Amazon's CEO Briefed U.S. Treasury on Anthropic Security Risks — While Holding $25B in Equity
Amazon CEO Andy Jassy briefed U.S. Treasury Secretary Scott Bessent and other government officials on security risks posed by Anthropic’s Fable 5 and Mythos 5 — the briefings that preceded the Trump administration’s decision to suspend foreign access to both models. The intervention puts Jassy in the unusual position of helping produce a policy outcome that constrains commercial deployments of the product his company’s $25 billion investment helped build.
The foreign access suspension blocked international commercial access to Fable 5 and Mythos 5, landing Anthropic on a Pentagon advisory watchlist. Anthropic had sought to expand access from 50 to 120 organisations before the restriction was imposed; that expansion was blocked.
What Jassy Raised
Mythos 5 demonstrated the ability to solve end-to-end cyberattack chains before the suspension was put in place — a capability confirmed by the UK’s AI Safety Institute, which verified Mythos cleared its 32-step corporate cyberattack range with no plateau in sight. Jassy’s concerns centred on whether unrestricted global deployment of that capability was compatible with U.S. national security interests at a moment when no comparable capability exists outside the United States.
The reasoning is internally consistent. A model that can execute full cyber kill chains across enterprise environments is, by definition, a dual-use capability. The prior covered disclosure that GPT-5.5 and Mythos cleared AISI’s cyberattack range — and that neither showed signs of levelling off — establishes the security case independent of commercial considerations.
The Structural Tension
Amazon’s relationship with Anthropic carries structural complexity at this investment level. The $25 billion commitment is the largest bilateral AI infrastructure deal on record, matched with a $100 billion AWS spend commitment from Anthropic through 2030. The commercial arrangement creates a direct alignment: Amazon benefits most when Anthropic’s models run through AWS infrastructure rather than Anthropic’s direct API.
The foreign access suspension effectively centralises Mythos 5 access through approved U.S. channels. AWS is the primary enterprise channel for Claude deployments. International workloads that might otherwise have accessed Anthropic’s direct API are now subject to a government approval process that, in practice, routes compliant deployments toward managed cloud infrastructure.
Whether Jassy’s security concerns were purely geopolitical or also reflected commercial logic about channel control is not established from the available reporting. Both can be simultaneously true. What is established is that the CEO of Anthropic’s largest investor took an active role in shaping U.S. government access policy for Anthropic’s most capable models.
State of Access
The Mythos 5 access program has grown to 2,100 vetted domestic organisations. International partners remain blocked without a stated review timeline. The NSA uses Mythos 5 for cyber operations. The Pentagon has been in discussions for access. U.S. military requests have been complicated by a separate procurement dispute, but domestic federal access has continued to expand while international access remains frozen.
Anthropic filed a confidential S-1 with the SEC, targeting an October Nasdaq listing at a $965 billion valuation. Foreign access restrictions on its two highest-capability models are a material business risk requiring S-1 disclosure. That disclosure will require explaining both the restriction and its origin — including the role its largest backer played in raising the security case to Treasury.
Jassy’s intervention is the first confirmed instance of a major technology executive, in an investor capacity, briefing U.S. officials on the security risks of a portfolio company’s products in a way that produced direct access restrictions on those products.