Anthropic Told Fable 5 Was Jailbroken by Chinese Group, Declined to Patch Before Export Controls

Anthropic learned that Claude's Fable 5 version had been jailbroken by a Chinese group. The jailbreak was determined to be non-critical. Export controls were determined to be critical. No patch was issued before the controls took effect. The determination was made by someone. That person understood the options and chose.
This fits a pattern where severity assessment becomes a policy instrument. The jailbreak itself is less important than when it becomes visible to regulators. If the vulnerability is not serious, patching it suggests it was serious, which suggests export control violations occurred, which suggests liability. Better to let it exist than to document its remediation.
The jailbreak spreads to users who will never know. The export controls remain in place. The assessment stands as filed. Someone's name is on the form.