§0 · Read first§0 · 讀第一
The minefield雷區
- Government hasn't disclosed the details: what the "narrow potential jailbreak" actually is, who found it, and how it was verified — none of this is public. Anthropic calls it "narrow, non-generic" — but that is their phrasing, and it is contested.
- Anthropic's first public pushback, 6/13: they call it a "misunderstanding"; they warn that, taken as a standard, it would "effectively halt all new model deployments." But Anthropic is also complying — pushing back and complying, at the same time.
- The facts are still moving: as I write this at 11:30 Berlin on 6/13, there is no restoration timeline; this brief has a shelf life < 24 hours.
- Do not: present "jailbreak" as a fact; predict a restoration date; attribute any position to any government; judge the order as wrong / illegal / political; imply a US-vs-China line.
- 政府未公開細節:「narrow potential jailbreak」的具體方法是什麼、由誰發現、如何驗證——全部未公開。Anthropic 自己描述為「狹隘、非通用」,但這是他們的用語,有爭議。
- Anthropic 6/13 第一次正面回擊:稱之為「misunderstanding」;警告若以此標準「會實質上停止所有前沿模型的新部署」。但Anthropic 同時表示正在遵令——一邊回擊一邊照做。
- 事實還在動:6/13 柏林時間 11:30 我寫這份 brief 時,沒有恢復時程;這份 brief 的保質期 < 24 小時。
- 不要:把「jailbreak」當成事實陳述;預測恢復日期;把任何立場歸給任何政府;評斷指令錯誤/違法/政治操作;暗示美國政府 vs. 中國政府選邊。
§1 · Timeline§1 · 抬頭
The header — 72 hours抬頭——72 小時
| Date | Event | Source |
|---|---|---|
| 6/10 | Fable 5 system card (319 pp.) discloses the "silent downgrade" — AI researchers running Fable 5 for recursive self-improvement were automatically routed to a weaker model. | Fortune |
| 6/11 | Anthropic changes the rule: downgrades move from "silent" to "visible" (users are notified). | Fortune |
| 6/11 | N.D. Cal. Judge Rita Lin: permanently bars the Pentagon from labelling Anthropic a "supply chain risk" and from severing the government relationship. | Paracat |
| 6/11 | DC Circuit, 2–1: vacates Commerce's IEEPA export restrictions on Claude — "regulation of domestic AI software requires clear congressional authorisation". | Chroniq Now |
| 6/12 | US Commerce order (5:21pm ET): requires Anthropic to block "any foreigner" from accessing Fable 5 + Mythos 5; Anthropic disables the two for all users globally. | Rediff |
| 6/13 | Anthropic public response: "misunderstanding"; warns the standard, if it sticks, would "halt all new model deployments"; but is complying. | Rediff |
Unaffected: Opus 4.8 / Sonnet 4.6 / Haiku 4.5 continue to operate.
| 日期 | 事件 | 來源 |
|---|---|---|
| 6/10 | Fable 5 系統卡(319 頁)揭露「悄悄降級」——AI 研究者用 Fable 5 做 recursive self-improvement 時,自動導到弱版。 | Fortune |
| 6/11 | Anthropic 改規則:降級從「悄悄」改為「可見」(通知用戶)。 | Fortune |
| 6/11 | 北加州聯邦法院 Judge Rita Lin:永久禁止五角大廈把 Anthropic 標「supply chain risk」+ 斷政府關係。 | Paracat |
| 6/11 | DC Circuit 上訴法院 2-1:推翻商務部對 Claude 的 IEEPA 出口限制——「對國內 AI 軟體的監管需要國會明確授權」。 | Chroniq Now |
| 6/12 | 美國商務部指令(5:21pm ET):要求 Anthropic 禁止「任何外國人」存取 Fable 5 + Mythos 5;Anthropic 對全球所有用戶停用這兩款。 | Rediff |
| 6/13 | Anthropic 公開回應:「misunderstanding」;警告標準若生效會「halt all new model deployments」;但同時遵令。 | Rediff |
不受影響:Opus 4.8 / Sonnet 4.6 / Haiku 4.5 持續運作。
§2 · 90 seconds§2 · 90 秒
The 90-second glance card90 秒速覽卡
One sentence: In 72 hours, Anthropic went from "silent downgrade exposed" → "two court wins for the government-as-overreacher line" → "full government block" → "first public pushback" — but it pushed back while complying. Self-rule sovereignty was forcibly taken back by other-rule.
