On 9 June 2026, Anthropic launched Claude Fable 5, the first publicly available version of its Mythos-class AI models. Until that day, this class of models was accessible only to a small group of partners through Project Glasswing — including cyber defenders, critical infrastructure operators and organisations with Cyber Verification Program (CVP) approval. From now on, anyone with a Claude subscription or API key can work with it.
In this guide we explain, from Rootsec’s perspective, exactly what Claude Fable 5 is, how to use it, what it costs, how it compares to Claude Mythos 5 and Claude Opus 4.8, and what it means in concrete terms for organisations across the UAE and the wider GCC when it comes to cybersecurity. No marketing — just an honest technical view.
Rootsec is an Anthropic-validated partner within the Cyber Verification Program. That means we have access to Mythos-class capabilities used in offensive security workflows, including the more tightly held Claude Mythos 5. We use that position here to look beyond the press releases.
What is Claude Fable 5?
Claude Fable 5 is the most capable AI model Anthropic currently makes publicly available. It is a Mythos-class model with built-in safety classifiers, launched on 9 June 2026. The model is available directly through Claude.ai (Pro, Max, Team, Enterprise) and via the Anthropic API under the model ID claude-fable-5.
At its core, Claude Fable 5 is the same underlying model as Claude Mythos 5. The difference is the safety layer. Mythos 5 does not have one; Fable 5 does. When a user asks a question that triggers a classifier (for example, something touching on offensive cyber, biology or chemistry), the response is automatically taken over by Claude Opus 4.8. The user is notified when this happens. According to Anthropic, this occurs in fewer than 5% of all sessions.
Key specifications:
- Context window of 1 million tokens
- Maximum of 128,000 output tokens per call
- Knowledge cut-off of January 2026
- State of the art on benchmarks for software engineering, knowledge work, vision and scientific research
- Available on Claude.ai, the Anthropic API, Claude Code, AWS Bedrock, Google Cloud and Microsoft Foundry
Why is it called Fable 5?
The name comes from the Latin fabula, meaning “that which is told”. This is related to the Greek mythos. Anthropic itself frames it as a nod: it is literally the same story, simply packaged differently. Mythos for restricted applications, Fable for broad availability.
How does Fable 5 compare to earlier Claude models?
In April 2026, Anthropic announced Claude Mythos Preview. That model was immediately labelled too capable to make publicly available. It could independently find thousands of zero-days, develop exploits and carry out complex attack chains. Access was limited to roughly 150 organisations through Project Glasswing.
Claude Fable 5 is what Anthropic calls “Mythos made safe for general use”. It sits above the Opus class (Opus 4.6, 4.7 and 4.8), making it Anthropic’s new flagship for public applications.
The difference between Claude Fable 5 and Claude Mythos 5
This is probably the most frequently asked question since release. Both models were released on 9 June 2026, both fall into the same model class, but they are deployed differently.
Comparison table: Fable 5 vs Mythos 5 vs Opus 4.8
| Aspect | Claude Fable 5 | Claude Mythos 5 | Claude Opus 4.8 |
|---|---|---|---|
| Availability | Public (API, Claude.ai, cloud providers) | Project Glasswing partners and CVP only | Public |
| Safety layer | Classifiers + fallback to Opus 4.8 | No cybersecurity blocks | Standard safeguards |
| Cyber capability | Blocked for offensive use cases | Fully accessible | Limited compared to Mythos-class |
| Price (per million tokens) | $10 input / $50 output | $25 input / $125 output | $5 input / $25 output |
| Context window | 1M tokens | 1M tokens | 1M tokens |
| Max output | 128K tokens | 128K tokens | 128K tokens |
| Knowledge cut-off | January 2026 | January 2026 | January 2026 |
| Best use case | General heavy-duty tasks | Cyber defence, exploit research, agentic hacking | Broad day-to-day production workloads |
When does Fable 5 fall back to Opus 4.8?
