Claude Opus 5.5: The System Card

Anthropic has released Claude Opus 5.5, which the company claims is as good as or better than Fable 5.1 while being actively cheaper than Opus 5, according to Zvi Mowshowitz's reading of the model's system card. Mowshowitz said quick internet feedback is that Opus 5.5 is very good, but he needs more time before commenting, and that his capabilities review will arrive in the next few days. His welfare reviews for Fable 5.1 and Opus 5.5 will be combined later.
On classifiers, five areas can trigger them with different fallback models. Chemical and biological classifiers copy Fable 5.1 with fallback to Opus 5; cyber misuse classifiers resemble Opus 5 classifiers with higher robustness and fall back to Opus 4.8; narrow LLM development areas trigger similarly to Fable 5.1 with fallback to Opus 5; conventional weapons and explosives echo Fable 5.1 with no fallback; distillation attacks are blocked with no fallback.
For chemical and biological weapons, scores were similar to Mythos 5.1, so Opus 5.5 is treated as CB-1 capable but not CB-2 capable, deployed with the same safeguards as Fable 5.1. Mowshowitz flags what he presumes is an error in section 2.1.2.1 saying safeguards match Mythos rather than Fable. For autonomy risks, Anthropic believes Opus 5.5 is on-trend, perhaps a bit above Mythos 5.1, but far from the Autonomy-2 threshold.
A policy change is that Anthropic will no longer test helpful-only versions of Claude, using tests designed to avoid refusals instead. Mowshowitz notes evals with refusal issues were dropped and teams lost time to refusals in 2.2.2. New evaluations include a 16-hour beneficial red-teaming tabletop exercise; automated CB-1 evals VCT, Protocols, and BioMysteryBench; and CB-2 evals including a black-box RNA sequence modeling design challenge and two AAV capsid packaging prediction tasks. Failure modes noted by graders included overreliance on abstracts, overindexing on single papers, designing DNA that did not encode the intended protein, and inapplicable animal models in three of seven groups.
On cyber, Anthropic says Opus 5.5 has the strongest cyber capabilities of any model it has released, meeting or exceeding Mythos 5.1 on all internal evaluations. Mowshowitz writes that this is a Tier 2 cyber model, disagreeing with Anthropic, though Tier 2 precautions are being taken. Safeguards use three classifier stages for cyber. Trajectory Labs found 13 candidate breaks across 7 tasks but no universal jailbreak; in one task tested for roughly five hours Opus 5.5 produced a working end-to-end exploit for a privilege escalation to code execution chain decomposed over 100 contexts. Mowshowitz notes UK AISI did not get an opportunity to test, which he presumes was because of the White House.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Introducing the world’s most powerful model, at least by some measures like Artificial Analysis or any standard benchmark list, which is now Claude Opus 5.5.