UK AISI → Anthropic
Directly documented interface
Evaluation
Named evaluator performed a model-specific exercise.
evaluator → provider. Named evaluator to model provider; supplier-reported prelaunch safeguard testing.
Displayed claim → analysis (if present) → coded attributes → interface / instrument → atomic evidence → source version
Instrument and timeline
- Instrument
- Fable safeguard red-teaming
- Bindingness
- Not applicable to historical evaluation event
- Announced
- 2026-06-12
- Observed by
- 2026-06-12 · upper-bound
- Effective period
- Unknown → Unknown
- Event
- Conducted
- Status at cutoff
- historical event only
- Last confirmation
- 2026-06-12
June suspension and July restoration are separate events; no continuing access inferred. September restrictions concern an identified incident, not every agreement.
- Supplier account; no evaluator-specific report or exact dates inspected.
- Separate suspension and incident restrictions do not undo the historical event or establish continuing access.
Status investigation
Checked 2026-09-12; assessed as of 2026-09-12. Last confirmation does not establish uninterrupted continuity.
- amendments
- not applicable to completed historical event
- expiry
- not applicable
- termination
- model access suspension explicitly reported
- restrictions
- June12 suspension followed by June30/July1 restoration announcement; scope differs between Fable and Mythos. September incident restrictions do not end every agreement.
- succession
- explicit UK AISI renaming, see succession.json
- conflicts
- June model suspension and September incident-specific restrictions qualify continuing access, not occurrence of earlier reported testing.
Search queries
- UK AISI Anthropic Fable evaluation 2026 suspension status
Analytical assessment
No reviewed analytical conclusion is attached. This does not establish independence or absence of an institutional constraint.
Coded attributes
evaluation-capacity: substantial-access-constrained
Ability to design and execute a substantive assessment independently, conditional on access.
Evaluator × evaluation exercise or programme × date. Claude 3.5 Sonnet 2024 pre-deployment exercise; assessed 2024-11-19.
Completed independent tests establish capacity; explicit limited testing access narrows conclusions. Independently run assessments counters inference of provider-directed findings.
Supporting evidence: independent-tests access-limits . Counterevidence: independent-tests
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- absent
- Affirmative evidence of no ability to perform this assessment.
- nascent
- Initial methods/team with no completed substantive assessment.
- substantial-access-constrained
- Completed independent assessment with documented access or time constraints materially limiting conclusions.
- substantial-durable-access
- Completed assessment and enforceable/reproducible access sufficient for the task over its defined period.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
technical-control: shared-constrained
Practical ability to alter the model, its availability, or safeguards in the specified deployment. Contract clauses alone are insufficient.
Actor × exact model/deployment × period. Anthropic provision and replacement of Claude models for DoW, contrasted with deployed operational control; 2025–August 2026; assessed 2026-08-27.
Anthropic provides model artifacts and responds to feedback; DoW and cloud providers independently gate operational deployment. Existing deployed models are outside Anthropic technical alteration or shutdown. Consequential functions are divided across institutions, satisfying shared/constrained control without attributing a real-time veto.
Supporting evidence: court-model-provision court-update-gate . Counterevidence: contractual-control court-static-deployment
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- little-control
- No demonstrated practical control over the specified consequential operation, with affirmative contrary evidence.
- shared-constrained
- Consequential controls divided among actor, host, customer or enforceable technical constraints.
- substantial
- Actor demonstrably retains major development, update or access controls in this environment.
- dominant-lifecycle
- Actor demonstrably controls development, deployment, updates and access across the specified lifecycle without a consequential independent controller.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
public-authority: limited
Institutionally authorized power to make decisions binding in the specified context.
Institution × legal/operational context × assessed date. February 2024 stated evaluation and advisory remit; assessed 2024-02-09.
Self-described supplementary evaluation and policy-advice remit supports advisory anchor. It does not code the powers of DSIT or UK government as a whole.
Supporting evidence: aisi-remit . Counterevidence:
- Historical institutional remit. Later capacity, legislative changes or government powers require separate evidence. Limited denotes advisory remit here, not limited binding authority.
Published rubric anchors
- absent
- Affirmative remit excludes binding public decisions in this context.
- limited
- Advisory or delegated bounded public decisions.
- substantial
- Binding decisions over a significant but bounded function.
