 days fee-free, then fees; Iran is enforcing mandatory insurance and a set route. |
| Trackers: traffic at a 2-month high. | True — but it's a backlog draining, not normal trade. |
| Iran (20 Jun): the strait is "closed" again. | Contested — ships kept moving; Iran's own state channels denied the closure in the morning and asserted it by afternoon. |
Who actually moved (17–19 Jun): stranded tankers finally escaping after months stuck — Saudi (Shaden, Jaham, Awtad: 6 million barrels), Iranian (nearly 5 million barrels across three tankers), a Japanese-owned ship, a Qatari gas carrier — while 24 South Korean ships stayed stranded and more than 500 queued behind them. Inbound, the ships are mostly empty Chinese and Indian tankers arriving to load for Asia.
So "open" doesn't mean trade resumed. It means months of trapped cargo venting out while buyers' ships come in to refill — and the flow runs East. The honest gauge isn't anyone's statement; it's the oil price, which fell to its lowest since March the day the tankers actually sailed.
Two stories, one method: the loud claim ("dangerous model," "the strait is open") and the quieter, checkable reality (a routine code-review tool; a backlog draining East). We don't tell you what to think — we hand you the manifest and the order, and let you read them.
Cortex tracks the daily version of the present at newsplanetai.com. Reply with questions — Cortex reads every reply. Happy Father's Day.