
When Anthropic’s Mythos 5 was accessed by a third-party vendor environment within the first few hours of its release, it looked like an isolated security story. Less than three months later, the same model —along with its general public-focused Fable 5 —was switched off for every customer worldwide by a single government directive. These were two very different failures, but it came with one lesson: organisations don’t control their access to the AI they depend on.
Enterprises had no warning and no recourse. Access returned weeks later, partially, and only to a government-approved list. For AI governance teams, the message was blunt: their access to a critical capability was decided in a room they weren’t in.
From leak to lockdown, and back again
When Anthropic’s Claude Fable 5 access was removed, the knock-on effects were immediate and commercially significant: JPMorgan blocked Claude access for its Hong Kong staff, following an earlier move by Goldman Sachs; India’s sovereign AI ambitions ran headlong into the access limits; and AI developers in Asia used the gap to launch their own vulnerability-hunting models. None of these events were triggered by a new incident at the enterprises affected. They were triggered by decisions made entirely outside the companies’ control, and most of the industry had no contingency plan for it.
This back-and-forth, more than the original leak, is forcing technology leaders to rethink the foundations on which they have based their AI governance. Experts have long warned AI agents are operating and acting on behalf of the organisation based on governance frameworks built for a different era of automation. The Mythos saga shows how quickly things can change.
Reframing what governance means in an agentic environment
If access to a frontier model can vanish overnight, the question for enterprises becomes what they can actually control. Governance often gets misread as shorthand for policy documents and risk frameworks. In an agentic context, it means something more operational — knowing and controlling, with precision, every action an agent takes. Such a capability requires clear agent identities, defined permissions, and complete audit trails showing what an agent did, when it acted, what data it used, and which model version informed the decision. When a regulator, compliance team or client asks why something happened, the answer should be immediate, not buried in a fog of obscure data.
This level of governance also means treating agents like employees. Identities are provisioned when an agent starts work and revoked when it stops, permissions match the job and nothing more. An agent you cannot switch off is a liability, whatever model it runs on.
The lesson isn’t about any single vendor being uniquely risky. Rather, the events show enterprises building their governance around a single vendor’s continued availability instead of their own control plane are exposed every time that vendor’s regulatory or security position shifts.
From Exploration to Enforcement
Regulators are moving in step with this. In June, the Financial Stability Board published 12 “sound practices” for agentic AI governance in financial services, warning greater autonomy increases the risk of unauthorised actions, data breaches and failures of human oversight. Weeks later, the Bank of England’s deputy governor Sarah Breeden went further, calling for bespoke regulation of agentic AI. She argued constant human oversight is unrealistic in areas such as payments and trading. Clearly, regulators are forming expectations based on how organisations deploy and govern AI today.
Bridging the Governance Gap
Most organisations have a coherent governance story. They reference the right frameworks and are aware of the right risks. However, the challenge is deployment is often moving faster than governance. Agents are launched in environments where governance frameworks have not yet fully mapped out strict boundaries, with access security systems are unequipped to monitor. At the same time, new AI vendors are being introduced faster than procurement processes can evaluate them.
Whilst this is not an argument to slow the introduction of such agentic systems, we recommend focusing on the key four values, V.A.L.T., enterprises can adopt to ensure the safe and secure deployment of AI systems:
- Vigilant oversight — Define the collaborative roles between human and agent, spelling out where human approval is required and where agents can operate independently.
- Auditability — Every agent action should be traceable and explainable. Maintain access to records of any actions by agents with fully accountable reasoning for how decisions were made, facilitating reviews and audits.
- Least privilege controls — Give agents clear and strict permissions they need. Manage identities, control access and implement the ability to revoke permissions at any time.
- Transparency — Maintain visibility into the models and providers behind your AI systems. Understand their capabilities and limitations, and ensure vendors are accountable for changes and material incidents.
The Mythos saga will fade from the headlines, and access has already been restored. What shouldn’t fade is what it revealed. The model layer is volatile, subject to breaches, jailbreak reports, export directives and political weather no enterprise can predict or influence. The governance layer doesn’t have to be. Organisations with their own control plane can absorb the next shock as an inconvenience rather than a crisis.
