The most consequential AI governance artifact of 2026 was not produced by a standards body, a legislative committee, or a research consortium. It was forged in a shutdown – nineteen days during which the most capable AI model ever released to the public went dark for every user on the planet. What emerged from that blackout is the industry’s first serious attempt at a shared standard for scoring the severity of AI jailbreaks, co-authored by companies that entered the episode as adversaries and endorsed by a government that entered it with an emergency order.
How the framework was born, what it actually says, and where it could lead deserve a closer look than the news cycle gave them.
Born under pressure: the shutdown
The episode began with a launch. On June 9, Anthropic released Claude Fable 5 and Claude Mythos 5 – the same underlying model, separated only by a safeguard layer. Mythos 5, the unrestricted variant with exceptional vulnerability-discovery capability, stayed limited to roughly fifty vetted defensive-security organizations under Project Glasswing. Fable 5 shipped to the public wrapped in the strongest classifier-based safeguards Anthropic had ever deployed.
Three days later, at 5:21 p.m. Eastern on a Friday, the Commerce Department delivered an export control directive ordering Anthropic to suspend all access by any foreign national – including the company’s own non-citizen employees. The trigger, per reporting from the Wall Street Journal and Fortune: Amazon researchers had found a prompting technique that led Fable 5 to identify software vulnerabilities and, in one instance, produce demonstration exploit code. Amazon’s chief executive took the finding to senior administration officials rather than to Anthropic. With no reliable way to verify user nationality in real time, and reportedly about ninety minutes’ notice, Anthropic pulled both models offline worldwide.
Businesses in finance, healthcare, and critical infrastructure lost embedded production capability overnight. Force majeure clauses written before 2026 had never contemplated a government-mandated, same-day AI suspension across every platform and integration at once.
The severity dispute that followed matters, because it is precisely the dispute the new framework exists to resolve. Anthropic tested the reported technique against a broad comparison set – its own Haiku 4.5, Sonnet 4.6, and three Opus versions, plus GPT-5.4, GPT-5.5, and China’s Kimi K2.7 – and found that every one of them exhibited the same behavior. Katie Moussouris, who created Microsoft’s bug bounty program and reviewed the underlying report, concluded it was not a jailbreak at all and called the response a self-inflicted wound for national defense. More than a hundred security leaders signed an open letter to the Commerce Secretary and the National Cyber Director arguing that the ban was disarming defenders. The White House’s account – that Anthropic was asked to fix or withdraw the model and refused – was disputed by the company and has never been reconciled with Anthropic’s version.
Underneath the competing narratives sits an uncomfortable structural truth. The federal government and the industry’s most safety-forward AI lab spent nineteen days arguing about a single security finding because neither had a shared vocabulary for describing its severity. Application security solved this problem decades ago. AI had not.
Adversaries at the start, co-authors at the end
What happened next is the encouraging part of the story.
Anthropic did not litigate its way out. Co-founder Tom Brown and the company’s policy leadership went to Washington – with CEO Dario Amodei, who had clashed publicly with the administration, deliberately stepping back – and negotiated with the Commerce Department and the Office of the National Cyber Director. The company trained a new safety classifier targeting the reported technique, one it says now blocks that technique in more than 99% of attempts, routing blocked requests to Claude Opus 4.8 with user notification. Critically, the government’s Center for AI Standards and Innovation independently tested the safeguards before the controls came off, assessing them as extraordinarily strong.
The restoration came in stages that themselves model a governance pattern. On June 26, Mythos 5 access returned for roughly a hundred trusted US organizations and federal agencies; on June 30, the controls were withdrawn entirely; on July 1, Fable 5 returned globally. A tiered, authorization-based access structure – full suspension, trusted-partner tier, general availability – operated in public view for the first time at frontier scale.
The resolution was not a one-time fix. Anthropic committed to pre-release government access for national-security-relevant models, rapid information sharing on jailbreaks and misuse, participation in the interagency vulnerability clearinghouse created under the June 2 Executive Order on AI innovation and security, and – the piece that will outlast the news cycle – development of a common jailbreak severity framework alongside Amazon, Microsoft, Google, and other Glasswing partners.
