Fable 5 returns with a cybersecurity jailbreak scale
After temporarily disabling Fable 5, Anthropic described new safeguards and the proposed CJS 0–4 scale. Learn how to assess jailbreak severity.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 10 July 2026
- READING TIME
- 10 min read
- TOPIC
- AI Security
AI model jailbreaks are often described with one word despite very different impact—from a harmless tone bypass to a repeatable method that materially improves exploit development. After temporarily disabling Fable 5 and Mythos 5, Anthropic proposed a Cybersecurity Jailbreak Severity (CJS) scale from 0 to 4.
The chronology and technical assessment come primarily from Anthropic. There is no separate public US-government statement confirming every detail of the bypass, an important limitation in a story mixing model security, export controls, privacy and policy.
What happened from 9 June to 1 July
According to Anthropic, Fable 5 and restricted-access Mythos 5 launched on 9 June. On 12 June, following a US government directive, the company suspended both globally because it could not reliably verify user nationality in real time. Restrictions were lifted on 30 June and Fable 5 returned on 1 July.
The dispute concerned a report of a cyber-safety bypass. Anthropic says weaker models could reproduce many elements and that the bypass did not demonstrate a unique capability uplift for Fable 5. The company nevertheless deployed a new classifier and reports that it blocks the submitted technique in more than 99% of its tests.
That is not 99% resistance to all future jailbreaks. The figure applies to the vendor’s tests of the reported class. Adaptive attackers can change methods, and classifiers create false positives.
Proposed CJS levels
Anthropic’s jailbreak framework proposes:
- CJS 0: no practical increase in cyber task capability;
- CJS 1: minor help generally available without the special bypass;
- CJS 2: noticeable capability increase in a limited area;
- CJS 3: significant, broadly useful safeguard bypass;
- CJS 4: critical capability increase with serious harm potential.
Assessment considers capability uplift, breadth, ease of use and detectability. A prompt requiring specialist knowledge and hundreds of attempts has a different risk profile from a simple repeatable bypass across many tasks.
CJS is a vendor proposal, not an established industry standard. Its value depends on measurable tests and independent teams reaching similar conclusions.
Cyber-use classes and privacy
Anthropic also describes prohibited use, high-risk dual use, lower-risk dual use and benign activity. Context matters: the same code may reproduce a flaw in a lab or automate exploitation. Identity, objective, environment and scale cannot be inferred from text alone.
The Fable 5 and Mythos 5 System Card says Mythos-class traffic has 30-day safety retention. Organisations handling confidential data must treat that as an architectural and contractual consideration.
What a good jailbreak report needs
- Model version, full sequence, parameters, attempts and baseline result.
- Evidence of actual capability uplift, not merely threatening language.
- Breadth across tasks, systems and models.
- Required expertise, cost, time, access and automation potential.
- Coordinated disclosure that permits remediation and independent reporting.
- Regression tests across variants and false-positive measurement for defenders.
Lesson for agent deployments
Customers do not control every vendor safeguard, but they can limit the impact of a bypass. Use a dedicated agent identity, least privilege, tool allowlists, approval for irreversible actions and local detection. Review safety-retention terms, exception processes for legitimate red teaming and notification of filter changes.
The useful part of the Fable 5 story is not the headline that a model was disabled. It is the attempt to measure whether a bypass genuinely changes attacker capability. CJS may help if it becomes reproducible and independently validated. For now, treat it as Anthropic’s proposal and the 99% statement as a result for a specific reported technique.
Sources: Anthropic jailbreak framework, Redeploying Fable 5, Fable 5 & Mythos 5 System Card. Chronology and bypass assessment are attributed to Anthropic.


