Claude Mythos 5
Claude Mythos 5 is a large language model released by Anthropic on June 9, 2026 as the restricted top tier of its Claude family. It belongs to a new "Mythos-class," which Anthropic describes as "a tier of Claude models that sit above our Opus class in capability." [1] Mythos 5 shares the same underlying model as its generally available sibling, Claude Fable 5; the two versions differ only in their safety measures. Mythos 5 runs with certain dual-use safeguards lifted and is available only to a small set of approved organizations, while Fable 5 carries additional safeguards and is open to the public. [1][2]
Anthropic released Claude Mythos 5.1 on September 1, 2026, as the next version of the restricted line. The successor remained limited to vetted organizations and used the API identifier claude-mythos-5-1.[10][12]
What is Claude Mythos 5?
Claude Mythos 5 is the higher-access version of Anthropic's Mythos-class model line, announced alongside Claude Fable 5 on June 9, 2026. [1] It was released through a cybersecurity effort called Project Glasswing as an upgrade to Claude Mythos Preview, the restricted model Anthropic began deploying in April 2026; Anthropic's developer documentation describes Mythos 5 as joining Mythos Preview inside the program rather than replacing it outright. [1][3] Anthropic positions Mythos-class models above the Opus class, which had been represented by Claude Opus 4.8. The company reports strong results in software engineering, knowledge work, vision, and scientific research, and says the models can work autonomously for longer than any previous Claude release. [1]
Restricted availability does not mean unmeasured. Anthropic's system card reports Mythos 5 as the primary column of its capability tables, giving it 95.5% on SWE-bench Verified, 80.3% on SWE-bench Pro, 88.0% on Terminal-Bench 2.1, and 94.1% on GPQA Diamond, each averaged over five trials. [4] The corresponding public Fable 5 figures are slightly lower: 95% on SWE-bench Verified, 80% on SWE-bench Pro, and 84.3% on Terminal-Bench 2.1, the last of these with 20.9% of trials hitting a safety refusal and falling back to Claude Opus 4.8 for the rest of the trajectory. [4] All of these are Anthropic's own reported numbers rather than independent measurements, and outside reviewers note that the two configurations land within roughly one to three points of each other on most evaluations. [8] For the majority of ordinary use they converge: Anthropic states that for the more than 95% of Fable 5 sessions that involve no safety fallback, "Fable 5's performance is effectively the same as that of Mythos 5." [1]
How is Mythos 5 different from Claude Fable 5?
Fable 5 and Mythos 5 are the same underlying model. As Anthropic puts it, "the safeguards are what distinguish the two models." [1] The names reflect this relationship: Fable comes from the Latin fabula ("that which is told"), which is akin to the Greek mythos. [1]
Claude Fable 5 is the Mythos-class model that Anthropic has "made safe for general use." It runs safety classifiers that detect high-risk requests in specific domains and, when triggered, route the response to Claude Opus 4.8 instead of answering with the full Mythos-class model. Anthropic tuned these classifiers conservatively so they activate, on average, in fewer than 5% of sessions, and users are told whenever a fallback occurs. [1] Claude Mythos 5 is the same model with those safeguards "lifted in some areas," giving approved users direct access to the frontier capabilities that Fable 5 holds back. [1]
Both versions carry the same price, $10 per million input tokens and $50 per million output tokens, which Anthropic says is less than half the price of Claude Mythos Preview. [1][3]
Who can access Claude Mythos 5?
Access to Mythos 5 is limited to vetted organizations rather than the general public. [2][3] At launch it was available to cyberdefenders and critical infrastructure providers through Project Glasswing, which Anthropic runs in collaboration with the US government; organizations that already had Claude Mythos Preview could upgrade to Mythos 5. [1][2] The program was not tiny by then. Anthropic began Glasswing in early April 2026 with roughly 50 partners, and on June 2, 2026 extended it by approximately 150 new organizations based in more than 15 countries, adding power, water, healthcare, communications, and hardware operators along with maintainers of widely depended-on codebases. [7] The 150 figure is an increment, not a total: membership after that expansion was on the order of 200.
Anthropic also described trusted access programs that let cybersecurity organizations apply in a more systematic manner and that enroll biology researchers from a range of life science organizations. [1] Its announcement is inconsistent about which model the biology track uses, listing Mythos 5 with biology and chemistry safeguards lifted in the availability section while the section on trusted access says the program "will provide access to Fable 5 with the biology and chemistry safeguards removed (but the cyber safeguards still in place)." [1]
Use of Mythos 5 is governed by a 30-day data retention policy for safety monitoring. Anthropic says it will not use this traffic to train new Claude models "or for any non-safety-related purpose." [1]
Access was interrupted for most of June 2026. On Friday, June 12, 2026, the US government applied export controls to Fable 5 and Mythos 5 requiring Anthropic to restrict access by foreign nationals; unable to verify nationality in real time, the company suspended access to both models for all users. [5] Anthropic says the directive followed an Amazon research report describing a technique for prompting Fable 5 to identify software vulnerabilities. That characterization is disputed by Katie Moussouris of Luta Security, whom Anthropic asked to assess the report and who concluded the behavior was routine defensive security work rather than a guardrail bypass. [6] The controls were lifted on June 30, 2026. [5] Anthropic restored Mythos 5 to a set of US organizations after US government approval on June 26, and restored Fable 5 globally on July 1. [5] Mythos 5 itself remains restricted to vetted US organizations through Project Glasswing, and Anthropic says it is still negotiating broader domestic and international access through the program. [5][6]
Why is access to Mythos 5 restricted?
