Skip to content
Skip to content

Independent e-magazine

the OUTSPOKEN digest

Anthropic Shipped the Same Model Twice Under Two Names, and the Difference Is Who Is Allowed to Use It

Fable 5.1 and Mythos 5.1 are the same model with different safeguards. One is generally available. The other is restricted to a set of American organisations through trusted access programmes, for work in cybersecurity and the life sciences.

Outspoken Digest Technology Desk

Tuesday, September 1, 2026/4 min read

A three dimensional protein model rendered in a virtual environment at Idaho National Laboratory, where researchers can examine and manipulate the structure
Photo: Idaho National Laboratory via Wikimedia Commons (CC BY 2.0)

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on Tuesday. They are the same model. What separates them is the set of safeguards each one runs and, following from that, who is permitted to use which.

Fable 5.1 is generally available. Mythos 5.1 goes out through trusted access programmes, with safeguards built for work in cybersecurity and the life sciences, and is currently limited to a set of organisations in the United States reached through government partnership programmes.

The pricing change is the part that will actually move behaviour

Base rates did not move: 10 dollars per million input tokens, 50 per million output.

What changed is the cache read price, cut by 75 per cent to 25 cents per million tokens. Anthropic puts the effect at roughly 25 per cent cheaper for typical workloads and up to about 45 per cent for heavily agentic work.

That spread between 25 and 45 is not marketing noise. It tells you exactly which kind of work the company expects to grow. A cache read happens when a system sends the same long prefix again: the same instructions, the same codebase, the same case file, on turn after turn. Ordinary chat barely touches it. An agent working through a long task touches almost nothing else, because every step re-sends everything that came before.

Cutting that price by three quarters is a decision that agents, not conversations, are where the tokens are going.

The capability claims, with the caveats attached

On Terminal-Bench 4.0, a coding and terminal-use benchmark, Anthropic reports 55.8 per cent against 42.0 for Fable 5. That is a large jump on one benchmark, from the vendor, and benchmarks are the weakest form of evidence in this field precisely because everyone optimises against them.

The scientific claims are more interesting and harder to check. The company reports designing protein binders with ten times the binding affinity of a competing approach, and a hit rate of 50 per cent against a typical 10 to 15, plus GPU speedups of up to 2.5 times in computational biology work.

Take those as what a vendor says its model did on problems the vendor chose. They are still worth noting, because the direction is consistent: the pitch has moved from writing text to doing laboratory and engineering work, and that is the direction that makes the access question below matter.

Why two names for one model

Because capability and permission have come apart, and the industry has not decided what to do about it.

A model good enough to design a protein binder is good enough to design a dangerous one. A model good enough to find a vulnerability is good enough to exploit it. There is no version of the weights that is excellent at defence and incapable of offence, because they are the same skill pointed in different directions.

So the split is not in the model. It is in the classifiers wrapped around it and in the contract you sign to reach it. Anthropic reports 60 per cent fewer false positives on the cybersecurity safeguards, which is the number a security team cares about most: a safety system that refuses legitimate work is a safety system that gets routed around.

We wrote about this two tier structure when the previous generation introduced it, in the debate over two tier access, and about how it arrived in the Fable and Mythos class launch. The arguments have not changed. The stakes have gone up, because the capability claims have.

The geography is the uncomfortable part

Mythos 5.1 is currently available to a set of American organisations, through government partnership programmes.

Read plainly, that means the more permissive configuration of a frontier model is reachable by institutions in one country and not by their equivalents elsewhere. A hospital research group in the Gulf, a European biosecurity lab and an American national laboratory are not being offered the same tool, and the difference is not technical.

There is a defensible case for that. Safeguards need somebody accountable on the other end, verification takes relationships, and relationships start where the company and its regulators are. There is also an obvious cost, which is that the rest of the world gets the safer model and the slower science, and did not vote on the arrangement.

It is also a reminder that this company's relationship with its own government is not simple. A federal judge ruled last week that the Defense Department unlawfully retaliated against Anthropic for refusing to drop its usage limits, which we covered in the ruling on the supply chain risk label. The same firm now distributes its least restricted model through government partnerships. Both of those are true.

What developers should read the release notes for

Two changes that will break existing code rather than improve it.

Forced tool use is gone: asking the model to call a specific tool, or any tool, is now rejected outright rather than obeyed. Anything built on that pattern has to move to asking politely in the prompt and validating what comes back.

And thinking is now bound to the turn that produced it, so a harness that rewrites its own conversation history breaks. Systems that edit earlier turns, or compact them, need to become append only. Accounts created from 31 August are already subject to it.

Both are the same lesson in different clothes. The model is being handed more autonomy, and the API is closing the routes by which a developer could quietly rewrite what the model was told it had already decided.

Published in The Outspoken Digest

Editorial desk

Outspoken Digest Technology Desk

Software, hardware, artificial intelligence and what they change for everyone else.

Newsletter

The Digest, in your inbox

One edition, sent when it is ready. No noise, and your address is never passed on.

We send a confirmation first. One click to leave, always.

Share this story

the OUTSPOKEN digest

Beyond boundaries. Independent stories on technology, culture, and the trends shaping how we live.