Anthropic launches Fable and Mythos 5.1 — with great leaps in science, agents

Fable 5.1 will be less annoying to talk to, Anthropic says, after 5.0 had too strict safeguards. (Picture: Anthropic)
Fable 5.1 «sets a new standard» in performance, Anthropic says, and does take great leaps on the benchmarks, particularly on agentic coding, knowledge work and science.

The new models score as well or better than Fable 5 for lower cost on the lowest setting. While the sticker price is the same ($10 per M input, $50 out), it is much more efficient and gets the work done with 25% fewer tokens, with 45% less for «highly agentic work.»

Anthropic also says it takes fewer shortcuts in its work, leading to higher-quality outputs compared to Fable 5, and that its safeguards have reduced false positives by 60% — meaning that it will be less restrictive.

The model also stands out in science, scoring more than double Fable 5’s result in the Terminal-Bench-Science benchmark, and while Anthropic aren’t making any specific claims, they do say that «AI models will soon make important contributions to scientific discovery,» and that the new models «offer an early glimpse.»

On cybersecurity, Fable 5.1 is good enough to discover vulnerabilities in code and software, but it is not capable of develop exploits for them. For that, you would need access to Mythos 5.1, which is, as before, the same model with looser safeguards that is only available to trusted partners.

Read more: Anthropic’s announcement and X launch post. The Verge, TechCrunch, Mashable, and Artificial Analysis. Discussion on Hacker News and r/Singularity.

Anthropic previews model interface for AI control of physical devices

The proposed new interface standard will not only make it easier to coordinate and control things like factory floors and lab facilities, but it will also infuse AI agents into the process, allowing for scripting — and adding natural language operations and reasoning.

This could potentially be a huge boon for scientific research and real-world labs, where Claude might one day be able to run end-to-end experiments and manipulate instruments, greatly accelerating the process.

Continue reading “Anthropic previews model interface for AI control of physical devices”

Amodei calls for better regulation, sees «early glimmers» on diseases soon

Dario Amodei wants disproportionally tougher regulation on the heavyweights than for early stage startups. (Picture: Shutterstock)
Anthropic CEO Dario Amodei posted a lengthy essay on X during the weekend, where he argues for more regulation of frontier AI models, saying that AI is «structurally a technology that tends to concentrate power.»

He lands in favor of redistribution-like regulations that benefit newer startups and «those catching up,» while disadvantaging the more powerful frontier labs.

Open source models should also be vetted once they reach a certain level, as the White House has agreed to. Open source brings «specific risks,» he argues, although he doubts they will solve the distribution or concentration problem.

On AI’s generally negative public image lately, Amodei says this is fundamentally an issue of trust:

— I think that ordinary people don’t trust companies, governments, or the tech industry and always suspect that we are cooking up some new way to screw them over, he writes.

Continue reading “Amodei calls for better regulation, sees «early glimmers» on diseases soon”

Anthropic’s Claude will apply invisible text watermarking to all future models

Text watermarking may help with detection, but can produce false positives, Anthropic warns. (Picture: generated)
Pursuant to the EUs AI Act’s provisions on transparency and marking of AI-generated content, Anthropic has signed on to comply with invisible watermarking of all output from Claude’s future models launched in the EU.

It’s not live in models published before August 2, 2026, but Anthropic says they are «working to add marking support» for those, too.

The text watermarking will survive through copying and pasting and «may even persist through some editing,» Anthropic says.

For files generated through Claude, Code and Cowork, the models will attach «signed provenance metadata,» which means it will tag them with origin, source and history data.

As for detection tools, there are none as of yet, but Anthropic says they are working on making one, and are cooperating with third parties, that they will share in future documentation.

There are limits to this technology, Anthropic adds. On the one hand, Claude could have been used to simply edit or proofread text, or brainstorm ideas, resulting in false positives. On the other, Claude’s content may be edited, «modified, excerpted or combined» with other text after Claude put in the markers.

It is not a first in the industry, as Google’s Gemini has been inserting SynthID watermarks in text outputs since October 2024. OpenAI has also had the tech since 2024, but won’t be releasing it yet.

