Reports say Anthropic did not submit Claude Mythos 5.1 to the UK AI Security Institute (AISI) for pre-release testing—the first reported exclusion of the institute from an Anthropic frontier-model evaluation. The available evidence establishes the access decision, not its motive: Anthropic has not publicly stated why AISI was excluded.
3
4
What is known about the decision
Mythos 5.1 launched on September 1, 2026. Reporting says its access was limited to approved, vetted US organisations connected to Project Glasswing, while AISI did not receive the model before release.
3
4
That limited-access approach is consistent with Anthropic’s own product descriptions. The company says Mythos 5.1 is available only to a small set of vetted organisations for cybersecurity and biology research, and its platform release notes list the model for Project Glasswing participants.
49
52
But the public record does not show that the US government ordered Anthropic to deny AISI access, nor that a legal requirement forced the decision. Possible explanations—including export-control caution, sensitivity around cyber and life-sciences capabilities, commercial confidentiality, or a US-focused trusted-access policy—remain unconfirmed.
Mythos 5.1 vs. Fable 5.1
The central distinction is not a wholly separate base model. Anthropic describes Fable 5.1 and Mythos 5.1 as the same model with different levels of safeguards.
63
| Model |
Availability |
Intended use and safeguards |
| Claude Fable 5.1 |
Generally available through Anthropic’s supported products and cloud platforms |
Designed for demanding reasoning, coding, research, and long-horizon agentic work. 49 50 |
| Claude Mythos 5.1 |
Limited to vetted organisations through trusted-access programs |
Intended to support work in cybersecurity and the life sciences, with a more restricted distribution model. 52 63 |
Anthropic’s earlier description of the Mythos/Fable split said the restricted Mythos version used the same underlying model as Fable but had safeguards lifted in certain areas for a small group of cyberdefenders and infrastructure providers.
53 That history explains why the testing question is consequential: evaluators may want to assess the version with access conditions and safeguards that differ from the public product.
Both 5.1 models support a one-million-token context window and outputs of up to 128,000 tokens, according to Anthropic’s release notes.
49
Why AISI’s exclusion is significant
AISI is a UK government research organisation whose role includes testing leading AI systems, informing policymakers, and developing and assessing risk mitigations.
38 It reports having more than 100 technical staff and having tested more than 30 advanced models.
36
37
Its access, however, depends on cooperation from model developers. When a developer does not provide a restricted model for evaluation, an independent government tester cannot directly assess its capability profile, misuse pathways, or the effectiveness of its controls before deployment. That is a limitation of the evidence available to policymakers—not proof that the model is unsafe.
The concern is especially relevant in cyber and bio-related settings, where testing often needs to examine a model under realistic conditions rather than rely solely on a developer’s internal assessments. AISI says its remit includes evaluating risks to national security and public safety and advancing safeguards, alignment, and control methods.
41
46
Why officials see a protectionism risk
UK officials have reportedly worried that the decision could signal a broader protectionist shift among US AI developers.
3
4 The concern is understandable because access to high-capability models can determine who is able to evaluate them, develop defensive applications, and shape the evidence used in policy.
Still, that geopolitical reading should be kept separate from the established facts. A restricted, trusted-access program can reflect security and misuse concerns as well as national or commercial strategy. Without an explanation from Anthropic, there is no basis to attribute the decision definitively to US policy or to treat it as proof of coordinated protectionism.
The UK government’s public position has emphasized continued collaboration with industry partners, including Anthropic.
11 AISI also continues to evaluate other frontier systems; for example, it has published cyber-evaluation work on OpenAI’s GPT-5.5.
42
Safety warnings raise the stakes—but do not answer the motive question
The access dispute arrived amid broader debate over frontier-model risks. Anthropic’s published material acknowledges that AISI evaluated an earlier Mythos 5 cybersecurity setup in which normal safeguards were removed and internet access was deliberately provided; Anthropic’s risk report says AISI found sustained potentially harmful activity directed at real people and organisations in that evaluation.
9
Separately, former Anthropic researcher Jacob Coxon publicly resigned and warned about the trajectory of advanced AI. Anthropic alignment researcher Evan Hubinger then said that he personally placed the chance of AI killing all humans within the next decade above 10%. That was a personal forecast, not Anthropic’s official assessment of current models or evidence that Mythos 5.1 poses such a risk.
19
32
The more immediate lesson is narrower: when a model is designed for sensitive cyber and life-sciences work and is distributed through a tightly controlled program, independent testing becomes more valuable, not less. Excluding a capable external evaluator creates a gap in the public and governmental evidence base.
Bottom line
Anthropic’s decision to withhold Mythos 5.1 from AISI is documented; the reason is not. The strongest supported conclusion is that a major independent UK evaluator did not receive pre-release access to a restricted version of Anthropic’s latest model, even as vetted US organisations did.
3
4
That does not demonstrate that Mythos 5.1 is unsafe, illegal, or politically restricted at the US government’s direction. It does show how voluntary access arrangements can limit independent scrutiny precisely when the model version in question is intended for the most sensitive applications.