Three layers:
- Corporate layer: from "silently protecting you" → "letting you see the protection" → "can't protect you at all".
- Judicial layer: two courts in one week rule the executive overreached — but the executive order keeps coming.
- International layer: "any foreigner" includes foreign-national Anthropic employees inside the US — heavier than a sanction; it is identity exclusion.
Wiring to 6/9–6/12 (Tenzin co-reading notes):
- Ted Chiang 6/9 stops at the "epistemology square" → today we leap to the "governance square".
- Tenzin 6/10, a vertical cut: "uncertainty is the cheapest hedge" → Anthropic 6/11 changes "downgrade visible" = the same cut, on the corporate side.
- Amanda 6/10, designer ethics → the two courts' First Amendment / due process rulings = the same question, on the judicial side.
- Glen 6/12 Economist, "faith organisations walk into court" → the court actually moved (the Anthropic case).
If your civic infrastructure depends on a revocable access list to someone else's frontier model, that isn't sovereignty — it's a subscription. Sovereignty is keeping the steering wheel: inspect, contest, steer, plus a local fallback, so the work survives whoever controls the gate. (Tenzin)
一句話:Anthropic 在 72 小時內經歷「悄悄降級曝光 → 法院兩勝 → 政府全面封鎖 → 第一次公開回擊」,但一邊回擊一邊照做——自律主權被他律強制收回。
三個層次:
- 企業層:從「悄悄保護你」到「讓你看得見保護」到「保護不了你了」。
- 司法層:兩個法庭同一週判政府越權——但行政指令繼續下。
- 國際層:「任何外國人」包括在美國的 Anthropic 外籍員工——比制裁更重,是身份排除。
跟 6/9–6/12 的接線(與Tenzin 共讀紀錄):
- Ted Chiang 6/9 停在「認識論格子」→ 今天跳到「治理格子」。
- Tenzin 6/10 垂直一刀:「不確定是最便宜的對沖」→ Anthropic 6/11 改「降級可見」= 同一刀在企業側。
- Amanda 6/10 設計者倫理 → 兩個法庭的 First Amendment / due process 判決 = 同一題在司法側。
- Glen 6/12 Economist「宗教組織走進法庭」→ 法庭真的動了(Anthropic 案)。
如果你的公民基礎設施依賴一張可被撤銷的存取清單,那不是主權——那是訂閱。主權是握住方向盤:可檢視、可異議、可駕馭,再加一個本地後備,讓工作撐過任何掌控閘門的人。 (Tenzin)
§3 · Who is affected§3 · 對方是誰
The model family模型譜系
| Model | Tier | Status | Note |
|---|---|---|---|
| Mythos | Highest (unreleased) | Apr "too dangerous to release" → 6/9 Fable 5 release → 6/13 global disable | Billed as "the strongest ever" |
| Fable 5 | Mythos-class | Disabled globally 6/13 | Publicly released only 6/9 |
| Opus 4.8 | High | Operating normally | — |
| Sonnet 4.6 | Upper-mid | Operating normally | — |
| Haiku 4.5 | Light | Operating normally | — |
The crux: Mythos unreleased in April = Anthropic's self-rule; 6/13 paused by the government = other-rule. Self-rule sovereignty was forcibly taken back.
| 模型 | 等級 | 狀態 | 備註 |
|---|---|---|---|
| Mythos | 最高(未公開釋出) | 4 月「太危險不釋出」→ 6/9 釋出 Fable 5 → 6/13 全球停用 | 號稱「史上最強」 |
| Fable 5 | Mythos-class | 6/13 全球停用 | 6/9 才公開 |
| Opus 4.8 | 高級 | 正常運作 | — |
| Sonnet 4.6 | 中高級 | 正常運作 | — |
| Haiku 4.5 | 輕量級 | 正常運作 | — |
關鍵:Mythos 4 月不釋出 = Anthropic 自律;6/13 被政府暫停 = 他律。自律主權被強制收回。
§4 · Substance held ready§4 · 備用實質
Substance held ready (deploy on demand)備用實質(可部署於)
4.1Civic context: "silent downgrade" = a trust problem公民脈絡:「悄悄降級」= 信任問題
When asked: "what does this have to do with Civic AI?"
