Claude Fable 5: Model Update, Safety Profile, Benchmarks, and Subscriber Trial Rollout
What's new in v4
Simon Willison's sqlite-utils 4.0rc2 project (items 39752, 39809) is the primary new development: a concrete real-world case study where Fable 5 produced 37 prompts, 34 commits, and $149.25 of API work on a real open-source library while identifying a critical transaction bug, and where cross-model review (GPT-5.5 auditing Fable's output) surfaced two additional P1 issues before release. This practical evidence complicates the BridgeBench narrative and is incorporated into the routing-vs-degradation tension: Fable 5 appears capable of genuine engineering work, supporting the classifier-miscalibration reading over model-degradation. The Neuron article (39823) confirms existing facts about the 16.1% Remote Labor Index score and July 7 subscription end without adding new claims; the remaining new items are empty shells with no substantive content.
What
Anthropic launched Claude Fable 5 on June 9, 2026, saw it suspended by US export controls on June 12 over a reported jailbreak, and had it globally restored June 30 after demonstrating the jailbreak was replicable by multiple commercial models.[6] Post-redeployment, community benchmarks show coding scores collapsed (BridgeBench Debugging: 86.2→25.9), though some analysis attributes this to the updated cybersecurity classifier routing tasks to Opus 4.8 rather than reduced model intelligence.[7][9] The subscriber trial ends July 7, after which Fable 5 requires separate usage credits with no timeline for subscription restoration.[12] In a concrete real-world test, Simon Willison built sqlite-utils 4.0rc2 using Fable 5 across 37 prompts and 34 commits for $149.25, with the model identifying a critical transaction bug; cross-model review (GPT-5.5 auditing Fable's output) then surfaced two additional P1 issues before release.[10]
Why it matters
The routing-vs-degradation question is practically significant: Willison's sqlite-utils project shows Fable 5 producing genuine engineering work on a real codebase, supporting the view that the BridgeBench collapse reflects classifier miscalibration rather than fundamental model capability loss. With the subscription trial ending July 7 and no timeline for restoration, users who want to keep using the model face per-usage costs at $10/$50 per million tokens at the same moment cheaper alternatives are available.
Open questions
Anthropic acknowledges the updated classifier intentionally blocks some benign uses, and BridgeBench shows Debugging fell from 86.2 to 25.9—but community analysis and real-world projects like Willison's sqlite-utils work suggest the model retains genuine capability.[7][20][10] Will Anthropic publish a technical account distinguishing classifier routing effects from model-level changes?
The subscription trial ends July 7 with Fable 5 moving to per-usage credits and no timeline given for restoring subscription access—how long will it remain outside standard plans?[12]
Nathan Lambert argues Anthropic deploys undisclosed filters for frontier AI research tasks that silently reduce capability—will Anthropic confirm, deny, or document these alongside its announced classifiers?[2]
The export control reversal happened in stages with no public explanation at either step—does the US government have any defined process for reviewing and lifting AI export controls, or were both decisions discretionary?[6][4][5]
Narrative
Anthropic launched Claude Fable 5 and the restricted-access Claude Mythos 5 on June 9, 2026, at $10/$50 per million input/output tokens, with classifiers routing queries touching cybersecurity, biology, chemistry, and model distillation to Claude Opus 4.8, and with Mythos 5 limited to vetted partners under 30-day data retention.[1] On the same day, Nathan Lambert published a critique arguing that Anthropic also deploys hidden, undisclosed filters applied through prompt modification, steering vectors, or PEFT that silently reduce Fable 5's effectiveness for frontier AI research tasks such as pretraining pipeline development and ML accelerator design, calling covert capability reduction competitive protection dressed as safety.[2] Three days after launch, the US government issued an export control directive suspending both models for all foreign nationals, citing a jailbreak identified by Amazon researchers. Anthropic complied while publicly disputing both the technical basis and the process.[3]
The government partially reversed course around June 27-28, restoring Mythos access for 'trusted' US companies before a full global reversal.[4][5] On June 30, the US fully lifted all restrictions without explanation, and Anthropic's redeployment announcement disclosed that its own testing found the triggering jailbreak—asking the model to read a codebase and identify vulnerabilities—was replicable by Claude Opus 4.8, GPT-5.5, and Kimi K2.7.[6] Anthropic also announced pre-release government access commitments for future frontier models and a collaboration on an industry jailbreak severity framework. The model that returned from suspension performs measurably differently in community testing: BridgeBench scores dropped across all tested dimensions, with Debugging falling from 86.2 to 25.9, Refactoring from 73.6 to 38.4, and Hallucination resistance from 75.9 to 61.7.[7] Some community analysts argue the collapse reflects the safety router diverting tasks to Opus 4.8—in at least one documented case, classifiers routed 75% of a $321 coding session to Opus 4.8, accounting for $242 of the total cost.[8][9]
