← All posts / Models

One Model, Two Masks: Anthropic Ships Claude Fable 5.1 and Claude Mythos 5.1

Anthropic's Fable 5.1 and Mythos 5.1 share identical weights but split safeguards — with a doubled science benchmark score, 60.9% on Terminal-Bench 4.0, and 75% cheaper cache reads.

One Model, Two Masks: Anthropic Ships Claude Fable 5.1 and Claude Mythos 5.1

Anthropic has released Claude Fable 5.1 and Claude Mythos 5.1, and the most important thing to understand about them is what they are not: they are not two models. They are one frontier model shipped under two names, with two different safeguard configurations. Fable 5.1 is the generally available version, wrapped in Anthropic’s standard protections. Mythos 5.1 is the exact same model with more permissive safeguards, restricted to vetted cyberdefenders and life scientists through Anthropic’s trusted access programs. One set of weights, two masks — and a release strategy that says a great deal about where frontier AI deployment is heading in late 2026.

The numbers: a generational jump, not an incremental one

Start with the science result, because it is the headline. On Terminal-Bench-Science 0.1, an agentic benchmark that measures a model’s ability to actually conduct scientific research in a live environment — running experiments, interpreting results, iterating — Fable 5.1 scores 52.6%. Its predecessor Fable 5 scored 24.7%. That is not a polish update; that is more than doubling the score in a single generation, and it comfortably clears the 29.0% posted by the strongest comparable competitor reported in Research World’s coverage.

The coding story is similar. On Terminal-Bench 4.0, which evaluates agentic software engineering in real terminal environments, Fable 5.1 reaches 55.8%, up from 42.0% for Fable 5 and ahead of Opus 5’s 52.3%. And here the split-model strategy shows its teeth: Mythos 5.1, running the same weights with looser restrictions on sensitive domains, scores 60.9% on the same benchmark. Five points of pure headroom unlocked not by training a bigger model but by relaxing guardrails for a vetted audience.

Pricing is the second headline. Via Anthropic’s API, Fable 5.1 is listed at $10.00 per million input tokens and $50.00 per million output tokens, with reused prompt prefixes billed at a discount. More significantly, VentureBeat reports a 75% cost reduction on Fable cache reads — a change aimed squarely at agentic workloads, where the same large codebases and system prompts get re-read on every step of a long task. The Decoder estimates that for typical coding and research workflows, the effective cost drops by up to 45%. For teams running long-horizon agents, cache economics matter as much as raw benchmark scores.

Why ship one model as two?

The split dates to June 2026, when Anthropic first introduced Fable 5 as a “Mythos-class” model wrapped in standard safeguards. The logic: frontier capability in domains like cybersecurity and the life sciences is inherently dual-use. The same model that helps a pharmaceutical researcher design a protein synthesis pathway could help someone with worse intentions. Rather than shipping a single model that is either too restricted for professionals or too loose for the general public, Anthropic segments at the safeguard layer.

Fable 5.1 carries the full default protection stack and is available to everyone through the standard API and Claude products. Mythos 5.1 keeps identical weights but relaxes refusals and content filters in specific professional domains. Access is gated through two channels: a vetting program for cyberdefenders, and the Life Sciences Verification Program, which Anthropic describes on its Mythos page as the route for qualified life-science researchers. Per the system card, direct access to Mythos 5.1 is “limited to vetted” individuals and organizations — identity verification, institutional affiliation, and use-case review are all part of the pipeline.

This is effectively a tiered-trust model of deployment. It also happens to be a subtle competitive weapon: Anthropic can tell enterprise customers “our safest model and our most capable model are the same model,” a line neither a purely-open nor a purely-restricted competitor can offer.

The context: a cyber-AI arms race

The launch does not exist in isolation. On the same news cycle, Research World reported that OpenAI says its Astra models have crossed a “critical cyber threshold” — a milestone the industry has been watching since the 116-company joint letter in late August warned that AI-enabled cyberattacks will grow far more capable. The Hacker News noted that Google, Anthropic, and OpenAI have all unveiled dedicated cyber AI models, safeguards, and access programs within the same window. When every frontier lab simultaneously ships defensive-capability models with restricted access, the signal is clear: offensive cyber capability in general-purpose models is no longer theoretical, and labs are racing to make sure the defense side of the ledger gets the same firepower — into the right hands.

The caveats: benchmarks versus trust

The community reaction has been notably more skeptical than the press coverage. On Reddit’s r/ClaudeAI, the top threads about the launch repeat a single refrain: “Nobody believes the benchmarks.” The reference point is the launch of Opus 5, which posted strong benchmark numbers but suffered from real-world performance complaints — a pattern that has made Anthropic’s user base warier of score-based marketing. Terminal-Bench results are Anthropic-reported, not independently verified, and the gap between 55.8% and Mythos’s 60.9% will inevitably raise questions about how much general-purpose users are leaving on the table.

There are also open governance questions. Who audits the Mythos vetting process? How quickly can a bad actor launder access through a legitimate-seeming institution? Anthropic’s system card addresses safeguards but the trusted-access programs are young, and a model this capable behind lighter guardrails is exactly the kind of asset that sophisticated threat actors target.

What it means

For practitioners, the practical takeaways are straightforward. If you are building agentic coding or research systems, Fable 5.1’s combination of doubled science capability, a 13.8-point Terminal-Bench jump, and 75% cheaper cache reads makes it one of the strongest price-performance propositions at the frontier right now. If you work in cyberdefense or the life sciences and can pass vetting, Mythos 5.1 offers measurably more capability for exactly the domains where refusal-happy models are most frustrating.

For the industry, the deeper significance is architectural. Anthropic is betting that the future of frontier deployment is not one model for everyone, but one model with multiple trust tiers — capability parity between the safe and the specialized, with access control doing the work that model training used to do. If the bet pays off, expect every major lab to copy the pattern. If the Mythos program leaks, expect the pendulum to swing hard the other way.