Fable, Mythos and the Illusion of AI Regulation

In less than 96 hours the new model from Anthropic went from highly anticipated to lights out. Mythos 5 and its corralled sibling Fable 5, launched on June 9 and three days later the U.S. Commerce Department issued an order to suspend access to all foreign nationals. Foreign nationals abroad and in the U.S. including members of the teams at Anthropic that built it. No exceptions and with little explanation. Anthropic, left with no specific solution to isolate specific users, disabled both models for everyone, everywhere. In the entire world. The government cited ambiguous national security concerns and little else. I can’t think of any other product that has at times been both encouraged by the government and completely constrained. It is a telling story about the current state of AI regulation.

Aligning Companies and Regulators

AI regulation has a ghostly aura right now. It has a presence, at times takes decisive action, then when industry seeks guidance, it vanishes. Anthropic thought they followed all the rules, even the ones they had to invent themselves, where none existed. AI regulation is not the same as other types of rules overseen by the government. There are few academic white paper studies or congressional hearings that lead to approvals. Rather, AI is out in the open like a product launch that also serves as a large-scale social experiment and that has government staffers checking their notes.

The AI companies and regulators both find themselves posturing. The companies, in their efforts to self-regulate, are projecting confidence in their safety frameworks, deliberate responsibility policies, and benchmark results.

The government, for its part, is projecting authority where it can (like citing national security and foreign trade) but those efforts are misaligned with the technology itself. The recent events show that there is not a clear forward-looking strategy for AI regulation. It is simply reaction.

The Responsible Exception

Anthropic had carefully planned its rollout of Mythos by creating Project Glasswing in early April. The project provided a preview version of the Mythos model to a small set of government regulators, corporations, and cyber security experts. Early observations showed that Mythos Preview was exceptional at finding vulnerabilities in thousands of popular code used to run core functions across the internet. The initial project team members identified more than 10,000 high or critical severity security flaws. Many of these so-called zero-day vulnerabilities have been evaluated and been fixed in the months that followed.

In the days before releasing Fable 5, which has guardrails set up to protect the types of vulnerabilities that Mythos can uncover, Anthropic extended Project Glasswing to more participants. The move also extends membership to 15 countries and many industries that were previously underrepresented such as healthcare, communications, and critical infrastructure. It represents an aspect of responsibility by Anthropic that we do not see from others racing to build AGI. It is also notable that we do not see government regulators in the U.S. and elsewhere giving more consideration to the impacts of AI and safety.

Global Regulation

Global recognition of AI safety has transformed from the early days that followed the release of OpenAI’s ChatGPT in late 2022. The world’s first AI Safety Summit was hosted by the U.K. a year later and cascaded to many of the participating nations to create their own agencies to review AI safety. The word “safety” was deliberate. In the U.S. the U.S. AI Safety Institute (AISI) was created following the summit. However, by 2025 the summit has been rebranded as the AI “Action” Summit and the 2026 event is simply the AI “Impact” Summit. The U.S. also rebranded AISI as the Center for AI Standards and Innovation (CAISI). The removal of the word safety signals something more important.

Global competition of AI has extended economic and political advantages. While AI can improve healthcare, farming, and manufacturing, it can also have other negative impacts, which Mythos has revealed. Safety – at least in the context of infrastructure crippling cybersecurity – is a real vulnerability. Nations that have cast aside concerns about AI safety are making priority choices, advancement over safety, that they need to reconsider. The decisions of the United States which cancelled all previous responsible AI policies only to shut down Fable entirely, reveal this dilemma.


What Fable and Mythos AI show is not a specific gap in any one country’s policy, rather a gap in the world’s readiness to govern. AI regulation in the U.S. is not completely absent, it just has not been able to establish its footing without stepping on itself. The known unknowns persist and few, from the data engineers to the bureaucrats, fully understand the scope of its capabilities, its benefits and its risks. Regulation is about mitigating those risks to organizations and society as a whole. At the moment, we are all actively working with AI in what experimental scientists would call the discovery phase, and we are all its subjects.


Discover more from Derek W Gibson

Subscribe to get the latest posts sent to your email.

Leave a Reply