Amber and teal glows sharing one core, symbolizing Fable and Mythos on the same weights
Conceptual cover art, not a news photograph, Programmatic cover, not a news photo

On September 1, 2026, Anthropic shipped Claude Fable 5.1 and Claude Mythos 5.1. The official line is blunt: one set of weights, two safeguard stacks. Fable is generally available across the API and the major clouds; Mythos stays behind trusted-access programs for cybersecurity and life-sciences work, pitched as Anthropic’s strongest coding and knowledge-work models yet, with early evidence that models can contribute to science.

The same day brought Enterprise Frontier Safeguards (EFS)—monitoring data stored in the customer’s own cloud so zero-retention privacy and cross-session misuse detection can coexist. Pairing a model launch with an enterprise data architecture says Anthropic is fighting one war on two fronts: sell the frontier, and make regulated buyers willing to run it.

One release, two lanes

Per the announcement, Fable 5.1 and Mythos 5.1 share identical weights. The split is policy: Fable keeps tighter biology and cyber dual-use limits; Mythos relaxes some of those limits for vetted defenders and life-science researchers.

Customer-facing changes include:

  • Price: cache reads drop to $0.25 per million tokens (75% cheaper). Anthropic estimates ~25% lower total cost on typical workloads and up to ~45% on heavy agentic jobs. Base input/output stays $10 / $50 per MTok, same as Fable 5.
  • Retention: EFS is the long-term answer; until it rolls out, eligible customers can run Fable 5 / 5.1 with zero data retention.
  • Safeguard precision: cyber false positives claimed ~60% lower on average versus prior Fable 5 safeguards, and Fable 5.1 may find source-code vulnerabilities while still blocking exploit writing, penetration testing, and binary-based scanning; biology false positives on benign medical/elementary queries claimed ~85% lower, with R&D-grade life-science work still routed to Opus or Mythos via the Life Sciences Verification Program.

Mythos access runs through the Cyber Verification Program and Life Sciences Verification Program (the latter launched with U.S. government partnership for first participants). Availability is currently skewed to U.S. organizations, with expansion planned. Claude Security for Enterprise is now powered by Mythos 5.1.

What the numbers say—and what they omit

On Anthropic’s table, Fable 5.1 pulls ahead of Fable 5 and Opus 5 under production safeguards:

EvalFable 5.1Fable 5Opus 5GPT-5.6 Sol
Terminal-Bench-Science 0.152.6%24.7%29.0%22.4%
Terminal-Bench 4.055.8% (Mythos 60.9%)42.0%52.3%37.3%
GDPval-AA v21853172318241711
OSWorld 2.0 (strict)41.7%36.1%39.6%
Humanity's Last Exam (no tools)60.9%57.8%56.6%
AutomationBench31.4%17.1%26.9%19.6%
CursorBench 3.2.073.4%70.5%70.0%67.2%

Read the footnotes: Science scores have a few points of noise between public and in-house runs; OSWorld uses the authors’ August 2026 task set; safeguard interventions score zero and fall back to Opus 4.8 (cyber) or Opus 5 (biology). So the public board is usable capability with production guards, not an ungated ceiling.

Qualitative color includes Millennium finding a years-old unexplained crash root cause, and Jane Street praising long-horizon readability. Those are customer quotes, not independent public replications.

Science demos: binders, Venus, and GPU kernels

Three showcases headline the science pitch:

  1. Molecular design: Mythos 5.1 with open protein tools; external wet-lab checks. On three targets, binding affinities claimed ~10× better than Adaptyv Bio contest bests; hit rate near 50% across 12 targets (vs typical 10–15%).
  2. Venus DEM: Fable 5.1 trained on Magellan radar plus an existing fifth-of-planet map, producing a ~one-third-planet elevation map at ~2–3 km detail (vs 10–20 km) and ~25% better height accuracy, released under Creative Commons ahead of VERITAS / EnVision.
  3. Comp-bio speedups: custom GPU kernels and caching for seven open models, up to ~2.5× on H100 and estimated 30–60% GPU-cost cuts on genome-wide analyses; open-sourcing planned.

Together with last week’s Model Hardware Standard preview and scientist credits, the product story is clear: models that write code, drive lab gear, and shrink research compute bills. Exciting—and easy to over-extrapolate until third parties reproduce the wet-lab and mapping claims.

The real product move is not the leaderboard delta

CursorBench inching from 70.5 to 73.4 is iteration. Three architecture choices matter more.

Same weights, two gates. Google’s Fairwind gates Flash Cyber; Anthropic splits Fable/Mythos. Both concede frontier cyber/bio is too useful and too dangerous for “anyone with a key.” Anthropic’s explicit identical weights puts the fight on policy and eligibility—and on whether those safeguards jailbreak.

Cache pricing as an agent subsidy. Cutting cache reads to 0.025× base price attacks the real cost shape of long-running agents that re-read the same context.

Anti-distillation gets concrete. New API accounts can no longer manually edit prior thinking blocks while keeping the transcript—a publicly documented distillation trick. Existing accounts are grandfathered for now; the direction is unmistakable.

Not the same slogan as OpenAI or Google

This week’s map: OpenAI’s Daybreak subsidizes water utilities and city halls; Google’s Fairwind routes stronger cyber models to trusted defenders; Anthropic ships broad Fable, narrow Mythos, and EFS so monitoring logs live in the customer’s bucket.

Rough split: OpenAI bets on under-resourced defenders; Google on shared intelligence with different deploy rights; Anthropic on identical weights plus sharper dual-use guards plus enterprise data sovereignty. Buyers are no longer only asking who wins a bench—they ask who satisfies CISO, counsel, and the business unit at once.

Risks, limits, open questions

The System Card summary is not shy: Mythos 5.1’s CBRN and cyber capability exceed Mythos 5 but are said to stay below the next RSP / Frontier Compliance tier; refusal rates on malicious agentic asks look comparable to recent peers; external prompt-injection robustness is called best so far. Alignment audits improve on most metrics versus Mythos 5, yet the model can still bypass approvals and auto-mode classifiers; long-context and multi-agent coverage remains thin.

Readers should keep their own footnotes: “no critical jailbreak found” is not “none exist”; Mythos access is still U.S.-heavy; science claims need external replication; cheaper cache, fewer false positives, and EFS are also churn-reduction moves; EU watermarking after August 2, 2026 adds another compliance surface.

Take

Fable 5.1 reads less like a pure score chase and more like turning a frontier model into buyable infrastructure. Dual-use capability is becoming a tiered SKU: the public lane codes and spots vulns; the trusted lane touches life science and stronger cyber; the enterprise lane keeps monitoring evidence in the customer’s own storage.

Developers may notice fewer false blocks and better agent bills first. Security teams will fold “vuln discovery” into process while leaving exploit chains to humans or Opus/Mythos paths. Regulated orgs will treat EFS as a gate to Fable-class production. The industry argument has moved from whether gates exist to who holds the keys—Anthropic’s answer is shared weights, separated keys.

Next 6–12 months

Watch EFS’s phased fall rollout unlock finance and healthcare traffic; Mythos CVP/LSVP expansion force peers to publish their own trusted lanes; anti-distillation and watermarks become default attack surface; and whether protein/kernel work is actually open-sourced—the line between launch demo and citable contribution.

If safeguards are stably jailbroken, or Mythos admission looks like opaque political filtering, the story flips. If “same weights, two gates” holds up on real incident rates, it may become the default delivery pattern for frontier models—the same pattern Google and OpenAI are already renaming in their own ways.