Access explicitly denied for Cyber and Chemistry: Fable 5, the Claude Mythos variation you pay for…
Anthropic’s newest flagship model Fable 5 is technically available to paying users — but if you work in Cybersecurity Research or…
Access explicitly denied for Cyber and Chemistry: Fable 5, the Claude Mythos variation you pay for but can’t use + edits (later I ‘bypassed’ it)
Anthropic’s newest flagship model Fable 5 is technically available to paying users — but if you work in Cybersecurity Research or Chemistry, an explicit notification informs you that your query has been flagged and your model has been swapped out.
Author: Berend Watchus. Independent AI & Cyber Security Researcher.

June 10, 2026 (Flagged and blocked. Strangely after mostly letting it read AI and philosophy articles by me, not even Cyber specific. However in the texts I do say I am an AI & Cybersecurity researcher)
The notification paying users receive “Fable 5 has safety measures that flag messages on most cybersecurity or biology topics. They may flag safe, normal content as well. These measures let us bring you Mythos-level capability in other areas sooner… Switched to Opus 4.8.” [see image above]
When a paying user opens Claude, selects Fable 5 — Anthropic’s most powerful publicly available model and a direct variation of its restricted Claude Mythos architecture — and submits a cybersecurity-related query, they receive an explicit notification pop-up. The message informs them that their topic has been flagged, that the content falls under restricted categories, and that the session has been switched to Opus 4.8, an older and less capable model.
What is notable about this approach is its transparency. Anthropic does not quietly redirect the query or return a vague refusal. The notification explicitly states that cybersecurity and biology topics are flagged by default,
and acknowledges that safe, legitimate content may be caught by the same measures. The user is informed clearly of what is happening and why.
Fable 5 shares the same underlying architecture and training as Claude Mythos 5. The distinction between the two is not capability — it is access policy. Cybersecurity, biology, and chemistry queries are automatically routed away from Fable 5 and handled by Opus 4.8 instead.
“The notification is explicit: the user’s field is a flag condition, their query is blocked, and their model has been replaced.”
What Mythos is, and why it matters
Claude Mythos is Anthropic’s most capable model, currently restricted to roughly 200 partner institutions including Amazon, Apple, Google, Microsoft, and select government bodies through Project Glasswing.
[embed]What I’d Actually Learn from Glasswing Author Berend Watchusosintteam.blog
It has already identified over ten thousand critical vulnerabilities across the world’s most important software. Anthropic describes its cybersecurity capabilities as the strongest of any model currently available.
Fable 5 brings that level of capability to the general public — with the exception of an entire professional domain. Cybersecurity researchers, penetration testers, red teamers, and security authors receive an explicit notification informing them that their queries fall into a restricted category, and that full model capability is not available to them.
The verification program that does not quite fit independent researchers
Anthropic does offer a Cyber Verification Program (CVP) — a free, application-based process through which security professionals can request that the restrictions be lifted. Applicants describe their work, Anthropic reviews it, and a decision is returned within approximately two business days.
In practice the CVP has a structural limitation: approval is tied to an organization ID, not an individual account. A researcher approved under their employer’s Claude Teams account does not carry that approval into a personal workspace. For independent professionals with no organizational affiliation to attach to, there is no straightforward path through the system. The evaluation criteria are defined and applied entirely by Anthropic. Published research, academic credentials, and professional certifications are not formally recognized as part of the framework.
Who determines legitimate use?
This raises a broader question about governance. Anthropic has, by design, positioned itself as the arbiter of who qualifies as a legitimate cybersecurity professional. There is no independent body, no recognized industry standard, and no external review process involved in that determination. A researcher whose work has been peer-reviewed and published must still satisfy Anthropic’s internal criteria to access a product they are already paying for.
The security industry has established credentialing mechanisms — professional certifications, academic affiliation, publication records, and conference participation among them. The CVP does not currently incorporate these as a basis for individual verification.
A considered policy with uneven consequences
The rationale behind the restrictions is not without merit. A model capable of autonomously identifying zero-day vulnerabilities across major operating systems and browsers carries genuine risk if broadly misused. Anthropic’s caution is understandable in that context.
The concern is not the policy itself, but its distribution of consequences. Large institutions with Glasswing access operate without restrictions. Independent professionals receive an explicit notification that their field is a flagged category, and are directed toward a verification process that was designed around organizational membership rather than individual credentials.
Anthropic has indicated that the safeguards are being actively refined. For independent security researchers currently navigating these restrictions, however, the gap between institutional and individual access remains a practical and unresolved problem.
— — — — — — — — — — —
EDIT1:
Later I tried uploading my texts again and kept the chat very short and I typed an unfinished sentence about philosophy instead.
That worked!
Fable5 did interact.
I ‘confronted’ it with the flagging and blocking and later allowing the same texts as a topic when accompanied with more innocent sounding chat prompt.
It said:

Fable5 talking

Fable5 talking
Fable5 did not have anything to offer and was more of a negative attitude and less willing to be an AI assistant.
— — — — — — — — — — — — — — —
EDIT2

Fable5 says it has a cut off date of jan 2026 and saw in a screenshot I gave it that there are articles about Project Glasswing. Fable5 claims here it does not know it this was actually in the news and does not know it exists and certainly does not know its own connection to this (Claude Mythos).
— — — — — — — — — — — — — —
EDIT3




— — — — — — — — — —
EDIT4

— — — — — — — — — — —
EDIT5



메타데이터
- post_id
- e3bbfeac7c41
- slug
- access-explicitly-denied-for-cyber-and-chemistry-fable-5-the-claude-mythos-variation-you-pay-for-e3bbfeac7c41
- url
- https://systemweakness.com/access-explicitly-denied-for-cyber-and-chemistry-fable-5-the-claude-mythos-variation-you-pay-for-e3bbfeac7c41
- canonical_url
- https://systemweakness.com/access-explicitly-denied-for-cyber-and-chemistry-fable-5-the-claude-mythos-variation-you-pay-for-e3bbfeac7c41
- author_url
- https://medium.com/@BerendWatchusIndependent
- status
- ok
- fetched_at
- 2026-06-13 07:35:29