Fable 5: как Anthropic переписала биозащиту Claude
Anthropic обновила биологические фильтры Claude Fable 5: на 85% меньше ложных блокировок при сохранении защиты от dual-use угроз. Разбираем, как это работает.
Fable 5: как Anthropic переписала биозащиту Claude и сократила блокировки на 85%
7 августа 2026 года Anthropic тихо выпустила обновление, которое изменит то, как миллионы людей пользуются Claude в медицине и биологии. Никакой новой модели, никаких громких анонсов — просто переписанный классификатор. Но за этим техническим изменением стоит один из самых сложных этических балансировочных актов в истории AI-индустрии: как дать врачам, студентам и исследователям то, что им нужно, не открывая дверь тем, кто хочет создать биооружие.
Разбираемся, что именно изменилось, почему это важно и каков контекст этого решения.
Что такое «fallback» и почему он раздражал пользователей
Fable 5 users were experiencing many «fallbacks» — situations where the system switched to a less capable model after a biology-related query. По-русски: вы задавали вопрос про анализ крови или симптомы болезни — и система автоматически переключала вас с мощного Fable 5 на менее способный Opus 5.
Fable 5 previously used broad safety classifiers that could redirect benign biology questions to Opus 5, which Anthropic describes as less capable in the field. Это создавало парадоксальную ситуацию: именно там, где Claude мог помочь лучше всего — в медицине и биологии — пользователи получали более слабые ответы.
The launch configuration deliberately erred wide: the company acknowledged it would block a high volume of false positives in exchange for getting Fable 5 to general users weeks or months earlier than a narrower safeguard would have allowed.
Проблема была не в самой идее защиты, а в её калибровке. Первоначальный классификатор был намеренно широким: лучше заблокировать лишний безвредный вопрос, чем пропустить опасный. The cautious approach reflected concerns that advanced models could assist with biological research, carrying both beneficial and harmful applications.
Почему биология — особенно сложная область для AI-безопасности
Биология принципиально отличается от других областей знаний тем, что полезное и опасное в ней неразделимы на ранних стадиях.
The company has illustrated the genuine difficulty of the line with two examples: developing a live vaccine requires scientists to grow the same pathogen they aim to prevent; and captopril, a widely used hypertension medication, was originally derived from toxic components of snake venom.
Anthropic says bad actors exploit that ambiguity to dress dangerous requests as ordinary research, and points to the US intelligence community’s 2026 threat assessment on state bioweapon programmes.
Это явление называется dual-use — двойное использование. Знание, которое спасает жизни в одних руках, может их уничтожать в других. И именно здесь классическая AI-безопасность через запреты начинает давать сбои: запрет слишком широкий блокирует науку, запрет слишком узкий — не защищает от угроз.
«Биология — это область, где наибольший потенциал AI для позитивного влияния на мир, и мы значительно инвестируем в это направление» — Anthropic
Исторический контекст: by April 2025, OpenAI had reversed its own assessment, concluding its models were approaching «high risk» — meaning, capable of substantially increasing the likelihood and frequency of bioterrorist attacks. Similarly, Anthropic’s own internal bioweapons acquisition uplift trials published in May 2025 found that Claude Opus 4 enhanced human performance by 2.53× on relevant tasks, enough to trigger activation of AI Safety Level 3.
Как именно переписали классификатор: технический разбор
Over the past several weeks, Anthropic rewrote the biology classifier’s constitution — the collection of rules the screening model uses to distinguish safeguarded from allowed content — carving out benign uses in more detail, soliciting feedback from internal and external experts, retraining the classifier on updated data, and verifying it still triggers on harmful and dual-use research content.
Процесс состоял из нескольких чётких этапов:
graph TD
A[Анализ ложных срабатываний\nпри запуске Fable 5] --> B[Переписывание constitution\nклассификатора]
B --> C[Сбор экспертной обратной связи\nвнутренние + внешние эксперты]
C --> D[Генерация новых тренировочных данных]
D --> E[Переобучение классификатора]
E --> F[Верификация: проверка\nна harmful и dual-use контент]
F --> G[Релиз обновления\n7 августа 2026]
Over the past several weeks, Anthropic carefully rewrote the classifier’s constitution, taking care to carve out benign uses in detail. They solicited feedback on the changes from a diverse range of experts (both internal and external to Anthropic), then developed updated training data for the classifier based on that constitution, retrained it, and verified the new classifier would still generally trigger for harmful and dual-use research biology content but would now enable a wider range of benign and beneficial uses.
Результаты: цифры и что изменилось для пользователей
In their testing, this update reduced biology-related fallbacks by about 85% across product surfaces. Это означает принципиально другой пользовательский опыт.
Кто получает выгоду прямо сейчас
In practice, users should see far fewer fallbacks on everyday health and educational questions — for example, interpreting lab results, understanding symptoms, and learning about biology in an educational context. Healthcare professionals will be able to receive more support from Fable 5 on clinical tasks.
Влияние на разные продукты Anthropic
The reduction in biology fallbacks is expected to bring down total fallback volume by roughly 67% on Claude.ai, 55% on Cowork, 17% on Claude Code, and 7% on the Claude Platform, according to a footnote in the post.
| Продукт | Снижение общего объёма fallbacks |
|---|---|
| Claude.ai | ~67% |
| Cowork | ~55% |
| Claude Code | ~17% |
| Claude Platform (API) | ~7% |
Что по-прежнему заблокировано
Despite the improvements, Fable 5 will continue to fall back to Opus 5 for dual-use domains such as virology, toxicology, and molecular design, meaning it remains unsuitable for professional biology research or drug development at the frontier.
