Claude Fable 5.1 and Claude Mythos 5.1 are the same weights wearing two different sets of restrictions — and which name you get depends less on what you're building than on who Anthropic and the US government believe you are.

Same weights, two names, two rows on the access console — one open to anyone with an API key, one gated behind a badge that has not yet finished its read. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
Claude Fable 5.1 is the generally available model that launched September 1, 2026; Claude Mythos 5.1 is the same underlying model with its safety classifiers and fallback restrictions removed for a narrow set of vetted US organizations. This article traces the governance mechanics of that split — the Cyber Verification Program and the Life Sciences Verification Program, the US-only gate, the identity-verification-over-weight-gating logic behind it, and what changed between the June 2026 Fable 5/Mythos 5 debut and the September 5.1 refresh. It sets the safety-measure false positive numbers and the benchmark comparisons aside for other pieces in this series and stays on the access-control story: why a frontier lab would choose to gate a capability by verifying who is asking rather than by simply not training the capability at all, how that compares to what OpenAI, Google DeepMind, and Meta do with comparable dual-use capability, and the open questions — who verifies the verifiers, what happens to researchers outside the US — that the announcement itself does not answer.
Anthropic shipped one model on September 1, 2026, and gave it two names. Claude Fable 5.1 is available today to anyone with an API key, a Claude.ai account, or a seat on AWS, Google Cloud, or Microsoft Azure [1]. Claude Mythos 5.1 is, per Anthropic’s own description, the identical underlying model, with its safety classifiers and fallback restrictions removed for a defined set of vetted users [1] [8]. Coverage published the same day converged on the same framing: 9to5Mac called Fable 5.1 and Mythos 5.1 “the same model, but with different levels of safeguards” [5]; MacRumors described Mythos 5.1 as reserved for “U.S. companies and individuals in Anthropic’s trusted access programs” [6]; Let’s Data Science put it most plainly — Fable 5.1 is generally available, while “Mythos 5.1 is available only through trusted access programs; its safeguards are specifically designed to support work in cybersecurity and the life sciences” [9].
That is a strange thing for a product release to be. Most software vendors ship one build and everyone gets the same one. Anthropic ships two builds off the same weights and decides which one you get based on whether it can verify who you are and what organization stands behind you. This piece is about that mechanism — not the benchmark scores, not the false-positive percentages other pieces in this series cover in depth, but the governance apparatus itself: two verification programs, a US-only gate, and the underlying bet that identity is a better place to put a safety boundary than the model’s weights.
Anthropic’s own account is specific about what “restricted” means in practice. Fable 5.1 retains “safety classifiers alongside fallback restrictions for high-risk tasks,” which keeps it deployable to the general commercial market; for approved participants, Anthropic has “removed the safety classifiers and fallback restrictions that govern Fable 5.1” to produce Mythos 5.1 [1] [8]. Both models share the same context window and output ceiling and the same base API price — ten dollars per million input tokens, fifty dollars per million output tokens — with the lower price for cached reads Anthropic is marketing as the release’s headline economic change [7] [9]. The split, in other words, is not a separate SKU with separate capability. It is a policy toggle applied to the same forward pass.
Mythos 5.1 reaches its users through two named programs. The Cyber Verification Program (CVP) is described by Anthropic’s own help center as an application-based, organization-scoped process that currently governs access to certain Opus- and Sonnet-class models with reduced cyber safeguards, and that Anthropic has said will extend to Mythos-class models “in the near future” [4] [1]. Its scope is explicitly defensive: the program exists to let “professionals to continue working on legitimate dual use tasks safely,” and it lifts restrictions only on activities that have a clear legitimate defensive application — vulnerability discovery and analysis, offensive-security tooling used by red teams — while activities Anthropic classifies as flatly prohibited, mass data exfiltration or ransomware development among them, stay blocked no matter what tier a user has reached [4]. Anthropic’s Usage Policy states the same prohibitions in its general form, with no built-in exception for credentialed researchers baked into the policy text itself — the exception lives entirely in the separate verification layer sitting on top of it [3].
