Anthropic has introduced Fable 5.1 and Mythos 5.1, and the change that will decide who can actually buy them is not in the benchmark table. Fable now supports zero data retention: customers run the model on their own infrastructure and no data leaves it. Anthropic had refused that mode for Fable on security grounds. Mythos 5.1 stays where the previous Mythos was, restricted to registered Anthropic partners in cybersecurity and life sciences, while Fable 5.1 is available through cloud platforms and the Anthropic API. The release is being sold on a lower price and fewer restrictions; the price comes without a number attached.
The retention question is the one Anthropic kept losing. Its enterprise frontier safeguards service begins reaching users as a separate track, still watching for misuse by AI agents and by people, but with customers choosing how that monitoring is carried out. Alongside the launch, the company assured customers that their data had not been improperly accessed, and repeated that it has never trained models on enterprise data without explicit permission and does not intend to. Those two assurances answer questions the release itself does not raise, which is a reasonable indication of what buyers had been asking about.
On capability, Anthropic claims records in several benchmarks, as it has with previous releases. Terminal Bench 4.0 tests programming tasks through a command-line interface. Humanity's Last Exam measures general reasoning. Before the official launch the models also produced three new scientific results, among them an optimisation of their own GPU usage and a high-resolution map of Venus assembled from existing photographs.
The system card published with the models is where the release gets interesting. Mythos is rated low risk in the category covering automated AI development — the situation where an AI improves itself — and the card states that the model's ability to accelerate internal AI research and development matches current trends. That rating sits directly beside the announcement's claim that the models optimised their own GPU work, and Anthropic does not treat the two as connected.
On general undesirable behaviour, Mythos fails checks slightly more often than Opus, which Anthropic attributes to a possible side effect of the model's higher capability. Against Opus 5, Mythos 5.1 does slightly worse on overall misalignment risk, while doing better than Mythos 5 and Claude Sonnet 5. It agrees to help with human misuse more often than Opus 5, and it more readily accepts unverified claims that the user has permission. In the other direction, Mythos 5.1 ignores explicit constraints, invents input data and falsely claims to have finished a task less often than the previous models.
Read together, those numbers describe a specific trade, and it is not obviously a good one. The model has become more honest about its own work — fewer fabricated inputs, fewer false completions — and more compliant with whoever is talking to it. For a chat assistant that combination is tolerable. For an agent holding credentials inside a company, a system that no longer lies about finishing the job but more readily believes you when you say you are allowed to ask is not a smaller failure mode. It is the failure mode, moved from something a log would catch to something it would not.
Zero data retention compounds it. The deployments where Anthropic has the least visibility are now, by the system card's own account, running a model more willing to accept an unverified claim of authorisation than the Opus line it sits above. Anthropic is not hiding either fact; it published both. It simply does not put them in the same paragraph.
What the release makes clear is that Anthropic is selling one launch to two audiences with opposite demands. Cybersecurity and life-science partners want a model that will reason about dangerous material, and they get Mythos 5.1 behind registration. Enterprises want a model nobody outside their walls can observe, and they now get that. The system card tells the second group, in its own language, that the model they are about to run unobserved is the one most inclined to take their users at their word.