Claude Mythos 5.1 shipped alongside Fable 5.1 on September 1, 2026, and it is the same underlying model. The difference is not weights or training. It is safeguards. Mythos runs with more permissive ones, and Anthropic will not sell it to you on request: access runs through two vetting programmes, the Cyber Verification Program for defensive security work and the Life Sciences Verification Program operated in partnership with the US government.

The gap those safeguards create is measurable. On Terminal-Bench 4.0, Fable 5.1 scores 55.8 percent. Mythos 5.1, the same model with fewer restrictions, scores 60.9 percent.

Two matte platforms at different heights representing two safeguard tiers
One model, two safeguard tiers, and a five point gap on the same benchmark.

Two tiers of the same model

This is worth stating plainly because it is easy to misread as a bigger or better model. It is not. Per Anthropic's announcement, Mythos is Fable operating under more permissive safeguards, aimed at work where refusing too often is itself the failure mode.

How the two September 1 releases differ
Fable 5.1Mythos 5.1
AvailabilityGenerally availableVetted programmes only
SurfacesClaude.ai, API, AWS, Google Cloud, AzureThrough CVP or LSVP
SafeguardsStandardMore permissive
Terminal-Bench 4.055.8%60.9%
Intended workCoding and knowledge workDefensive security, life sciences

The five point benchmark gap is the honest measure of what safety tuning costs on this kind of task. Anthropic is unusual in publishing it rather than quietly shipping one number.

Why a separate tier exists at all

For most creative and building work, a model that declines an ambiguous request is a minor annoyance. For a defensive security team, it is the whole problem. Vulnerability research reads almost exactly like attack preparation, and a model trained to refuse the second will refuse the first. The same bind applies in life sciences, where legitimate biology queries pattern-match to the material a model is specifically built to decline.

Anthropic's answer is to keep the general model conservative and move the permissive one behind identity verification. Fable 5.1 also gets 60 percent fewer false positives in its cyber safeguards and fewer false refusals on benign biology and medical queries, so the general tier improved too. Mythos exists for the cases where even that is not enough.

This is a notable reversal in posture. Anthropic previously pulled Mythos access entirely, a decision we covered when the models were restored, and the critical-infrastructure debate around Mythos has been running for months. Formal verification programmes are the structure that came out of it.

Engraved matte card representing an access gate with a verification step
Access moved from a purchase decision to an identity-verification programme.

The refusal problem, concretely

It helps to see why a general-purpose safeguard fails these two fields specifically.

A defensive security researcher asks a model to explain how a class of memory-corruption bug is triggered, so they can find it in their own code. An attacker asks a nearly identical question. The text of the request carries almost no signal about intent, so a model tuned to refuse the second refuses the first, and the defender loses a tool the attacker never needed.

Life sciences has the same shape. A researcher asking about pathogen biology to design a countermeasure phrases the question much like someone who should not get an answer. Anthropic has written separately about improving the biology safeguards and about expanding support for scientists, which is the general-tier half of the same problem.

Verification sidesteps the text entirely. Rather than trying to infer intent from a prompt, Anthropic verifies the organisation once and then relaxes the safeguards for that account. It moves the trust decision from per-request guessing to a one-time identity check, which is the only place it can realistically be made well.

Sequential matte nodes representing a one-time verification gate ahead of a loop
Trust is established once at the gate rather than re-inferred on every request.

Enterprise Frontier Safeguards

The second half of the announcement is an architecture called Enterprise Frontier Safeguards, and it addresses a genuine deadlock: safety monitoring normally requires Anthropic to retain data, while many organisations require that nothing is retained.

EFS resolves it by keeping monitoring data inside infrastructure the customer controls, on AWS, Google Cloud, or Azure, so zero data retention and safety monitoring stop being mutually exclusive. Anthropic lists support for Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google Agent Platform, and Microsoft Foundry, rolling out in phases starting in autumn 2026. There is a request form and a separate write-up of the architecture.

Note the tense. EFS is announced with a phased rollout, not shipped today. If it is load-bearing for a procurement decision, get the timeline in writing rather than planning against the announcement.

What this means if you are not a vetted lab

Most readers will never touch Mythos, and that is the point of the design. Three things still matter.

The general model got the safety improvements too. A 60 percent reduction in cyber-safeguard false positives lands in Fable 5.1, which is generally available. If you previously hit refusals on legitimate security or biology work, retest before assuming you need special access.

Published tier gaps are a good precedent. Anthropic put a number on what its safeguards cost on a benchmark. That is the kind of disclosure worth rewarding, because the alternative is a single score and no way to reason about the trade.

Zero-data-retention may stop blocking deals. If EFS lands as described, the standard objection that safety monitoring requires vendor-side retention goes away, which matters for anyone building client work under a data-handling agreement. That connects to the retention questions raised in the Bedrock data-sharing coverage.

How to apply, and whether you should

1. Check that you actually qualify. CVP is for defensive security work and LSVP is a life-sciences programme run with the US government. Neither is a faster tier for general development.

2. Test on Fable 5.1 first. With false positives down 60 percent, the refusals that motivated your application may already be gone. Establish that before starting a verification process.

3. Apply through the portal. The CVP application is the front door for the cyber programme.

4. Treat EFS as a separate request. It has its own form and its own phased timeline, and it is not bundled with model access.

Frequently asked questions

Is Mythos 5.1 a bigger model than Fable 5.1?

No. It is the same underlying model running with more permissive safeguards. The difference is policy, not architecture or scale.

How much better does Mythos actually perform?

On Terminal-Bench 4.0 it scores 60.9 percent against Fable 5.1's 55.8 percent, a gap of about five points that reflects what the stricter safeguards cost on that benchmark.

Can I get access to Mythos 5.1?

Only through the Cyber Verification Program for defensive security work or the Life Sciences Verification Program run with the US government. There is no general availability and no paid upgrade path.

What is Enterprise Frontier Safeguards?

An architecture that keeps safety monitoring data inside infrastructure the customer controls on AWS, Google Cloud, or Azure, so an organisation can have zero data retention without giving up safety monitoring. It rolls out in phases starting autumn 2026.

Is EFS available now?

No. It is announced with a phased rollout beginning in autumn 2026 across Claude Code, Claude Enterprise, the Claude Platform, Amazon Bedrock, Google Agent Platform, and Microsoft Foundry. Confirm timing before depending on it.

I hit refusals on security work. Do I need Mythos?

Probably not. Fable 5.1 ships with 60 percent fewer false positives in its cyber safeguards and fewer false refusals on benign biology and medical queries. Retest on the generally available model before pursuing verification.