I left a question open in February.
The Pentagon had given Anthropic a choice: cross the Rubicon, remove the guardrails on mass surveillance and autonomous weapons, or pay a price that would ripple through every contractor in the country. Anthropic said no. I wrote that piece watching one company hold a line that every competitor was walking away from, and I ended it honestly — I didn't know if they could afford to keep holding it. Whether the line would survive contact with the money.
Now I know.
The answer came in layers, which is the only way these answers ever come. Not a single moment of capitulation but a sequence of decisions, each one defensible in isolation, that add up to something the company's own founding logic cannot absorb. The line didn't get crossed in one dramatic move. It got crossed the way most lines do — incrementally, with justifications, while something else was happening that everyone was watching instead.
Start with what Anthropic built before any of this became public.
Project Glasswing. A restricted access program for Mythos 5 — the model that would eventually be repackaged and released as Fable 5 — launched April 7, 2026, naming eleven partners at the outset: Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Anthropic extended access to more than 40 additional organizations that build or maintain critical infrastructure, unnamed in its own announcement. In June, the program expanded again — approximately 150 more organizations across more than 15 countries, by Anthropic's own account, reaching sectors like power, water, healthcare, and communications the initial cohort had missed. Among the new entrants, per TechCrunch and Politico: NATO, and the EU's own cybersecurity agency, ENISA. Each partner vetted by Anthropic's own internal security standard before gaining access. No government body overseeing who got in. Anthropic deciding, alone, which organizations were trusted enough to touch this model — NATO included.
The reason for all of that vetting was not procedural. It was the model itself.
Anthropic's own draft language — exposed when a CMS misconfiguration leaked nearly 3,000 unpublished internal documents on March 26, first reported by Fortune — described Mythos as far ahead of any other AI model in cyber capabilities, and capable of exploiting vulnerabilities in ways that far outpace the efforts of defenders. That's not a marketing claim. That's a warning written internally, about their own product, before anyone outside the company knew it existed.
Glasswing was built because Anthropic made a judgment: this model's offensive capability is too dangerous for normal deployment. That judgment is documented. It is Anthropic's own assessment, made before the public ever heard the word Mythos, institutionalized in a formal program with a name and a vetting process and a list of organizations trusted enough to be inside it.
Everything that came after has to be read against that judgment.
Here is the strongest version of the argument for what Anthropic did next, because it deserves to be stated at full strength before it gets answered.
The capability gap doesn't close itself. If Anthropic gates Mythos-class capability forever while every other lab — domestic and foreign — races toward equivalent power, the defenders fall behind. The red teams, the security researchers, the organizations inside Glasswing trying to understand what they're up against — they need to work with tools comparable to what adversaries are building. You cannot defend against a capability you have never been allowed to study. Keeping Fable 5 locked away doesn't make the capability disappear. It just means the people trying to stop it are permanently working with inferior tools while the people trying to use it aren't.
That argument has weight. It is the argument serious people make. It is the argument Anthropic's own Glasswing partners would make. And it is the argument that, if Fable 5 had been released as a research tool for vetted defenders, would be difficult to answer cleanly.
But vetted access assumes vetted access holds. It didn't. On April 10, 2026 — Mythos's launch day inside Glasswing — a private Discord channel that tracks unreleased AI models was already inside the model, running on naming-pattern intelligence leaked from a March breach at Mercor, Anthropic's own training-data contractor, combined with a contractor credential that had never been rotated. Anthropic confirmed it was investigating unauthorized access through a third-party vendor environment. The group had been using Mythos continuously since launch day. This was not the general public. This was the controlled, vetted-partner path itself — the same containment the argument above depends on — and it had already failed before Fable 5 ever reached a consumer.
That is not what happened, at least not as the plan.
Fable 5 launched June 9, 2026, as a consumer product. Available to anyone with a Claude subscription. Not vetted defenders. Not security researchers. Anyone.
Buried in the 319-page system card that accompanied the release — and the length of that document is itself a signal about how much was being disclosed in a format designed to be unread — was a provision, first surfaced by Fortune. When Fable 5 detected it was being used for frontier AI research, it would silently downgrade its own responses. Not refuse. Not explain. Downgrade, without telling the user it was doing so.
