The ledger remembers what the hype forgets. A rumor emerged from SemiAnalysis, an intelligence firm known for its granular reads of GPU supply chains and lab architectures: Anthropic has completed a model codenamed Mythos 2, but it remains unreleased. Worse, the rumor suggests this unreleased model is being used internally to train the next generation of AI. If true, this is not a simple delay. It is a structural shift in how frontier capability is accumulated, hidden, and deployed. I do not cover the story; I follow the code. And in this case, the code—or the absence of it—tells a story that the market is not ready to hear.
Context: The Apparent and the Hidden
Anthropic is the lab that built Claude, a series of models prized for their safety alignment and nuanced reasoning. The company operates under a self-imposed framework called the Anthropic Safety Level (ASL), which mandates rigorous evaluation before deployment. The public story is that models like Claude Opus 4.5 represent the current state of the art. But the rumor points to a different reality: a model named Mythos 2, allegedly stronger than anything publicly available, sits completed but locked away. And a separate model, Fable, is said to be the one that will eventually be released—heavily shackled with safety classifiers. The implication is that the strongest model is never seen by the public, while the public model is a filtered, weaker version.
This pattern is not new. In my experience auditing ICOs in 2018, I saw projects that claimed to have a revolutionary consensus algorithm but only released a stripped-down version to the market. The full capability was held back for internal use or for a later, more profitable release. The ledger remembers: the hype always precedes the truth. Here, the truth is that Anthropic may be operating a two-tier model system: an internal, unrestricted powerhouse and a public, sanitized interface.
Core: The Technical Feasibility of Hidden Evolution
Let me be clear: the technical mechanism described is not only plausible but already standard practice in frontier labs. The practice of using a stronger, unreleased model to generate synthetic data for training a smaller or next-generation model is called distillation. It is the same technique that allowed Alpaca to mimic GPT-3.5 using only a few hundred examples. The difference here is scale and intent. If Mythos 2 is used to generate preference data, chain-of-thought traces, or code verification outputs, and those outputs are fed into the training of the next model, then the capability of Mythos 2 leaks into the next generation without ever being exposed to the public. This creates a private evolution loop: the model improves itself behind closed doors, while the public sees only the downstream product.
From a technical perspective, this is a sound engineering strategy. The quality of synthetic data from a frontier model is significantly higher than what can be sampled from the public API. The internal model can be fine-tuned on specific tasks without the constraints of rate limits, content filters, or adversarial probing. The result is a training distribution that is cleaner, more aligned, and more capable—but also opaque. The code does not lie, but the absence of code leaves room for narrative.
The security implications are profound. If the internal model has flaws—biases, safety blind spots, or emergent behaviors—those flaws are inherited by the next generation through the distilled data. The safety filters applied to the public model (Fable) may catch some issues, but the internal model operates without those filters. The risk is that the private evolution loop amplifies hidden vulnerabilities, creating a system that is both more capable and less safe than the public one.
Contrarian: What the Bulls Got Right
Before I condemn the practice, I must acknowledge the counterargument. The rumored strategy is rational from a competitive and commercial standpoint. Anthropic is in a race against OpenAI and Google. If they have a stronger model, releasing it immediately would expose their hand and trigger a counter-response. By keeping it internal, they can use it to improve their product line (Claude Code, Claude for Enterprise) without revealing the full extent of their capability. The market rewards the visible, but the invisible can create a moat. The bulls are right to point out that this is a classic strategy of asymmetric advantage: show only enough to win, but keep the real firepower in reserve.
Furthermore, the delay may be justified by safety concerns. The ASL framework requires extensive red-teaming and evaluation before any model that could reach ASL-3 is released. If Mythos 2 is close to that threshold, the prudent move is to delay until safety mechanisms are proven. The public is served by a model that is safe, not by a model that is dangerously powerful. The bulls argue that this is responsibility, not deception.
But I have seen this movie before. In 2021, I investigated a DeFi protocol that claimed to have a governance mechanism that was fully decentralized. The code revealed that 5% of addresses controlled 60% of voting power. The protocol's own internal model of governance was hidden from the public. The surface was democratic; the reality was feudal. The same pattern applies here: a public model that is safe, and a hidden model that is the real source of power. The bulls mistake a delay for prudence, when it is actually a power play.
Takeaway: The Accountability Call
We traded value for visibility, and lost both. The crypto industry learned this lesson the hard way with ICOs, DeFi, and NFTs. The promise of transparency was always undermined by hidden ledgers, private keys, and off-chain governance. Now, the same dynamic is emerging in AI. A lab holds a model that is not just a product but a tool for creating the next generation. The public is left to consume the filtered output, while the internal loop runs unchecked.

What is needed is not a rumor mill, but verifiable proof. The code should be audited by independent third parties. The training data distributions should be disclosed. The safety classifiers should be open to inspection. The ledger remembers what the hype forgets: that trust is built on verification, not on press releases. If Anthropic wants to be the responsible actor it claims to be, it must either release the model for public evaluation or provide cryptographic proof that the internal model is not being used to train the next generation without oversight. The silence in the code is the loudest confession.

The hidden model is not a myth. It is an emerging reality. And the question is not whether it exists, but whether we are willing to accept it without proof.