
Two Claude models launched on the same day, September 1, 2026, sharing every fact about them that actually determines how a model performs: the same weights, the same 1-million-token context window, the same $10-per-million-input and $50-per-million-output price. One of them, Claude Fable 5.1, you can start using in the next five minutes. The other, Claude Mythos 5.1, needs your organization to already be enrolled in a vetting program almost nobody outside cybersecurity and biotech has heard of.
That's the whole story, and the honest place to start is saying it plainly: for nearly everyone reading this, the real recommendation isn't Claude Mythos 5.1. It's Claude Fable 5.1, the generally available version of the exact same weights.
One note before anything else. Anthropic, like every frontier AI lab right now, ships new models, prices, and access programs on a timeline measured in weeks. Treat every number and every access detail below as accurate as of September 12, 2026, and confirm the current lineup, pricing, and eligibility directly on Anthropic's site before you act on anything here.
So if Mythos 5.1 isn't a better model in any way that would show up on a spec sheet, what is it, and why does it exist at all? That's the actual question this post is about.
Claude Mythos 5.1 at a Glance
Spec | Detail |
|---|---|
Maker | Anthropic |
Released | September 1, 2026 |
Model ID | claude-mythos-5-1 |
Built on | Same underlying weights as Claude Fable 5.1 |
Context window | 1,000,000 tokens |
Input price | $10 per million tokens |
Output price | $50 per million tokens |
Cache reads | $0.25 per million tokens (2.5% of base input) |
Availability | Invite-only via Project Glasswing; US organizations in Anthropic's Cyber Verification Program or Life Sciences Verification Program |
Notice how little separates the top half of that table from Fable 5.1's own spec sheet. The entire story is in the last row.
What Claude Mythos 5.1 Actually Is, and Why It's Gated
Here's the direct answer: Claude Mythos 5.1 is Claude Fable 5.1 with a different safeguard layer wrapped around the same underlying weights. Not a bigger model, not a retrained one, not one trained on different data. The same brain, with different rules about which requests it's allowed to answer without pushing back.
Specifically, Mythos declines fewer benign requests in two domains: cybersecurity and life sciences. A biosecurity researcher asking a detailed question about pathogen behavior, or a security engineer asking a detailed question about a specific vulnerability class, is more likely to get a direct, useful answer from Mythos than from Fable, which is tuned to err toward caution on requests that sit close to genuinely dangerous territory even when the person asking has a legitimate reason. Mythos can also identify software vulnerabilities for defensive purposes, a capability Fable's own safeguards are built to be more conservative about surfacing in detail.
Think of it less like two different products and more like the same car with the speed limiter set differently for two different drivers. Fable's limiter is calibrated for a general public that includes people with no way to prove they're not about to misuse the answer. Mythos's limiter is calibrated for an organization Anthropic has already checked, with a much narrower reason to loosen it: real professional work in exactly the two domains where "the model was too cautious" and "the model helped someone build something dangerous" are both realistic, costly outcomes.
That's also, honestly, why Mythos can't just be handed out the way Fable is. The specific capability being unlocked, useful, detailed reasoning about vulnerabilities and pathogens, doesn't distinguish between a defender and an attacker asking the same question. A safeguard loosened for one is loosened for both. Gating access isn't a marketing flourish here; it's the actual mechanism doing the work that model architecture alone can't.
What's Actually New in Mythos 5.1
Mythos 5.1 isn't Anthropic's first attempt at this. The lineage runs Claude Mythos Preview, then Claude Mythos 5, then Mythos 5.1, and it's worth knowing where each one sits today. Mythos Preview (claude-mythos-preview) launched under Project Glasswing, Anthropic's April 2026 cybersecurity collaboration with AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, and seven other founding partners. Anthropic's own model deprecation documentation confirms Mythos Preview is now deprecated, with a documented migration path to Mythos 5 (claude-mythos-5). Mythos 5.1 is the current generation, built on Fable 5.1's weights rather than an older base.
One small technical detail carries through the whole family: on Claude 4.7-and-later models, including Mythos Preview by name in Anthropic's own docs, the temperature, top_p, and top_k parameters return a 400 error if you set them to anything other than their default. Anthropic's guidance is to use prompting instead of sampling parameters to steer output, a real workflow change if you're migrating an older integration onto this generation.
A more interesting new detail: Claude Security, Anthropic's own internal security tooling, now runs on Mythos 5.1. Anthropic is willing to run its own defensive security work on the loosened-safeguard version rather than the general-release one, a small but genuine signal of how it rates the trade-off for its own use case. Access also comes with a real string attached: organizations approved for Mythos have to accept a 30-day data retention policy specifically for safety monitoring, longer than Anthropic's standard retention terms for most API use.
