Model access · Trusted capability

Fable 5 vs Mythos 5: Who Gets the Full Model?

A source-backed comparison of Fable 5 and Mythos 5: public access, trusted access, Project Glasswing, fallback rules, reported scale, pricing, and who should care.

Bottom line: Fable 5 and Mythos 5 are best understood as two access paths to the same Mythos-class capability. Fable 5 is the public product with stronger guardrails and fallback. Mythos 5 is the trusted-access product for vetted cyberdefenders, infrastructure providers, government-linked partners, and other approved organizations.

Why this comparison matters

The easiest mistake is to treat Claude Fable 5 and Claude Mythos 5 like two ordinary product tiers.

That misses the real story.

Anthropic says Mythos 5 uses the same underlying model as Fable 5, but with safeguards lifted in some areas. Mythos 5 is being deployed first through Project Glasswing and will later expand through a broader trusted-access program. Fable 5 is the public model most users can actually buy or call today. AIAnthropic Fable/Mythos launch note

So the buyer question is not simply “which model is smarter?” The better question is:

Who gets access to the less restricted version of the same capability?

Quick comparison

QuestionClaude Fable 5Claude Mythos 5
Access modelPublic release for Claude users and API customersTrusted access through Project Glasswing and approved partners
Underlying capabilityMythos-class public modelSame underlying model, with safeguards lifted in some areas
Cybersecurity capabilityHigh-risk requests restricted, refused, or routed to Opus 4.8More capability available to vetted cyberdefenders and infrastructure partners
Bio / chem / distillation limitsStronger public safeguards and fallback behaviorPublic details are limited; access is controlled rather than broadly public
Typical userAdvanced individual users, developers, teams, API customersGovernment-linked partners, critical infrastructure, security organizations, vetted institutions
Main buyer questionWill my task trigger fallback?Can my organization qualify for trusted access?

This is not the same as Free vs Pro or Pro vs Enterprise. It is closer to public capability vs credentialed capability.

Timeline: how Mythos access widened before Fable launched

DateEventWhy it mattersSource
2026-04Anthropic gives about 50 initial partners access to Claude Mythos Preview under Project Glasswing.Mythos starts as a controlled defensive-security program, not a public model launch.TechCrunch / Reuters
2026-06-02Anthropic says it is expanding Project Glasswing to about 150 new organizations in more than 15 countries.Trusted access expands, but it still requires security requirements before access.Anthropic / TechCrunch
2026-06-02Reuters reports Mythos access will grow from about 50 to about 200 Glasswing partners.The rough scale of trusted access becomes visible.Reuters
2026-06-03Reuters reports South Korea’s KISA gained Mythos access through Project Glasswing.Mythos access reaches national cybersecurity agencies and major technology firms.Reuters
2026-06-09Anthropic launches Claude Fable 5 publicly and Claude Mythos 5 for trusted users.Public and trusted-access versions now coexist.Anthropic / Reuters / WIRED
2026-06-11Media reports cover invisible guardrail backlash and Anthropic’s policy adjustment.The access-control layer becomes the central trust issue.The Verge / Business Insider / WIRED

Anthropic’s own Project Glasswing update says the expansion covers approximately 150 new organizations in more than 15 countries, and that each must meet security requirements before gaining access. Reuters separately reported the access base growing from about 50 to about 200 Glasswing partners. AIAnthropic Project Glasswing expansionRReuters on 200 Glasswing partners

What Project Glasswing is actually for

Project Glasswing is the best way to understand Mythos. It is not a generic beta program. Anthropic describes it as an initiative for partners to receive access to Claude Mythos Preview to find and fix vulnerabilities or weaknesses in foundational systems that represent a large share of the world’s shared cyberattack surface.