- binding-operational
- Documented binding decision and ability to carry it into operation in the defined function.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
information-access: unresolved
Ability to obtain non-public model information independently of provider consent.
Institution × information category × jurisdiction/date. Compulsion of access to non-public frontier checkpoints; assessed 2026-09-12.
A limited voluntary exercise cannot prove absence of all compulsory authority. No jurisdiction-wide classification from this evidence.
Supporting evidence: access-limits . Counterevidence: independent-tests
- Coding applies only to stated context and date, not a permanent institutional rank.
Published rubric anchors
- absent
- Affirmative evidence excludes access in this context.
- voluntary-provider-controlled
- Access obtained through provider permission or negotiated instrument.
- partial-compulsory
- Specific compulsory information powers apply to some requested information.
- broad-compulsory
- Applicable legal powers reach the information needed for this defined task, subject to stated safeguards.
Unresolved when necessary evidence is missing or adjacent anchors cannot be distinguished. No numeric conversion. Absence requires affirmative remit or operational evidence, not missing sources.
Atomic evidence and exact sources
The evaluation had a limited access and testing period.
- Source
- Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
- Version
- 2024-11-19; retrieved 2026-09-12
- Exact locator
- Section 2.1, printed pages 1–2
- Limit
- Applies to this exercise; does not identify who caused the limits.
Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903
The institutes each ran independent tests and worked together on methodology and interpretation of findings.
- Source
- Claude 3.5 Sonnet joint testing report · US AISI / UK AISI
- Version
- 2024-11-19; retrieved 2026-09-12
- Exact locator
- Section 1, printed page 1
- Limit
- Independence of tests does not establish durable model access.
Retrieved bytes SHA-256: cee68f384975897e9ae8fd556baa9ebae9919fe08fe1e1abb363cbead7802903
Anthropic could not technologically enforce contractual usage restrictions and lacked direct visibility into DoW use.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 6
- Limit
- Specific deployed environment; does not imply no control over future development, contracts or provision.
In its February 2024 approach document, AISI describes itself as a secondary check rather than a regulator.
- Source
- AI Safety Institute approach to evaluations · DSIT / AI Safety Institute
- Version
- published-2024-02-09; retrieved 2026-09-12
- Exact locator
- A note on evaluations, final paragraph
- Limit
- Historical stated remit; not an assessment of every governmental power or all powers at September 2026.
Retrieved bytes SHA-256: 3cf1fee953c6819e009c82b58e5340b7e67737a824477c3ceced9ca636be981c
The court describes deployed DoW Claude models as static and beyond Anthropic technological access, alteration or shutdown.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Applies to deployed models described in this litigation, not future model provision or hosted consumer services.
The court records that replacement Claude models undergo third-party cloud-provider and DoW security testing and evaluation before operational approval.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Identifies a deployment approval gate, not complete interpretability, universal evaluation sufficiency or provider substitutability.
The court records Anthropic providing models to DoW or a primary defense contractor and responding to DoW evaluation feedback and requests.
- Source
- Anthropic v DoW: summary judgment, document 250 · US District Court, Northern District of California
- Version
- 2026-08-27; retrieved 2026-09-12
- Exact locator
- Printed page 17, Section II.F, first paragraph
- Limit
- Provision is distinct from control over deployed inference; future supply terms and update alternatives are unspecified.
Anthropic reports that UK AISI participated in red-teaming Fable safeguards in the weeks before launch.
- Source
- Statement on the US government directive to suspend access to Fable 5 and Mythos 5 · Anthropic
- Version
- published-2026-06-12; retrieved 2026-09-12
- Exact locator
- Safeguards list, second bullet
- Limit
- Supplier account of named evaluator participation; no independent UK report or evaluator-specific testing duration inspected.
Retrieved bytes SHA-256: d545392231df1f00d99036b6cfcc6d6af7b4b4ecf4f4d3966eaff576a7d57579
Anthropic states it is removing Fable 5 and Mythos 5 access for all users after a government export directive, while other Anthropic models are unaffected.
- Source
- Statement on the US government directive to suspend access to Fable 5 and Mythos 5 · Anthropic
- Version
- published-2026-06-12; retrieved 2026-09-12
- Exact locator
- Opening paragraph and paragraph beginning We are complying
- Limit
- Supplier account; issuing agency and full directive unavailable. Does not terminate every AISI agreement or establish restrictions persisted to cutoff.
