Anthropic · 2026-06-10 · major
Cybersecurity Researchers Rip Anthropic Claude Fable 5's Overbroad Cyber Guardrails — IBM X-Force's Valentina 'Chompie' Palmiotti and Tolmo's Matt Suiche Say the New Classifier Reroutes Even Code Reviews and Reading Security Blog Posts to the Older Claude Opus 4.8, Forcing Pros Into Anthropic's Cyber Verification Program
Security pros say Fable 5's keyword-based cyber and bio classifier silently routes them to the older Opus 4.8 for routine work like code reviews, and the only escape is Anthropic's application-gated Cyber Verification Program.

Day-two backlash against Fable 5: the cyber/bio classifier is so broad it punts code reviews to an older model.
Key specs
| Fallback model | Claude Opus 4.8 |
|---|---|
| Fallback rate | <5% of sessions per Anthropic |
| Named critics count | 6 |
What is it?
TechCrunch reported on June 10, 2026 that named cybersecurity practitioners are publicly criticizing the new safety classifier on Anthropic's Claude Fable 5 — the Mythos-class model released to the public on June 9. The complaint is that the classifier reroutes requests it suspects are cyber- or bio-related to the older Claude Opus 4.8, even when the request is a routine code review or asks Fable to read a security blog post.
How does it work?
Anthropic's safeguard sits outside the model: a separate classifier inspects every request and, if it pattern-matches cyber or bio keywords, swaps in Opus 4.8 instead of Fable. Anthropic says the fallback fires on under 5% of sessions, but IBM X-Force's Valentina 'Chompie' Palmiotti said on X that Fable 'rejects any request that could be tangentially cyber related,' and Tolmo founder Matt Suiche said asking Fable to write secure code triggers the cyber path and 'falls back to a weaker model.' Other named critics include @Behi_Sec, @zeroxjf, Alex Plaskett, Mehul Mpt, and evilsocket. The escape valve is the Cyber Verification Program, a free but vetted application that takes roughly two business days and is not open to Zero Data Retention customers.
Why does it matter?
Fable 5 is supposed to be the everyday Mythos-class model, but the most demanding offensive- and defensive-security users — exactly the population Anthropic needs onside via Project Glasswing — are saying it cannot do their job out of the box. If the classifier stays this strict, vetted competitors (and Mythos 5 through Glasswing) get an opening, and Anthropic's own dual-use research-flow story takes a hit one day after launch.
Who is it for?
red teamers, security researchers, AppSec engineers, Anthropic policy team
Try it
https://support.claude.com/en/articles/14604842-real-time-cyber-safeguards-on-claude