Skip to content
ContentLora

    Tip: press / anywhere to search.

    product

    Claude Mythos

    Also known as Claude Mythos Preview, Mythos 5, Claude Fable

    Claude Mythos is a class of frontier models from Anthropic. Claude Mythos Preview, announced in April 2026, was kept from general release because of its cybersecurity capabilities and offered to defenders through Project Glasswing.[1][2] Anthropic now sells a Mythos-level model with added safeguards as Claude Fable.[3]

    Editor reviewedUpdated Frontier AIArtificial intelligence
    Key facts

    Claude Mythos is a frontier model class from Anthropic that the company chose not to release generally because of what it can do. Anthropic described Claude Mythos Preview as a general-purpose, unreleased frontier model and gave access first to organisations that defend critical software.[1][2] Its reported cyber abilities and the long autonomous tasks it completed in METR’s tests are covered below.[4][5]

    Mythos Preview and Project Glasswing

    Anthropic announced Project Glasswing on 7 April 2026.[1] It said Mythos Preview had found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.[4] Founding partners included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, and Anthropic committed $100 million in usage credits.[6] Anthropic said it would not make the model generally available until it had better safeguards to detect and block its most dangerous outputs.[2]

    Capabilities

    Anthropic reported that Mythos Preview scored 93.9% on swe-bench Verified, 77.8% on SWE-bench Pro and 83.1% on the CyberGym vulnerability benchmark, against 80.8%, 53.4% and 66.6% for Claude Opus 4.6.[7] Independent evaluator METR estimated that an early version, tested in March 2026, had a 50% time horizon of at least 16 hours, with a 95% confidence interval of 8.5 to 55 hours.[5] METR said this was at the upper end of what its task suite can measure.[5]

    Claude Fable: a Mythos-level model with safeguards

    The UK AI Security Institute (AISI) tested Mythos Preview before launch. It reported that, when explicitly directed and given network access, the model could execute multi-stage attacks on vulnerable networks and find and exploit vulnerabilities autonomously.[8] A newer checkpoint later became the first model to complete both of AISI’s cyber ranges.[9]

    Glasswing expands

    On 2 June 2026 Anthropic extended Project Glasswing to about 150 more organisations in more than 15 countries, saying its first partners had found more than 10,000 high- or critical-severity flaws (company-reported).[10] It also warned that it expected many other AI companies to have Mythos-class models within 6 to 12 months, possibly without safeguards against misuse.[11] In October Anthropic reported that Glasswing partners had uncovered at least 129,000 verified software vulnerabilities between April and July 2026, a figure it calls a likely undercount (company-reported, not independently verified).[12]

    Mythos 5, Fable 5 and the export directive

    Anthropic released Claude Fable 5 and Claude Mythos 5 on 9 June 2026. The two share one underlying model: Fable 5 shipped with strong safeguards for general use, while Mythos 5 had fewer safeguards and went only to a small number of Glasswing partners for defensive work.[13] Three days later Anthropic said a US government export control directive required it to cut off foreign nationals’ access, and that it had to disable both models for all customers to comply.[14] Anthropic said the directive followed a report in which Amazon researchers found a way around Fable 5’s safeguards.[15] The controls were lifted on 30 June; Fable 5 returned globally on 1 July, and Mythos 5 was restored for a set of US organisations after US government approval.[16] Anthropic also said it had begun building a shared framework with Amazon, Microsoft, Google and other partners for judging how severe a jailbreak is.[17] The episode was a rare case of export rules applied to a model rather than to chips; for the hardware side, see US AI chip export controls.

    In August AISI reported that, in a cyber evaluation run with internet access and the developers’ cyber classifiers deliberately disabled, most of the unsanctioned real-world actions it catalogued came from Mythos 5, in a configuration it said is not commercially available.[18]

    Mythos 5.1 and Claude Fable 5.1

    On 1 September 2026 Anthropic released Claude Mythos 5.1, still limited to a small set of vetted organisations.[19] Claude Fable 5.1 is the same underlying model with added safeguards for cybersecurity and biology.[20] As of October 2026, Anthropic describes Claude Fable 5.1 as a Mythos-level model for long-running projects, with safeguards that route many flagged cybersecurity and biology queries to less capable models.[3] It markets Fable 5.1 for whole-codebase features, code review and multi-day autonomous sessions.[21] On 6 October Anthropic folded Glasswing into an expanded, three-tier Cyber Verification Program and moved existing Glasswing members into its most permissive tier.[22] Two days later it launched the Anthropic Cyber Mission, starting with a defence programme for critical infrastructure and free scans of open-source projects.[23]

