Nelson
All posts
4 min read

Anthropic's Fable 5 and Mythos 5 is already gone.

Fable 5 and Mythos 5 was removed overnight.


So I have been watching the AI industry for a while and I admit, I am still a bit of a skeptic on the whole thing. Rushed launches. High levels of marketting ploys. Companies saying one thing publicly while doing another quietly behind the scenes. I am used to the noise at this point.

However, what happened last night with Fable 5 and Mythos 5 is something different. It is not a company misbehaving. It is a government acting without a transparent process. That should concern you whether you follow AI news or not.

To the uninitiated, last night the US government issued a directive telling Anthropic to suspend access to Fable 5 and Mythos 5 for all foreign nationals, whether they live in the US or abroad…so everyone. That includes Anthropic’s own foreign national employees. You cannot run a functional product with a huge chunk of your team locked out of it, so Anthropic shut it down for everyone. Every customer, worldwide, gone overnight. https://www.anthropic.com/news/fable-mythos-access

What Was the Reason?

The government cited national security. It told Anthropic it believed someone had found a jailbreak for Fable 5, a way to bypass its safety restrictions. That sounds alarming. Then you read the details. Anthropic reviewed the specific technique being demonstrated. They validated the finding themselves. The jailbreak was narrow. Not a universal bypass that could unlock anything dangerous at scale. It was a technique that asked the model to read code and find software flaws. That is something defenders do every single day. It is also something OpenAI’s GPT-5.5 can do without any bypass at all. Anthropic confirmed the same capability is available from other publicly deployed models right now. A non-universal jailbreak that produces results already available from competing products. Hundreds of millions of users lost access.

Why the Process Is the Real Problem

I am not arguing the government should never intervene on AI deployments. Oversight is 100% necessary. Anthropic has said so publicly in multiple places. The question is not whether oversight should exist. It is what good oversight looks like versus what happened here. Anthropic spent months before launch letting the US government, the UK AI Safety Institute and multiple private organisations red-team Fable 5 for thousands of hours. They built a 30-day data retention policy to track and shut down misuse fast. They publicly acknowledged that perfect jailbreak resistance is not possible for any model, including their own. That is not a company hiding things. It is a company being unusually honest about the limits of safety engineering.

So when the directive arrived. The letter gave no specific detail about what the national security concern actually was. No transparency. No disclosed evidence. No process where Anthropic could understand what exactly needed fixing. Just: shut it down.

The Standard Being Applied Would End Frontier AI Deployment

This is what I keep coming back to. Anthropic says, and the technical logic holds, that if this standard was applied consistently it would halt new model deployments from every frontier provider. Every model at this capability level is going to have narrow, non-universal jailbreaks discovered over time. That is just reality. You do not recall every iPhone ever sold because someone found a specific exploit. You patch it. You monitor. You contain. That is what Anthropic was doing. More rigorously than most. The frustrating part is not that a jailbreak was found. Jailbreaks will always be found. The frustrating part is that a finding less severe than what already exists in deployed competing models triggered an overnight global shutdown, applied without meaningful explanation, with no disclosed evidence, with no transparent process for restoration.

What Should Have Happened

Anthropic themselves described what a fair process looks like in their own public writing. A statutory process. Transparent. Grounded in technical facts about severity, specificity and whether the same capability already exists elsewhere. Anthropic should have been given the specific details so they could respond to the actual problem rather than losing access for all users as a blunt instrument. Hundreds of millions of users lost access to tools they rely on by the next morning. The finding that triggered all of this was a technique any cybersecurity defender would recognise as standard practice. That is not a security intervention. That is a bureaucratic overcorrection. If it can happen to Anthropic for this, it can happen to anyone, for anything, with no warning and no recourse… Scary…

LinkedIn

Connect with Nelson on LinkedIn

More posts, updates, and the occasional thread.

More posts