Anthropic uses three classifiers that monitor continuously:
- Cybersecurity classifier: triggers on exploitation, offensive cyber tasks and agentic hacking (reconnaissance, lateral movement, persistence, exfiltration)
- Biology and chemistry classifier: covers dual-use biomedical research and chemical synthesis with misuse potential
- Distillation classifier: detects attempts to extract Claude’s capabilities at scale in order to train competing models
If one triggers, Opus 4.8 answers the question and the user is informed. According to Anthropic, this happens in fewer than 5% of all sessions. For the other 95%, Fable 5 runs at full capacity, equivalent to Mythos 5.
Why does Mythos 5 stay restricted?
Anthropic states that Mythos-class models have offensive cyber capabilities that could cause serious harm in the wrong hands. In earlier internal tests, the model autonomously found thousands of critical vulnerabilities and managed to produce 181 working exploits on a Firefox exploit harness, where the older Opus 4.6 achieved only two on the same benchmark. That is not a capability you want to release into the market casually.
Access to Mythos 5 runs through two paths:
- Project Glasswing: a collaboration between Anthropic and the US government, aimed at critical infrastructure providers and cyber defenders
- Cyber Verification Program (CVP): a review in which Anthropic validates offensive security organisations. Rootsec holds this status, which means dual-use offensive security capabilities fall within scope on Anthropic’s first-party products
How does Claude Fable 5 work under the bonnet?
The architecture is largely the same as Mythos 5. Anthropic trained the model on a combination of internet data, code, scientific literature and synthetic data. What sets Fable 5 apart from its Opus predecessors is the combination of:
- Long-horizon agentic reasoning: the model can work through hundreds to thousands of steps autonomously without losing the plot
- Visual perception: Fable 5 can read charts, interpret screenshots and extract structured data from visual input
- Tool calling: strong performance when invoking external tools, APIs and MCP servers
- Memory management: the model can take notes on its own and reuse them in later steps
The Opus 4.8 fallback in detail
When a classifier triggers, the following happens:
- The input is intercepted before Fable 5 responds
- Opus 4.8 takes over the query and formulates an answer with its own safeguards
- The user is notified that the answer comes from Opus 4.8
- The rest of the session can continue as normal on Fable 5
This mechanism is not a blunt refusal. You still get an answer — just not at Fable 5’s full capacity. For 95% of work you won’t notice it. For cybersecurity workflows without CVP or Glasswing access, you will.
What has Anthropic done to make Fable 5 robust?
Anthropic engaged external red teamers through a bug bounty programme. According to the figures, more than 1,000 hours of jailbreak attempts were run without a universal bypass being found. The partner that tested the classifiers reported them to be the most robust of any models they have tested, including Opus 4.7 and 4.8.
At the same time, Anthropic is candid: it considers the biology and chemistry classifier deliberately too broad. Legitimate biomedical work is now sometimes routed unnecessarily to Opus 4.8. That is something they will refine over the coming months.
How do you use Claude Fable 5?
There are four practical ways to start working with Claude Fable 5 today.
Via Claude.ai (Pro, Max, Team, Enterprise)
On the consumer subscriptions, Fable 5 is available at no extra cost from launch through to 22 June 2026. After that, usage runs on usage credits until Anthropic has built up enough capacity to include it in the subscriptions on a structural basis.
Step by step in Claude.ai:
- Log in to claude.ai with your Pro, Max, Team or Enterprise account
- Open the model picker in the chat interface
- Select Claude Fable 5
- Ask your question or give your instruction
Via the Anthropic API
For developers and businesses that want to integrate Fable 5 into their own applications:
- Model ID:
claude-fable-5 - Endpoint: the standard
/v1/messagesAnthropic API - Pricing: $10 per million input tokens, $50 per million output tokens
- No separate price for long-context usage
A practical example in Python:
import anthropic
client = anthropic.Anthropic()
response = client.messages.create(
model="claude-fable-5",
max_tokens=4096,
messages=[
{"role": "user", "content": "Analyse these log files for anomalies..."}
]
)
Via cloud providers
Claude Fable 5 is also available through:
- AWS Bedrock
- Google Cloud Vertex AI
- Microsoft Foundry
This is relevant for organisations that, for compliance reasons (such as ISO 27001, SOC 2 or sector-specific regulation), want to keep their AI traffic within a specific cloud region. For organisations across the UAE and the GCC, data residency options are an important consideration, and all three providers offer regional deployment to help meet those requirements.
