Claude Sonnet 5 is a mid-tier general-purpose model released by Anthropic on June 30, 2026, in the Claude 4.x/5 line. Anthropic describes it as "the most agentic Sonnet model yet," able to make plans, use tools such as browsers and terminals, and run autonomously "at a level that, just a few months ago, required larger and more expensive models" (Source: anthropic.com). Anthropic positions it as narrowing the gap to its frontier Opus 4.8 model at lower cost, and made it the default model for Free and Pro users on release (Source: anthropic.com; Source: axios.com).
Provenance note: This page cites the Claude Sonnet 5 System Card by URL pending ingestion. Once the system card is ingested to
Wiki/sources/, inline(Source: …system-card…)citations should be upgraded to[[sources/claude-sonnet-5-system-card]].
| Field | Value | |
|---|---|---|
| Developer | [[companies/anthropic\ | Anthropic]] |
| Released | June 30, 2026 | |
| Model family | Claude Sonnet line | |
| Type | Mid-tier general-purpose, agentic | |
| Parameters | Undisclosed | |
| Predecessor | [[claude-sonnet-46\ | Claude Sonnet 4.6]] |
| Higher tier | [[claude-opus-4-8\ | Claude Opus 4.8]] |
| Open weights | No | |
| System card | [[sources/claude-sonnet-5-system-card\ | Claude Sonnet 5 System Card]] (pending ingest) |
| API identifier | claude-sonnet-5 | |
| Cyber safeguards | Real-time cyber safeguards enabled by default (Cyber Verification Program) |
Lineage and positioning
Anthropic frames Sonnet 5 as a continuation of the Sonnet line that, in its account, began the agentic era for many developers: it states that Claude Sonnet 3.5, 3.6, and 3.7 "were the first models that showed impressive skills in coding and tool use," while more recently the clearest agentic gains had come in its higher-capability Opus models (Source: anthropic.com). Sonnet 5 is the direct successor to Claude Sonnet 4.6 (February 17, 2026), which Anthropic said "fell well short of Opus 4.8"; Anthropic describes Sonnet 5's performance as "close to that of Opus 4.8, but at lower prices" and "a substantial improvement over its predecessor" on reasoning, tool use, coding, and knowledge work (Source: anthropic.com).
Axios described the release as bringing agentic capabilities — browser use, planning, coding, and knowledge work — to everyday users at a lower price, positioning Sonnet 5 as a cheaper option for coding and agentic workloads amid cost pressure that has pushed some developers toward cheaper Chinese models (Source: axios.com). The launch came the same day the Trump administration lifted export controls on Anthropic's Fable 5 model, and Anthropic contrasted Sonnet 5's lower cyber risk with its restricted Mythos 5 and Fable 5 models (Source: axios.com; see Export Controls (AI)).
Architecture and training
Anthropic does not disclose Sonnet 5's parameter count, training-compute budget, or detailed architecture. The model exposes an effort parameter that lets users trade cost against performance across a range of levels (medium, high, and "extra high"), which Anthropic presents as covering "a much wider range of cost-performance options" than Opus 4.8 (Source: anthropic.com). Anthropic states that Sonnet 5 uses an updated tokenizer that changes how the model processes text — similar to the change introduced with Claude Opus 4.7 — with the tradeoff that the same input can map to roughly 1.0–1.35× as many tokens depending on content type; it set introductory pricing so the transition from Sonnet 4.6 would be "roughly cost-neutral" (Source: anthropic.com).
Capabilities and benchmarks
Anthropic's announcement compares Sonnet 5 against its predecessor Sonnet 4.6 and its frontier Opus 4.8 model across a range of evaluations, presenting cost-performance curves on the agentic search benchmark BrowseComp and the computer-use benchmark OSWorld-Verified. It describes Sonnet 5 as "a strict improvement over Sonnet 4.6" that "covers a much wider range of cost-performance options than Opus 4.8," providing "substantially improved cost efficiency at medium effort," with higher-effort performance that "can match Opus 4.8 on some tasks" (Source: anthropic.com). Anthropic said a fuller set of evaluations is reported in the system card (Source: anthropic.com).
The BrowseComp cost-performance chart was corrected after publication. In a June 30, 2026 changelog, Anthropic said the original post had used "a simpler methodology that did not reflect the standard methodology" it uses for agentic search evaluations, which underestimated Sonnet 5's performance; it republished the chart using the system-card methodology (a 10M-token budget with compaction and programmatic tool calling) and updated the surrounding text (Source: anthropic.com). In the same update Anthropic revised two Sonnet 4.6 comparison figures — Humanity's Last Exam (to 34.6% without tools and 46.8% with tools, after a grader-model change) and OSWorld-Verified (to 78.5%, after evaluation changes) — noting these differ from the figures in the Sonnet 4.6 launch blog (Source: anthropic.com).
Availability and pricing
Claude Sonnet 5 became available across all Claude plans on June 30, 2026, as the default model for Free and Pro plans and available to Max, Team, and Enterprise users, as well as in Claude Code and on the Claude Platform (Source: anthropic.com). Developers can call it via the Claude API using the identifier claude-sonnet-5.
