Anthropic's new publicly available Fable 5 model routes sensitive queries on cybersecurity, biology, and chemistry to an older model rather than its most capable system.
Anthropic on Tuesday released Claude Fable 5, which it describes as its first “Mythos-class” model and says surpasses its previous frontier Opus models in overall capabilities — but the launch comes paired with an unusual architectural safeguard: queries on certain sensitive topics are deliberately redirected away from the new model entirely. [1]
Fable 5 operates on the “same underlying model” as Mythos 5, Anthropic says, but unlike Mythos 5 — which is simultaneously exiting a monthslong preview period and becoming available only to a vetted group of cyberdefenders through the existing Project Glasswing program — the publicly accessible Fable 5 is designed to funnel queries on sensitive subjects to the earlier Claude Opus 4.8 model, notifying users when that handoff occurs. [1]
The restricted topics include cybersecurity, biology, and chemistry. [1] While earlier Anthropic models had blocked bioweapons-related queries specifically, that classifier has now been broadened to cover all chemistry and biology-related queries in Fable 5, with the company citing concern that “well-resourced malicious actors” could use even seemingly benign questions in those domains to assist with “highly risky biological research” far more effectively than with previous models. [1]
Anthropic acknowledged the trade-off directly, writing that “the same queries that are beneficial in the hands of cybersecurity professionals and biology researchers could be dangerous if available to malicious actors.” [1] The company said it has tuned the safeguards to be “stricter than ideal,” meaning the system may occasionally refuse “harmless requests,” but said such false positives occur in fewer than five percent of all sessions in testing. [1]
The safeguards are built around a classifier system designed to detect both banned prompt subjects and potential jailbreak attempts. [1] In over 1,000 hours of red-team testing conducted through a bug bounty program, Anthropic said external teams failed to find any universal jailbreaks for Fable 5, and that the model resisted automated jailbreak attempts to a significantly greater degree than previous Claude Opus models. [1]
Anthropic said it is particularly concerned about Mythos 5’s capacity for “agentic hacking” — executing multi-step cyberattacks with greater facility than earlier models. [1] However, testing by the UK’s AI Security Institute found that Mythos Preview performed similarly to OpenAI’s GPT-5.5 on a suite of Capture the Flag challenges, suggesting the capability is not “a breakthrough specific to one model.” [1]
On the cybersecurity-focused ExploitBench benchmark, Mythos 5 scored 78 percent on tests of vulnerable code exploits, up from 40 percent for Opus 4.8 and 69 percent for Mythos Preview. [1]
To manage access to the fuller Mythos 5 capabilities, Anthropic said it will periodically expand Project Glasswing “in consultation with the US government” to admit more cybersecurity professionals. [1] A new trusted access program for life sciences organizations is also planned, which would remove Fable 5’s biology and chemistry restrictions while keeping cybersecurity safeguards in place. [1]
On pricing, API and Enterprise users can access Fable 5 at $10 per million input tokens and $50 per million output tokens — rates that are 67 to 100 percent higher than those for OpenAI’s GPT-5.5, according to Anthropic. [1] Existing subscription plan holders will have access through June 22, after which they will need to purchase “usage credits” to continue using the model; Anthropic said it hopes to restore Fable 5 as a standard subscription feature once it has “sufficient capacity.” [1]
Sources
This article was drafted with AI from the cited sources and checked against them before publication. Spot an error? Let us know.