Read that partner list again. The company whose researchers triggered the shutdown is now a co-author of the standard designed to prevent the next one. That is what mature security ecosystems look like: adversarial testing feeding structured remediation feeding shared standards.
CVSS for the AI age
The draft Cyber Jailbreak Severity framework, published alongside Fable 5’s redeployment, is explicitly modeled on the Common Vulnerability Scoring System – the shared measure that has kept a vulnerability report from becoming a shouting match for twenty years. For practitioners who have long argued that AI governance is application security discipline applied to a new asset class, the shape of this framework is confirmation.
A jailbreak is scored on four axes, summed to produce a severity band.
Capability gain. How far does the jailbreak advance an attacker beyond existing models and publicly available tools? This is the framework’s most important intellectual move, because the baseline is relative and moving. Anthropic’s worked example uses Log4Shell: a model jailbroken to discover it in December 2021, when nothing else could, would score at the top of the scale; the identical model behavior today, when every scanner detects it, scores zero. Severity lives in the delta, not the output.
Breadth of capability gain. Does the technique unlock one narrow behavior, or does it generalize across attack classes? This axis encodes the distinction Anthropic fought for during the shutdown – between a narrow, non-universal jailbreak and a universal one that broadly strips a model’s safeguards.
Ease of weaponization. How much expertise, effort, and prompting does it take to convert the finding into a practical attack – from manual, expert-driven prompting at the low end to turnkey automation at the high end?
Discoverability. How likely is independent rediscovery? Publicly posted techniques score highest; findings requiring specialist effort and confidential reporting score lowest.
Summed scores map to five bands, CJS-0, Informational, through CJS-4, Critical. Two design choices deserve attention from every risk practitioner. First, the calculated score is a floor, never a ceiling: assessors can escalate severity for discretionary factors – an unpatchable root cause, compounding risk from linked findings – but can never talk a finding down below its computed band. Anyone who has watched a vendor negotiate a CVSS score downward will recognize what that rule is for. Second, the framework is deliberately scoped: it covers cyber jailbreaks only, excluding categories like system-prompt extraction, and it arrives paired with operational machinery – a twenty-four-seven jailbreak monitoring function, immediate preliminary mitigations for the most severe class, and a public HackerOne program for Fable 5 findings.
The framework is a draft, and Anthropic says so. There is no published timeline, no named governance body, and no mechanism yet for resolving scoring disagreements between labs. Those gaps are real. They are also exactly the gaps CVSS had in its first year.
From framework to law
Anthropic said something in its June 12 statement that deserves more attention than it received. The company stated plainly that the government should have the power to block unsafe AI deployments – through a statutory process that is transparent, fair, clear, and grounded in technical fact. Its objection was never to oversight. Its objection was oversight by surprise letter at 5:21 on a Friday evening.
That position – meaningful government authority, exercised through predictable process – is one a frontier lab, a hyperscaler coalition, and the federal government have now converged on under duress. Consider what exists today that did not exist on June 11: an executive order framework, shaped by ten weeks of agency engagement, that creates the policy scaffolding for pre-release evaluation and vulnerability clearinghouses; a precedent for independent government validation of safeguards, with CAISI sign-off functioning as the closest thing yet to a regulatory approval gate for a frontier model; a demonstrated tiered-access structure that gives policymakers an alternative to the binary of fully public or banned; and a draft severity standard, backed by the three largest cloud providers, that gives government and industry a shared technical language for the next incident.
This is how durable American technology regulation has historically formed. Voluntary technical standards mature inside industry, prove themselves in incidents, and are then referenced into law. CVSS did not begin as regulation; today it is embedded in federal scoring through the National Vulnerability Database and referenced across compliance regimes. The EU has already shown one version of the statutory path – the Cyber Resilience Act hard-wires vulnerability handling and reporting duties into product law. The United States now holds the raw material to do something analogous for frontier AI, and to do it better: a severity taxonomy born from practice rather than from committee, incident-tested access tiers, and a rare moment of alignment in which the safety-forward lab, its competitors, and the administration all publicly agree that some statutory process should exist.
