Sonnet 5 Is the Workhorse; Fable and Mythos Are the Dual-Use Split

Anthropic’s June-July 2026 release wave is not three unrelated model drops. It is a deliberate split: Sonnet 5 as the default agentic workhorse with cyber safeguards on, Fable 5 as Mythos-class capability wrapped in classifier fallbacks for general users, and Mythos 5 as the same weights with safeguards lifted for trusted defenders. The hype mistake is treating “most agentic Sonnet” and “strongest cyber model” as one product decision. They are opposing deployment postures on a shared capability frontier.

Featured visual
Featured visual for this News Dossier.
Lecture map: Sonnet 5 Is the Workhorse; Fable and Mythos Are the Dual-Use Split
Operating map for this News Dossier.

Sonnet 5: the agentic workhorse

BrowseComp · OSWorld-Verified · intro pricing · cyber safeguards default

Claude Sonnet 5 is positioned as the most agentic Sonnet yet: planning, browsers, terminals, and sustained autonomous runs at a price point closer to Opus 4.8 than previous Sonnets. Anthropic reports strict improvement over Sonnet 4.6 on agentic search and computer use across effort levels, with cost-performance curves that sometimes match Opus 4.8 on selected tasks.

“Claude Sonnet 5 is built to be the most agentic Sonnet model yet. It can make plans, use tools like browsers and terminals, and run autonomously at a level that, just a few months ago, required larger and more expensive models.” – Anthropic, Introducing Claude Sonnet 5

Pricing is explicitly time-boxed: $2 per million input tokens and $10 per million output through 31 August 2026, then $3/$15. Anthropic notes an updated tokenizer can map the same text to roughly 1.0–1.35× more tokens, with introductory pricing intended to keep migration roughly cost-neutral. Sonnet 5 is default on Free and Pro; available on Max, Team, and Enterprise; API id `claude-sonnet-5`.

“From today, Claude Sonnet 5 is available across all plans: it is the default model for Free and Pro plans, and is available to Max, Team, and Enterprise users. It’s also available in Claude Code and on the Claude Platform, where it launches with introductory pricing of $2 per million input tokens and $10 per million output tokens through August 31, 2026, after which it will be priced at $3 per million input tokens and $15 per million output tokens.” – Anthropic, Introducing Claude Sonnet 5

Safety posture differs from Mythos-class releases. Anthropic did not deliberately train Sonnet 5 on cybersecurity tasks. It shows substantially poorer dangerous cyber performance than Opus 4.8 and Mythos 5 on Firefox exploit development evals (0% full exploits for Sonnet models). Because Sonnet 5 is somewhat stronger than Sonnet 4.6 on partial cyber tasks, it launches with cyber safeguards enabled by default, using the same real-time blocking stack as Opus 4.7/4.8, less strict than Fable 5’s launch safeguards.

“Since Sonnet 5 is somewhat stronger than its predecessor on these tasks, we’ve launched it with cyber safeguards enabled by default.” – Anthropic, Introducing Claude Sonnet 5

For teams building everyday agents, Sonnet 5 is the sensible default in Anthropic’s stack: strong tool follow-through, lower tariff than Opus, safeguards on. Route heavy cyber work to Opus 4.8 with Cyber Verification Programme access, not to Sonnet with safeguards disabled (you cannot). This aligns with tiered routing in LLM routing by task complexity and cost-aware orchestration in cost-per-task harness design.

Merits of the argument. Anthropic’s own evals show Sonnet 5 narrows the Opus gap on agentic tasks without matching Mythos cyber ceilings. The tokenizer caveat is load-bearing for budgets: “$2/$10” is not automatically cheaper per real prompt. The cyber safeguard default is credible given partial-success upticks. Weak spot: introductory pricing ends 31 August 2026; architecture decisions should use post-intro $3/$15 for steady-state TCO.

Fable and Mythos: one model, two postures

Mythos-class · Project Glasswing · classifier fallback · trusted access

Claude Fable 5 and Claude Mythos 5 share one underlying model. Fable 5 is “a Mythos-class model that we’ve made safe for general use” with safeguards that route some cyber, bio/chem, and distillation-flagged requests to Opus 4.8 instead of refusing outright. Mythos 5 is the same weights with cyber safeguards lifted for Project Glasswing partners and expanding trusted access. Footnote naming: Fable from Latin fabula (“that which is told”); Mythos from Greek mythos; safeguards are the product difference.

“Releasing a model this capable comes with risks.” – Anthropic, Claude Fable 5 and Claude Mythos 5

“For a small group of cyberdefenders and infrastructure providers, we’re also launching Claude Mythos 5. It’s the same underlying model as Fable 5, but with the safeguards lifted in some areas.” – Anthropic, Claude Fable 5 and Claude Mythos 5

Fable 5 pricing is $10/$50 per million tokens (under half Mythos Preview pricing). Anthropic states safeguards trigger on average in less than 5% of sessions, with more than 95% of sessions seeing no Opus fallback, but deliberately conservative tuning causes false positives on benign cyber-shaped requests. Mythos 5 is described as the strongest cybersecurity model Anthropic offers, deployed first through Glasswing with US government collaboration.

Merits of the argument. The dual-use split is explicit in primary sources, not analyst inference. Fallback-to-Opus is a product choice to avoid hard refusals whilst limiting Mythos uplift in general chat. Risk: users experience “Fable” branding but sometimes get Opus behaviour without noticing the swap. Mythos access remains gated; do not architect consumer features on Mythos assumptions.

