Skip to main content
New

Fable 5.1 and Mythos 5.1: one model, two levels of safeguards

Released September 1, 2026, Claude Fable 5.1 and Mythos 5.1 are the same model with different protections. Cache reads cut by 75%, fewer cyber false positives: the rundown for developers.

  • Guide
  • Security
Published

Quick answer

On September 1, 2026, Anthropic released Claude Fable 5.1 and Claude Mythos 5.1. The most surprising part is spelled out in the announcement: they're the same model, with different levels of safeguards.

Fable 5.1 is generally available. Mythos 5.1 is only available through trusted access programs designed for defensive cybersecurity and the life sciences.

Think of a production car and its track version. Same engine, same chassis. The track version has no speed limiter, but it's only handed to licensed drivers on registered circuits.

What changes on your bill

Input and output prices don't move: $10 per million input tokens and $50 per million output tokens, same as Fable 5. The cut is on cache reads only, which drop to $0.25 per million tokens, 75% less.

Anthropic estimates the overall effect at about 25% savings on a typical workload, and up to about 45% on highly agentic work, where cache reads weigh the most. These estimates come from four weeks of real usage measured in August 2026.

A customer quoted in the announcement, who runs the Devin agent, sums it up: with the new cache pricing, a Fable-class model is finally economical for the workloads they had kept on Opus, starting with code review.

# In a Claude Code session
/model fable

The numbers against Fable 5

A selection from Anthropic's published table (vendor-reported scores):

BenchmarkFable 5.1Fable 5
Terminal-Bench 4.055.8%42.0%
Terminal-Bench-Science 0.152.6%24.7%
AutomationBench31.4%17.1%
CursorBench 3.2.073.4%70.5%

One methodology detail matters here. Fable 5.1 was evaluated with its production safeguards on. When they intervened, cyber tasks were completed by Opus 4.8 and biology tasks by Opus 5, and on some benchmarks an intervention counted as zero. Anthropic notes this likely lowers Fable 5.1's scores.

On Terminal-Bench 4.0, the gap between Fable 5.1 and Mythos 5.1 (60.9%) comes precisely from those interventions, since it's the same model.

Fewer cybersecurity false positives

This was a common complaint with Fable 5: perfectly legitimate requests blocked because they looked like offensive security. Anthropic announces several fixes:

  • The new cyber safeguards block 60% fewer false positives. In Claude Code, that means around 60% fewer interventions per session on average.
  • Fable 5.1 can now be used to discover software vulnerabilities, meaning defensive work. It still shouldn't develop exploits.
  • Penetration testing, exploit generation and binary-based vulnerability scanning are still rerouted to Opus models.
  • In biology, the new safeguards fire 85% less often on elementary biology and medical questions compared with those that launched with Fable 5.

If you work on a security project, you'll see Claude Code switch models less often, but it will still happen. We explain the mechanism in Why Claude Code sometimes switches models mid-session.

Mythos 5.1: who's it for?

Mythos 5.1 goes through two programs:

  • Cyber Verification Program (CVP): it already gives access to some Opus and Sonnet models with reduced cyber safeguards for defensive work. Access to Mythos-class models is announced "in the near future".
  • Life Sciences Verification Program (LSVP): it lets life sciences professionals use Mythos 5.1 with safeguards designed for research, in partnership with the US government.

The announcement notes that Mythos 5.1 is currently only available to a set of US organizations. For most teams, Fable 5.1 is the one that matters.

The Claude Security product, which scans codebases for vulnerabilities and suggests patches for human review, now runs on Mythos 5.1.

Privacy: Enterprise Frontier Safeguards

Anthropic also announced a new system, Enterprise Frontier Safeguards (EFS). The idea: data stays stored in cloud infrastructure controlled by the customer, not Anthropic, and any human review is done by the customer by default. Anthropic keeps the ability to detect misuse.

EFS rolls out in phases starting this fall, on Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google's Agent Platform and Microsoft Foundry. Until then, eligible customers can use Fable 5.1 with zero data retention.

A change that can break an API integration

Fable 5.1 introduces an anti-distillation mechanism. For API accounts created from the release date onward, you can no longer manually edit Claude's prior context in a multi-turn conversation while keeping the transcript of its prior thinking. Existing accounts aren't affected for now, but Anthropic warns the rule will apply to everyone with future model releases.

If your code rewrites message history before sending it back to the API, test it now.

And science?

The announcement gives a lot of space to research. Two examples published by Anthropic:

  • Mythos 5.1 designed protein binders with a hit rate close to 50% across 12 targets, validated in the lab by two external organizations. Anthropic says hit rates of 10 to 15% are typical today.
  • Fable 5.1 trained a neural network to produce a new elevation map of a third of Venus, from radar images taken by NASA's Magellan mission.

Next steps