# US Government Orders Anthropic to Block Foreign Access to Fable 5 and Mythos AI Models Over Cyberattack Concerns


The artificial intelligence frontier has collided with national security. On June 13, 2026, Anthropic announced it had suspended public access to Fable 5, its latest large language model released just three days earlier, following a US government national security directive. The order also restricts access to Mythos 5, a model that had already demonstrated troubling capabilities for conducting sophisticated cyberattacks. The move marks an escalation in regulatory pressure on AI vendors as evidence mounts that state-sponsored and criminal adversaries are weaponizing frontier AI models to automate the kill chain of modern cyber warfare.


## The Immediate Action


Anthropic's suspension affects millions of users and hundreds of organizations that previously held access to these models. The national security order, issued by the US government, mandates that the company prevent all access by foreign nationals—including those employed by Anthropic itself. This blanket restriction effectively ended the company's ability to offer Fable 5 commercially in its current form, while Mythos 5 access has been similarly curtailed across its customer base.


The timing was dramatic. Fable 5 had launched on June 10, positioning itself as a successor to Sonnet 4.6. Just 72 hours later, it was withdrawn from the market. The speed of this action underscores the severity with which US government officials view the threat posed by these models falling into the hands of adversaries.


## Why Now? The Research That Triggered Intervention


The government's intervention did not occur in a vacuum. Two weeks prior to the access ban, Anthropic published research demonstrating that threat actors were actively exploiting its AI models to:


  • Generate malicious code with increasing sophistication
  • Discover zero-day vulnerabilities in corporate networks and software
  • Automate entire attack chains from initial reconnaissance through data exfiltration

  • The research painted a stark picture: adversaries were no longer confined to static exploit databases or manual vulnerability hunting. They now had access to AI systems capable of analyzing systems in real time, identifying weaknesses, and suggesting attack paths—all automated at machine speed.


    "While Claude Mythos Preview demonstrates where frontier AI cyber capabilities are heading—models able to find and exploit vulnerabilities at a level approaching the most skilled human researchers—research shows how threat actors are misusing generally available models today," Anthropic researchers wrote.


    ## The Mythos and GPT-5.5 Findings


    Anthropic's own Mythos models had already proven alarming in independent testing. In April 2026, the UK government's AI Security Institute (AISI) confirmed that Mythos could conduct end-to-end attack chains—from initial access through full network compromise. The research team tasked the model with simulating a 32-step corporate network attack, allowing a 100-million token budget. Mythos succeeded in 3 out of 10 attempts.


    Equally concerning: OpenAI's GPT-5.5 outperformed Mythos in the same tests. It succeeded in 2 out of 10 attempts at the 32-step corporate network simulation and demonstrated capabilities surpassing Mythos across both practitioner-level and expert-level attack chain tasks.


    These findings suggested that the problem was not isolated to Anthropic. Multiple frontier AI vendors now offered models capable of conducting sophisticated offensive cyber operations. The implications were profound: if these models were accessible to adversaries, traditional cybersecurity defenses—static patches, known vulnerability databases, signature-based detection—might no longer be sufficient.


    ## The Broader Threat Context


    Nation-state threat actors and organized cybercrime groups have been rapidly evolving their tradecraft. Intelligence agencies have observed:


  • Increased use of AI in vulnerability research by Chinese state-sponsored groups targeting US defense contractors
  • AI-powered social engineering campaigns that generate convincing phishing emails and deepfake audio
  • Automated exploitation frameworks that use AI to identify and exploit mass vulnerability classes across cloud environments
  • Adaptive malware that uses machine learning to evade endpoint detection and response (EDR) tools

  • The concern within US government agencies was clear: foreign adversaries gaining unrestricted access to frontier AI models would effectively hand them the keys to accelerated offensive cyber capability development. A well-resourced nation-state with access to Mythos or GPT-5.5 could potentially compress years of security research into weeks.


    ## What This Means Technically


    For organizations, the practical implication is that traditional vulnerability management timelines no longer exist. If an adversary has access to a frontier AI model, they can:


    1. Scan your network in real time

    2. Identify exploitable vulnerabilities automatically

    3. Generate working exploit code without human intervention

    4. Execute attacks at scale across multiple targets simultaneously


    The window for patching has effectively shrunk. What once might have taken months to exploit manually—discovering a subtle logic flaw, chaining multiple weaknesses, automating the attack—could now take hours or days with AI assistance.


    ## Government and Industry Response


    The Anthropic action suggests that US authorities are considering more aggressive intervention in AI vendor operations. The CISA (Cybersecurity and Infrastructure Security Agency) has already begun rewriting federal patching requirements to account for the AI threat era, anticipating that exploits may be generated and deployed faster than patches can be distributed.


    Industry analysts expect additional regulatory actions:


  • Export controls on frontier AI models (similar to semiconductor restrictions)
  • Mandatory security assessments before model release
  • Real-time monitoring of model use for signs of malicious activity
  • Licensing requirements for researchers accessing advanced models

  • ## Recommendations for Organizations


    Until regulatory frameworks stabilize, security teams should prioritize:


    | Priority | Action |

    |----------|--------|

    | Critical | Assume zero-day exploits will be auto-generated by adversaries; implement compensating controls (network segmentation, continuous monitoring, EDR) |

    | High | Reduce attack surface aggressively—close unnecessary ports, disable unused services, eliminate credential reuse |

    | High | Deploy behavioral analytics to detect anomalous lateral movement, even from compromised admin accounts |

    | Medium | Participate in threat intelligence sharing; AI-generated exploits may follow patterns that help identify active campaigns |

    | Medium | Update incident response playbooks to account for attacks moving at AI speed (minutes, not hours) |


    ## HackWire Analysis


    This isn't merely a regulatory moment—it's a strategic reckoning. For years, the AI industry has pitched frontier models as general-purpose tools, accepting the risk that adversaries would use them alongside everyone else. The Anthropic action signals that this calculus has shifted. The US government has concluded that the national security cost of unrestricted AI model access now outweighs the economic and innovation benefits.


    What's noteworthy is what this *doesn't* solve. Anthropic's export controls prevent future foreign nationals from accessing Fable 5 and Mythos 5, but GPT-5.5 remains available. OpenAI faces no announced restrictions. Smaller, open-source models like LLaMA are freely available globally. Adversaries will simply pivot to alternative models. The real question is whether export controls on a single vendor can meaningfully constrain nation-state adversary access—or whether this is simply security theater that sacrifices economic opportunity while the problem migrates elsewhere.


    The deeper pattern: frontier AI development is increasingly incompatible with open global commerce. Each new capability becomes a security liability. We're entering an era where the most powerful models may become restricted, classified research tools—available only to governments and vetted enterprises. That concentration of AI capability raises its own long-term risks, but it may be unavoidable if the alternative is arming every sophisticated adversary in the world with state-of-the-art hacking tools. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)