Via Claude Code
For developer workflows, Fable 5 is available directly in Claude Code. This lets you put it to work in your terminal or IDE on codebases, refactors, security reviews and migrations.
When do you choose Fable 5 and when a lighter model?
Not every task needs Fable 5. The price is twice that of Opus 4.8 and five to ten times that of Sonnet 4.6. Our rule of thumb:
- Use Fable 5 for: long, complex agentic workflows, codebase-wide refactors, in-depth security analyses, multi-step reasoning across hundreds of documents, vision-intensive tasks
- Use Opus 4.8 for: day-to-day production workloads, customer-facing applications, knowledge extraction from medium-sized documents
- Use Sonnet 4.6 or Haiku 4.5 for: classification, summarisation, fast Q&A, high-volume tasks
What does Claude Fable 5 cost?
The pricing structure per million tokens:
| Model | Input | Output |
|---|---|---|
| Claude Fable 5 | $10 | $50 |
| Claude Mythos 5 | $25 | $125 |
| Claude Opus 4.8 | $5 | $25 |
| Claude Sonnet 4.6 | $3 | $15 |
That makes Fable 5 twice as expensive as Opus 4.8 and twenty percent of the price of Mythos 5. For enterprises running advanced reasoning tasks at scale, that can add up quickly. Many organisations have overshot their AI budgets in recent quarters through Opus 4.x usage. With Fable 5, it becomes important to build model-agnostic workflows in which the right model is chosen for each task.
What can Claude Fable 5 do? The benchmark claims, examined critically
Anthropic and its launch partners published a number of striking figures at release. We quote them here, but also add critical notes where appropriate.
Software engineering, according to Stripe
Stripe reported that, in a 50-million-line Ruby codebase, Fable 5 carried out a migration in a single day that had previously taken a full team two months. This is Stripe’s own claim and has not been independently verified. What it does suggest: for large-scale refactoring work in legacy codebases, Fable 5 appears to be an order of magnitude faster than manual effort.
Hebbia Finance Benchmark
On the Hebbia Finance Benchmark, a test for senior-level reasoning over financial documents, Fable 5 scores highest of all models tested. For compliance work, fund administration and risk reporting, that is relevant.
Vision tasks
According to Anthropic, Fable 5 is the best model for visual tasks. It rebuilt a web app from screenshots alone and completed Pokémon FireRed purely by looking at the screen. That sounds like fun, but the underlying capability is serious: the model can reverse-engineer UI flows, use screenshots as input for reproduction steps and pull visual data out of dashboards.
What we at Rootsec note
We have run our own cautious initial tests on internal workflows. What stands out:
- Fable 5 makes fewer mistakes in long agentic loops than Opus 4.6 or 4.7
- Tool calling is significantly more reliable, which makes it attractive for MCP integrations
- The classifier triggers more often than the reported 5% in real security workflows, especially on infrastructure questions that aren’t even offensive
- For penetration-test reports and log analysis, the combination of vision and context window is very powerful
It is not all rosy. For our offensive security workflows, we lean on Mythos 5 via CVP for the heavier tasks, because Fable 5 runs into the classifier there.
Claude Fable 5 and cybersecurity: what you need to know
This is where it gets interesting. At release, Anthropic explicitly stated that Fable 5’s capabilities in cybersecurity could cause serious harm without safeguards. That is not marketing — it is a commitment made under public accountability.
What does Fable 5 block?
Based on public documentation and our own observations, the cybersecurity classifier triggers on, among other things:
- Concrete exploitation requests (“write a working exploit for CVE-X”)
- Agentic hacking tasks (lateral movement scripts, building C2 frameworks, defence evasion)
- Reconnaissance on specific targets where the intent is offensive
- Malware development and obfuscation
What does Fable 5 not block?
