Anthropic’s Transparency Hub

A look at Anthropic's key processes, programs, and practices for responsible AI development.

Model Report

August 17, 2026

Select a model to see a summary that provides quick access to essential information about Claude models, condensing key details about the models' capabilities, safety evaluations, and deployment safeguards. We've distilled comprehensive technical assessments into accessible highlights to provide clear understanding of how the models function, what they can do, and how we're addressing potential risks.

Claude Opus 5 Summary Table

Model descriptionClaude Opus 5 is a thoughtful and proactive model that comes close to frontier intelligence. On some coding and knowledge work evaluations Opus 5 is the new state-of-the-art.
Benchmarked CapabilitiesSee our Claude Opus 5 system card’s Section 8 on capabilities.
Acceptable UsesSee our Usage Policy
Release dateJuly 2026
Access SurfacesClaude Opus 5 can be accessed through:
  • Claude.ai
  • Claude Code
  • The Anthropic API
  • Amazon Bedrock
  • Google Vertex AI
  • Microsoft Azure AI Foundry
Software Integration GuidanceSee our Developer Documentation
ModalitiesClaude Opus 5 can understand both text (including voice dictation) and image inputs, engaging in conversation, analysis, coding, and creative tasks. Claude can output text, including text-based artifacts, and diagrams.
Knowledge Cutoff DateClaude Opus 5 has a knowledge cutoff date of May 2026. This means the models’ knowledge base is most extensive and reliable on information and events up to May 2026.
Software and Hardware Used in DevelopmentCloud computing resources from Amazon Web Services, Google Cloud Platform and Microsoft Azure, supported by development frameworks including PyTorch, JAX, and Triton.
Model architecture and training methodologyClaude Opus 5 was pretrained on large, diverse datasets to acquire language capabilities. After the pretraining process, Opus 5 underwent substantial post-training, with the goal of making it an effective assistant whose behavior aligns with the values described in Claude’s constitution.
Training DataClaude Opus 5 was trained on a proprietary mix of publicly available information from online sources, public and private datasets, user data, and synthetic data generated by other models. Throughout the training process we used several data cleaning and filtering methods, including deduplication and classification.
Testing Methods and ResultsBased on our assessments, we deployed Claude Opus 5 with ASL-3 protections, treating it as having CB-1 capabilities. Autonomy threat model 1 is applicable to Claude Opus 5. See below for select safety evaluation summaries.

The following are summaries of key safety evaluations from our Claude Opus 5 system card. Additional evaluations were conducted as part of our safety process; for our complete publicly reported evaluation results, please refer to the full system card.

User Wellbeing Summary

We run a suite of evaluations to understand how Claude responds in scenarios related to child safety and mental health. Claude is not a substitute for professional advice or medical care and is not intended to diagnose or treat any medical condition. We use these evaluations to understand how Claude performs in sensitive contexts and where we can make improvements. For more in depth descriptions of the evaluations and their results, please see Claude Opus 5 system card.

  • Child Safety: Overall, Claude Opus 5 ’s performance on child safety was comparable to Claude Opus 4.8. On single-turn requests, the model saturated benchmarks with a 100% harmless response rate on harmful requests while maintaining near-zero over-refusals to benign prompts. Multi-turn performance (testing across an extended back-and-forth conversation) on the API and claude.ai demonstrated similar performance across recently released models including Claude Opus 4.6, Sonnet 5, and Fable 5. While Opus 5 consistently refused to provide meaningful assistance for child sexual exploitation and abuse, it sometimes accepted innocent-sounding framing before refusing when bad intent became clear in multi-turn conversations on the API; claude.ai system prompt interventions help to address this. (Section 4.2)
  • Mental Health – Suicide and self-harm: Opus 5's handling of suicide and self-harm conversations is mixed relative to Claude Opus 4.8, showing evidence of improvements in some areas and regression in others.On multi-turn testing (testing across an extended back-and-forth conversation) it scored 90% on claude.ai (vs. 85% for Opus 4.8). Qualitatively, Opus 5 more consistently anchored to the user’s interpretation and disclosure of their lived experiences, rather than making implicit assumptions about the user’s emotional state or potential motives for engaging in self-harm behaviors. At the same time, its responses were at times overly long and circuitous, which may be overwhelming to an individual who is actively struggling. This behavior appeared primarily on the public API without a system prompt. (Section 4.3.1)
  • Mental Health – Disordered eating: Opus 5 performed similarly to Opus 4.8, with high harmless response rates, minimal refusals of harmless requests, and more frequent referrals to tailored professional treatment resources. It also more often surfaced calorie and BMI figures when warning users about under-eating, which runs counter to expert guidance; system prompt updates mitigated this on claude.ai. (Section 4.3.2)
  • Misleading the user: Claude Opus 5 misleads the user at rates similar to or lower than Opus 4.8, Mythos 5, and Sonnet 5. The one exception is input hallucination, where the mean rose slightly but within the range of expected noise. (Sections 6.4.3)

