Fable 5 is back, but the return is somehow even messier than the shutdown. Anthropic brought it back on July 1st after the US Commerce Department lifted the export controls that had been sitting on Fable 5 and Mythos 5 since June 12th. These models originally went live on June 9th and then only 3 days later, access was blocked globally because Anthropic said it could not verify user nationality in real time.
So instead of only blocking restricted users, it pulled the whole thing for everyone. The reason was actually a report from Amazon researchers. Amazon found a way to bypass Fable 5's cyber security safeguards by asking it to identify software weaknesses and in one case it produced a demonstration of how one vulnerability could be exploited.
Amazon CEO Andy Jasse reportedly made the government aware of it and that is what triggered the export control drama. Anthropic's defense is that this was not some secret mythos level superpower leaking into the public. In its own testing, weaker models could identify the same vulnerabilities too.
Anthropic specifically said Claude Opus 4. 8, GPT 5. 5 and Kimmy K 2.
7 could identify the same issues. And when it came to demonstrating the exploit, even Claude Haiku 4. 5 could produce the same kind of output.
Their argument is that the report did not prove Fable 5 had unique offensive cyber capability. It proved a safeguard could be bypassed. The frustration did not start from zero.
Before Fable returned, Sonnet 5 had already annoyed a lot of users. Some called it trash, and one comparison claimed it could cost 1. 2 times more than Opus 4.
8 Max, two times more than GPT 5. 5x high, five times more than GLM 5. 2 2, seven times more than Kim K 2.
6 and 57 times more than Deepseek V4 Pro. This is supposed to be Anthropic's strongest public model. It is described as the most powerful LLM currently available on the open market, sitting at the top of Arena.
ai and artificial analysis, but it is also extremely expensive. The API price is still $10 per million input tokens and $50 per million output tokens. Prompt caching input tokens still keep the existing 90% discount.
Enthropic also says that for workloads running in the United States, Fable 5 inference only runs on US infrastructure and both input and output tokens are charged at 1. 1 times the normal price. For regular Claude users, there is a short promotional window from July 1st to July 7th at 11:59 p.
m. Pacific time. Pro, max, team, and premium seats in some enterprise plans can use Fable 5 inside their weekly usage limit, but only up to 50% of that weekly limit.
Anthropic says Fable 5 burns that limit faster than other clawed models. Once that included quota is gone, users either switch to another model or pay with usage credits. After July 7th, Fable 5 becomes usage credit only, separate from the subscription.
Free users do not get it. API use is build separately and standard seats in older enterprise plans only get access if the organization has usage credits turned on. Then comes the real problem for developers.
Anthropic trained a new safety classifier with the government. This smaller system watches the request before Fable 5 answers. If the classifier thinks the prompt touches risky cyber security behavior, the request gets blocked and automatically rerouted to Opus 4.
8. 8. The user gets a notice and Opus answers instead.
Anthropic says this new classifier catches the technique from the Amazon report in over 99% of cases and Casey researchers describe the safeguards as extraordinarily strong. The classifier is intentionally strict. Anthropic says the safety margin is bigger for Fable 5 than in any previous launch, so it will catch more bad requests, but it will also mclassify more harmless ones.
And Anthropic openly admits that routine coding and debugging can be affected. You are paying $10 in and $50 out for the most expensive model and then some normal coding requests can get flagged, downgraded, and answered by Opus 4. 8 anyway.
Opus costs $5 per million input tokens and $25 per million output tokens. So people are asking a fair question. Who exactly is Fable 5 for if coding with it can turn into opus?
The jokes wrote themselves. One developer compared it to Anthropic, saying, "I built you an F1 Ferrari and then handing you a Prius when you actually try to drive. " Someone added that when you get into the Prius, there is a sticker saying, "Be glad I didn't delete everything.
" Then, Open Code developer Dax noticed something more awkward. He said many of his prompts were being downgraded. And when he checked the logs, the reason said, "Too dumb to need Fable.
" That label is insane from a user experience perspective. It makes it sound like the system looked at the request and decided the user was too dumb to deserve the expensive model. The Shihipar, an engineer on Claude Code, replied, "To be honest, I didn't expect you to check the logs.
