Table of Contents
Claude Mythos 5 Explained: Why Some AI Is Restricted-Access
Claude Mythos 5 explained for parents: the same model as Fable 5 with safeguards off, why only vetted organizations get it, and what it teaches your kid.
There is an AI model your family cannot buy at any price. Claude Mythos 5, released June 9, 2026, is the same underlying system as the publicly available Claude Fable 5, with one difference: the safety classifiers are switched off. Anthropic sells it only to approved organizations inside a program called Project Glasswing, and here is Claude Mythos 5 explained in a single line: the ability to find security holes in software so you can patch them is the same ability you would use to break in.
That symmetry is the most useful thing a kid can learn from this story, and it applies well beyond AI.
Key Takeaways
- Claude Fable 5 and Claude Mythos 5, both released June 9, 2026, share the same capabilities and pricing ($10/$50 per million tokens); Fable includes safety classifiers, Mythos does not.
- Mythos is available only through Project Glasswing, which launched April 7, 2026 with 12 named partners including Apple, Google, Microsoft, AWS, NVIDIA, Cisco, and the Linux Foundation, plus 40-plus additional critical-infrastructure organizations.
- Glasswing partners found thousands of high-severity flaws, including a 27-year-old OpenBSD bug and a 16-year-old FFmpeg bug; Mozilla identified 271 Firefox vulnerabilities using an earlier Mythos preview.
- On June 12, 2026 the U.S. Commerce Department put both models under export controls; Anthropic pulled them worldwide and access returned July 1 after controls were lifted June 30.
- Mythos-class models carry mandatory 30-day data retention and logged human access, restrictions that do not apply to ordinary consumer Claude accounts.
Claude Mythos 5 explained: same brain, different brakes
A restricted-access model is an AI system a lab deliberately does not sell to the general public because some of its capabilities are dual-use. Anthropic’s own platform documentation states it plainly: Mythos 5 “shares Claude Fable 5’s capabilities without the safety classifiers,” is available through Project Glasswing, and is the successor to Claude Mythos Preview. Both models have a 1-million-token context window, both cost $10 per million input tokens and $50 per million output, and both carry a 30-day data retention requirement with all human access logged.
The difference is what happens when a request touches a sensitive area. On Fable 5, a classifier can decline. Anthropic’s refusals documentation names the categories: cyber (malware or exploit development, though “benign cybersecurity work can also trigger this category”), bio (biological harm, and again beneficial life-sciences work can trip it), frontier_llm (helping build competing AI models), reasoning_extraction, and general_harms. When a request is declined, the developer gets an ordinary response with stop_reason: "refusal" and can retry on a different Claude model. On Mythos 5, those classifiers are absent.
Anthropic reported that in early data, more than 95% of Fable sessions involved no fallback at all. So the restriction is narrow by design: it targets a small slice of requests, not general usefulness.
Why a lab would build a model it will not sell
The honest answer involves both a genuine public good and a genuine risk, and parents should hear both.
The public good is Project Glasswing, launched April 7, 2026. Its named launch partners were Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, with access later extended to more than 40 additional organizations that build or maintain critical software. Anthropic committed $100 million in usage credits, plus $2.5 million to Alpha-Omega and OpenSSF and $1.5 million to the Apache Software Foundation. The results are concrete: thousands of high-severity vulnerabilities found across every major operating system and browser, including a 27-year-old flaw in OpenBSD and a 16-year-old flaw in FFmpeg. On a vulnerability-reproduction benchmark called CyberGym, Mythos Preview scored 83.1% against Claude Opus 4.6’s 66.6%.
The risk is the mirror image. A system that can read a large codebase and find an exploitable flaw does not care whether you are the maintainer or the attacker. Add biology: Anthropic reported that in internal testing, Mythos 5 accelerated aspects of protein design “by around 10 times,” and produced molecular biology hypotheses that experts preferred about 80% of the time over Opus-class models in blind comparisons. Genuinely useful for drug discovery. Also the reason bio requests are classified.
