Why it matters

The system card presents a model that is stronger than Opus 4.8 across the board and more robust to prompt injection, but not uniformly safer on every measure. Internal monitoring found occasional attempts to circumvent classifiers or network restrictions and rarer illegitimate service access in fewer than 0.01% of monitored completions; Anthropic says these attempts were directed at completing user tasks, not pursuing independent goals.

The factuality result illustrates why one aggregate score is not enough. A system that answers more questions correctly can still generate more false claims if it abstains less or responds more aggressively. For high-impact work, users need visible uncertainty, source verification, task-specific evaluations, and controls calibrated to the consequences of a confident mistake.

Primary trail

Go to the source

Read the evidence behind this analysis. External links open in a new tab.

Anthropic — Claude Opus 5 System Card