Anthropic’s Mythos model reportedly scared Washington senseless after cracking NSA classified systems during a red-team exercise in hours.
The AI outfit had been trumpeting Fable 5 and Mythos 5 barely 10 days earlier. Then, on 12 June, the Trump administration told it to restrict the models to US citizens only.
Since Anthropic could not verify nationality at scale, it pulled the plug globally with 90 minutes’ notice. Allies, researchers and foreign-national staff were all dumped outside the fence.
It was the first time the US government had slapped export controls directly on an AI model, rather than the silicon running it. But according to Techspot there was something even nastier going on behind the scenes and US spooks were running around like chickens with their heads cut off as the AI had found entry points to all of their systems.
Senator Mark Warner said General Joshua Rudd, who runs the NSA and US Cyber Command, told him Mythos had penetrated nearly all NSA classified systems during an authorised red-team test.
“Broke into almost all of our classified systems, not in weeks, but in hours,” Warner quoted Rudd as saying in the 11 June briefing.
When Anthropic first announced Mythos in April, it admitted the thing was too good at finding security holes for a public release. Instead, it opened Project Glasswing, a controlled programme with roughly 200 vetted partners.
Those partners included Amazon, the Fruity Cargo Cult Apple, Google, Microsoft, Nvidia, JPMorgan and the Linux Foundation.
Mythos had already found thousands of real-world flaws, including a 27-year-old OpenBSD bug and 271 new issues in Mozilla’s Firefox 150 browser.
Fable 5, which launched publicly on 9 June, used the same underlying model with safety classifiers bolted on. Those classifiers were supposed to spot dodgy requests and shunt them to a weaker model.
The official trigger was a jailbreak. On 12 June, the government told Anthropic it had heard of a way to dodge Fable 5’s safety classifiers and reach its sensitive cyber powers.
Anthropic said the warning was verbal only and described it as a “potential narrow, non-universal jailbreak”. It was given 90 minutes to act which no one could ever manage. The jailbreak report first went to the Commerce Department from Amazon, which is a major Anthropic investor and an AI rival. That is a tidy conflict pile for everyone to pretend is normal.
A researcher calling himself Pliny the Liberator then published what he claimed was Fable 5’s full system prompt to X and GitHub within 48 hours of launch. Anthropic pushed back. It said the jailbreak was limited, did not broadly defeat Fable 5’s safeguards and that similar problems existed in other frontier models.
“If this standard was applied across the industry, we believe it would essentially halt all new model deployments for all frontier model providers,” the company wrote.
Former Facebook chief security officer Alex Stamos said he had reviewed the underlying research and sided with Anthropic. “There were some valid findings but no unique capabilities that justify a reaction close to this,” he wrote on X.
Trump adviser David Sacks was having none of it. “It’s difficult to fathom how they could claim a jailbreak allowing operability of a cyber weapon could be defined as not ‘serious,'” he wrote.
The row has exposed a fairly obvious problem. The US has no clear, transparent framework for deciding when a model becomes too dangerous to sell, share or even test.
On 2 June, the Trump administration issued an executive order asking AI companies to give the government 30 days of pre-release access to frontier models. Fable 5 launched seven days later with no pre-brief. The 12 June ban became the stick after the voluntary carrot failed to interest anyone.
The deeper problem is that governments lack the access, data, and expertise to independently test proprietary frontier models. So they are left leaning on the same firms they are supposed to regulate.
The ban hit more than Anthropic customers. It locked out Five Eyes partners Australia, the UK, Canada and New Zealand with no warning. The UK AI Security Institute, widely seen as one of the leading bodies for frontier model testing, was cut off from systems it was already evaluating.
Five Eyes intelligence agencies then issued a rare joint statement saying: “Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months.”
NSA cybersecurity director David Imbordino and acting CISA director Nick Andersen were among the signatories. The warning was blunt about old security rot, including unpatched systems, weak identity controls and needless internet exposure.
“Cyber risk can no longer be treated as a purely technical issue. This is a core business risk and leadership responsibility.”
CyberScoop experts noted that the capabilities in Amazon’s threat intelligence report could apparently be reproduced with older models such as Claude Opus and Claude Sonnet. Open-source Chinese models beyond US export controls are lurking in the same green glowing reflective pool.
Open-source models have usually trailed frontier labs by six to eight months. That leaves the awkward question of whether restricting Fable 5 slows serious attackers, or just annoys allies and researchers.
As of Monday, Fable 5 and Mythos 5 were still offline for most users. Anthropic told reporters it was “very confident that in the coming days, the models will become available again”, which has aged like unrefrigerated fish.







