Key Takeaways
- Anthropic’s Cyber Jailbreak Severity (CJS) framework, built with Amazon, Microsoft and Google, introduces a five-tier scale modelled on CVSS to rate AI jailbreaks across four measurable axes, the first cross-industry attempt to replace subjective “danger” language with repeatable metrics.
- Amazon’s role is worth watching closely: its researchers reported the Fable 5 jailbreak directly to the U.S. Commerce Department, bypassing Anthropic despite being its largest investor, then joined as a founding CJS partner, a sequence that suggests cloud providers are positioning themselves as active governance players, not passive infrastructure.
- OpenAI is absent from the coalition while navigating its own government-gated GPT-5.6 Sol rollout. If that absence hardens into a parallel standard, regulators face incompatible frameworks at exactly the moment they need a common language.
The 19-day shutdown of Anthropic’s Fable 5 model grabbed the headlines. The framework that came out of it is the more consequential development. Published on July 2, 2026, the Cyber Jailbreak Severity (CJS) framework is the AI industry’s first serious attempt to do for jailbreak risk what CVSS did for software vulnerabilities, and OpenAI’s absence from the founding coalition is the detail that should worry everyone paying attention.
What the Fable 5 shutdown actually revealed
On June 12, 2026, the U.S. Commerce Department issued an export-control order against Anthropic‘s Fable 5 and Mythos 5 models after Amazon researchers reported a jailbreak that allowed the model to identify software vulnerabilities and generate working exploit-demonstration code. Anthropic couldn’t filter users by nationality, so it took both models offline globally for 19 days. The shutdown ended July 1.
Anthropic’s own position was that the jailbreak wasn’t uniquely severe, that other frontier models were equally susceptible. Regulators didn’t accept that framing. The gap between what the developer considered a manageable risk and what government considered an emergency is precisely the problem CJS is designed to close. Without a shared vocabulary, that gap will keep producing crises.
What CJS actually does
The CVSS parallel is the right one to start with. For decades, cybersecurity teams have used CVSS scores to classify software vulnerabilities consistently, low, medium, high, critical, giving researchers, vendors and incident responders a common baseline for prioritisation. It’s not a perfect system, but it made coordinated response possible at scale. CJS attempts the same thing for AI jailbreaks.
The framework runs a five-tier scale from CJS-0 to CJS-4, rating jailbreaks across four axes: capability gain (how much an attacker gains beyond existing tools); breadth (how many offensive tasks the technique enables); ease of weaponisation (the effort required to operationalise it); and discoverability (how easily a threat actor could find it independently). A jailbreak that scores high on all four is a different order of problem from one that scores low on discoverability and weaponisation. That distinction matters operationally, and until now the industry had no standard way to make it.
The framework was developed under what Anthropic is calling the “Glasswing” partnership, with Amazon, Microsoft and Google as co-authors. These are not bit players. Between them they run the dominant cloud infrastructure on which most frontier AI is deployed. A safety standard with their backing has real weight.
Amazon’s position deserves scrutiny
The sequence of Amazon’s involvement is the strangest part of this story. Amazon researchers discovered the Fable 5 jailbreak. Rather than reporting it to Anthropic directly, they reported it to the U.S. Commerce Department, triggering the shutdown. Amazon is Anthropic’s largest investor. That’s an unusual chain of events, and it suggests Amazon’s relationship with Anthropic is more complicated than a straightforward investor-developer dynamic.
What followed was Amazon joining Anthropic as a founding partner in CJS. Whether that represents a genuine alignment on safety governance or a strategic move to shape the standard from the inside is harder to say, but the pattern, cloud provider surfaces risk through regulators, then co-authors the framework for categorising that risk, is one that positions Amazon as a governance actor in its own right, not just a platform. That’s a meaningful shift in how AI accountability is being distributed, and it’s one the industry is still working out how to handle.
OpenAI’s absence is the real problem
OpenAI is not part of CJS. That’s the sentence that changes the significance of everything else in this story.
OpenAI and Anthropic have both signed agreements with the U.S. AI Safety Institute at NIST for collaboration on safety research, testing and evaluation. Those agreements were supposed to represent a shared commitment to coordinated safety work. The CJS coalition’s formation without OpenAI either means OpenAI wasn’t invited, didn’t want in, or is developing a parallel approach. None of those options is reassuring.
OpenAI’s current situation adds another layer. Its GPT-5.6 Sol model launched under a government-gated rollout, with initial access restricted to government-approved organisations following a Trump administration executive order. OpenAI is already navigating a distinct regulatory relationship with the federal government, one that may be driving it toward different safety frameworks rather than shared ones. The history between the two companies doesn’t help: Anthropic reportedly revoked OpenAI’s API access after OpenAI was found testing against Claude’s internal tools, which is the kind of friction that makes collaborative standard-setting harder.
The risk here isn’t abstract. If OpenAI develops its own jailbreak severity standard, or simply operates without one, regulators end up comparing AI risks across incompatible scales. Researchers can’t share findings cleanly. Enterprise security teams buying AI products from multiple vendors have no common benchmark. The governance gaps that already exist in enterprise AI procurement get wider, not smaller.
Why fragmentation is the worst outcome
CVSS worked because it achieved broad adoption. Its value wasn’t the scoring methodology, it was that everyone used it. A jailbreak severity framework adopted by three major cloud providers and one major lab is better than nothing, but it’s a long way from CVSS, which became the default precisely because it wasn’t owned by a competitive faction within the industry.
If CJS succeeds as a de facto standard, driven by the market weight of Amazon, Microsoft and Google, it will be because competitive pressure made non-adoption costly for other developers, not because the industry reached genuine consensus. That’s a workable outcome, but it’s fragile. A framework perceived as giving structural advantage to its founding members will face constant pressure from those outside it, and that pressure tends to produce rival standards rather than convergence.
The alternative, regulators mandating a single standard before the industry fragments further, is increasingly plausible given what the Fable 5 shutdown demonstrated about government willingness to intervene. That’s not necessarily a bad outcome either, but it would represent a significant reduction in industry self-governance at exactly the moment the industry is trying to establish it.
CJS is a genuine advance. The four-axis methodology is rigorous, the CVSS lineage is credible, and the founding coalition has enough market weight to drive adoption. The open question is whether OpenAI’s absence is temporary or structural. If it’s structural, the industry will have two competing safety languages at the frontier, and that’s a problem no scoring system can fix. Regulators, researchers and enterprise buyers should be pushing hard for OpenAI to engage with this framework, publicly and on the record, before the gap becomes a precedent. For daily AI news and analysis, visit Auton AI News.