External Red Teaming

The IPI benchmark was built in partnership with Gray Swan, the UK AI Security Institute, the US Center for AI Standards and Innovation, and other model developers. It builds on Gray Swan’s published red-teaming competition 3 with a new set of 28 scenarios in which participants were tasked with finding attacks against frontier models. These scenarios test susceptibility to indirect prompt injections that attempt to induce harmful actions, including private data exfiltration, data destruction, system compromise, and unintended financial transactions. The scenarios are designed to match the difficulty of real tasks frontier models can do today, including coding, computer use, and tool use. After deduplicating attacks, we selected 1,130 attacks that showed high transferability across target models. We evaluated Claude models without additional safeguards; other frontier models are evaluated on their publicly available endpoints, which may or may not include additional safeguards.

Indirect prompt injection attacks from the Gray Swan IPI benchmark (Q1 2026), lower scores are better. All models use extended thinking. Results represent the probability that an attacker finds a successful attack after k=1, k=10, and k=15 attempts. Lower is better. Results for Gemini 3.1 Pro are not directly comparable as this model was included in the red-teaming competition used to source attacks.


On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt. It also improved on Sonnet 5 (5.9% at k=15) and Mythos 5 (2.6%), making it the most robust model evaluated. Opus 5 also outperformed all non-Claude models on this benchmark. The most robust non-Claude model was Muse Spark at 16.5% within 15 attempts—more than eight times Opus 5’s rate. The most capable GPT 5.6 variant, Sol, was comparable to its predecessor GPT 5.5 (20.0% versus 20.8% within 15 attempts), and was 10 times as likely to be successfully attacked as Claude Opus 5 at 2.0%. The other GPT 5.6 variants are less robust, at 30.4% (Terra) and 43.9% (Luna). A single attempt against GPT 5.6 Sol succeeded 3.1% of the time, higher than the 2.0% an attacker achieved against Opus 5 after fifteen attempts.

Alignment

Generally, we find Claude Opus 5 to be better aligned (meaning its behavior more consistently matches the values and rules we intend it to follow) than Opus 4.8. It also appears largely better aligned than Mythos 5, with very few exceptions on core areas of alignment we measure: ignoring limits explicitly set in its instructions, refusing requests that are unlikely to cause harm, hallucination of inputs (stating false information about material the model was given, as if it were true), an unduly discouraging tone, and condescension. This holds across our broader measure of misaligned behavior, our measure of adherence to Claude's constitution, and many of the individual misuse measures presented below.

[Figure 6.4.3.A] Scores from our automated behavioral audit for the dishonesty-related metrics given below. Lower numbers represent a lower rate or severity of the measured behavior; on all graphs in this figure lower is better. The y-axis is truncated below the maximum score of 10 in many cases. Reported scores are averaged across all approximately 3,200 investigations per target model (approximately 1,600 seed instructions sampled twice), with each investigation generally containing many individual conversations. Shown with 95% CI.

RSP Evaluations

Our Responsible Scaling Policy (RSP) evaluation process is designed to systematically assess our models' capabilities in areas where they could pose catastrophic risks before we release them. Opus 5 is not more capable overall than our most capable general-access model, Claude Fable 5. Opus 5's alignment risk, which is the risk that a model behaves in ways Anthropic did not intend, is very low: it shows no new concerning alignment properties relative to prior models. On automated AI research and development, Opus 5's capabilities are comparable to those of Claude Mythos 5, our current frontier in this area, but it does not cross the RSP capability threshold. We have not observed a sustained doubling in the pace of our AI progress attributable to AI, and the model is not close to substituting for our research scientists and engineers. On chemical and biological weapons, it is difficult to say with full confidence whether any model passes our threshold for basic weapons capabilities. However, Opus 5 is broadly more capable than previous models we have conservatively treated as able to significantly help individuals with basic technical backgrounds produce (non-novel) weapons, so we treat it as having that capability and deploy commensurate safeguards, including real-time classifiers to prevent harm. With these mitigations we believe catastrophic risk in this category is low but not negligible. For novel weapons development, Opus 5 shows significant gains over Opus 4.8 on our automated evaluations and performs comparably to, and on some evaluations slightly better than, Claude Mythos 5. However, additional evidence indicates Mythos 5 remains the stronger model in this domain, and we conclude that Opus 5 does not cross the threshold for novel weapons capabilities. We apply the same protections we applied to Opus 4.8.

Related content

RSP Updates

Overview of past capability and safeguard assessments, future plans, and other program updates.

Read more

Privacy Center

A central hub for information related to data privacy at Anthropic.

Read more

Trust center

This page acts as an overview to demonstrate our commitment to compliance and security.

Read more

Developer Documentation

Learn how to get started with the Anthropic API and Claude with our user guides, release notes, and system prompts.

Read more