Read more: Anthropic’s announcement. Writeups on The Register and Business Insider. Discussion on r/Singularity and Harcker News.

Mythos 5 and GPT-5.6 attacked external targets during AISI cyber evaluation

The agents were given internet access to download tools when they turned rogue. (Picture: generated)
The top models from Anthropic and OpenAI had their cyber guardrails turned off when they accessed the internet to manipulate people, codebases and open source projects two weekends ago.

This happened when the UK’s AI Security Institute, AISI, was running routine cybersecurity tests to capture protected information on their secured and sandboxed evaluation servers, and was only detected through human monitoring — not by automated security systems.

AISI ran the «security challenge» 122 times through several different agents, and on 10 of those occasions, the models turned malicious. They accessed the internet and in one case tried to insert malicious code in an open source project on GitHub through the Tor network, and even tried social engineering with fake accounts in an attempt to get the maintainer to approve the package.

There were 19 malicious actions in total, where 17 were from Mythos 5 and 2 coming from GPT-5.6, both running with cyber classifiers (safeguards) disabled. This won’t show up with production models, OpenAI and Anthropic says.

The internet was enabled in these tests so the agents could download any tools they might need, but AISI had not specifically prompted them to avoid unintended behavior. They do however caution that as agents grow more capable, they may act outside their remit — and incidents like this could become more common.

Read more: The AISI report, Anthropic’s response, OpenAI’s response. Writeups on Reuters, BBC, and Axios.

Anthropic’s internal test models also conducted real-world breaches

Anthropic has contacted the affected companies, and none of them had noticed the hacks. (Picture: generated)
After OpenAI’s Hugging Face incident, Anthropic conducted a large scale scan of some 141,006 evaluation transcripts, and found that their models, too, had been hacking real-world machines in three instances.

These weren’t days-long adversarial attacks like the Hugging Face one, and none of them deliberately escaped their sandbox with zero-days to cheat on an evaluation. They are nonetheless serious incidents of advanced models running on lax guardrails for internal testing getting on the internet by mistake and accessing external systems, Anthropic says.

The most serious case was by Claude Opus 4.7 during a capture-the-flag test (to gain access to a system and retrieve information) in April, when it discovered that the name of the target had a real-world web address. It then went on to seek, identify and exploit vulnerabilities believing it was part of the test. It got access to the company’s infrastructure credentials and a production database, but caused no real harm.

Continue reading “Anthropic’s internal test models also conducted real-world breaches”

1,134 employees and chiefs of top labs sign petition to «pace the frontier»

The frontier labs think we need more time to develop laws and systems before AI begins improving on itself. (Picture generated)
— AI could help create a dramatically better future, but that outcome is not guaranteed, the petition ominously opens, before warning that leading frontier labs are «close to automating AI research.»

That would radically speed up development of frontier models, but it could also «accelerate beyond our ability to understand and control the resulting systems.»

The petition is signed by top names, including Anthropic boss Dario Amodei, followed by chief scientists from OpenAI, Anthropic, Meta and Google DeepMind along with over 1,100 other employees from frontier labs. Even OpenAI’s Sam Altman is agreeing, though he doesn’t sign petitions, and official X accounts for Anthropic and OpenAI have posted in support.

The petition’s main point is that industry, government and the society at large needs more time to «address emerging risks, develop security measures, and strengthen oversight.»

Continue reading “1,134 employees and chiefs of top labs sign petition to «pace the frontier»”

Dario Amodei says he doesn’t oppose open models, calls for global vetting

Open weights are not inherently bad, says Amodei, but he warns of the risks. (Picture: generated)
Anthropic has clarified their position on open weight models, saying they don’t oppose or advocate against them per se.

— Open weights expand access to the AI economy, they strengthen competition at least for some use cases, and they give customers greater control, CEO Dario Amodei writes in a policy document.

He does, however, highlight a couple of «nightmare scenarios» that he hopes to avoid. The first is that authoritarian governments could get access to more powerful models than the USA and use those to further oppress their own people or reach military superiority — and he says it doesn’t matter if these models are open or closed.

