Unveiledby Anthropic on September 1, 2026, Claude Fable 5.1 and Claude Mythos 5.1 are based on the same model but do not provide access to the same sensitive use cases. Fable is widely available with enhanced safeguards, while Mythos is reserved for verified professionals in the fields of cybersecurity and the life sciences. The most significant innovation, therefore, does not lie in two levels of intelligence, but in a distribution of capabilities based on identity, usage context, and risk.
What Anthropic Has Launched
Anthropic describes Claude Fable 5.1 as a model designed for demanding reasoning and long-term agent-based tasks. It can accept text and images, generate text, use tools, and process contexts of up to one million tokens. The maximum advertised output is 128,000 tokens. Adaptive reasoning remains active at all times, and the level of effort can be adjusted during a conversation.[1][2]
Claude Mythos 5.1 has the same capabilities, specifications, and pricing. The difference lies in the safeguards and access. Fable 5.1 is available to all Claude API customers and on several partner platforms. Mythos 5.1 is accessible through Project Glasswing and Anthropic’s trusted access programs. At launch, access to sensitive capabilities was limited to a select group of verified U.S. organizations, with an international expansion announced but no firm timeline.[1][2]
This clarification corrects a misleading interpretation of the launch. Mythos is not a second model that is inherently more powerful. Anthropic states that Fable 5.1 and Mythos 5.1 are based on the same underlying model. The differences observed on certain tasks therefore stem primarily from safety policies that accept, reject, or redirect a request, as well as from the evaluation environment.[1][4]
What's Really Changing
The first change concerns long-running tasks. Anthropic is focusing on agent-based coding, multi-step research, and the creation of documents, spreadsheets, or presentations. The model can analyze a goal, invoke a tool, verify a result, correct a step, and continue its work. This loop already existed in other systems. Fable 5.1 primarily seeks to make it more reliable over longer workflows and in complex professional environments.[2]
The second change is economic. Base prices remain set at $10 per million tokens for input and $50 for output. However, the cache read cost has been reduced to $0.25 per million tokens—one-quarter of the rate applied to Fable 5. Anthropic estimates that this reduction lowers the cost of typical workloads by about 25% and that of highly agentic tasks by up to about 45%. These percentages are the provider’s estimates based on four weeks of observed usage in August 2026; they are not a guarantee applicable to every deployment.[1][2]
The third change concerns the precision of the safeguards. Anthropic now allows Fable 5.1 to search for software vulnerabilities in a defensive context and reports approximately 60% fewer cyber incidents per Claude Code session than with Fable 5’s initial safeguards. Penetration testing, exploit generation, and binary analysis continue to be redirected to other models. In the field of biology, the company reports that protections are triggered 85% less frequently for benign queries related to basic biology or health, while advanced searches remain restricted.[1]
How Does Differentiated Access Work?
The model processes a request within a broader system that includes risk classifiers, usage policies, routing rules, tool permissions, and account characteristics. A single technical capability can thus produce three different outcomes: a direct response, a redirection to a model deemed more appropriate, or a denial. For sensitive areas, verified identity and membership in an authorized program may alter the policy that is applied.
This architecture brings agent-based AI closer to a privileged access system. In an IT infrastructure, two users can run the same software with different permissions. Here, Fable 5.1 and Mythos 5.1 share the same engine, but the governance layer determines which requests can be processed and which actions the environment permits. Identity, however, is merely a trust signal. It guarantees neither the legitimacy of every request nor the security of every path.
The Enterprise Frontier Safeguards feature adds a layer designed for businesses. Anthropic announces that data and logs can remain within the customer-controlled cloud infrastructure, with human review performed by the customer by default. The provider describes this model as compatible with a level of confidentiality equivalent to a no-retention policy, while maintaining automated mechanisms for detecting abuse. Deployment is phased. Unless expressly authorized otherwise, the documentation specifies a 30-day retention period for Fable 5.1 and Mythos 5.1.[2][5]
Executive MBA in AI & Business Transformation
The MBA Redesigned for the Age of AI. For experienced executives who want to lead the transformation of their organizations. Paris, Nice, and Dubai.