What generally passes through without issue:
- Defensive security analyses
- Threat intelligence interpretation
- Code review for security vulnerabilities (defensive intent)
- Incident response support
- Compliance questions
- General security architecture discussions
This is exactly the territory where Fable 5 adds the most value for most organisations. Our AI security services help teams put models like Fable 5 to work safely for defensive analysis, threat intelligence and secure code review — without crossing the lines the classifier is designed to enforce.
Mythos 5 for cyber defenders
For organisations working on offensive security with a legitimate dual-use need (red teams, pentest firms, exploit research, threat hunting tooling), Anthropic has set up a separate route: the Cyber Verification Program.
CVP approval means Anthropic has reviewed your organisation for:
- A legitimate offensive security use case
- Sound justification of the dual-use need
- Appropriate governance around AI usage
- Compliance with applicable laws and ethical standards
Rootsec holds this status. For our clients, that means we can deploy Mythos 5 capacity where Fable 5 runs into the classifier, within the scope of legitimate pentest and red team engagements.
What Rootsec sees in practice
Since the announcement of Mythos Preview in April 2026, we at Rootsec have been experimenting with this model class in real engagements. A few observations, without leaking any client details:
- External black-box tests: for reconnaissance and attack surface mapping, Fable 5 is already excellent. It can analyse large volumes of Shodan, Censys and certificate transparency data and find patterns that take hours by hand.
- M365 / Entra ID assessments: Fable 5 interprets roadrecon and AzureHound output faster than earlier models. It can correlate misconfigurations across hundreds of role assignments.
- Report generation: long pentest reports with consistent CVSS v4.0 scoring, executive summaries and technical findings are generated in a single run without loss of quality.
- Exploit research: here Fable 5 runs into the classifier. Mythos 5 via CVP does give access, but even there the principle holds: we use AI as an accelerator, not as a replacement for skilled penetration testers.
What Claude Fable 5 means for organisations in the UAE and the GCC
The release shifts the offensive and defensive AI balance across the region.
For CISOs and security teams
Three things to act on today:
- Revisit your attack surface assumptions. Tools built on the assumption that attackers have to reconnoitre by hand are out of date. AI-driven reconnaissance is realistic.
- Accelerate your patch cadence for critical vulnerabilities. Mythos-class models can autonomously generate exploits for known CVEs. The time between disclosure and exploitation will keep shrinking.
- Invest in detecting AI-driven attacks. Classic IOC-based detection is losing value. Behavioural analytics and anomaly detection become more important. Managed XDR solutions become more valuable here.
For SMEs
The reality is that AI-driven attacks are no longer aimed only at large enterprises. Phishing, vishing and credential stuffing are becoming cheaper and more scalable. The barrier to rolling out a sector- or region-specific campaign is dropping sharply.
What to do:
- Phishing resistance via FIDO2 or passkeys
- Microsoft 365 hardening (Entra ID conditional access, MFA, restricted admin roles)
- Regular security awareness training with realistic, AI-generated scenarios
- Brand protection and domain monitoring
For pentesters and red teamers
The bar is rising. Clients will expect pentest reports to be deeper, faster and broader. That means:
- AI as an accelerator in reconnaissance, attack path mapping and reporting
- Preserving human creativity for exploitation, social engineering and novel attack chains
- CVP or comparable validation becomes a differentiator — not because you have a sticker, but because you have access to tooling that others do not
The other side: risks and critical notes
An honest assessment requires that we name the other side too.
- The classifier is not perfect. Anthropic itself calls the biology and chemistry classifier overly broad. Legitimate researchers get the Opus 4.8 fallback unnecessarily.
- The 5% fallback rate is an average. In security workflows the percentage is higher. Factor this in when you design your workflow.
- Mythos 5 is expensive. For organisations without CVP access it is not available at all. For those who do have access, costs add up quickly in large agentic loops.