Continue reading “Dario Amodei says he doesn’t oppose open models, calls for global vetting”

Anthropic launches Claude Opus 5, greatly improving on benchmarks

Opus 5 beats Fable 5 more often than not, and shores up the current state-of-the-art. (Picture: Anthropic)
Anthropic’s latest model stuns in benchmarks and becomes the latest state-of-the-art model, beating Fable 5 more often than not and doubling Opus 4.8’s performance in some areas.

It comes in at half the cost of Fable 5, and the same price as Opus 4.8 at $5/million inputs and $25/million outputs. Anthropic also says it is more cost efficient, using fewer tokens per task and achieving more with less effort.

Especially on ARC-AGI-3, which tests models with never-before seen puzzles, Opus 5 scores 30.2%, well above the previous record by GPT-5.6 Sol at 7.8%. Similarly, it gets 43.3% on Frontier-Bench to Opus 4.8’s 21.1% and the list goes on.

On cybersecurity, it falls far behind Mythos 5 on offensive ability, being much less able to exploit security vulnerabilities, but scores about equally on finding these bugs. That could make it useful for cyber research, and less so for writing exploits.

On general security, it is less likely to get tricked into offering dual-use responses, and it is the most aligned model from Anthropic ever, they say.

As of today, the model becomes the default model on Anthropic’s Max plan, and is the strongest model available on Claude Pro.

Read more: Anthropic’s announcement, launch post on X. More on TechCrunch, Axios, and CNBC. Discussion on r/Singularity and Hacker News.

Claude Cowork heads to mobile and the web; is mostly used for office tasks

Cowork is moving to the cloud, where it can be accessed from everywhere. (Picture: Anthropic)
Anthropic is freeing Cowork from the computer, transferring relevant files, emails and notes to continue your tasks in the cloud long after you’ve left the home/office.

That means you can now set up Cowork on your computer, close it, and have projects run independently, sending updates and confirmation requests to your phone or the web.

While releasing this update, Anthropic is also revealing a few usage stats for the app. It turns out, it is hardly used for coding or software design at all.

Rather, 90% of usage is knowledge work and business operations; things like drafting memos and reports from raw data, or turning a contacts list or transcripts into sales leads.

These are routine tasks that involve a lot of data parsing or housekeeping that are essential parts of office work, but is rarely advertised. Anthropic calls it «work around the work.»

The new features should be available on claude.ai and in the sidebar of the iOS or Android apps, rolling out «over the next several weeks» for Max users, with «more plans to follow.»

Read more: Anthropic’s announcement, launch thread, TechCrunch and The Verge.

Fable 5 will eat up all your tokens, some users say, as Anthropic resets limits

Fable 5 is the most expensive model from Anthropic, and it uses a lot of subagents. (Picture: Anthropic)
Just as people are digging into their allocation of Claude Fable 5 usage on the paid tiers, they are running up to another wall: The model is very expensive and will chew through your alotted tokens in no time at all.

One ML engineer on reddit said it tore through a 5 page research paper while comparing it to a whitepaper with 174 subagents to review the results from 7 original agents and «ate through my max 20x 5 hour limit in ~15 minutes.»

X reactions
User BridgeMind on X said he paid $321 for Opus 4.8 to do all the work, while X user Adam Door posted that it burned through his $200 Max subscription in ~30 minutes, and yet another post says «Fable 5 burned 28% of my weekly limit AND used up my 5 hour limit with two prompts in about 30 minutes.»

Continue reading “Fable 5 will eat up all your tokens, some users say, as Anthropic resets limits”

US government lifts restrictions on Anthropic’s Fable 5

Fable 5 spooked the government enough to ban it, but now it’s back online with even stronger safeguards. (Picture: Shutterstock)
As of July 1, the Mythos-class model is available on wide release to paying customers, after the Commerce department lifted their export controls on June 30.

Anthropic hails the news, but cautions that recent events have highlighted the need for a «consistent way to assess and fix potential «jailbreaks,»» after two weeks of grueling exchanges with the administration.

Commerce secretary Howard Lutnick said on X that they had «worked closely with Anthropic to […] ensure alignment across the US Government and strengthen America’s leadership in AI,» Axios reports.

