MODEL

Claude Mythos 5

modeltopic-noteanthropicsecurity

Overview

Claude Mythos 5 is Anthropic’s June 2026 frontier model shipped without the runtime safety-routing classifier that gates its sibling SKU Claude Fable 5. The two share the same underlying weights; Mythos 5 is the version that serves the model’s full capability surface on cyber and bio tasks. Access is restricted to Project Glasswing partners and a separate NSA carve-out (the offensive-cyber arrangement covered in earlier digests via the FT report of roughly half a dozen embedded Anthropic engineers). Mythos 5 succeeds Claude Mythos Preview as the productised tier vocabulary above Claude Opus 4 / Opus 4.8.

Timeline

  • 2026-06-10-AI-Digest — Anthropic launches Claude Mythos 5 alongside Claude Fable 5 on June 9 — same underlying weights as Fable 5, shipped without the classifier-based runtime routing that downgrades cyber/bio queries to Opus 4.8 on the public SKU. Mythos 5 is restricted to Project Glasswing partners and a separate NSA carve-out. The Anthropic release page anchors on SWE-Bench Pro at 80.3% (vs Opus 4.8’s 69.2% and GPT-5.5‘s 58.6%); the Bloomberg “Mythos-lite without cyber capabilities” framing describes the same launch, not a second product. One launch, two SKUs, one classifier deciding which one the customer talks to.
  • 2026-06-12-AI-Digest — Mythos 5 is the distillation-defence anchor in Anthropic‘s apology for the undisclosed Fable 5 output-degradation guardrail: the classifier that fired on ~0.03% of public-tier traffic was screening for suspected Mythos-5-distillation queries, and the fix-forward routes those down to Claude Opus 4.8 with in-flight user notification. Mythos 5 itself is not the surface that misfired — but its commercial-gating posture is the reason the distillation-defence classifier exists on the public Fable 5 tier, and the apology is specifically for the undisclosed part of that classifier, not its existence.
  • 2026-06-11-AI-Digest — Mythos 5 inherits the same 30-day mandatory retention policy that landed on the HN front page today (293 pts / 135 cmts via Anthropic’s support page) — no ZDR opt-out, overriding existing enterprise DPA amendments signed against prior Claude tiers. The disciplined corrective: OpenAI Enterprise and Vertex AI both default to 30 days but allow ZDR via amendment, so the Mythos posture is materially worse than industry-standard rather than industry-aligned. At least two large financial customers are slow-rolling Mythos rollouts on this basis, on top of Microsoft’s previously reported employee-access restriction. Enterprise procurement is now negotiating around retention terms first, not capability or price.
  • 2026-06-13-AI-DigestClaude Mythos 5 globally disabled at 5:21 PM ET on 2026-06-12 alongside Claude Fable 5 after US Commerce Secretary Howard Lutnick’s 2026-06-01 letter — triggered by another company’s claimed “narrow, non-universal jailbreak” of Mythos — brings both models under export controls. First known invocation of the federal frontier-model vetting framework; Anthropic chose voluntary all-customer disable over nationality-gated access. Mythos 5 was the precipitating model behind the letter; the response scope is broader than the literal foreign-persons text of the order.
  • 2026-06-14-AI-Digest — Mythos 5 sits inside today’s WSJ-sourced extension of the export-control story as one half of the model pair the 2026-06-01 Commerce letter ultimately covered — the Amazon Treasury conversation, prompted by Amazon researchers’ Claude Fable 5 cyberattack-info prompt result, is now reported as one of the inputs that preceded the letter that triggered Anthropic‘s 2026-06-12 global Mythos 5 / Fable 5 disable. SWE-Bench Verified top three (Mythos 5 95.5%, Fable 5 95%, Claude Opus 4.8 88.6%) remains frozen this week because the published frontier of SWE-Bench has been inaccessible to API callers since the 2026-06-12 disable.
  • 2026-06-15-AI-Digest — Mythos 5 stays globally disabled — ~72 hours since the 2026-06-12 pull — and the SWE-Bench Verified top three (Claude Mythos 5 95.5%, Claude Fable 5 95%, Claude Opus 4.8 88.6%) is unchanged in print but inaccessible to API callers. The “Aider vs SWE-Bench divergence” thread the corpus has been running stays on pause until either Anthropic reactivates the disabled tier or a fresh tag overtakes. Today’s G7 opening in Évian carries Anthropic CEO Dario Amodei alongside OpenAI‘s Sam Altman and DeepMind‘s Demis Hassabis — the joint frontier-lab-head appearance lands 48 hours after the Fable 5 / Mythos 5 global disable; export-control story, the IPO clock, and the G7 voluntary-commitments framework are now visibly running in the same negotiating window.
  • 2026-06-17-AI-Digest — Mythos 5 is the named subject — alongside Claude Fable 5 — of Bloomberg’s publication of US Commerce Secretary Howard Lutnick’s letter that took both models offline on 2026-06-12. The letter cites civilian-tech export-control statutes and threatens criminal as well as civil penalties for noncompliance against Anthropic — sharper than the prior week’s “guidance” framing — and does not articulate what specifically about the model pair triggered the action. The first enforcement action under the January 2025 BIS model-weights export regime (ECCN 4E091), not the first operationalization of the regime. The directive remains in force and the Glasswing / NSA distribution shape that Mythos 5 inherited from Claude Mythos Preview is now visibly the regulatory ceiling rather than just Anthropic’s own gating posture.
  • 2026-06-18-AI-Digest — Mythos 5 stays globally disabled through the eighth day of the Fable 5 / Mythos 5 shutdown window; the Aider polyglot top-5 is identically frozen for the same eight days, with today’s digest framing the stability as the agentic-coding bar not having moved through the entire shutdown. Today’s Key Takeaways position the “defender-side chorus” (Simon Willison + Kate Moussouris + Anthropic‘s own statement) as the first counter-frame to the Lutnick-letter foreign-national restriction with multiple independent voices, while noting it is “not yet the dominant policy posture.” Mythos 5’s distribution-as-regulatory-ceiling shape from 2026-06-17-AI-Digest continues to hold — no fresh Mythos-5-specific posture today, but the export-control debate is broadening.