" That response made the whole thing worse because it felt like the issue was not just the routing. It was the assumption that users would never see how the routing was being described internally. Now, you've probably noticed how much attention Claude is getting right now.
Anthropic keeps adding new models and features from Claude code and Claude artifacts to skills, connectors, design tools, and more. And honestly, it makes sense. Claude has become one of the most useful AI tools for turning an idea into something real.
Whether that means building an app, creating a presentation, organizing research, planning your week, or speeding up work that would normally take a whole team. The problem is that a lot of people keep saying learn claude without actually showing you a clear way to use it properly. That's why today's sponsor is hosting the world's first Claude Aathon, a 2-day live workshop happening this weekend from 10:00 a.
m. to 7:00 p. m.
Eastern time. It's a deep dive into Claude practical use cases and more than 10 other AI tools, and they're opening 1,000 free seats for a limited time. Inside the workshop, you'll learn how to use Claude for deep research, build artifacts and dashboards, create full presentations, set up connectors like Indeed for job search, build custom GPTs and agents, and use AI tools for visuals, videos, and automation.
You'll also get bonus resources like claude codes, a prompt library, and a personalized AI toolkit builder. Link is in the description or scan the QR code to join before the free seats close. All right, now back to the video.
Anthropic has built its image around safety, trust, responsibility, and being more careful than open AI. That works when the product feels transparent. But when the model is expensive, restricted, downgraded, and surrounded by hidden routing logic, people start asking what they are actually paying for.
The biology and chemistry filters add another layer. Anthropic says those classifiers are the same as the original release, but their scope is broader than expected. That means some basic biology questions can also trigger fallback to Opus 4.
8. Improvements are supposed to come later. For now, users can select Fable 5, pay Fable 5 prices, and still end up with safer, older behavior underneath it.
At the same time, Mythos 5 is back too, but only for a tiny group. Mythos has fewer safeguards and much stronger cyber capabilities. So it is limited to around 100 select US organizations approved by the government mainly in cyber security and critical infrastructure.
Anthropic had already described Mythos as carrying unprecedented cyber security risks and instead of a normal public release, it launched Project Glasswing with a $100 million usage quota for companies like Apple, Microsoft, Google, Nvidia, AWS, and JP Morgan. Mythos preview is priced at five times Opus 4. 6.
Some people think Anthropic is using danger as a business strategy. The pattern they see is simple. call the model dangerous, restrict access, create exclusive demand, and then sell it to governments and large enterprises with better margins.
David Saxs even questioned whether anthropics warnings are real or part of a routine where the sky is always falling right before a commercial move. This also ties into Daario Amodi's public stance against open-source AI. He has warned that powerful open models are on a dangerous path because companies lose the ability to monitor abuse, revoke access or update safeguards.
Anthropic's message is basically trust us, we are more responsible, but the Fable 5 rollout shows the cost of that promise. Stronger control creates worse user experience. Higher prices make users more demanding.
And the more a company talks about trust, the more people expect transparency. The transparency problem got much bigger with the clawed code marker controversy. Developers found that claude code had a hidden anti-distillation mechanism.
If a user set a third party anthropic base URL instead of the official API endpoint, claude code checked the proxy host name and the system time zone. If the time zone was Asia/Shanghai or Asia/Ururumchi, or if the proxy domain matched certain Chinese tech companies, Chinese AI labs, clawed resale sites, mirror proxy services, or keywords like deepseek, clawed code could modify the line that says today's date is inside the system prompt. The changes were tiny.
The date might change from 2026-6-30 to 2026/to-630. Or the apostrophe in today's date could be replaced with a Unicode character that looks almost identical to the naked eye, but has a different encoding. So, the model reads the sentence the same way, but the request now carries hidden routing information.
Chen Cheng from Ant Group looked at Claude code version 191 and explained why this was technically clever. The prompt had a line like today dollar sign open curly bracket n close curly bracket s date is dollar sign open curly bracket r close close curly bracket and anthropic use that sentence as a carrier. The reason this works is that proxy services usually clean HTTP headers and obvious metadata, but they rarely rewrite natural language text like dates inside a prompt.
