Anthropic’s ‘Mythos’ Crisis: A Timeline of AI, Security, and Government Intervention
The core of the narrative involves the model's advanced capability to discover and exploit software vulnerabilities, which prompted both a limited private release and, later, a national security directive from the Trump administration.
The Announcement of 'Mythos' and Project Glasswing
In early April 2026, Anthropic formally announced the development of a new frontier AI model, referred to as 'Claude Mythos Preview.' According to a data leak preceding the official announcement, the model was internally codenamed "Capybara." The company stated the model was a general-purpose system that, due to its advanced code and reasoning skills, demonstrated a "step change" in its ability to discover high-severity vulnerabilities and autonomously develop working exploits for major operating systems, web browsers, and other software.
Citing the risk of misuse, Anthropic announced it would not release the model to the general public. Instead, it launched "Project Glasswing," an industry consortium that provided limited access to the model. The stated goal was to give cybersecurity defenders a head start in identifying and fixing vulnerabilities before the technology became more widely available. Initial partners in the consortium included Amazon, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks.
Reactions and Independent Testing
The announcement generated significant discussion within the cybersecurity community. Some experts expressed concern, while others questioned the extent of the model's novelty. Alex Stamos stated, "LLMs have now bypassed human capability for bug finding."
Shortly after the announcement, several organizations reported results from testing the model:
- Mozilla reported that testing Claude Mythos Preview led to the identification of 271 vulnerabilities in Firefox 150. Mozilla CTO Bobby Holley stated that while the model did not find vulnerabilities beyond the capability of an elite human researcher, the volume of findings represented a significant change.
- Cloudflare found 2,000 bugs, of which 400 were classified as high or critical severity.
- Anthropic reported that, in collaboration with partners, the model found over 10,000 high- or critical-severity vulnerabilities. The company also stated it was used to find a 27-year-old vulnerability in OpenBSD and a 17-year-old bug in FreeBSD (CVE-2026-4747) .
Government and Regulatory Scrutiny
"The world may not have the ability to protect the international monetary system against the massive cyber risks posed by such technology." — IMF Managing Director Kristalina Georgieva
The capabilities of the Mythos model prompted meetings between top U.S. financial regulators and major bank CEOs. Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent convened a meeting with the heads of Bank of America, Citigroup, Goldman Sachs, Morgan Stanley, and Wells Fargo to discuss potential systemic cybersecurity risks. JPMorgan Chase CEO Jamie Dimon was unable to attend the meeting. During the meeting, officials also reportedly encouraged the banks to use the model to detect vulnerabilities.
International Monetary Fund (IMF) Managing Director Kristalina Georgieva expressed concern, stating in an interview that the world may not have the ability to protect the international monetary system against the "massive cyber risks" posed by such technology. She called for more attention to regulatory guardrails.
The Release of Fable 5 and Subsequent Government Export Controls
On June 9, 2026, Anthropic released two new AI models: Claude Mythos 5, an iteration of its most capable cybersecurity model, and Claude Fable 5, a publicly available version intended for general use. Fable 5 was designed to include safeguards, or "guardrails," that would block its use for offensive cybersecurity tasks, routing those requests to a weaker model. Anthropic stated that in over 95% of sessions, Fable 5 would behave like the more powerful Mythos 5.
Three days after the release, on Friday, June 12, the U.S. Commerce Department issued a national security directive ordering Anthropic to suspend access to both Fable 5 and Mythos 5 by any foreign national, including the company’s own foreign national employees. Anthropic subsequently disabled access to the models for all users globally to ensure compliance. Access to other Anthropic models was not affected.
Anthropic stated that the directive provided no specific details but that the company understood the government’s concern related to a potential method to "jailbreak" Fable 5. Anthropic disputed the severity of the vulnerability, describing it as a "narrow, non-universal jailbreak" with capabilities it argued were already replicable using other publicly available models, such as OpenAI's GPT-5.5. The company stated it disagreed that such a finding warranted recalling a commercial model deployed to hundreds of millions of people.
Reported events leading to the directive included reports that Amazon CEO Andy Jassy raised concerns with senior U.S. officials after Amazon researchers found a method to bypass Fable 5’s guardrails. The National Security Agency (NSA) subsequently reviewed and validated these findings. A White House official stated the directive was a "last resort" after hours of failed attempts to secure voluntary compliance from Anthropic.
Responses and Reactions
The government's action generated a wide range of responses.
- Anthropic argued the directive was disproportionate and lacked due process, though it complied.
- Cybersecurity Researchers: A group of 76 cybersecurity experts, including Alex Stamos, Casey Ellis, and Katie Moussouris, published an open letter calling on the government to lift the order. They argued the restriction removed powerful tools from defenders and that the reported "jailbreak" did not constitute a real threat. Katie Moussouris stated the Amazon paper did not describe a proper jailbreak.
- Industry and Government Leaders:
- David Sacks, a former White House AI advisor, supported the export controls, stating the administration values Anthropic’s capabilities but expects cooperation on safety.
- Pentagon Chief Information Officer Kirsten Davies wrote that "some things are simply more important than revenue cycles, clickbait, and pre-IPO valuation."
- OpenAI CEO Sam Altman expressed reservations about the government selecting customers for AI models. OpenAI also agreed to allow the administration to screen users of its new GPT-5.6 Sol model.
- International Leaders: Several foreign government leaders and politicians cited the shutdown as evidence for the need to reduce dependence on U.S. technology and develop domestic AI capacity. Former French Prime Minister Gabriel Attal characterized the incident as the start of "the AI war." Canadian Prime Minister Mark Carney stated it highlighted the risk of overreliance on a single partner for critical resources.
Partial Reversal and Authorization for Limited Use
"Some things are simply more important than revenue cycles, clickbait, and pre-IPO valuation." — Pentagon CIO Kirsten Davies
Following two weeks of negotiations, on June 26, the U.S. Commerce Department partially reversed the ban. Commerce Secretary Howard Lutnick sent a letter to Anthropic authorizing the redeployment of the Claude Mythos 5 model to over 100 approved U.S. organizations that operate and defend critical infrastructure. The license requirements were revised to permit access by the foreign national employees of those approved organizations and of Anthropic.
Anthropic stated it was restoring access for these organizations and was continuing to work with the government to expand access further. The directive regarding Fable 5 remained in effect, and discussions for its potential release were ongoing. OpenAI did not believe this government access process should become the long-term default.
Broader Context: Legal and Ethical Disputes
The export control event occurred within the context of an ongoing legal dispute between Anthropic and the Trump administration. In February, the administration ordered federal agencies to stop using Anthropic’s models after the company refused the Pentagon's contract terms for unrestricted use, citing concerns about the use of its AI for autonomous weapons and mass surveillance. In March, the Department of Defense designated Anthropic a "supply chain risk." Anthropic filed lawsuits challenging this designation, with litigation ongoing.