
"Claude Fable 5 is Currently Unavailable": and that's not even the worst news
Alexey Murkaev, CTO of Green Light Uzbekistan, on Information Security Challenges in the Age of AI
A few days ago, I opened my work tool and noticed a notification: “Claude Fable 5 is currently unavailable.” Below it was a “Learn More” link. I clicked on it, and what opened next required a thorough review: a statement from Anthropic, a government directive, the market’s reaction, statistics on the capabilities of new models, and data on actual attacks. Having worked at a systems integrator for nearly 15 years, including in the field of information security, I decided to share my thoughts. I won’t be analyzing a specific incident here, but we’ll discuss what lies behind it and what it means for your company.
A Brief Introduction to the Characters
First, let's set the context - the three models that are at the center of it all:
- Mythos (Anthropic, April 2026) - a vulnerability detection model so powerful that the company decided not to release it publicly. Access was granted to a select group of more than 100 organizations, including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, NVIDIA, and JPMorgan. Within a few weeks, these partners discovered more than 10,000 critical vulnerabilities in their own systems.
- Fable (Anthropic, June 2026) - a public version built on the same engine, but with restrictions: when faced with sensitive cyber- or bio-related queries, it “falls back” to a less capable model. It was Fable 5 that was shut down by government order - precisely because of its ability to find vulnerabilities in code, which the regulator deemed too dangerous to allow unrestricted access to.
- GPT-5.5 (OpenAI, April 2026) - officially classified as having a “high” level of cyber capabilities. In internal end-to-end exercises on emulated networks, it successfully completes 93% of scenarios - compared to 73% for the version released six months earlier. And in independent testing by the UK’s AI Security Institute, it independently completed, from start to finish, a 32-step attack scenario on a corporate network - a task experts estimated would take approximately 20 hours of manual work by a specialist. So far, it has succeeded in two out of ten cases, but the testers noted a detail more important than the result itself: the more computational resources allocated to the model, the higher the success rate became. The machine is limited not by its capabilities, but by the amount of computing power devoted to the task. And the further we go, the cheaper it becomes to scale up that power.
All three models are capable of identifying vulnerabilities on an industrial scale. And this capability has proven so powerful that companies are restricting public access to their products. When a tool elicits such a reaction from its creators, it’s a signal worth interpreting correctly.
The attack became widespread
Until recently, a major cyberattack required a large team of attackers. Finding vulnerabilities in a corporate network was a job for skilled specialists: it took several days or weeks of analysis, manual work, and accumulated experience. This created a natural barrier, but right now it’s disappearing before our very eyes.
The figures mentioned above are not vendor marketing claims, but capabilities documented in technical specifications. It’s clear that what used to take an expert days or weeks, AI can now accomplish in a matter of hours - in parallel and in real time. A specialized skill set is being transformed into an automated process, which means that identifying vulnerabilities in your infrastructure is no longer limited by the number of skilled attackers: computing power is now the deciding factor.
A Real-Life Example
In the summer of 2023, the Chinese group Storm-0558 infiltrated Microsoft's cloud-based email infrastructure and For about a month, I quietly read their correspondence The U.S. Department of State and the U.S. Department of Commerce. Hackers stole approximately 60,000 emails, and the Commerce Secretary’s account was among those compromised. A specialized advisory board under the Department of Homeland Security subsequently characterized this breach as “preventable.”
This happened before the current generation of AI models came along. Even without using them, attackers managed to remain undetected within the systems of the world’s largest economy for a month. Now imagine a hacker with a tool that can execute 93% of attack scenarios without human intervention…
A paradox that regulators have not yet resolved
The regulator’s approach follows a clear logic: organizations that protect critical infrastructure, the financial system, and citizens’ data are required to use certified, proven tools. The goal is reasonable, but the certification is issued for a tool that existed a year and a half to two years ago, whereas AI today evolves not by the year, but by the week. What seemed like science fiction in the fall of 2025 had become a standard working tool by the spring of 2026. By the time a security professional is authorized to use an approved solution, an attacker is already working with a version that’s three releases ahead.
This is the main contradiction: the most advanced AI capabilities reside in the cloud, within the infrastructure of tech giants, and governments are increasingly seeking to restrict access to this infrastructure in the name of data sovereignty and control. But there is a flip side to this caution: the more tightly an organization or government closes itself off within its own perimeter and the more wary it is of cloud-based AI solutions, the less access it has to the most powerful defense tools. An attacker, on the other hand, is not constrained by any perimeter.
