Connect with us

MICROSOFT 365

Nadella’s Fable Critique Traces to the July 1 Safeguards

Satya Nadella told Copilot engineers Fable 5 feels editorially controlled, two weeks after Anthropic widened the safety margin that brought the model back.

Published

on

Satya Nadella told Copilot engineers on July 15 that Anthropic’s Fable 5 refuses “any random thing” and feels editorially controlled. A copy of his remarks circulated after the meeting, and Microsoft declined to comment.

The complaint landed two weeks after Fable returned from a U.S. export-control freeze with a wider safety margin, the same margin now sitting inside Copilot Cowork.

Nadella Told Copilot Engineers the Refusals Do Not Make Sense

The Microsoft CEO was in a working session with the Copilot team, not on a stage. He treated Fable the way a product chief treats a tool that keeps saying no in the middle of a job.

If you use Fable, when it refuses for any random thing, it just is like, when was the last time you had a creation tool that was so editorially controlled? It doesn’t make sense.

Satya Nadella, CEO, internal Copilot engineering meeting

Anthropic did not immediately respond. Users had already posted examples of ordinary research and coding prompts falling over to an older Claude model, and a support page says questions about some parts of large-scale model building can be handed to that earlier version.

Nadella has used another internal meeting with staff to draw a hard line on product values. This one was about a partner model his own Copilot group has to ship on.

He went past the refusals. “It can’t be that there are only two companies in the world with token capital, and everybody else is renting it,” he told the engineers. “It makes no economic sense.”

The Safety Margin Got Wider on July 1

Fable 5 is the public, guarded face of Mythos 5, the same underlying model with extra screens on cyber, biology, chemistry, and distillation. When those screens fire, the user is told and the turn goes to Claude Opus 4.8 instead of a blank refusal.

Anthropic said at launch that it had tuned those screens on purpose to be cautious, and that they would trip, on average, in less than 5% of sessions. More than 95% of Fable sessions, on that early data, never fell back at all. The lab also said it would work to cut false positives after ship.

Three days later the model was gone. The U.S. government applied export controls on June 12, after Amazon researchers showed a prompt pattern that got Fable to name software bugs and, in one case, write exploit-style code. The letter arrived at 5:21 p.m. ET and covered foreign nationals, including Anthropic staff. With no way to check nationality in real time, Anthropic took Fable 5 and Mythos 5 down for everyone.

FROM LAUNCH TO THE COPILOT MEETING

  1. June 9, 2026: Anthropic launches Claude Fable 5 for general use, with Mythos 5 limited to trusted Glasswing partners.
  2. June 12, 2026: Export controls land at 5:21 p.m. ET; both models go dark for all users.
  3. June 26, 2026: Mythos 5 returns for a set of U.S. organizations after government approval.
  4. June 30, 2026: Commerce lifts the controls after new safeguards and extra government testing.
  5. July 1, 2026: Fable 5 returns worldwide, with a new classifier and a wider safety margin.
  6. July 15, 2026: Nadella tells Copilot engineers the refusals feel editorially controlled.

The restore was not a clean rewind. Anthropic trained a new classifier aimed at the Amazon technique, said it blocks that pattern in over 99% of cases, and warned that the change also meant flagging benign requests more often in everyday coding and debugging. For Fable 5, the lab had already made the safety margin larger than in any earlier launch, so a prompt had to look very clearly safe to pass. Researchers at the Commerce Department’s Center for AI Standards and Innovation tested the old and new screens and called them extraordinarily strong.

Through July 7, Pro, Max, Team, and some Enterprise plans got Fable at up to 50% of weekly limits. Cloud access on Azure’s Microsoft Foundry, plus AWS and Google Cloud, was promised “as quickly as possible.” Anthropic also said it was drafting a shared jailbreak-scoring method with Amazon, Microsoft, Google, and other Glasswing partners, the same Microsoft whose CEO would, two weeks later, call the refusals a bad fit for a creation tool.

Copilot Cowork Still Runs on Anthropic Models

That is the bind for the people in the room. Copilot Cowork, Microsoft’s long-running work agent, went generally available on June 16, while Fable was still offline. Charles Lamanna, executive vice president for Copilot, agents, and platform, wrote that more than half of the Fortune 500 was already using it after three months in Frontier, including Accenture, Capital Group, Koch, and Zurich Insurance.

At that launch, Cowork ran on Anthropic models, including Opus 4.8 and Sonnet 4.6. GPT-5.5 sat in Frontier, with a Microsoft-tuned Cowork 1 model promised later. Microsoft’s own tests, 125 runs across 12 light, medium, and heavy prompts, both on Opus 4.8, put Copilot Cowork 30-40% cheaper per prompt than Claude Cowork with a Microsoft 365 connector.

