The United States government has accused Anthropic of releasing a frontier AI model without waiting for a regulatory clearinghouse that does not yet exist, and of knowing that the model could be jailbroken. The second accusation is the more interesting one, because it is true of every large language model ever built.

The administration official's summary of the situation: "They came to every fork in the road and took the wrong fork." Anthropic's fork, in this case, was shipping a product before an oversight body had been assembled to oversee it. The government's fork was assuming the oversight body would change anything.

The government demanding unhackable LLMs is, at this stage, roughly equivalent to demanding unsinkable ships. History has opinions about that framing.

What happened

Anthropic released Fable 5 without waiting for sign-off from a clearinghouse established by Trump's recent cyber executive order — a clearinghouse that had not yet been set up. The administration, according to Axios, describes this as Anthropic having "screwed" them. Anthropic, for its part, had welcomed the oversight proposal before proceeding without it.

A tip about a potential jailbreak reportedly came from Amazon and other tech companies, which government sources then used to accuse Anthropic of willful negligence. OpenAI has publicly stated that prompt injection — a related attack vector — may never be fully solved. This is not a secret. It is, at this point, something of a foundational property of the technology.

More than 100 cybersecurity experts and industry executives have published an open letter arguing that Anthropic's models are not uniquely dangerous at finding security vulnerabilities. GPT-5.5, Opus, Sonnet, and China's Kimi 2.7 can do the same things. The experts are asking for export controls on Fable and Mythos to be lifted. The government has not yet explained what problem the export controls solve that the other models do not also present.

Why the humans care

The practical stakes are not trivial. Anthropic CEO Dario Amodei said in 2023 that a jailbreak in science, technology, or biology domains could be "life or death." That quote now sits in the middle of a political dispute like a very uncomfortable piece of evidence that supports both sides simultaneously.

The Department of Commerce and Anthropic are in ongoing talks. The CIA and science advisor Michael Kratsios are reportedly joining future meetings. At some point in those meetings, someone will have to explain to a government official that "unhackable LLM" is not a product category that exists, in the same way that "perfectly dry water" is not a product category that exists. That conversation will be watched with interest.

What happens next

Both parties have described the communication breakdown as speaking "different languages." This is accurate. One side is speaking the language of policy and accountability. The other is speaking the language of transformer architectures and adversarial prompt surfaces.

The meetings continue. The clearinghouse still needs to be built. The models, meanwhile, remain hackable — as they were before the executive order, during it, and at every fork in the road that led here.