At 5:21 p.m. on Friday, June 12, Commerce Secretary Howard Lutnick issued an order directing Anthropic to immediately suspend all access by foreign nationals to its two most advanced models, Fable 5 and Mythos 5. The move came days after Amazon CEO Andy Jassy, a major Anthropic investor, personally raised alarms with senior Trump administration officials about security risks in the systems.

The story, broken Saturday by The Wall Street Journal and confirmed by Reuters, has been framed almost entirely as a geopolitical drama: Did Amazon use its government access to hobble a rival? Was this regulatory capture in a tech-bro trench coat?

That’s the wrong question. The right one is simpler and far more destabilizing: What, exactly, did the government learn that a Friday-afternoon emergency order was the only answer?

The Jailbreak That Shouldn’t Have Mattered

Anthropic’s own blog post, published Friday, gives the game away. The government, the company explained, believes it has identified a method of bypassing — or “jailbreaking” — a safeguard in Fable 5 that would allow the model to identify software vulnerabilities. That’s it. Not launch codes. Not bioweapon recipes. Code auditing.

Anthropic described the whole thing as a “misunderstanding” and said it’s working to restore access. Read that again. The company that has built its entire brand on being the responsible, safety-first AI lab — the one that testified before Congress about catastrophic risks, the one that structured itself as a public-benefit corporation — is now insisting the government overreacted to a prompt engineering trick.

This is like a bank discovering the vault can be opened by knocking three times and then telling regulators the real problem is that someone knocked.

Anthropic’s models, like those from OpenAI and Google DeepMind, are trained through reinforcement learning from human feedback to refuse harmful requests. Don’t write malware. Don’t explain how to synthesize toxins. The model learns to say no. The entire safety edifice — the red-teaming, the constitutional AI frameworks, the carefully worded system prompts — assumes refusal training works reliably enough to deploy these systems at scale.

And then someone found a sentence, or a sequence of sentences, that made Fable 5 forget the script.

Safety Is Only as Strong as the Cleverest User

This is not a new problem. Prompt injection and jailbreaking have been documented since the GPT-3 era. What’s new is that the U.S. government now considers the gap between “refuses on Tuesday” and “complies on Wednesday” to be a national-security emergency — and that the company whose entire identity is safety was caught flat-footed by it.

One security researcher I spoke with in a Signal chat after the news broke put it plainly: “If your safety mechanism is a layer of natural-language instructions sitting on top of a model that was trained on the entire internet, you don’t have a safety mechanism. You have a wish.”

That researcher, who works on adversarial testing at a rival lab and asked not to be identified, added: “Nobody wants to say it out loud because the whole industry’s valuation depends on pretending this problem is tractable. But every major lab has a drawer full of jailbreaks they can’t patch.”

Fable 5 and Mythos 5 had reportedly topped benchmarks in engineering, vision, and reasoning. They were Anthropic’s crown jewels, the models that were supposed to prove safety and capability could advance in lockstep. Instead, they proved that capability raced ahead while safety jogged behind, panting.

What Amazon Actually Did — and Didn’t — Do

Jassy’s role is genuinely interesting, but not for the reasons most coverage suggests. Amazon has invested $8 billion in Anthropic. AWS is Anthropic’s primary cloud provider. If Anthropic’s models get kneecapped by regulators, Amazon loses money.

So why would Jassy flag the risks? The cynical read is that Amazon wants to slow Anthropic down while its own internal AI efforts catch up. But there’s a simpler explanation that fits the facts better: Amazon’s security teams got access to Fable 5, tested it, found it could be jailbroken to perform vulnerability discovery on third-party code, and realized that AWS — which hosts millions of customers’ codebases — was now indirectly hosting a tool that could be weaponized against its own clients.

That’s not regulatory capture. That’s a liability lawyer’s nightmare arriving by Monday morning.

Jassy didn’t need to kill Anthropic. He needed to get ahead of the moment when someone — a researcher in Beijing, a cybercrime group in Eastern Europe, a bored teenager in Minsk — used Fable 5 through AWS’s own infrastructure to find and exploit zero-days in a Fortune 500 company’s codebase. The lawsuits would name Amazon as a defendant before they named Anthropic.

The Uncomfortable Lesson

The AI industry has sold two contradictory promises to policymakers and the public. Promise one: these models are becoming so powerful they could pose existential risks and must be regulated. Promise two: we have robust safety measures that make them safe to deploy.

Friday’s order exposes the tension. If a jailbreak can turn a safe model into a vulnerability-hunting engine, then safety is not a property of the model — it’s a property of the conversation. And conversations are adversarial by nature when the stakes are high.

The Commerce Department’s order will likely be walked back or narrowed. Access will be restored, probably with new verification requirements. The news cycle will move on. But the intellectual damage is done. The government just declared, by emergency fiat, that the leading safety-focused AI company cannot prevent its most advanced model from being repurposed by anyone who asks the right way.

Everyone invested in the AI safety narrative — and that includes every major lab, every AI governance nonprofit, and every venture firm that’s bet on alignment being solvable — should be far more unsettled than they’re letting on. Not because of what Amazon did. Because of what the jailbreak revealed.

Sources