On 1 July 2026, Anthropic restored global access to Claude Fable 5, the most advanced artificial intelligence model the company has made available to the general public. The restoration ends 18 days of suspension, triggered by a US government export control order following the discovery of a technique that bypassed the model's cybersecurity safeguards. The case offers a concrete example of how government regulation can affect, directly and immediately, the availability of AI tools that companies worldwide already run inside their operations.
The launch and the suspension
Anthropic launched Claude Fable 5 and Claude Mythos 5 on 9 June 2026. Both models share the same technical base but differ in purpose and in the level of safeguards applied. Mythos 5, with fewer restrictions, was distributed only to a small group of trusted US government partners under Project Glasswing, aimed at defensive cybersecurity work. Fable 5, by contrast, launched to the general public with what Anthropic describes as the strictest set of safeguards ever applied to one of its models, after doubling in the preceding month the number of researchers and engineers dedicated to that work.
That balance was interrupted on 12 June, when the United States government issued an export control order covering both models. The measure followed a report from Amazon researchers of a technique capable of circumventing Fable 5's safeguards: through specific prompts, the model went as far as identifying software vulnerabilities and, in one case, generating code demonstrating how to exploit one of them.
The order required immediate restriction of access for any user who was not a US citizen, inside or outside the country. According to Anthropic, no reliable mechanism existed to verify users' nationality in real time, so the company chose to suspend access to both models globally, for all users, until the situation could be resolved.
The technical and regulatory response
Over the following two and a half weeks, Anthropic worked jointly with the US government —including the Office of the National Cyber Director, the Office of Science and Technology Policy, the Treasury Department and the Commerce Department, through its Center for AI Standards and Innovation (CAISI)— and with Amazon to review the report and the available evidence.
According to the company, its own testing showed that less capable models —among them Claude Opus 4.8, GPT-5.5 and Kimi K2.7— could identify the same reported vulnerabilities, and that virtually every model evaluated, including Claude Haiku 4.5, Sonnet 4.6 and Opus 4.6 and 4.7, could reproduce the exploitation demonstration for the specific vulnerability named in the report. Anthropic maintains that the reported technique did not expose cybersecurity capabilities exclusive to Mythos, but rather an edge case in Fable 5's safeguards tied to routine cyberdefence tasks.
On the basis of that analysis, Anthropic trained a new safety classifier targeted specifically at the behaviour flagged in the report. The company states that this classifier blocks the reported technique in more than 99% of cases, and that Department of Commerce researchers evaluated both the previous and the new safeguards, rating them "extraordinarily robust". When a request to Fable 5 is blocked by the new classifier, it is automatically rerouted to Claude Opus 4.8.
On 30 June, the United States government lifted the export controls on both models. Mythos 5 was restored on 26 June for a specific set of authorised US organisations, while Fable 5 became globally available again from 1 July.
Availability and what it means for businesses
Fable 5 is available again on Claude.ai, Claude Platform, Claude Code and Claude Cowork. For Pro, Max, Team and certain Enterprise plans, the model is included up to 50% of weekly usage limits until 7 July, after which access continues through additional usage credits. Access via AWS, Google Cloud and Microsoft Foundry is being restored progressively.
Beyond the specific incident, the episode drove two initiatives with direct implications for the sector. The first is a consensus framework Anthropic is developing alongside Amazon, Microsoft, Google and other Project Glasswing partners to objectively assess the severity of AI jailbreaks —techniques that bypass a model's safeguards. The proposal sets out four criteria: the capability uplift the technique offers over existing tools, the breadth of offensive tasks it works for, how easily it can be turned into a real attack, and how easy it is for third parties to discover or access it. No equivalent standard currently exists in the AI industry to the Common Vulnerability Scoring System (CVSS), used for years to score software vulnerabilities.
The second is a broader commitment to collaboration with the US government, including early access for pre-launch evaluations of future frontier models, faster information sharing on safeguards and misuse findings, dedicated resources for joint AI safety research, and a push for a common industry-wide safety standard. Anthropic also launched a HackerOne programme for security researchers to report potential cybersecurity jailbreaks found in Fable 5.
Conclusion
The Fable 5 case illustrates a type of risk that organisations depending on frontier AI models are starting to have to consider explicitly: a provider's availability depends not only on its technical or operational stability, but also on the regulatory framework it operates under, which can change abruptly. At the same time, the episode accelerated a joint effort among several of the leading AI developers to establish common risk assessment criteria — a step that, if it holds, could give both companies and governments greater predictability in managing the deployment of increasingly capable models.
Does your team already factor regulatory risk into its AI vendor strategy? Follow us for more analysis on the business of artificial intelligence, or get in touch if you would like to talk about applying this in your organisation.
Sources
- Anthropic. "Redeploying Fable 5". Anthropic News. 2026. https://www.anthropic.com/news/redeploying-fable-5
- Anthropic. "Claude Fable 5 and Claude Mythos 5". Anthropic News. 2026. https://www.anthropic.com/news/claude-fable-5-mythos-5
- Anthropic. "Statement on the US government directive to suspend access to Fable 5 and Mythos 5". Anthropic News. 2026. https://www.anthropic.com/news/fable-mythos-access
- TechCrunch. "Anthropic's Claude Fable 5 is a version of Mythos the public can access today". 2026. https://techcrunch.com/2026/06/09/anthropics-claude-fable-5-is-a-version-of-mythos-the-public-can-access-today/
- CNBC. "Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5". 2026. https://www.cnbc.com/2026/06/30/anthropic-says-trump-admin-has-lifted-export-controls-on-claude-fable-5-and-mythos-5.html
- VentureBeat. "Anthropic is bringing back Claude Fable 5 globally after US lifts export control order". 2026. https://venturebeat.com/technology/anthropic-is-bringing-back-claude-fable-5-globally-after-us-lifts-export-control-order-where-can-enterprises-access-it
- The Hacker News. "Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls". 2026. https://thehackernews.com/2026/07/anthropic-restores-claude-fable-5-after.html
- Infosecurity Magazine. "Anthropic's Fable 5 and Mythos 5 Are Back with New Security Guardrails". 2026. https://www.infosecurity-magazine.com/news/anthropic-fable-mythos-back/



