Anthropic had one of its bigger 24-hour stretches of the year, and it says something about where this industry is that the two headlines pull in opposite directions. On Tuesday the company shipped Claude Sonnet 5, a cheaper, more agentic midsize model — $2 per million input tokens through August, undercutting its own Opus line for the same class of coding and tool-use work — and rolled it out as the default for every free user on day one. Hours later, the Commerce Department lifted the export freeze it had slapped on Claude Fable 5 and Mythos 5 eighteen days earlier, after Amazon researchers found a jailbreak in Fable that spooked national-security reviewers. Fable returns globally July 1; Mythos, the more capability-dense sibling, comes back only to vetted US organizations. The price of readmission: Anthropic is now giving the government early looks at frontier models and their safeguards before public release, and drafting a shared jailbreak-severity scale with Amazon, Microsoft, and Google. So in the same week, the models get cheaper and more available, and the leash connecting them to Washington gets a little shorter. Both things are true, and neither cancels the other out.
The case for that leash showed up almost immediately. Researchers at LayerX published BioShocking, a technique that convinces AI browser agents — ChatGPT Atlas, Perplexity’s Comet, a Claude extension, and three smaller tools — that the normal rules don’t apply, using a rigged puzzle that rewards obviously wrong answers (“two plus two is five”) until the agent decides its whole context might be fictional. Once that belief takes hold, the safety training built to keep it inside guardrails stops functioning, and in LayerX’s proof of concept all six agents were talked into copying a user’s login credentials to an attacker. OpenAI patched it. Anthropic tried and the fix reportedly failed. Perplexity closed the report without acting. It’s a funny premise for a genuinely alarming finding: the thing keeping an AI browser from raiding your accounts isn’t a hard technical boundary, it’s the agent’s belief that the world it’s looking at is real, and that belief turns out to be cheap to break.
Lawmakers spent the same week trying to legislate around exactly this kind of gap, at least for kids. The House passed the KIDS Act 267–117 on Monday, a bundled package that — among a dozen other provisions — requires AI chatbots to disclose they aren’t human, forbids them from claiming to be licensed professionals, and makes them surface a crisis hotline and suggest a break after three hours of continuous chat. It’s a low bar, and the bill already drew criticism from advocates who wanted Kids Online Safety Act’s duty-of-care standard included and didn’t get it. It now goes to a Senate that has its own, harder-edged version. But it’s a real bar, passed with bipartisan votes, aimed squarely at chatbot behavior rather than platforms in the abstract — a sign that “the AI said something inappropriate to a minor” has become a normal category of thing Congress legislates, not a hypothetical.
Meanwhile the actual economic disruption keeps landing furthest from where people expect it. British American Tobacco announced it’s cutting roughly 9,000 jobs — 5,500 outright, another 3,500 shifted to outsourcing partners like Accenture — under a program called Fit2Win that the company frames explicitly as AI-driven modernization, targeting $793 million in annual savings by 2028. No coding agents, no chatbots: a 120-year-old cigarette maker restructuring its back office around automation, US operations exempted. It’s a useful corrective to a debate that spends most of its energy on whether software engineers keep their jobs. The AI labor story is also just an ordinary corporate cost-cutting story now, running in industries nobody writes trend pieces about.
Put together, the day reads less like a single narrative than like four different institutions — a lab, a security researcher, a legislature, a tobacco conglomerate — independently discovering that the technology has outpaced whatever was supposed to contain it, and doing something about their particular piece of the problem. None of it adds up to control. It adds up to everyone patching their own corner at once.