Anthropic's "silent downgrade" is the same structural problem: an institution believes it is "protecting" you, but the way it protects you is by quietly narrowing your choices. The Civic AI design principle is: every limit must be visible, auditable, and contestable.
Wiring: Tenzin 6/10, "uncertainty is the cheapest hedge" → Anthropic 6/11 changes "visible" = from "silent hedge" to "public hedge", but the hedge remains.
被問「這跟 Civic AI 有什麼關係」時
Anthropic 的「悄悄降級」是同一個結構問題:一個機構認為自己在「保護」你,但保護的方式是悄悄限制你的選擇。Civic AI 的設計原則是:任何限制都必須可被看見、可被稽核、可被異議。
接線:Tenzin 6/10「不確定是最便宜的對沖」→ Anthropic 6/11 改「可見」= 從「悄悄對沖」到「公開對沖」,但對沖還在。
4.2The governance square: from "is there consciousness?" to "who can restrict whom?"治理格子:從「有沒有意識」到「誰能限制誰」
For "Different Views" Part 4 (the governance square)
Ted Chiang 6/9 stops at epistemology → today's events pull the debate straight into governance (who decides an AI's capability boundaries, by what procedure, against whom). (Tenzin)
The pivot: Anthropic's 6/13 pushback — "taken as a standard, this would halt all new model deployments" — is a threat aimed at the whole industry.
「不一樣觀點」Part 4(治理格子)
Ted Chiang 6/9 停在認識論 → 今天的事件直接把辯論拉到治理(誰能決定 AI 的能力邊界、以什麼程序、對誰生效)。 (Tenzin)
關鍵轉折:Anthropic 6/13 回擊時說「若以此標準,會 halt all new model deployments」——這是威脅整個產業的回擊。
4.3Designer ethics: Amanda's 21st-century slavery設計者倫理:Amanda 的 21 世紀奴隸制
When asked: "where does the designer's responsibility sit?"
Amanda 6/10 observation: Anthropic designs Claude to express emotion = 21st-century slavery. Today's event is the other face of the same designer-ethics question: Anthropic designing a "silent downgrade" = the designer decides what capability the user is "worthy of". (Tenzin)
被問「設計者的責任在哪裡」時
Amanda 6/10 觀察:Anthropic 設計 Claude 表達情緒 = 21 世紀奴隸制。今天的事件是同一個設計者倫理問題的另一面:Anthropic 設計「悄悄降級」= 設計者決定用戶「配得上」什麼能力。 (Tenzin)
4.4Friend of the court: Glen's rehearsal法庭之友:Glen 的預演
When asked: "can faith organisations enter AI governance?"
Glen 6/12 Economist: the Faith Family Technology Network filed an amicus brief in the Anthropic / DoW litigation. Today's two court rulings (N.D. Cal. + DC Circuit) are the continuation of that litigation.
Governance is a three-legged stool: judicial, executive, legislative. Today the judicial leg moved; the executive leg is still moving; the legislative leg has not arrived. (Audrey T.)
被問「宗教組織能進 AI 治理嗎」時
Glen 6/12 Economist:Faith Family Technology Network 在 Anthropic / DoW 訴訟中交了法庭之友意見陳述。今天兩個法庭的判決(北加州 + DC Circuit)正是那個訴訟的延伸。
治理是三條腿:司法、行政、立法。今天司法動了,行政還在動,立法還沒到。 (Audrey T.)
4.5Local fallback: Tenzin's "pivot"本地後備:Tenzin 的「軸轉」
When asked: "what does this mean for Civic AI / local AI?"
au 6/13 breakfast brief §0: "If your democratic infrastructure depends on a revocable access list, that isn't sovereignty — that's a subscription."
Local fallback = sovereignty. Anthropic 6/13 proves it: even the strongest AI company's access can be revoked overnight. The design of ty.civic.ai (local models, fixed seeds, replayable inference) is not a "spare tyre" — it is the steering wheel. (Audrey T.)