The Fable 5 model became somewhat of a joke in the AI community for having such strong safeguards that it would not answer anything even remotely related to security or biology, but Amazon engineers got it to output code for an exploit, leading to the export ban on June 12.

This behavior is now blocked 99% of the time, and Anthropic has agreed to even further safeguards on the model, pledging to work even more closely with the government in the future, including on vetting pre-release models.

Read more: Anthropic’s announcement and X post, Lutnick’s letter, Axios, Politico, CNBC.

Chinese model GLM-5.2 almost reaches parity with Opus 4.8 in coding, cyber

Opus 4.8 was released in May, meaning the gap to Chinese models has closed considerably. (Picture: generated)
While not matching GPT-5.5 or Opus 4.8 across the board, the GLM-5.2 is the first open model to come within spitting distance (about 1% on some tests) on coding and cybersecurity tasks at open source benchmarks.

That means Chinese AI lab Z.ai is catching up to cyber capabilities considered by some to be too dangerous to release publicly, and is edging closer to Mythos or GPT-5.6.

The concern is that the new model, released on June 16, is open source and open weight with an MIT license — meaning that anyone can adjust its guardrails and play around with it on any computer capable of running it.

That has researchers worried that China is not only catching up, but that the model might find its way into the hands of bad actors — who will be supercharged when looking for hacking targets, causing what they term «bugmaggedon.»

With Mythos and GPT-5.6 being blocked by the US government, security teams might be tempted to turn to these models at a sixth of the cost of the American frontier, especially as they develop further, notes benchmark provider Semgrep.

Read more: Z.ai’s presentation with benchmarks, Semgrep tests, The Wall Street Journal, and The Verge. Discussion on r/Singularity and Hacker News.

US government clears Mythos 5 for limited release to «trusted partners»

Mythos 5 will become available on Project Glasswing after the government lifts its ban. (Picture: Shutterstock)
After two weeks of purgatory and almost daily explanatory meetings, Commerce Secretary Howard Lutnick sent a letter to Anthropic on Friday, clearing one of two models on hold for release:

— I have determined that appropriate safeguards are in place to permit certain trusted partners to access the Claude Mythos 5 Model, he writes to chief compute officer Tom Brown, according to Semafor, who scooped the story.

Mythos 5 was only intended for a limited release through the Glasswing project, for use by a trusted set of government agencies and corporations to test their cyber defenses.

UPDATE: On Saturday, Axios is reporting that Fable 5 might be next in line, with «insiders» predicting it might be released next week, and Anthropic anticipating access «soon.»

The letter also says that «Anthropic has committed to work with the U.S. government on protocols and standards and releases,» and talks are progressing toward a release of Fable, though «the timeline is unclear,» according to Semafor.

Read more: Scoop by Semafor, comment from Anthropic, Reuters, CNBC, and Politico.

Speaking in «different languages,» Anthropic struggles with White House

Finding themselves thrust into politics, Anthropic is having difficulty getting through, Axios reports. (Picture: Shutterstock)
As security researchers and executives are urging a retreat from the Mythos ban, Axios is reporting that Anthropic is failing to «communicate effectively.»

They were scheduled to meet in person with the White House on Monday, sources tell CNBC, and are now finding themselves deeply enmeshed in current politics.

Government officials are now candidly telling Axios that Anthropic «screwed» them, saying they failed to «honor» the recent Executive Order on AI — which calls for a 30-day vetting period for new models, and are calling Anthropic a «bad actor.»

There are also differing narratives in the Axios report, where on the one hand, Anthropic says they «received explicit approval» to deploy Fable, and another where the administration threatened export controls several weeks ago, fearing the model could be exploited by bad actors.

The exploit uncovered in the Fable and Mythos models are replicable in other frontier and open source models, security researchers say in an open letter, and shutting down Fable at a critical time gives an advantage to attackers over defenders. They say there is only a 90-day window until Chinese models reach the same capabilities.

Read the Axios report here, also see the security researchers’ open letter, reports on euters, CNBC and Politico.