What happened
Anthropic's release turns a policy distinction into product packaging. Fable 5.1 is the version most customers can use. Mythos 5.1 exposes stronger sensitive-domain capability through controlled programs. The company says the models are the same at their core; the difference is the safeguard regime and who can gain access.
The price change is concentrated in cache reads, where a model reuses input it has already processed. Anthropic estimates a 25% reduction for typical token-priced workloads and says heavily agentic applications may save as much as approximately 45%. That qualification matters: those are company estimates, not a universal discount. Actual savings depend on how often an application reuses context and which effort settings it selects.
The release also introduces Enterprise Frontier Safeguards, or EFS. Anthropic says the system is intended to provide privacy equivalent to zero data retention while still detecting adversarial use by keeping relevant data in cloud infrastructure controlled by the customer rather than Anthropic. The company plans a phased enterprise rollout beginning later this fall. Eligible customers can use Fable 5.1 with zero data retention until EFS is available.
On cybersecurity, Anthropic says the new safeguards produce 60% fewer false positives than the previous version. Fable 5.1 may be used to discover software vulnerabilities but is designed to block development of exploits. Mythos is the route for more advanced cyber work. In biology, Anthropic says it developed an access program with the U.S. government and expects to open enrollment for scientists. A separate safeguards note describes the framework behind the release.
Fable 5.1 also adds a more visible effort dial. Anthropic says the model defaults to High effort in Claude Code and Medium in Claude Cowork and on Claude.ai. That makes cost, latency, and result quality a configuration choice rather than a property implied by a single model name.
Why it matters
The general/trusted split is a preview of how frontier models may be sold as capabilities become more uneven. A single model can be ordinary enough for daily coding and powerful enough to require special handling in a sensitive domain. Naming both tiers helps customers understand that distinction, though it also creates more procurement and governance work.
For agent builders, the cache-price change could matter more than a headline token price. Long-running agents repeatedly read instructions, histories, and workspace context. Reducing the cost of those reads changes which workflows are economical. Teams should still test with their own traces: an estimated saving from a vendor is not a bill forecast.
EFS is the most consequential promise in the announcement. Enterprises have often had to choose between strong monitoring and strict data-retention rules. Customer-controlled storage could narrow that tradeoff if the implementation matches the description. The open questions are operational: supported cloud setups, auditability, failure handling, and who can inspect what when a system flags misuse.
The fine print
The benchmark, price, and safeguard figures are Anthropic's claims. The company's article shows internal and selected external evaluations, but independent tests across production workloads are still needed. Mythos access criteria and the biology program are not the same thing as broad availability.
The model family now comes with two names, several effort levels, and an access program. Frontier intelligence has discovered enterprise packaging.
