The Fable 5 shutdown
It starts with Mythos Preview. In April, Anthropic decided the model was too good at finding and exploiting vulnerabilities to release publicly. It went to defenders through Project Glasswing instead, and by early June about 150 organizations in more than 15 countries had access.
On 9 June Anthropic released Fable 5 and Mythos 5. They’re the same model. Fable 5 has extra safeguards so anyone can use it, and Mythos 5 has some of them lifted and stays with Glasswing partners.
Three days later both were switched off. Amazon researchers had found a jailbreak that got Fable 5 to find software vulnerabilities, and in one case write code showing how to exploit one. Once the report reached the government, the Commerce Department sent Anthropic a letter on 12 June barring every foreign national from both models, citing national security. Anthropic can’t check a user’s nationality in real time, so it revoked access for all customers.
The defenders got their model back first. On 26 June, Mythos 5 was restored to a set of US organizations that operate and defend critical infrastructure, while Fable 5 was still off for everyone else.
Anthropic concluded the jailbreak didn’t expose any unique Mythos-level cyber capability, and retrained its classifier to block it in more than 99% of cases. Commerce lifted the export controls on 30 June and Fable 5 came back globally on 1 July. Requests the classifier flags as cyber, bio or distillation now go to the less capable Opus instead, so some routine coding and debugging gets caught too.
The Atlantic Council points out that the US has no clear, public process for restricting a privately developed model. The order came with as little as ninety minutes to comply, and the deal to bring the models back was negotiated privately, so the next company has nothing to go on.
Anthropic’s full account is in Redeploying Claude Fable 5. By Fable 5.1 in September, the cyber safeguards were flagging harmless requests about 60% less often.