Quoting Boris Cherny
Simon Willison Simon Willison ● Covered by 13 sources
Anthropic engineer Boris Cherny stated that Claude Opus 5 is their most resistant model to prompt injection attacks. The claim is documented in the model's system card on page 73, with results from prompt injection evals and red teaming across their safety testing. This suggests Opus 5 offers improved robustness against a common method of manipulating AI model behavior.
Why it matters
More than any of these eval scores, what is most exciting to me is something else: Opus 5 is our least prompt injectable model yet. It is a bit buried in the system card, but across PI evals and red teaming, Opus 5 is very hard to prompt inject successfully. — Boris Cherny, here's that System Card section, page 73 Tags: prompt-injection, anthropic, claude, generative-ai, ai, llms, boris-cherny
Also covered by
- Simon Willison — Introducing Claude Opus 5
- MarkTechPost — Meet the New Claude Opus 5: Frontier-Class Agentic Coding and Computer Use at Unchanged Opus Pricing
- Ars Technica — Anthropic's Opus 5 is about token efficiency, not a capability leap
- The New Stack — Opus 5 costs a third of the price — and that’s actually the problem
- AWS Machine Learning — Introducing Claude Opus 5 on AWS: Anthropic’s most capable Opus model
- Anthropic News — Introducing Claude Opus 5
- The New Stack — Anthropic’s Opus 5 is almost Fable 5
- TechCrunch AI — Anthropic launches Opus 5
- Sakana AI — Announcing Fugu-Ultra v1.1 and Claude Code interface for Fugu
- The Verge — Anthropic releases Opus 5 with ‘close’ to Fable 5’s capabilities
- The Batch — Mythos Begets Fable, Cursor's Composer 2.5, Agents Building Agents
- The Batch — Testing Mythos and Fable, Moving Beyond SWE-bench, Nvidia's Open Contender