Anthropic recently announced the release of Claude Fable 5, a public version of its more powerful Mythos AI model. Technology that was previously only accessible to a select few organizations is now available to businesses at an enterprise level. AI vendors are building the guardrails while threat actors are studying their attack vectors. Essentially, we are giving the keys to the AI world to businesses and hoping the guardrails hold steady. Security teams need to prepare even faster now. Mythos is no longer a theoretical risk.
Why Fable 5 matters for security teams
To me, the bigger story of Anthropic’s Fable 5 release is what it signals for security teams: AI is becoming more powerful, more embedded in business workflows, and harder to contain within traditional risk management processes. Anthropic has even warned that AI is quickly approaching recursive self-improvement, or the ability for AI systems to improve themselves without direct human intervention. For anyone who remembers a time when autonomous systems were the stuff of Science Fiction, this feels a little too close. We are certainly in uncharted territory in which we must adapt quickly.
Fable 5’s safety guardrails: A good start (but not enough)
Fable 5 is the publicly available, more heavily guarded version of Anthropic’s Mythos-class model. It comes with safety classifiers, fallback behavior, and hard limits around high-risk areas like cybersecurity, biology, chemistry, and model distillation. Anthropic has also said it will require 30-day retention on Fable 5 and Mythos 5 traffic, even for some enterprise customers that previously had zero-retention agreements.
This is huge. On one hand, it shows that Anthropic is taking misuse seriously, which is a concern many security professionals have voiced. More capable models need more monitoring, more visibility, and more safeguards. On the other hand, it also highlights a much larger issue for businesses: the more powerful these models become, the more risk they introduce around data access, retention, permissions, and third-party exposure.
Often, we give these models access to our data in order to help us scale faster. The tradeoff is that with more access to our data, if the AI tool, connected system, or identity layer is compromised, a threat actor could potentially gain access to that same sensitive data.
CISOs cannot rely on vendor guardrails alone to manage this risk. Safety classifiers are important, but they are not a complete security strategy. Models can be jailbroken. Bitsight Threat Intelligence has observed threat actors across all three buckets (ransomware, hacktivists, and nation-state actors) discussing ways to jailbreak various AI models.
The real risk: Data access and permissions
While Anthropic is taking security seriously, it is fair to plan for a world where not every competing model releases with the same level of safeguards. And even when the model provider is doing the right things, enterprises still need to understand how these tools are being used across their business, their vendor ecosystems, and the level of data the AI models have access to.
Businesses are giving AI systems more permissions than ever before. AI tools are being connected to code repositories, cloud environments, customer data, ticketing systems, internal documents, collaboration tools, and security workflows. In many cases, these tools are not just generating text. They are taking action, calling tools, writing code, analyzing vulnerabilities, and making recommendations that can affect real business operations.