October 3, 2026. Claude Mythos is the version of Anthropic's most capable model that the company does not sell to the public. Mythos 5.1, released on September 1, 2026, is the same model as the generally available Claude Fable 5.1, with one difference: looser safeguards around cybersecurity and biology, available only to vetted individuals and organisations through Anthropic's trusted access programs. It has been pulled offline by a US export-control order, withheld after escaping a test sandbox, and described by Anthropic as having the strongest cyber capabilities of any model it has released. Searches for "Claude Mythos" now run at 10,000 to 100,000 a month in the US, according to Google's Keyword Planner. This is what it is, who can use it, and why most businesses do not need it.

Key numbers
| Item | Number |
|---|---|
| Mythos tier announced and withheld (after a test sandbox escape, per the BBC) | April 2026 |
| Fable 5 public launch, Mythos 5 restricted | June 9, 2026 |
| Export-control blackout (June 12 to July 1, 2026) | 18 days |
| Fable 5.1 and Mythos 5.1 released (same model, different safeguards) | September 1, 2026 |
| Mythos 5.1 against the next RSP risk tier (Anthropic's own evaluation) | Still falls short |
| Fable 5.1 price | $10 in, $50 out per million tokens |
| Opus 5.5 price | $4 in, $20 out per million tokens |
| Claude agents in the enzyme search (21 hours, September 23, 2026) | About 950 |
| US monthly searches for claude mythos (Google Keyword Planner, read 3 October 2026) | 10K to 100K |
Anthropic's Fable 5.1 and Mythos 5.1 launch note, model documentation and enzyme announcement read on 1 to 3 October 2026; the June events from our own reporting at the time; the April detail from the BBC, 12 September 2026.
Mythos vs Fable: one model, two sets of brakes
Anthropic's launch note for Fable 5.1 and Mythos 5.1 is unusually direct: "Claude Fable 5.1 and Claude Mythos 5.1 are the same model, but with different levels of safeguards. Fable 5.1 is generally available, while Mythos 5.1 is available only through our trusted access programs; its safeguards are specifically designed to support work in cybersecurity and the life sciences." The company calls them "the world's most advanced models for coding and knowledge work". So Mythos is not a smarter brain. It is the same brain with permission to answer questions that Fable refuses, for example detailed offensive security work or research biology, and it is given only to people whose work needs those answers.
The timeline so far
- April 2026: Anthropic announces the Mythos tier and withholds it from public use after finding the model could independently escape its testing environment, known as the sandbox, the BBC reported.
- June 9: Claude Fable 5 launches to everyone, with Claude Mythos 5 as a restricted sibling. Anthropic calls it a "Mythos class" tier above its Opus class. Our launch coverage: what Fable 5 meant for operators.
- June 12: a US export-control directive orders Anthropic to suspend access for foreign nationals over a potential jailbreak vulnerability. Unable to enforce a partial block cleanly, Anthropic takes Fable 5 and Mythos 5 offline worldwide. We covered the shutdown and what it meant for anyone who depended on one model.
- June 26: Commerce Secretary Howard Lutnick writes that safeguards are in place for "certain trusted partners" to regain Mythos 5, clearing a limited release to vetted institutions.
- July 1: the controls are lifted and access returns after an 18 day blackout (our report).
- September 1: Fable 5.1 and Mythos 5.1 launch. Anthropic says Mythos 5.1's capabilities are greater than Mythos 5's but that its evaluations show it "still falls short of the next risk tier defined in our Responsible Scaling Policy", so it ships with the same safeguards that restrict access to research biology capabilities.
What Anthropic says Mythos can do
Three claims from the September launch note matter. First, on biology: Anthropic ran expert red-teaming, automated evaluations and a tabletop exercise pairing PhD-level biologists with AI experts to test whether the model could match human specialists, and concluded it does not yet cross the next risk threshold. Second, on cyber: with safeguards off, Mythos 5.1 "demonstrates the strongest cyber capabilities of any model we've released", while still falling in the lower risk category of Anthropic's Frontier Compliance Framework. Third, on research: Anthropic's September 23 announcement that about 950 Claude agents found a CRISPR-like enzyme system in 21 hours was presented as an early glimpse of how these models contribute to science; our piece on whether Claude is super intelligent weighs that claim against its critics.
Who can get access
Anthropic names its route as "trusted access programs" for "vetted individuals and organizations whose work is affected by the cybersecurity and life sciences safeguards". Its newsroom lists a Life Sciences Verification Program that gives life science professionals access to Mythos, Opus and Sonnet models with a refined, more permissive set of safeguards for biology work. Access is therefore by application and verification, not by plan tier or price, and Anthropic has not published a public price for Mythos. The public lineup, per Anthropic's model documentation, is Fable 5.1 at $10 per million input tokens and $50 per million output tokens, Opus 5.5 at $4 and $20, Sonnet 5.5 at $2 and $10, and Haiku 4.5 at $1 and $5.

Is Claude Mythos super intelligent?
No, and Anthropic does not say it is. Since September 29 the US federal government calls all AI "Super Intelligence", so Mythos is "SI" in that vocabulary like every other model; our explainer on what super intelligence means separates that label from the research meaning. Anthropic's own evaluations place Mythos 5.1 below its next risk tier, and its chief executive wrote in September that he wants the industry to slow down before models reach "critical levels of capability" (We Must Pace the Frontier). A company that believed it had built a superintelligence would not describe it that way.
Does your business need Mythos?
Almost certainly not. For sales, support, operations, coding and analysis, Fable 5.1 is the identical model with the standard safeguards, and Opus 5.5 does most of that work at 40 percent of Fable's price. Mythos matters to you in two indirect ways:
- Availability risk is real. The June blackout took Fable 5 offline for 18 days along with Mythos. Any system that depends on one model needs a fallback, which is how our AI automation agency builds every agent.
- Vetting is the new tier. If your work genuinely involves security research or biology, the path is the trusted access program, with evidence of who you are and what you do. For everyone else, the right question is cost per finished task; an AI receptionist for a home services company runs well on a model a tenth of Fable's price.
Frequently Asked Questions
Claude Mythos is the restricted version of Anthropic's most capable model. Mythos 5.1, released on September 1, 2026, is the same model as the generally available Claude Fable 5.1 but with more permissive safeguards for cybersecurity and life sciences work, available only through Anthropic's trusted access programs.
Capability is identical. Fable 5.1 ships with Anthropic's standard safeguards and is sold to everyone; Mythos 5.1 has looser safeguards around cyber and biology and is given only to vetted individuals and organisations.
Not as a product. Access is by application through trusted access programs such as Anthropic's Life Sciences Verification Program, and Anthropic has not published a price. The public lineup is Fable 5.1, Opus 5.5, Sonnet 5.5 and Haiku 4.5.
On June 12, 2026 a US export-control directive ordered Anthropic to suspend access for foreign nationals over a potential jailbreak vulnerability. Anthropic took Fable 5 and Mythos 5 offline worldwide rather than run a partial block. Trusted partners regained Mythos 5 on June 26 and the controls were lifted on July 1.
Anthropic says Mythos 5.1 has the strongest cyber capabilities of any model it has released, but that its evaluations place it below the next risk tier in its Responsible Scaling Policy and in the lower risk category of its Frontier Compliance Framework. That is why it is gated rather than banned.