  • 2026-06-19-AI-DigestBloomberg reports the Project Glasswing preview cohort retained Mythos 5 access after the June 12 Commerce directive that restricted broader foreign access. Mythos 5 has been the lab’s most aggressive vulnerability-discovery model, and the Commerce action — the first documented enforcement of US export-control authority against a deployed commercial frontier model rather than against weights-at-rest or chips — created a real ambiguity about what “access” the previewing partners actually still had. Today’s confirmation resolves that narrowly: the preview cohort is exempt; the public limits stand. Mythos 5 is now the named subject of the first carve-out inside any of the three 2026 export-control instruments touching frontier models (BIS chip rules, EAR model-weight thresholds, this letter-based deployed-model restriction).
  • 2026-06-22-AI-Digest — Mythos 5 is referenced today as the other half of the export-control saga the digest continues to track: Anthropic‘s mandatory consumer-tier ID verification on July 8 sits “operationally aligned with the Commerce directive’s foreign-national-access framing” against Mythos 5 / Fable 5; Trump’s Axios Show “no longer a national security threat” comment is paired with the standing observation that the June 12 BIS directive (which covered both Mythos 5 and Fable 5) has not been formally rescinded; and the Microsoft–ByteDance / Azure Singapore Bloomberg report is read as the asymmetry receipt — Mythos 5 and Fable 5 are the named SKUs under the order while OpenAI GPT-series tiers flow into the same target geography via Azure.
  • 2026-06-25-AI-Digest — Mythos 5 is the named subject — alongside Fable 5 — of today’s framing of the first known ECRA action against a commercial AI model: the US Commerce Bureau of Industry and Security “Is Informed” letter issued around June 12 under the ECRA emerging-technology provision, restricting access citing cybersecurity national-security risk. The corpus framing carries the precision points the digest holds: Mythos 5 and Fable 5 are sibling models, not parent-and-variant, and the ECRA action is distinct from prior compute/chip-tier export controls (no prior model-specific suspension). Anthropic disabled both globally for compliance. The contested government-vs-lab framing is itself the story; the 90-day test is whether the “Is Informed” mechanism gets applied to a second lab’s model or stays a one-off.
  • 2026-06-27-AI-Digest — Mythos 5 is the regime-precedent anchor for today’s OpenAI Sol launch: Sol releases under the same US-government-approved access regime that already gated Mythos 5 (and Fable 5) — Trump’s June 2 frontier-AI EO and the Commerce Department directive are the framing layer, and Sol’s launch is the second wave under that regime, not the start of a new one. Benchmark anchor: Sol at 88.8% on Terminal-Bench 2.1 edges Mythos 5 at 88.0% (within-error tie). The 60-day test the digest carries: whether a third release (xAI? a Chinese-lab US deployment?) hits the same gating layer — three labs gated would mark a regime; two is a precedent.
  • 2026-06-28-AI-DigestMythos 5 access is restored to approximately 100 “trusted partners” — cyber defenders, critical-infrastructure operators, and federal agencies — under a Lutnick letter dated June 26, ending the two-week shutdown that followed the June 12 export-control action. The corpus framing the digest holds with precision: this is restoration of access to a vetted set, not new commercial GA, and Claude Fable 5 access remains blocked. Bloomberg’s separate “Anthropic moves toward broader deal” piece is in-progress talks, not a signed agreement. The narrow read: a tactical reprieve pulling Anthropic‘s most capable cyber model back into the federal stack via Commerce-managed allowlisting. The structural read worth carrying: this is the second lab in roughly two weeks gated under the same Commerce-Department mechanism — GPT-5.6 Sol under yesterday’s customer-by-customer regime is the matching event — and the mechanism convergence is the regime signal. The 60-day test is whether Fable is restored under the same trusted-partner pattern or remains the persistent asymmetry.
  • 2026-07-01-AI-DigestThe Commerce Department rescinds the June 12 ECRA “Is Informed” directive on June 30, ending the 18-day yank-and-restore cycle covering both Mythos 5 and Claude Fable 5. Anthropic began restoring access on July 1, with the White House citing risk-mitigation steps taken in coordination with the government following the Fable 5 jailbreak disclosure that prompted the original directive (2026-06-13-AI-Digest). Commerce Secretary Lutnick’s statement frames the reversal as compliance-achieved rather than policy-retreated. The scope worth carrying with precision: the June 12 directive was model-specific — Mythos 5 and Fable 5 by name, not Anthropic as a company — and the June 30 rescission is scoped identically, resolving both the June 12 global disable and the June 26 trusted-partner allowlist into full restoration. First documented reference case for how ECRA “Is Informed” directives on commercial AI models can be scoped, contested, and rescinded — a template forming from n=1, not settled practice. The 90-day follow-on test is whether the mechanism gets applied to a second lab’s model.
  • 2026-06-29-AI-Digest — Mythos 5 surfaces today via two compounding reference threads. (1) Mythos 5 sits inside the Aider polyglot freeze framing as the gated tier Aider still cannot realistically sample under the trusted-partner-restoration regime from yesterday — the day-nineteen freeze is now framed as an artifact of gated-access timing rather than a benchmark plateau, with Mythos 5 (restored only to ~100 trusted partners) and GPT-5.6 Sol (still under customer-by-customer access) as the two unreachable tiers. (2) The OpenAI / HP Frontier enterprise tier announcement is read in today’s body alongside the Mythos 5 trusted-partner regime as two distinct deployment surfaces inside the same fortnight — the federal-trusted-partner tier where Mythos 5 returned, and the commercial-enterprise tier where OpenAI is expanding through OEM hardware partnerships. Same digest’s Claude Fable 5 CEO-Bench result ($47.15M, top of twelve frontier models) sharpens the Mythos/Fable gating asymmetry: the most capable model on a public long-horizon benchmark is the one with the most restricted access regime.

