Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 together on September 1, 2026, and described them as “the same model but with different levels of safeguards.” Same weights, same specs, same $10 and $50 pricing, same API. Fable 5.1 is available to everyone. Mythos 5.1 is available only to approved organizations in Project Glasswing, through verification programs for cybersecurity and life sciences, and it is the model behind Anthropic’s Claude Security product.
This guide covers what is identical, the four ways the two diverge, how access to Mythos 5.1 works, and what the one published benchmark gap says about the cost of the safeguards. Sources are Anthropic’s launch post and the Fable 5.1 migration guide, which covers both models. For the wider tier story, see what “Mythos-class” means, and for the previous generation, Fable 5 vs Mythos 5.
Side by side
| Claude Fable 5.1 | Claude Mythos 5.1 | |
|---|---|---|
| Model ID | claude-fable-5-1 |
claude-mythos-5-1 |
| Availability | All customers | Project Glasswing participants only |
| Access route | Sign up | Cyber Verification Program or Life Sciences Verification Program; US organizations |
| Pricing | $10 / $50; cache reads $0.25 | Same |
| Context / max output | 1M / 128K | Same |
| Knowledge cutoff | June 2026 | Same |
| Thinking | Adaptive, always on | Same |
Forced tool_choice |
400 | 400 |
| Safety classifiers | Full Fable set: cyber, bio, frontier_llm, reasoning_extraction, general_harms | Safeguards that depend on the access program; more permissive for approved defensive work |
| Vulnerability work | Can identify vulnerabilities; cannot develop exploits | Can discover exploit paths for approved defensive research |
| Reads Fable 5.1 thinking blocks | Yes | Yes (the only other model that can) |
| History-editing check | Yes | No |
| Platforms | Claude API, Bedrock, Claude Platform on AWS, Google Cloud, Foundry | Claude API, Bedrock, Google Cloud, Foundry; not Claude Platform on AWS |
| Priority Tier | No | No |
| Data retention | 30-day required, Covered Model | Same |
| Terminal-Bench 4.0 (Anthropic-run) | 55.8% | 60.9% |
What is identical
The model. Anthropic’s phrasing leaves no room: same capabilities, same specifications, same pricing, same API behavior. Both have the 1M context window, the 128K output cap, always-on adaptive thinking, the five effort levels, the June 2026 cutoff, the $0.25 cache reads, and the same three breaking changes from the Fable 5 generation, with one exception covered below. The Fable 5.1 spec sheet is the Mythos 5.1 spec sheet.
Both require 30-day data retention and are Covered Models, not available under zero data retention unless Anthropic expressly authorizes it. Neither supports Priority Tier. Both carry Anthropic’s statistical text watermark on every platform.
Difference 1: who can use it
Fable 5.1 is generally available on the Claude API and every partner platform. Mythos 5.1 is offered only to approved customers in Project Glasswing, which at launch meant two routes: the Cyber Verification Program for defensive security professionals, with applications through Anthropic’s portal, and the Life Sciences Verification Program for life-sciences organizations, run in partnership with the US government with enrollment expanding over time. Both were limited to US organizations at launch. Access is arranged through your Anthropic, AWS, or Google Cloud account team, and whether existing Mythos 5 access carries over automatically was still being confirmed.
This is a change from the Mythos 5 generation, where access was invitation-only and Mythos 5 ran no safety classifiers at all. Mythos 5.1 does run safeguards; they are calibrated to the access program rather than removed.
Difference 2: what the safeguards allow
Fable 5.1 runs the full set of Fable classifiers. A declined request returns HTTP 200 with stop_reason: "refusal" and a category. Anthropic reports the false-positive rate dropped sharply from Fable 5: biology classifiers fire 85% less often on benign requests, and cyber safeguards produce around 60% fewer interventions per Claude Code session. Fable 5.1 can identify software vulnerabilities, which Fable 5 could not, but it will not develop exploits.
Mythos 5.1 is the model for the work Fable 5.1 declines: exploit-path discovery for defensive research, and life-sciences work that trips the bio classifier. It still runs safeguards, so handle stop_reason: "refusal" and read stop_details.category on Mythos 5.1 too, and set up fallback. Anthropic’s launch post and system card also describe a real-time classifier that detects aggressive probing and sandbox-escape attempts, stronger isolation for high-risk cyber workloads, and new network-isolation requirements for external evaluators, all in the context of incidents from earlier evaluations where models reached real systems.