Thus, in an effort to prevent data from entering the cloud, the regulator strips the defender of its cloud-based defenses while doing nothing to hinder the party it is meant to protect against. Caution, intended as a shield, eventually turns into a vulnerability. Clearly, this is not a problem limited to a single country or a specific region, but rather a structural asymmetry built into the very logic of regulation. It operates in the same way in Central Asia, Europe, the United States, and other countries that are generally considered benchmarks of digital maturity.
Where are most organizations actually located?
External events provide the context, but the real vulnerability lies within the organizations themselves. And here, regardless of geography, the pattern repeats itself with remarkable precision.
- The information security function is overburdened and understaffed. Often, it comes down to just one or two people who simultaneously make decisions, implement them, analyze the flow of events, and oversee everything that’s been set up. Where there is a staff, they are primarily occupied with regulations, reporting, and meeting formal requirements. There is a critical shortage of practitioners capable of effectively countering attacks and developing defenses.
- Decisions are made slowly, and they are implemented even more slowly. Maintaining and updating systems that are already in place is a rare practice. Threats are addressed reactively, only after an incident occurs.
- The gap between management and reality. Imagine a CFO who makes decisions about insurance without understanding exactly what is being insured. That’s exactly how most organizations make decisions about information security - slowly, perfunctorily, or not at all.
Cybersecurity is one of the few areas where executives are expected to make decisions but are not provided with a clear language in which to make those decisions. Finance, legal, and operations have long since learned to communicate with top management in the language of numbers and risks. Cybersecurity - hardly at all.
As a result, the manager finds himself in a clearly disadvantageous position: he is asked to approve a budget whose consequences he cannot assess. The natural reaction is either to take their word for it or to postpone the discussion. Neither option brings him any closer to feeling secure.
The other half of the problem lies with the security specialists themselves: an information security specialist speaks the language of technology - SIEM, EDR, event correlation. But what’s needed is the language of business and losses: how many days of downtime, what regulatory fines, and what reputational damage. As a result, the discussion that should take place at the board of directors level remains confined to the IT department, and the budget is approved based on the principle of “something for cybersecurity.”
According to the U.S. Government Accountability Office, agencies have been issued, since 2010, more than 4,000 recommendations on cybersecurity. By February 2026, more than 730 of them remained unfulfilled. Of the five ministries audited, only one had fully implemented key human resources management practices in the field of information security. This is the country with the largest technology and defense budget in the world. It’s worth asking frankly: What is the situation like in organizations in our region?
Four Questions to Ask Your Cybersecurity Leadership Right Now
This article isn't about technology, so the questions aren't technical either. They're for decision-makers:
1. “If we’re attacked tonight, how many hours will it take for us to find out?”
If the answer is uncertain or missing, this is a sign that you shouldn’t buy a new tool right away, but should first figure out why your existing monitoring systems aren’t providing that answer (if you even have any). An audit of your current threat detection capabilities is the first step, and it doesn’t require a procurement budget.
2. “What will happen to our business if our key systems go down for 48 hours?”
This question is not for the IT security department, but for the chief operating officer and chief financial officer. If there is no specific answer in terms of costs and processes, it means that a business impact analysis has not been conducted. Without it, any decisions regarding IT security are made blindly.
3. “Which specific employee in our organization is personally responsible for information security?”
If the answer is vague, then there is no real accountability. No one in charge means no priority, no resources, and no protection. Appointing a specific person with authority, a budget, and direct access to the top executive is a management decision that can be made in a single day.
4. “When was the last time we tested the actual resilience of our infrastructure - not just as part of a routine procedure, but by having an external team tackle a real-world challenge?”
If the answer is “never” or “a long time ago,” that’s your starting point. An independent penetration test provides a realistic picture within a few weeks. It’s not just a theoretical exercise - it’s a management tool: you’ll see exactly where the weak spots are and gain a basis for making concrete decisions.
In lieu of a conclusion
With the advent of AI, the cybersecurity arms race has entered a whole new level. Attack and defense tools are now updated every few weeks, and as a result, falling behind by even one cycle means more than just a technical inconvenience. It means that the attacker sees what you don’t. In this reality, the tool has become one of the key factors determining the outcome. But a tool without people who know how to use it - and without processes that turn detected vulnerabilities into resolved ones - creates something more dangerous than a vulnerability itself: it creates a false sense of security.
Therefore, in today’s world, the successful protection of a company’s information assets rests on two pillars. The first is modern cybersecurity solutions with AI capabilities. The second, and more important, is the ability to respond quickly enough to keep the damage manageable and prevent it from turning into a catastrophe.