Anthropic has rewritten the rulebook behind the safety classifier that decides which biology questions Fable 5 is allowed to answer, and the model now handles a far wider range of them. Everyday health and education queries — reading lab results, looking up symptoms, studying biology in a classroom context — should be handed off to a weaker model much less often, and clinicians should get more support from Fable 5 in clinical work. By the company's own count, the change cut model switching, for biology and everything else, by roughly 67% in Claude.ai, 55% in Cowork, 17% in Claude Code and 7% in Claude Platform.
Fable 5 launched with almost all biological requests blocked. The gate is a safety classifier: a small automated AI system that decides whether a user is asking Fable 5 to perform a protected biological task or to produce a harmful output. Anthropic has described similar classifiers for cybersecurity before. When the classifier fires, Fable 5 routes the request to Opus 5 — a broadly capable model that is weaker at biology and therefore cannot give an attacker the same level of help. That handoff is what users saw whenever a question was blocked. It is worth being precise about what this is: not a tier downgrade to a cheaper model, but a deliberate swap to a model chosen for what it cannot do.
The reason for the original posture is stated plainly. On some complex biological tasks Fable 5 already outperforms experts, and on others it can provide practical support. The same capability that helps a researcher develop a new treatment can reach someone building a biological weapon. Anthropic's capability evaluations, the company says, show Fable 5 can substantially uplift such an actor — give them abilities they would not have had from other available sources.
Separating the beneficial from the harmful is genuinely hard in this field. Developing a treatment sometimes requires producing the dangerous compound that causes the disease. Live vaccines are the clearest case: to make one, scientists have to grow the pathogen it protects against. Pharmacology has the same pattern. Captopril, a hypertension drug, came out of work isolating the toxic components of snake venom that sharply lower human blood pressure.
Anthropic frames the timing as a race condition — it does not want the risks of frontier biological capability to arrive before the scientific benefit. Experienced attackers can exploit exactly that ambiguity, hiding intent and dressing dangerous work up as ordinary research. The 2026 US Intelligence Community annual threat assessment states that such actors exist and that advances in biotechnology, including synthetic biology and genome editing, "may lead to new biological threats." The same document notes that several states likely continue active offensive biological and chemical weapons programs, and that access to basic frontier AI capabilities could accelerate them.
Building an accurate, durable classifier is not simple. It has to distinguish permitted topics and requests from ones the company considers potentially dangerous, quickly and consistently. Tuning takes time: reducing false positives, where safe content is blocked, and false negatives, where a dangerous request slips through. It also has to hold up against attempts to work around it, which requires further research and testing. Anthropic started with a very broad biological classifier because that let it open Fable 5 to users while the refinement continued. Waiting for better defenses, by the company's account, would have delayed general access by weeks or months.
Over the past several weeks Anthropic rewrote the classifier's "constitution" — the rule set it uses to tell protected content from permitted content. The new version spells out safe use cases in detail. The company collected feedback from specialists inside and outside Anthropic, generated new training data from the updated rules, retrained the classifier and validated it. The new version is still supposed to fire on malicious and dual-use biological research while allowing more safe and useful requests through. Compared with the day Fable 5 launched, it blocks far fewer safe biology queries.
Source: anthropic.com
The four percentages are the most revealing part of the announcement, and not for the reason the headline number suggests. A 67% drop in Claude.ai against 7% in Claude Platform does not mean the classifier behaves differently across surfaces; it means the over-blocking was concentrated where consumers ask health questions and nearly absent where developers call the API. The figure everyone will quote measures the surface with the least at stake.
This reads like the correction of a deliberate over-correction, and Anthropic is close to saying so outright. The company chose a classifier it knew was too broad, shipped it, and spent weeks tuning it while users absorbed the false positives. That is a defensible trade against a catastrophic downside — but it means the launch-day capability claims for Fable 5 in biology described a model most users could not actually reach. The update does not expand what Fable 5 can do. It removes a restriction the company placed on it.
Notably absent from the announcement is the other side of the ledger. Anthropic quantifies how much less it now blocks; it says nothing about whether the new constitution also lets more genuinely dangerous requests through. False negatives are named as a problem in the abstract and never measured. A classifier rewrite is a two-sided trade, and only one side has numbers attached. The same gap applies to the fix Anthropic keeps pointing at: professional dual-use biology and drug development remain blocked, and the "verified channels" that are supposed to give researchers access to frontier biological capability come with no date, no eligibility criteria and no name. Acknowledged false positives also remain by design, since some low-risk requests fall inside the classifier's safety margin and get blocked anyway.
The rest of the day's announcements point the same direction. Anthropic is opening a research preview of the Model Hardware Standard (MHS), a common specification meant to let AI agents safely control physical devices, initially for a group of scientific laboratories and advanced manufacturers. Starting today, 10,000 scientists worldwide can begin using Claude for free; verified research leads become eligible for the Claude Team plan and can then add their research team on standard seats at no cost, with enhanced-capability seats at $15 per month for up to one year. The company is also launching a $5 million grant program for independent research into AI's effect on user wellbeing.
So Anthropic is handing free access to 10,000 scientists in the same announcement in which it confirms that the capability those scientists would most want — professional dual-use biology, drug development — still gets their questions routed to a model chosen because it is worse at the job.