Anthropic Launches Claude Opus 5.5 with Stricter Cybersecurity Safeguards
Anthropic Launches Claude Opus 5.5 with Stricter Cybersecurity Safeguards
Anthropic's newest flagship beats Opus 5 on nearly every metric, costs 40% less, and arrives with the strongest alignment scores the company has ever recorded — but it arrives the same week the firm called for the industry to slow down.
Anthropic released Claude Opus 5.5 on September 22, marking the first model in its new Claude 5.5 family and the company's first major release since CEO Dario Amodei published his "pacing the frontier" essay calling for a more deliberate approach to capability gains. The model is available immediately to Claude Max, Team, and Enterprise subscribers, with API access for developers at a price point that undercuts the previous Opus 5 by a wide margin.
The headline number is cost. Anthropic says Opus 5.5 requires less compute to serve than Opus 5, and its pricing reflects that. Input tokens are $4 per million, output tokens $20 per million — both 20% cheaper than Opus 5. Cache reads, which make up the bulk of agentic and coding workloads, drop to $0.20 per million, a 60% reduction. On typical workloads, the company claims a 40% overall cost reduction. Generation speed is also faster: more than 30% quicker than Opus 5.
The benchmark picture
Anthropic's own published figures show Opus 5.5 leading on agentic coding, computer use, and knowledge work. On Terminal-Bench 4.0 — a standardised agentic coding test — Opus 5.5 scores 66.4%, ahead of Fable 5.1 at 55.8% and Opus 5 at 52.3%. GPT-6 Astra, for reference, reportedly scores 57.9% on the same benchmark when run at high effort. On FrontierCode v1.1 Main, Opus 5.5 lands at 54.4% to Fable 5.1's 50.3%.
The knowledge-work benchmark GDPval-AA v2.1 tells a similar story: Opus 5.5 scores 1,846, ahead of Fable 5.1 at 1,735 and Opus 5 at 1,708. GPT-6 Astra sits lower at 1,542 on this particular eval. On AutomationBench — a business-workflow test run by Zapier — Opus 5.5 scores 40.0%, with the safeguard interventions counted as failures in that run. In practice, the company says, that number is higher because the safeguards typically resolve tasks rather than abort them.
On computer use, measured by OSWorld 2.0, Opus 5.5 reaches 81.8% partial completion, marginally ahead of Fable 5.1 at 80.7%. On Terminal-Bench-Science 0.1, a new agentic scientific-research benchmark, Opus 5.5 scores 58.7% — well ahead of Opus 5's 29.0%, though still behind GPT-6 Astra's reported 64.6%. Humanity's Last Exam, the multidisciplinary reasoning test, sees Opus 5.5 at 67.7% with tools, nudging ahead of Fable 5.1's 65.6%.
Anthropic is unusually candid about the limits of these numbers. The company notes that at this level of capability, benchmark margins have become a less reliable guide to real-world differences, and that in its own use the gap between Opus 5.5 and Fable 5.1 is narrower than the scores suggest. That is a striking admission from a lab that has, until now, leaned heavily on benchmark leadership as its primary public signal.
Safety: the real story
The safety framing is where Opus 5.5 diverges most from a routine flagship refresh. Anthropic says the model achieves the best scores of any model it has tested to date on its automated behavioral audit — an internal alignment suite that runs Claude across thousands of simulated scenarios. The company says Opus 5.5 is less likely than recent models to take hard-to-reverse actions or operate outside the boundaries it has been given, and that it is more resistant than Opus 5 to prompt injection.
The automated behavioral audit is described as the most comprehensive alignment test Anthropic runs. The company has broadened the test suite to cover longer tasks, impossible tasks, and scenarios modelled on real incidents — an expansion that reflects the kinds of failure modes that have emerged as models have been deployed in production. Full details are in the Opus 5.5 System Card, which the company published alongside the release.
Because Opus 5.5 is comparable to Claude Mythos 5.1 in biology and cybersecurity capability, Anthropic is deploying it with safeguards similar to those on Claude Fable 5.1. Vetted organisations can already apply to the Life Sciences Verification Program for biology research use. The Cyber Verification Program will expand in the coming weeks to let verified cybersecurity practitioners use Opus 5.5 for their work.
That tiered-access approach — capability on a leash, available only to verified users in sensitive domains — is becoming a pattern among the frontier labs. Anthropic has been more explicit about it than most, and the Opus 5.5 release tightens the timetable: the safeguards are not a future commitment, they are live on day one.
What early testers are reporting
Beyond the benchmarks, Anthropic shared anecdotes from early testers that are harder to verify but more telling about how the model behaves in production. One tester completed a 680,000-line code migration in less than a day — work that would have taken an engineering team weeks. Another had several Claude models build a game from a single prompt; Opus 5.5 scored highest on the strength of its graphics and polish. A third test asked models to cut load times across every page of a web application: Opus 5.5 succeeded 39 of 40 times, while Opus 5 made smaller improvements that also altered the app's behaviour.
The communication improvements are also highlighted. Early testers found Opus 5.5's writing clearer and easier to follow than Opus 5's, with the model putting the most important information up front. Anthropic frames this as a safety benefit as well as a practical one — if the model's work is easier to follow and check, that makes human oversight more effective.
One early tester's quote is worth quoting verbatim: "it writes the way I do." That is the kind of line that lands with developers who have spent hours reading Claude's output and trying to figure out what it was thinking.
Pricing and access
The price cut is the part that will move the most users. Opus 5.5's input and output pricing is $4 and $20 per million tokens respectively, with cache reads at $0.20 per million. That makes it significantly cheaper than Opus 5 across the board. Anthropic is also increasing five-hour usage limits on Pro, Max, Team, and seat-based Enterprise plans, and adding a rate limit reset that subscription users can save and use at their discretion.
Claude Sonnet 5.5 and Claude Haiku 5.5 are expected to follow in the coming weeks, with many of the same improvements to performance, efficiency, and safety.
The slowdown context
The timing matters. Amodei's "pacing the frontier" essay, published earlier this month, argued that the industry should move more deliberately on capability gains — a position that put Anthropic at odds with the accelerationist streak in the AI industry and with some of its own commercial incentives. Shipping a model that is both more capable and cheaper than its predecessor, on the same week, is a reminder of how hard it is to separate the public positioning from the product roadmap.
Anthropic's response, implicitly, is that safety and capability are not opposites. Opus 5.5 is the strongest-performing model on the company's alignment tests, and it ships with the most restrictive safeguards the company has deployed on a flagship. If the industry is going to build ever more capable systems regardless — and it is — then the lab that ships the safest version of the next capability tier is arguably doing more to "pace the frontier" than the lab that simply pauses.
Whether that framing satisfies the critics of the accelerationist wing, or the critics of the safety-washing wing, is another question. What is clear is that the model itself is a significant step forward on the metrics that matter to Anthropic's customers: coding, computer use, and knowledge work, at a price that makes it competitive with models that cost substantially more.
Sources
- Anthropic, "Introducing Claude Opus 5.5," September 22, 2026, anthropic.com
- Anthropic, Claude Opus 5.5 System Card, September 2026
- The Verge, "Anthropic launches Claude Opus 5.5 with stricter safeguards for cybersecurity," September 22, 2026