共有:
Model Access Policy

Fable 5.1 and Mythos 5.1
are actually the same model.

Anthropic just announced two new models, Claude Fable 5.1 and Claude Mythos 5.1. They look like two separate models with different roles, but they share the same underlying weights — what differs is only how the safety guardrails are applied. Mythos 5.1 is available only through vetted programs for cybersecurity defenders and life-sciences researchers; ordinary developers can't prompt it directly.

AI Navigate Editorial·2026.09.03·6 min read
Same model weights Claude 5 family Fable 5.1 General availability, standard safeguards Mythos 5.1 Vetted access only, relaxed safeguards Developers / Pro & Max Cybersecurity / life sciences vetted specialists only
01
Before / After

From one blanket safeguard
to a two-tier one

Until now, Anthropic applied uniform safety guardrails across the whole model in domains with real misuse risk — cyberattacks and bioweapon-relevant knowledge chief among them. With the previous generation, Fable 5, those guardrails sometimes blocked entirely legitimate questions too, and researchers and security professionals pointed out that the balance between safety and usefulness felt coarse.

The joint launch of Fable 5.1 and Mythos 5.1 rethinks that blanket-guardrail approach itself. Per Anthropic's official announcement, the two are literally the same model sharing the same weights — only the safety configuration applied to each differs. Fable 5.1 is the generally-available version with standard safeguards, while Mythos 5.1 runs with those safeguards relaxed, but only inside vetted programs for cybersecurity defenders and life-sciences researchers.

Fable 5.1Mythos 5.1
Anyone can prompt it directlyNo direct prompting — authorized paths only
Standard safety guardrailsGuardrails deliberately relaxed for specialists
Up to 45% cheaper than Fable 5Reached only via programs like Claude Security
Available via API and Pro/MaxVetted cybersecurity / life-sciences experts only

The same brain,
handed a different key.


02
How Access Works

What a "vetted program" means

Mythos 5.1 isn't something you can freely prompt — it only runs inside the work of specialists Anthropic has individually approved.

Developer / App direct: blocked Vetted program (e.g. Claude Security) GATE Mythos 5.1
FIG. Direct developer calls are blocked at the gate; only authorized programs like Claude Security reach Mythos 5.1

One concrete use case is Anthropic's own security product, Claude Security, which scans codebases for vulnerabilities and suggests patches for human review. It's now powered by Mythos 5.1. The idea: unlock advanced security-analysis capability — the kind that could also be misused to write attack code — only inside the work of vetted security professionals. The life-sciences vetted program works the same way, opening up specialized biology discussion that's normally restricted to misuse-prevention, but only for identity-verified researchers.

Fable 5.1, meanwhile, got more precise about its own safeguards compared to Fable 5. Some security use cases, like identifying vulnerabilities in source code, are now available even in the generally-available Fable 5.1, and the biology safeguards now intervene on benign requests 85% less often than Fable 5's did. That's the real shape of this change: safety moved from being applied bluntly and uniformly to being applied precisely, tailored to who's actually asking.

03
By the Numbers

Cheaper, and smarter
about what it blocks

Up to 45%
Cost cut vs. Fable 5 for heavy agentic workloads
75%
Price cut on cached input reads
−85%
Fewer benign biology requests wrongly blocked, vs. Fable 5

For typical workloads, Fable 5.1 runs roughly 25% cheaper than Fable 5, with a 75% cut on cached input reads — the discount grows for heavier, more agentic workloads. At the same time, the "hit rate" of misuse detection has improved, so legitimate users run into the safeguards less often. Cutting cost and improving safety at the same time, while carving out only the highest-risk use cases for Mythos 5.1, is the core shape of this update.

04
Why It Matters

How to read this shift

The race to make models smarter is being joined by a second race: designing who gets how much capability, and through which door.

01

Why it matters now

Safety measures used to be close to binary — restrict the whole model, or don't. Splitting the same model into two safety configurations lets a lab narrow misuse risk without cutting raw capability, which is one real answer to the safety-vs-usefulness tradeoff.

02

Who it affects, and how

In-house security teams get indirect access to Mythos 5.1's vulnerability-scanning power through Claude Security. Life-sciences researchers who apply to the vetted program get room for more specialized discussion. Regular API developers and Claude Pro/Max users never touch Mythos 5.1 directly, but they benefit from Fable 5.1's lower cost and fewer false-positive blocks.

03

What to do next

Security teams should prioritize evaluating Claude Security; life-sciences researchers should check the vetted program's application requirements. For most developers, the practical move is simpler: check whether switching to Fable 5.1 nets you the cost savings and fewer over-blocks.

04

Counterpoint, risk, and limits

Anthropic hasn't published the detailed review criteria or operating process for deciding who counts as a vetted specialist, so the program's transparency remains an open question. Relaxing safeguards in the life-sciences domain, even for vetted users, can't fully eliminate misuse risk if someone slips through vetting. Gating access is an attempt to balance misuse prevention against legitimate specialists' needs — but the vetting process itself could become a new bottleneck, or a black box.


05
Frontier

From uniform release
to staged release

Frontier models have mostly followed a straight line so far: make it more capable, then release it broadly. But in domains with real misuse risk, how a lab releases that capability is now itself under scrutiny. The relationship between Fable 5.1 and Mythos 5.1 shows that designing who gets the same capability, through which path, and how much of it is becoming a competitive axis alongside raw model improvement.

Whether Anthropic adds vetted programs beyond Claude Security, and how much of its review criteria it discloses, will be worth watching as a signal of whether other frontier labs follow this staged-access model.