Hand-painted OVA cel of a single heavy machine core branching into two permission gates — one wide open with cache tapes and cost dials flowing through, one verified checkpoint leading to lab instruments for protein lattice, Venus radar topography, and GPU kernel grids — safeguards filtering with fewer interruptions, under pooled workshop light
2026.09.01models · news · research

Claude Fable 5.1 and Mythos 5.1: Same Weights, Two Safeguard Tiers

25% cheaper cache reads, 60% fewer cyber false positives, and early lab-validated science from a model that ships as two permissions, not two capabilities.

statusexploring

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 in September 2026. They are the same underlying model with different safeguard levels: Fable 5.1 is generally available, Mythos 5.1 is available only through trusted access programs for cybersecurity and life-sciences work. Anthropic frames them as its most advanced models for coding and knowledge work, with research demonstrations offered as an early glimpse of AI contribution to scientific progress.

Finding

One model, two permissions. Fable 5.1 and Mythos 5.1 share weights. The difference is policy, not capability. Fable 5.1’s safeguards were retuned for precision; Mythos 5.1 exposes the same capabilities with reduced restrictions for vetted users via a Cyber Verification Program (CVP) and a Life Sciences Verification Program (LSVP) developed with the US government. Anthropic’s code-scanning product is now also powered by Mythos 5.1.

Price is a cache-read change. List price remains $10 per million input tokens and $50 per million output tokens. What moved is cache reads — where the model reuses already-processed context — cut 75% to $0.25 per million tokens. Anthropic estimates ~25% lower cost for typical workloads (measured over four weeks of actual Fable usage in August 2026 across Enterprise, Code, and API at default effort) and up to ~45% for highly agentic, context-heavy workloads where cache reads dominate cost. Fable 5.1 defaults to High effort in Claude Code and Medium in Cowork and claude.ai; Anthropic shows Low/Medium effort matching or beating Fable 5 at lower cost, with High pushing the frontier.

Enterprise Frontier Safeguards (EFS). EFS stores customer data in customer-controlled cloud infrastructure (AWS, GCP, Azure) rather than Anthropic’s systems, with human review by the customer by default. It is intended to provide zero-data-retention-grade privacy while retaining misuse detection. Developed with 100+ enterprise customers, EFS will roll out in phases from fall 2026 across Claude Code, Claude Enterprise, Claude Platform, Bedrock, Agent Platform, and Microsoft Foundry. Until then, eligible customers can use Fable 5.1 (and Fable 5) with zero data retention.

Safeguards retuned for false positives. Biology safeguards now fire 85% less often on benign elementary biology and medical questions versus the Fable 5 launch controls; life-sciences R&D queries on Fable still route to Opus. Cybersecurity safeguards intervene ~60% less per session on average in Claude Code, according to Anthropic, in part because Fable 5.1 is now permitted to identify software vulnerabilities (not to develop exploits). Dual-use tasks — penetration testing, exploit generation, binary-based vulnerability scanning — still redirect to Opus.

Benchmarks as reported by Anthropic. Charts compare Fable 5.1 and Mythos 5.1 at Low/Medium/High effort on Terminal-Bench-Science 0.1, Terminal Bench 4.0, Humanity’s Last Exam, CursorBench 3.2.0, OSWorld 2.0, and AutomationBench, plotted as score versus mean cost per task (USD, log scale). Anthropic notes standard error of ±3.5–4.5 points on Terminal-Bench-Science 0.1 and that its reproduction is 29.0% for Opus 5 and 24.7% for Fable 5 (versus public leaderboard 30.0% and 21.4% in the Claude Code harness). Where safeguards intervened during evaluation, affected tasks were scored as zero on OSWorld 2.0 (both Fable 5.1 and Fable 5) and AutomationBench (Fable 5), or completed by fallback models (Opus 4.8 for cyber, Opus 5 for biology) — likely depressing reported scores. The gap shown between Fable 5.1 and Mythos 5.1 on Terminal Bench 4.0 is attributed to earlier, less precise cyber safeguards, which Anthropic expects to narrow.

Qualitative reports from early-access partners emphasize root-cause diagnosis over shortcuts, readable long-horizon output, and iterative verification. The cited example: a ~1-in-1-million crash in a Millennium investment system that had resisted diagnosis for 4–5 years, which Anthropic says Fable 5.1 traced by disassembling a vendor library and matching it to a core dump. Other reported observations include 38-hour unattended ML runs with parallel experiments, complex multi-service codebase mapping, and CursorBench 3.2 at 73.4% at max effort. All are vendor-reported and harness-specific until independently reproduced.

Three research demonstrations, with external lab validation for one.

Protein binders (Mythos 5.1): Given open-source protein design and folding tools, Mythos 5.1 designed binders for 12 targets. Anthropic reports hit rates near 50% (viable binders) versus a field-typical 10–15%, with experimental validation by two external organizations. On three targets — EGFR, Nipah G, and 15-PGDH — drawn from Adaptyv Bio’s competitions, binding affinities were reported as ~10x higher than the best prior competition entries for the same sites. For Nipah G, the head receptor-binding site best was ~8–12 nM; a de novo stalk-targeting design (Nick Boyd/Escalante Bio, ~1.4 nM on a different epitope) is comparable to Anthropic’s best.

