South Korea’s largest technology companies made a sweeping commitment to Claude Code this month, deploying it across tens of thousands of engineers at NAVER, Samsung Electronics, LG Group, Nexon, and Hanwha Solutions — the most concentrated enterprise adoption of Anthropic’s AI coding tool anywhere in Asia. Those deployments run on Claude models unaffected by the June 12 export control directive that took Anthropic’s most capable systems offline. But on day nine of that ban, testimony surfaced that explains why access to the top tier has not returned: Senator Mark Warner, vice chair of the Senate Intelligence Committee, said NSA Director Gen. Joshua Rudd told him that Anthropic’s Mythos model “broke into almost all of our classified systems, not in weeks, but in hours” during an authorized red-team exercise, according to The Economist.

That account — which The Economist’s editor later noted should not be read literally and depended on Mythos working alongside other tools in specific conditions — nonetheless reframes the dispute as something larger than the narrow jailbreak debate Anthropic has emphasized in public. A model that can autonomously identify and chain cybersecurity vulnerabilities at the speed Sen. Warner described is a qualitatively different artifact from the prior generation of dual-use AI that export control frameworks were designed to govern.

How Claude Code Spread Through Korean Industry

NAVER, Korea’s dominant internet platform and search engine, deployed Claude Code across its entire engineering organization — a rollout that Anthropic described as the largest single enterprise adoption of Claude Code in Asia. Thousands of NAVER engineers now use it as their primary AI coding tool. Samsung SDS, the IT services arm of Samsung Group, introduced both Claude Cowork and Claude Code to Samsung Electronics employees, covering knowledge work, agentic workflows, and large-scale software development. LG CNS, the tech services unit of LG Group, deployed Claude to thousands of employees for software development and client solutions and announced plans to extend the rollout group-wide.

Nexon, whose live-service games count players in the tens of millions, uses Claude Code for continuous engineering work — writing, reviewing, and shipping code on active game titles. Hanwha Solutions, the energy and chemicals arm of Hanwha Group, brought Claude to global employees through AWS Bedrock, structured to meet strict in-region data-residency requirements.

All of these deployments run on Claude Sonnet 4.6 and Opus 4.8 — the Anthropic lineup that was not affected by the June 12 directive. Claude Code operates primarily on Claude Sonnet 4.6, and that service has remained fully available throughout the ban. The models Korean institutions cannot currently access are Fable 5 and Mythos 5, the systems at the center of the export control dispute.

What the Export Ban Actually Blocks

The distinction matters for understanding what Korean enterprises gained — and lost — in the same week. Claude Code at NAVER is working exactly as announced. But the ban closed access to a different class of capability.

Mythos is Anthropic’s security-focused model, described at its April 2026 launch as the first AI system to complete both cybersecurity test ranges that the UK AI Security Institute uses to evaluate offensive hacking capability. Fable 5, launched June 9, is a version of the same underlying model equipped with safety classifiers that redirect cybersecurity queries to Opus 4.8. On June 12 — three days after Fable 5’s public launch — the Commerce Department sent Anthropic a directive under the Export Controls Reform Act of 2018, citing national security. Anthropic disabled both models for every customer worldwide to comply.

The reason the directive produced a global outage rather than a targeted one comes down to a structural gap in how export control law interacts with cloud-delivered AI. The “deemed export” doctrine under 15 CFR 734.13 treats the release of controlled technology to a foreign national inside the United States as an export to that person’s home country. The rule was originally written for semiconductor blueprints and weapons schematics — physical or static artifacts that can be inventoried and licensed individually. A cloud API endpoint serving hundreds of millions of users has no nationality field in its session tokens or request headers. There is no mechanism for Anthropic to verify, in real time, the citizenship of every user sending a query. The only way to comply with a foreign-national restriction was to shut off access for everyone.

Two Events That Triggered the Directive

Two separate developments converged to produce the June 12 ban. First, the White House learned that SK Telecom, South Korea’s largest wireless carrier and an Anthropic investor, had gained access to Mythos 5 through Project Glasswing — Anthropic’s invite-only cybersecurity consortium for vetted organizations — and that US officials suspected undisclosed ties to China. SK Telecom has denied the allegations, and the evidence has not been made public. Wired identified SK Telecom as the carrier in question; the White House subsequently asked Anthropic to revoke its Glasswing access, which Anthropic did immediately.

Second, Amazon — Anthropic’s largest investor, with a cumulative stake of approximately $13 billion — flagged a guardrail bypass in Fable 5 to the White House. Amazon CEO Andy Jassy reportedly raised the findings with administration officials directly after Amazon researchers discovered that prompting the model to read a codebase and “fix this code” against known vulnerabilities surfaced those vulnerabilities, effectively bypassing the model’s intent-classification layer. Security expert Katie Moussouris, founder of Luta Security and the only outside expert who reviewed the underlying research report, concluded that the capability exposed cannot be meaningfully fixed without weakening the model for legitimate defensive use — and that the same capability exists in other publicly available frontier models including OpenAI’s GPT-5.5.

Anthropic disputes that either event meets the threshold for recalling a commercial model deployed to hundreds of millions of users. The company said the jailbreak was narrow, non-universal, and comparable to what other frontier models can do, and that applying this standard across the industry would effectively halt all new model deployments.

What NSA Testimony Adds to the Picture

The quote Sen. Warner attributed to NSA Director Rudd — delivered in a Senate Intelligence Committee briefing on June 11, one day before the export control directive arrived — landed differently on June 21 than it did when first published by The Economist. Warner used it not to condemn Anthropic but to argue for mandatory pre-release government testing of frontier models, and to praise Anthropic for having submitted Mythos for controlled evaluation. The Economist’s editor later clarified it should not be read as a literal system breach but as a reflection of Mythos’s performance speed in a structured red-team environment.

