Anthropic Ships Claude Fable 5 as Two Products, One With the Cyber Guardrails Off

The public gets Fable 5. A vetted cyber cohort gets Mythos 5 — the same model with safety classifiers lifted.

ThreatVectr Newsdesk· 3 min read
Anthropic Ships Claude Fable 5 as Two Products, One With the Cyber Guardrails Off
Share

Anthropic made Claude Fable 5 generally available on June 9, calling it the most capable model it has shipped. The release came with a wrinkle worth flagging.

The company is shipping one underlying model as two products. The split is not capability. It is policy.

Fable 5 is the public-facing build, with cyber safety classifiers active. Claude Mythos 5 is the same model with those cyber safeguards lifted, gated behind access controls and routed only to a vetted group of cyber operators.

That is an unusual disclosure to put in writing.

Most frontier labs talk about safety as a property of the model. Anthropic is now openly treating it as a deployment-layer toggle — one cohort of customers gets a permissive variant the rest of the user base cannot touch. The capability ceiling is identical. Only the classifier stack differs.

For anyone who covers breach response, the implications run in two directions. Defensive teams inside vetted programs presumably get a model that will engage more freely with offensive security workflows: exploit reasoning, payload analysis, adversary emulation, the categories Fable 5 will refuse or hedge on. That is genuinely useful for red teams and incident responders who have spent two years arguing with refusal messages.

The other direction is the uncomfortable one. A model trained to the same capability level as Mythos 5 exists. Anthropic is asserting that access governance — not training — is what keeps it out of the wrong hands. The integrity of that boundary is now a vendor-trust question, not a technical one.

Anthropic has not, at time of writing, published the vetting criteria for Mythos 5 access, the audit cadence, or the revocation process. Nor has it said which regulator, if any, it briefed before the split-deployment model went live. The EU AI Act's general-purpose AI obligations and the US AI Safety Institute's voluntary commitments both touch this territory, and neither has a clean precedent for a deliberately de-restricted variant of a frontier model.

Worth watching: whether downstream enterprise customers who license Claude through cloud resellers can tell which variant they are talking to, and whether prompt-injection or jailbreak research against Fable 5 inadvertently maps the delta to Mythos 5.

What security teams should do now

If your organisation uses Claude in production, ask your Anthropic account contact in writing which variant your API key is bound to, whether that binding can change without notice, and what logging you receive on classifier decisions. If you run a bug bounty or red team program that has been approved for Mythos 5 access, treat the credentials like any other high-value secret: hardware-backed auth, short-lived tokens, and access reviews on a calendar, not a vibe.

And if you are a regulator reading this: the interesting question is not the model. It is the access list.

© 2026 Threat Vectr