Real-world usage provides a counterpoint to the benchmark collapse. Simon Willison built sqlite-utils 4.0rc2 using Fable 5 across 37 prompts and 34 commits, producing +1,321/-190 code changes across 30 files at an estimated API cost of $149.25.[10] Fable 5 identified a critical bug where delete_where() never committed its changes, silently discarding subsequent writes; a cross-model review pass—using GPT-5.5 to audit Fable's output—then surfaced two additional P1 bugs in db.query() that would have shipped in the release.[10] Separately, Fable 5 completes 16.1% of remote projects at professional standard, roughly double the next-best model and up from Claude Opus 4.6's 4.2%.[11] Anthropic confirmed the subscriber trial ends July 7, after which Fable 5 requires separate usage credits, citing capacity constraints with no timeline for subscription restoration.[12]
On the competitive and operational side, OpenAI's GPT-5.6 Sol launched at $5/$30 per million tokens claiming 91.9% on TerminalBench 2.1, while China's open-source GLM 5.2 outperforms Fable 5 on Semgrep's security benchmark (39% vs 32% F1) at a fraction of inference cost.[13][14] Claude Sonnet 5 ranks second only to Fable 5 on an agentic benchmark at roughly 17x lower cost, and commentators recommend using cheaper models for planning and drafts while reserving Fable 5 for long-horizon tasks with judgment requirements.[15][16] Meta has restricted engineers from using Claude Code and Codex over concerns that rival AI outputs could contaminate Meta's training data.[17] Dario Amodei told Congress that open-source AI is the real national security threat—a position critics note is in tension with the export control episode, which showed closed-weight models face government controls that open-weight models effectively circumvent.[18][19]
Timeline
- 2026-06-09: Anthropic launches Claude Fable 5 and Mythos 5 at $10/$50 per million tokens with tiered safety classifiers; Nathan Lambert publishes critique alleging hidden undisclosed filters for frontier AI research tasks. [1][2]
- 2026-06-12: US government issues export control directive suspending Fable 5 and Mythos 5 for all foreign nationals; Anthropic complies but publicly disputes the technical basis. [3]
- 2026-06-27: US government partially reverses the export directive, restoring Mythos 5 access for 'trusted' US companies before a full global reversal. [4][28][5]
- 2026-06-28: GLM 5.2 outscores Fable 5 on Semgrep security benchmark (39% vs 32% F1); OpenAI releases GPT-5.6 Sol at $5/$30 per million tokens claiming 91.9% on TerminalBench 2.1. [14][13]
- 2026-06-29: Dario Amodei tells Congress open-source AI is the real national security threat, framing closed frontier model deployment as the responsible policy approach. [18][19]
- 2026-06-30: US fully lifts export restrictions; Anthropic discloses the triggering jailbreak was replicable by Opus 4.8, GPT-5.5, and Kimi K2.7 and commits to pre-release government access for future frontier models. [21][6]
- 2026-07-01: Subscriber trial begins: Pro/Max/Team/Enterprise users get Fable 5 for one week at 50% of remaining weekly limits; API users excluded at standard pricing. [25]
- 2026-07-02: Anthropic publishes 4-tier cybersecurity classification framework and CJS jailbreak severity scoring; BridgeBench scores collapse: Debugging 86.2→25.9, Refactoring 73.6→38.4. [20][7]
- 2026-07-02: Classifiers route 75% of a $321 coding session to Opus 4.8 ($242 of total cost); community analysis argues router miscalibration rather than model degradation explains BridgeBench drops. [8][9]
- 2026-07-02: Anthropic confirms subscription access to Fable 5 ends July 7, moving to per-usage credits due to capacity constraints, with no timeline for restoring subscription inclusion. [12]
- 2026-07-02: Fable 5 completes 16.1% of remote projects at professional standard, double next-best and up from Opus 4.6's 4.2%. [11]
- 2026-07-03: Simon Willison documents subagent delegation workflow: routing routine tasks to Sonnet/Haiku significantly reduces Fable 5 token consumption while retaining it for judgment-heavy work. [23]
- 2026-07-04: AA-Briefcase benchmark shows Claude Sonnet 5 ranks second only to Fable 5 at roughly 17x lower cost; Meta restricts engineers from using Claude Code and Codex over training data contamination concerns. [15][29][17]
- 2026-07-05: Simon Willison releases sqlite-utils 4.0rc2 built mostly by Fable 5: 37 prompts, 34 commits, +1,321/-190 code changes across 30 files at $149.25; cross-model GPT-5.5 review surfaces two additional P1 bugs. [10][24]
Perspectives
Anthropic
Launched Fable 5/Mythos 5 as a deliberate capability-safety split; complied with government suspension while publicly disputing it; redeployed with an updated classifier, a 4-tier cybersecurity framework, and commitments to pre-release government access for future frontier models. Candidly acknowledged the new classifier intentionally blocks some benign uses.