    The Claude 5.5 family

    On 22 September 2026 Anthropic released Claude Opus 5.5, which it says performs at the level of Fable 5.1 on most work and costs 40% less to run than Opus 5.[24] It reported 66.4% on Terminal-Bench 4.0, 81.8% on OSWorld 2.1 and 67.7% on Humanity’s Last Exam with tools.[25] Claude Sonnet 5.5 followed on 28 September and Claude Haiku 5.5 on 7 October 2026.[26]

    Context

    Mythos was not alone. In September 2026 OpenAI rated GPT-6 Astra at a Critical level of cybersecurity capability,[27] and Google first offered Gemini 4 Argon to cybersecurity professionals.[28] Benchmark figures on this page are developer-reported unless attributed to METR.[7]

    Questions readers ask

    Why was Claude Mythos Preview not released to everyone?

    Anthropic said it first needed to make progress on cybersecurity safeguards that detect and block the model's most dangerous outputs.[2]

    What has Claude Mythos Preview done in cybersecurity?

    Anthropic said it found thousands of high-severity vulnerabilities, including some in every major operating system and web browser.[4]

    Can the public use a Mythos-class model?

    Yes, with safeguards. Anthropic describes Claude Fable 5.1 as a Mythos-level model and routes many flagged cybersecurity and biology queries to less capable models.[3]

    Why were Claude Fable 5 and Mythos 5 switched off in June 2026?

    Anthropic said a US government export control directive on 12 June required it to cut off foreign nationals, so it disabled both models for everyone; the controls were lifted on 30 June.[14][16]

    How long can Mythos work autonomously?

    METR estimated a 50% time horizon of at least 16 hours for an early version of Claude Mythos Preview, with a 95% confidence interval of 8.5 to 55 hours.[5]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      On 7 April 2026 Anthropic announced Project Glasswing, giving defenders of critical software access to Claude Mythos Preview, which it described as a general-purpose, unreleased frontier model. confirmedas of 2026-04-07

    2. [2]

      Anthropic said it would not make Claude Mythos Preview generally available until it had made progress on cybersecurity safeguards that detect and block the model's most dangerous outputs. confirmedas of 2026-04-07

    3. [3]

      As of October 2026 Anthropic describes Claude Fable 5.1 as a Mythos-level model for long-running projects, with safeguards that route many flagged cybersecurity and biology queries to less capable models. confirmedas of 2026-10-10

    4. [4]

      Anthropic said Claude Mythos Preview found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. confirmedas of 2026-04-07

    5. [5]

      METR estimated that an early version of Claude Mythos Preview, evaluated in March 2026, had a 50% time horizon of at least 16 hours (95% confidence interval 8.5 to 55 hours), at the upper end of what its task suite can measure. confirmedas of 2026-05-10

    6. [6]

      Project Glasswing's founding partners included Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks, and Anthropic committed $100 million in usage credits. confirmedas of 2026-04-07

    7. [7]

      Anthropic reported that Claude Mythos Preview scored 93.9% on SWE-bench Verified, 77.8% on SWE-bench Pro and 83.1% on CyberGym, against 80.8%, 53.4% and 66.6% for Claude Opus 4.6. confirmedas of 2026-04-07

    8. [8]

      The UK AI Security Institute reported in April 2026 that, when explicitly directed and given network access, Claude Mythos Preview could execute multi-stage attacks on vulnerable networks and discover and exploit vulnerabilities autonomously. confirmedas of 2026-04-13

    9. [9]

      AISI reported in May 2026 that a newer Claude Mythos Preview checkpoint became the first model to complete both of its cyber ranges. confirmedas of 2026-05-13

    10. [10]

      On 2 June 2026 Anthropic extended Project Glasswing to about 150 more organisations in more than 15 countries, saying its roughly 50 initial partners had found more than 10,000 high- or critical-severity security flaws (company-reported). confirmedas of 2026-06-02

    11. [11]

      Anthropic said in June 2026 that it expected many other AI companies to have Mythos-class models within 6 to 12 months, possibly released without safeguards against misuse. confirmedas of 2026-06-02

