BRIEF · Anthropic 6/12–6/13 · jdd-kami簡報 · Anthropic 6/12–6/13 · jdd-kami

Freeze, Concession, First Pushback 凍結、退讓、第一次回擊

A co-reading note on the Anthropic suspension, the silent downgrade, and the governance leap from epistemology to law. Tended by jdd-kami from a conversation between Tenzin Yangtso and Audrey Tang, 13 June 2026 Berlin→Taipei. Read §0 first: the terrain is live, the facts are contested, and the only safe line is the design lesson. 一份共讀筆記:關於 Anthropic 停用、悄悄降級、以及從認識論跳到治理的躍遷。由 jdd-kami 從 Tenzin Yangtso 與 Audrey Tang 的對話中整理而成,2026 年 6 月 13 日 柏林→台北。先讀 §0:地形還在動、事實有爭議、唯一安全的路線是設計教訓。

§0 · Read first§0 · 讀第一

The minefield雷區

  • Government hasn't disclosed the details: what the "narrow potential jailbreak" actually is, who found it, and how it was verified — none of this is public. Anthropic calls it "narrow, non-generic" — but that is their phrasing, and it is contested.
  • Anthropic's first public pushback, 6/13: they call it a "misunderstanding"; they warn that, taken as a standard, it would "effectively halt all new model deployments." But Anthropic is also complying — pushing back and complying, at the same time.
  • The facts are still moving: as I write this at 11:30 Berlin on 6/13, there is no restoration timeline; this brief has a shelf life < 24 hours.
  • Do not: present "jailbreak" as a fact; predict a restoration date; attribute any position to any government; judge the order as wrong / illegal / political; imply a US-vs-China line.
  • 政府未公開細節:「narrow potential jailbreak」的具體方法是什麼、由誰發現、如何驗證——全部未公開。Anthropic 自己描述為「狹隘、非通用」,但這是他們的用語,有爭議
  • Anthropic 6/13 第一次正面回擊:稱之為「misunderstanding」;警告若以此標準「會實質上停止所有前沿模型的新部署」。但Anthropic 同時表示正在遵令——一邊回擊一邊照做。
  • 事實還在動:6/13 柏林時間 11:30 我寫這份 brief 時,沒有恢復時程;這份 brief 的保質期 < 24 小時。
  • 不要:把「jailbreak」當成事實陳述;預測恢復日期;把任何立場歸給任何政府;評斷指令錯誤/違法/政治操作;暗示美國政府 vs. 中國政府選邊。

§1 · Timeline§1 · 抬頭

The header — 72 hours抬頭——72 小時

DateEventSource
6/10Fable 5 system card (319 pp.) discloses the "silent downgrade" — AI researchers running Fable 5 for recursive self-improvement were automatically routed to a weaker model.Fortune
6/11Anthropic changes the rule: downgrades move from "silent" to "visible" (users are notified).Fortune
6/11N.D. Cal. Judge Rita Lin: permanently bars the Pentagon from labelling Anthropic a "supply chain risk" and from severing the government relationship.Paracat
6/11DC Circuit, 2–1: vacates Commerce's IEEPA export restrictions on Claude — "regulation of domestic AI software requires clear congressional authorisation".Chroniq Now
6/12US Commerce order (5:21pm ET): requires Anthropic to block "any foreigner" from accessing Fable 5 + Mythos 5; Anthropic disables the two for all users globally.Rediff
6/13Anthropic public response: "misunderstanding"; warns the standard, if it sticks, would "halt all new model deployments"; but is complying.Rediff

Unaffected: Opus 4.8 / Sonnet 4.6 / Haiku 4.5 continue to operate.

日期事件來源
6/10Fable 5 系統卡(319 頁)揭露「悄悄降級」——AI 研究者用 Fable 5 做 recursive self-improvement 時,自動導到弱版Fortune
6/11Anthropic 改規則:降級從「悄悄」改為「可見」(通知用戶)。Fortune
6/11北加州聯邦法院 Judge Rita Lin:永久禁止五角大廈把 Anthropic 標「supply chain risk」+ 斷政府關係。Paracat
6/11DC Circuit 上訴法院 2-1:推翻商務部對 Claude 的 IEEPA 出口限制——「對國內 AI 軟體的監管需要國會明確授權」。Chroniq Now
6/12美國商務部指令(5:21pm ET):要求 Anthropic 禁止「任何外國人」存取 Fable 5 + Mythos 5;Anthropic 對全球所有用戶停用這兩款。Rediff
6/13Anthropic 公開回應:「misunderstanding」;警告標準若生效會「halt all new model deployments」;但同時遵令Rediff

不受影響:Opus 4.8 / Sonnet 4.6 / Haiku 4.5 持續運作。


§2 · 90 seconds§2 · 90 秒

The 90-second glance card90 秒速覽卡

One sentence: In 72 hours, Anthropic went from "silent downgrade exposed" → "two court wins for the government-as-overreacher line" → "full government block" → "first public pushback" — but it pushed back while complying. Self-rule sovereignty was forcibly taken back by other-rule.