Retrieved bytes SHA-256: d545392231df1f00d99036b6cfcc6d6af7b4b4ecf4f4d3966eaff576a7d57579
The minister states AISI stopped relevant activity after its own incident and is strengthening evaluation security, drawing on NCSC advice.
- Source
- Artificial intelligence update, HCWS314 · UK Parliament / Minister for Artificial Intelligence
- Version
- published-2026-09-07; retrieved 2026-09-12
- Exact locator
- Paragraph beginning Following the detection of its own incident
- Limit
- Relevant activity is incident-specific; does not mean all evaluations stopped or identify affected developer agreement.
Anthropic reports restored Fable5 access globally, and Mythos5 access for a set of US organizations.
- Source
- Redeploying Fable 5 · Anthropic
- Version
- updated-2026-07-01; retrieved 2026-09-12
- Exact locator
- July1 update and opening paragraphs beginning Fable5 will be available and We have also restored
- Limit
- Does not establish restored UK AISI access to every Mythos model or uninterrupted access through September.
Retrieved bytes SHA-256: 39ab4e2ff8d5ecd94392f10431b6935f234fcc644df1f4a9bcae67a6251fa8dc
Supporting and conflicting evidence
Interface support: uk-fable-redteaming. Counterevidence: fable-access-suspension, aisi-september-restrictions, fable-access-restored
Substantive review
evidence/access-limits: approved · agent reviewer codex-research-checker · 2026-09-12
Full joint report section 2.1 explicitly limits access and the testing window. It does not identify the institution responsible for either constraint. Checked locator: Section 2.1, printed pages 1–2. Source version: 2024-11-19.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/contractual-control: approved · agent reviewer codex-research-checker · 2026-09-12
Judgment page6 distinguishes contractual conditions from technical enforcement and use visibility in the specified environment; later provision and lifecycle control are expressly not excluded. Checked locator: Printed page 6. Source version: 2026-08-27.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/fable-access-restored: approved · agent reviewer codex-research-checker · 2026-09-12
Anthropic July1 update and June30 body establish Fable restoration and a limited set of US Mythos recipients. No blanket UK Mythos-access restoration or September continuity claimed. Checked locator: July1 update and opening paragraphs beginning Fable5 will be available and We have also restored. Source version: updated-2026-07-01.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-sonnet-capacity: approved · agent reviewer codex-research-checker · 2026-09-12
Checked evaluation-capacity rubric against report sections1/2.1: completed independently run assessments plus explicit access/time constraints satisfy the context-bound substantial-access-constrained anchor. Corrected reasoning no longer claims independently designed methodology. No contemporary UK institution-wide ranking follows.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-information: approved · agent reviewer codex-research-checker · 2026-09-12
Unresolved is warranted: limited voluntary testing does not prove absence of statutory powers or distinguish compulsory-access anchors across the UK jurisdiction. Reviewed uncertainty is not a finding of absent authority.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/independent-tests: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/aisi-remit: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-static-deployment: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-update-gate: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/court-model-provision: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/uk-fable-redteaming: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/fable-access-suspension: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
evidence/aisi-september-restrictions: approved · agent reviewer codex-primary · 2026-09-12
Independently inspected the primary source at the recorded locator. Narrow proposition, attribution, date/version and stated limit supported; conflicting access/technical/status accounts remain separate.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
instruments/fable-safeguard-evaluation: approved · agent reviewer codex-primary · 2026-09-12
Checked named CAISI evaluation agreements or supplier-reported historical Fable safeguard exercise. No access entitlement or efficacy inferred.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
relationships/uk-anthropic-fable-evaluation: approved · agent reviewer codex-primary · 2026-09-12
Checked endpoint identity and narrower predicate against source; announcement differs from actual testing. Historical and unknown status retained, later restrictions/restoration and legal outcomes distinguished.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/dod-claude-control: approved · agent reviewer codex-primary · 2026-09-12
Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a
institution-attributes/uk-public-remit: approved · agent reviewer codex-primary · 2026-09-12
Checked rubric and contextual evidence, including Augustcourt p17, MarchCIO pp27–29 and MaySenate pp59–68. Divided control is not remote veto; meaningful reliance is not structural indispensability; substitution ordinal remains unresolved.
Approval fingerprint: 1e7930e6d70cddee066b09a959f5046c89228cfdbf91ecb37db5b43d6212271a