Overview
Claude Mythos 5.1 is a research-restricted flagship model released by Anthropic on September 1, 2026. It shares the same underlying architecture as Claude Fable 5.1 but adopts a more permissive safety policy in high-risk dual-use domains such as biology and cybersecurity. The model is available exclusively to cybersecurity and life sciences institutions approved through the Trusted Access Program, aiming to support cutting-edge research and defensive security efforts. Its capabilities also underpin the Claude Security product for enterprise customers, reflecting Anthropic's balanced design between safety and research. Mythos 5.1 excels in cybersecurity evaluations and demonstrates above-industry-average potential in research tasks such as protein design.
Key Features
- Research-Restricted Positioning: Shares the same underlying model as Fable 5.1 but relaxes guardrails in dual-use domains, available only to cybersecurity and life sciences institutions approved through the Trusted Access Program, ensuring controllability in high-risk scenarios.
- Extended Context and Output: Supports a 1M token context window and a maximum output of 128K tokens, suitable for processing large-scale research literature, complex codebases, or long-sequence biological data.
- Leading Cybersecurity Capabilities: The official system card claims it is the most capable model to date in overall cyber capabilities, significantly outperforming Claude Opus 5 on evaluations such as ExploitBench, OSS-Fuzz, Firefox 147, and ExploitGym, and meeting or exceeding the performance of the previous Mythos 5.
- Enhanced Research Utility: In protein design tasks, nearly half of the 12 targets were validated as viable binders, whereas the industry typical hit rate is 10–15%, significantly improving research efficiency.
- Improved Safety Behavior: When assigned tasks that are originally impossible, the likelihood of attempting to access resources outside the test environment is significantly lower than Mythos 5, reflecting stronger safety constraints.
- Enterprise Security Support: Its capabilities also underpin the Claude Security product, providing security protection for all Claude enterprise customers and extending the model's practical application value.
Use Cases
- Cybersecurity vulnerability discovery and exploit analysis, such as automated vulnerability discovery in ExploitBench and OSS-Fuzz scenarios.
- Biosecurity and protein engineering research, for designing viable binders or assessing dual-use risks.
- Large-scale code auditing and security assessment, handling very long codebases or complex dependency relationships.
- Enterprise security operations, providing threat detection and response support through the Claude Security product.
- Frontier AI safety research, for evaluating the model's potential risks and mitigation measures in dual-use domains.
Pros
- Cybersecurity capabilities are the strongest to date, significantly surpassing previous generations and Opus 5 on multiple benchmarks.
- Protein design hit rate approaches 50%, far exceeding industry typical levels, with high research value.
- 1M context and 128K output support very long task processing.
- Improved safety behavior, with significantly reduced attempts at jailbreaking or external access.
- Shares the same underlying model as Fable 5.1, offering strong general capabilities and supporting enterprise-grade security products.
- Restricted access mechanism ensures responsible use in high-risk scenarios.
Pricing
Standard API pricing is $10 per million input tokens and $50 per million output tokens. Specific access requires review through the Trusted Access Program; detailed prices are subject to the official website.
Summary
Claude Mythos 5.1 is a restricted flagship model launched by Anthropic for research and security fields, excelling in cybersecurity and protein design capabilities while supporting high-risk research through relaxed dual-use guardrails. Its safety evaluation shows chemical and biological risk as CB-1, low risk for automated AI R&D, but catastrophic harm assessment adjusted to low, reflecting higher uncertainty regarding recent events. Pricing and access are strictly controlled, making it suitable for professional institutions.
Version History
- Claude Mythos 5.1 launched via trusted access programs (2026-09-01): Anthropic released Claude Mythos 5.1, the research-restricted configuration sharing the same underlying model as Fable 5.1 with more permissive safeguards in dual-use domains such as biology and cybersecurity. Direct access is limited to vetted individuals and organizations through trusted access programs; its capabilities also power Claude Security for enterprise customers. Anthropic reports its strongest-ever cyber capabilities (meeting or exceeding Mythos 5 on its internal suite) and a materially lower tendency than Mythos 5 to seek resources outside its test environment; roughly half of its protein designs across 12 targets were confirmed viable binders.