Anthropic is updating Claude Fable 5's biology safeguards in a way that substantially cuts down on false positives. Fable 5 users will now encounter far fewer "fallbacks"-instances where the system switches to a less capable model after a biology-related query is made. In Anthropic's testing, this update reduced biology-related fallbacks by approximately 85% across product surfaces.
As a result, Fable 5 will be able to help with a broader range of biology tasks.
In practice, users should see significantly fewer fallbacks on everyday health and educational questions-such as interpreting lab results, understanding symptoms, and learning about biology in an educational setting. Healthcare professionals will also receive more support from Fable 5 on clinical tasks.
Anthropic believes the greatest opportunity for AI to positively impact the world lies in biology and medicine, and the company is investing heavily in building responsible frontier access for biologists. Currently, Fable still falls back to Opus 5 for requests considered dual-use-including virology, toxicology, and molecular design-so it is not yet suitable for professional biology research and drug development. Anthropic is committed to closing that gap through trusted access pathways for frontier biology capabilities.
Why strong biology safeguards were built
Anthropic's objective is to get Fable 5's frontier capabilities into the hands of as many users as possible, as quickly as possible. However, doing so requires managing the increasing risks that come with models this capable. One such risk is in the field of biology: Fable 5 can now outperform experts on some highly complex biological tasks and provide operational support on others. This means it can genuinely assist a researcher developing a new medical treatment (which is why Anthropic is eager to widen access through both classifier improvements and trusted access programs). But in the wrong hands, those same capabilities could be exploited by a malicious actor, for example in developing a biological weapon. Anthropic's capability assessments show that Fable 5 could provide significant uplift to such an actor-meaning it could give them capabilities not available elsewhere.
Distinguishing between beneficial and harmful uses of AI in biology is often difficult. In some cases, researching a treatment for a disease requires scientists to produce the dangerous compounds that cause that disease. This is most evident with live vaccines, which require growing the same pathogen being targeted for prevention. It also applies to some medicines: to develop the drug captopril for treating hypertension, scientists isolated toxic components of snake venom that crash blood pressure in humans. As new biological capabilities emerge at the frontier of AI, caution is needed to ensure that new risks do not materialize ahead of potential scientific benefits.
Sophisticated actors who wish to misuse Anthropic's models know how to exploit this ambiguity to disguise their intent, making dangerous tasks look like ordinary research. The US Intelligence Community's 2026 Annual Threat Assessment makes clear that such actors exist, and that advances in biotechnology including synthetic biology and genomic editing "could lead to novel biological threats." It notes that several state actors likely maintain active offensive biological and chemical weapons programs-programs that could be accelerated by access to frontier AI models' raw capabilities.
Because of concerns about these "dual-use" capabilities (those usable for either beneficial or harmful purposes, where the boundary is not always clear), Anthropic intentionally launched Fable 5 with almost all biology queries blocked. This made the model available for users in other domains. Anthropic knew this would frustrate legitimate biology users, resulting in a high number of false positives in the near term where biology-related questions would be blocked and routed to a less capable model. Nonetheless, this tradeoff was made because the cost of Fable being misused in a dual-use domain like biology could potentially be catastrophic.
How Anthropic's biology safeguards work
One of the core protections against misuse in biology involves safety classifiers: smaller, automated AI systems that detect when Fable 5 is asked to perform a safeguarded biology task or produce harmful output (Anthropic has previously written about similar classifiers in the cybersecurity domain).
For Fable 5, when a classifier fires, the model re-routes the user's request to Opus 5-a capable model that lacks Fable 5's level of biological capability and therefore cannot provide as much assistance to a malicious user. This re-routing is the fallback that users see when their requests are blocked.
Developing precise, robust classifiers is not straightforward. For a classifier to work rapidly and consistently, it must learn the difference between "in scope" and "out of scope" content for topics and queries considered potentially harmful. Tuning the classifiers takes time and iteration to avoid both false positives (where classifiers fire on out-of-scope content) and false negatives (where in-scope content is missed). The classifiers must also be robust against bypass attempts (known as jailbreaks), which requires further research and testing.
Starting with a very broad biology classifier meant that users could access Fable 5 while Anthropic continued research to refine it. The alternative-holding back the model until more safeguards progress was made-would have delayed general access and its potential benefits by weeks or months.
Over the past several weeks, Anthropic carefully rewrote the classifier's constitution (a collection of rules helping the model distinguish between safeguarded and allowed content), taking care to carve out benign uses in detail. Feedback was solicited from a diverse range of experts both internal and external to Anthropic. Updated training data was then developed based on that constitution, the classifier was retrained, and the new classifier was verified to still generally trigger for harmful and dual-use research biology content while enabling a wider range of benign and beneficial uses.
These updates mean that-compared to at the time of Fable 5's launch-the classifier triggers for far fewer benign biology-related requests.
Conclusions
There is still much more work to be done in refining these safeguards. Some false positives will inevitably remain-requests falling within the classifier's safety margin where the request is very low-risk but the classifier still fires. As noted above, Fable will continue to block dual-use professional biology and drug development queries due to potential dual-use risk. Anthropic is fully committed to developing a safe, scalable path for researchers to use the most capable models via trusted access pathways.
Anthropic encourages users to continue sharing feedback so that safeguards can be improved even further.
Footnote: As a result of this update, the total number of fallbacks-for biology-related or any other reasons-is also expected to decrease: by roughly 67% on Claude.ai, 55% on Cowork, 17% on Claude Code, and 7% on the Claude Platform.