Claude Fable 5 and Mythos 5: Two Models, Two Access Tiers

Anthropic released guarded Fable 5 to general users and restricted Mythos 5 to approved partners, with classifiers covering cyber, biology and distillation risks.

One model, two names, two audiences

On June 9, 2026, Anthropic released two models built on the same underlying system. Claude Mythos 5 is the unrestricted version, made available to organizations already approved through Anthropic's invitation-only critical infrastructure program. Claude Fable 5 is described as Mythos-class capability with safety guardrails applied, and it is the one available to the general public through the Claude API and subscription plans. [1][3]

Atlas interpretation: The naming makes the safety trade explicit rather than hiding it inside a version number. Most vendors ship one model and describe its limits in a system card; Anthropic shipped two names for what it says is the same underlying capability, so the guardrail itself becomes part of the product description rather than a footnote. [1][3]

The public release follows a model Anthropic held back

Mythos did not start as a product decision. A preview version found more than 10,000 high and critical severity vulnerabilities in its first month, including a seventeen-year-old remote root hole in FreeBSD that it exploited without assistance, and Anthropic kept it out of general release, restricting it instead to Project Glasswing, an invitation-only program for critical infrastructure operators. Cloudflare, one of the program's participants, reported the model chaining low-severity bugs into working exploits with compiling proofs, rather than stopping at describing a bug the way earlier models did. [1]

Atlas interpretation: Fable 5's guardrails are the direct answer to that history: the same offensive security capability that justified restricting Mythos to a vetted list of infrastructure operators is exactly what the cybersecurity classifier in Fable 5 is built to catch before it reaches a general user. [1]

What the guardrail actually does

Anthropic built three classifier systems into Fable 5, covering cybersecurity exploitation, biology and chemistry research with weapons potential, and attempts to extract the model's own capabilities through distillation. A flagged query is deflected to Claude Opus 4.8 rather than answered by Fable 5 or refused outright. Anthropic said the guardrails activate in under 5% of sessions and that external red-teaming totaling more than 1,000 hours found no universal jailbreak. TechCrunch, citing Anthropic's own reporting, put the figure at roughly 95% of sessions running entirely within the model's ordinary capabilities, which is the same number stated the other way. [1][2][3]

The classifier system also changes billing and data handling. When a request is routed to Opus 4.8, the user is charged Opus rates rather than Fable rates for the deflected portion of the conversation, and Anthropic requires 30-day retention of inputs and outputs for every Fable and Mythos user, including customers who had previously negotiated zero-retention terms, so it can review false positives and look for new misuse patterns. [2][3]

Atlas interpretation: A guardrail that changes what a customer pays and how long their data is kept is a different commitment than a refusal message, and it is worth noting that the figures behind it, the session percentage and the red-team hours, come from Anthropic itself. No independent audit of either number had been published at the time of this review. [1]

Availability, pricing, and the claimed capability gains

Fable 5 launched free within Pro, Max, Team, and enterprise subscription plans through June 22, after which usage past plan limits billed at $10 per million input tokens and $50 per million output tokens, twice Claude Opus 4.8's rate. It reached Amazon Bedrock and the Claude Platform on AWS the same day, initially in the US East and Stockholm regions for Bedrock and more broadly on the Claude Platform, with access to Bedrock expanding gradually and existing Bedrock customers given priority. Mythos 5 stayed restricted to Glasswing partners and a small group of biology researchers. [1][2]

Anthropic's own capability claims, echoed by named customers, included Stripe describing a 50-million-line Ruby codebase migration completed in a day, and Cognition, Hebbia and other partners reporting top scores on their respective evaluations. Cursor's Michael Truell said the model opened up long-horizon problems earlier models could not sustain. TechCrunch's independent write-up repeated several of the same customer-supplied figures, including analytics firm Hex's reported 90% score on a complex analytical benchmark, without an independent benchmark of its own. [1][3]

Atlas interpretation: Every capability figure attached to this launch, the Stripe migration, the Hex score, the FrontierCode result, comes from a vendor or a named customer with a reason to say the model performed well, and none of the coverage available at review time reproduced a benchmark independently. That does not make the claims false, but it means the launch is documented almost entirely from the inside. [1][3]

Access changed three days later

On June 12, a US Commerce directive suspended foreign-national access to Fable 5 and Mythos 5. That later restriction belongs to a separate policy event, dated to the directive rather than the model release. [4]

Sources

  1. Claude Fable 5 and Claude Mythos 5

    Anthropic · Jun 9, 2026

  2. Anthropic Claude Fable 5 on AWS: Mythos-class capabilities with built-in safeguards now available

    Amazon Web Services · Jun 9, 2026

  3. Anthropic's Claude Fable 5 is a version of Mythos the public can access today

    TechCrunch · Jun 9, 2026

  4. Statement on the US government directive to suspend access to Fable 5 and Mythos 5

    Anthropic · Jun 12, 2026