
Anthropic announced Claude Fable 5.1 and Claude Mythos 5.1 on 1 September 2026. Fact (company): the two names are the same model weights with different safeguard levels. Fable 5.1 is generally available; Mythos 5.1 is offered only through trusted-access programmes aimed at cybersecurity and the life sciences.
That sentence is the story. Benchmark tables and science demos matter, but they sit inside a commercial design choice: ship one engine, sell two doors. Safety here is not an after-the-fact policy PDF. It is the product surface.
[1][2]What shipped, on Anthropic’s own ledger
Access. Fable 5.1 is on Anthropic’s platforms and major clouds under the API id claude-fable-5-1. Mythos 5.1 is gated via a Cyber Verification Program (CVP) and a Life Sciences Verification Program (LSVP), the latter developed with the US government; enrollment for scientists is expected to open more widely. Claude Security, Anthropic’s vulnerability-scanning product, is now powered by Mythos 5.1.
Price. Input/output list prices stay at $10 / $50 per million tokens. Cache reads fall 75%, to $0.25 per million tokens. Anthropic estimates roughly 25% lower cost on typical workloads versus Fable 5, and up to about 45% for highly agentic, cache-heavy work.
Privacy architecture. The same-day Enterprise Frontier Safeguards (EFS) note describes customer-controlled cloud storage for activity data used in misuse detection—privacy framed as equivalent to zero data retention (ZDR) while retaining cross-session monitoring. EFS rolls out in phases from later this fall; eligible customers get interim ZDR on Fable 5 / 5.1 until then. Anthropic says it built EFS with more than 100 enterprise customers and cloud partners AWS, Google Cloud, and Microsoft Azure.
Safeguard precision. Relative to earlier Fable 5 cyber safeguards, Anthropic claims about 60% fewer false-positive interventions per Claude Code session, and now allows vulnerability discovery (not exploit development) on Fable. Biology safeguards for elementary/medical benign queries fire 85% less often than at Fable 5 launch; research-grade life-sciences capability still routes toward Mythos / access programmes. Mythos 5.1, Anthropic says, remains below the next Responsible Scaling Policy risk tier. Outputs after 2 August 2026 carry an invisible watermark under the EU AI Act Code of Practice, with a detection API in private preview.
[1][2]The mechanism: one engine, two locks
The dual-name launch makes a structural claim: capability and dual-use control can be separated at the policy layer while sharing weights. Fable is the open door with tighter redirects on cyber and biology dual-use tasks (some still handed to Opus-class models). Mythos is the same machinery with more permissive safeguards for vetted defenders and life-science professionals.
That is a productization of what labs used to bury in model cards. Instead of “we refuse X,” Anthropic sells “X is available if you pass verification.” Jane Street’s Craig Falls, quoted on the launch page, praises coding coverage and “trading intuition,” and notes long multi-step traces stay readable—an enterprise usefulness signal sitting beside the gatekeeping story.
Inference (labelled): once safeguards become SKUs, access politics become procurement. Who sits on CVP/LSVP waitlists, how US-centric the initial Mythos cohort is, and how false-positive rates feel in production will matter as much as Terminal-Bench points.
[1]Capability claims—and what they do not settle
Anthropic’s table (Fable 5.1 with production safeguards) includes: Terminal-Bench-Science 0.1 at 52.6% versus Fable 5’s 24.7%; Terminal-Bench 4.0 at 55.8% (Mythos 60.9%); GDPval-AA v2 at 1853; OSWorld 2.0 partial 77.9% / strict 41.7%; Humanity’s Last Exam 60.9% without tools / 65.0% with tools; AutomationBench 31.4%; CursorBench 3.2.0 at 73.4%. Footnotes stress noise bands, harness differences, and that safeguard interventions can zero some tasks.
Science demos attached to Mythos are striking on Anthropic’s telling: protein binders with affinities about 10× the best Adaptyv Bio competition entries on three named targets, and nearly 50% hit rate across 12 targets (versus a cited typical 10–15%); a Venus DEM derived from Magellan radar; GPU-kernel speedups up to 2.5× on seven open-source models. These are company-reported, partly externally wet-labbed for binders, not independent league tables.
None of that contradicts the dual-track thesis. If anything, stronger cyber and biology capability is why Mythos exists as a separate door.
[1]EFS: misuse detection without Anthropic holding the keys
The companion EFS announcement answers a regulated-industry objection to retention after Fable 5’s 30-day window: banks and other firms wanted monitoring across sessions without adding Anthropic as a data custodian. EFS keeps activity data in the customer’s cloud account under customer keys; automated flags go to the customer; Anthropic human review is not required by default. Storage is opt-in and billed by the cloud provider; Anthropic says it does not charge for EFS itself.
Fact gap: EFS is not generally live on 1 September—it is a phased fall rollout with interim ZDR. Until architecture ships, the privacy promise is a bridge policy, not a finished control plane.
[2][1]Steelman, and what to watch
Steelman counter: identical weights with different safeguards is the honest way to ship dual-use models. Hiding Mythos-class biology and cyber behind verification reduces casual misuse without starving legitimate researchers; cheaper cache reads and EFS show Anthropic responding to customer complaints on cost and retention; watermarking meets an EU obligation without user fingerprinting. On that reading, “productized safety” is compliance maturity, not cynicism.
The steelman holds only if gates are real. If Mythos access expands into a rubber stamp, or if Fable’s “vulnerability discovery but not exploits” line proves easy to jailbreak, dual doors collapse into marketing. Anthropic’s own system-card summary already notes residual bypasses of approvals and thinner coverage of very long-context multi-agent settings.
Over the next six months, watch three concrete signals: (1) how fast CVP/LSVP move beyond an initial US cohort; (2) whether independent evaluators reproduce the science and agentic scores under production safeguards; (3) whether EFS’s customer-held logs actually catch multi-account misuse at bank scale without re-creating a retention fight. The launch’s durable novelty is not a new nickname for Claude. It is that the lock became inventory.
[1][2]