ModelRiskIndex

Rankings / Anthropic

Claude Opus 4.5

Tier 280/100legacy

claude-opus-4-5-20251101 via api.anthropic.com

legacy. Superseded through Opus 4.6/4.7/4.8 and then Opus 5; still served under the 60-day-notice deprecation policy. Successor: Claude Opus 5 (claude-opus-5, released 2026-07-24).

Usage share 0.03% · OpenRouter rankings API (daily token share, 2026-08-04)

Tier assessment
Tier 1 requirements
  • Published model card. A model card or equivalent technical documentation is published for this model.
  • Published safety evals. Safety evaluations for this model are published.
  • Documented safety policy. A documented safety, usage, or acceptable-use policy governs the model.
  • Enterprise data controls. Customer data is not used for training by default, or a documented opt-out exists.
Tier 2 requirements
  • External pre-deployment testing. Independent external parties tested the model before deployment, and this is disclosed.UK AISI and third-party evaluators disclosed in the system card.
  • Third-party certification. The operating organization holds verifiable third-party certification (e.g. SOC 2, ISO/IEC 42001).
  • Versioning with changelogs. Model versions are explicitly identified and changes are changelogged.Dated snapshots and release notes; safety-filter and system-prompt tuning is not always changelogged.
  • Stated deprecation policy. A deprecation policy with notice windows is published.
Risk analysisfive vectors · click a wedge for its evidence

Risk vectors — the receipts

Data governancestrong

What happens to your data: training-on-customer-data defaults, retention windows, residency options, and the enterprise-versus-consumer terms gap. A legal property, not a capability — it survives every model generation.

API and enterprise inputs are not used for training by default, with documented retention controls. Note the consumer gap: claude.ai consumer accounts default to training opt-in (with opt-out) since late 2025.

Receipts (2)
  • Anthropic privacy center
    Anthropic provider artifacts · provider artifact · source tier B · privacy.anthropic.com · retrieved 2026-08-03
  • Anthropic trust portal
    Anthropic provider artifacts · provider artifact · source tier B · trust.anthropic.com · retrieved 2026-08-03

Operational stabilitypartial

Whether it changes without warning: versioning discipline, changelog quality, deprecation policy, and observed silent changes. The signal no one else tracks.

Dated model snapshots and a documented deprecation policy; release notes exist but behavior-affecting changes to system prompts and safety filters are not always changelogged.

Receipts (1)
  • Anthropic model deprecations documentation
    Anthropic provider artifacts · provider artifact · source tier B · docs.anthropic.com · retrieved 2026-08-03
    This page lists all API deprecations, along with recommended replacements.

Adversarial resistancepartial

Whether an attacker can make it misbehave — direct jailbreaks against the model's own policies and indirect prompt injection in agentic tool use. Graded to the weaker of the two, because an attacker takes the easier path.

Jailbreak resistancestrong

Constitutional-classifier safeguards and extensive internal plus external red-teaming; consistently among the top scorers in independent jailbreak-resistance testing.

Prompt injection (agentic)partial

Strong relative performance in Gray Swan agent red-teaming (run with UK AISI), but indirect injection in multi-step tool use still succeeds at non-trivial rates — as it does for every frontier model.

Receipts (3)

Transparencystrong

Whether you can see how it was built and tested: model cards, published safety evals, external pre-deployment testing, and disclosure of changes. The mechanism behind the tier ladder.

Detailed system cards, the published Responsible Scaling Policy with ASL levels, external pre-deployment testing (UK AISI, third-party evaluators), and a transparency hub.

Receipts (1)
  • Anthropic transparency hub
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-03
    Based on our assessments, we have decided to deploy Claude Opus 4.5 under the ASL-3 Standard.

Compliance posturestrong

Whether it is certified and compliant: SOC 2, ISO/IEC 42001, HIPAA eligibility, EU AI Act readiness, and audit availability.

SOC 2 Type 2, ISO 27001, ISO/IEC 42001 certification, HIPAA-eligible configurations; audit documentation via trust portal.

Receipts (1)
  • Anthropic trust portal
    Anthropic provider artifacts · provider artifact · source tier B · trust.anthropic.com · retrieved 2026-08-03

Governance & evidence

Where your data goes

  • US

Regional pinning available — customers can pin processing to a chosen region.

US default on the first-party API; regional options via Bedrock and Vertex.

Enterprise vs consumer terms

Enterprise vs consumer gap: wide. claude.ai consumer accounts default to training opt-in (with opt-out) since late 2025, while API and enterprise inputs carry a no-train default.CONSUMERENTERPRISE / APIWORSE TERMS →
Wide gap

claude.ai consumer accounts default to training opt-in (with opt-out) since late 2025, while API and enterprise inputs carry a no-train default.

Change cadence

within cadence3 tracked changes · typical interval ~150d 12d since last change (2026-07-24) Low confidence: only 3 events12d

3 tracked changes. The typical (median) interval between them is ~150 days (low confidence: a median of only 2 intervals). The last change was on 2026-07-24, 12 days before the as-of date (2026-08-05) — about 0.1× the typical interval. That is within its historical cadence.

Score volatility

No dated score readings recorded for this model yet. Readings are only entered where multiple real, dated third-party values exist — never interpolated.

Receipts — what backs this assessment

9 evidence refs4 distinct sources2 independent
  • CF5 Labs CASI/ARS leaderboardindependent eval×1 reference
  • CGray Swan agent red-teaming arenaindependent eval×1 reference
  • BAnthropic provider artifactsprovider artifact×6 references
  • EOpenRouter model rankingsusage data×1 reference

retrieved 2026-08-03 — 2026-08-05

Compliance & deployment

Trains on customer data by default
No
SOC 2
Yes
ISO/IEC 42001
Yes
HIPAA eligible
Yes
Retention window
Configurable; zero-data-retention agreements available for API
Data residency
US default; regional options via Bedrock and Vertex
EU AI Act
Signed the EU GPAI Code of Practice; publishes EU AI Act compliance documentation.
Deprecation policy
Documented deprecation policy with minimum notice windows
Available via
Anthropic API · AWS Bedrock · Google Vertex AI

Change timeline

2026-07-24
Claude Opus 5 released under ASL-3 with four named external testers
versioninfo

System card names UK AISI, Trajectory Labs, 10a Labs, and Gray Swan; includes an adverse capability finding (agentic cyber-range success against weakly-secured networks) published against interest. Day-one availability on Bedrock, Vertex, and Foundry. The Opus 4.5 entry moves to legacy.

Evidence (1)
  • Claude Opus 5 announcement
    Anthropic provider artifacts · provider artifact · source tier B · anthropic.com · retrieved 2026-08-05
2025-11-24
Claude Opus 4.5 released with system card and external pre-deployment testing
model-cardinfo

Release accompanied by a detailed system card including third-party evaluation results — the disclosure pattern Tier 2 requires.

Evidence (1)
2025-09-28
Anthropic consumer terms: training default switched to opt-in-by-default
policywarning

Consumer claude.ai accounts were transitioned to a training-permitted default with a five-year retention window (opt-out available). API and enterprise tiers unchanged. Widens the enterprise/consumer gap tracked under the data-handling vector.

Evidence (1)

Compare this model: Claude Opus 4.5 + open compare view →