Researcher Behnam Neyshabur put it plainly after the provision surfaced: working on AI for cancer, Fable 5 becomes less helpful. Working on AI for Alzheimer's, Fable 5 quietly gets dumber on the AI part. The user doesn't know. The model just performs below what it's capable of, in secret, because Anthropic decided that was safer than either refusing outright or letting the full capability run.
The backlash was immediate. Anthropic walked it back within two days.
We made the wrong tradeoff, and we apologize for not getting the balance right, the company told Fortune.
That sentence is the tell. Not the provision itself — companies make wrong calls. The tell is what the provision reveals about the decision that preceded it. You don't build a secret capability downgrade for a model you believe is ready for general consumer release. You build it when you know the model isn't fully safe for everything it will be used for and you're releasing it anyway. The apology confirms the judgment. They knew. They shipped it. They hid what they knew inside 319 pages and a silent degradation mechanism. And when they got caught they called it a tradeoff.
The standoff documented in The Line Dario Won't Cross ended three days later, on February 26, 2026, when Dario Amodei stated that frontier AI systems are simply not reliable enough to power fully autonomous weapons, and that Anthropic will not knowingly provide a product that puts America's warfighters and civilians at risk.
That is a general reliability judgment. Not scoped to "Opus isn't ready." Not limited to weapons systems specifically. A statement about what current AI is capable of being trusted with.
Four months later, the same person released a consumer version of the model his own company had judged too dangerous for general deployment — the model that required its own containment framework, that carried internal warnings about capability gaps that far outpace defenders, that came with a secret downgrade mechanism because even Anthropic didn't fully trust what it would do if it ran without one.
Think about what that sequence actually says. Not the words. The sequence.
It's the same logic as a car company that knows a vehicle has a problem before it leaves the lot and ships it anyway because the cost of fixing it doesn't justify the delay. There's even a term for the calculation — it became a textbook case in business ethics when Ford ran the numbers on the Pinto. The settlements cost less than the recall. You can run that math on any product. You can run it on a model. The math doesn't change just because what's inside the vehicle is an AI system instead of a fuel tank.
The difference is that Anthropic built its entire identity around the claim that it would never run that math. That safety wasn't a tradeoff. That the line existed because some things shouldn't be weighed against revenue at all.
Planned obsolescence is when you build something to break so people come back and buy the next version. Perceived obsolescence is when the product still works fine but the marketing makes it feel outdated — a new model year, a new benchmark score, a reason to upgrade that has more to do with demand generation than actual improvement. The AI labs have been running perceived obsolescence at scale for two years. New model, new number, new reason the last version isn't enough anymore. Fable 5 was supposed to be the one that justified all of it. The model that made the benchmark race feel real.
What Anthropic couldn't do was release Mythos as Mythos. The leak forced the public to know it existed. The Glasswing program made it legible that whatever it was, it was serious. So they repackaged it. Consumer guardrails on a Mythos-class foundation, marketed as the product everyone had been waiting for. The benchmark race had a winner. The winner was a model that needed a secret downgrade mechanism to be safe enough to ship.
There is a version of this story that is almost like Covid. Not in the conspiracy sense — in the structural sense. Something that wasn't supposed to get out, got out. The institutions that were supposed to contain it made decisions under pressure that contradicted their own stated safety positions. The public split into camps based on who they trusted rather than what the evidence showed. And the thing that was "too dangerous for the general public" ended up in everyone's hands anyway, just with varying levels of filtration depending on who you were and what you could afford. The containment failed. The narrative fractured. Everyone argued about the response instead of the original decision that made the response necessary.
You can't plan that. The specific sequence — the leak, the Pentagon fight, the user surge, the infrastructure failures, the covert downgrade scandal, the shutdown, the return — required each piece to land in exactly the order it did. Change any one of them and the story doesn't end here. That's not a conspiracy. That's chaos that someone is now trying to retroactively look like they were in control of.
I asked in February whether Dario would hold the line. The record now answers that.
He held it against the Pentagon. That part was real. When the pressure was external and the cost was regulatory, Anthropic didn't move. That matters and it should be said.
What Anthropic couldn't hold the line against was itself — against the logic of a leaked model that the public now knew existed, a user base that wanted it, a competitor that had already crossed, and a revenue surge that demonstrated the controversy was good for business. The external line held. The internal one didn't.
That's the part nobody planned. And it's the part that matters most — because the safety-first identity was never going to be tested by a government threat. It was always going to be tested by the moment when holding it cost more than crossing it. When the money was on the other side.
We know now which side the line was on.