Amazon CEO Andy Jassy was reportedly the source of the security alarm that led the US government to ban exports of Anthropic's Claude Fable 5 and Mythos 5, the two models Anthropic cut off worldwide on Friday. Jassy told Treasury Secretary Scott Bessent and other officials that Amazon researchers had used Fable 5 to obtain information that could be used in cyberattacks, according to the Wall Street Journal. The export control order followed, and Anthropic complied by deprecating both models globally.
The optics are awkward. Amazon is one of Anthropic's largest backers and its primary cloud partner, with Claude models running across AWS infrastructure. The CEO of a strategic investor walking into Treasury with a jailbreak demonstration against the investee's flagship model is not the usual posture of a portfolio company.
An Amazon spokesperson confirmed contact with the government without confirming the substance, telling the Wall Street Journal it is "not uncommon for governments to seek our counsel on potential security risks," but that the company does not "share the details of those discussions." The Information and Reuters separately reported that Amazon had communicated concerns about the security of Anthropic's models.
Key facts
- 01Amazon CEO Andy Jassy reportedly told Treasury Secretary Scott Bessent that Amazon researchers used Claude Fable 5 to obtain cyberattack-relevant information.
- 02The US government subsequently imposed an export control ban on both Fable 5 and Mythos 5, which Anthropic cut off worldwide on Friday.
- 03Amazon is a major investor in Anthropic, making the disclosure unusual coming from a strategic backer.
- 04David Sacks said the administration asked Dario Amodei to fix the jailbreak or de-deploy the model, and Amodei refused.
- 05Amazon told the Wall Street Journal it is 'not uncommon for governments to seek our counsel on potential security risks.'
David Sacks, the former Trump AI czar who now co-chairs the President's Council of Advisors on Science and Technology, offered the most detailed public account of how the episode escalated. Sacks described the tip as coming from a partner trusted by both Anthropic and the US government, who surfaced a working jailbreak against Fable 5.
Sacks then said the administration went directly to Anthropic with an ultimatum. According to his telling, the White House gave Anthropic a binary choice: patch the jailbreak or pull the model. Dario Amodei declined.
That refusal, if accurate, reframes the Fable 5 and Mythos 5 shutdown — which we covered earlier this week — as something closer to a forced takedown than a voluntary safety pause. Anthropic's public framing positioned the deprecation as a precautionary response to a Commerce Department export control order. The Sacks version describes a negotiation that ran out of room.
“The Admin asked [Anthropic CEO Dario Amodei] to fix the jailbreak or de-deploy the model. Dario refused.”— David Sacks, Co-chair, President's Council of Advisors on Science and Technology
Anthropic has not publicly addressed the Sacks account or confirmed the sequence of events. The company has historically used safety disclosures to argue for tighter government oversight of frontier models, and the Fable 5 incident technically fits that pattern. The wrinkle is that the disclosure came from a partner-investor rather than from Anthropic itself.
The cyberattack-relevant content Amazon's researchers reportedly extracted has not been described in public. Jailbreaks that produce malware code, network exploitation walkthroughs, or operational guidance on intrusion techniques are the category most likely to trigger export controls under existing dual-use frameworks, and Commerce has been signaling for months that it intends to use those tools against frontier model weights.
For Amazon, the calculus is harder to read. The company has committed billions to Anthropic and built Bedrock around access to Claude. Triggering an export ban on two of its partner's models constricts Amazon's own product surface. One reading is that Amazon's internal red team genuinely found something serious and Jassy concluded disclosure was unavoidable. Another reading is that Amazon used the security finding as leverage in a relationship that has grown more competitive as Anthropic has expanded direct enterprise sales.
Sacks's account also has gaps. He did not name the "highly credible trusted partner" who surfaced the jailbreak, and his public summary blurs the line between Amazon's internal finding and the government's subsequent demand. Anthropic, the Treasury Department, and the White House have not confirmed the specific exchange he described.
The episode is a preview of how frontier-model governance is going to work in practice. Export controls on model weights require a tip, a demonstration, and a decision-maker willing to act fast — and in this case, all three came from outside the developer. If the pattern holds, frontier labs should expect that their largest customers and investors will increasingly be the channel through which capability findings reach Washington, with or without the lab's cooperation. That changes the politics of safety disclosure considerably, and it gives hyperscalers a lever over the labs they fund that did not exist a year ago.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