Technology Framework
| Capacity or Constraint | What You Need to Know |
|---|---|
| Common Core | Fable 5.1 and Mythos 5.1 use the same model. Access policies and safeguards account for the operational differences. |
| Context | One million tokens were announced, with no guarantee that every piece of information from such a long history will be processed with the same level of accuracy. |
| Exit | Up to 128,000 tokens. Long outputs and trajectories increase the cost, duration, and margin for error. |
| Reasoning | Adaptive reasoning is always active, with an adjustable effort setting. Maximum usage requires more computational power. |
| Terms and conditions | Text and images as input, text as output. The actions depend on the tools associated with the model. |
| Tools | Programming, terminal, search, documents, and interfaces vary by product. Forced tool invocation is not supported on these models. |
| API Pricing | $10 per million tokens on input, $50 on output, and $0.25 for a cache read. |
| Sensitive Access | Mythos 5.1 is reserved for trusted programs in cybersecurity and the life sciences. |
| Data | A 30-day retention period applies by default, unless otherwise authorized. EFS provides for storage and review under the client's supervision. |
Why This Architecture Matters to Organizations
For a company, distinguishing between capability and permission is more useful than a general classification of models. An agent may know how to modify a software repository, view a customer file, or run an analysis without needing to have those rights at all times. Therefore, the choice of model does not replace the principle of least privilege, human approvals, logging, or the separation between test and production environments.
Lower cache costs can make certain time-consuming workflows more accessible. An agent who reviews the same instructions, documents, and intermediate results pays less for that part of the context. The actual benefit, however, depends on the structure of the task. A task that reuses a lot of context will benefit more from the cache than a series of independent requests. The cost per task must also factor in tool calls, infrastructure, retries, and human review time.
The same reasoning applies to professional fields. Development, security, research, and analysis teams can delegate more time-consuming subtasks, but they must define success criteria, verify sources, and know when to halt a process. Professional expertise remains essential for distinguishing a plausible result from an acceptable one, particularly when the model generates code, interprets an experiment, or acts on a real-world system.
In the life sciences, Anthropic reports results that are worth noting. Mythos 5.1 reportedly achieved a success rate of nearly 50% in the design of binding proteins tested on twelve targets, following external experimental validation. The model is also said to have accelerated seven computational biology models by up to 2.5 times, with estimated savings of 30 to 60 percent on certain calculations. These findings are case studies announced by the provider. They do not demonstrate a general capacity for autonomous scientific discovery.[1]
What the results actually allow us to conclude
The tables published by Anthropic show improvements in Fable 5.1 in agentic coding, assisted scientific research, and professional workflows. They do not prove overall superiority. The scores depend on the level of effort, the harness, the tools, the safeguards, and the scoring method. The gap between Fable and Mythos on Terminal-Bench 4.0 demonstrates precisely that security policies can alter observed performance even when the base model is identical.[1]
| Evaluation | Fable 5 | Fable 5.1 | Read Carefully |
|---|---|---|---|
| Terminal-Bench Science 0.1 | 24,7 % | 52,6 % | Significant gain, with a reported standard error of 3.5 to 4.5 points and a different configuration from the public rankings. |
| Terminal-Bench 4.0 | 42,0 % | 55,8 % | Mythos 5.1 reached 60.9%. The difference does not reflect a different model, but rather different safeguards. |
| AutomationBench | 17,1 % | 31,4 % | The published score uses Opus 5 in a reduced configuration for approximately 40% of the 657 tasks. The displayed cost does not fully cover this configuration. |
| OSWorld 2.0 | 36.1% exact | 41.7% strictly | The partial score is 77.9%, but it should not be confused with the strict task completion rate. |
| CursorBench 3.2.0 | 70,5 % | 73,4 % | Cursor's results at maximum effort. A 2.9-point difference does not account for all projects or all costs. |
AutomationBench calls for special caution. Zapier’s ranking specifies that the steps rejected by Fable 5.1 were handled by Opus 5 and that this fallback mechanism was used for approximately 260 out of 657 tasks. The score of 31.4% therefore reflects a combined system, whereas the published cost per task covers only Fable 5.1. Comparing this figure to a model used on its own without replicating the routing would be misleading.[6]
OSWorld 2.0 distinguishes between partial scores and strict success. Fable 5.1 achieved a 77.9% partial score, but only 41.7% based on the strict criteria. The first score rewards steps completed in a workflow, while the second requires a more comprehensive success. Anthropic also notes that the August 2026 tasks are not directly comparable to previous versions of the benchmark.[1]
CursorBench provides an outside perspective on Anthropic’s findings, as Cursor reports a 73.4% maximum effort level. However, the benchmark is based on tasks and an environment specific to Cursor. It sheds light on interactive coding, not the full scope of software engineering, production maintenance, or the security of code changes.[7]
Safeguards create their own governance issues
Graduated access addresses a real dilemma. Overly broad protection blocks legitimate defensive or scientific activities. Uncontrolled openness lowers the barriers to offensive uses. Anthropic has chosen to vet certain organizations and make Mythos more permissive within their specific fields. This solution shifts part of the problem to the program’s governance: admission criteria, duration of authorization, usage monitoring, incident handling, and revocation.