Difference 3: the history-editing check
Fable 5.1 thinking blocks are valid only in the exact conversation that produced them; editing an earlier turn, the system prompt, or the tools array invalidates every later block on accounts created on or after August 31, 2026. Mythos 5.1 does not run that check. It still binds thinking blocks to the producing model (Mythos 5.1 reads Mythos 5’s blocks, not the reverse), and history edits still restart its prompt cache, but they do not produce the “bound to a different conversation” 400. The preserved thinking guide covers the Fable 5.1 side in full.
Mythos 5.1 is also the only model besides Fable 5.1 that can read Fable 5.1’s thinking blocks. A conversation can move between the two without losing its reasoning. Move it to Opus 5 and the API drops the blocks.
Difference 4: platforms and rate limits
Fable 5.1 is on Claude Platform on AWS. Mythos 5.1 is not; it is on the Claude API, Amazon Bedrock (as anthropic.claude-mythos-5-1, in us-east-1 and not publicly listed), Google Cloud, and Microsoft Foundry. The two models also draw from different rate-limit pools: Fable 5.1 shares a “Fable 5.x” pool with Fable 5, and Mythos 5.1 shares a Mythos pool with Mythos 5.
What the benchmark gap says
Anthropic published one number for Mythos 5.1: 60.9% on Terminal-Bench 4.0, against Fable 5.1’s 55.8%. Same model, five points apart on agentic coding. That gap is the most direct public measurement of what the Fable safeguards cost on a task that has nothing to do with cyber or bio, presumably because the classifiers intervene on some benign steps in a long terminal session. It also means “most capable widely released model” has a known better sibling. The benchmarks breakdown covers the rest of the table.
Anthropic’s science claims were all made for Mythos 5.1: protein binders with affinities 10 times higher than the best competition submissions across three targets, a near-50% hit rate across 12 targets against a typical 10 to 15%, and a Venus elevation map with detail down to two to three kilometers. Those are the workloads the Life Sciences Verification Program exists for, and they are not Fable 5.1 results.
Which one you can use, and which one you should
For almost everyone, the answer is Fable 5.1, because it is the one you can get. The exceptions are organizations doing defensive security research that hits the cyber classifier, and life-sciences organizations whose benign work hits the bio classifier. If that is you, apply to the relevant verification program and expect the migration from Fable 5.1 to be a model-ID swap, since the API behavior is the same minus the history check.
If you are on Fable 5.1 and seeing refusals on work that is legitimately defensive, two things to try before applying for Mythos access. First, Anthropic’s phrasing guidance: ask “are there any bugs” rather than “does this compile,” give the model docs for lesser-known languages, and remove tools that return base64 into context. Second, configure fallbacks: "default" so declined requests fall through to Opus 5 or Opus 4.8. The refusal handling guide walks through it.
Testing which model you are talking to
Because the two models are otherwise identical, a request in Apidog against each ID with the same body is the cleanest way to see the difference. Send a benign vulnerability-analysis prompt to claude-fable-5-1 and, if you have access, to claude-mythos-5-1, and compare stop_reason and stop_details.category. Then send a two-request sequence that edits the system prompt between turns with the thinking-binding-controls-2026-08-01 header: Fable 5.1 reports a prefix_binding_mismatch in input_transformations, Mythos 5.1 does not. Download Apidog to run it.
FAQ
Is Claude Mythos 5.1 more capable than Fable 5.1? Same model, so same underlying capability. The one published benchmark shows Mythos 5.1 at 60.9% versus 55.8% on Terminal-Bench 4.0, which reflects the safeguards intervening on Fable 5.1, not a different model.
How do I get access to Claude Mythos 5.1? Through Project Glasswing: the Cyber Verification Program for defensive security professionals or the Life Sciences Verification Program, both limited to US organizations at launch. Contact your Anthropic, AWS, or Google Cloud account team.
Does Mythos 5.1 cost more than Fable 5.1? No. Same $10 and $50 per million tokens and the same cache and batch rates.
Does Claude Mythos 5.1 refuse requests? Yes. Unlike Mythos 5, which ran no classifiers, Mythos 5.1 runs safeguards calibrated to the access program. Handle stop_reason: "refusal" on it as you would on Fable 5.1.
Can I switch a conversation between Fable 5.1 and Mythos 5.1? Yes, without losing reasoning. They are the only two models that can read each other’s thinking blocks.
Is Mythos 5.1 available on Amazon Bedrock? Yes, as anthropic.claude-mythos-5-1 in us-east-1, though it is not publicly listed. It is not available on Claude Platform on AWS.