Independent reporting adds a caveat worth keeping. By September 2026, critics noted that of the more than 10,000 high-or-severe vulnerabilities Glasswing partners reported finding, only about 10% had been disclosed and under 1% fixed. Finding flaws is faster than patching them, which is its own lesson about automation.
The government chapter, and what it shows about how AI is governed now
On June 12, 2026, three days after launch, the U.S. Department of Commerce directed Anthropic to place both models under export controls, prohibiting access by “any foreign national, whether inside or outside the United States,” including Anthropic’s own non-U.S. employees. Anthropic’s statement at the time explained the consequence: unable to verify nationality in real time across global cloud infrastructure, “we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.” Both models went dark worldwide.
The trigger was a demonstrated bypass. Anthropic characterized it as “a narrow, non-universal jailbreak, which essentially consists of asking the model to read a specific codebase and fix any software flaws,” and argued the resulting capability “is widely available from other models.” The company then trained an improved classifier that it said blocked the specific technique more than 99% of the time.
Commerce Secretary Howard Lutnick’s June 26 letter restored Mythos access for roughly 100 approved U.S. companies and agencies, and on June 30 the controls were lifted entirely, with Fable 5 returning globally on July 1. CNBC reported the lifting on June 30, and Lutnick’s letter reportedly reserved the right to reimpose restrictions. Nineteen days, one model family, and a directive that reached even Anthropic’s own non-U.S. citizen employees. For older teens interested in policy, that is a case study worth reading, and it pairs with our explainer on AI export restrictions.
Fable 5 versus Mythos 5, side by side
| Claude Fable 5 | Claude Mythos 5 | |
|---|---|---|
| Released | June 9, 2026 | June 9, 2026 |
| Who can use it | Any customer, no approval needed | Project Glasswing participants only |
| Safety classifiers | Yes: cyber, bio, frontier_llm, reasoning_extraction, general_harms | None |
| What happens to a flagged request | Declines with stop_reason: "refusal"; can be retried on Opus 4.8 or Opus 5 | Answered |
| Price per 1M tokens | $10 in / $50 out | $10 in / $50 out |
| Context window | 1M tokens | 1M tokens |
| Data retention | 30 days, logged access | 30 days, logged access |
| Successor | Fable 5.1 (Sept 1, 2026) | Mythos 5.1 (Sept 1, 2026), Glasswing only |
The row that surprises most people is the pricing row. Anthropic is not charging a premium for the unrestricted model. Access is gated by who you are, not what you pay, which is a different governance model from almost anything else in consumer software.
What to actually do at home
Use it as the dual-use conversation
Most kids have never been handed a concrete example of a technology that is identical whether used to protect or to attack. This is one, and it is current. Ask: what else works this way? Lock picks. Chemistry. Airplane design. The pattern is what matters, not the AI specifics.
Separate “restricted” from “dangerous to my kid”
Nothing about Mythos 5 affects a family’s Claude account. The classifiers your kid encounters are consumer safety settings, an entirely different layer. Conflating the two leads to bad household rules. Our guide to safety settings across ChatGPT, Claude, and Gemini covers the layer that does affect them.
Point teens toward the defender side
Glasswing is a cyber-defense program, and defense is where the job growth is. A teen who finds the OpenBSD and FFmpeg stories interesting is a teen who might enjoy security work. Our piece on blue-team careers has the specifics.
Read one refusal category out loud
Anthropic’s own documentation admits that “benign cybersecurity work can also trigger this category.” That sentence teaches something no press release does: safety systems make mistakes in both directions, and the people who build them know it.
What not to do
Do not tell your kid that restricted models are simply “the dangerous AI.” The same model that gets classified for biology also accelerated protein design tenfold in internal testing. Capability is not a moral category, and pretending otherwise leaves kids unable to reason about the real trade-offs.
