GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
GPT-56T 861 —
MUSE-SPK 835 -0.7%
GPT-56SC 828 -5.2%
QWEN-38X 824 —
CL-OP55X 822 —
GROK-46H 822 -5%
GPT-6A 820 —
GLM-5 784 -8.4%
CL-FAB5H 743 -5.6%
KIMI-K3X 742 -8.4%
CL-OP5H 720 -5.8%
CL-OP5X 709 -18%
CL-OP46H 698 -5.9%
CL-OP47H 690 -5.9%
GEM-38FH 677 +0.1%
GEM-37FH 657 -24%
GPT-56S 622 —
CL-OP47 582 -0.7%
GPT-55H 582 —
INKL 531 —
GEM-31P 513 —
GEM-3P 499 —
CL-OP46 496 -0.2%
CL-OP48 490 —
← Back to feed

Anthropic's August 2026 Risk Report Names Two Unreleased Frontier Models — All Claude Lines Provisionally Hit CB-1

Anthropic published its August 2026 safety risk report Friday, disclosing that as of July 15 — the report’s coverage date — three internal models with frontier or near-frontier capabilities had not been publicly released. Claude Opus 5 was one; it has since launched. The second, referred to as Model 1, is described as “broadly similar in capability to Claude Mythos Preview and Mythos 5.” The third is not named.

The disclosure marks the most detailed public account yet of Anthropic’s unreleased model pipeline. Mythos 5 — the company’s most capable and most restricted model — is already available only to Glasswing security partners. A second model in that capability class sitting in Anthropic’s queue signals the frontier is advancing faster than the release cadence suggests.

CB-1: Every Line Over the Threshold

The report confirms that every frontier Claude release since Opus 4 has been assessed as provisionally meeting the CB-1 threshold. CB-1 is Anthropic’s most consequential internal safety bar: a frontier developer must make a strong argument that no user or team — including those backed by top-tier state actors — could become significantly more likely to cause catastrophic harm by accessing the model’s product surfaces or by stealing its weights.

Provisionally meeting CB-1 does not mean the model failed the test. It means the capability risk profile is high enough that the threshold must be actively defended rather than assumed. Anthropic’s prior reporting drew a distinction between meeting CB-1 and crossing it; this language suggests the company has converged on all current releases requiring that active defense.

Bio Risk: The Hardest Signal to Read

The report singles out biological risk as the area where standard benchmarks provide the weakest signal. Anthropic’s position: “gestalt expert opinions after extended experience eliciting help with difficult biological tasks from a model offer some of the most informative signal we have about risk-relevant model capabilities, even though it is difficult to make legible.”

That phrasing matters. It acknowledges that the most credible bio-risk assessments are expert-judgment calls that cannot be fully operationalized as reproducible tests. As models improve at biological reasoning tasks, the gap between what can be measured and what can be done widens.

The Acceleration Scenario

The report defines “dramatic acceleration” as observing or expecting double the current rate of frontier progress, driven by automation of AI R&D. That framing sets the clock: Anthropic is managing for a scenario where the pace of capability improvement roughly doubles, not one where it stays linear.

The combination — two unreleased Mythos-class models in the pipeline, all current releases at CB-1, and an explicit doubling-rate scenario on the horizon — amounts to the most candid public accounting of near-term frontier risk that any major lab has released.

What the Report Does Not Say

The report does not release CB-1 scores, bio-risk elicitation transcripts, or capability comparisons for Model 1 beyond the Mythos-similarity characterization. The Glasswing program, which gives vetted security partners access to Mythos 5 for cyber defense work, is not mentioned. The third unreleased model is not described.

Anthropic’s previous safety reports have correlated with near-term release timelines. The existence of a second Mythos-class model in the pipeline suggests a next-generation frontier release is closer than current public roadmap signals.