Fable, Mythos, and the Consequences of a Warning Unheeded

June 26, 2026

On a Tuesday, Anthropic released its most advanced public model to date. By Friday evening, it had vanished. As I write this, two weeks later, it remains inaccessible.

Claude Fable 5 was unveiled on June 9. On June 12 at 5:21pm Eastern, Anthropic got an order from the Commerce Department. It told the company to immediately suspend access to Fable 5 and its unconstrained counterpart, Mythos 5, for all foreign nationals worldwide, both within and outside the United States. That included Anthropic's own employees who are not US citizens.

The company couldn't verify the citizenship status of every API request instantaneously, so it was left with no choice but to shut down both models for all users, US citizens included. This marks the first instance of the US government invoking export controls to remove a software model from the market, rather than targeting the underlying hardware. The precedent itself is the crux of the matter; the model is nearly secondary.

The true nature of Fable and Mythos is key to the rationale behind this action. They are one and the same, merely wearing different masks. They're built upon a shared set of underlying weights.

Mythos 5 is the unadulterated model. It has the most potent offensive cyber and life sciences capabilities of any system developed by Anthropic. It's accessible only to a select group of vetted partners through an initiative known as Project Glasswing.

Fable 5 is that identical model with safety classifiers layered on top. When queried about topics in cybersecurity, biology, chemistry, or distillation, the request is redirected to the less powerful Opus 4.8. The performance metrics are striking. Fable achieves an 80.3 percent score on SWE-Bench Pro, compared to 69.2 for Opus 4.8 and 58.6 for GPT-5.5. Mythos 5 reaches 78 percent on ExploitBench, while Opus 4.8 manages only 40.

Anthropic implemented Fable's safeguards precisely because it considered the underlying model sufficiently dangerous to warrant them. It said this loudly and emphatically in every announcement. This is more significant than anything else here.

The official impetus for the ban was a jailbreak. Anthropic's own account states that officials told them, orally, that someone had discovered a method to get around Fable's safety measures. When Anthropic analyzed what it believes was the underlying demonstration, the technique involved instructing the model to examine a specific codebase and fix the software vulnerabilities it identified. It revealed a small number of previously known, minor flaws.

The company's case is straightforward and, on its face, compelling: this is not a universal jailbreak that unleashes the model's full cyber arsenal, but rather a narrow one. It yields nothing that defenders don't routinely perform. An identical prompt elicits comparable behavior from other publicly available models, such as OpenAI's GPT-5.5, which faced no such directive.

Anthropic's unequivocal conclusion was that if a single narrow jailbreak were sufficient grounds to recall a model serving hundreds of millions of users, the same logic could be applied to halt any frontier model in the industry.

The situation then becomes murkier. There are at least three competing narratives regarding how the government became aware of the issue, and they do not cast the same parties in a flattering light.

According to Semafor, the White House was alerted by Amazon CEO Andy Jassy, whose company is among Anthropic's largest investors. He reportedly conveyed a second, more serious allegation: that a China-linked group may have gained access to Mythos.

David Sacks, the administration's AI advisor, portrayed it as Anthropic being cautioned and opting to take no action. Anthropic's framing is that it was provided verbal evidence of a benign or inconsequential finding and no disclosure of any harmful outcome whatsoever.

Politico's reconstruction of the weekend describes a flurry of tense exchanges between Amodei, National Cyber Director Sean Cairncross, Treasury Secretary Bessent, and Commerce Secretary Lutnick, with officials remaining steadfast. A senior White House official characterized the export controls as a last resort after hours of attempting to secure the company's cooperation.

This can be interpreted as a safety apparatus functioning as intended or as a grudge seizing upon a pretext. The reporting supports either view, which is itself problematic.

Then, three days following the ban, the narrative took a wholly different turn due to a leak that reframed the entire incident. It was about something far more significant than a codebase-reading prompt.

On June 14, The Economist reported that Senator Mark Warner, the vice chair of the Senate Intelligence Committee, had relayed information shared by General Joshua Rudd. Rudd oversees both the NSA and US Cyber Command. He shared it during a June 11 briefing, one day prior to the issuance of the directive.

In an authorized red-team exercise, Rudd reportedly stated, Mythos had penetrated "almost all of our classified systems, not in weeks, but in hours." If one seeks a single sentence to explain the government's complete lack of urgency in restoring access, that is the sentence. It recasts the export control from a dispute over a narrow API jailbreak to a battle against an autonomously capable offensive cyber weapon. That weapon had just waltzed through the front door of the agency whose sole purpose is to prevent such an occurrence.

The claim is monumental and the evidence supporting it is a solitary quote, conveyed secondhand, which has since been partially retracted by the individual who published it. The Economist's editor responsible for the write-up, Shashank Joshi, stated within days that the line should not be interpreted literally. The exercise almost certainly involved Mythos operating in conjunction with other tools under highly specific simulated conditions. He said he had erred in omitting those caveats.

A US official went even further, asserting that Warner had misunderstood Rudd. The "hours, not weeks" phrasing was authentic, but it referred to a red-teaming effort. It was the NSA evaluating its own defenses using the model, rather than an adversary unleashing the model on classified infrastructure.

There is no incident report, no CISA or NSA technical bulletin, no disclosure of methodology or scope, no independent corroboration of any kind. What exists is a single quote that journeyed from a classified briefing to a senator to a magazine to every timeline in existence. It accumulated certainty at each step while gaining no new facts.

The cybersecurity researchers who challenged Anthropic's initial Mythos marketing also have a point worth noting here. The company's headline claim of thousands of severe zero-days reportedly hinged on a couple hundred manual reviews. A model that excels at identifying bugs and a model that single-handedly outmaneuvered the NSA are not equivalent. The space between them is precisely where a story like this resides.

