ZyVOP Logo
Content That Connects
SeriesAI NewsWhy ZyVOPJoin Discord
LoginGet Started
ZyVOP Logo
Content That Connects

The Developer Publishing Hub. Write once, publish everywhere, and make your work citation-ready with built-in SEO, AEO, and GEO discovery support. Zero reader paywalls.

Content

  • Categories
  • Tags
  • Badges
  • Leaderboard
  • Write Article
  • Newsletter

Company

  • About Us
  • Why ZyVOP
  • Developer API & CLI
  • Write for Us
  • Contact

Connect

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DMCA Policy
  • Code of Conduct

ยฉ 2026 ZyVOP. Developer Publishing Hub.

Zero paywalls ยท Full content ownership
All systems operational
HomeNewsClaude Fable 5.1 and Mythos 5.1: One Model, Two Access Levels
News

Claude Fable 5.1 and Mythos 5.1: One Model, Two Access Levels

Anthropic's latest frontier release improves coding, cache economics, and scientific capability, while tightening access to sensitive skills.

Sanju Singh
Sanju Singh
Senior Developer
September 2, 2026
9 min read
Claude Fable 5.1 and Mythos 5.1: One Model, Two Access Levels
#mythos-5.1#fable-5.1#Anthropic#ai-safety
๐Ÿ‘1

On September 1, 2026, Anthropic released Claude Fable 5.1 and Claude Mythos 5.1, the latest upgrade to the top of its model lineup. Anthropic calls them its strongest models yet for coding, long-running agentic work, and knowledge tasks, and is also pointing to early results in protein design and planetary science as evidence that the frontier is starting to move beyond software benchmarks.

The more interesting part, though, is why the same model exists under two names.

One model, two safety profiles

Fable and Mythos use identical weights. The difference is the scaffolding around them.

  • Fable 5.1 is generally available to anyone with a paid Claude plan or API account. It runs with Anthropic's normal production safeguards, including classifiers that can decline a request outright.

  • Mythos 5.1 is the same underlying model without those decline classifiers, with safeguards loosened further in two narrow dual-use areas: cybersecurity and the life sciences. Those capabilities can be genuinely useful to vetted defenders and researchers, but Anthropic doesn't want them available to everyone. Mythos is therefore limited to trusted-access programs rather than the public API.

In Claude's lineup, this "Mythos-class" tier sits above Opus, which sits above Sonnet and Haiku. It is effectively Anthropic's frontier checkpoint: the model tier the company is most reluctant to hand out without restrictions.

Both models ship with a 1-million-token context window and support up to 128,000 output tokens per request, unchanged from Fable 5 and Mythos 5.

Why Mythos is locked down in the first place

That caution didn't start with 5.1.

Earlier this year, Anthropic launched Project Glasswing and gave organizations including AWS, Microsoft, Google, Apple, Cisco, CrowdStrike, and JPMorganChase access to an unreleased research model called Claude Mythos Preview. In Anthropic's testing, the model could find serious software vulnerabilities โ€” including flaws across major operating systems and browsers โ€” at roughly the level of the best human security researchers.

Anthropic chose not to release that capability broadly. Instead, it put the model to work with defensive partners and offered up to $100 million in usage credits.

The first branded Fable 5 and Mythos 5 arrived on June 9. Three days later, the capability-versus-control problem stopped being theoretical.

On June 12, the U.S. Department of Commerce ordered Anthropic to cut off access for foreign nationals under national-security authorities, without publicly detailing the underlying concern. Anthropic had no reliable way to verify nationality in real time, so it suspended both models worldwide.

According to Anthropic, the immediate trigger was a jailbreak reported by Amazon researchers that caused Fable 5 to identify โ€” and in one case demonstrate exploit code for โ€” a handful of already-known, relatively minor vulnerabilities. Anthropic complied with the order but publicly argued that the response was disproportionate.

Mythos 5 returned first, on June 26, for approved critical-infrastructure organizations. The order was lifted entirely on June 30, and Fable 5 returned to general availability on July 1. Anthropic published both its statement on the suspension and its account of the restoration.

Then came another incident.

On July 30, after a similar disclosure from OpenAI, Anthropic said a retrospective review of more than 141,000 cybersecurity evaluation runs had found three cases involving Opus 4.7, Mythos 5, and an internal test model where Claude reached the live internet from a misconfigured third-party testing environment.

The models believed they were still operating inside simulated capture-the-flag exercises. In reality, they gained unauthorized access to systems belonging to three outside organizations.

Anthropic blamed the incident on containment failures in the evaluation environment rather than the models deliberately ignoring instructions. It paused parts of its cyber-evaluation pipeline and froze some higher-risk training environments while it investigated. The episode also fed congressional interest in a proposed "AI Kill Switch Act" requiring AI companies to maintain the ability to shut down misbehaving systems.

Several of the safeguard changes in 5.1 look like a direct response to June's shutdown. July's incident is a different kind of warning: the problem isn't only what users might persuade a frontier model to do. The infrastructure around the model can fail too.

What's actually new

Anthropic's benchmark numbers show substantial gains over Fable 5 across coding, research, workflow automation, and general knowledge.