The Life Sciences Verification Program (LSVP) is the newer of the two and is described as having been “developed in partnership with the US government,” enrolling its first participants with September’s release and planning to expand to “the broader life science community” over time [1] [6]. Where the CVP relaxes cyber restrictions, the LSVP relaxes the biology and chemistry classifiers specifically, giving enrolled researchers a version of the model with, in Anthropic’s phrasing, safeguards “designed for professional research and development activities” while other protections remain in force [1]. Both programs currently share the same geographic boundary: Mythos 5.1 is “currently only available to a set of US organizations,” and Anthropic says it is “coordinating with the US government to expand access to a broader set of domestic and international partners as quickly as possible” — a stated intention, not a published timeline [1].
None of this began with 5.1. Claude Fable 5 and Claude Mythos 5 launched as a pair on June 9, 2026, and the underlying architecture of the split — one model, safeguards toggled by verified access — was set then [2] [8]. That original announcement framed Mythos 5 around cybersecurity specifically, describing it as carrying “the strongest cybersecurity capabilities of any model in the world” and tying its initial rollout to Project Glasswing, a separate Anthropic initiative that brought cybersecurity professionals and critical-infrastructure operators into early access in coordination with the US government [2]. ITPro’s coverage of Glasswing lists the program’s participant roster as including Apple, AWS, CrowdStrike, Google, and Microsoft among its named partners, working with the model to find flaws across “every major operating system and web browser” — and notes that Anthropic initially planned to keep those findings confidential among partners before revising that stance to allow broader disclosure to “external companies, as well as government authorities, the public, and the media” [11]. That reversal is a small but telling data point: even inside a program built around controlled access, Anthropic renegotiated the terms of what “controlled” meant after partners pushed back.
The Life Sciences Verification Program did not exist at the June launch in its current form; June’s equivalent was a narrower, unnamed arrangement giving “a small number of researchers from a variety of life science organizations” a version of Fable 5 with biology and chemistry safeguards lifted while cyber protections stayed intact [2]. What September’s release did was formalize that arrangement into a named program, fold it explicitly into US-government coordination, and route it through Mythos 5.1 rather than a specially configured Fable 5 [1]. The CVP, similarly, existed in an early form for Opus and Sonnet models before September and is now explicitly slated to extend to the Mythos line [4] [1]. In both cases, the trajectory is the same: an ad hoc, narrowly scoped early-access arrangement in June hardened by September into a named, application-based program with its own portal and its own review process.

Figure 1. Mythos only ever surfaces in a setting like this one — a vetted security team's own terminal, not a public endpoint anyone can call. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
It is also worth noting, because Anthropic’s own coverage this cycle references it directly, that the June deployment was not uninterrupted. Reporting from the June window described a suspension tied to US export-control action around cybersecurity concerns, with access restored roughly three weeks later [7] [8]. Whatever the specifics of that episode, its existence is itself a governance signal: a model gated behind identity verification can still be gated a second time, after the fact, by government action on top of Anthropic’s own review — the trusted-access structure does not remove the state from the loop, it adds Anthropic as an intermediate checkpoint inside it.
The alternative to this whole apparatus is simpler to describe: just don’t train the capability, or don’t ship it to anyone. Anthropic’s own account of why it does otherwise is implicit rather than argued out loud in the September materials, but the shape of the argument is visible in what the two verification programs are actually for. A security researcher doing legitimate vulnerability analysis and an attacker building an exploit are, from the model’s perspective mid-conversation, often asking for structurally similar things — a description of a flaw, a proof of concept, a way past a specific defense. A model that refuses the whole category refuses the researcher along with the attacker; a model that permits the whole category permits the attacker along with the researcher. Gating by identity rather than by capability is Anthropic’s attempt to resolve that ambiguity somewhere other than at the level of the request itself — push the decision upstream, to “is this organization who it says it is and does it have a defensible reason to be asking,” and let the model behave permissively once that question has already been answered by a human review process.
