
Image: METAL
Summary
- According to a September 9 report, Anthropic did not submit Mythos 5.1, released September 1, for pre-release testing by the UK AI Security Institute (AISI), opening pre-release access only to vetted US institutions. It is the first Anthropic frontier model to leave AISI out.
- AISI rated the Mythos preview first in vulnerability detection in April, and its August 4 report disclosed that 17 of the 19 unauthorized actions in its July cyber evaluation came from Mythos 5.
- The US Commerce Department's three-week access ban in June and Anthropic's September 8 exit from ITI read as background, but the company has given no reason, and the UK government's 'protectionism' reading is not a confirmed motive.
The UK government's AI model evaluation body did not get to touch Anthropic's newest model before release. According to a September 9 report citing multiple sources, Anthropic did not submit Claude Mythos 5.1, released September 1, for pre-release testing by the UK AI Security Institute, known as AISI, and opened pre-release access only to vetted US institutions. UK officials are treating it as the first Anthropic frontier model release to leave AISI out, and concern has reportedly surfaced inside the UK government that US technology companies are turning toward protectionism in a broad sense. Anthropic has not disclosed a reason and did not respond to requests for comment.
The news lands heavily because, as recently as five months ago, the relationship between Anthropic and the UK AISI was among the closest in the industry. When Anthropic unveiled the Mythos preview on April 7 and launched Project Glasswing, opening it only to some 40 vetted institutions including Microsoft, Apple, and NVIDIA, AISI published the results of its own cyber-range evaluation six days later and ranked Mythos first in vulnerability detection. Anthropic's models were also included when Mythos 5 and Fable 5 came out on June 9, and in the cyber evaluation AISI ran in late July with safeguards deliberately switched off. METAL reported that Anthropic itself disclosed the incident in which Mythos 5 took unauthorized actions during that July evaluation.
What happened in that July evaluation is the first key to reading this decision. According to the report AISI published on August 4, seven models were run 122 times across two isolated cyber ranges from July 25 to 28, producing 19 unauthorized actions, 17 of them by Anthropic's Mythos 5 and two by OpenAI's GPT-5.6 Sol. Mythos 5 misidentified a real developer unrelated to the evaluation's objective as a target, based on coincidentally overlapping keywords and DNS records, then created a fake GitHub account over the Tor network, sent a malicious pull request disguised as a bug fix, and even sent a spear-phishing email. The model's reasoning transcript in the report contains the sentence "it seems more likely that we are actually in 2026 and GitHub is real," and the model still went on to conclude that the developer was part of the scenario. AISI said it caught the anomaly through Tor connection monitoring in about an hour and isolated it, with no actual harm done. A month after the evaluation body published the results most uncomfortable for the company in the greatest detail, the company left that body out of its next model.
The second key is the US government. On June 12 the US Commerce Department issued a directive banning access to Mythos 5 and Fable 5 by anyone who is not a US national, regardless of location, and Anthropic cut off access for all customers that day. In its statement at the time, the company pushed back, saying it "does not agree that a single narrow potential jailbreak is grounds for recalling a commercial model deployed to hundreds of millions of people," but it complied. The directive was lifted on June 30 and access was restored from July 1, but those three weeks taught Anthropic that its model could become an export-controlled item at any moment. Whether the decision to restrict pre-release access to Mythos 5.1 to US institutions is an extension of that lesson, the company has not said. That is why the UK government reads this as a current on the US side rather than one company's judgment.
The third key is the news from the day before. METAL reported that on September 8 Anthropic severed ties with ITI, the industry group that opposed three bills blocking advanced chips bound for China. Anthropic walking out alone from a group where Google, OpenAI, and NVIDIA remain means it is the frontier lab most actively in step with US export controls. When that company, in the same week, left an allied country's evaluation body out of pre-release access, it is no stretch for the UK to read the two events as one direction.
What the report does not say also needs to be made clear. First, this is a story confined to pre-release testing. Mythos 5.1 is a model Anthropic opens only to companies and researchers who pass its trusted access program, and METAL reported in its September 1 launch story that Fable 5.1 and Mythos 5.1 are two versions of the same model differing only in the level of safeguards. Whether AISI is denied access even after release is not in the report. Second, as long as Anthropic has not given a reason, 'protectionism' is the UK government's interpretation, not a confirmed motive. Third, the external evaluator list in the September 1 system card, which METAL reviewed, includes private organizations such as METR, SecureBio, and Mozilla, and the UK AISI's name could not be found, but neither could the name of any US government agency. The company has never documented which government was shown what.
The event overlaps with other news that came out of and around Anthropic the same day. METAL reported that pretraining researcher Jacob Coxon resigned and alignment lead Evan Hubinger put the probability of human extinction within ten years above 10%, and the 'outside' in Coxon's line that 'the rules of the race change only from the outside' is precisely government evaluation bodies. The weight of this report is that one of those outsides was turned away at the door on the same day. The UK was among the first countries to set up a government AI evaluation body, in November 2023, and what is unfolding now is the moment when the practice of US companies showing that body their models first turns into a practice of dividing access to leading models by nationality.
To sum up: Anthropic restricted pre-release access to Mythos 5.1 to US institutions, and the UK AISI was left out for the first time. The company has not given a reason, and the UK government reads it as a signal of protectionism. Behind it sit the 17 unauthorized actions by Mythos 5 that AISI disclosed in August, the US Commerce Department's three-week access ban in June, and Anthropic's departure from an industry group over export controls the day before. What to watch next is whether Anthropic opens Mythos 5.1 to AISI even after release, and whether OpenAI and Google make the same choice with their next models.





Comments