AI
Claude Fable 5 Keeps Mythos-Class Cyber Work Behind a Gate
Claude Fable 5 is Mythos with classifiers that still send cybersecurity questions to Opus 4.8, while vetted partners keep the unlocked model.
Anthropic’s Claude Fable 5 is the public face of a Mythos-class model that still cannot answer many cybersecurity questions without dropping to Claude Opus 4.8. Fable 5.1, shipped on September 1, 2026, keeps that switch in place.
The fight around the model is usually framed as users hating safety. The split underneath is colder. Mythos-class weights exist. Independent developers do not get to run them on the work that made the lab withhold Mythos in the first place.
Fable 5 Is Mythos With the Dangerous Bits Routed Away
Anthropic launched Claude Fable 5 on June 9, 2026 as a Mythos-class system it said was safe enough for general use. When a classifier flags a prompt, the company does not always refuse outright. It hands the turn to a weaker Claude model and keeps going.
On consumer and enterprise chat, queries in those domains fall back in a visible way. Offensive cybersecurity work, including exploits, malware, and attack tooling, is sent to Opus 4.8. A large share of biology, chemistry, and life-sciences prompts, including virology, toxicology, and molecular design, is sent to Opus 5. Distillation attempts and some frontier model-building tasks are in the same net.
WHERE THE SWITCH FIRES
- Cyber harm: Exploit writing, malware, and attack tooling leave Fable and land on Opus 4.8.
- Biology and chemistry: Dual-use lab and drug-design prompts leave Fable and land on Opus 5.
- Model theft: Distillation and some frontier training work are blocked or degraded on purpose.
- The miss rate: Anthropic says the net is intentionally broad, so routine coding and security review get caught too.
At launch the company said the safeguards would “sometimes catch harmless requests,” and that they trigger, on average, in less than 5% of sessions. Fable 5.1 still carries cybersecurity and biology safeguards, and Anthropic still tells buyers that many flagged queries are routed to less capable models. Users are not billed Fable prices for those reroutes.
The September 1 system card loosened one corner of the cyber net. Fable 5.1 can look for vulnerabilities in source code at all access levels, including general availability. Offensive technique work still falls off the model. That is a different rule, not a lifting of the gate.
The Same Weights, Two Permission Slips
Claude Mythos 5 is the same underlying model as Fable 5, with the cyber and biology safeguards lifted in some areas. Mythos 5.1 is the same arrangement on the newer checkpoint. Both public and gated versions list at $10 per million input tokens and $50 per million output tokens, with a 1 million token context window and up to 128,000 output tokens. That is less than half the $25 / $125 price Anthropic charged for Claude Mythos Preview.
FABLE VERSUS MYTHOS
| Rule | Fable 5 and 5.1 | Mythos 5 and 5.1 |
|---|---|---|
| Who can call it | General API, Claude apps, AWS, Google Cloud, Microsoft Foundry | Project Glasswing and other trusted-access programs |
| Cyber and biology net | Classifiers on; fallbacks to Opus models | Those classifiers lifted for vetted orgs |
| Sticker price | $10 / $50 per million tokens | $10 / $50 per million tokens |
| Context and output | 1M context, 128K output | 1M context, 128K output |
| Default logs | 30-day retention for safety monitoring | Same retention rules on the gated line |
US-only inference is offered at 1.1 times input and output prices for workloads that must stay in the United States. Knowledge cutoff on the Bedrock card is January 2026. That is not the real divider. The divider is whether the classifier stack is allowed to speak.
When Fable is left alone, the model is a long-horizon coding and knowledge-work engine. Stripe said Fable 5 took a 50-million-line Ruby codebase through a migration in a day that would have taken a team more than two months by hand. That is the product Anthropic is selling to Pro, Max, Team, and Enterprise seats. The product it will not sell the same way is Mythos doing unfiltered vulnerability work.
A June Order Took Both Models Offline
Three days after launch, that split stopped mattering for anyone. On Friday, June 12, the U.S. government applied export controls to Fable 5 and Mythos 5 and required Anthropic to cut off foreign nationals, including its own staff abroad. The company said it had no reliable way to check nationality in real time, so it suspended both models for every user.
The trigger was an Amazon research report. Researchers prompted Fable 5 until it identified software flaws, and in one case produced code showing how a flaw could be used. Anthropic later said many weaker models, including Opus 4.8, GPT-5.5, and Kimi K2.7, could find the same flaws, and that every model it tested could produce the same exploit demonstration. It also said the technique “only involved routine defensive cybersecurity work” and did not expose unique Mythos-level offense.
Washington still treated it as an export-control event. Anthropic trained a tighter classifier, then said the Amazon technique was blocked in over 99% of cases. The U.S. government’s Center for AI Standards and Innovation tested the old and new nets and, in Anthropic’s account, called them extraordinarily strong. The new net, the company admitted, would flag benign coding and debugging more often.
THE 19 DAYS FABLE WENT DARK
- April 7, 2026: Anthropic opens Project Glasswing around Claude Mythos Preview and withholds a general release.
- June 9, 2026: Fable 5 ships widely; Mythos 5 ships to trusted Glasswing partners.
- June 12, 2026: Export controls land; both models go down worldwide.
