Added to our archive on 1 October 2026. This report is dated to the day of the event.

Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 on 1 September 2026 without touching the list price: USD 10 per million input tokens and USD 50 per million output tokens, the same as Fable 5. One line on the bill did change. Cache reads, the charge for reading back a prompt that has already been stored, fell from USD 1.00 to USD 0.25 per million tokens.

The two releases are one model sold under two sets of safeguards. Fable 5.1, the version anyone can use, now accepts security work that its predecessor often turned away: it may search software for vulnerabilities, but it still will not write exploits for them. Mythos 5.1, with lighter safeguards, stays with a small group of vetted organisations in the United States.

  • What: Claude Fable 5.1 (open to all customers) and Claude Mythos 5.1 (restricted), one model under two levels of safeguards.
  • Price: USD 10 and USD 50 per million input and output tokens, unchanged; cache reads cut 75 percent to USD 0.25.
  • Why it matters: defenders get bug hunting in the public model, and long agent runs get cheaper.

Bug hunting yes, exploits no

Anthropic's announcement says Fable 5.1 "can now be used to discover software vulnerabilities", though not to develop exploits for them. The company expects Claude Code users to see "an average of around 60% fewer interventions per session from our cyber safeguards, relative to the previous safeguards on Fable 5."

The line falls at dual use work, meaning tasks that can serve defence or attack. Those requests still go to Anthropic's Opus models, and the company lists "penetration testing, exploit generation, and binary-based vulnerability scanning." In the API, a declined request can be retried automatically on another model; for Fable 5.1 the developer documentation lists Claude Opus 4.8 and Claude Opus 5 as the permitted fallbacks.

The biology rules loosened as well. Anthropic says its latest biology safeguards for Fable 5.1 and Fable 5 "fire 85% less often for benign requests related to elementary biology and medical questions."

One model, two doors

Claude Fable 5.1 and Claude Mythos 5.1 are the same model, but with different levels of safeguards.
Anthropic, release announcement, 1 September 2026

The developer documentation offers Mythos 5.1 "only to approved customers in Project Glasswing", the restricted programme that also carried Mythos 5. The announcement adds two trusted access routes. The Cyber Verification Program gives defensive security teams certain Opus and Sonnet class models with reduced cyber safeguards and will add Mythos class models "in the near future". The Life Sciences Verification Program lets researchers use Mythos 5.1 with safeguards designed for professional research, while all other safeguards stay in place; Anthropic enrolled the first participants "in partnership with the US government".

For now, the announcement says, Mythos 5.1 "is only available to a set of US organizations", and Anthropic is working with the US government to widen that circle. The Next Web pointed out that this leaves European cyber defenders and life scientists outside the programmes for now.

The discount sits in the cache

Prompt caching lets a developer store a long prefix, such as a codebase or a set of instructions, and pay a lower rate each time the model reads it again. On Fable 5.1 a cache read costs 0.025 times the base input price, against 0.1 on other Claude models, the documentation says, so long agent sessions that keep rereading a cached prefix pay a quarter of the Fable 5 rate. Cache writes are unchanged, and batch jobs cost USD 5 and USD 25.

75%
Cut in the Fable 5.1 cache read price, from USD 1.00 to USD 0.25 per million tokens. Anthropic, 1 September 2026.

Anthropic estimates that Fable 5.1 will cost about 25 percent less than Fable 5 on typical workloads and up to about 45 percent less on highly agentic work. Those are company estimates. On Anthropic's own tests, which are vendor reported, Fable 5.1 scored 55.8 percent on the Terminal-Bench 4.0 coding test against 42.0 percent for Fable 5, the company said; MarkTechPost reported the same 55.8 percent figure.

What developers have to change

The model ID is claude-fable-5-1 (anthropic.claude-fable-5-1 on Amazon Bedrock). Anthropic made it available on launch day "on all platforms", including the Claude apps, the Claude API and the Amazon, Google and Microsoft clouds, as MacRumors also reported. Like Fable 5, it has a one million token context window, up to 128,000 output tokens and adaptive thinking that cannot be switched off.

Three changes can break existing code. Forced tool use, where a request makes the model call one specific tool, now returns a 400 error. Older models cannot read Fable 5.1's thinking blocks. And editing anything that came before a thinking block, whether the system prompt, the tool list or an old message, invalidates it. For accounts created on or after 31 August 2026 the API rejects such requests by default.

Anthropic presents that last rule as a defence against distillation, the practice of copying a model's abilities by training another model on its outputs. "This closes off a common, publicly documented distillation technique, which allowed distillers to illicitly extract Claude's thinking," the company wrote. Existing accounts are not affected yet, but the change will apply to all users with future model releases.

New beta features let developers change the effort setting from one message to the next and add system messages that apply to a single turn. Fable 5.1's text also carries an invisible watermark, which Anthropic added after signing the EU AI Act's code of practice on transparency; a detection API is in private preview for regulators, media, researchers and other eligible groups.

What happened next

On 22 September, Anthropic released Claude Opus 5.5, which it says "performs at the level of Claude Fable 5.1 on most work" at USD 4 and USD 20 per million tokens. From 24 September, Fable 5.1 refusals that arrive before any output are billed when they fall in a category with low volumes of false positives, a rule the documentation says is meant to disrupt attempts to get around Anthropic's safeguards at scale.