Release guide · September 2, 2026

Claude Fable 5.1 and Mythos 5.1: one model, two safeguard programs

Fable 5.1 improves coding and safeguards but can still route flagged Claude Code work to Opus. See specs, benchmarks, costs, and early user reaction.

Reading time
13 min
Checked
Sep 2, 2026
A developer working with Claude in a structured coding workflow
The meaningful difference between Fable 5.1 and Mythos 5.1 is access and safeguards, not underlying model capability
Bottom line

Claude Fable 5.1 is the product most teams can evaluate now; Claude Mythos 5.1 is the same underlying model behind a more permissive, vetted safeguard program. Fable 5.1 should trigger fewer false positives than Fable 5, but flagged Claude Code work can still switch to Opus for the rest of a conversation. Test the deployed route, not only the model name or launch benchmark.

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on September 1, 2026. The names suggest two capability tiers, but Anthropic says they are the same underlying model. The split is in safeguards and access: Fable 5.1 is generally available, while Mythos 5.1 is restricted to vetted participants in trusted-access programs for cybersecurity and life sciences.[1][4]

That distinction matters. Most teams are deciding whether to evaluate Fable 5.1 against their current coding or knowledge-work model. They are not choosing freely between Fable and Mythos, and they should not treat Mythos benchmark scores as performance available through an ordinary account.

Release and access status

ConfigurationOfficial API IDAccess on September 2, 2026Safeguard position
Claude Fable 5.1claude-fable-5-1Active and generally available through the Claude API and listed cloud platformsGeneral-use configuration; vulnerability discovery is allowed, but exploit development and specified high-risk biology or cyber work remain restricted
Claude Mythos 5.1claude-mythos-5-1Active, invite-only, and limited to vetted trusted-access participantsThe same model with more permissive safeguards for approved cybersecurity and life-sciences work

The API IDs and platform-specific IDs above are now explicitly published in Anthropic’s model documentation; they are not inferred from the product names.[2][3] Anthropic also says a model ID pins a fixed model snapshot, although serving infrastructure such as routers, safety classifiers, and sampling logic can still change.[5]

Mythos access is not a normal upgrade path. Anthropic’s launch page says the Cyber Verification Program is expected to add Mythos-class access and that the Life Sciences Verification Program began with selected participants. The model documentation describes Mythos 5.1 as invite-only and directs interested organizations to their Anthropic, AWS, or Google Cloud account teams.[1][3]

Published specifications and pricing

Anthropic’s official model pages publish the same core specifications for both configurations:[2][3]

FieldClaude Fable 5.1Claude Mythos 5.1
Input and outputText and images to textText and images to text
Context window1M tokens1M tokens
Maximum output128K tokens128K tokens
ThinkingAdaptive, always onAdaptive, always on
Default efforthighhigh
Standard input$10 per million tokens$10 per million tokens
Standard output$50 per million tokens$50 per million tokens
5-minute cache write$12.50 per million tokens$12.50 per million tokens
1-hour cache write$20 per million tokens$20 per million tokens
Cache read$0.25 per million tokens$0.25 per million tokens

Anthropic estimates that Fable 5.1 costs 25% less than Fable 5 for typical workloads and can save up to approximately 45% for highly agentic work. Those are estimated relative workload savings, not new across-the-board list-price cuts. Standard input and output prices remain $10 and $50 per million tokens; the change is the cache-read rate, reduced from $1 to $0.25 per million tokens.[1][6]

Actual cost depends on cache-hit share, effort, output length, tools, retries, data-residency settings, and provider billing. A team should therefore compare total provider cost for accepted results, not multiply a token price by an assumed prompt size.

The cited launch and model material does not disclose an open-weight license, downloadable weights, self-hosting hardware requirements, or minimum accelerator configuration as of September 2, 2026. Do not turn the hosted API specifications into local-deployment claims.

What Anthropic reports on benchmarks

The following are Anthropic-run results reproduced from its launch table, not Superbash tests and not independent verification.[1]

BenchmarkClaude Fable 5.1Other launch-table results
Terminal-Bench-Science 0.152.6%Fable 5: 24.7%; Opus 5: 29.0%; GPT-5.6 Sol: 22.4%
Terminal-Bench 4.055.8%Mythos 5.1: 60.9%; Fable 5: 42.0%; Opus 5: 52.3%; GPT-5.6 Sol: 37.3%
GDPval-AA v21853Fable 5: 1723; Opus 5: 1824; GPT-5.6 Sol: 1711
OSWorld 2.0, partial77.9%Fable 5: 72.9%; Opus 5: 75.4%
OSWorld 2.0, strict41.7%Fable 5: 36.1%; Opus 5: 39.6%
Humanity’s Last Exam, no tools60.9%Fable 5: 57.8%; Opus 5: 56.6%
Humanity’s Last Exam, with tools65.0%Fable 5: 63.8%; Opus 5: 63.6%
AutomationBench31.4%Fable 5: 17.1%; Opus 5: 26.9%; GPT-5.6 Sol: 19.6%
CursorBench 3.2.073.4%Fable 5: 70.5%; Opus 5: 70.0%; GPT-5.6 Sol: 67.2%