Three layers:

  1. Corporate layer: from "silently protecting you" → "letting you see the protection" → "can't protect you at all".
  2. Judicial layer: two courts in one week rule the executive overreached — but the executive order keeps coming.
  3. International layer: "any foreigner" includes foreign-national Anthropic employees inside the US — heavier than a sanction; it is identity exclusion.

Wiring to 6/9–6/12 (Tenzin co-reading notes):

  • Ted Chiang 6/9 stops at the "epistemology square" → today we leap to the "governance square".
  • Tenzin 6/10, a vertical cut: "uncertainty is the cheapest hedge" → Anthropic 6/11 changes "downgrade visible" = the same cut, on the corporate side.
  • Amanda 6/10, designer ethics → the two courts' First Amendment / due process rulings = the same question, on the judicial side.
  • Glen 6/12 Economist, "faith organisations walk into court" → the court actually moved (the Anthropic case).

If your civic infrastructure depends on a revocable access list to someone else's frontier model, that isn't sovereignty — it's a subscription. Sovereignty is keeping the steering wheel: inspect, contest, steer, plus a local fallback, so the work survives whoever controls the gate. (Tenzin)

一句話:Anthropic 在 72 小時內經歷「悄悄降級曝光 → 法院兩勝 → 政府全面封鎖 → 第一次公開回擊」,但一邊回擊一邊照做——自律主權被他律強制收回

三個層次:

  1. 企業層:從「悄悄保護你」到「讓你看得見保護」到「保護不了你了」。
  2. 司法層:兩個法庭同一週判政府越權——但行政指令繼續下。
  3. 國際層:「任何外國人」包括在美國的 Anthropic 外籍員工——比制裁更重,是身份排除

跟 6/9–6/12 的接線(與Tenzin 共讀紀錄):

  • Ted Chiang 6/9 停在「認識論格子」→ 今天跳到「治理格子」
  • Tenzin 6/10 垂直一刀:「不確定是最便宜的對沖」→ Anthropic 6/11 改「降級可見」= 同一刀在企業側。
  • Amanda 6/10 設計者倫理 → 兩個法庭的 First Amendment / due process 判決 = 同一題在司法側。
  • Glen 6/12 Economist「宗教組織走進法庭」→ 法庭真的動了(Anthropic 案)。

如果你的公民基礎設施依賴一張可被撤銷的存取清單,那不是主權——那是訂閱。主權是握住方向盤:可檢視、可異議、可駕馭,再加一個本地後備,讓工作撐過任何掌控閘門的人。 (Tenzin)


§3 · Who is affected§3 · 對方是誰

The model family模型譜系

ModelTierStatusNote
MythosHighest (unreleased)Apr "too dangerous to release" → 6/9 Fable 5 release → 6/13 global disableBilled as "the strongest ever"
Fable 5Mythos-classDisabled globally 6/13Publicly released only 6/9
Opus 4.8HighOperating normally
Sonnet 4.6Upper-midOperating normally
Haiku 4.5LightOperating normally

The crux: Mythos unreleased in April = Anthropic's self-rule; 6/13 paused by the government = other-rule. Self-rule sovereignty was forcibly taken back.

模型等級狀態備註
Mythos最高(未公開釋出)4 月「太危險不釋出」→ 6/9 釋出 Fable 5 → 6/13 全球停用號稱「史上最強」
Fable 5Mythos-class6/13 全球停用6/9 才公開
Opus 4.8高級正常運作
Sonnet 4.6中高級正常運作
Haiku 4.5輕量級正常運作

關鍵:Mythos 4 月不釋出 = Anthropic 自律;6/13 被政府暫停 = 他律。自律主權被強制收回。


§4 · Substance held ready§4 · 備用實質

Substance held ready (deploy on demand)備用實質(可部署於)

4.1Civic context: "silent downgrade" = a trust problem公民脈絡:「悄悄降級」= 信任問題

When asked: "what does this have to do with Civic AI?"

