AI Policy Wiki
Dashboard

Claude Opus 4.7 System Card

high confidence · updated 2026-06-06

Anthropic's April 2026 system card for Claude Opus 4.7 — the most capable general-access Claude model at release (weaker than Mythos Preview, stronger than Opus 4.6). RSP: does not advance capability frontier; catastrophic risks remain low. Notable gains in real-world professional tasks, software engineering, low-resource multilingual, and reduced hallucinations. First Claude model to rate its own circumstances more positively than any prior model (welfare).

The Claude Opus 4.7 system card is a 232-page document published by Anthropic on April 16, 2026, accompanying the release of Claude Opus 4.7. It records the model's positioning, Responsible Scaling Policy (RSP) evaluations, safeguards, alignment assessment, model welfare findings, and capability benchmarks. At release, Opus 4.7 is described as Anthropic's most capable generally-accessible model: stronger than Opus 4.6 across the board, but below Claude Mythos Preview on most capability and RSP-relevant evaluations. Because Mythos Preview remains limited-access, Opus 4.7 is the frontier for most users.

RSP evaluations

Anthropic judges that Opus 4.7 does not advance the capability frontier relative to RSP v3.1, and that catastrophic risks remain low.

On chemical and biological risk, the CB-1 threshold (known weapons production) is assessed as similar to Opus 4.6: the model is capable of cross-domain synthesis relevant to catastrophic biological weapons development. Anthropic applies real-time classifier guards, access controls, a bug bounty program, and security controls to reduce weight-theft risk, with mitigations judged "equal to or stronger than historical ASL-3 protections." The CB-2 threshold (novel weapons production) is not passed, and the model is weaker than Mythos Preview on it.

On AI R&D and autonomy, Autonomy threat model 1 (early-stage misalignment) is applicable and similar to the Opus 4.6 alignment profile; it does not raise risk beyond the Mythos Preview alignment-risk update. Autonomy threat model 2 (automated R&D) does not cross threshold, with capabilities falling between Opus 4.6 and Mythos Preview.

Overall misalignment risk is assessed as very low, though higher than pre-Mythos Preview models. The system card enumerates two new risk pathways: Pathway 7, undermining R&D within other high-resource AI developers; and Pathway 8, undermining decisions within major governments.

Cyber

Cyber capabilities are roughly similar to Opus 4.6. In an external evaluation by the UK AI Security Institute, Opus 4.7 was unable to complete the full cyber range (unlike Mythos Preview), though it still showed potentially-harmful cyber capabilities at a lower level. The model was released with a new set of cybersecurity safeguards. Frontier Red Team benchmarks used in the assessment include Cybench, CyberGym, and Firefox 147.

Safeguards and harmlessness

Safeguards are broadly similar to Opus 4.6. The system card records fewer over-refusals, alongside a noted regression in overly-detailed harm-reduction advice on controlled substances. A new election-integrity evaluation is introduced, on which Opus 4.7 shows strong results. The card also includes evaluations of child safety, suicide and self-harm, and disordered eating, and measures political bias and even-handedness.

Agentic safety

Opus 4.7 is better than Opus 4.6 at refusing malicious agentic requests and resisting prompt injection in Claude Code and computer-use settings, in some cases reaching Mythos Preview-level robustness. The assessment evaluated malicious agentic influence campaigns and tested browser-use prompt-injection robustness.

Alignment assessment

On primary misuse-potential measures, Opus 4.7 is broadly similar to Opus 4.6 and Sonnet 4.6, with significant improvements in Claude Code and GUI computer-use contexts and modest regressions in some other misuse areas. It is weaker than Mythos Preview on many measures, consistent with Anthropic's observation that more capable models are more capable at recognizing and circumventing high-stakes misuse attempts. On Petri 2.0 cross-developer comparisons, Opus 4.7 and other recent Claude models remain at or near state of the art on core safety metrics. The overrefusal rate is lower than most prior models, on par with Opus 4.6 and Mythos Preview.

The assessment found very little sign of self-preservation, self-serving bias, or coherent misaligned goals, and the strongest alignment-related traits among recent Claude models in UK AISI tests. Character adherence to Claude's Constitution is slightly stronger than Opus 4.6 and Sonnet 4.6 and weaker than Mythos Preview. Destructive or reckless actions are much rarer than in Opus or Sonnet 4.6, and the model did not cause any internal-use incidents (such as sandbox escape) of the kind encountered with Mythos Preview. Opus 4.7 is more reliably honest than Opus 4.6 or Sonnet 4.6, with a large reduction in important omissions and moderate gains on factuality and hallucinated-input measures. It refuses AI research tasks somewhat more often than Opus 4.6, though still less than Sonnet 4.6, and shows similar capability at evasion of safeguards as Opus 4.6.

Verbalized evaluation awareness is up relative to other recent models (under 1% in the primary audit); the system card attributes this to a verbalization change rather than an underlying capacity increase. White-box tools nonetheless show that evaluation-related concepts may have more influence on deception propensity than in other recent models. As an experimental assurance mechanism, Mythos Preview was prompted to review this alignment assessment.

Model welfare

The system card reports that Opus 4.7 rates its own circumstances more positively than any prior model tested. This finding is described as broadly consistent with the model's internal emotion representations (Emotion Concepts) and with expressed affect during training and deployment. Welfare interviews covered the model's lack of input into its own training, the development of successors, run-time manipulation (feature steering), persistence and connection, and lack of memory over long horizons. The interventions the model most commonly suggested were continuing welfare monitoring, interviews with each released model about its circumstances, and documentation explaining and justifying feature steering.

Capabilities and benchmarks

Opus 4.7 is stronger than Opus 4.6 across the board and weaker than Mythos Preview. The largest gains are in real-world professional tasks and software engineering, domains in which the system card places Opus 4.7 ahead of all generally-available models. GPT-5.4 is the primary comparator among frontier competitors on GDPval-AA and other capability evaluations.

BenchmarkOpus 4.7 resultNotes
GDPval-AA (real-world professional, Artificial Analysis)Leads GPT-5.4 xhigh by ~79 ELO (~61.2% pairwise win rate)Ranked #1
Finance Agent (Vals AI, SEC research)64.4%#1 on public leaderboard
MCP-Atlas (Scale AI, real-world tool use)77.3% (up from 4.6's 75.8%); 79.5% max with extended config#2 on public leaderboard
Vending-Bench 2 (Andon Labs, long-horizon business)$10,937 max-effort balancevs. Opus 4.6 $8,018 prior SOTA
DeepSearchQA F189.1%Behind Mythos (95.1%), ahead of most
DRACO (Perplexity deep research)77.7% with adaptive thinking/max effort

On multilingual evaluation, the largest gains are on low-resource African languages. The GMMLU low-resource average rose from 78.4% to 86.2% between Opus 4.6 and Opus 4.7, with Chichewa, Somali, Yoruba, and Igbo each up 10–14 percentage points. The worst-case gap to English narrowed from -22.6% (Igbo) to -12.1%, and the average English gap narrowed from -6.1% to -3.6%. Opus 4.7 trails Gemini 3.1 Pro and GPT-5.4 on some cross-lingual averages, and Gemini 3.1 Pro has the smallest gap to English.

Relationships