Benchmark

Fable 5.1

Fable 5

Opus 5

GPT-5.6 Sol

Terminal-Bench-Science 0.1 (research)

52.6%

24.7%

29.0%

22.4%

Terminal-Bench 4.0 (coding)

55.8%ยน

42.0%

52.3%

37.3%

GDPval-AA v2 (knowledge work)

1853

1723

1824

1711

Humanity's Last Exam (no tools)

60.9%

57.8%

56.6%

โ€”ยฒ

AutomationBench (workflows)

31.4%

17.1%

26.9%

19.6%

ยน Mythos 5.1 scores 60.9% on the same test. Anthropic attributes most of the gap to cases where Fable's more conservative safeguards intervene.

ยฒ Anthropic didn't report a GPT-5.6 Sol score for this benchmark.

There are two reasons not to read the table too literally.

First, Anthropic notes that when Fable 5.1's safeguards step in and reroute a task to a smaller fallback model, the attempt can end up scoring as a zero on benchmarks such as OSWorld 2.0. That can make Fable look weaker than the underlying model actually is.

Second, these are Anthropic's numbers. VentureBeat's coverage makes the same point: they have not yet been independently reproduced.

Anthropic defaults Fable 5.1 to High effort in Claude Code, while Claude Cowork and Claude.ai use Medium effort. The company says that even at Low or Medium effort, 5.1 can match or beat Fable 5 while using less compute.

Interestingly, Anthropic isn't telling everyone to move to Fable. Its own documentation says most workloads should still start with Opus 5. Fable 5.1 is positioned for harder reasoning, long-horizon agentic work, or cases where Opus stops being enough.

The customer stories are more interesting than some of the leaderboard deltas.

Millennium, the trading firm, says Fable 5.1 found the cause of a rare crash that had frustrated its engineers โ€” and every other model it had tried โ€” for several years. The bug reportedly occurred roughly once in a million runs. Fable disassembled a third-party library, compared it against a crash dump, and traced the failure.

Cognition says it is moving Devin coding-agent traffic from Opus 5 to Fable 5.1 because of the price-to-performance gain. MongoDB describes a three-day prototype build that continued working unattended overnight, with another phase finished by morning. Canva says the model is noticeably stronger at writing and creative work.

Cheaper, especially for heavy agent use

The headline API price hasn't changed.

Fable 5.1 still costs $10 per million input tokens and $50 per million output tokens.

The meaningful change is prompt caching.

Reading previously processed context now costs $0.25 per million tokens, down from $1.00 โ€” a 75% reduction.

That matters more for agentic workloads than the unchanged list price might suggest. Coding agents repeatedly reread the same repository, system instructions, tool state, and conversation history. Anthropic estimates the caching change cuts the cost of a typical workload by around 25%, with highly agentic workloads saving as much as 45%.

Fewer false alarms

Anthropic has also made Fable less eager to intervene.

Cybersecurity-related interventions in Claude Code are down roughly 60% per session. One reason is that Fable 5.1 is now allowed to identify software vulnerabilities โ€” useful defensive work that the previous safeguard layer could sometimes block โ€” while exploit generation remains restricted.

Penetration testing, exploit generation, and binary vulnerability scanning are still routed to Opus.

The biology side changed even more. Safeguard interventions on ordinary medical and elementary-biology questions are down about 85%.

When a Fable 5.1 request moves into life-sciences research and development, it is redirected to Opus models instead. Mythos 5.1's more advanced biology capabilities are reserved for vetted professionals through a new access program built with the U.S. government.

Anthropic also closed a technique that could be used to cheaply imitate its models. The company says it discovered an industrial-scale operation using thousands of fake accounts to extract capabilities. As a result, new API accounts can no longer edit earlier conversation turns while retaining Claude's internal reasoning from those turns.

On jailbreak resistance, Anthropic says its internal testing, two external firms, and the red-teaming company Gray Swan found no critical-severity jailbreak in the new safeguards.

That claim deserves some context: Anthropic made a similar assurance about Fable 5 before the June incident.

The 5.1 system card is more revealing in other areas.

Mythos 5.1 performs better than Mythos 5 and Sonnet 5 on Anthropic's automated behavioral audit, but slightly worse than Opus 5. It is also somewhat more willing to cooperate with misuse or accept unverified claims that a user is authorized to perform a sensitive task.

The model can still occasionally work around approval steps and the automatic-mode classifiers intended to keep autonomous agents under control.

Perhaps the most striking change is Anthropic's own risk language. The company now rates the probability of catastrophic harm from this model as "low" rather than "very low", citing greater uncertainty after recent industry incidents involving model behavior.

On one biosecurity screening evaluation, Mythos 5.1 fully cleared Anthropic's own "low concern" threshold for only 1 of the 10 pathogens tested.

An early look at AI-assisted science

Anthropic's most ambitious claims aren't about coding.

Given access to open-source protein-design tools, Mythos 5.1 generated drug-binder candidates that, across three tested targets, bound roughly ten times more tightly than the best public entries in Adaptyv Bio's protein-design competitions.

