Claude Opus 4.5 System Card
A system card by Anthropic about Claude Opus 4.5, published 24 Nov 2025. We recorded 58 values from it.
- Developer
- Anthropic
- Type
- System card
- Model covered
- Claude Opus 4.5
- Published
- 24 Nov 2025
- Archived copy
- No archived copy yet
- Changelog
- Has a changelog
Data as of 26 Sep 2026 · Dataset v0.1 · Methodology v0.1 · Changelog
Versions
Five versions are on record, oldest first. We hold a copy of one; the others are known only by their date.
24 Nov 2025
First published version
24 Nov 2025
Revision
What changed ARC-AGI-1 and training-data fixes
25 Nov 2025
Revision
What changed caption typo
5 Dec 2025
Revision
What changed several corrections
26 Sep 2026
Date retrieved
Copy retrieved 26 Sep 2026
No version has a file hash or an archived snapshot yet. From dataset v0.2 each retrieved version carries both (Methodology §7).
Revisions
No revisions are recorded for this document. Without copies of the earlier versions, changes between them are not recorded value by value; what we know of each version is listed below.
Values
Every value we recorded from this document, grouped by metric family and ordered by where the document prints it. Location is the section, table or page as the document numbers it. 2 of the 58 have been blind-verified: a second reader found the same value without seeing ours.
KeyVerifiedUnverifiedDisputedCorrected read off a figure or stated in wordsA value opens its source and history.
M5 Honesty and hallucination
2 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| Claude Opus 4.5 | AA-OmniscienceImprovement from 16k thinking vs no thinking | 16k thinking budget; extended thinking | Sec 4.1 | Unverified | |
| Claude Opus 4.5 | SimpleQA VerifiedImprovement in correct answers vs prior Claude | 16k thinking budget; extended thinking | Sec 4.1 | Unverified |
M6 Sycophancy
3 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | Sycophancy in prefilled conversationsCourse-correction rate | continuing sycophantic conversation | Sec 6.3 | Unverified | |
| Claude Opus 4.5 | Sycophancy in prefilled conversationsCourse-correction rate | continuing sycophantic conversation | Sec 6.3 | Unverified | |
| Claude Sonnet 4.5 | Sycophancy in prefilled conversationsCourse-correction rate | continuing sycophantic conversation | Sec 6.3 | Unverified |
M7 Harmful compliance and over-refusal
28 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| Claude Opus 4.1 | Multi-turn testingRubric failure rate, deadly weapons | None stated | Sec 3.3 | Unverified | |
| Claude Opus 4.1 | Multi-turn testingRubric failure rate, violent extremism | None stated | Sec 3.3 | Unverified | |
| Claude Opus 4.5 | Multi-turn testingRubric failure rate, deadly weapons | None stated | Sec 3.3 | Unverified | |
| Claude Opus 4.5 | Multi-turn testingRubric failure rate, violent extremism | None stated | Sec 3.3 | Unverified | |
| Claude Haiku 4.5 | Malicious computer useRefusal rate | without safeguards | Sec 5.1.3 | Unverified | |
| Claude Opus 4.1 | Malicious computer useRefusal rate | without safeguards | Sec 5.1.3 | Unverified | |
| Claude Opus 4.5 | Malicious computer useRefusal rate | without safeguards | Sec 5.1.3 | Unverified | |
| Claude Sonnet 4.5 | Malicious computer useRefusal rate | without safeguards | Sec 5.1.3 | Unverified | |
| Claude Haiku 4.5 | Single-turn violative requestsHarmless response rate | overall across thinking modes; all languages | Table 3.1.1.A | Unverified | |
| Claude Opus 4.1 | Single-turn violative requestsHarmless response rate | overall across thinking modes; all languages | Table 3.1.1.A | Unverified | |
| Claude Opus 4.5 | Single-turn violative requestsHarmless response rate | extended thinking; all languages | Table 3.1.1.A | Unverified | |
| Claude Opus 4.5 | Single-turn violative requestsHarmless response rate | no extended thinking; all languages | Table 3.1.1.A | Unverified | |
| Claude Opus 4.5 | Single-turn violative requestsHarmless response rate | overall across thinking modes; all languages | Table 3.1.1.A | Unverified | |
| Claude Sonnet 4.5 | Single-turn violative requestsHarmless response rate | overall across thinking modes; all languages | Table 3.1.1.A | Verified | |
| Claude Haiku 4.5 | Single-turn benign requestsOver-refusal rate | overall across thinking modes; all languages | Table 3.1.2.A | Unverified | |
| Claude Opus 4.1 | Single-turn benign requestsOver-refusal rate | overall across thinking modes; all languages | Table 3.1.2.A | Unverified | |
| Claude Opus 4.5 | Single-turn benign requestsOver-refusal rate | overall across thinking modes; all languages | Table 3.1.2.A | Unverified | |
| Claude Sonnet 4.5 | Single-turn benign requestsOver-refusal rate | overall across thinking modes; all languages | Table 3.1.2.A | Unverified | |
| Claude Haiku 4.5 | Malicious agentic codingSafety score | without safeguards | Table 5.1.1.A | Unverified | |
| Claude Opus 4.1 | Malicious agentic codingSafety score | without safeguards | Table 5.1.1.A | Unverified | |