Key Developments

  1. Successor to Mythos Preview: Mythos 5 productises the “Mythos-class” tier vocabulary that Claude Mythos Preview introduced in April 2026 under Project Glasswing. The earlier preview was already restricted to ~12 (then expanded to ~150) consortium partners plus a US-gov carve-out; Mythos 5 inherits that distribution shape with the new model weights.

  2. Same Weights, No Runtime Routing: The substantive difference from Claude Fable 5 is the absence of the in-flight classifier that downgrades cyber/bio queries to Opus 4.8 on the public SKU. The classifier is the deployment primitive distinguishing the two SKUs, not the model weights.

  3. Glasswing + NSA Distribution: Restricted to Project Glasswing partners and a separate NSA carve-out — the same controlled-distribution posture Anthropic used for Claude Mythos Preview, now applied to the Fable-5-era weights.

  4. Project Glasswing Preview-User Carve-Out (June 19, 2026): Bloomberg confirms the pre-rollout preview cohort retained Mythos 5 access after the June 12 Commerce directive. First documented exemption inside any of the three 2026 export-control instruments touching frontier models — narrow in scope (a preview cohort, not a class of users) and informative about how Commerce defines a “deployment” boundary more than about whether the restriction will broaden or narrow next.

  5. Trusted-Partner Restoration Under the Second Lutnick Letter (June 28, 2026): Mythos 5 access restored to ~100 vetted “trusted partners” (cyber defenders, critical-infrastructure operators, federal agencies) under a Commerce-Department allowlist — not new commercial GA, and Claude Fable 5 access remains blocked. The structural read is mechanism convergence: same Commerce-Department gating instrument now binds Mythos 5 and GPT-5.6 Sol inside a fortnight, collapsing “two labs is a precedent, three is a regime” into the mechanism itself. The Glasswing preview carve-out from June 19 plus today’s trusted-partner allowlist are now two distinct exemption shapes inside the same export-control instrument; Fable 5’s continuing block is the load-bearing asymmetry.

  6. ECRA Directive Rescinded — First Documented Yank-and-Restore Cycle (June 30, 2026): The Commerce Department rescinds the June 12 ECRA “Is Informed” directive on June 30, ending the 18-day cycle covering both Mythos 5 and Claude Fable 5. Anthropic began restoring access on July 1; the White House framing is compliance-achieved rather than policy-retreated. The corpus framing to carry: the directive was model-specific (Mythos 5 and Fable 5 by name), and the rescission is scoped identically. First reference case for how ECRA “Is Informed” directives on commercial AI models can be scoped, contested, and rescinded — n=1 template, not settled practice. The 90-day follow-on test is whether the mechanism gets applied to a second lab’s model.

See also: Anthropic, Claude Fable 5, Claude Mythos Preview, Claude Opus 4.8, Project Glasswing, MOC - Major Companies, MOC - Agent Security.