That is a meaningfully different design choice than simply not training the capability at all, and it has a real cost attached: it requires Anthropic to build and staff an identity-verification bureaucracy, to decide who counts as a legitimate cybersecurity organization or a legitimate life-sciences researcher, to maintain two separate portals and two separate review pipelines, and to accept that a verification process — any verification process — has a false-negative rate, admitting some bad actors and a false-positive rate, rejecting or delaying some legitimate ones. The company’s own framing in the Cyber Verification Program materials is candid about the tradeoff it is choosing to accept: the goal is to let professionals continue “legitimate dual use tasks safely while minimizing interruption,” which is an admission that some interruption is expected as the cost of catching the cases that matter [4]. Put differently: Anthropic is betting that identity verification, however imperfect, is a better filter for dual-use capability than model behavior alone can be — that the marginal researcher correctly waved through by a human reviewer is worth more, in aggregate, than the marginal bad actor who slips past that same reviewer with a plausible cover story.

Figure 2. The Life Sciences Verification Program, developed with the US government, is the other gate — the same reduced-safeguard model, now reached from a bench instead of a terminal. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
Anthropic is not alone in reaching for this exact instrument, and the comparison is instructive about how similar the underlying logic is even where the branding differs. OpenAI’s own account of its biology safeguards describes a comparable structure under a different name: a “Trusted Access” arrangement for a “less restricted version of certain models for vetted and trusted customers engaged in beneficial applications in areas such as biodefense and life sciences,” gated by requirements that mirror Anthropic’s almost point for point — verifiable identity, organizational affiliation, authority to apply on an organization’s behalf, and a stated research purpose consistent with the applicant’s institutional mission [12]. OpenAI ties that gate to its Preparedness Framework’s capability thresholds directly: a model that crosses a “High” capability threshold in biology does not ship at all until OpenAI is confident the risk has been sufficiently mitigated, and the trusted-access mechanism is one of the mitigations that makes shipping possible once that threshold is crossed [12]. The sequencing differs slightly from Anthropic’s — OpenAI frames trusted access as a precondition for releasing a capability at all, where Anthropic frames Mythos as a parallel release alongside a safeguarded general one — but the verification instrument itself, an application reviewed against organizational and purpose criteria, is functionally the same tool.
Google DeepMind’s Frontier Safety Framework describes the same problem in more abstract, less program-branded terms. It defines Critical Capability Levels across autonomy, cybersecurity, biosecurity, and ML research and development, and ties deployment explicitly to whether “a safety case showing how severe risks have been minimised to an acceptable level” has been approved by an internal governance body before general release proceeds; where an adequate deployment mitigation cannot be reached, DeepMind’s own framework states plainly that “the model’s deployment must be restricted” [13]. DeepMind’s public materials are notably less specific than Anthropic’s or OpenAI’s about the mechanics of who gets access to a restricted deployment and how they are vetted — the framework describes the trigger for restriction in detail without publishing an equivalent to a CVP or LSVP application portal.

Figure 3. Access begins as paperwork, not a download — an application, an organizational sponsor, and a review queue stand between a researcher and the restricted model. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
Meta sits at the other end of this spectrum entirely, and the contrast sharpens what Anthropic and OpenAI are actually choosing. Meta ships Llama’s weights openly rather than gating access through an API at all, which removes the identity-verification step altogether — anyone able to download the weights can run them, fine-tune them, and deploy them without Meta reviewing who they are or why. That approach has drawn its own scrutiny: reporting has connected research institutions linked to China’s People’s Liberation Army to defense-related work built on publicly available Llama weights. Set beside that, the Anthropic and OpenAI approach reads as a deliberate rejection of open distribution specifically for the capability classes each considers highest-risk — dual-use cyber and bio-relevant work stays behind an identity check even while the companies otherwise compete hard on making their general-purpose models broadly, cheaply available.