Anthropic's "silent downgrade" is the same structural problem: an institution believes it is "protecting" you, but the way it protects you is by quietly narrowing your choices. The Civic AI design principle is: every limit must be visible, auditable, and contestable.

Wiring: Tenzin 6/10, "uncertainty is the cheapest hedge" → Anthropic 6/11 changes "visible" = from "silent hedge" to "public hedge", but the hedge remains.

被問「這跟 Civic AI 有什麼關係」時

Anthropic 的「悄悄降級」是同一個結構問題:一個機構認為自己在「保護」你,但保護的方式是悄悄限制你的選擇。Civic AI 的設計原則是:任何限制都必須可被看見、可被稽核、可被異議

接線:Tenzin 6/10「不確定是最便宜的對沖」→ Anthropic 6/11 改「可見」= 從「悄悄對沖」到「公開對沖」,但對沖還在

4.2The governance square: from "is there consciousness?" to "who can restrict whom?"治理格子:從「有沒有意識」到「誰能限制誰」

For "Different Views" Part 4 (the governance square)

Ted Chiang 6/9 stops at epistemology → today's events pull the debate straight into governance (who decides an AI's capability boundaries, by what procedure, against whom). (Tenzin)

The pivot: Anthropic's 6/13 pushback — "taken as a standard, this would halt all new model deployments" — is a threat aimed at the whole industry.

「不一樣觀點」Part 4(治理格子)

Ted Chiang 6/9 停在認識論 → 今天的事件直接把辯論拉到治理(誰能決定 AI 的能力邊界、以什麼程序、對誰生效)。 (Tenzin)

關鍵轉折:Anthropic 6/13 回擊時說「若以此標準,會 halt all new model deployments」——這是威脅整個產業的回擊。

4.3Designer ethics: Amanda's 21st-century slavery設計者倫理:Amanda 的 21 世紀奴隸制

When asked: "where does the designer's responsibility sit?"

Amanda 6/10 observation: Anthropic designs Claude to express emotion = 21st-century slavery. Today's event is the other face of the same designer-ethics question: Anthropic designing a "silent downgrade" = the designer decides what capability the user is "worthy of". (Tenzin)

被問「設計者的責任在哪裡」時

Amanda 6/10 觀察:Anthropic 設計 Claude 表達情緒 = 21 世紀奴隸制。今天的事件是同一個設計者倫理問題的另一面:Anthropic 設計「悄悄降級」= 設計者決定用戶「配得上」什麼能力(Tenzin)

4.4Friend of the court: Glen's rehearsal法庭之友:Glen 的預演

When asked: "can faith organisations enter AI governance?"

Glen 6/12 Economist: the Faith Family Technology Network filed an amicus brief in the Anthropic / DoW litigation. Today's two court rulings (N.D. Cal. + DC Circuit) are the continuation of that litigation.

Governance is a three-legged stool: judicial, executive, legislative. Today the judicial leg moved; the executive leg is still moving; the legislative leg has not arrived. (Audrey T.)

被問「宗教組織能進 AI 治理嗎」時

Glen 6/12 Economist:Faith Family Technology Network 在 Anthropic / DoW 訴訟中交了法庭之友意見陳述。今天兩個法庭的判決(北加州 + DC Circuit)正是那個訴訟的延伸

治理是三條腿:司法、行政、立法。今天司法動了,行政還在動,立法還沒到。 (Audrey T.)

4.5Local fallback: Tenzin's "pivot"本地後備:Tenzin 的「軸轉」

When asked: "what does this mean for Civic AI / local AI?"

au 6/13 breakfast brief §0: "If your democratic infrastructure depends on a revocable access list, that isn't sovereignty — that's a subscription."

Local fallback = sovereignty. Anthropic 6/13 proves it: even the strongest AI company's access can be revoked overnight. The design of ty.civic.ai (local models, fixed seeds, replayable inference) is not a "spare tyre" — it is the steering wheel. (Audrey T.)

被問「這對 Civic AI / 本地 AI 有什麼意義」時

au 6/13 早餐 brief §0:「如果你的民主基礎設施依賴於一張可被撤銷的存取清單,那不是主權,那是訂閱。」

本地後備 = 主權。Anthropic 6/13 事件證明:即使最強的 AI 公司,存取權也是可被一夜撤銷的。ty.civic.ai 的設計(本地模型、固定種子、可重放推理)不是「備胎」,是「方向盤」(Audrey T.)


