July 17, 2026

Anthropic, Microsoft, Amazon, and Google agreed on something this week, and I honestly can’t remember the last time that sentence made sense to write. The four of them have proposed a shared way to score how bad an AI jailbreak actually is, four axes, one scale, something researchers and buyers can point to instead of talking past each other. If you’re the one who ends up doing AI vendor risk assessment for your law firm, whether that’s officially your job or just something that lands on your desk anyway, this is worth five minutes of your attention.
Here’s the honest version of where things stood before this. When a vendor told you their model was safe, you were mostly taking their word for it. A shared severity scale doesn’t fix that overnight. But it’s the first real crack in a problem that’s been sitting there since the first AI tool showed up in a partner’s inbox with a slide deck attached.
The timing is worth sitting with for a second. On July 1, Anthropic brought its Fable 5 model back online after roughly eighteen days of export control restrictions) and added a new cybersecurity classifier alongside it. At the same time, Anthropic, Amazon, Microsoft, and Google jointly floated an industry wide framework for scoring jailbreak severity, the technique that gets used to talk a model into ignoring its own safeguards.
Four axes make up the scale: how much capability gain the jailbreak actually unlocks, how broad the impact is across different tasks, how much effort it still takes to weaponize, and how easily someone else could stumble onto the same technique independently. None of this has a name yet, no public rubric, no lead author named in the announcement. Still early. But four competitors agreeing on a shared measuring stick is rare enough that it’s worth paying attention to, even in its rough draft form.
Security teams have had CVSS for years, a shared scoring system for software vulnerabilities that lets a buyer compare a critical flaw in one product against a critical flaw in another using the same yardstick. AI never had that. Every lab scored its own safety work by its own rules, published in its own format, on its own schedule.
That’s the gap this proposal is trying to close. Not eliminate risk, nobody’s claiming that, just give buyers a common language for comparing it. For a law firm running AI vendor risk assessment on Harvey, CoCounsel, a Copilot deployment, or whatever shows up next quarter, that’s a real shift, even a modest one. Right now, the honest answer to “how safe is this tool” is usually “as safe as the sales deck says it is.” That’s not a great place for a firm handling privileged client information to be standing.
Think about how this plays out in practice. A firm evaluating two competing legal AI platforms today has almost no way to compare their actual safety posture beyond marketing language and a security questionnaire the vendor wrote about itself. One vendor might have genuinely rigorous internal red teaming. Another might have a nice looking trust page and not much behind it. Without a shared scale, those two vendors can sound identical in a sales pitch. That’s the exact gap a shared jailbreak severity score is meant to close, even in its early, rough draft form.
It is worth breaking these out plainly, since they’ll likely show up in vendor conversations before long, formally or not.
None of these four questions require a technical background to ask a vendor. They’re the kind of thing a managing partner or a general counsel can put directly into a procurement conversation, which is exactly the point.
We’ve written before about what a law firm’s biggest AI risk actually looks like, and the core finding still holds, most firms worry about picking the wrong tool when the bigger exposure is having no governance layer at all around whichever tool wins. This jailbreak scoring framework doesn’t replace that governance work. It gives it one more concrete lever to pull.
Picture a real vendor bake-off, Harvey against CoCounsel against whatever Perplexity’s legal platform turns into. Right now, the conversation is drafting quality, citation accuracy, price per seat. Add one more question to that list: has this vendor participated in a third-party jailbreak severity review, and what did it show. That’s a fair, specific, answerable question, and it beats “do you take security seriously,” which every vendor answers the same way regardless of what’s actually true.
If your firm has already leaned into Microsoft’s ecosystem, our Copilot strategy guide built specifically for law firm innovation walks through the adoption side of that relationship, and it’s worth reading alongside this, since Microsoft is one of the four labs behind this proposal. Adoption and vendor scrutiny really should move together, not months apart like they usually do.
Practically, that might mean adding a single line to your next AI vendor request for proposal: describe your organization’s participation, if any, in third party jailbreak severity testing, and share the results. Most vendors won’t have a polished answer yet, this is days old. But how a vendor responds to that question, defensively, vaguely, or with an actual answer, tells you almost as much as the answer itself would.
There’s a second story tucked inside this one that’s easy to miss. Fable 5 wasn’t just relaunched with a new classifier; it came back after being gated by export controls for over two weeks. An external party, not the vendor and not the customer, decided who got to use it during that window.
Sit with what that means for a firm that built real workflow around a single AI vendor. It’s not just a jailbreak risk question anymore, it’s an ai vendor concentration risk question. What happens to your document review pipeline, your drafting workflow, your whole AI dependent process, if the model you’ve built around gets restricted with roughly zero notice for reasons that have nothing to do with your firm at all.
Most firms haven’t mapped how much of their operation actually leans on one AI vendor until something forces the question. We built our shadow AI assessment for law, energy, and medical practices around exactly this blind spot, not just which tools are approved, but which ones the firm has quietly become dependent on without ever writing that dependency down anywhere.
This is really the second half of a proper AI vendor risk assessment, and it’s the half most firms skip entirely. Jailbreak severity tells you something about how a model behaves under attack. Vendor concentration tells you something different, how exposed your firm is if that vendor becomes unavailable, restricted, or acquired with zero warning. Both questions belong in the same conversation, but only one of them shows up in most procurement checklists today.
None of this means law firms need to become AI security researchers overnight, and I’d push back hard on anyone selling that idea. What it does mean is that “trust the vendor” was never a real strategy, it was just the only option available. Now there’s a second one starting to take shape, even if it’s still rough around the edges and unnamed as an official rubric.
A workable version of this doesn’t need to be complicated. Ask every AI vendor the same four questions this framework is built on. Write the answers down somewhere, even informally. Revisit them whenever a vendor ships a major update, not just once at signing. That’s most of what a real AI vendor risk assessment process looks like in practice, less a formal audit and more a habit of asking the same sharp questions every time.
A shared severity score doesn't make a vendor safe. It makes an unsafe vendor easier to spot before you sign anything.
That’s the whole value of this, not a guarantee, a better set of questions to ask before the contract gets signed instead of after something goes wrong.
Want a clearer picture of where your firm’s actual AI vendor exposure sits right now, jailbreak scoring aside?
Cocha Technology’s Zero Trust Assessment is built around the same idea this whole post keeps circling back to: verify before you trust, rather than trusting because a vendor asked nicely. A reasonable step before the next AI procurement conversation, not after you’ve already signed something.
Call or email Cocha. We can help with your cybersecurity needs!
About the Author:
Co-Founder & Managing Director, Cocha Technology
Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.