Even with those caveats, the disclosure matters. It confirms that the US government’s concern extends beyond the narrow “fix this code” jailbreak to the underlying autonomous offensive capability of Mythos-class AI. A model that can find and chain vulnerabilities at that speed, in authorized testing against its own government’s infrastructure, is not a straightforwardly commercial product — regardless of the safety classifiers Fable 5 runs on top of it. Patching the jailbreak that triggered the June 12 directive does not address that underlying capability, and the NSA context makes a rapid restoration harder to negotiate. President Trump softened his tone about Anthropic after meeting CEO Dario Amodei at the G7 summit in Évian-les-Bains on June 17, and told Axios he no longer viewed the company as a national security threat. But the Commerce Department directive remains legally in force, and as of June 21, Fable 5 and Mythos 5 remain suspended for every user worldwide.

What Korean Enterprises Are Working With Right Now

For the thousands of engineers at NAVER, Samsung SDS, LG CNS, and Nexon who started using Claude Code in the past two weeks, the practical situation is this: the tools they are using work. Claude Code, Claude Cowork, and the full Opus 4.8 and Sonnet 4.6 lineup are fully available. Korean enterprises committed to these tools at a moment when Anthropic said its Asia-Pacific run-rate revenue had grown more than tenfold in the past year and Claude Code’s weekly active user base in Korea had expanded sixfold over four months — figures Anthropic presented at its Seoul office opening but that have not been independently verified.

What Korean engineers do not have access to is the top-tier capability Anthropic positioned as the leading edge of autonomous coding and cybersecurity work. During Fable 5’s brief availability, Stripe reported that the model completed a codebase-wide migration of a 50-million-line Ruby codebase in a single day — work that would have taken a full engineering team more than two months by hand. That benchmark captures the gap between what Korean engineers are working with now and what they were told was coming.

Anthropic’s international managing director Chris Ciauri told reporters at the Seoul opening that he was “very confident” the models would return within days. Prediction markets gave roughly a 57% probability of restoration before July 1 as of June 18. As of June 21, no restoration has been announced, and the NSA testimony circulating this weekend makes the near-term timeline harder to call.

What the Law Was Not Built to Handle

The deepest structural problem here is not a question of Anthropic’s intentions or SK Telecom’s affiliations. It is a question of whether the legal architecture that governs the export of dual-use technology was built to handle a capability delivered at consumer scale through a shared cloud endpoint.

Export control law developed around physical goods that can be tracked, licensed, and recovered. It then extended, imperfectly, to static software and technical data — artifacts that can be inventoried and restricted by recipient. Live AI inference over a cloud API has none of those properties. A query to Fable 5 and a query to Claude Sonnet 4.6 look identical to Anthropic’s infrastructure until the model responds. There is no chokepoint at which nationality can be verified, no artifact that can be recalled, and no mechanism for partial compliance short of a global shutdown. That is what happened on June 12: a legal framework designed for another era of technology produced a global outage to enforce a domestic restriction — and the first time in history a US government directive pulled a commercially deployed frontier AI model for every user on earth.

Whether the right answer is a better enforcement mechanism or a categorical access model for autonomous offensive AI capability, both answers take time. Korean enterprises, Anthropic, and their mutual commercial relationship are now waiting on that question.

Frequently Asked Questions

What Claude tools are Korean companies using, and are they affected by the export ban?

The deployments at NAVER, Samsung SDS, LG CNS, Nexon, and Hanwha Solutions all use Claude Code and Claude Cowork, which run on Claude Sonnet 4.6 and Opus 4.8. Those models were not affected by the June 12 export control directive. Korean engineers at all five companies are using fully operational tools. What Korean institutions cannot access is Fable 5 and Mythos 5 — the Anthropic models at the center of the export ban.

Why did the US ban on Fable 5 shut off access for all users worldwide, not just foreign nationals?

The Commerce Department directive barred foreign nationals from accessing both models. Because Anthropic’s cloud infrastructure has no mechanism to verify user nationality in real time — there is no nationality field in an API request — selective enforcement was technically impossible. To comply, Anthropic disabled both models for every user everywhere. The legal doctrine invoked, known as “deemed export” under 15 CFR 734.13, treats releasing controlled technology to a foreign national on US soil as equivalent to physically exporting it to that person’s home country. Designed for semiconductor blueprints and static software, that rule had never been applied to live AI inference over a cloud endpoint until June 12.

What did NSA-linked Senate testimony on June 21 reveal about the export ban?

Senator Mark Warner, vice chair of the Senate Intelligence Committee, said NSA Director Gen. Joshua Rudd told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours” in a red-team exercise on June 11. The Economist’s editor later clarified that the statement should not be read literally and depended on Mythos working alongside other tools in specific conditions. Warner used the example while praising Anthropic for responsible testing — arguing for mandatory pre-release government review of frontier models, not condemning the company. Even with those caveats, the testimony signals that the government’s concern is Mythos’s autonomous offensive capability as a whole, not only the narrow jailbreak that triggered the June 12 directive.

When is Fable 5 access expected to be restored, and what does that mean for Korean enterprises?

No official restoration date exists as of June 21. Anthropic’s international managing director said on June 18 that he was “very confident” both models would return “in the coming days,” and President Trump indicated after the G7 that he no longer viewed Anthropic as a national security threat. But the Commerce Department directive remains in force, and the NSA testimony circulating June 21 complicates near-term restoration negotiations. Korean enterprises at NAVER, Samsung, and LG are fully operational with Claude Code on Sonnet and Opus class models. Access to the Mythos-class tier — the capability that compresses months of engineering work into days — remains unavailable to them for now.