The work Anthropic highlights includes local vulnerability detection, black-box testing of binaries, securing endpoints, and penetration testing of systems. That explains why Mythos is not simply published like a normal consumer chatbot. Its strongest advertised value is also its release risk. AIProject Glasswing overview

Reported numberMeaningSource
~50 organizationsInitial Project Glasswing partner cohort with Mythos Preview accessTechCrunch / Reuters
~150 new organizationsAnthropic’s stated expansion target across more than 15 countriesAnthropic / TechCrunch
~200 Glasswing partnersReuters’ report of expanded total partner accessReuters
15+ countriesInternational expansion of critical-infrastructure accessAnthropic / TechCrunch / Reuters

These numbers should not be collapsed into one claim. The safer reading is that Mythos access is expanding from dozens of partners to roughly 150–200 organizations, depending on whether the source is describing new participants, total partners, or national cohorts.

Same underlying model, different product

The most important product detail is that “same underlying model” does not mean “same user experience.”

Anthropic says Mythos 5 is the same underlying model as Fable 5, but with safeguards lifted in some areas. WIRED frames the same split more bluntly: Mythos goes to trusted organizations, while Fable is the public version with guardrails. AIAnthropic on same underlying modelWWIRED on trusted Mythos vs public Fable

LayerFable 5Mythos 5
Base capabilityMythos-classMythos-class
Access policyPublic model accessCredentialed / vetted access
Safety layerPublic-release guardrailsSafeguards lifted in some areas for approved users
Cybersecurity useHigh-risk requests may be refused or routed awayDesigned for approved defensive-security work
Evaluation riskFallback can affect benchmark and workflow testsAvailability depends on access program and contract terms

This is why “Fable is a nerfed Mythos” is emotionally loaded but not baseless. A more precise version is: Fable 5 is Mythos-class capability with public-release controls.

Where the capability split matters most

For ordinary writing, summarization, and general coding, the difference between Fable and Mythos may not matter much. The split matters most near high-risk capabilities.

Capability areaFable 5Mythos 5
General software engineeringOpen to public usersOpen within trusted-access environments
Long-horizon agentic codingCore public selling pointAlso available, depending on access
Cybersecurity vulnerability discoveryHigh-risk requests restricted, refused, or routed to Opus 4.8Core Glasswing use case for vetted defenders
Biology / chemistry sensitive requestsPublic safeguards and fallback can applyPublic details limited; access remains controlled
Distillation / model reproductionCentral to the invisible-guardrail backlashPublic details limited
Critical infrastructure securityNot the primary public access routeExplicit Project Glasswing target

Reuters reports that Fable is a public version of Mythos without the same high-risk cybersecurity capability; Anthropic says Mythos 5 has the strongest cybersecurity capabilities of any model and will initially be deployed through Project Glasswing. RReuters on public FableAIAnthropic on Mythos 5 cybersecurity

Pricing: same public price, different access reality

For public API users, Anthropic lists Fable 5 at $10 per million input tokens and $50 per million output tokens. Reuters reported the same price level in the context of the Fable/Mythos launch.

Model / access pathReported input priceReported output priceImportant caveat
Claude Fable 5$10 / 1M tokens$50 / 1M tokensVerify current API pricing before purchase.
Claude Mythos 5Reported as same levelReported as same levelTrusted access may involve contracts, eligibility rules, or non-public terms.

The key point is that price is not the only gate. Even if two access paths are reported at the same token price, only approved users can access Mythos 5. For frontier models, identity and use case are becoming part of product access.

Who should use Fable 5?

User typeFitReason
Advanced individual usersGood fitFable is the accessible Mythos-class route for non-vetted users.
Developers and product teamsGood fit with testingStrong public model for coding and agentic work, but track fallback.
Enterprise API usersGood fit with governanceRequires pricing, metadata, logging, and data-retention review.
Security researchersCautionHigh-risk cybersecurity prompts are explicitly guarded.
AI evaluation teamsCautionFallback can pollute model comparison if not visible in logs.
Bio / chemistry usersCautionBroad public safeguards may create false positives or refusal patterns.