Worth noting too, since it undercuts any sense that Fable is the "weak" option here: Anthropic's own Mythos landing page states that Fable 5.1's biology safeguards already intervene on benign requests 85% less often than earlier Fable versions. The generally available model has been getting less trigger-happy on its own, independent of Mythos existing at all, which is a real reason the gap between "the model everyone can use" and "the model almost nobody can use" is narrower than the gating itself might suggest.
What the Benchmarks Say (and What Nobody Outside Anthropic Can Check)
This is the section where coverage of a model like this quietly becomes a vendor's press release with someone else's byline on it, so it's worth being direct about a structural fact first: independent labs can't benchmark a model they don't have access to. Claude Mythos 5.1 is available to a small set of vetted organizations under a data-retention agreement built for safety monitoring, not to the research groups, red teams, or evaluation firms that normally run independent tests on a new frontier model. That absence of outside verification isn't an oversight anyone forgot to fix. It's a direct consequence of the access model itself, and it holds for the entire time a model stays gated this way.
What does exist is Anthropic's own number, and it's about the predecessor, not this model. At Project Glasswing's April 2026 launch, Anthropic reported that Mythos Preview scored 83.1% on an internal vulnerability-reproduction benchmark, against 66.6% for Claude Opus 4.6, the general model it was compared to at the time. That's a real, specific, dated figure, worth stating plainly as what it is: a vendor-reported number, on an internally defined benchmark, about a now-deprecated model that Mythos 5.1 has since replaced. Nobody has published an equivalent, independently run number for Mythos 5.1 itself, and given the access model, nobody outside the vetted program currently can.
This isn't unique to Anthropic. OpenAI's directly equivalent model, GPT-5.6-Cyber, sits behind its own Daybreak Red vetting tier for almost identical reasons, and its own headline completion-rate numbers are OpenAI's internal evaluation too, with no independent replication published as of this writing. Two frontier labs, working independently, arrived at the same structural answer: a model this capable at finding software vulnerabilities gets access-gated rather than benchmarked in the open. That convergence is itself a data point worth taking seriously, separate from either company's specific numbers.
There's a smaller, quieter signal worth pointing out too. Anthropic's own model pricing and model deprecation pages list Fable 5.1, Fable 5, Opus 5, Opus 4.8, Opus 4.7, Sonnet 5, Sonnet 4.6, and Haiku 4.5 in their main comparison tables, current state and retirement date included for each. Mythos doesn't appear in that lineup table at all, not Preview, not 5, not 5.1. It shows up only as a footnote linking out to Project Glasswing wherever its price happens to be listed. That's a small thing, but it's consistent with everything else here: Mythos isn't positioned as a product competing for a spot in the regular lineup a developer scans when picking a model. It's infrastructure for a specific, vetted purpose, documented adjacent to the main model family rather than inside it.
What Claude Mythos 5.1 Costs
Here's the detail that actually surprises people once they see the pricing table: Claude Mythos 5.1 doesn't cost more than Claude Fable 5.1. Both run $10 per million input tokens and $50 per million output tokens, standard API pricing, identical to the cent. Cache writes cost $12.50 per million tokens for a 5-minute cache and $20 per million for a 1-hour cache on both models. Cache reads are the real standout: $0.25 per million tokens, just 2.5% of the base input price, a rate that applies only to Fable 5.1 and Mythos 5.1 among every current Claude model. Every other model in Anthropic's lineup, including Opus 5 and Sonnet 5, prices a cache read at 10% of base input, four times higher. Run either model through the Batch API and both drop to $5 per million input and $25 per million output, the standard 50% batch discount.
That flat pricing is worth pausing on, because it isn't how every gated security model in this category works. GPT-5.6-Cyber, OpenAI's closest equivalent, runs roughly three times its own general-purpose sibling's price once you account for API surcharges, a real premium layered on top of the approval requirement. Mythos 5.1 charges nothing extra at all. The barrier to using it isn't money. Anthropic isn't trying to make Mythos a premium product; it's trying to keep a specific capability out of hands it hasn't vetted, full stop, and the pricing reflects that the restriction is the whole point rather than a revenue lever.
Where It's Strong, Where It Falls Short
Where it's strong:
Answers benign, professional cybersecurity and life-sciences questions that Fable 5.1 is more likely to decline or hedge on, with no drop in underlying reasoning quality since the weights are identical.
Can identify software vulnerabilities for defensive purposes, a real capability Anthropic trusts enough to run its own Claude Security tooling on this model rather than the general-release one.
Same $10/$50 pricing and 1M-token context window as Fable 5.1, so approved organizations pay nothing extra for the loosened safeguards.
The 2.5% cache-read rate, shared with Fable 5.1 only, meaningfully cuts costs for any workload that reuses long context repeatedly.
Where it falls short:
Genuinely inaccessible to almost everyone: invite-only, US organizations only for now, and routed entirely through Anthropic, AWS, or Google Cloud account teams rather than any self-serve signup.