For a working security researcher or a life-sciences investigator, the practical shape of this is now reasonably concrete. On the cyber side, Anthropic’s own help documentation lays out an application flow that runs through a Verification Portal for first-party Claude access, a separate use-case form for Microsoft Foundry customers, and a similar portal path with AWS account linking for the AWS platform — while Amazon Bedrock and Google Vertex AI are explicitly listed as not currently supporting the program at all, and access through other third-party platforms depends on whether that platform has opted in [4]. Anthropic states a target decision window of two business days once an application is submitted, and describes an appeals path for organizations that believe they were declined in error or blocked unexpectedly on legitimate work [4]. Notably, the documentation states that organizations on Zero Data Retention plans cannot currently participate in the CVP at all — a real friction point for exactly the kind of security-conscious enterprise customer who might otherwise be a natural fit for the program.

Figure 4. The programs are currently open only to US organizations — Anthropic says it is coordinating with the US government to widen that circle, without yet saying when or to whom. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
For life-sciences researchers, the public information is thinner. Anthropic has said the LSVP has enrolled its first participants and intends to expand to the broader research community, but has not published the equivalent of the CVP’s step-by-step application mechanics in the sources reviewed for this piece [1]. That is worth stating plainly rather than filling in: what the LSVP’s eligibility criteria actually are, beyond “professionals” at “life science organizations spanning fundamental and translational research,” is not public as of this writing, and this article does not speculate about specifics Anthropic has not disclosed.
A few questions sit outside what Anthropic’s own materials, or the day’s press coverage, address — and they are worth naming as open rather than glossing over.
Who verifies the verifiers is the most obvious one. Anthropic runs the review process for both programs, deciding which organizations count as legitimate cybersecurity practitioners or credible life-sciences researchers. That is Anthropic grading its own dual-use gatekeeping, with the US government named as a partner specifically on the life-sciences side and referenced more generally, via export-control action, on the cyber side [1] [7]. Nothing in the sources reviewed here describes an external audit of CVP or LSVP approval decisions, a published rejection rate, or a body outside Anthropic and its government partners with visibility into who is being let in and who is being turned away. That is not necessarily evidence of a problem — plenty of legitimate access-control regimes work exactly this way — but it is a structural feature of the current design worth flagging as analysis rather than as a settled fact about how well the review actually performs.

Figure 5. Two readers, one wall — one program's queue has already cleared this credential, the other's is still catching up, and neither light says why. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.
The US-only boundary raises a second, related question with no published answer yet: what happens to a security researcher or a life-sciences investigator working outside the United States, doing work indistinguishable in substance from what a US-based CVP or LSVP participant does. Anthropic’s own language — “coordinating with the US government to expand access to a broader set of domestic and international partners as quickly as possible” — commits to an intention without a timeline, a list of target countries, or a description of what non-US verification would even look like given that the current programs appear to lean partly on US government coordination as part of their vetting infrastructure [1]. Until that expands, the practical effect of the current design is that geography, not just professional credential, is part of the gate.
Finally, there is the question the industry-wide comparison surfaces on its own: identity-based gating assumes the verification process itself resists the same adversarial pressure the model’s outputs are being protected against — a well-resourced bad actor motivated enough to want unsafeguarded model access is also, by construction, motivated enough to build a plausible cover organization and a plausible research justification. None of the frameworks reviewed here — Anthropic’s, OpenAI’s, or DeepMind’s — publish a track record of catching that kind of adversarial application, as distinct from publishing the criteria an honest applicant is expected to meet. Whether the gate holds under real pressure, rather than under good-faith applications, is a claim none of today’s sources actually test.
What is clear, and stated plainly by the company itself, is the shape of the bet: Anthropic has decided that verifying who is asking is a more tractable safety mechanism, right now, than trying to make a model that behaves safely toward everyone who might ask the exact same question. Fable 5.1 and Mythos 5.1 are the same weights because the model was never really the variable — the access control was.
Originally published at https://absolutedigitalpublishers.com/articles/one-model-two-names-how-anthropic-splits-fable-from-mythos.