Anthropic released Claude Fable 5 on Tuesday with hard refusals on cybersecurity, biology, and chemistry queries, the company's most restrictive public model to date. Fable 5 runs on the same underlying weights as Mythos 5, Anthropic's new frontier model, but routes sensitive prompts to the older Claude Opus 4.8 and warns users when it does so. API pricing lands at $10 per million input tokens and $50 per million output tokens — 67 to 100 percent higher than OpenAI's GPT-5.5.
The trigger for the lockdown is a 78% score Mythos 5 posted on ExploitBench, a benchmark of vulnerable-code exploit tasks. That's up from 40% for Opus 4.8 and 69% for Mythos Preview, the closed beta that ran for several months and ended today. Anthropic flagged the jump as evidence that Mythos 5 can perform what it calls agentic hacking — multi-step cyberattacks executed end-to-end — at a level its earlier models could not.
Mythos 5 itself is not going on general sale. Anthropic is keeping it inside Project Glasswing, an existing vetted-access program for cyberdefenders, and will expand the program in consultation with the US government. A separate trusted-access tier for life-sciences organizations will lift the biology and chemistry restrictions while keeping the cybersecurity ones in place. Everyone else gets Fable 5.
Key facts
- 01Claude Fable 5 routes cybersecurity, biology, and chemistry prompts to the older Opus 4.8 model instead of answering directly.
- 02Mythos 5 scored 78% on ExploitBench, versus 40% for Opus 4.8 and 69% for Mythos Preview.
- 03API pricing is $10 per million input tokens and $50 per million output tokens — 67-100% above OpenAI's GPT-5.5.
- 04Anthropic logged over 1,000 hours of red-team testing and says no universal jailbreak was found.
- 05Subscription access to Fable 5 ends June 22, 2026, after which users must buy usage credits.
The Fable 5 safeguards are built on a classifier system that flags banned topics and detects jailbreak attempts. Anthropic ran over 1,000 hours of red-team testing through a bug bounty program and says no external team found a universal jailbreak. The classifiers also held up against automated attacks at rates Anthropic says exceed previous Opus models by a wide margin. The company tuned the filters to be, in its words, stricter than ideal — refusing some harmless requests in under 5% of sessions in testing.
The biology and chemistry restrictions are notably broader than in previous Claude releases. Earlier models blocked bioweapons-specific queries; Fable 5 blocks general chemistry and biology questions entirely, on the rationale that well-resourced malicious actors could chain benign-looking queries into something dangerous. That framing tees up an awkward gatekeeping question Anthropic acknowledges directly.
“the same queries that are beneficial in the hands of cybersecurity professionals and biology researchers could be dangerous if available to malicious actors”— Anthropic, company statement
Independent testing complicates Anthropic's threat narrative. The UK AI Security Institute evaluated Mythos Preview on a suite of Capture the Flag challenges in recent months and found it performed similarly to GPT-5.5, suggesting the cyber capability isn't unique to Mythos. If two frontier models are roughly tied on offensive cyber tasks and only one is being restricted at the consumer level, the safeguards become a market-positioning question as much as a safety one.
Pricing reinforces that read. At $10 input and $50 output per million tokens, Fable 5 sits well above GPT-5.5 at a moment when buyers are already pushing back on frontier-model costs. We covered the broader shift toward cheaper inference earlier this month — workloads that don't need a frontier model are quietly migrating to smaller, cheaper alternatives. Anthropic is betting Fable 5's capability gains justify a premium even as the rest of the market discounts.
Distribution gets messier in two weeks. Anthropic's existing subscription plans include Fable 5 access only through June 22, 2026. After that, subscribers will need to buy usage credits to keep using the new model, with Anthropic saying it hopes to restore standard subscription access once it has sufficient capacity. That's a soft way of saying inference demand is exceeding supply, a familiar story across the frontier labs this year.
This is also the second Claude release in quick succession. Anthropic shipped Fable 5 as its first public Mythos-class model after running the Mythos Preview through closed testing — a staged rollout that gives Anthropic time to study red-team findings before opening the gates wider. The Glasswing-only path for full Mythos 5 access is the most aggressive tiering any major lab has imposed on a flagship model so far.
The strategy is a bet that capability and access can be decoupled cleanly. Anthropic gets to claim a frontier release, charge frontier prices, and point to its safeguards in any regulatory conversation — while reserving the unfiltered model for a hand-picked customer list. The risk is that customers paying a premium for Fable 5 discover the refusals bite into real workflows, and migrate to a competitor whose model will simply answer the question. The next quarter of API revenue will say which way that trade lands.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.