No independent benchmark of Mythos 5.1 itself exists, and the access model that gates the product also structurally prevents that from changing anytime soon.
Requires accepting a 30-day data retention policy for safety monitoring, a real trade-off for organizations with their own strict data-handling requirements.
Doesn't appear in Anthropic's own main model-lineup and deprecation tables the way Fable 5.1, Opus 5, Sonnet 5, and Haiku 4.5 do, making it easy to miss entirely if you're not already looking for it.
How to Actually Get Claude Mythos 5.1
Start with the honest baseline: there is no signup form. Claude Mythos 5.1 is gated behind Project Glasswing, and the two specific doors into it are Anthropic's Cyber Verification Program, for defensive security work, and its Life Sciences Verification Program, for advanced biology research. Both are currently restricted to organizations based in the United States, though Anthropic says it's working to expand access beyond that.
If either program sounds like it applies to your organization, the actual next step is contacting your Anthropic account team, or your AWS or Google Cloud account team if that's how you already buy Claude. There's no self-serve application you fill out and wait on; it runs through an existing or new enterprise relationship, which in practice means this is built for organizations, not individual developers browsing an API console on a weekend.
Expect the process to include real verification, not a checkbox. Anthropic vets the organization itself, and access comes with that 30-day retention policy for safety monitoring attached, a condition worth weighing seriously if your organization has its own data-handling constraints that don't normally allow that kind of retention.
One timing nuance worth knowing rather than assuming: the two programs aren't at the same stage. Anthropic describes the Life Sciences Verification Program as an invite-only beta already granting Mythos access, with reduced biology safeguards, to advanced life-sciences researchers today. The Cyber Verification Program, by contrast, is described as adding access to Mythos models "in the near future," a program built to grant exceptions to security professionals whose legitimate work is otherwise restricted by standard safeguards. If you're applying on the cybersecurity side specifically, go in expecting a program still rolling out rather than one fully live end to end.
It's also worth knowing where this infrastructure came from. Project Glasswing launched April 7, 2026, as an industry collaboration between Anthropic and eleven founding partners, including AWS, Apple, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks, built around the idea that AI models capable of finding software vulnerabilities should help defenders first. Participating organizations get access to gated Mythos-class models across the Claude API, Amazon Bedrock, Google Vertex AI, and Microsoft Foundry, plus a share of $100 million in cumulative usage credits Anthropic committed at launch. That collaboration is the backbone the Cyber Verification Program now sits on top of.
Who Should Use It, Who Should Use Fable 5.1 Instead
Pursue access to Claude Mythos 5.1 if you work defensive cybersecurity or advanced life-sciences research at an organization that can clear a real vetting process, and you're regularly hitting Fable 5.1's safeguards on requests you can document as legitimate. That's a narrow, specific group, and if you're not confident you're in it, you're very likely not the intended user right now.
Use Claude Fable 5.1 instead if you're doing anything else, which describes almost every reader of this post. Same weights, same 1M context window, same $10/$50 pricing, and a biology safeguard layer that already declines 85% fewer benign requests than earlier Fable versions. For the overwhelming majority of use cases, even ones that brush up against security or biology topics in a normal, legitimate way, Fable 5.1 is not meaningfully behind Mythos in capability, only in how cautious it is about a narrow slice of requests most people never send. If you want to see how Fable 5.1 stacks up against the rest of Anthropic's current lineup, including Opus 5, our Claude Opus 5 review covers the full family comparison this post deliberately doesn't repeat.
Verdict: The Model You Probably Already Have
Here's the honest verdict, and it's a different shape than most model reviews on this site: the interesting thing about Claude Mythos 5.1 isn't the model. It's identical, weight for weight, to one you can already use. The interesting thing is what Anthropic decided was worth gating, and why a company would ship two products from the same brain and lock only one of them behind a vetting program.
That decision holds up under scrutiny better than a cynical read might expect. The specific capability being unlocked, detailed help with vulnerabilities and pathogens, is exactly the kind of dual-use capability where "helps the defender" and "helps the attacker" aren't separable by the model itself, only by who's asking and why. Restricting it to organizations Anthropic has already vetted, at no pricing premium, is a defensible way to handle that, even if it's also true that nobody outside the vetted group can independently confirm Anthropic's own numbers about it, and won't be able to for as long as the access model stays this narrow.
For almost every reader, the actual, actionable takeaway is simple: go use Claude Fable 5.1. It's the same model, generally available, already quite good at not over-refusing benign questions, and priced identically to the version you probably can't get anyway. Claude Mythos 5.1 matters as a policy decision worth understanding, not as a product worth chasing.
Curious to see how it performs?
Try
Claude
Now
GOT ANY QUESTIONS LEFT?
What is Claude Mythos 5.1?
How do I get access to Claude Mythos 5.1?
What is the difference between Claude Mythos 5.1 and Fable 5.1?
How much does Claude Mythos 5.1 cost?