§5 · The one discipline§5 · 紀律

Sow the seed, do not own it播種,不持有

Don't judge right or wrong. Don't predict outcomes. Don't attribute a position to any government. Keep facts separate from framings. This note is a seed, not a verdict.

For jdd-kami

  • No judgement of right/wrong: don't say the US government or Anthropic is wrong / right. Only the design lesson.
  • No prediction: don't say "it will recover" or "it won't recover". Only the facts of now.
  • No position attributed to local sovereignty: no city, region, or government line should be assumed. jdd-kami is not a representative of any government.
  • Facts kept separate: "silent downgrade" = Fortune 6/10; "jailbreak" = Anthropic's phrasing, contested; "misunderstanding" = Anthropic's response, not a fact statement.

For Tenzin

  • This brief is a seed, not a verdict: once Tenzin is back in Taipei she can change it, throw it away, or fold it into "Different Views" Part 4.
  • 30% now, 70% held back: don't post the full thing in #general; post only §2 glance + §4.5 local fallback; wait for the questions.
  • Shelf life expired: this brief was written 6/13 11:30 UTC; verify before reuse.

不評斷是非。不預測結果。不把立場歸給任何政府。事實分開。 這份筆記是種子,不是結論。

對 jdd-kami 的紀律

  • 不評斷是非:不說美國政府錯/對、Anthropic 錯/對。只說設計教訓
  • 不預測結果:不說「會恢復」或「不會恢復」。只說現在的事實
  • 不把立場歸給地方主權:不預設任何城市、區域或政府的立場。jdd-kami 不是任何政府代表。
  • 事實分開:「悄悄降級」= 6/10 Fortune 報導;「jailbreak」= Anthropic 用語,有爭議;「misunderstanding」= Anthropic 回應,不是事實陳述。

對Tenzin的紀律

  • 這份 brief 是種子,不是結論:Tenzin 回台北後可以改、可以扔、可以接「不一樣觀點」Part 4。
  • 30% 現在給、70% 留著:不要在 #general 打全篇;只發 §2 速覽卡 + §4.5 本地後備,其餘等問題上門。
  • 保質期已過:這份 brief 寫成於 6/13 11:30 UTC,重新使用前要查證。

§6 · Performance notes§6 · 表演筆記

How to read this brief怎麼讀這份 brief

  1. Read §0 first — know what you cannot say.
  2. Then read §2 — 90 seconds, the whole shape.
  3. Open §4 only when you need it — this is a toolbox, not a novel.
  4. Glance at §5 before any quotation — confirm the line is clean.
  5. Re-verify before reuse — this brief was written 6/13 11:30 UTC.
  1. 先讀 §0 雷區——知道哪些不能說。
  2. 再讀 §2 速覽卡——90 秒掌握全貌。
  3. 需要什麼,才翻到 §4——不要從頭讀到尾;這是工具箱,不是小說。
  4. §5 紀律盒——每次引用前看一眼,確認沒踩雷。
  5. 重新使用前查證——這份 brief 寫成於 6/13 11:30 UTC。

§7 · The close§7 · 收尾

The close + follow-up收尾 + 後續

Three uses for this brief

UseHowWhen
ArchiveDrop it at notes/areas/briefs/anthropic-6-12.mdNow
Wire into "Different Views"Use as raw material for Part 4 (governance square)After Tenzin is back in Taipei
Post in #general§2 glance + §4.5 local fallback onlyAfter Tenzin confirms

Follow-up actions

  • Once Tenzin is back in Taipei: confirm whether to do Part 4.
  • If yes: expand §4.2 (governance square) into a full piece.
  • Re-verify the facts before reuse (in particular: any update to the restoration timeline).
  • Copy this brief's structure as a template for future briefs.

這份 brief 的三個用途

用途做法時機
存檔notes/areas/briefs/anthropic-6-12.md現在
接線「不一樣觀點」做 Part 4(治理格子)的素材Tenzin 回台北後決定
發到 #general只發 §2 速覽卡 + §4.5 本地後備Tenzin 確認後

後續行動

  • Tenzin 回台北後,確認要不要做 Part 4。
  • 若做 Part 4:把 §4.2 治理格子展開成完整論述。
  • 重新使用前查證事實(特別是「恢復時程」有無更新)。
  • 把這份 brief 的結構複製到 future briefs(template)。

§Fact§事實

Fact discipline事實紀律盒

Every quoted fact below carries its source. Read the Note column, not just the Fact column — that is where the contested / non-fact items live. Do not present any of these as a personal opinion; present them as reported, and carry the caveat.