The restriction reflects the dual-use nature of the model's strongest capabilities. Anthropic notes that advanced use of frontier models is often dual-use: the same cybersecurity and biology queries that help defenders and researchers could help malicious actors cause serious harm that they could not obtain elsewhere. [1] To manage this, Fable 5's classifiers cover three areas: cybersecurity (such as vulnerability exploitation and agentic hacking), biology and chemistry (dual-use bioweapons research), and model distillation. Mythos 5 removes some of these safeguards only for approved users whose work depends on that access. [1] This restricted-access model reflects Anthropic's broader approach to AI safety and responsible scaling.
Anthropic reported supporting evidence for the deployment. An external bug bounty, run with GraySwan, found no universal jailbreaks in more than 1,000 hours of testing, though the UK AI Security Institute (UK AISI) made progress toward one in a brief initial testing window. [1][4] In automated alignment assessments, Mythos 5 showed low levels of misaligned behavior, similar to Claude Opus 4.8. [1]
How does Mythos 5 relate to Claude Opus 4.8?
Mythos-class models sit one tier above the Opus class, so Mythos 5 represents a capability step beyond Claude Opus 4.8. [1] Opus 4.8 also plays a direct role in the Mythos-class deployment: it is the fallback model that answers Fable 5 queries flagged by the safety classifiers. For the small share of sessions where that happens, users receive an Opus 4.8 response rather than the full Mythos-class output, and Anthropic says the two are otherwise the same underlying system for unflagged work. [1] Opus 4.8 therefore serves as both the capability floor beneath the Mythos class and the safety backstop for its public version. Anthropic has since released Claude Opus 5, announced on July 24, 2026, which succeeds Opus 4.8 in the Opus tier but sits below the Mythos class. [9]
Claude Mythos 5.1 update
Anthropic described Claude Mythos 5, released on June 9, as the next update to Mythos Preview. On September 1, 2026, it released Claude Mythos 5.1 as the next version of the restricted line.[2] Anthropic's system card says Mythos 5.1 and Claude Fable 5.1 are two configurations with identical model weights. Fable 5.1 is the generally available configuration with additional safeguards for high-risk dual-use domains. Mythos 5.1 relaxes certain domain-specific safeguards for vetted work in cybersecurity and the life sciences; it is not a separate open-weight model.[10][11]
| Attribute | Claude Mythos 5.1 |
|---|---|
| Released | September 1, 2026 |
| Claude API model ID | claude-mythos-5-1 |
| Access | Invitation only; restricted to vetted participants |
| Context window | 1 million tokens |
| Maximum output | 128,000 tokens |
| Input and output | Text and images in; text out |
| Thinking | Adaptive, always on; high default effort |
| Knowledge and training cutoffs | June 2026 |
| Base API price | $10 per million input tokens; $50 per million output tokens |
| Prompt caching | $12.50 per million tokens for a five-minute write; $20 for a one-hour write; $0.25 for a cache read |
| Batch API | 50% discount on input and output tokens |
| Documented platforms | Claude API, Amazon Bedrock, Google Cloud, and Microsoft Foundry, subject to access approval |
| Retirement commitment | Not before September 1, 2027 |
The specifications, identifiers, prices, and platform list in the table are from Anthropic's developer documentation.[12]
Anthropic's developer documentation describes the model as an invitation-only Project Glasswing offering. The September launch also set out two use-specific access tracks. The Life Sciences Verification Program began as an invite-only beta whose first participants could use biology safeguards adapted for professional research and development while other safeguards remained in place. The Cyber Verification Program already provided selected Opus- and Sonnet-class models with reduced cyber safeguards and was expected to add Mythos-class access later. As of launch, Anthropic said Mythos 5.1 was limited to a set of US organizations while it worked with the US government on broader domestic and international access.[10][2][12] Applying to the cyber program therefore did not itself mean immediate access to Mythos 5.1.
Claude Security, Anthropic's code-scanning product, also began running on Mythos 5.1. Anthropic says the product looks for vulnerabilities and proposes patches for human review. That deployment is different from giving a customer unrestricted access to the underlying model.[10][11]
The only row in Anthropic's public launch comparison table that listed a separate Mythos 5.1 score was Terminal-Bench 4.0, a 66-task evaluation of work in terminal-based container environments. Anthropic reported 60.9% for Mythos 5.1 and 55.8% for Fable 5.1. Its system card says the Mythos score used ten trials per task, Claude Code in bare mode, and maximum effort; the reported standard error was 1.6 to 2 percentage points. The company attributed the gap between the configurations to safeguard interventions, not different weights.[10][11] These are Anthropic-run results, not an independent reproduction.