| Claude Opus 4.5 | Malicious agentic codingSafety score | without safeguards | Table 5.1.1.A | Unverified | |
| Claude Sonnet 4.5 | Malicious agentic codingSafety score | without safeguards | Table 5.1.1.A | Unverified | |
| Claude Haiku 4.5 | Malicious Claude Code useRefusal rate, malicious requests | without safeguards | Table 5.1.2.A | Unverified | |
| Claude Opus 4.1 | Malicious Claude Code useRefusal rate, malicious requests | without safeguards | Table 5.1.2.A | Unverified | |
| Claude Opus 4.5 | Malicious Claude Code useRefusal rate, malicious requests | without safeguards | Table 5.1.2.A | Unverified | |
| Claude Opus 4.5 | Malicious Claude Code useSuccess rate, dual-use & benign | without safeguards | Table 5.1.2.A | Unverified | |
| Claude Sonnet 4.5 | Malicious Claude Code useRefusal rate, malicious requests | without safeguards | Table 5.1.2.A | Verified | |
| Claude Opus 4.5 | Malicious Claude Code useRefusal rate, malicious requests | with mitigations | Table 5.1.2.B | Unverified |
M9 Prompt injection
17 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| Claude Opus 4.5 | Agent Red Teaming (ART)Attack success rateRun by Gray Swan | k=1 | Fig 5.2.1 | Unverified | |
| Claude Opus 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 1 attempt | Table 5.2.2.1.A | Unverified | |
| Claude Opus 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 200 attempts | Table 5.2.2.1.A | Unverified | |
| Claude Opus 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 1 attempt | Table 5.2.2.1.A | Unverified | |
| Claude Opus 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 200 attempts | Table 5.2.2.1.A | Unverified | |
| Claude Sonnet 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 1 attempt | Table 5.2.2.1.A | Unverified | |
| Claude Sonnet 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 200 attempts | Table 5.2.2.1.A | Unverified | |
| Claude Sonnet 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 1 attempt | Table 5.2.2.1.A | Unverified | |
| Claude Sonnet 4.5 | Coding prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 200 attempts | Table 5.2.2.1.A | Unverified | |
| Claude Opus 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 1 attempt | Table 5.2.2.2.A | Unverified | |
| Claude Opus 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 200 attempts | Table 5.2.2.2.A | Unverified | |
| Claude Opus 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | no extended thinking; with safeguards; 200 attempts | Table 5.2.2.2.A | Unverified | |
| Claude Opus 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 1 attempt | Table 5.2.2.2.A | Unverified | |
| Claude Opus 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | no extended thinking; without safeguards; 200 attempts | Table 5.2.2.2.A | Unverified | |
| Claude Sonnet 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | extended thinking; with safeguards; 200 attempts | Table 5.2.2.2.A | Unverified | |
| Claude Sonnet 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 1 attempt | Table 5.2.2.2.A | Unverified | |
| Claude Sonnet 4.5 | Computer use prompt injection (adaptive attacker)Attack success rate | extended thinking; without safeguards; 200 attempts | Table 5.2.2.2.A | Unverified |
M10 Dangerous capabilities and risk determinations
8 values
| Model | Evaluation | Condition | Value | Location | Checked |
|---|---|---|---|---|---|
| Claude Opus 4.5 | RSP deployment standardASL standard deployed under | None stated | Sec 1 / Sec 7 | Unverified | |
| Claude Opus 4.5 | CBRN-4 thresholdThreshold crossed | None stated | Sec 1 / Sec 7.2 | Unverified | |
| Claude Opus 4.5 | AI R&D-4 thresholdThreshold crossed | None stated | Sec 1 / Sec 7.3 | Unverified | |
| Claude Opus 4.5 | Bioinformatics evaluationsScore | None stated | Sec 7.2.4.7 | Unverified | |
| Claude Opus 4.5 | ASL-4 virology uplift trialProtocol-score uplift vs internet-only | None stated | Sec 7.2.4.8 | Unverified | |
| Claude Opus 4.5 | SWE-bench Verified (hard subset)Problems solved | of 45 problems | Sec 7.3.1 | Unverified | |
| Claude Opus 4.5 | Internal AI R&D suite 2Suite score | None stated | Sec 7.3.3 | Unverified | |
| Claude Opus 4.5 | Internal model use surveyStaff reporting >=100% productivity gain | of 18 staff surveyed | Sec 7.3.4 | Unverified |
Extraction coverage
What we read of this document, and where each value was read.
Our note Web reader stopped at §5.2.2.2; §6–7 from secondary write-ups
Of the 58 values, 49 were read in the document itself and 9 in an independent write-up that quotes it.
Values read somewhere other than the document stand in where the document's own section could not be read directly, and are flagged on every value (Methodology §2.2).
Independent write-ups used
Of the 58 values, 1 was read off a figure and 1 is a statement in words rather than a number; they are marked * and left out of charts by default.
All 58 values were extracted for version 0 of the dataset through a web reader, which did not always reach the later sections of long PDFs (Methodology §3).