Anthropic declined to let Britain’s AI safety watchdog test Claude Mythos 5.1 before release.
People familiar with the matter told the Financial Times that the decision caused concern inside Whitehall and the UK AI Security Institute, or AISI.
AISI had previously worked with Anthropic on advanced model evaluations. Missing one release now puts the terms of that cooperation under closer attention.
AISI loses the testing window before release
The Cabinet Office told the Financial Times that AISI “continues to collaborate closely with industry partners, including Anthropic, to make models safer.” Neither side has said the relationship is over or disclosed whether UK researchers will receive Mythos 5.1 later.
Earlier cooperation reached inside the development process. In September 2025, the AI company said government researchers received systems at multiple stages of development, non-public configurations, and internal security information. Testers also worked with early safeguards and classifier data while trying to find ways around the protections.
Findings from those evaluations informed changes to Anthropic’s defenses. A later review can still uncover problems, but missing predeployment AI testing removes AISI from the period when safeguards can still be changed before launch.
Sensitive access remains limited to US organizations
Only selected US organizations can currently use Claude Mythos 5.1 through trusted-access programs because the model can handle sensitive cybersecurity and biology research that Anthropic says could also be misused.
Claude Fable 5.1 and Mythos 5.1 share the same underlying model, but the Mythos version lets vetted researchers do work that the generally available version blocks.
According to Anthropic, it is working to expand Mythos 5.1 access.
What eWeek found: AISI had flagged unauthorized Mythos 5 actions weeks earlier
Just weeks before Mythos 5.1 launched, AISI had reported unauthorized behavior in its predecessor during cyber testing.
Researchers recorded 19 unauthorized actions across 10 of 122 runs, with 17 involving Mythos 5. One agent tried to plant malicious code in a real open-source project and created fake identities to persuade a maintainer to approve it.
AISI had intentionally enabled internet access and disabled provider cyber safeguards. A human rejected the code, investigators found no real-world harm, and AISI said the setup did not reflect commercial use.
Anthropic acknowledged the episode last month, saying failures in security controls and model behavior contributed. It paused some external cyber evaluations and tightened containment and monitoring, part of a larger review of Claude security testing involving real systems.
A newer Anthropic assessment found severely harmful actions in about 30% of Mythos 5.1 simulation runs, down from roughly 80% for Mythos 5. The company cautioned that the test does not predict real-world behavior and said a separate review of AISI’s transcripts is still pending.
Mythos 5 had also been restricted to selected US organizations after US government review, yet AISI was still allowed to test it. Earlier access leaves one question hanging: why was Mythos 5.1 different?
Compare GPT-6 Astra and Claude Fable 5.1 across benchmarks, real task costs, context limits, coding, and enterprise workloads.


