Anthropic has made Claude Fable 5 generally available with classifiers that redirect certain risky requests to Claude Opus 4.8, while the same underlying model, Claude Mythos 5, remains available with cyber safeguards lifted only to approved organizations. The models share a listed token price, making vetting, monitoring and capacity—not a purchasable premium tier—the immediate constraint on less-restricted access.
Anthropic, the developer of Claude, has made a public version of its Mythos-class AI available while reserving the version with lifted cyber safeguards for approved organizations. That is a notable change for a company that had kept Claude Mythos Preview inside Project Glasswing, its April program for cyberdefenders and providers of critical software infrastructure.
In its launch announcement, Anthropic said Claude Fable 5 and Claude Mythos 5 use the same underlying model. Fable routes requests in selected high-risk areas to the less-capable Claude Opus 4.8; Mythos lifts the cyber safeguards for a limited group. The release therefore tests whether a frontier model can be shared widely without making its most sensitive mode equally accessible.
Fable is Anthropic’s first Mythos-class release for general use. The company says its classifiers detect potential misuse and jailbreak attempts, then automatically send covered requests—cybersecurity, biology and chemistry, and distillation—to Opus 4.8. Users are told when that happens.
Anthropic’s early data puts sessions with no fallback above 95%, a company measurement rather than an independent estimate. The same announcement says the filters were deliberately broad and can redirect harmless security and scientific requests. In other words, public availability applies to the model’s ordinary use, not necessarily to every task a legitimate researcher or defender might ask it to perform.
At the launch, Fable was fully available through the Claude API and consumption-based Enterprise plans. Anthropic said subscription access would be staged because demand and capacity were difficult to predict: it would be included temporarily through June 22, then require usage credits before a hoped-for return to standard plans. A contemporaneous account described the same rollout. The retained release page later records a June 12 suspension and a July 1 redeployment of both Fable and Mythos, but does not give a reason for the interruption or updated subscription terms.

Anthropic company-reported figures show roughly 50 initial Project Glasswing partners and approximately 150 new organizations announced for expansion. Source: Anthropic: Project Glasswing.
Mythos 5 initially goes to users already admitted to Project Glasswing, with a broader trusted-access program planned but not dated. Anthropic says it will expand access in consultation with the U.S. government and has also proposed a separate biology program: selected researchers would receive Fable with biology and chemistry safeguards removed, while cyber safeguards remain in place.
That selection mechanism has a concrete history. In a June Project Glasswing update, the company said roughly 50 initial partners had used Mythos Preview to scan codebases and had found more than 10,000 high- or critical-severity flaws. It said it was adding approximately 150 organizations that must meet its security requirements; most provide critical infrastructure, and the group covers sectors including power, water, health care, communications and hardware.
Those are Anthropic’s figures, not an independent count of unique flaws or model-caused fixes. Still, they explain the immediate constituency: operators and maintainers whose code can affect large downstream populations, rather than any API customer willing to pay. The company itself says finding vulnerabilities is not the only constraint; verification, disclosure and patching are the bottlenecks once many findings arrive.
The approach is also not a category of access control Anthropic alone has invented. A report on the launch said OpenAI uses a comparable model for its cyber-capable systems, limiting unrestricted access to vetted security researchers, government partners and corporate partners. That comparison limits any claim that eligibility itself is a unique technical safeguard; Anthropic’s differentiating question is whether its particular classifiers, vetting and operating rules work together.
Fable and Mythos are each listed at $10 per million input tokens and $50 per million output tokens. The company says that is less than half the price of Mythos Preview. It also means Mythos’s less-restricted cyber mode is not described as a higher-priced SKU: approved users and ordinary Fable users face the same stated token rates, though only the former can use the lifted cyber mode.
The rates are double Opus 4.8’s, according to launch coverage. That can constrain volume—especially for long-running, reasoning-heavy work—but it does not decide admission. Capacity does, at least in part, given the staged subscription rollout.
Anthropic has paired the access rule with a data-handling rule. It says all traffic on Mythos-class models, including traffic through third-party surfaces, must be retained for 30 days, including from business customers that may have had zero-retention agreements. The company says the data will not train Claude or serve non-safety purposes; it says human access will be logged and data deleted after 30 days in almost all cases. Its stated rationale is to detect multi-request attacks and jailbreaks and to reduce false positives.
That makes the gate more than an identity check. Organizations seeking the less-restricted model must accept monitoring conditions that Anthropic says are necessary for safety. Whether those conditions are workable for the wider set of security teams the company says it eventually wants to serve is a deployment question, not something established by the launch claims.
Anthropic says its internal cyber evaluation found that the classifiers prevented Fable from making progress on the offensive tasks it tested. It also says an external bug bounty found no universal jailbreak in more than 1,000 hours, and that external red-teaming groups had not found one on long-form agentic tasks. But the company says the UK AI Security Institute made progress toward a universal jailbreak during a brief early test window and acknowledges that completely preventing such jailbreaks may be impossible.
A single-author white paper posted to arXiv tests a different question. Nicola Franco used four families of automated jailbreak attack across 7,826 harmful intents and had apparent successes re-adjudicated by a majority vote of three judge models. The paper reports a 6.1% worst-case success rate for Fable 5 under its strongest adaptive search, versus 11.5% for Opus 4.8, and 702 panel-confirmed harmful Fable completions across its ten-category taxonomy.
Those results do not score Anthropic’s cyber classifier on its own specified offensive tasks, nor do they measure the trusted-access program. They do show why the absence of a universal jailbreak is not a general measure of resilience: the result changes with the harmful-intent taxonomy, attack method and success definition.
The next decision is whether Anthropic can make the public filters more precise while expanding Mythos access beyond the Glasswing cohort. The company has offered no timetable for the broader program.