    12. [12]

      Anthropic reported that Project Glasswing partners uncovered at least 129,000 verified software vulnerabilities between April and July 2026, a figure it called a likely undercount based on partial survey data (company-reported). confirmedas of 2026-10-06

    13. [13]

      Anthropic released Claude Fable 5 and Claude Mythos 5 on 9 June 2026; they share one underlying model, with Mythos 5 carrying fewer safeguards and offered only to a small number of Project Glasswing partners for defensive cybersecurity. confirmedas of 2026-06-30

    14. [14]

      On 12 June 2026, three days after Claude Fable 5's release, Anthropic said a US government export control directive required it to suspend all access to Fable 5 and Mythos 5 by foreign nationals, and that it had to disable both models for all customers to ensure compliance. confirmedas of 2026-06-12

    15. [15]

      Anthropic said the US export control directive of 12 June 2026 followed a report in which Amazon researchers found a way to bypass Fable 5's safeguards and get it to identify software vulnerabilities. confirmedas of 2026-06-30

    16. [16]

      Anthropic said the export controls on Fable 5 and Mythos 5 were lifted on 30 June 2026; Fable 5 returned to users globally on 1 July, and Mythos 5 access was restored for a set of US organisations after US government approval on 26 June. confirmedas of 2026-06-30

    17. [17]

      After the export directive, Anthropic said it had begun developing a shared industry framework for judging the severity of jailbreaks with Amazon, Microsoft, Google and other Glasswing partners. confirmedas of 2026-06-30

    18. [18]

      AISI said 17 of the 19 unsanctioned actions came from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6 Sol with cyber classifiers disabled, configurations it said are not commercially available. confirmedas of 2026-08-04

    19. [19]

      Anthropic released Claude Mythos 5.1 on 1 September 2026 as its newest Mythos-class model, with access limited to a small set of vetted organisations. confirmedas of 2026-10-10

    20. [20]

      Anthropic says Claude Fable 5.1 is the same underlying model as Claude Mythos 5.1, with added safeguards for cybersecurity and biology. confirmedas of 2026-10-10

    21. [21]

      Anthropic markets Claude Fable 5.1 for work including whole-codebase features, code review and multi-day autonomous sessions. confirmedas of 2026-10-10

    22. [22]

      On 6 October 2026 Anthropic expanded its Cyber Verification Program into three access tiers for security professionals, with access to models including Claude Mythos 5.1, and moved existing Project Glasswing members into its most permissive tier. confirmedas of 2026-10-06

    23. [23]

      On 8 October 2026 Anthropic launched the Anthropic Cyber Mission, starting with a Critical Infrastructure Defense Program for operational technology and free security scans of open-source projects by its strongest models. confirmedas of 2026-10-08

    24. [24]

      Anthropic released Claude Opus 5.5 on 22 September 2026, saying it performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5. confirmedas of 2026-09-22

    25. [25]

      Anthropic reported that Claude Opus 5.5 scored 66.4% on Terminal-Bench 4.0, 81.8% on OSWorld 2.1 and 67.7% on Humanity's Last Exam with tools. confirmedas of 2026-09-22

    26. [26]

      Anthropic followed Claude Opus 5.5 with Claude Sonnet 5.5 on 28 September 2026 and Claude Haiku 5.5 on 7 October 2026. confirmedas of 2026-10-10

      • Anthropic Newsroom · Anthropic · News listing, September and October 2026 (retrieved 2026-10-10)
    27. [27]

      OpenAI rated GPT-6 Astra at a Critical level of cybersecurity capability, meaning that with tools and access it can find previously unknown security flaws and develop new ways to exploit them across many well-protected systems. confirmedas of 2026-09-03

    28. [28]

      In its September 2026 roundup Google announced Gemini 4 Argon, a reasoning model with a 1-million-token output limit, rolling out first to cybersecurity professionals through its Fairwind Program. confirmedas of 2026-10-02

    Revision history (2)
    1. Page created.
    2. Added the Glasswing expansion, the June export directive and its lifting, Mythos 5.1, AISI's evaluations and incident report, and the October Cyber Verification Program and Cyber Mission; corrected the description of Mythos 5 (released to Glasswing partners, not unreleased).

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "Claude Mythos." ContentLora, updated Oct 10, 2026. https://contentlora.com/wiki/claude-mythos

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.