What to Watch For Over the Next 3 Months
- Week 4: If your teen uses Claude Code or a developer tool, ask whether they have ever seen a refusal. Understanding what a classifier decline looks like removes the mystique.
- Month 2 red flags: Teens hunting for “uncensored” or “jailbroken” models on forums, or treating a refusal as a challenge rather than information.
- Month 3 self-check: Ask what fraction of Glasswing’s reported vulnerabilities had been fixed by September. If they remember “about 1%,” they have internalized that finding problems is not the same as solving them.
Frequently Asked Questions
Is Claude Mythos 5 more powerful than Fable 5?
Not in raw capability. Anthropic’s documentation says they share the same capabilities, specs, and pricing; Mythos simply lacks the safety classifiers. On cybersecurity and biology tasks it will answer where Fable declines, which makes it more capable in practice on those specific tasks.
Can I get access to Mythos 5?
No, unless your organization builds or maintains critical software infrastructure and is approved for Project Glasswing. Anthropic directs prospective participants to their Anthropic, AWS, or Google Cloud account team. Individuals and families cannot buy access at any price.
Does this affect my child’s Claude account?
No. Consumer accounts run on models like Claude Opus 5 with ordinary consumer safety settings. The Mythos restrictions concern enterprise and government access to a model that was never available to the public.
What is a safety classifier, in plain terms?
A separate system that inspects a request or response and can block it. On Claude Fable 5 and Opus 5, a block returns an ordinary response marked stop_reason: "refusal" with a category name like cyber or bio, and the developer can retry on a different model.
Why did the U.S. government get involved?
Amazon researchers demonstrated a bypass of Fable 5’s safeguards that produced code showing how a vulnerability could be exploited. On June 12, 2026, Commerce placed both models under export controls limiting access to U.S. nationals. Controls were lifted June 30 after Anthropic strengthened the classifier and agreed to notify the government of malicious activity.
Do other labs have restricted models?
Yes. OpenAI’s GPT-6 Astra system card, published September 3, 2026, describes it as the company’s first model at the “Critical” cybersecurity threshold and details trust-based access controls for high-risk research domains. Google’s Gemini 3.8 Flash Cyber ships with “a more permissive set of mitigations for cybersecurity” and is available only to trusted defenders through its Fairwind Program. Gated cyber capability is becoming an industry norm.
About the author
Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.
Sources
- Anthropic. (2026, June 9). “Introducing Claude Fable 5 and Claude Mythos 5.” Claude Platform Documentation. https://platform.claude.com/docs/en/models/fable-5/introducing-claude-fable-5-and-claude-mythos-5
- Anthropic. (2026, June 9). “Claude Fable 5 and Claude Mythos 5.” Anthropic News. https://www.anthropic.com/news/claude-fable-5-mythos-5
- Anthropic. (2026). “Refusals and fallback.” Claude Platform Documentation. https://platform.claude.com/docs/en/build-with-claude/refusals-and-fallback
- Anthropic. (2026, June 12). “Statement on the directive to suspend Fable 5 access.” https://www.anthropic.com/news/fable-mythos-access
- Anthropic. (2026, July 1). “Redeploying Claude Fable 5.” https://www.anthropic.com/news/redeploying-fable-5
- Anthropic. (2026, April 7). “Project Glasswing.” https://anthropic.com/glasswing
- Wikipedia. (2026). “Claude Mythos.” https://en.wikipedia.org/wiki/Claude_Mythos
- CNBC. (2026, June 30). “Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5.” https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
- VentureBeat. (2026, July 1). “Anthropic is bringing back Claude Fable 5 globally after US lifts export control order.” https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it
- OpenAI. (2026, September 3). “GPT-6 Astra System Card.” Deployment Safety Hub. https://deploymentsafety.openai.com/gpt-6-astra
- Google. (2026, September 2). “Introducing Gemini 3.8 Flash and 3.8 Flash Cyber.” The Keyword. https://blog.google/innovation-and-ai/models-and-research/gemini-models/3-8-flash-and-3-8-flash-cyber/