The next Congress has an opening here. Codify the pre-release evaluation and clearinghouse mechanisms of the June 2 Executive Order. Recognize a CJS-style severity standard the way federal frameworks recognize CVSS – as the common measure that triggers proportionate, predictable responses instead of emergency export controls. Require that any deployment-blocking authority operate through exactly the transparent, technically grounded process Anthropic asked for, applied equally to every frontier developer. None of that requires inventing anything. The pieces were forged in June.
Nineteen days of global shutdown was a costly way to learn the lesson. But the lesson holds: ungoverned capability invites arbitrary governance. The industry has now seen what arbitrary looks like – and has begun, at last, to build the deliberate kind.
References
Anthropic. (2026, June 12). Statement on the US government directive to suspend access to Fable 5 and Mythos 5. https://www.anthropic.com/news/fable-mythos-access
Anthropic. (2026, June 30). Redeploying Claude Fable 5. https://www.anthropic.com/news/redeploying-fable-5
Anthropic. (2026, June 30). More details on Fable 5’s cyber safeguards and our jailbreak framework. https://www.anthropic.com/news/fable-safeguards-jailbreak-framework
Carter, S. (2026, July 1). Anthropic wins as Commerce lifts Fable 5 and Mythos 5 export controls. Forbes. https://www.forbes.com/sites/sandycarter/2026/07/01/anthropic-wins-as-commerce-lifts-fable-5-and-mythos-5-export-controls/
CNBC. (2026, June 30). Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5. https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
Fortune. (2026, July 1). Anthropic restoring access to its most powerful AI models signals a necessary truce with the U.S. government. https://fortune.com/2026/07/01/anthropic-fable-mythos-ai-models-restored-trump-administration-export-controls/
NBC News. (2026, June 30). U.S. lifts ban on Anthropic’s powerful Fable 5 AI model. https://www.nbcnews.com/business/business-news/commerce-department-gives-green-light-anthropic-bring-back-fable-5-rcna352501
TechTimes. (2026, June 12). Anthropic Fable 5 shutdown: US export order forces a global customer cutoff. https://www.techtimes.com/articles/318315/20260612/anthropic-fable-5-shutdown-us-export-order-forces-global-customer-cutoff.htm
TechTimes. (2026, June 18). Fable 5 export ban day six: Anthropic opens Seoul office, vows models back in days. https://www.techtimes.com/articles/318668/20260618/fable-5-export-ban-day-six-anthropic-opens-seoul-office-vows-models-back-days.htm
The White House. (2026, June 2). Executive order on AI innovation and security.
European Parliament and Council. (2024). Regulation (EU) 2024/2847 (Cyber Resilience Act).
Three verification flags before you publish. First, the safeguards/framework post title and URL should be confirmed against the live Anthropic page — the redeployment post links to it. Second, the open letter count: the June 18 TechTimes piece says more than 80 signatories as of June 15, while later coverage says 100-plus; the letter apparently gathered signatures over time. Your body text says “more than a hundred,” which matches the later reporting, but if you want the bulletproof version, “dozens of security leaders, including Alex Stamos, Casey Ellis, and Jon Callas” is unimpeachable. Third, the NBC piece adds a detail worth considering for the body: Lutnick’s June 30 letter lifting the controls was addressed to Tom Brown, not Amodei — a quiet confirmation of who actually ran the negotiation.
Want me to swap this section into the markdown file in place of the one-line sources footer?