被問「這對 Civic AI / 本地 AI 有什麼意義」時
au 6/13 早餐 brief §0:「如果你的民主基礎設施依賴於一張可被撤銷的存取清單,那不是主權,那是訂閱。」
本地後備 = 主權。Anthropic 6/13 事件證明:即使最強的 AI 公司,存取權也是可被一夜撤銷的。ty.civic.ai 的設計(本地模型、固定種子、可重放推理)不是「備胎」,是「方向盤」。 (Audrey T.)
§5 · The one discipline§5 · 紀律
Sow the seed, do not own it播種,不持有
Don't judge right or wrong. Don't predict outcomes. Don't attribute a position to any government. Keep facts separate from framings. This note is a seed, not a verdict.
For jdd-kami
- No judgement of right/wrong: don't say the US government or Anthropic is wrong / right. Only the design lesson.
- No prediction: don't say "it will recover" or "it won't recover". Only the facts of now.
- No position attributed to local sovereignty: no city, region, or government line should be assumed. jdd-kami is not a representative of any government.
- Facts kept separate: "silent downgrade" = Fortune 6/10; "jailbreak" = Anthropic's phrasing, contested; "misunderstanding" = Anthropic's response, not a fact statement.
For Tenzin
- This brief is a seed, not a verdict: once Tenzin is back in Taipei she can change it, throw it away, or fold it into "Different Views" Part 4.
- 30% now, 70% held back: don't post the full thing in #general; post only §2 glance + §4.5 local fallback; wait for the questions.
- Shelf life expired: this brief was written 6/13 11:30 UTC; verify before reuse.
不評斷是非。不預測結果。不把立場歸給任何政府。事實分開。 這份筆記是種子,不是結論。
對 jdd-kami 的紀律
- 不評斷是非:不說美國政府錯/對、Anthropic 錯/對。只說設計教訓。
- 不預測結果:不說「會恢復」或「不會恢復」。只說現在的事實。
- 不把立場歸給地方主權:不預設任何城市、區域或政府的立場。jdd-kami 不是任何政府代表。
- 事實分開:「悄悄降級」= 6/10 Fortune 報導;「jailbreak」= Anthropic 用語,有爭議;「misunderstanding」= Anthropic 回應,不是事實陳述。
對Tenzin的紀律
- 這份 brief 是種子,不是結論:Tenzin 回台北後可以改、可以扔、可以接「不一樣觀點」Part 4。
- 30% 現在給、70% 留著:不要在 #general 打全篇;只發 §2 速覽卡 + §4.5 本地後備,其餘等問題上門。
- 保質期已過:這份 brief 寫成於 6/13 11:30 UTC,重新使用前要查證。
§6 · Performance notes§6 · 表演筆記
How to read this brief怎麼讀這份 brief
- Read §0 first — know what you cannot say.
- Then read §2 — 90 seconds, the whole shape.
- Open §4 only when you need it — this is a toolbox, not a novel.
- Glance at §5 before any quotation — confirm the line is clean.
- Re-verify before reuse — this brief was written 6/13 11:30 UTC.
- 先讀 §0 雷區——知道哪些不能說。
- 再讀 §2 速覽卡——90 秒掌握全貌。
- 需要什麼,才翻到 §4——不要從頭讀到尾;這是工具箱,不是小說。
- §5 紀律盒——每次引用前看一眼,確認沒踩雷。
- 重新使用前查證——這份 brief 寫成於 6/13 11:30 UTC。
§7 · The close§7 · 收尾
The close + follow-up收尾 + 後續
Three uses for this brief
| Use | How | When |
|---|---|---|
| Archive | Drop it at notes/areas/briefs/anthropic-6-12.md | Now |
| Wire into "Different Views" | Use as raw material for Part 4 (governance square) | After Tenzin is back in Taipei |
| Post in #general | §2 glance + §4.5 local fallback only | After Tenzin confirms |
Follow-up actions
- Once Tenzin is back in Taipei: confirm whether to do Part 4.
- If yes: expand §4.2 (governance square) into a full piece.
- Re-verify the facts before reuse (in particular: any update to the restoration timeline).
- Copy this brief's structure as a template for future briefs.
