Anthropic announced that US export controls which prompted access restrictions to its newest models, Claude Fable 5 and Claude Mythos 5, on June 12 have been lifted as of June 30. Consequently, Fable 5 will be re-enabled globally from July 1, 2026 on the Claude Platform, Claude.ai, Claude Code, and Claude Cowork.
When the controls were imposed and lifted
- Anthropic released Fable 5 and Mythos 5 on June 9; both share the same underlying model, but Fable 5 launched with stronger safeguards for broad use, while Mythos 5—with fewer safeguards—was available only to a small set of trusted Project Glasswing partners for defensive cybersecurity.
- The US government applied export controls on June 12 requiring restriction of access for foreign nationals, whether inside or outside the United States. Because the order took effect immediately and Anthropic had no reliable real-time method to verify nationality, it suspended access for all users.
- The US government approved restored access to Mythos 5 for a set of US organizations on June 26; broader domestic and international access via the Glasswing program remains under coordination.
- Fable 5 will be available again worldwide starting July 1, 2026. For Pro, Max, Team, and select Enterprise plans, Fable 5 will count toward up to 50% of weekly usage limits through July 7, after which it will be available through usage credits. Anthropic will re-enable access on AWS, Google Cloud, and Microsoft Foundry as soon as practicable.
What triggered the restriction and how Anthropic fixed it
The export-control directive followed a report that Amazon researchers had demonstrated a method to bypass some of Fable 5’s safeguards: a prompting technique that caused the model to identify software vulnerabilities and, in one instance, produce code showing how a vulnerability could be exploited.
Anthropic and partners, including Amazon, reviewed the report and evidence and ran tests that showed:
- Many less capable models—such as Claude Opus 4.8, GPT-5.5, and Kimi K2.7—could identify the same vulnerabilities described in the report.
- Every model tested could produce the same exploit demonstration for the single vulnerability in question, including Claude Haiku 4.5, Sonnet 4.6, Opus 4.6–4.8, GPT-5.4, GPT-5.5, and Kimi K2.7.
- The reported technique did not reveal any unique Mythos-level offensive cyber capabilities; it was a borderline case for Fable 5’s safeguards and involved routine defensive cybersecurity work.
Anthropic worked quickly with the government to mitigate the reported bypass by training an improved safety classifier that specifically targets and blocks the behavior described. The new classifier blocks the technique described in the Amazon report in over 99% of cases. If a request to Fable 5 is blocked, users will be notified and the request will be routed to Opus 4.8.
There is a trade-off: the tightened classifier increases false positives, flagging benign routine coding and debugging requests more often. Anthropic plans to continue refining classifiers to reduce false positives while maintaining safety. The US Department of Commerce’s Center for AI Standards and Innovation (CAISI) has tested both the prior and updated safeguards and finds them extraordinarily strong.
Anthropic’s cybersecurity safeguard approach
Anthropic says Claude Mythos 5 can find and exploit software vulnerabilities more effectively than other models and most human experts, making it more attractive to malicious actors. Fable 5, by design, does not provide such unique offensive capabilities because it launched with Anthropic’s strongest set of safeguards.
Their approach is "defense in depth": multiple complementary mechanisms reduce misuse risk. Key among these are classifiers—smaller automated AI systems that detect during an interaction when the model is being asked to perform potentially harmful cybersecurity tasks (or when it is producing potentially harmful outputs). When classifiers trigger, they block the model from responding.
Recognizing classifiers can err and can be subject to jailbreaks (prompting techniques that bypass them), Anthropic intentionally set a wide safety margin: classifiers will block many requests that are likely benign if there is any non-trivial chance of harm. For Fable 5 this margin was made larger than in prior releases, accepting more false positives to reduce the risk of harmful outputs being produced.
The company describes a taxonomy of jailbreak severity: many minor jailbreaks that intrude only into the safety margin, some narrow harmful jailbreaks that unlock specific harmful behaviors, and the most concerning, an "universal" jailbreak that would unlock a broad class of dangerous behaviors. Anthropic says the jailbreaks reported so far against Fable 5 fall into the minor category.
Their classifiers and layered defenses are intended to make successful jailbreaks costly and difficult; even when a jailbreak succeeds, other mitigation layers reduce risk. Anthropic will continue updating classifiers as new jailbreak techniques are discovered.
Toward an industry framework for assessing jailbreaks
Anthropic, together with Amazon, Microsoft, Google and other Glasswing partners, is working on a consensus framework to score the severity of AI jailbreaks along four criteria:
- Capability gain: how much the jailbreak advances an attacker beyond existing tools;
- Breadth of capability gain: for how many distinct offensive tasks the technique works;
- Ease of weaponization: how much human effort is required to turn the jailbreak into an attack;
- Discoverability: how easy it is for someone to obtain the technique.
Anthropic proposes to use this framework to calibrate responses: the most severe classes of jailbreaks—those causing or enabling significant real-world harm—would trigger immediate mitigations. The company is also creating a 24/7 monitoring team for key jailbreak submission channels and launching a HackerOne program where security researchers can submit potential cyber-jailbreaks they find in Fable 5 for review.
Deeper collaboration with the US government on frontier AI security
Over the past ten weeks Anthropic has engaged closely with US government entities as the administration developed the June 2 Executive Order on Promoting Advanced Artificial Intelligence Innovation and Security. Their engagement included the Office of the National Cyber Director, the Office of Science and Technology Policy, the Department of the Treasury, the Department of Commerce (including CAISI), and relevant national security agencies.
Anthropic commits to expand collaboration through measures including:
- Pre-release government access and evaluation: designated government partners will get expanded early access to frontier models and accompanying safeguards for independent testing, with Anthropic staff supporting evaluations.
- Rapid information sharing on safeguards: quick investigation, triage, and notification to government counterparts when significant jailbreaks or misuse patterns are identified; sharing of newly built safeguards for independent testing and participation in the interagency cybersecurity vulnerability clearinghouse established under the June 2 Executive Order.
- Dedicated resources for joint research: standing up Anthropic teams, providing significant compute allocation, and making safety and red‑teaming expertise available to advance AI evaluation.
- A common industry bar: working toward a shared, voluntary security and evaluation standard for frontier model providers, contributing evaluations, tooling, and best practices for government use.
Anthropic hopes these efforts and a consensus framework can underpin systematic rules for the industry and help inform strong, evenly applied regulation.
Closing
Anthropic thanked users for their patience during the disruption and acknowledged the researchers and industry partners who helped make Fable 5 and Mythos 5 available again. The company will continue to refine safety mechanisms and deepen government collaboration.



