Fable 5.1 and Mythos 5.1
are actually the same model.
Anthropic just announced two new models, Claude Fable 5.1 and Claude Mythos 5.1. They look like two separate models with different roles, but they share the same underlying weights — what differs is only how the safety guardrails are applied. Mythos 5.1 is available only through vetted programs for cybersecurity defenders and life-sciences researchers; ordinary developers can't prompt it directly.
From one blanket safeguard
to a two-tier one
Until now, Anthropic applied uniform safety guardrails across the whole model in domains with real misuse risk — cyberattacks and bioweapon-relevant knowledge chief among them. With the previous generation, Fable 5, those guardrails sometimes blocked entirely legitimate questions too, and researchers and security professionals pointed out that the balance between safety and usefulness felt coarse.
The joint launch of Fable 5.1 and Mythos 5.1 rethinks that blanket-guardrail approach itself. Per Anthropic's official announcement, the two are literally the same model sharing the same weights — only the safety configuration applied to each differs. Fable 5.1 is the generally-available version with standard safeguards, while Mythos 5.1 runs with those safeguards relaxed, but only inside vetted programs for cybersecurity defenders and life-sciences researchers.
| Fable 5.1 | Mythos 5.1 |
|---|---|
| Anyone can prompt it directly | No direct prompting — authorized paths only |
| Standard safety guardrails | Guardrails deliberately relaxed for specialists |
| Up to 45% cheaper than Fable 5 | Reached only via programs like Claude Security |
| Available via API and Pro/Max | Vetted cybersecurity / life-sciences experts only |
The same brain,
handed a different key.
What a "vetted program" means
Mythos 5.1 isn't something you can freely prompt — it only runs inside the work of specialists Anthropic has individually approved.
One concrete use case is Anthropic's own security product, Claude Security, which scans codebases for vulnerabilities and suggests patches for human review. It's now powered by Mythos 5.1. The idea: unlock advanced security-analysis capability — the kind that could also be misused to write attack code — only inside the work of vetted security professionals. The life-sciences vetted program works the same way, opening up specialized biology discussion that's normally restricted to misuse-prevention, but only for identity-verified researchers.
Fable 5.1, meanwhile, got more precise about its own safeguards compared to Fable 5. Some security use cases, like identifying vulnerabilities in source code, are now available even in the generally-available Fable 5.1, and the biology safeguards now intervene on benign requests 85% less often than Fable 5's did. That's the real shape of this change: safety moved from being applied bluntly and uniformly to being applied precisely, tailored to who's actually asking.
Cheaper, and smarter
about what it blocks
For typical workloads, Fable 5.1 runs roughly 25% cheaper than Fable 5, with a 75% cut on cached input reads — the discount grows for heavier, more agentic workloads. At the same time, the "hit rate" of misuse detection has improved, so legitimate users run into the safeguards less often. Cutting cost and improving safety at the same time, while carving out only the highest-risk use cases for Mythos 5.1, is the core shape of this update.
How to read this shift
The race to make models smarter is being joined by a second race: designing who gets how much capability, and through which door.
Why it matters now
Safety measures used to be close to binary — restrict the whole model, or don't. Splitting the same model into two safety configurations lets a lab narrow misuse risk without cutting raw capability, which is one real answer to the safety-vs-usefulness tradeoff.
Who it affects, and how
In-house security teams get indirect access to Mythos 5.1's vulnerability-scanning power through Claude Security. Life-sciences researchers who apply to the vetted program get room for more specialized discussion. Regular API developers and Claude Pro/Max users never touch Mythos 5.1 directly, but they benefit from Fable 5.1's lower cost and fewer false-positive blocks.
What to do next
Security teams should prioritize evaluating Claude Security; life-sciences researchers should check the vetted program's application requirements. For most developers, the practical move is simpler: check whether switching to Fable 5.1 nets you the cost savings and fewer over-blocks.
Counterpoint, risk, and limits
Anthropic hasn't published the detailed review criteria or operating process for deciding who counts as a vetted specialist, so the program's transparency remains an open question. Relaxing safeguards in the life-sciences domain, even for vetted users, can't fully eliminate misuse risk if someone slips through vetting. Gating access is an attempt to balance misuse prevention against legitimate specialists' needs — but the vetting process itself could become a new bottleneck, or a black box.
From uniform release
to staged release
Frontier models have mostly followed a straight line so far: make it more capable, then release it broadly. But in domains with real misuse risk, how a lab releases that capability is now itself under scrutiny. The relationship between Fable 5.1 and Mythos 5.1 shows that designing who gets the same capability, through which path, and how much of it is becoming a competitive axis alongside raw model improvement.
Whether Anthropic adds vetted programs beyond Claude Security, and how much of its review criteria it discloses, will be worth watching as a signal of whether other frontier labs follow this staged-access model.