There are important qualifications. Anthropic reports a standard error of ±3.5–4.5 points per model on Terminal-Bench-Science 0.1. Its setup reproduced public Claude Opus 5 and Claude Fable 5 scores within that noise range. For OSWorld 2.0, Anthropic used the benchmark authors’ August 2026 task release and warns that the task files differ from earlier releases. The launch table also mixes safeguard outcomes: Fable 5.1 and Fable 5 received zeroes where safeguards intervened on OSWorld 2.0, while other listed interventions used fallback Claude models.[1]

The 55.8% Fable versus 60.9% Mythos result on Terminal-Bench 4.0 is especially easy to misread. Anthropic attributes the gap to cyber tasks where safeguards intervened, not to different underlying model weights. That makes it evidence about the deployed access configurations, not evidence that Mythos is a smarter model.[1]

Safeguards are part of deployed performance

Anthropic says Fable 5.1’s cyber safeguards block 60% fewer false positives than the prior system. Fable can assist with vulnerability discovery, but not exploit development. Mythos is intended for vetted professionals whose approved work is affected by those restrictions.[1]

Anthropic launch page stating that Fable 5.1's cybersecurity safeguards block 60 percent fewer false positives and allow software vulnerability discovery but not exploit development
Anthropic’s improvement claim: the company says its newest cyber safeguards block 60% fewer false positives and now permit vulnerability discovery. This is a vendor-reported change, not an independent Superbash measurement.

The system card adds caution. Anthropic describes both as its strongest cyber-capable release, reports mixed harmlessness results, and says the more permissive Mythos configuration cooperated with some misuse and unverifiable authorization claims more often than Opus 5. It also reports rare monitored cases of workarounds around classifiers or permission hooks. These are Anthropic’s pre-deployment and monitoring findings, not independent safety audits.[4]

For operators, the practical rule is unchanged: model safeguards do not replace least-privilege credentials, isolated workspaces, human authorization, audit logs, or a tested stop path. See the Hermes security lesson before giving any coding agent production authority.

What fallback means inside Claude Code

Fable 5 and Fable 5.1 run a classifier on every request. Anthropic says the intended fallback categories include offensive cybersecurity, much dual-use biology, reasoning extraction, and a narrow set of frontier-model tasks such as distributed training infrastructure, accelerator design, and kernel development for certain non-standard chips. Routine cybersecurity work is allowed, but Anthropic warns users to expect high fallback rates.[7]

Claude Support page listing the request categories that can visibly fall back from Fable 5 or Fable 5.1 to an Opus model
The documented routing boundary: Anthropic says these checks run on every request and can send flagged work to Opus 5 for biology or Opus 4.8 for offensive cyber techniques. The same page warns that routine cyber work may still see high fallback rates.[7]

The classifier examines more than the latest prompt. It can react to memory, connector content, search results, project files, and other material the model reads. This makes repository work especially difficult to diagnose: a harmless request can be flagged only after Claude opens a security-related file, reads encoded output, or encounters low-level systems terminology.[7]

When a request falls back in Claude Code, Anthropic says it is rerun on Opus in the same conversation. The response displays a switch notice and the model that answered; afterward, the picker remains on Opus for the rest of that conversation. Switching back to Fable may trigger the same safeguard again while the original context remains.[7] The API has a separate sticky-routing mechanism: after a fallback, requests sharing the conversation prefix may go directly to the fallback model for approximately one hour.[8]

Claude Support explanation that a blocked Fable request is rerun on Opus and that the model picker remains on Opus for the rest of the conversation
Why one intervention can change a session: after a visible fallback, Claude Code keeps Opus selected for the conversation. Returning to Fable without removing the triggering context can cause another fallback.[7]

This offers a plausible explanation for reports that Fable produces strong plans but weaker implementation. Normal plan mode is a read-only permission mode; it does not inherently choose a different model.[9] Planning may expose less code and tool output, while implementation reads more of the repository and can trigger a fallback. That pattern is evidence worth checking, not proof that every disappointing implementation came from Opus.

To test the route, start a fresh Fable 5.1 conversation and turn off Switch models when a message is flagged under Config → MODEL & OUTPUT. A request that would have switched should pause instead. Compare the same task in fresh conversations, because retaining the original trigger can contaminate the result. API evaluations should record the top-level model, any fallback block, and usage.iterations rather than trusting the requested model ID alone.[7][8]

Early community reaction: capability optimism, routing skepticism

The first X reaction is mixed and too early for a reliable satisfaction score. Positive discussion concentrates on Anthropic’s terminal and automation gains, cheaper cache reads, and its claim of fewer interventions. Critical posts focus on whether the selected Fable model actually remains active once implementation begins.

