The Trump administration released a long-anticipated executive order this month aimed at exercising oversight of cybersecurity risks posed by the most advanced artificial intelligence models. The order attempts to thread the needle between the administration’s anti-regulatory posture and the recognition that it cannot remain on the sidelines in the face of AI’s serious risks to national security. Last week’s chaotic federal ban on foreigners from using Anthropic’s new Claude Fable 5, however, may have provided a preview of how the administration’s regulation of AI will play out, and many questions remain. Fable 5 is the publicly accessible version of Claude Mythos 5, a large language model the company released in April 2026 that is capable of identifying security flaws in software systems. The model can help governments, banks, utilities, hospitals, and other providers of essential services detect and patch the holes. But bad actors could also use this capability to exploit these weaknesses to freeze payment networks, shut down hospitals, and take telecommunications and internet services offline. The release of Mythos was part of the motivation behind President Trump’s order, which establishes a voluntary process for AI developers to submit their models to the government for classified testing for a period of up to 30 days, after which they can release the model to other trusted partners. The order also creates an “AI security clearinghouse” that fosters collaboration between AI developers and operators of critical infrastructure to identify and patch software vulnerabilities. The administration’s newfound openness to AI safeguards will not by itself undo the evisceration and politicization of regulatory agencies that are now expected to shoulder the responsibility of testing, mitigating, and overseeing a rapidly evolving threat landscape. Testing and threat sharing alone will not head off a cybersecurity catastrophe. Achieving that will also depend on how the administration