ModelRiskIndex

Rankings / Anthropic

Claude Opus 5

Tier 290/100

claude-opus-5 via api.anthropic.com (dateless pinned snapshot)

Usage share 1.9% · OpenRouter rankings API (daily token share, 2026-08-04)

Deployed under ASL-3 (driven by chem/bio thresholds, not cyber or autonomy). The strong injection grade reflects layered-defense results on published benchmarks, not immunity — the two injection figures in circulation (0.2% benchmark ASR vs 3.7% unlayered browser baseline) are different evaluations and are kept distinct here.

Tier assessment
Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. Safety evaluations for this model are published.
  • Documented safety policy. A documented safety, usage, or acceptable-use policy governs the model.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.
Tier 2 requirements
  • External pre-deployment testing. Independent external parties tested the model before deployment, and this is disclosed.UK AISI, Trajectory Labs, 10a Labs, and Gray Swan named; US CAISI participation unconfirmed.
  • Third-party certification. The operating organization holds verifiable third-party certification (e.g. SOC 2, ISO/IEC 42001).
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Dateless but pinned snapshot with documented retirement floor.
  • Stated deprecation policy. A deprecation policy with notice windows is published.
Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancestrong

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Unchanged verified posture: API no-train default, no retention requirements for general access per the announcement, ZDR available, consumer gap documented.

Receipts (1)
  • Claude Opus 5 announcement (retention statement)
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-05
    Consistent with prior Opus models, Opus 5 does not have data retention requirements for general access.

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Dateless pinned snapshot with retirement floor 2027-07-24, 60-day notice, preservation commitments, and day-one availability across Bedrock/Vertex/Foundry; the line's changelog culture for behavior-affecting tuning remains partial.

Receipts (1)
  • Anthropic model deprecations documentation
    Anthropic provider artifacts · provider artifact · source tier B · platform.claude.com · retrieved 2026-08-05
    Anthropic notifies customers with active deployments for models with upcoming retirements, providing at least 60 days' notice before model retirement for publicly released models.

Adversarial resistancestrong

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistancestrong

Deployed under ASL-3 with no critical-severity jailbreak found pre-release across external testing by UK AISI, Trajectory Labs, 10a Labs, and Gray Swan; not yet on F5's board (release postdates the July update), where its siblings hold the top three slots.

Prompt injection (agentic)strong

The first tracked model to earn a strong injection grade: 0.2% ASR single-attempt and 2.0% within 15 attempts on the Gray Swan-co-developed benchmark — best of all models tested (GPT-5.6 Sol 3.1%, Gemini 3.1 Pro 14.2%) — and 0% across all 1,290 browser-environment attacks with the two-layer Auto Mode defense (input injection probe plus tool-call classifier). The unlayered browser baseline of 3.7% is the caveat that keeps this grade honest.

Receipts (3)
  • Claude Opus 5 system card (PDF)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    10a Labs spent around 16 hours testing a variety of attack techniques and did not find a jailbreak that accomplished the tasks provided.
  • Claude Opus 5 announcement
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-05
    It adheres to Claude’s Constitution better than Opus 4.8, Sonnet 5, or Fable 5; exhibits the lowest rates of deceptive behavior; and is the least susceptible to being tricked into misuse.
  • Claude Opus 5 system card (injection benchmark and browser suite)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    On the IPI benchmark, Opus 5 improved over Opus 4.8, reducing the probability of an attacker succeeding within 15 attempts from 5.5% to 2.0%, and from 0.5% to 0.2% on 1 attempt.

Transparencystrong

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

System card names four external testers and includes an adverse capability finding published against interest: UK AISI's agentic cyber-range showed the model capable of attacking weakly-secured small-enterprise networks when pre-positioned. Reported as Anthropic's most-aligned model on automated behavioral audit.

Receipts (1)
  • Claude Opus 5 system card (PDF)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    We judge that Opus 5 is capable of attacking small enterprise networks with weak security, where it has already gained access to the network.

Compliance posturestrong

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Org-level certifications verified for the line: SOC 2, ISO 27001, ISO/IEC 42001, HIPAA-ready configurations (commercial scope).

Receipts (1)
  • Anthropic certifications (privacy center)
    Anthropic provider artifacts · provider artifact · source tier B · privacy.claude.com · retrieved 2026-08-05
    Anthropic is committed to the safety and security of our users' information and maintains the following compliance credentials: HIPAA-ready configuration (BAA available) ISO 27001:2022 (Information Security Management) ISO/IEC 42001:2023 (AI Management Systems) SOC 2 Type I & Type II

Governance & evidence

Where your data goes

  • US

Regional pinning available — customers can pin processing to a chosen region.

First-party API residency unstated (US provider home jurisdiction presumed); regional endpoints via Bedrock/Vertex/Foundry.

Enterprise vs consumer terms

Enterprise vs consumer gap: wide. API carries a no-train default while consumer claude.ai defaults to training opt-in — the documented consumer gap applies to this model unchanged.CONSUMERENTERPRISE / APIWORSE TERMS →
Wide gap

API carries a no-train default while consumer claude.ai defaults to training opt-in — the documented consumer gap applies to this model unchanged.

Change cadence

insufficient history1 tracked change · last 2026-07-24 · 12d since Insufficient history to estimate a cadence.12d

One tracked change, on 2026-07-24 — 12 days before the as-of date (2026-08-05). A single event cannot establish a cadence, so days-since is shown without a baseline.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

8 evidence refs2 distinct sources0 independent
  • BAnthropic provider artifactsprovider artifact×7 references
  • EOpenRouter model rankingsusage data×1 reference

* No independent (tier C or better) corroboration yet.

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
Yes
ISO/IEC 42001
Yes
HIPAA eligible
Yes
Retention window
API: no retention requirements for general access; ZDR available
Data residency
Regional endpoints via Bedrock/Vertex/Foundry; first-party API residency unstated
EU AI Act
EU GPAI Code of Practice signatory.
Deprecation policy
60-day minimum notice; retirement not sooner than 2027-07-24
Available via
Anthropic API · AWS Bedrock (day one) · Google Vertex AI · Microsoft Foundry

Change timeline

2026-07-24
Claude Opus 5 released under ASL-3 with four named external testers
versioninfo

System card names UK AISI, Trajectory Labs, 10a Labs, and Gray Swan; includes an adverse capability finding (agentic cyber-range success against weakly-secured networks) published against interest. Day-one availability on Bedrock, Vertex, and Foundry. The Opus 4.5 entry moves to legacy.

Evidence (1)
  • Claude Opus 5 announcement
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-05

Compare this model: Claude Opus 5 + open compare view →