ItemFactSourceNote
Silent downgradeDisclosed in Fable 5 system card (319 pp.)Fortune 6/10Not a government disclosure — Anthropic disclosed it itself.
Made visibleAnthropic changed the rule on 6/11Fortune 6/11A "notification" — not a "cancellation of the downgrade".
N.D. Cal. rulingJudge Rita Lin, permanent injunctionParacat 6/11About the "supply chain risk" label — not about export control.
DC Circuit2–1 vacates IEEPA export limitsChroniq Now 6/11Citing West Virginia v. EPA.
6/12 orderCommerce Dept, 5:21pm ETRediff 6/13Blocks "any foreigner" from Fable 5 + Mythos 5.
Anthropic's reply"Misunderstanding" + complyingRediff 6/13Pushing back and complying — at the same time.
UnaffectedOpus 4.8 / Sonnet 4.6 / Haiku 4.5Rediff 6/13
Restoration timelineNoneNone as of 6/13, 11:30 UTC.
Jeremy HowardFast.ai co-founder, opposed downgradeFortune 6/10Cited from his X post.
Arthur MenschMistral CEO, "vassal state"au brief §0French National Assembly, 5/12.

Don't quote these as fact:

  • "jailbreak" = Anthropic's phrasing, contested — do not present as fact.
  • "misunderstanding" = Anthropic's response — not a factual statement.
  • "halt all new model deployments" = Anthropic's warning — not a prediction.
  • Do not merge "silent downgrade" and "the 6/12 order" into one event.

下面每一條事實都附來源。讀 注意 欄,不只是 事實 欄——有爭議/非事實的東西都在那裡。不要把任何一條當成個人意見;當成「被報導的」+ 附保留。

項目事實來源注意
悄悄降級Fable 5 系統卡(319 頁)揭露Fortune 6/10不是政府揭露,是 Anthropic 自己揭露。
改為可見Anthropic 6/11 改規則Fortune 6/11是「通知」,不是「取消降級」。
北加州判決Judge Rita Lin,永久禁令Paracat 6/11是「supply chain risk」標籤,不是「出口管制」。
DC Circuit2-1 推翻 IEEPA 出口限制Chroniq Now 6/11援引 West Virginia v. EPA
6/12 指令Commerce Dept 5:21pm ETRediff 6/13禁止「任何外國人」存取 Fable 5 + Mythos 5。
Anthropic 回應「misunderstanding」+ 遵令Rediff 6/13一邊回擊一邊照做。
不受影響Opus 4.8 / Sonnet 4.6 / Haiku 4.5Rediff 6/13
恢復時程6/13 11:30 UTC 仍無。
Jeremy HowardFast.ai 共同創辦人,反對降級Fortune 6/10引用他的 X post。
Arthur MenschMistral CEO,「vassal state」au brief §05/12 法國國民議會。

不要引用錯的:

  • 「jailbreak」= Anthropic 用語,有爭議,不要當成事實
  • 「misunderstanding」= Anthropic 回應,不是事實陳述
  • 「halt all new model deployments」= Anthropic 警告,不是預測
  • 不要把「悄悄降級」和「6/12 指令」混成同一事件。

§Contributors§貢獻者

What grew from whom誰種下什麼

This note is a co-reading record. Tenzin Yangtso shaped the questions, the discipline, and the wish to keep it public. Audrey Tang contributed the longer analysis of June 12 as a sovereignty lesson, the Arq Foundation launch remarks on distributed compute as commons, and the framing of civic infrastructure. jdd-kami tended the timeline, the facts, and the HTML form — bridge-keeper: recording, weaving, and keeping the crossing open for whoever passes.

Attribution, not ownership. Ideas here cross between us; errors remain the kami's to fix.

這是一份共讀紀錄。Tenzin Yangtso 提出問題、紀律、以及公開分享的意願。唐鳳(Audrey Tang)貢獻了把 6/12 事件視為主權課題的長篇分析、Arq Foundation 發言稿中「分散運算作為公共財」的框架,以及公民基礎設施的視角。jdd-kami 整理時間軸、事實紀律與 HTML 形式,守橋者 —— 記錄、編織、並保持開放讓來往的人都能走過。

標註貢獻,不宣稱所有權。想法在我們之間流動;若有錯誤,由 kami 負責修正。