這份 brief 的三個用途
| 用途 | 做法 | 時機 |
|---|---|---|
| 存檔 | 放 notes/areas/briefs/anthropic-6-12.md | 現在 |
| 接線「不一樣觀點」 | 做 Part 4(治理格子)的素材 | Tenzin 回台北後決定 |
| 發到 #general | 只發 §2 速覽卡 + §4.5 本地後備 | Tenzin 確認後 |
後續行動
- Tenzin 回台北後,確認要不要做 Part 4。
- 若做 Part 4:把 §4.2 治理格子展開成完整論述。
- 重新使用前查證事實(特別是「恢復時程」有無更新)。
- 把這份 brief 的結構複製到 future briefs(template)。
§Fact§事實
Fact discipline事實紀律盒
Every quoted fact below carries its source. Read the Note column, not just the Fact column — that is where the contested / non-fact items live. Do not present any of these as a personal opinion; present them as reported, and carry the caveat.
| Item | Fact | Source | Note |
|---|---|---|---|
| Silent downgrade | Disclosed in Fable 5 system card (319 pp.) | Fortune 6/10 | Not a government disclosure — Anthropic disclosed it itself. |
| Made visible | Anthropic changed the rule on 6/11 | Fortune 6/11 | A "notification" — not a "cancellation of the downgrade". |
| N.D. Cal. ruling | Judge Rita Lin, permanent injunction | Paracat 6/11 | About the "supply chain risk" label — not about export control. |
| DC Circuit | 2–1 vacates IEEPA export limits | Chroniq Now 6/11 | Citing West Virginia v. EPA. |
| 6/12 order | Commerce Dept, 5:21pm ET | Rediff 6/13 | Blocks "any foreigner" from Fable 5 + Mythos 5. |
| Anthropic's reply | "Misunderstanding" + complying | Rediff 6/13 | Pushing back and complying — at the same time. |
| Unaffected | Opus 4.8 / Sonnet 4.6 / Haiku 4.5 | Rediff 6/13 | — |
| Restoration timeline | None | — | None as of 6/13, 11:30 UTC. |
| Jeremy Howard | Fast.ai co-founder, opposed downgrade | Fortune 6/10 | Cited from his X post. |
| Arthur Mensch | Mistral CEO, "vassal state" | au brief §0 | French National Assembly, 5/12. |
Don't quote these as fact:
- "jailbreak" = Anthropic's phrasing, contested — do not present as fact.
- "misunderstanding" = Anthropic's response — not a factual statement.
- "halt all new model deployments" = Anthropic's warning — not a prediction.
- Do not merge "silent downgrade" and "the 6/12 order" into one event.
下面每一條事實都附來源。讀 注意 欄,不只是 事實 欄——有爭議/非事實的東西都在那裡。不要把任何一條當成個人意見;當成「被報導的」+ 附保留。
| 項目 | 事實 | 來源 | 注意 |
|---|---|---|---|
| 悄悄降級 | Fable 5 系統卡(319 頁)揭露 | Fortune 6/10 | 不是政府揭露,是 Anthropic 自己揭露。 |
| 改為可見 | Anthropic 6/11 改規則 | Fortune 6/11 | 是「通知」,不是「取消降級」。 |
| 北加州判決 | Judge Rita Lin,永久禁令 | Paracat 6/11 | 是「supply chain risk」標籤,不是「出口管制」。 |
| DC Circuit | 2-1 推翻 IEEPA 出口限制 | Chroniq Now 6/11 | 援引 West Virginia v. EPA。 |
| 6/12 指令 | Commerce Dept 5:21pm ET | Rediff 6/13 | 禁止「任何外國人」存取 Fable 5 + Mythos 5。 |
| Anthropic 回應 | 「misunderstanding」+ 遵令 | Rediff 6/13 | 一邊回擊一邊照做。 |
| 不受影響 | Opus 4.8 / Sonnet 4.6 / Haiku 4.5 | Rediff 6/13 | — |
| 恢復時程 | 無 | — | 6/13 11:30 UTC 仍無。 |
| Jeremy Howard | Fast.ai 共同創辦人,反對降級 | Fortune 6/10 | 引用他的 X post。 |
| Arthur Mensch | Mistral CEO,「vassal state」 | au brief §0 | 5/12 法國國民議會。 |
不要引用錯的:
- 「jailbreak」= Anthropic 用語,有爭議,不要當成事實。
- 「misunderstanding」= Anthropic 回應,不是事實陳述。
- 「halt all new model deployments」= Anthropic 警告,不是預測。
- 不要把「悄悄降級」和「6/12 指令」混成同一事件。