- June 26, 2026: The government clears a path to restore Mythos 5 for a set of U.S. organizations.
- June 30, 2026: The export controls are lifted.
- July 1, 2026: Fable 5 returns globally after 19 days offline.
- September 1, 2026: Fable 5.1 and Mythos 5.1 ship on the same two-track terms.
Senator Mark Warner said NSA chief Gen. Joshua Rudd had told him Mythos “broke into almost all of our classified systems, not in weeks, but in hours.” A U.S. official later said the exercise found flaws in hours and did not show the model exploiting them on that clock. Finding is not owning a network. It was still enough to put a public model and its gated twin under a Commerce letter.
Who Gets the Version Without Classifiers?
Project Glasswing is the actual customer for the unlocked weights. Anthropic describes it as a bid to secure critical software by giving defenders a head start with Mythos. Launch partners named on the program page include Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. The lab also said it had extended access to more than 40 other groups that build or maintain critical software, and it committed up to $100 million in usage credits and $4 million in donations to open-source security groups.
In early June it invited about 150 more organizations, in more than 15 countries, across healthcare, power, water, communications, and hardware. Each still has to pass Anthropic’s security bar. Mythos 5.1 remains invitation-only. Cyber defenders can apply to a Cyber Verification Program that, Anthropic says, will include Mythos access in the near future rather than on the public API today.
That is the second-order design. Apple, Microsoft, and a water utility with a Glasswing seat can point Mythos at their own code. A freelance researcher, a mid-size software vendor, or a national cyber agency that is not on the list gets Fable, then Opus 4.8, the moment a prompt smells like offense. The EU cyber agency ENISA only confirmed testing of Mythos 5 in September, and Mythos 5.1 was still being held back from that channel.
Ordinary Coding Still Trips the Cyber Flag
Valentina Palmiotti, a researcher at IBM X-Force, put the working complaint in one line after launch. “[Fable] rejects any request that could be tangentially cyber related. Even innocuous tasks like reading a blog post,” she said. Matt Suiche, on staff at Tolmo, said asking the model to write secure code was enough for it to treat the job as cybersecurity and downgrade the answer.
Anthropic has not pretended this is a bug. It built a wider “safety margin” than on any prior Claude launch, so a request has to look very clearly safe to pass. The company said it doubled the staff on the problem in the month before Fable 5 shipped, then chose false positives over missed harm.
We understood that these kinds of false positives would be frustrating for users, but made this tradeoff in the interest of making the model’s other capabilities widely available.
Anthropic, Redeploying Fable 5, June 30, 2026
On Bedrock, blocked calls still return HTTP 200 with a stop_reason of refusal on blocked calls, plus a restriction category. Prompt-stage refusals are not billed. Mid-stream blocks are billed for tokens already produced. Developers are told to treat refusal as a primary path, not an error.
The live product copy is blunt about the trade. A Fable 5 notice still tells people the safeguards are “intentionally broad,” that they “can sometimes flag legitimate coding, cybersecurity, and biology tasks,” and that the session has been switched to Opus 4.8 with a [cyber] tag. That wording was still appearing on September 14, 2026, two weeks after Fable 5.1.
Biology got a real trim. On August 6 and 7, Anthropic said a classifier update cut biology fallbacks by about 85% across its products. Dual-use biology, including virology, toxicology, and molecular design, still goes to Opus 5, and the lab still says Fable is not ready for professional biology research and drug development. Cyber did not get a matching cut. The Amazon-era classifier was built to catch more coding, and that is the net users still hit.
Astra Is Building the Same Kind of Gate
OpenAI has already shipped GPT-6 Astra as its first Critical-level cyber model, and it is gating the sharpest exploit work to a vetted program rather than leaving it on the public endpoint. The labs are not having different arguments. They are drawing the same line in different brand language: a general model with production safeguards, and a narrower seat for people they will vouch for.
Independent testers who spent nights trying to jailbreak Fable 5 described stacked input and output classifiers, multilingual intent checks, and a wall that dropped most of their attempts. That is the story Anthropic wants told. The story developers keep hitting is smaller and more expensive. They paid for a Mythos-class coder. They received a switcher that treats “fix this code” as a near-miss for an export-controlled weapon.
ENISA is now running Mythos 5. Mythos 5.1 is still a U.S.-gated artifact. Fable 5.1 is on the public menu, with the same classifier habit that defined Fable 5 in June. The unlocked model has a waiting list. The public one has a fallback.
-
AI3 months agoFable 5 Came Back Under a Commerce On-Off Switch
-
AI4 months agoGoogle’s SpaceX GPU Lease Has a Sept. 30 Deadline
-
CRYPTO4 months agoPlasma One’s XPL Locks Face a 1.81 Billion Cliff
-
APPS4 months agoDGO’s Rs 549 World Cup Pass Cost Fans Sleep and Data
-
AI4 months agoMoonshot AI’s $30 Billion Ask Became a $35 Billion Close
-
NEWS4 months agoColorOS 17 Device List Spans Oppo, OnePlus and Realme
-
GAMING4 months agoXbox Cuts 3,200 Jobs After Five Years of Thin Returns
-
GAMING3 months agoThe RTX 4050 Under Rs 70,000 Hides a Wattage Gap
