Anthropic has revealed that it has developed an unreleased artificial intelligence model that is more capable than Claude Mythos 5 on an important internal evaluation. The company disclosed the existence of the system, referred to as Model 2, in its latest AI risk report, but said it currently has no plans to release the model publicly. The disclosure provides a rare look at an AI system that has already moved beyond one of Anthropic’s most advanced publicly known models.

 

The comparison is particularly interesting because Claude Mythos 5 is already positioned by Anthropic as its most capable model for cybersecurity and biology research. Mythos 5 is not generally available to everyone; access is restricted to a small group of vetted partners because of the model’s advanced capabilities and the potential for those capabilities to be misused. Anthropic says Mythos 5 represents a significant capability frontier in areas including cybersecurity, scientific research and complex knowledge work.

 

According to the newly reported results, Model 2 scored 62.8% on the CoBench evaluation, compared with 50.3% for Claude Mythos 5. That difference is significant on this particular test, but it does not mean Model 2 is automatically better than Mythos 5 at every task. AI benchmark results measure specific capabilities, so the result is better understood as evidence that Model 2 has surpassed Mythos 5 in at least one area of advanced AI research.

 

The decision not to release Model 2 is what makes the announcement especially interesting. AI companies frequently develop internal versions of models before launching public products, but Anthropic's decision comes at a time when the company is becoming increasingly concerned about the risks associated with more capable AI systems. Its latest risk report changed its assessment of catastrophic harm from misalignment in high-stakes settings from “very low” to “low,” while still describing the overall probability as low.

 

This does not mean Anthropic believes Model 2 is uncontrollable or that it represents some form of superintelligence. The available information does not support either conclusion. What the announcement does show is that Anthropic is reaching a point where simply making an AI model more capable is no longer enough; the company also has to understand what the system can do, how it could be misused and whether its existing safeguards are strong enough.

 

That concern is particularly relevant to cybersecurity. Anthropic says Claude Mythos 5 has capabilities that can help security researchers discover vulnerabilities and protect important software, but the same capabilities could potentially be used by attackers. The company has therefore limited access to Mythos 5, rather than making the unrestricted system available to everyone.

 

Model 2 could eventually make that problem even more complicated if its stronger performance extends to areas such as cybersecurity, automated research or advanced programming. A more capable AI can be extremely valuable when placed in the hands of researchers and developers, but greater capability can also increase the consequences of mistakes or deliberate misuse. That is one reason frontier AI companies are increasingly evaluating models before deciding how widely they should be deployed.

 

There is also a bigger reason to pay attention to Model 2: AI could increasingly be used to develop better AI. As models become stronger at programming, research, analysis and experimentation, they can assist human researchers with some of the work involved in creating future systems. If that capability continues improving, an AI model could eventually contribute to the development of the next generation rather than simply being the final product humans build.

 

Anthropic is already treating automated AI research and development as an important area to monitor. Its safety framework considers how increasingly capable systems could affect the speed of AI development, which means a model that can meaningfully assist researchers with building better AI could become more important than a model that simply performs better on ordinary chatbot tasks.

 

For ordinary Claude users, however, Model 2 does not mean that a new Claude model is arriving tomorrow. Anthropic has not announced that Model 2 will become the next public Claude product, and there is no confirmation that the company intends to release it under that name. It is better to view Model 2 as evidence of what Anthropic is experimenting with internally rather than as a confirmed future product.

 

The situation also reveals something important about the AI race that users rarely see. People normally judge companies by the models they can access through an app or API, but those public models may not always represent the strongest systems being developed inside the laboratories. Companies can keep more capable systems private while they test their abilities, improve safeguards and decide whether releasing them would be responsible.

 

That could become increasingly common as AI models become more powerful. Instead of immediately releasing every new frontier system, companies may develop several internal versions, evaluate them against difficult capability and safety tests, and only release the versions they believe can be deployed safely. The strongest model inside an AI laboratory could therefore remain unavailable to the public for months or even longer.

 

Claude Mythos 5 itself demonstrates why this distinction matters. Anthropic says Mythos 5 and Fable 5 share the same underlying model, but Fable 5 includes additional safeguards that make it suitable for broader use, while Mythos 5 is provided through restricted trusted-access programs. Anthropic specifically says the unrestricted capabilities of Mythos 5 in cybersecurity and biology can carry risks if made widely available.

 

That means the question surrounding Model 2 is not simply whether it is “better” than Claude Mythos 5. The more important question is what Model 2 can do that makes Anthropic unwilling to release it yet. The company has not publicly provided enough information to answer that completely, but the decision itself suggests that capability, safety and deployment are becoming increasingly connected.

 

The development could also affect expectations for the next generation of Claude. If Anthropic continues improving its internal models, a future public Claude system could eventually inherit some of the capabilities being tested in Model 2. Whether that happens through a completely new model or through improvements to the existing Claude family remains unknown, but the existence of a stronger internal system suggests that Anthropic's development has already moved beyond what users can currently access.

 

For now, Model 2 should not be treated as a secret superintelligent AI or an imminent Claude replacement. What can be said with confidence is much more interesting: Anthropic has acknowledged an internal model that outperforms Claude Mythos 5 on a notable evaluation, yet the company has decided not to release it.

 

That decision could become increasingly normal as the AI industry enters a more cautious stage of development. The competition is no longer only about who can build the smartest model first. Companies also have to determine whether they understand their systems well enough to release them, whether the safeguards work and whether the benefits of greater capability outweigh the risks.

 

Model 2 may therefore be important not because people can use it today, but because it gives us a glimpse of what is happening behind the public AI frontier. The next major Claude breakthrough could already be under development inside Anthropic, waiting for the company to decide that the technology is ready for the world.