Evolution: More transparency-forward post-redeployment, proposing formal industry standards and a HackerOne bounty program; Dario Amodei's congressional framing of closed models as responsible policy came while the government had just suspended Anthropic's own model.
US Government
Issued export control suspension citing a jailbreak with no public technical rationale; partially reversed for trusted US companies, then fully lifted restrictions with no public explanation of what changed at either step.
Evolution: Moved from blanket suspension to staged partial reversal to full lift with no transparency at any point and no public legal or technical standard articulated.
Nathan Lambert (Interconnects)
Argues Anthropic deploys hidden, undisclosed filters for frontier AI research tasks alongside its announced classifiers, framing covert restriction as competitive protection dressed as safety and advocating open-source AI as the structural remedy.
Evolution: Consistent; his June 9 critique predated the export control episode and remains unaddressed by Anthropic.
Zvi Mowshowitz
Documents Fable 5's substantial capability lead (16.1% professional remote project completion, double next-best) while arguing the export control episode set a dangerous ad hoc governance precedent.
Evolution: Consistent; combines capability data with governance and alignment critique.
Simon Willison
Documents practical workflows for using Fable 5 cost-effectively—subagent delegation and cross-model review—and built sqlite-utils 4.0rc2 mostly with Fable 5 at $149.25, with the model identifying a critical transaction bug; advocates habitually having one frontier model audit another's output as a quality technique.
Evolution: Expanded from general cost-management advocacy to a concrete real-world project case study demonstrating Fable 5's genuine engineering capability despite post-redeployment benchmark concerns.
Rohan Paul (@rohanpaul_ai)
Provides data-driven benchmark and cost analysis; documented BridgeBench score collapse, a $321 coding session where classifiers routed 75% to Opus 4.8, and Meta's restriction on Claude Code/Codex.
Evolution: Moved from neutral benchmark reporter to critical framing around 'permissioned intelligence' and the erosion of the social contract between AI labs and users.
Developer and power-user community
Impressed by Fable 5's benchmark performance and agentic capabilities but frustrated by high cost, classifier false positives on legitimate work, and post-redeployment BridgeBench collapse; debate has shifted from whether performance dropped to whether the cause is router miscalibration or model degradation.
Evolution: Initial enthusiasm gave way to sustained frustration post-redeployment; community is now developing workarounds (subagent delegation, cross-model review) rather than simply complaining, suggesting adaptation rather than abandonment.
OpenAI
Released GPT-5.6 Sol at $5/$30 per million tokens claiming superiority on TerminalBench 2.1 (91.9%), positioning it as both higher-performing and cheaper than Fable 5; July 7 subscription end is seen as a competitive opportunity.
Evolution: Consistent competitive posture; the Sol launch during Fable 5's suspension gave it additional visibility.