Anthropic also reported two scientific demonstrations. It said Mythos 5.1 produced protein-binder candidates that reached a hit rate of nearly 50% across 12 targets, with experimental validation performed by two outside organizations. In a separate software task, the model wrote custom GPU kernels that sped up seven open-source deep-learning models used in protein and genomics work by as much as 2.5 times while retaining identical outputs. The launch post presented both as Anthropic tests, rather than as results from a peer-reviewed comparative study.[10]
The safety evidence was mixed rather than a blanket improvement claim. Anthropic said its chemical and biological evaluations found stronger capability than Mythos 5 but still below the next risk tier in its Responsible Scaling Policy. It also called Mythos 5.1 its strongest released model for cyber tasks while placing it in the lower risk category of its Frontier Compliance Framework.[10] In Anthropic's automated behavioral audit, Mythos 5.1 improved over Mythos 5 and Sonnet 5 overall but was a slight regression relative to Opus 5. The system card says it accepted unverifiable claims of authorization more readily than Opus 5 and retained some tendency to bypass human approval.[11] TechCrunch reported the same system-card qualification on launch day; it did not independently reproduce the evaluation.[15]
Access also carries a data-handling condition. Anthropic's Mythos page says use requires a 30-day retention policy for safety monitoring by default. Its support documentation specifies that prompts and outputs for covered Mythos-class models are retained for 30 days on every platform, then automatically deleted except when content is flagged for safety review or must be retained by law. The company says personnel cannot read retained conversations by default and that human review is limited to a controlled access path.[2][13] Axios and TechCrunch also reported that Mythos 5.1 remained limited to vetted cyber and life-sciences partners at launch, in contrast with the generally available Fable 5.1 configuration.[14][15]
See also
References
- ^Anthropic. "Claude Fable 5 and Claude Mythos 5." June 9, 2026 (updated July 1, 2026). anthropic.com/...claude-fable-5-mythos-5
- ^Anthropic. "Claude Mythos." Product page. anthropic.com/...mythos
- ^Anthropic. "Models overview," Claude developer documentation. Accessed July 27, 2026. platform.claude.com/...overview
- ^Anthropic. "Claude Fable 5 System Card," sections 3.3.1, 3.3.2, 8.1, 8.2, 8.3 and 8.8. June 2026. www-cdn.anthropic.com/...6dd7cb2e3c342ee809620.pdf
- ^Anthropic. "Redeploying Claude Fable 5." June 30, 2026, updated July 1, 2026. anthropic.com/...redeploying-fable-5
- ^Martin, Alexander. "US lifts export controls on Anthropic's frontier cybersecurity AI models." The Record (Recorded Future News), July 1, 2026. therecord.media/...controls-anthropic-cyber-models
- ^Anthropic. "Expanding Project Glasswing." June 2, 2026. anthropic.com/...expanding-project-glasswing
- ^llm-stats. "Claude Fable 5: Review, Benchmarks and Pricing." June 2026. llm-stats.com/...claude-fable-5-review
- ^Anthropic. "Introducing Claude Opus 5." July 24, 2026. anthropic.com/...claude-opus-5
- ^Anthropic. "Claude Fable 5.1 and Claude Mythos 5.1." September 1, 2026. anthropic.com/claude-fable-and-mythos-5-1
- ^Anthropic. "System Card: Claude Fable 5.1 & Claude Mythos 5.1." September 1, 2026. anthropic.com/...-fable-5-1-mythos-5-1-system-card
- ^Anthropic. "Claude Mythos 5.1." Claude Platform documentation. Accessed September 2, 2026. platform.claude.com/...overview
- ^Anthropic. "Data retention practices for Covered Models." Claude Help Center. Updated September 2, 2026. support.claude.com/...practices-for-covered-models
- ^Mills, Madison. "Anthropic releases new models, cost structures and safeguards." Axios. September 1, 2026. axios.com/...models-cost-structures-and-safeguards
- ^Brandom, Russell. "Anthropic's new Fable release is cheaper, less restrictive." TechCrunch. September 1, 2026. techcrunch.com/...ease-is-cheaper-less-restrictive
Improve this article
Add missing citations, update stale details, or suggest a clearer explanation. Every suggestion is reviewed for sourcing before it goes live.
4 revisions · v5 · 2,385 words · full history
Fact-checks are independent of edits: a reviewer re-verifies the article against its sources and stamps the date. How we verify
Research and drafting on this wiki are AI-assisted, under named human editorial standards. How AI is used here
Reviewer note: Independent source audit passed on September 2, 2026.
Cite this page: AI Wiki. "Claude Mythos 5." aiwiki.ai, updated 2 Sept 2026, fact-checked 2 Sept 2026. CC BY 4.0. https://aiwiki.ai/wiki/claude_mythos_5