Claude Mythos 5: The Same Model, Minus the Guardrails
Claude Mythos 5 strips Fable 5's safety classifiers for vetted users only, forcing a fresh argument over who gets to use AI without a leash.

Ask Claude Fable 5 to help you understand how a piece of malware works, and there is a decent chance the request gets quietly rerouted to a more conservative model before you notice. Ask the exact same question through Claude Mythos 5, if you happen to be one of the small number of organizations approved to use it, and depending on your role you might get a direct answer.
Same weights. Same underlying training. A different answer, because Anthropic decided the person asking mattered as much as the question itself. That is the entire premise of Claude Mythos 5, and a month after its rocky debut alongside Claude Fable 5, it is turning into one of the clearer test cases yet for how the AI industry plans to handle models capable enough to be genuinely dangerous in the wrong hands.
What Mythos 5 actually removes
Fable 5 ships with automatic classifiers that watch for three categories of risk: offensive cybersecurity requests, dual-use biology or chemistry queries, and attempts to extract or distill the model's own capabilities. When one of those trips, the session gets handed off to the more restrained Claude Opus 4.8 instead. Anthropic has said this reroute fires in under five percent of sessions, according to the company's own launch announcement, but for a security researcher or biomedical scientist doing legitimate work in exactly those categories, a five percent interruption rate on your actual job is not a rounding error.
Mythos 5 is Anthropic's answer to that friction. Coverage from HokAI describes it scoring around 78 percent on ExploitBench, a benchmark built around real offensive security tasks, well above what Fable 5 would report given its own routing behavior around exactly those tasks. The model is not more capable in a raw sense. It is simply allowed to show its full capability to people Anthropic has decided it can trust.
That trust is not evenly distributed even within Mythos 5's user base. Cyber defenders admitted through the program get the cybersecurity classifiers lifted entirely. Biomedical researchers admitted through a separate track get the biology and chemistry restrictions lifted, while the cyber protections stay firmly in place. Nobody gets everything removed at once, and access is scoped narrowly to the specific dual-use category a given organization actually needs.
Project Glasswing: the gate, not the model
The mechanism for all of this is a program Anthropic calls Project Glasswing. According to a breakdown from TechJack Solutions, getting into Glasswing requires an invitation, a signed non-disclosure agreement, and approval from Anthropic made in direct consultation with the U.S. government. The company has said the kinds of organizations it is looking to admit include red team firms, vulnerability researchers, academic security labs, and government contractors, groups whose entire professional function already involves the categories of activity Fable 5's classifiers are built to catch.
The government's fingerprints on the approval process are not incidental. When export controls briefly shut down both Fable 5 and Mythos 5 in mid-June, the restoration of Mythos 5 access came in a specific, narrow form first, before the wider Fable 5 relaunch: a small group of cyber defenders and critical infrastructure providers, reinstated on the government's own terms, according to reporting from GovConWire. Anthropic is not the only party deciding who gets the unrestricted version of its own model.
The argument this keeps reopening
The core tension is not new to AI, but Mythos 5 makes it unusually literal. Split a model's capability into a public tier and a permissioned tier, and you are effectively deciding, on a rolling basis, which humans are safe to trust with which categories of dangerous knowledge. Get the gate too narrow and legitimate researchers get stuck behind guardrails meant for people acting in bad faith. Get it too wide and you have built an approval process that is really just theater around a capability that was never contained to begin with.
Reporting on the broader reaction, including analysis from Memeburn, frames the whole episode as a live argument over whether frontier safety guardrails are becoming too restrictive, too opaque, and too disruptive for the researchers they are ostensibly protecting the work of. It is a fair complaint. It is also worth noting that the same guardrail architecture is what let Anthropic keep Fable 5 broadly available at all, rather than gating the entire Mythos-class tier behind an approval process from day one.
There is a version of the AI safety debate that plays out mostly in position papers and congressional testimony. Mythos 5 is that debate showing up as a product decision instead, with a signup form, an NDA, and a government official somewhere in the approval chain. Whether that model of graduated, permissioned access becomes the template other labs follow, or a cautionary example of how quickly access control turns into a bottleneck, will depend less on the technology itself and more on how consistently Anthropic and its government partners can run the approval process at a scale beyond a few hundred vetted organizations.
For now, Project Glasswing remains small by design. Anthropic has described it as expanding over time rather than opening broadly, which means for the foreseeable future, the fullest version of one of the most capable AI models in the world will keep answering to a much shorter list of names than the public model sitting one tier below it.
Published in The Outspoken Digest