At the same time, Anthropic said it continues restricting access to certain forms of dual-use biological research by limiting those capabilities to its more advanced Opus 5 model.
Теперь разрешено (Fable 5 отвечает напрямую):
- «Расшифруйте мой общий анализ крови: гемоглобин 110 г/л»
- «Какие симптомы характерны для тиреоидита Хашимото?»
- «Объясните механизм действия CRISPR-Cas9 для студентов»
- «Каков протокол подготовки к гастроскопии?»
По-прежнему идёт на Opus 5 (или отклоняется):
- Синтез конкретных патогенов
- Вопросы об усилении вирулентности
- Детальные протоколы работы с опасными агентами BSL-3/4
Архитектура многоуровневой безопасности: Fable 5 vs Opus 5
Обновление раскрывает важную деталь архитектуры Anthropic: компания строит многоуровневую систему доступа, а не единую модель с единым уровнем ограничений.
The distinction between Claude Fable 5 and Opus 5 reflects a broader trend in AI product design. AI companies are increasingly creating multiple model tiers with different capabilities, access levels, and safety controls. Smaller or general-purpose models may provide broad accessibility, while more advanced systems may include additional safeguards and restrictions. This approach allows companies to serve different user groups while managing risks associated with increasingly powerful models.
| Параметр | Claude Fable 5 | Opus 5 |
|---|---|---|
| Целевая аудитория | Широкий круг: студенты, врачи, пациенты | Верифицированные исследователи |
| Биология: базовые вопросы | ✅ Полный доступ | ✅ Полный доступ |
| Клинические задачи | ✅ После обновления | ✅ Всегда |
| Dual-use исследования | ❌ Fallback на Opus 5 | ⚠️ Ограниченный доступ |
| Вирусология / синтез патогенов | ❌ Заблокировано | ❌ Заблокировано |
| Frontier биология / разработка препаратов | ❌ | 🔒 Только verif. доступ |
Anthropic says it is developing trusted access pathways for frontier biology capabilities — a vetted, gated model for researchers who need the full power of Fable 5 without open-ended exposure. То есть в будущем появится третий уровень: верифицированный исследователь с подтверждённой идентификацией сможет получить доступ к полным возможностям модели.
Более широкий контекст: AI, биобезопасность и гонка с угрозами
Обновление вышло в символически значимый день. Anthropic updated its Fable 5 biology safeguards on August 7, the same day researchers from Stanford and the Arc Institute published a paper in Science demonstrating that their Evo 1 and Evo 2 models can design fully functional viral genomes.
Это совпадение — или точнее, синхронизация двух движущихся фронтов — наглядно показывает природу проблемы: пока одни компании строят защиту, научные возможности AI продолжают расти независимо.
U.S. policymakers face the challenge of strengthening biosecurity measures for an AI era while ensuring that biotechnology innovation can still flourish. AI-enabled biotechnology stands to improve billions of lives globally by accelerating vaccine discovery, improving healthcare diagnostics, and enhancing countless other fields. At the same time, the trajectory of AI’s biological capabilities points to a world in which evading existing safeguards could become increasingly straightforward.
While participants with Claude 4 models received higher scores and developed plans with fewer critical failures compared to internet-only groups, physical barriers and tacit knowledge remain significant obstacles to real-world success. This matters. AI lowered barriers but didn’t eliminate them. — это важное уточнение от исследователей RAND: AI снизил барьеры, но не устранил их полностью.
As The Next Web observed in its coverage: the company is moving the fence, not taking it down. That description captures the structural reality: the classifier’s update is a calibration decision, not a resolution.
Выводы: чему учит кейс Fable 5
История с биологическими фильтрами Claude Fable 5 — это не просто технический апдейт. Это иллюстрация того, как должна работать ответственная разработка AI в областях высокого риска.
Главные уроки:
Безопасность и полезность — не противоположности. By reducing false-positive restrictions while maintaining stronger controls for sensitive dual-use research, Anthropic is attempting to create a more balanced approach to AI-assisted biology. Это не компромисс, а инженерная задача точной калибровки.
Лучше выпустить с широкими ограничениями, чем задержать. Starting with a very broad biology classifier meant that the company could give users access to Fable 5 while continuing research aimed at refining it. The alternative — holding back the model until much more safeguards progress was made — would have delayed the model’s general access, and its potential benefits to users, by weeks or months.
Классификаторы нуждаются в постоянном пересмотре. Первоначальный «широкий» классификатор был осознанным техническим долгом, который Anthropic планировала погасить — и погасила через несколько недель.
Многоуровневый доступ — будущее AI-безопасности. Tiered access controls offer a path to minimize this trade-off by enabling differentiated access based on factors such as verified identity and demonstrably legitimate use cases. This approach mirrors established biosecurity frameworks: physical laboratories implement Biosafety Levels (BSL-1 through BSL-4) with increasingly stringent requirements.
Угрозы реальны и документируются. Anthropic не занимается театром безопасности — внутренние тесты показали конкретный прирост возможностей потенциального злоумышленника, и компания на это реагирует.
Для рядового пользователя Claude изменение выглядит незаметно: просто исчезли раздражающие переключения на более слабую модель при вопросе о симптомах. Но за этим незаметным изменением — недели экспертной работы, сотни часов тестирования и фундаментальный вопрос, который вся AI-индустрия решает прямо сейчас: как строить системы, которые максимально помогают людям, не давая злоумышленникам значимого преимущества.