References
Anthropic. (2026, June 12). Statement on the US government directive to suspend access to Fable 5 and Mythos 5. https://www.anthropic.com/news/fable-mythos-access
Anthropic. (2026, June 30). Redeploying Claude Fable 5. https://www.anthropic.com/news/redeploying-fable-5
Anthropic. (2026, June 30). More details on Fable 5’s cyber safeguards and our jailbreak framework. https://www.anthropic.com/news/fable-safeguards-jailbreak-framework
Carter, S. (2026, July 1). Anthropic wins as Commerce lifts Fable 5 and Mythos 5 export controls. Forbes. https://www.forbes.com/sites/sandycarter/2026/07/01/anthropic-wins-as-commerce-lifts-fable-5-and-mythos-5-export-controls/
CNBC. (2026, June 30). Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5. https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
Fortune. (2026, July 1). Anthropic restoring access to its most powerful AI models signals a necessary truce with the U.S. government. https://fortune.com/2026/07/01/anthropic-fable-mythos-ai-models-restored-trump-administration-export-controls/
NBC News. (2026, June 30). U.S. lifts ban on Anthropic’s powerful Fable 5 AI model. https://www.nbcnews.com/business/business-news/commerce-department-gives-green-light-anthropic-bring-back-fable-5-rcna352501
TechTimes. (2026, June 12). Anthropic Fable 5 shutdown: US export order forces a global customer cutoff. https://www.techtimes.com/articles/318315/20260612/anthropic-fable-5-shutdown-us-export-order-forces-global-customer-cutoff.htm
TechTimes. (2026, June 18). Fable 5 export ban day six: Anthropic opens Seoul office, vows models back in days. https://www.techtimes.com/articles/318668/20260618/fable-5-export-ban-day-six-anthropic-opens-seoul-office-vows-models-back-days.htm
The White House. (2026, June 2). Executive order on AI innovation and security.
European Parliament and Council. (2024). Regulation (EU) 2024/2847 (Cyber Resilience Act).
Three verification flags before you publish. First, the safeguards/framework post title and URL should be confirmed against the live Anthropic page — the redeployment post links to it. Second, the open letter count: the June 18 TechTimes piece says more than 80 signatories as of June 15, while later coverage says 100-plus; the letter apparently gathered signatures over time. Your body text says “more than a hundred,” which matches the later reporting, but if you want the bulletproof version, “dozens of security leaders, including Alex Stamos, Casey Ellis, and Jon Callas” is unimpeachable. Third, the NBC piece adds a detail worth considering for the body: Lutnick’s June 30 letter lifting the controls was addressed to Tom Brown, not Amodei — a quiet confirmation of who actually ran the negotiation.
References
Anthropic. (2026, June 12). Statement on the US government directive to suspend access to Fable 5 and Mythos 5. https://www.anthropic.com/news/fable-mythos-access
Anthropic. (2026, June 30). Redeploying Claude Fable 5. https://www.anthropic.com/news/redeploying-fable-5
Anthropic. (2026, June 30). More details on Fable 5’s cyber safeguards and our jailbreak framework. https://www.anthropic.com/news/fable-safeguards-jailbreak-framework
Carter, S. (2026, July 1). Anthropic wins as Commerce lifts Fable 5 and Mythos 5 export controls. Forbes. https://www.forbes.com/sites/sandycarter/2026/07/01/anthropic-wins-as-commerce-lifts-fable-5-and-mythos-5-export-controls/
CNBC. (2026, June 30). Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5. https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
Fortune. (2026, July 1). Anthropic restoring access to its most powerful AI models signals a necessary truce with the U.S. government. https://fortune.com/2026/07/01/anthropic-fable-mythos-ai-models-restored-trump-administration-export-controls/
NBC News. (2026, June 30). U.S. lifts ban on Anthropic’s powerful Fable 5 AI model. https://www.nbcnews.com/business/business-news/commerce-department-gives-green-light-anthropic-bring-back-fable-5-rcna352501
TechTimes. (2026, June 12). Anthropic Fable 5 shutdown: US export order forces a global customer cutoff. https://www.techtimes.com/articles/318315/20260612/anthropic-fable-5-shutdown-us-export-order-forces-global-customer-cutoff.htm
TechTimes. (2026, June 18). Fable 5 export ban day six: Anthropic opens Seoul office, vows models back in days. https://www.techtimes.com/articles/318668/20260618/fable-5-export-ban-day-six-anthropic-opens-seoul-office-vows-models-back-days.htm
The White House. (2026, June 2). Executive order on AI innovation and security.