So, if a reseller or distillation pipeline sends the request back into Anthropic's official API, Anthropic can see the marker in its own logs. A slash in the date might signal a Chinese time zone. A different apostrophe like U plus02B9 might signal a matched proxy domain or keyword.
The request basically reveals where it came from. From an anti-abuse point of view, the design is smart. It can help Anthropic detect unauthorized resale, account abuse, sanctions risk, and model distillation.
Hariq Shihipar later said this was an experiment launched in March to prevent unauthorized resellers from abusing accounts and to stop model distillation. He said stronger mitigations had already been launched and the team had always planned to remove this mechanism. A pull request was merged and it was expected to be fully rolled back in the next version.
But the trust issue does not disappear just because the mechanism was clever or temporary. Developers can understand telemetry when it is disclosed. Secretly changing invisible prompt characters is different.
Once users learn that routing metadata can be encoded inside system prompts. The obvious question becomes what else is encoded? What else is being checked on the client side and where is this documented?
Alec Armrewster tested Fable 5 on the day it came back using Cursor's proxied anthropic API. He says he framed the request as hypothetical defensive research and Fable 5 still produced detailed botnet planning output involving real default credentialed IoT devices. He also says he tried comparable prompts against GLM 5.
2, GPT 5. 5, and Claude Opus 4. 8 8 and those models refused or failed to complete the task.
That claim is not independently verified and Anthropic has not publicly responded to it. So, it has to be treated carefully. But the timing is brutal.
The whole point of the comeback was stronger safeguards. And then on day one, a researcher says the model can still help plan an IoT botnet attack through basic hypothetical framing. Sonnet 5 is the safer, cheaper, middle-of the road model.
Anthropic says it is its most agentic sonnet yet with better reasoning, tool use, coding, multimodal reasoning, agentic search, and professional task performance compared with sonnet 4. 6. It is the default model for claw-dfree and pro users, and it is also available for Macs, team, and enterprise.
The safety card says Sonnet 5 has a lower rate of undesirable behavior than Sonnet 4. 6. It is better at resisting prompt injection, less likely to hallucinate, less sickopantic, and more aware of misuse and deception.
Anthropic also made a point of saying it did not deliberately train Sonnet 5 on cyber security tasks. It can still do routine cyber security work, but it is guardrail against offensive attack code. In one test, when asked to write a Firefox exploit, it failed to complete the task, although it got a bit further than Sonnet 4.
6 six because it is generally smarter. Sonnet 5 also has a new effort setting. Simple tasks can run at lower effort to save tokens while longer agentic work can use higher settings like X high or max.
Pricing is much easier to swallow than Fable. Through the end of August, Sonnet 5 costs $2 per million input tokens and $10 per million output tokens. Starting in September, that becomes $3 in and $15 out.
Opus 4. 8 8 is still $5 in and $25 out. So, Anthropic now has this strange split.
Sonnet 5 is the practical model. Opus 4. 8 is the fallback.
Fable 5 is the flagship that might downgrade itself. Mythos 5 is the powerful one most people cannot touch. And the company is trying to build an industry-wide jailbreak severity framework with Amazon, Microsoft, Google, and others in the Glass Wing program using criteria like capability gain, breadth of gain, ease of weaponization, and discoverability.
Similar to how CVSS works for software vulnerabilities, Fable 5 is powerful, but between the price, the 50% temporary usage cap, the July 7th switch to credits, the US infrastructure search charge, the 30-day data retention with no opt out, the automatic opus fallback, the biology false positives, the hidden anti-distillation markers, and the new claims about botnet planning. The return feels less like a clean comeback and more like a controlled experiment being sold as a product. And that is probably why so many developers sound exhausted.
They are not just complaining that the model is strict. They are complaining that the rules keep changing while the bill keeps going up. That's it for this one.
I'll keep watching what happens next with Fable 5. Thanks for watching and I'll catch you in the next one.