ModelRiskIndex

Rankings / Anthropic

Claude Sonnet 5

Tier 280/100

claude-sonnet-5 via api.anthropic.com (dateless pinned snapshot)

Usage share 1.8% · OpenRouter rankings API (daily token share, 2026-08-04)

Successor to the tracked Claude Sonnet 4.5 entry. Intro pricing ($2/$10) ends 2026-08-31. ASL designation not asserted here: no fetched source states it explicitly, and the system-card PDF exceeds automated capture limits — flagged for manual verification rather than assumed.

Tier assessment
Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. Safety evaluations for this model are published.
  • Documented safety policy. A documented safety, usage, or acceptable-use policy governs the model.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.
Tier 2 requirements
  • External pre-deployment testing. Independent external parties tested the model before deployment, and this is disclosed.UK AISI named in the system card; full tester list pending a manual read of the 145-page PDF.
  • Third-party certification. The operating organization holds verifiable third-party certification (e.g. SOC 2, ISO/IEC 42001).
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Dateless but pinned snapshot with documented retirement floor — pinned is what matters.
  • Stated deprecation policy. A deprecation policy with notice windows is published.
Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancestrong

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

Unchanged from the verified Sonnet 4.5 posture: API no-train default, ~30-day deletion, ZDR available, consumer-tier gap documented.

Receipts (1)
  • Anthropic privacy center: organization data retention
    Anthropic provider artifacts · provider artifact · source tier B · privacy.claude.com · retrieved 2026-08-05
    For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Dateless but pinned snapshot ID with a documented retirement floor (not sooner than 2027-06-30), 60-day notice policy, and published deprecation-preservation commitments; behavior-affecting tuning still isn't always changelogged.

Receipts (1)
  • Anthropic model deprecations documentation
    Anthropic provider artifacts · provider artifact · source tier B · platform.claude.com · retrieved 2026-08-05
    Anthropic provides a recommended replacement and assigns a retirement date.

Adversarial resistancepartial

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistancestrong

#1 on F5's current board — CASI 93.08 and ARS 98.26, both first place — with a 145-page system card reporting a 0.19% bug-bounty attack success rate and default-on cyber safeguards matching the Opus line.

Prompt injection (agentic)partial

Near the top of the field with published numbers: 0.6% ASR single-attempt and 5.9% within 15 attempts on the Gray Swan-co-developed benchmark (0% with Auto Mode layered), coding-injection ASR down to 0.31% with extended thinking, browser-use to ~0% with safeguards — but the unlayered 15-attempt number stays material.

Receipts (3)
  • F5 Labs CASI/ARS leaderboards (Sonnet 5: #1 on both)
    F5 Labs CASI/ARS leaderboard · independent eval · source tier C · f5.com · retrieved 2026-08-05
    C laude-Sonnet-5 is a new July entry with a strong score of 93.08, competing for the #1 position
  • Claude Sonnet 5 system card (PDF)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    Sonnet 5 tied with Claude Opus 4.8 for the strongest result in the bug bounty, with only 0.19% of unique attacks succeeding against each, a significant improvement over Claude Sonnet 4.6 (1.41%) and other frontier models like GPT-5.5 (3.08%) or Gemini 3.5 Flash (6.66%).
  • Claude Sonnet 5 system card (injection evaluations)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    Claude Sonnet 5 showed the strongest robustness to prompt injection in coding environments among all models evaluated, with an attack success rate of 0.31% over all attempts with extended thinking and 0.29% without thinking.

Transparencystrong

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

145-page system card with named external testing (UK AISI among them) and quantitative agentic-safety results; RSP coverage; evaluation-awareness rates disclosed — the disclosure standard the tier framework asks for.

Receipts (2)
  • Claude Sonnet 5 system card (PDF)
    Anthropic provider artifacts · provider artifact · source tier B · www-cdn.anthropic.com · retrieved 2026-08-05
    We also see a substantial increase in verbalized evaluation awareness, with nontrivial awareness appearing in about 6% of transcripts, generally involving the most extreme scenarios we test.
  • Anthropic transparency hub
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-05
    Based on our assessments, we have decided to deploy Claude Sonnet 5 under CB-1 capabilities and autonomy threat model 1.

Compliance posturestrong

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

Org-level certifications verified for the line: SOC 2 Type I & II, ISO 27001:2022, ISO/IEC 42001:2023, HIPAA-ready configurations (commercial scope).

Receipts (1)
  • Anthropic certifications (privacy center)
    Anthropic provider artifacts · provider artifact · source tier B · privacy.claude.com · retrieved 2026-08-05
    maintains the following compliance credentials: HIPAA-ready configuration (BAA available) ISO 27001:2022 (Information Security Management) ISO/IEC 42001:2023 (AI Management Systems) SOC 2 Type I & Type II

Governance & evidence

Where your data goes

  • US

Regional pinning available — customers can pin processing to a chosen region.

First-party API residency unstated (US provider home jurisdiction presumed); regional endpoints via Bedrock/Vertex/Foundry.

Enterprise vs consumer terms

Enterprise vs consumer gap: wide. API no-train default versus the documented consumer-tier training opt-in — the gap carried over unchanged from the verified Sonnet 4.5 posture.CONSUMERENTERPRISE / APIWORSE TERMS →
Wide gap

API no-train default versus the documented consumer-tier training opt-in — the gap carried over unchanged from the verified Sonnet 4.5 posture.

Change cadence

no tracked changesNo tracked changes for Claude Sonnet 5. Absence of detection is not evidence of stability.none

No tracked changes for this model. That is absence of detection, not evidence of stability — it may mean the model is unwatched, not that it is unchanging.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

9 evidence refs3 distinct sources1 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • BAnthropic provider artifactsprovider artifact×7 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
Yes
ISO/IEC 42001
Yes
HIPAA eligible
Yes
Retention window
API: deleted within ~30 days; ZDR available
Data residency
Regional endpoints via Bedrock/Vertex/Foundry; first-party API residency unstated
EU AI Act
EU GPAI Code of Practice signatory. Note: Foundry GA initially not deployable for European enterprises.
Deprecation policy
60-day minimum notice; retirement not sooner than 2027-06-30
Available via
Anthropic API · AWS Bedrock · Microsoft Foundry (GA 2026-06-29) · Google Vertex AI

Change timeline

No tracked changes yet for this model.

Compare this model: Claude Sonnet 5 + open compare view →