New reporting from the Wall Street Journal reveals that Amazon’s cybersecurity research, followed by direct conversations between CEO Andy Jassy and the White House, triggered the sudden export control directive that forced Anthropic to restrict access to its Fable 5 and Mythos 5 models. The move, which barred foreign nationals—including many of Anthropic’s own researchers—from using the models, marks an extraordinary escalation in the US government’s approach to AI model security and has reignited tensions between Anthropic and the Trump administration.
The Research That Sparked the Directive
According to the report, a paper produced by Amazon’s security team demonstrated that through a carefully sequenced set of prompts, researchers were able to elicit responses from Fable 5 that could be repurposed to assist in cyberattacks. The White House acted swiftly after Jassy presented the findings, issuing a directive that effectively blocked the models from being accessed by foreign nationals. The irony was immediate: many of Anthropic’s own researchers are foreign-born, meaning the company had to bar its own staff from working with the product they had helped build.
Amazon has not yet responded to requests for comment on the research or its role in the policy decision.
Anthropic Disputes the “Jailbreak” Label
In a formal statement, Anthropic pushed back against the government’s characterization of the findings, arguing that the demonstrated vulnerabilities do not constitute a true jailbreak. The company further contends that similar weaknesses can be reproduced using other publicly available models, including GPT 5.5, suggesting that the issue is not unique to its systems.
Several security researchers appear to support Anthropic’s interpretation. Katie Moussouris, founder and CEO of LutaSecurity, posted on BlueSky that she had reviewed the paper and concluded that “It’s not a jailbreak.” This distinction matters: a true jailbreak implies bypassing safety guardrails entirely, whereas the Amazon research appears to have exploited subtler, prompt-based pathways that other models also exhibit.
A Pattern of Escalating Tensions
Kate Koren, a former Commerce Department official, speculated to the WSJ that the White House’s existing friction with Anthropic may have influenced the severity of the response. The company and the Trump administration have been at odds for months, primarily over Anthropic’s refusal to allow its AI to be used for mass surveillance of American citizens or to power lethal autonomous weapons.
In February, the administration directed federal agencies to stop using Anthropic’s AI entirely. Hours later, Secretary of Defense Pete Hegseth designated the company a supply chain risk. Both actions appeared to stem from Anthropic’s insistence on ethical use restrictions that the government found unacceptable.
After a period of apparent reconciliation—during which the two sides worked together to expand access to Mythos through Project Glasswingaa—the relationship now appears headed for another confrontation. The export control directive represents a significant reversal of that thaw.
Why This Matters for the AI Industry
The incident raises several critical questions for developers and enterprise users of large language models. First, it demonstrates that model access can be revoked suddenly based on security assessments conducted by third parties, not just by the model developer itself. Companies building workflows on top of models like Fable 5 and Mythos 5 now face real geopolitical risk to their access.
Second, the situation underscores a growing tension between national security objectives and the practical realities of AI development, where global talent pools are essential. If foreign-born researchers at major AI labs cannot access their own models, the US risks undermining the very innovation ecosystem the export controls are meant to protect.
Third, this episode signals that the definition of a “jailbreak” is itself becoming a contested policy question. If techniques that produce harmful outputs through complex prompt sequences are treated as security breaches warranting government intervention, the bar for regulatory action may be far lower than many in the industry anticipated.
What to Watch Now
For professionals working with Anthropic’s models, the immediate takeaway is that access remains fragile and policy-driven. Anyone relying on Fable 5 or Mythos 5 for production workloads should evaluate alternative models and document their prompt security practices in case the regulatory environment shifts again. Meanwhile, the broader industry should monitor whether the administration’s actions against Anthropic become a template for export controls on other frontier models, particularly those trained by companies with strong ethical use policies. The technical debate over what constitutes a genuine jailbreak versus a prompt-based exploit is no longer academic—it may determine which models remain available and to whom.