Redeployment, export controls, and safeguard iteration

June 12 suspension · Amazon bypass report · classifier patch · industry jailbreak framework

Fable 5 and Mythos 5 launched 9 June 2026. Access suspended 12 June after US export controls required restricting foreign nationals; Anthropic could not verify nationality in real time. Export controls lifted 30 June; global Fable access restored 1 July with Mythos restored for approved US Glasswing organisations. Parallel safeguard work: Amazon researchers reported a bypass where Fable identified vulnerabilities and, in one case, produced exploit demonstration code. Anthropic tested and found many less capable models could identify the same vulnerabilities; all tested models could produce the same demonstration. They judged the technique a borderline false-positive case, not unique Mythos-level uplift, but still shipped an improved classifier blocking the specific technique in over 99% of cases.

Anthropic’s redeployment post outlines defence-in-depth: training refusals, retroactive misuse analysis, and classifiers with an enlarged “safety margin” that blocks ambiguous cyber requests (row B vs row A in their diagram). Minor jailbreaks may intrude into the safety margin without reaching core harmful behaviours; universal jailbreaks remain the top concern. They propose an industry jailbreak severity framework (capability gain, breadth, ease of weaponisation, discoverability) with Amazon, Microsoft, Google, and Glasswing partners, plus deeper US government pre-release testing.

Merits of the argument. The timeline shows capability launches and governance can collide in the same week. The Amazon bypass was real enough to trigger export controls and classifier retraining, yet Anthropic’s comparative testing downgrades its uniqueness. Operators should treat Fable as high-capability with noisy guardrails, not as “safe because renamed.” For multi-agent stacks, coordinator models must handle fallback notifications and session continuity when classifiers route to Opus; see multi-agent coordination.

Named failure cases

Failure mode What goes wrong Mitigation
Assuming Sonnet 5 equals Mythos for cyber Team picks Sonnet for purple-team automation; hits safeguards or lacks exploit depth Use Cyber Verification / Opus 4.8 for reduced-guardrail cyber; Mythos only via trusted programmes
Ignoring tokenizer inflation Budget model built on old Sonnet token counts; August intro expiry surprises finance Re-benchmark prompts on Sonnet 5 tokenizer; plan at $3/$15 from September
Fable fallback blindness Users think Fable solved a cyber-shaped task; Opus actually responded Surface Anthropic fallback notices in logs; tag traces with effective model id
False positive frustration Legitimate defensive cyber queries fall back or block under conservative classifiers Apply trusted access programmes; document retry paths; expect iterative narrowing per Anthropic
Single-model agent default Running Fable for all agent steps when Sonnet 5 suffices at half the tariff Route planner/worker tiers; Fable only when long-horizon or specialist evals justify cost
Export-control surprise Global team assumes Mythos/Fable availability; access suspended without nationality verification Track model availability by region and plan; maintain Sonnet/Opus fallbacks in manifest

Migration steps

  1. Default new agent workloads to Sonnet 5 on Claude Code, Platform, and API where Opus was overkill for cost.
  2. Re-run token and cost baselines on representative prompts with Sonnet 5 tokenizer; compare intro vs post-August pricing.
  3. Reserve Fable 5 for long-horizon coding, research, and vision-heavy tasks where partners report step-change gains; monitor fallback rates in logs.
  4. Keep Mythos/Fable cyber split explicit in security architecture: consumer paths on Fable with safeguards; defensive cyber on Mythos/Glasswing or Opus CVP only.
  5. After Amazon-class bypass news, retest any automation that depended on borderline cyber-shaped Fable behaviours; expect stricter classifier hits.
  6. Implement model routing tables aligned with sudoall cost-per-task patterns: Sonnet for volume agents, Fable for frontier sessions, Opus/Mythos for verified cyber lanes.

When it is actually fine

Sonnet-only shops · Fable without cyber prompts · Opus for cyber CVP

Stay on Sonnet 4.6 or Opus only when: you have not revalidated prompts on Sonnet 5 tokenizer; your workload is short non-agent chat; or compliance requires a frozen model id until a formal change window. Using Fable without touching cyber/bio/distillation-shaped prompts is fine for many coding and knowledge tasks; Anthropic reports >95% of sessions without fallback. Using Opus 4.8 for cyber with Cyber Verification is fine and Anthropic’s own recommendation over disabling Sonnet safeguards. Mythos is not fine for general product features; it is fine inside approved defender programmes.

What to check right now

  • Which Claude model id is your agent default today? Should it be `claude-sonnet-5`?
  • Have you measured token count delta on top 20 production prompts vs Sonnet 4.6?
  • Do logs record when Fable requests fall back to Opus 4.8?
  • Is any workflow assuming Mythos availability outside Glasswing/trusted access?
  • Calendar reminder: 31 August 2026 intro pricing expiry for Sonnet 5 TCO review.
  • For cyber automation, is Cyber Verification Programme enrollment documented with Opus 4.8 as the reduced-guardrail path?
  • Multi-agent orchestrators: do sub-agents use mixed tiers or one expensive model for all roles?

Sources and references

Primary links for every quotation and load-bearing number in this dossier. Verify before you reuse a figure elsewhere.

nJoy 😉

Leave a Reply

Your email address will not be published. Required fields are marked *