Claude Fable 5 and Mythos 5 available again

On June 9, 2026, Anthropic launched two new models: the Claude Fable 5 and the Claude Mythos 5. Both are based on the same underlying model, but were given different levels of protection. Fable 5 received strong protection mechanisms for general use, while Mythos 5 — with fewer restrictions — was released only to a few trusted partners in the so-called Glasswing program, for defensive cybersecurity work.

What happened on June 12?

The US government became aware of a report that researchers at Amazon found a way to bypass Fable 5's protection mechanisms. By asking specific questions, they were able to get the model to identify a number of software vulnerabilities — and in one case, the model produced code that showed how the vulnerability could be exploited. On the same day, Friday, June 12, the government imposed export controls on Fable 5 and Mythos 5. The controls required that access be restricted to foreign nationals, regardless of whether they were in or outside the United States. Because the decision was effective immediately, and Anthropic lacked a reliable way to verify users' nationalities in real time, access to both models was suspended for all users.

Anthropic investigation

In its review, Anthropic tested whether other, less capable models could do the same thing that the Fable 5 did in the report.

The result:several models — including Claude Opus 4.8, GPT-5.5 and Kimi K2.7 — were able to identify the same vulnerabilities. When it came to demonstrating how the specific vulnerability could be exploited, all tested models (including Claude Haiku 4.5, Sonnet 4.6, Opus 4.6, Opus 4.7, Opus 4.8, GPT-5.4, GPT-5.5, and Kimi K2.7) were able to produce the same type of demonstration as Fable 5. Anthropic emphasizes that the reported technology did not provide access to any unique Mythos-level cyber capabilities. It was a borderline case in Fable 5's protection mechanisms — a type of task that is rarely dangerous but is still blocked as a precaution. In this case, it was routine, defensive security work.

New security classifier — and eased checks

Anthropic worked with the authorities to develop an improved security classifier that specifically targets the reported technology. It now blocks that specific method in over 99% of cases. If a request to Fable 5 is blocked, the user is notified, and the request is sent to Opus 4.8 instead. Researchers at the US Department of Commerce's CAISI (Center for AI Standards and Innovation) have reviewed both the previous and the new protection mechanisms and rate them as very strong. On June 26, the government approved restored access to Mythos 5 for a group of US organizations under the Glasswing program. On June 30, export controls on Fable 5 and Mythos 5 were completely lifted. Since Wednesday, July 1, Fable 5 is available globally via the Claude platform, Claude.ai, Claude Code, and Claude Cowork. For Pro, Max, Team and some Enterprise plans, Fable 5 is included in up to 50% of the weekly usage limit until July 7th, after which the model is accessed via usage credits. Access via AWS, Google Cloud and Microsoft Foundry will be restored as soon as possible.

This is how Anthropic's security classifier works

Anthropic describes its approach as "defense in depth" — multiple layers of protection that are individually incomplete, but together make the model difficult to abuse. A central part is classifiers: smaller AI systems that detect during a conversation if the model is being asked to perform a potentially harmful cybersecurity task, and then block the response. The classifiers are deliberately set with a margin of safety — they also block some requests that are likely to be harmless, to reduce the risk of missing something that is actually malicious. For Fable 5, that margin was made larger than in any previous launch, meaning more blocked but harmless requests. Anthropic describes it as a conscious trade-off in order to make the model's other abilities widely available. Anthropic also divides jailbreak attempts (techniques that bypass a model's protection mechanisms) by severity: minor jailbreaks that only reach into the margin of safety, narrow malicious jailbreaks that unlock a single malicious behavior, and universal jailbreaks that unlock a broad set of malicious behaviors. According to Anthropic, no universal jailbreaks have been found for the Fable 5 so far, but the model is under ongoing review by external security researchers.

A common industry framework for jailbreaks The incident showed that the industry lacks a common standard for judging the severity of a given AI jailbreak.

Together with Amazon, Microsoft, Google and other Glasswing partners, Anthropic is now developing such a framework. The proposal assesses a jailbreak based on four criteria:

  • Capability gain — how much further does the technology take the user compared to tools already available? Breadth — the same technique works for several different types of malicious data

  • Ease of weaponization — how much human effort is required to turn the technology into an attack?

  • Discoverability — how easy is the technology to come across? For the most serious cases — for example, a jailbreak actively used to cause serious damage to critical infrastructure such as power grids or banking systems, Anthropic will begin deploying preliminary countermeasures immediately upon confirmed severity.

The company is also setting up a team for round-the-clock monitoring of channels where jailbreaks are reported, and is launching a new HackerOne program where security researchers can submit cyber-related jailbreaks of Fable 5 for review.

Deeper cooperation with authorities

Anthropic also describes a deepened collaboration with US authorities, building on almost two years of previous collaboration around testing and evaluation before launch:

Early authority access

for models that significantly advance the capability frontier in areas connected to national security, select government partners receive extended early access to both the models and their protection mechanisms, to run their own evaluations before broad launch.

Quick information sharing

in the event of serious jailbreaks or abuse patterns, Anthropic will quickly investigate, prioritize and inform relevant government contacts, as well as share the new protection mechanisms built in response.

Dedicated resources for joint research

Anthropic scales up collaboration around AI security, with dedicated teams, computing power, and its own security and red teaming expertise.

A common industry standard

work together with authorities and industry colleagues towards a shared, voluntary security and evaluation standard for providers of frontier models.

For regular Enterprise seats, no Fable 5 quota is included, but access can be gained via usage credits. For premium Enterprise seats, Fable 5 is included at no additional cost until July 7, after which usage credits are required for continued access.

See source reference further down in the article.