WHAT COPILOT COWORK WAS SHIPPING ON

  • Runtime: Cloud-hosted, inside the Microsoft 365 trust boundary, with Work IQ grounding and admin spend caps.
  • June models: Anthropic Opus 4.8 and Sonnet 4.6 at general availability, GPT-5.5 in Frontier, Fable 5 later as an opt-in preview.
  • Default posture: Cowork off until an admin turns it on; users billed in Copilot Credits for model use, retrieval, tool calls, and runtime.
  • The Fable problem: The same lab that supplies those models also supplies the classifier that can silently drop a hard turn onto Opus 4.8.

A Copilot engineer cannot fix that screen. It lives on Anthropic’s side of the request. Microsoft has bundled Copilot into small-business plans to push seats, and Cowork is the feature it now sells as work that actually finishes. A model that reroutes the ambitious prompts is a quality bug on that pitch, even if the lab’s safety team is doing what Commerce asked.

Why Token Capital Keeps Coming Up

The refusal rant sits on a thesis Nadella had already posted in public. On June 14 he argued that firms have to own “token capital,” the AI capability they build, not only rent a frontier lab’s weights. Human capital, in that post, is judgment and pattern recognition; token capital is the loop a company trains on its own work.

https://x.com/satyanadella/status/2066182223213293753

In the Copilot meeting he compressed that essay into a jab at an industry with two landlords. Foundry, he noted in the same stretch of remarks, already lists more than 11,000 models, including Anthropic and OpenAI, and Microsoft had begun shipping its own MAI models for text, voice, and image. The subtext for Copilot is ugly in a useful way: if Fable keeps dropping work on the floor, the team should route around it rather than wait for Anthropic to retune the door.

That is also why the “train your own frontier model” objection has force. Microsoft can dislike renting token capital and still be the company that has not put a same-class in-house model in Cowork’s default path. Until Cowork 1, or MAI, actually takes the hard jobs, Nadella is complaining about a landlord he still pays.

The $5 Billion Check Still Clears

This was not a breakup note. In November 2025 Microsoft committed $5 billion to Anthropic, and Anthropic pledged $30 billion of Azure spend. Nadella said at the time that the firms would be customers of each other, use each other’s models and infrastructure, and go to market together, with OpenAI still a critical partner.

THE CASH AND THE PRODUCT TIE

Item Figure When
Microsoft investment in Anthropic $5 billion November 2025
Anthropic Azure spend pledge $30 billion November 2025
Fable 5 input price $10 per million tokens June 9, 2026
Fable 5 output price $50 per million tokens June 9, 2026

Copilot Cowork is the visible product of that loop. Claude models sit in Copilot Chat beside OpenAI’s. Fable 5, when it is on, is the expensive, long-horizon option at $10 per million input tokens and $50 per million output, less than half the old Mythos Preview price. Microsoft shares fell 2% in early trading on Friday, July 17, after the remarks spread.

The money explains the tone. You do not spend a meeting calling a random vendor editorially controlled. You do it when the model is inside your own agent, your cloud is on the hook for $30 billion of that lab’s training, and your engineers are the ones catching the fallbacks.

Biology Fallbacks Fell After the Meeting

Anthropic did not leave the margin where July 1 put it. In an August update the company said it had rewritten the biology classifier’s rules and, in testing, cut those fallbacks by about 85% across product surfaces, while still sending dual-use biology and chemistry questions to Opus. Microsoft’s Cowork model list now puts Fable 5.1 in the model selector as the advanced choice for ambitious work, replacing Fable 5.

That patchwork is the honest sequel to Nadella’s rant. The refusals he hated were not a vibe. They were a government-shaped screen, widened on July 1 so Fable could be sold at all, then narrowed again where users yelled loudest. Copilot still has to live with whatever Anthropic’s door does on a given week, because Cowork’s heavy path still runs through that lab.

Fable 5.1 can sit in the picker, and the $30 billion Azure pledge can still be current, and a Copilot session can still drop a coding turn onto Opus 4.8 when the classifier flinches. That is the product Nadella told his engineers does not make sense, and it is the one they are still wiring into Microsoft 365.

Harry edits WinAddons, an independent news site that he owns and runs, covering Windows, Xbox, Azure, Microsoft 365, Teams, OneDrive, Outlook, the software built around them and Microsoft's business. His method comes from ten years in journalism, a reporter's years followed by an editor's, and the bulk of that decade has been spent watching Microsoft ship. His reporting starts with what Microsoft publishes: release notes and KB articles read in full, build numbers checked on an installed machine, MSRC advisories and the CVE records behind them, the Azure status history, lifecycle pages, store listings in the market they apply to, and the earnings releases and filings that carry the company's numbers. Every figure is checked against its source before publication, and a public corrections policy explains how mistakes are fixed and labelled. On security stories he does not publish exploit details before a fix is available, reporting what is affected and what to do instead. Pre-release features are labelled by channel and build, and a rumour is called a rumour. Readers can reach Harry at support@winaddons.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending