Omi Iyamu · Personal DossierVol. XVII · 2026 Edition
Omi Iyamu.
← All essays
2026 · 07 · 043 min read

How the world's top AI models were revived

# The 19 days Anthropic couldn't ship

The most useful piece of AI journalism this year is not about a model. It is about what happened in Washington between June 12 and July 1, when Anthropic could not ship its two most capable models. Axios has the reconstruction, and every AI operator should read it.

The bullet version. Amazon flagged a jailbreak in Fable 5 and Mythos 5 to the administration. Commerce Secretary Howard Lutnick called Dario Amodei at Trump's direction on June 12. Export controls landed the same week. Anthropic sent engineers to DC. CAISI and the NSA said their initial fixes were not good enough. Sarah Heck and Tom Brown got directly involved, going line-by-line through how the models behave under stress. Various agency heads eventually approved, and the models shipped again on July 1.

That is 19 days from flagged-vulnerability to green-light. It is the first time I can point to a public timeline for what a frontier model export negotiation actually looks like. Not a policy paper. A timeline.

Three things worth sitting with.

First, the mechanism is not "regulation" in the sense we usually mean. There is no rulebook here. No clear public criteria for what a jailbreak severity of X does or does not trigger. The mechanism is a direct call from Commerce to a CEO. That is discretionary export policy applied to a software product, and it is not the same as saying "the AI Act requires a system card." It is closer to how the government treats certain semiconductor products, and it is the pattern I now expect to spread.

Second, the framework that emerged — a cross-lab jailbreak severity scoring system Anthropic is building with Amazon, Microsoft, Google, and others — is the interesting downstream artifact. It sounds bureaucratic. It is actually the first attempt at a CVSS-equivalent for AI capability jailbreaks, and if it holds it will change how every enterprise procurement team thinks about model risk. The four proposed criteria are capability gain, breadth of that gain, ease of weaponization, and discoverability. That is a defensible starting rubric. It also has open questions — no named lead author, no published timeline, no resolution mechanism for disagreements between labs — that we should track. I would rather have a shared severity framework than fifteen private ones. I would also rather it be governed than owned by any single lab.

Third, and this is the part I want AI startup CTOs to sit with. Your enterprise customers now have no guaranteed continuity of service on frontier models, no published recourse process, and no advance notice mechanism. If a jailbreak lands, a model can go away for 19 days. Or 30. Or longer. If your product is built on a single frontier model and your SLA does not account for this, you are shipping a promise you cannot keep. Three-tier stacks with fallbacks are not paranoia anymore. They are basic hygiene.

There is a subtler point in the Axios piece that I did not see amplified elsewhere. Amazon, Anthropic's largest investor, is the entity that flagged the vulnerability. That is either a triumph of the safety-first partnership model or a case study in what happens when your biggest investor also runs the second-largest cloud that would benefit from your top model being unavailable. I do not have the reporting to say which. I am watching the next round of AWS Bedrock announcements with more curiosity than I would have last week.

What I am not going to do is grade the government's response. That is the part of this story I am least qualified to evaluate. I will say that the Anthropic team's willingness to send engineers to DC, sit with specialists, and go through model behavior line-by-line under stress is the operational posture I want from every lab. If your safety team cannot do that when a Cabinet Secretary calls, you do not have a safety team. You have a compliance function.

For CTOs and founders, my one-line takeaway. Put an export-controls clause in your model provider contract, and know exactly what your fallback is if your primary model is unavailable for three weeks. The 19-day gap is the new datum. What are you rewriting because of it?

If this was useful, the weekly Brief covers shorter ideas like this every Wednesday.
Read the Briefs →
© Omi Iyamu · MMXXVIContact → · linkedin.com/in/omiiyamu