The model launched with introductory pricing of $2 per million input tokens and $10 per million output tokens through August 31, 2026, after which it rises to $3 per million input tokens and $15 per million output tokens (Source: anthropic.com; Source: axios.com). For comparison, Anthropic priced Opus 4.8 at $5 per million input tokens and $25 per million output tokens (Source: anthropic.com). Anthropic said it raised rate limits across Chat, Cowork, Claude Code, and the Claude Platform to accommodate the higher token usage of higher effort levels (Source: anthropic.com).
Safety and evaluations
Anthropic reported that its pre-deployment safety evaluations found Sonnet 5 to be "overall an improvement on Sonnet 4.6": better at refusing malicious requests and resisting hijack attempts in prompt-injection attacks, with lower rates of hallucination and sycophancy (Source: anthropic.com). On its automated behavioral audit, which tests for a range of misaligned behaviors such as cooperation with misuse and deception, Anthropic said Sonnet 5 "scored lower (that is, safer) overall" than Sonnet 4.6, but showed "somewhat higher rates of misaligned behavior" than the more capable Opus 4.8 and Claude Mythos Preview (Source: anthropic.com; Source: anthropic.com).
Anthropic said it "did not deliberately train Sonnet 5 on cybersecurity tasks" and that on evaluations of potentially dangerous cyber skills — such as developing software exploits — the model performs substantially worse than Opus 4.8 and Mythos 5 (Source: anthropic.com). On an evaluation developed with Mozilla that tested models' ability to develop exploits for vulnerabilities in Firefox 147, Anthropic reported that Sonnet 5 "was never able to develop a full working exploit" (a 0.0% success rate, matching Sonnet 4.6) but showed a slightly higher rate of partial success than Sonnet 4.6, which it attributed to gains in general intelligence rather than specific training (Source: anthropic.com). Because Sonnet 5 is somewhat stronger than its predecessor on these tasks, Anthropic launched it with real-time cyber safeguards enabled by default under its Cyber Verification Program — the same safeguards used in Claude Opus 4.7 and 4.8, and less strict than those launched with the export-restricted Fable 5, which block a wider range of cybersecurity tasks (Source: anthropic.com). Anthropic recommended Opus 4.8 for cybersecurity work requiring reduced guardrails. Its full assessment across safety and capability evaluations is reported in the Claude Sonnet 5 System Card (Source: anthropic.com).
In multiagent experiments published by Anthropic's Frontier Red Team in August 2026, Sonnet 5 was the only model of the five tested that combined a high pull-request merge fraction with relatively high code sharing across agents in 12-hour collaborative software builds (Patterns and problems in emerging multiagent systems). The report characterizes the more capable Opus 4.8 and Mythos Preview as raising their merge rates by having each agent retain high ownership of its own files rather than by coordinating, so the metric pair distinguishes Sonnet 5's result from theirs. The report gives no run counts for this experiment and reports no statistical testing.
Reception
Anthropic published statements from early-access partners alongside the release, several emphasizing sustained, autonomous multi-step execution. Testers described the model finishing complex tasks where previous Sonnet models "would stop short," checking its own output without being asked, and completing end-to-end automation and software-engineering workflows — writing a reproducing test, implementing a fix, and verifying it "in a single pass" — at what partners characterized as an attractive price point (Source: anthropic.com). Axios framed the launch in the context of Anthropic's ongoing discussions with the Trump administration over its more powerful models, noting that Sonnet 5 was positioned as posing lower dangerous-cyber risk than its restricted Mythos and Fable models (Source: axios.com).
Related models
- Claude Sonnet 4.6 — predecessor model (February 17, 2026).
- Claude Opus 4.8 — Anthropic's frontier model at the time of release; Sonnet 5's higher-capability reference point.
- Claude Mythos 5 and Fable 5 — Anthropic's export-restricted higher-cyber-capability models, contrasted with Sonnet 5's lower cyber risk.
The system card places Sonnet 5 as "our most capable Sonnet-class model" that "does not advance our capability frontier compared to more capable Opus- or Mythos-class models." It reports very low alignment risk "though higher than for previous Sonnet models"; no crossing of the automated AI R&D threshold, being "less capable than Claude Mythos 5 on every automated evaluation"; limited CBRN uplift for threat actors lacking existing capability, with residual uncertainty about accelerating those who have it; and cyber capability described as emergent rather than trained, "significantly less capable at cyber tasks than Mythos 5," so its safeguards match those applied to Opus 4.7 and 4.8. The behavioural improvement singled out concerns timing rather than refusal: the model "tends to surface concerns about a request's end goal earlier in conversations, for instance asking the purpose of a requested artifact before beginning work."
Relationships
- related: System Card: Claude Sonnet 5 (Anthropic, June 2026) — primary source for capability and safety data (pending ingest; queued)
- related: Claude Sonnet 4.6 — predecessor model
- related: Claude Opus 4.8 — higher-capability model in the same generation
- related: Anthropic — developer
- related: Export Controls (AI) — Sonnet 5 released amid the export-control standoff over Anthropic's most capable models
Sources
- Anthropic, "Introducing Claude Sonnet 5" (Jun 30, 2026) — primary announcement (Source: anthropic.com)
- Anthropic, Claude Sonnet 5 System Card (Jun 30, 2026) — pending ingest (Source: anthropic.com)
- Axios, "Anthropic debuts Sonnet 5 for everyday agent tasks with lower cyber risk" (Jun 30, 2026) (Source: axios.com)