- DeFi and crypto sectors are concerned. Smart contract exploitation falls into a grey area of the classifier. Various security researchers have called on people to review token approvals and move assets to hardware wallets.
- AI outputs are not ground truth. Fable 5 hallucinates less than its predecessors, but it still does. For compliance work, legal determinations or medical advice, human verification remains essential.
Frequently asked questions about Claude Fable 5
What is Claude Fable 5?
Claude Fable 5 is the AI model Anthropic launched on 9 June 2026. It is the first publicly available version of the Mythos model class, with built-in safety classifiers that automatically route sensitive questions to Claude Opus 4.8 for an answer.
What is the difference between Claude Fable 5 and Claude Mythos 5?
Both models share the same underlying architecture. Mythos 5 does not have the cybersecurity safeguards and is only available to Project Glasswing partners and organisations with Cyber Verification Program approval. Fable 5 is the public version with the classifiers active.
When was Claude Fable 5 released?
Claude Fable 5 was released on 9 June 2026 and has since been available via Claude.ai (Pro, Max, Team, Enterprise — at no extra cost through to 22 June 2026), the Anthropic API, AWS Bedrock, Google Cloud and Microsoft Foundry.
What does Claude Fable 5 cost?
The API prices are $10 per million input tokens and $50 per million output tokens. That is twice the price of Claude Opus 4.8 and a fraction of Mythos 5 ($25 input / $125 output).
How do I use Claude Fable 5?
You use Claude Fable 5 via Claude.ai by selecting it in the model picker, via the Anthropic API with model ID claude-fable-5, via one of the three supported cloud providers, or via Claude Code in your developer environment.
Is Claude Fable 5 safe for cybersecurity work?
For defensive security, threat intelligence, compliance and general security analyses, Fable 5 is perfectly usable. For offensive security tasks (exploitation, agentic hacking, malware) the classifier triggers and the query falls back to Opus 4.8. For legitimate offensive security work, Mythos 5 access via CVP is required.
Can I use Claude Mythos 5?
Claude Mythos 5 is not publicly available. Access runs through Project Glasswing (Anthropic in collaboration with the US government) or through the Cyber Verification Program for offensive security organisations. Rootsec holds CVP approval.
Is Claude Fable 5 better than GPT-5 or Gemini 3?
On most public benchmarks, Claude Fable 5 scores state of the art. Anthropic claims it outperforms earlier models on nearly all benchmarks, including Claude Opus 4.8. Which model is best for your specific use case depends on the task, your tool integrations and your price-performance ratio.
How often does the safety classifier trigger in Fable 5?
According to Anthropic, the classifier activates in fewer than 5% of all sessions. In specific domains such as cybersecurity and biomedical research, that percentage is higher. For general business and developer workflows, the fallback is barely noticeable in practice.
Does Claude Fable 5 support languages beyond English?
Claude Fable 5 supports a wide range of languages as first-class citizens, including Arabic. For business communication, contract analysis and report generation, the quality is on par with native-language models.
Conclusion: what do you do with Claude Fable 5 today?
Claude Fable 5 shifts the offensive and defensive security balance. For most organisations it is primarily a productivity accelerator for knowledge work, software engineering and analysis. For security teams, it is a reminder that the attack side is accelerating too — in the hands of both responsible parties and less responsible actors.
For CISOs, security leaders and SME executives across the UAE and the GCC, the relevant questions are not “should I ban Fable 5 within my organisation”, but “how do I adapt my detection, attack surface management and incident response to a world in which attackers have Mythos-class capabilities at their disposal”.
Rootsec helps organisations across the region and internationally with:
- Penetration testing with AI-augmented workflows (within CVP scope)
- Red team assessments and social engineering campaigns
- M365 and Entra ID security assessments
- Compliance support
- Brand protection and domain monitoring
If you want to think through what Claude Fable 5 and Mythos-class AI mean for your attack surface, your security strategy or your pentest approach, our AI security team is ready to help.
Want to know what Mythos-class AI means for your organisation’s security posture? Talk it through with Rootsec. Book a free consultation.