Fable 5 is the right starting point for almost everyone who cannot qualify for trusted access. But it should be tested task-by-task if your work lives near policy boundaries. Our related note covers the fallback categories in more detail. APAI Picker fallback review

Who may need Mythos 5?

Mythos 5 is more likely to matter if the work requires capabilities that public Fable is designed to restrict.

User typeWhy Mythos access may matter
Government cybersecurity agenciesNational-scale vulnerability discovery and infrastructure protection.
Critical infrastructure providersSecurity testing for systems where successful attacks could affect large populations.
Security companiesVulnerability research, code auditing, endpoint security, and defensive testing.
Large enterprise security teamsLower false-positive pressure for high-stakes internal security work.
Approved research institutionsControlled access to high-risk capability for legitimate research.

TechCrunch reports that the expanded Glasswing organizations cover areas such as power, water, healthcare, communications, and hardware. Anthropic’s own Glasswing page emphasizes shared cyberattack surface and defensive tasks. This is a very different access model from a normal model subscription. TCTechCrunch on critical infrastructure accessAIProject Glasswing overview

The real risk: capability becomes credentialed

The Fable/Mythos split shows a structural change in AI product access.

Old AI product tiers looked like this:

Free → Plus → Pro → Enterprise

The Fable/Mythos model points toward something more like this:

Public access → Enterprise access → Trusted access → Government / critical infrastructure access

That change has a reasonable safety argument. If a model can materially improve cyber offense or other high-risk work, broad public release is dangerous.

But it also creates three buyer problems.

1. Transparency risk

If public users do not know when Fable falls back, they cannot evaluate the model properly. That is why the invisible-guardrail backlash mattered. The Verge and Business Insider both reported Anthropic’s shift toward visible fallback and refusal reasons after criticism. VThe Verge on invisible guardrailsBIBusiness Insider on policy reversal

2. Competition and evaluation risk

If some organizations can access less restricted capability while independent researchers can only test the public guarded version, third-party evaluation becomes harder. WIRED reported that researchers criticized covert limitations because they could affect legitimate AI research and model comparison. WWIRED on public vs trusted access

3. Concentration risk

If the most capable models are only available to governments, large infrastructure operators, and approved partners, small teams may end up building on policy-shaped public models while larger organizations operate with fuller capability.

That may be necessary. It is still a distribution-of-power decision.

Buyer checklist

Before choosing between Fable 5, a trusted-access request, or a different model, ask these questions:

  • Are Fable 5 and Mythos 5 using the same underlying model for my use case?
  • Which safeguards apply to Fable 5 but not to Mythos 5?
  • Does the API show when Fable falls back to Opus 4.8?
  • Does fallback affect billing?
  • Can fallback and refusal logs be exported?
  • How do I apply for trusted access?
  • What are the security requirements for Project Glasswing or future trusted access?
  • Does trusted access allow cybersecurity, bio, chem, or model-development work that public Fable restricts?
  • Does data retention differ by public API, enterprise plan, or trusted-access contract?
  • Can independent evaluators verify which model actually answered a prompt?

The most important question is not “is Fable 5 good enough?” It is whether your work needs the part of Mythos-class capability that Anthropic has decided not to ship to the public.

The bottom line

Fable 5 and Mythos 5 are not just two models.

They are two distribution systems for the same frontier capability.

Fable 5 is how Anthropic turns Mythos-class capability into a public product. Mythos 5 is how Anthropic distributes higher-risk capability to organizations it has decided to trust.

If you are a normal developer or team, Fable 5 is the version you should start with. If you are a security organization, government agency, critical-infrastructure provider, or large enterprise working near high-risk capability boundaries, the real question is whether you can qualify for trusted access.

The bigger lesson is this:

AI model access is starting to depend not only on what you pay, but on who you are and what the lab believes you can be trusted to do.

Future buyers may not be buying a model. They may be applying for a capability pass.