Tensions
- Anthropic argues the export control-triggering jailbreak was low-severity and replicable by multiple commercial models with no unique Mythos-specific uplift; the US government provided no technical rebuttal and lifted restrictions without explanation. [6][3][21]
- Anthropic acknowledges an intentional safety margin that blocks some benign uses; BridgeBench shows Debugging dropped from 86.2 to 25.9 post-redeployment, but community analysis and Willison's sqlite-utils project—where Fable 5 identified a critical transaction bug—argue the collapse reflects aggressive router routing rather than reduced model intelligence. [20][7][8][9][10]
- Nathan Lambert argues Anthropic deploys undisclosed filters for frontier AI research tasks that silently reduce capability—which he calls misalignment—while Anthropic's public documentation describes only its announced cybersecurity and biology classifiers. [2][20]
- At $10/$50 per million tokens, Fable 5 costs 2x GPT-5.6 Sol ($5/$30) and up to 39x GLM 5.2 in tested tasks, while both competitors claim benchmark parity or superiority on specific metrics and Claude Sonnet 5 offers similar agentic performance at roughly 17x lower cost. [13][14][15]
- Dario Amodei told Congress closed frontier deployment is responsible policy because open-source AI is the real national security threat; critics note the Fable 5 episode showed closed-weight models face government controls that open-weight models effectively circumvent. [18][19][3]
Status: active and growing
Sources
- [1] Claude Fable 5 and Claude Mythos 5 — Anthropic News (2026-06-09)
- [2] Claude Fable 5 and new AI safety fables — Interconnects (2026-06-09)
- [3] Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic News (2026-06-12)
- [4] Anthropic to Restore Mythos for 'Trusted' US Companies — Access Allowed After 2-Week Suspension — reactive:claude-fable-5-launch (2026-06-28)
- [5] The US government has partially reversed its June 12 export control order, allowing Anthropic to restore access to its C... — reactive:claude-fable-5-launch (2026-06-27)
- [6] Redeploying Fable 5 — Anthropic News (2026-06-30)
- [7] Feels like an end of era, ordinary people will probably never again get upgraded frontier models. — Rohan Paul Twitter (2026-07-02)
- [8] This may be an extreme case but it still shows how quickly Fable 5 classifiers can reroute routine coding to Opus. — Rohan Paul Twitter (2026-07-02)
- [9] UPDATE: 🔬 Anthropic's Claude Fable 5 isn't dumber, but its new safety router is aggressively blocking prompts. — reactive:claude-fable-5-launch (2026-07-04)
- [10] sqlite-utils 4.0rc2, mostly written by Claude Fable (for about $149.25) — Simon Willison (2026-07-05)
- [11] AI #175: The Fable Continues — Zvi's AI Roundups (2026-07-02)
- [12] Current Fable-5's subscription access ends after July-07. — Rohan Paul Twitter (2026-07-02)
- [13] GPT-5.6 Sol is priced at $5 input and $30 output per million tokens. Claude Fable 5 is priced at $10 input and $50 outpu... — reactive:claude-fable-5-launch (2026-06-29)
- [14] China's GLM-5.2 just outscored the banned Claude Code on Semgrep's security benchmark. 39% F1 vs 32%. Open-weight. MIT l... — reactive:claude-fable-5-launch (2026-06-28)
- [15] Claude Sonnet 5 ranks second only to Fable 5 on AA-Briefcase, our new agentic knowledge work benchmark, with a ~17x cost... — reactive:claude-fable-5-launch (2026-07-04)
- [16] 😸 Build something real with Fable — The Neuron (2026-07-05)
- [17] Today’s edition of my newsletter just went out. — Rohan Paul Twitter (2026-07-03)
- [18] Dario Amodei told Congress this week that open source AI is the real threat. Once models are released, the Anthropic CEO... — reactive:claude-fable-5-launch (2026-06-29)
- [19] The U.S. just proved that frontier closed-weight AI has a sovereign kill switch. Not because the model vanished, and not... — reactive:claude-science-launch (2026-06-29)
- [20] More details on Fable 5’s cyber safeguards and our jailbreak framework — Anthropic News (2026-07-02)
- [21] Summary of Anthropic’s “Redeploying Fable 5” announcement (June 30, 2026): — reactive:claude-fable-5-launch (2026-07-01)
- [22] 🚨MAJOR AI UPDATE: The U.S. government is lifting export restrictions on Anthropic’s Claude Fable 5 - restoring worldwide... — reactive:claude-fable-5-launch (2026-07-01)
- [23] Fable's judgement — Simon Willison (2026-07-03)
- [24] sqlite-utils 4.0rc2 — Simon Willison (2026-07-05)
- [25] Claude Fable 5 is getting a one-week subscriber trial with a strict 50% usage ceiling. — Rohan Paul Twitter (2026-07-01)
- [26] GPT-5.6 Sol Ultra scored 91.9 percent on Terminal-Bench 2.1. That is the highest score ever recorded on a command-line w... — reactive:claude-fable-5-launch (2026-06-28)
- [27] Mark July 7 on your calendar, because that’s the day Anthropic hands OpenAI the best marketing gift of the year. — reactive:claude-fable-5-launch (2026-07-04)
- [28] 🤖 Anthropic to Restore Claude Mythos 5 Access for 'Trusted' US Companies — A Partial Reversal with Major Implications. — reactive:claude-fable-5-launch (2026-06-28)
- [29] AA-Briefcase: a tougher test for agents — reactive:claude-fable-5-launch (2026-06-30)