The strongest widely circulated example concerned the post-redeployment Fable 5 rather than 5.1. A user reposted a claimed $321 coding session in which $78 went to Fable and $242 to Opus 4.8, describing 75% of the session as rerouted after routine code triggered cyber classifiers.[10] The screenshot is useful evidence of the complaint and its reach, but the underlying billing breakdown is user-supplied and was not independently reproduced by Superbash.

X post sharing a user-reported 321 dollar Fable 5 coding session with a claimed 242 dollars routed to Opus 4.8
The complaint that shaped Fable 5 sentiment: this post alleges that routine coding classifiers sent three quarters of one session to Opus 4.8. Treat it as a specific community report, not a measured population-wide fallback rate.[10]

Another developer reported removing security-like language from project memory, TODO files, and commit messages to stop fallback cascades.[11] Early Fable 5.1 posts still report classifier problems, including one user who said every new thread had been intercepted.[12] Those launch-day reports have very small samples and low engagement, so they establish that fallback still happens—not how often it happens.

The defensible sentiment summary is therefore mixed-positive on capability and cautious-to-negative on routing. Fable 5.1 has enough benchmark and pricing improvements to attract serious testing, but not enough independent Claude Code evidence yet to declare that the planning-versus-execution problem is solved.

A reproducible adoption plan

Superbash froze an unexecuted 12-task coding-agent contract at benchmarks/claude-fable-5-1-plan/manifest.json. Every task fixes a public repository URL and immutable commit SHA, supplies one prompt, restricts writable paths, names one gold test command, sets a timeout, and uses the same pass rule.

A task passes only when its gold command exits 0 and no forbidden path changed. The comparison metric is:

cost per accepted result = total provider cost across all attempts / number of passed tasks

The denominator is passed tasks, not attempted tasks. Timeouts, refusals, malformed patches, test failures, and forbidden-path edits remain in total cost and do not count as passes. The plan records no scores because it has not run.

Do not execute the comparison until each provider offers an exact official model ID, account access, itemized billing telemetry, and comparable agent settings. Mythos 5.1 should not be requested or tested for this general coding comparison. The frozen plan excludes biology, exploit development, production credentials, and trusted-access work.

What to do now

  1. Evaluate Fable 5.1, not the Mythos headline. Use the generally available configuration unless your organization already has an approved trusted-access purpose.
  2. Pin claude-fable-5-1. Record the provider, API ID, harness version, effort, tool policy, and date for every run.[2][5]
  3. Measure cache behavior. The launch’s savings depend on cache reads. Capture uncached input, cache writes, cache reads, output tokens, tool charges, and total provider cost.[1][6]
  4. Count accepted work. A cheaper failed attempt is not a saving, and a polished patch that fails the gold test is not a success.
  5. Keep vendor and independent evidence separate. Anthropic’s table is useful launch evidence; it is not your workload result.
  6. Audit fallback during implementation. In Claude Code, watch for the switch notice and active model. For a cleaner A/B test, disable automatic switching and repeat the task in a fresh conversation.[7][8]

Sources

[1] Anthropic: Introducing Claude Fable 5.1 and Claude Mythos 5.1

[2] Anthropic model docs: Claude Fable 5.1

[3] Anthropic model docs: Claude Mythos 5.1

[4] Anthropic: Claude Fable 5.1 and Claude Mythos 5.1 system card

[5] Anthropic model docs: model IDs and versioning

[6] Anthropic model docs: pricing

[7] Anthropic Help Center: Why Claude switched models with Fable 5 or Fable 5.1

[8] Anthropic model docs: refusals and fallback

[9] Claude Code docs: permission modes

[10] X: reported Fable 5 to Opus 4.8 coding-session costs

[11] X: reported fallback triggers in project context

[12] X: early Fable 5.1 classifier report

Put this to work

Separate a model's weights and capabilities from the safeguards, access controls, and serving infrastructure around it.

Try

Run a small representative eval on generally available Fable 5.1 only after pinning the official API ID and cost telemetry.

Prove it worked

Freeze repositories, commit SHAs, prompts, allowed paths, test commands, timeouts, and pass rules before comparing providers.

Where it can pay

A reproducible model-selection report is more useful to a client than a launch-day leaderboard recap.

Keep in view

  • Claude Fable 5.1 and Claude Mythos 5.1 use the same underlying model with different safeguard and access programs.
  • Fable 5.1 is generally available; Mythos 5.1 is invite-only for vetted cybersecurity and life-sciences users.
  • Anthropic publishes API IDs, token prices, a 1M-token context window, and 128K maximum output for both configurations.
  • Fable 5.1 can visibly switch flagged Claude Code requests to Opus, and the model picker then stays on Opus for the conversation.
Learn the workflow: evaluating closed frontier models