When Anthropic launched its most capable AI model on June 9, 2026, it did not just give it a version number. It gave it a class. The company called Claude Fable 5 a "Mythos-class" model, a label meant to signal a step up in raw capability and a step up in the controls that come with it. Within days that label would help trigger a U.S. export-control fight. So it is worth understanding what a model "class" actually is, and why labs are increasingly sorting their systems this way.
Start with the simple part. "Mythos-class" is Anthropic's name for its highest capability tier, one it says sits above its earlier Opus line. There is one underlying frontier model at that level. Anthropic then wraps it in different safety settings and ships those as separate, named products. Fable 5 is the version anyone can use, with guardrails switched on. Mythos 5 is the same engine with some of those guardrails lifted, and it stays restricted to roughly 50 vetted partners in a cyberdefense program the company calls Project Glasswing. Same brain, two different keys.
The capability jump is real. Anthropic says Fable 5 leads on nearly all the benchmarks it tested, especially on long, complex tasks such as multi-hour coding runs and scientific research. It costs $10 per million input tokens and $50 per million output tokens, double the price of Claude Opus 4.8. Developers reach it through the model ID claude-fable-5, with a one-million-token context window.
The more interesting part is the safety machinery bolted to the class. Fable 5 ships with a set of classifiers, separate AI systems that watch for misuse. When a request touches cybersecurity, biology and chemistry, or "distillation" (copying the model's abilities into a rival system), the answer is quietly handed off to the weaker Opus 4.8 instead, and the user is told. Anthropic says this happens in fewer than 5% of sessions, and that more than 1,000 hours of outside red-teaming found no universal jailbreak.
So why bother with classes at all? The logic sits inside Anthropic's Responsible Scaling Policy, which uses a ladder of "AI Safety Levels." Each rung answers one question: as a model grows more capable, what protections must be in place before it can be trained or deployed? A more powerful model is not dangerous in everyday use. The concern is that if its guardrails fail, the damage could be far worse than with a weaker system, because the same model that helps a scientist could, in the wrong hands, help build a weapon. Sorting models by tier lets a company attach mandatory rules to each level: stronger testing, tighter access, and fallback filters like the ones in Fable 5.
Anthropic is not alone in this shift. OpenAI runs a similar "Preparedness Framework" that grades models by risk in areas like cybersecurity and biology. The pattern is the same: a version number tells you which release you have, while a class or level tells you how much the lab thinks it needs to worry.
Beyond the mechanics, the value of these labels is contested. Simon Willison, an independent developer who reviews new models, called Fable 5 "a beast" and said the tiered restrictions made sense to him: "I think the security risks really are credible here, and having extra time for trusted teams to get ahead of them is a reasonable trade-off." But he also flagged a hidden side of the class. Anthropic, he noted, built in invisible interventions that degrade the model's answers when a user tries to design competing AI systems, with no visible fallback message. Willison said he was not thrilled about "a model that secretly distorts its answers" to slow down rivals. A capability class, in other words, can protect the public and protect the company's own interests at the same time, and the two are not always easy to tell apart.
The labels also carry weight outside the lab. On June 12, three days after launch, the U.S. Commerce Department ordered Anthropic to disable both models on national-security grounds, after a reported jailbreak alarmed officials. Anthropic disputed the framing and said comparable models, including OpenAI's, could do the same things without facing controls. Critics warned about the precedent. "If you describe your product as a munition in every press release, eventually a government takes you at your word," cybersecurity researcher Peter Girnus wrote on X. By late June the administration had begun lifting the restrictions after Anthropic added a new filter it says blocks the workaround more than 99% of the time.
The takeaway for anyone watching AI is that the marketing has quietly changed. A model's power is no longer just a number that goes up; it is now a category that decides what you are allowed to do with it, and sometimes what governments will allow at all. As more labs adopt these tiers, the open questions are who defines the thresholds, whether the safeguards are applied evenly across competitors, and how much a private company's "class" system should shape public access. Those debates, more than any benchmark score, are what to watch next.