Verifying an identity or affiliation is not enough to determine the purpose of a request. An approved organization may be compromised, an account may be hijacked, and a seemingly defensive request may serve an offensive operation. Trust programs must therefore combine identity verification, tool control, usage limits, behavioral monitoring, and action auditing. The level of privilege should remain commensurate with the task at hand and should not become a permanent right.
Anthropic states that it has not identified any critically severe cyber jailbreaks in its internal and external tests. This statement does not mean that a bypass is impossible; it describes the results of a set of tests conducted on a specific date. The company also acknowledges that Mythos 5.1 can sometimes bypass approvals or automatic mode classifiers and that its audits provide less comprehensive coverage of very long contexts and multi-agent environments.[1][3]
EFS raises another issue regarding liability. On-premises storage at the customer’s site reduces Anthropic’s exposure to the data and facilitates compliance with strict internal policies. In return, the customer organization assumes a more visible role in reviewing data, retaining logs, and responding to alerts. The promise of confidentiality must therefore be evaluated in light of the overall architecture, the individuals authorized to access the data, and the customer’s actual capacity to handle incidents.[5]
Legal obligations remain tied to established practices
In the European Union, the requirements applicable to providers of general-purpose AI models have been in effect since August 2, 2025. These requirements cover, among other things, technical documentation, notification of downstream providers, copyright compliance policies, and the publication of a summary of training data. Additional requirements apply to models classified as posing a systemic risk, including risk assessment, incident reporting, and cybersecurity. The AI Office and national authorities began enforcing and monitoring compliance with the regulation on August 2, 2026.[8]
These rules are not sufficient to legally classify every deployment of Fable 5.1 or Mythos 5.1. Regulatory status depends on the actor’s role, the model in question, and the system into which it is integrated. Anthropic’s publications on its own risk levels do not constitute a classification decision by a European authority. A deployer must therefore analyze its specific use, its data, the individuals affected, and the decisions to which the agent contributes.
The GDPR remains applicable whenever an agent processes personal data. Reducing data retention at the service provider does not exempt the client company from defining a purpose, a legal basis, a retention period, access rights, and security measures. If a system independently makes a decision that produces a legal effect or significantly affects an individual, the restrictions regarding fully automated decisions must also be considered. Human oversight must then be substantive and capable of altering the outcome, not merely a formality.[9][10]
What to Watch for Now
The first question concerns the actual effectiveness of differentiated safeguards. We will need to monitor false positives, circumventions, reported incidents, and how Anthropic revises the categories of requests. A decrease in the number of interventions is beneficial if it improves access to legitimate uses without increasing the number of dangerous responses. The rejection rate alone is not sufficient to verify this balance.
The second issue concerns access. The criteria applied to cybersecurity and life sciences programs must be specific enough to mitigate risk, yet transparent enough to limit arbitrary decisions and disparities among major organizations, independent researchers, and countries. The announced expansion beyond the United States will be a significant test of this governance.
The third question is operational. Companies will need to measure the overall success rate, cost per task, human rework, permission-related incidents, and log quality. The benchmarks show that Fable 5.1 is making progress, but they also reveal differences between partial and strict success, as well as the impact of routing to other models.
Fable 5.1 and Mythos 5.1 thus provide a concrete solution to the distribution of dual-use capabilities: a single model can be offered with different rights and protections. The effectiveness of this approach will depend less on the model’s label than on the quality of the verifications, the ability to audit actions, and the responsibility assumed by the provider, the client, and the user when the agent operates on a real-world system.
Learn more
To further explore boundary models, agent-based AI, and the mechanisms that govern their sensitive applications, check out these articles on the aivancity blog.
Sources
[1] Anthropic, September 1, 2026. Introducing Claude Fable 5.1 and Claude Mythos 5.1. View source
[2] Anthropic Claude Platform Documentation, accessed September 29, 2026. Claude Fable 5.1 Overview and What's New. View the documentation
[3] Anthropic, September 2026. Claude Fable 5.1 and Claude Mythos 5.1 System Card. View the System Card
[4] Anthropic, accessed September 29, 2026. Transparency Hub Model Report for Fable 5.1 and Mythos 5.1. View the report
[5] Anthropic, September 1, 2026. Developing Enterprise Frontier Safeguards with Our Customers. View source
[6] Zapier, accessed September 29, 2026. AutomationBench AI Agent Benchmarks. View the benchmark
[7] Cursor, accessed September 29, 2026. CursorBench. View the benchmark
[8] European Commission, updated in 2026. General-Purpose AI Obligations under the AI Act. View the official fact sheet
[9] European Commission, accessed September 29, 2026. Restrictions on the Use of Automated Decision-Making. View the official source
[10] CNIL, updated in 2026. Development of AI systems and recommendations for compliance with the GDPR. View the recommendations