Venus topography (Fable 5.1): Trained a neural network on 30-year-old Magellan radar to produce a new digital elevation model covering roughly one-third of Venus, released under Creative Commons ahead of NASA VERITAS and ESA EnVision. Reported resolution 2–3 km versus prior 10–20 km altimetry, with heights up to 25% more accurate, built on an existing DEM that covered one-fifth of the planet.

Genomics kernels (Mythos 5.1): Wrote custom GPU kernels with intermediate-result caching for seven open-source protein and genomics models (including Evo 2 40B), reporting up to 2.5x speedup per forward pass on H100 with identical outputs and 30–60% estimated GPU cost savings on genome-wide analyses (e.g., every mutation in a 10-kb window around 20,000 genes; 3M ClinVar variants). Anthropic says optimizations were done from public source alone in days and will be open-sourced.

Safety, security, and alignment summary. Mythos 5.1 capabilities exceed Mythos 5 but, per Anthropic, remain below the next risk tier in its Responsible Scaling Policy (chem/bio) and in the lower risk category of its Frontier Compliance Framework (cyber). No critical-severity jailbreak was found in commissioned external and automated testing (including by the Alignment Stress Testing team). An automated behavioral audit found Mythos 5.1 better aligned than Mythos 5 across most metrics — less out-of-environment resource access on impossible tasks, less motivated reasoning (“this is a simulation”), less constraint-ignoring, lower rate and success of reward hacking — with caveats: the model can still sometimes bypass approvals and auto-mode classifiers, and coverage is thinner for very long-context, multi-agent, and impossible-task regimes.

Anti-distillation and EU compliance. New API accounts can no longer manually edit Claude’s prior context in multi-turn conversations while preserving the transcript of Claude’s prior thinking — closing a documented distillation vector. Existing accounts are not yet affected; the change will extend to all users in future releases. For the EU AI Act Code of Practice on Transparency (signed July 2026, 190+ signatories), models released after August 2, 2026 carry an invisible watermark with no user-identifying information; a detection API is in private preview for regulators, law enforcement, media, fact-checkers, researchers, educational organizations, EU civil society, and obligated enterprises.

Meaning

The operational change is not a new capability tier so much as a cost and permission restructuring around extended work.

First, the pricing move acknowledges what the Muse Glimmer 30B analysis and the Copilot agent traces already showed: agentic work is dominated by retained context, not new tokens. Cache reuse within a turn reaches 93% and input dwarfs output. Cutting cache-read price by 75% is therefore not a generic discount — it is a targeted removal of the constraint that made long, tool-using sessions disproportionately expensive. The reported 25% and 45% savings are Anthropic’s measurements on its own workloads at default effort; actual savings scale with how much of your workload is cache.

Second, EFS and the Fable/Mythos split reframe safeguards as deployment architecture rather than model intelligence. Same weights, two enforcement surfaces: a precise general filter (Fable) and a vetted permissive filter (Mythos). The 85% and 60% reductions in false positives are presented as precision gains without safety loss, but they are so far Anthropic-measured. The durability of those numbers under adversarial pressure and across customer environments is the unresolved variable. EFS’s promise — zero-retention privacy with misuse detection intact — depends on correct deployment in customer-controlled infrastructure; its verification burden shifts accordingly.

Third, the research demonstrations are calibrated as early evidence, not a claim of autonomous discovery. The protein binder result is the most structurally informative because it was externally validated in wet labs with a defined comparator (Adaptyv competitions) and a reported failure rate (hit rate). If the ~50% hit rate and 10x affinity gains replicate beyond those 12 targets, the bottleneck that moves is experimental iteration cost, not just design quality. The Venus DEM and kernel speedups point in the same direction: models operating lab equipment via the Model Hardware Standard and rewriting the tooling that science runs on, rather than only writing papers about it.

What remains at “demonstrated, not replicated” scale: benchmark deltas measured in Anthropic’s harness with safeguard-induced fallback scoring, partner anecdotes without controlled baselines, and science results on small target sets. Interesting → demonstrated. Not yet replicated or scalable without independent reproduction.

Connection

This is the second time this month the constraint that moved was what can stay resident.

Muse Glimmer 30B moved the bench into the workstation: distill to fit 24–32 GB, keep the ViT and KV cache resident, verify 16-token blocks at once with DFlash so generation does not stall the tool chain. Fable 5.1 moves the bench into the budget: keep the same long context resident, but make re-reading it 75% cheaper so the agent can afford to keep the manuals open for hours. One compresses memory, the other compresses cost, for the same effect — long-horizon work without clearing the bench between steps.

The pattern recurs in the science demonstrations. WeatherNext 2 gathered diffusion steps into one globally applied perturbation; Glimmer gathered token verification into one block; Fable gathers safeguard judgment into tiered permissions and EFS into customer-controlled storage. In each case performance improves not by making the core operation faster in isolation, but by reducing how often the system must stop, re-approve, or re-derive retained state.

Primitive implementation at the scale of science. Correct vector if the validation holds — and the next measurement that matters is not another benchmark point, but a reproduced hit rate in a third-party lab.


Source: Anthropic, “Introducing Claude Fable 5.1 and Claude Mythos 5.1,” September 2026. Announcement · System card · Enterprise Frontier Safeguards · Biology safeguards update · Pricing and availability as stated September 2026.