So believe whichever version you deem more plausible. No one outside that briefing room can substantiate the factor that contributed most to justifying the ban. The most consequential AI policy action ever taken by the US rests partly on a quote its own author says should not be taken at face value. That should trouble you regardless of your position on whether Mythos is dangerous. It probably is dangerous. That is a separate matter from whether the process that removed it was sound.

The irony of the situation stops being incidental and starts to appear structural. Two days prior to the directive, on June 10, Dario Amodei published a post titled "Policy on the AI Exponential." In it, he singled out Mythos, his own model, as the quintessential example of the national security threat that frontier systems now pose.

He called for mandatory third-party testing of frontier models in cybersecurity, bioweapons, loss of control, and automated R&D. He argued that the government should possess the authority to block unsafe deployments through a transparent, equitable, technically grounded process.

Just days earlier, the company had urged the entire industry to agree on a coordinated brake on frontier development. For months, Anthropic had been telling Washington, through press release after press release, that these models were sufficiently powerful to be regarded as weapons. Someone with authority should have the ability to prevent a dangerous one from being released.

And then someone with authority did precisely that, to this exact model. Anthropic's objection was that the process lacked transparency, fairness, and technical grounding. The cyber researcher Peter Girnus put it about as well as it can be put. The company, he remarked, authored the legal predicate itself and labeled it a brand. If you devote two years to describing your product as a munition, you shouldn't be startled when a government decides to regulate it as one.

The clearest way to tell how much of this is about the model and how much is about the relationship is to examine what happened with OpenAI during the same week. On June 25, OpenAI consented to stagger the release of GPT-5.6. Both the company and the administration reportedly consider that model comparable to Mythos in cybersecurity.

The arrangement: a limited preview for enterprise partners, with the government approving access on a customer-by-customer basis. The request originated from the Office of the National Cyber Director and the Office of Science and Technology Policy, the same orbit of officials. Lutnick, the same Commerce Secretary who signed Anthropic's export order, advised OpenAI against launching without cross-agency approval.

That is the distinction between a negotiated rollout and a kill switch. Same week, same agencies, comparable capability, yet one company receives a collaborative ramp while the other has its model abruptly taken offline worldwide with ninety minutes' notice. Altman, for his part, told staff that this customer-by-customer approval is not OpenAI's preferred long-term model. That's a remarkable thing to be mildly annoyed about while your competitor is completely dark.

The backstory is key to interpreting the asymmetry. In late February, the Pentagon designated Anthropic a supply-chain risk, a label typically reserved for foreign adversary contractors. That happened after the company refused to allow Claude to be used for fully autonomous weapons or mass domestic surveillance.

Trump ordered federal agencies to cease using its tools. Within hours of that blacklisting, OpenAI announced an agreement to put its models on the Pentagon's classified networks. Anthropic sued the administration in March. It won a preliminary injunction restoring its federal work, lost a separate bid at the appeals court, and is still engaged in active litigation at present.

Thus, the company that received the export-control hammer is the one suing the government over its safety guardrails. The company that received the gentle staggered preview is the one that struck a deal the moment the first company was sanctioned. The capabilities may be comparable, but the postures toward the administration could not be more divergent. The treatment aligns with the posture, not the benchmark.

Trump told Axios last week that he no longer considers Anthropic a national security threat. If taken at face value, that means the company's threat level is now a function of presidential mood rather than anything in a system card.

The collateral damage points in the same direction. The order did not merely lock out adversaries; it locked out the Five Eyes. The UK's AI Security Institute, the single most important international body for evaluating frontier models for safety, was cut off from systems it was in the midst of testing. An export control justified by safety severed the world's premier safety evaluator from the model it was attempting to make safe.

Allied banks and agencies that had built on Mythos through Glasswing lost access without warning. The former British security minister Tom Tugendhat's reaction was that after a lesson this clear, every nation will start asking what it needs to achieve sovereignty. That is precisely the outcome that US AI policy claims to be trying to prevent.

Gary Marcus noted the deeper incoherence. An administration that says it must beat China at AI just gave every Chinese-born researcher at a US lab a fresh reason to go home. It gave every foreign government a reason to distrust American AI as a dependency. You can loosen chip exports to China and hard-block allied access to a model in the same month only if the policy is being made one weekend at a time.

I have written before about the loop closing, capability outrunning evaluation, evaluation outrunning oversight, oversight outrunning the public. The Fable episode is what it looks like when the government finally reaches into that loop and grabs something.

The optimistic reading is that a brake now demonstrably exists. The state can pull a deployed frontier model off the market in an afternoon. This is the brake Anthropic and many safety-minded individuals have been requesting.

The pessimistic reading is that the brake was pulled on a verbal, unverified basis. It was applied to one company and not its near-identical competitor, justified by a quote its own author retracted, with no statute, no published evidence, and no process that could be replicated or appealed. Both readings are simultaneously true.

We discovered that the off switch is real. We also discovered that no one can tell you the rule that governs when it gets used because there isn't one yet. There is an executive order calling for a pre-release review framework that wasn't even operational when Fable shipped seven days after it.

This is the field I'm about to enter. I'm starting CS this fall, and the kind of work I want to pursue, autonomous systems and the perception and ML stack underlying them, falls squarely within the cybersecurity and dual-use categories that just got a model deleted from the internet by letter.

The lesson I'm taking from these fourteen days is not that the government acted wrongly or rightly. I genuinely cannot tell that from the outside, and neither can anyone else who wasn't in that briefing.

The lesson is that the rules for deploying the most capable software humans have ever built are currently being written in real time, in tense phone calls over a weekend, on the strength of claims no one can verify. Anthropic asked for a world where someone could stop a dangerous model from shipping. It got that world. It just didn't get to be the one holding the brake.