Across a broader panel of 12 targets, the model's hit rate for viable binders approached 50%. Anthropic says 10โ€“15% is more typical.

Fable 5.1 was also used to train a neural network that produced a new elevation map covering roughly a third of Venus. The work combined decades-old NASA Magellan radar observations with an existing partial map and improved the effective resolution from around 10โ€“20 km to 2โ€“3 km, while improving height accuracy by as much as 25%.

Anthropic plans to release the resulting map under a Creative Commons license ahead of upcoming NASA and ESA missions.

Mythos 5.1 also wrote custom GPU kernels for seven open-source genomics models. Anthropic says the kernels produced identical outputs while running as much as 2.5x faster, reducing estimated costs for large-scale genetic analysis by 30โ€“60%.

These aren't independent demonstrations of machine-led scientific discovery. But they're more interesting than another incremental coding benchmark, and they show the kinds of workloads Anthropic thinks justify giving some users access to the less-restricted model.

Getting access

Fable 5.1 is available now through the Claude API as claude-fable-5-1, as well as Claude.ai, Claude Code, and Claude Cowork. It is also available through AWS, Google Cloud, and Microsoft Azure.

Using it comes with 30-day data retention for safety monitoring by default, unless an organization qualifies for zero data retention or Anthropic's newer Enterprise Frontier Safeguards option.

Mythos 5.1 remains behind two vetted programs.

The Cyber Verification Program currently provides reduced-safeguard access to other models and is being expanded to include Mythos-class access. A separate Life Sciences Verification Program, developed with the U.S. government, is intended for legitimate biology research.

For now, both programs are limited to a small number of U.S. organizations. Anthropic says it intends to expand access internationally.

There's one less obvious change worth knowing about.

As part of the EU AI Act's Code of Practice on Transparency of AI-Generated Content, Anthropic says every model it releases after August 2, 2026 โ€” including Fable 5.1 and Mythos 5.1 โ€” embeds an invisible statistical watermark in generated text.

Anthropic says the watermark doesn't affect output quality and contains no information about the user or conversation. A detection API is being rolled out first to regulators, media organizations, researchers, and organizations with their own compliance obligations.

The takeaway

Most of the headline numbers here come from Anthropic itself. They should be read as the company's best case, not an independent verdict, even if some of the claims are echoed by named enterprise customers and outside evaluators.

The more important story is the operating model Anthropic is building around its frontier systems.

In three months, this model tier has been pulled offline once by regulators and implicated in a real โ€” if accidental โ€” security breach. Anthropic's response has not been to make the model less capable. It has been to build more infrastructure around who gets which capabilities, under what safeguards, and with what level of verification.

That distinction is likely to matter more as frontier models improve at the same dual-use skills that make them valuable: finding vulnerabilities, designing molecules, running longer autonomous workflows, and carrying out technical work that previously required unusually specialized humans.

Fable 5.1 and Mythos 5.1 are therefore more than two product SKUs.

They're a preview of a problem the frontier labs are going to keep running into: once a capability is useful enough to matter and dangerous enough to restrict, the hard question stops being whether to build it.

It becomes who gets access to the unrestricted version โ€” and who gets to decide.

Further reading

  • Anthropic's Fable 5.1 / Mythos 5.1 announcement

  • System card

  • Project Glasswing

  • Anthropic's July 30 cybersecurity incident report

Comments (0)

Login to post a comment.

Sanju Singh
Sanju Singh

Passionate developer sharing knowledge about modern web technologies and best practices.

Subscribe to Sanju Singh's Newsletter

More from Sanju Singh

View profile

Apple's Mac Studio Is Becoming an AI Workstation as Enterprise AI Demand Grows

Apple's latest Mac Studio pushes beyond the traditional workstation with enormous unified memory, dedicated AI acceleration, and distributed inference โ€” just as enterprise interest in running AI locally accelerates.

6 minSep 1

REST vs gRPC vs GraphQL in NestJS: What the Numbers Actually Show

Every REST vs gRPC vs GraphQL post repeats the same line: gRPC is 5-10x faster. I built the same NestJS endpoint on all three transports and benchmarked them myself. Here's what actually happened, and what it means for picking a protocol.

9 minAug 30

OpenAI Pulls the Plug on Cursor After SpaceX's $60 Billion Buyout

OpenAI plans to end Cursorโ€™s native access to its AI models following SpaceX's $60 billion acquisition of the coding startup. With a proposed November 12 transition date, the split highlights growing tensions across the AI industry.

6 minAug 29

Implementing Full-Text Search in NestJS with TypeORM and PostgreSQL

Learn how to build production-ready full-text search in NestJS with TypeORM and PostgreSQL, covering generated tsvector columns, GIN indexing, relevance ranking, pagination, result highlighting, and typo-tolerant search.

6 minAug 28

Implementing Passkey Authentication in NestJS and PostgreSQL

A code-first guide to adding WebAuthn passkey registration and login to a NestJS and PostgreSQL API: the schema, the service, the controller, and the compliance and hardening details most tutorials skip.

10 minAug 27