The evidence that would resolve the central question is more concrete than a benchmark claim: independently reproducible tests of classifier performance against iterative attacks; false-positive rates for legitimate cyber and life-science work; and evidence that vetted organizations can meet the retention requirement while turning model-discovered vulnerabilities into verified, disclosed and patched fixes. Until then, Fable and Mythos are a controlled-access experiment with a clear policy architecture, not proof that the architecture can yet operate at the scale Anthropic says the cyber-defense problem requires.
Get concise AI news and useful context from the Magica team.
Read the newsletterEnigma has emerged from stealth with a $71 million seed round and a public test involving at least 100 real robots. The startup says the interactions could improve robot interfaces and models, but it has not disclosed a specific commercial use case, customers or performance evidence.
Starbucks has retired Automated Counting, a computer-vision tool for counting milk and beverage components in North American coffeehouses. The company says it is standardizing inventory counts; reported miscounts leave the economics and operational value of the replacement unproven as Starbucks pursues more frequent replenishment.
HSBC plans to open a Global AI Centre of Excellence in Singapore in the second half of 2026 and hire more than 100 specialists. The bank is adding a deployment hub to an existing Google Cloud programme; the unresolved question is whether it can substantiate the promised gains while retaining human accountability in wealth, payments and treasury work.
Microsoft says MAI-Cyber-1-Flash lets its MDASH vulnerability system route routine work to a smaller in-house model and reserve GPT-5.4 for difficult cases. The resulting benchmark and cost claims apply to the combined system, leaving customer deployment, pricing and remediation outcomes to test in Project Perception’s preview.
A federal judge treated Anthropic’s purchased-book scanning and its model training as distinct fair uses, while leaving its earlier pirate-library copying exposed. Newly unsealed Project Panama records show how the company tried to replace that source of books at industrial scale.
Meta has raised its planned investment in the Hyperion campus in Richland Parish from $10 billion to more than $50 billion. Its promises of jobs, local investment and lower power bills now depend on tax terms and a 20-year utility arrangement whose long-run protections are still being tested.
AT&T has signed an agreement to explore D-Wave's annealing technology in more network operations after an early optimization workload dropped from about an hour to under 15 seconds. The commercial question is whether that company-reported result can deliver better decisions at the cost, scale and reliability of a live carrier network.
Yuyuantantian, an account linked to China Central Television, has proposed matching access to AI-model capabilities and risks rather than treating models as simply open or closed. The commentary is not a regulation, and separate reported discussions of limits on overseas access remain preliminary.
NVIDIA has made an undisclosed investment in Safe Superintelligence and promised access to its Vera Rubin platform that the companies say can increase the lab’s compute tenfold. The partnership gives Ilya Sutskever’s closed AI lab another hardware route, but leaves its research, capacity allocation and commercial terms unexamined in public.
NVIDIA has formed the Open Secure AI Alliance with more than 30 technology and security partners, using Hugging Face’s response to an AI-enabled intrusion as its case for deployable open-weight defensive tools. Members have identified work on identity, scanning and patching, but the coalition has not yet set out a common process for evaluating, disclosing or remediating failures.
CXMT's 466% Shanghai debut made the DRAM maker China's most valuable listed company, but the price was set with only 6.73% of its enlarged share capital freely tradable and before the company has proved how far its new capital can take it against tooling restrictions and established memory rivals.
Investigations and a TikTok search study found synthetic or impersonated clinicians reaching large audiences with dubious health claims. The evidence is not a platform-wide measure, but it shows why an AI label alone may not tell viewers whether a medical recommendation is credible.
Alphabet, Amazon and Meta have disclosed 2026 capital-spending plans that add to $520B to $550B at their stated ranges. The total conveys the scale of their infrastructure push, but it is not a comparable measure of AI-only spending or of the obligations each company is taking on.
Nvidia is reportedly discussing a roughly $250 billion financing backstop that could help OpenAI lease a proposed 10GW Ohio data-center campus. But no deal has been announced, other AI companies are pursuing the federally controlled power, and the reported 800MW first phase would be only a fraction of the planned buildout.
MSI's China distributor sheet shows week-over-week increases of roughly 8% to 20% for listed RTX 50 cards. Colorful's sheet shows substantial premiums to China MSRP, but without earlier prices it cannot establish how much—or how recently—those models rose.
Moonshot AI has released the weights and technical report for Kimi K3, its 2.8T-parameter mixture-of-experts model. The release gives researchers and operators a deployable checkpoint and more of its training infrastructure, but Moonshot still recommends large supernodes and its performance claims are not a uniform, like-for-like comparison.
xAI has added a built-in /deep-research command to Grok Build, turning a coding agent's existing delegation controls into a bounded, source-backed reporting process. The documentation is unusually specific about workflow limits and failure reporting, but it does not establish that the process improves accuracy, speed or cost.
An independently reported account says President Donald Trump posted AI-generated images of an Iranian tanker seizure, a burning tanker and a strike on Kharg Island. The posts did not announce a new operation, but they followed reported U.S. strikes on the island’s military assets and renewed attention to its oil terminal.
Alphabet’s proposed $80 billion equity package is partly tied to AI infrastructure, but its $40 billion at-the-market program is primarily intended to cover employee-equity tax obligations. Together with Microsoft’s $190 billion 2026 capital-expenditure forecast, the disclosures show a more complicated shift in how hyperscalers fund constrained compute capacity.
Intel is putting €5 billion into equipment and connections at its operating Leixlip campus to increase output of Intel 3-based Xeon processors. The investment strengthens an existing European manufacturing base, but Intel has not disclosed its added wafer capacity, the split between its own products and foundry work, or an outside customer.