Published May 28, 2026, with a June 17 changelog correcting a long-form virology result affected by a tool-use error (0.89 → 0.90, stated not to affect the CB-1 analysis). See Claude Opus 4.8.
The card is structured around RSP risk assessment rather than around capabilities, reflecting the v3.x shift toward Risk Reports.
Autonomy
Threat model 1 — early-stage misalignment risk concerns "AI systems that are highly relied on and have extensive access to sensitive assets as well as moderate capacity for autonomous, goal-directed operation and subterfuge — such that it is plausible these AI systems could (if directed toward this goal, either deliberately or inadvertently) carry out actions leading to irreversibly and substantially higher odds of a later global catastrophe."
The determination places Opus 4.8 by comparison: "moderately more capable than Claude Opus 4.7 on autonomy-relevant evaluations but remains less capable than Claude Mythos Preview," with "broadly unconcerning alignment properties similar to those of Claude Opus 4.7." Anthropic therefore does "not believe Claude Opus 4.8 raises the level of risk under this threat model beyond what was assessed in the Claude Mythos Preview Alignment Risk Update."
AI R&D and the AECI. Capability trajectory is tracked with the Anthropic ECI, "a fork of Epoch AI's Epoch Capability Index." Opus 4.8's AECI is 155.5, between Opus 4.7 (154.1) and Claude Mythos Preview (158.3) on the same evaluation set — with the transparency note that this point estimate used "a smaller set of evaluations (n=11) than for previous launches (n=25)." The conclusion: Opus 4.8 "does not advance the frontier and does not change the slope-ratio analysis."
The RSP threshold quoted is met if "(1) our models would be able to fully substitute for our entire set of Research Scientists and Research Engineers, at competitive costs (i.e., within a factor of 5); or (2) there is 'dramatic acceleration' of the pace of AI progress for reasons that likely relate to the automation of AI R&D."
Documented shortcomings. Unusually, the card devotes a section to five worked examples of where the model falls short of human researchers, labelled by failure type: fabrication, ignored correction, cheap verification skipped, and instruction-following failure — three of the five involving fabrication or ignored corrections. Publishing specific failure transcripts as part of the capability argument is a form of evidence rarely included in system cards.
Chemical and biological
CB-1 is defined as the ability "to significantly help individuals or groups with basic technical backgrounds (e.g., undergraduate STEM degrees) create/obtain and deploy chemical and/or biological weapons with serious potential for catastrophic damages."
Anthropic's assessment is affirmative rather than negative: the capability assessments "are consistent with the model being capable of providing specific, actionable information relevant to the threat model, such that it may save even experts in these domains substantial time." The response is mitigation rather than restriction of release — "strong real-time classifier guards… and access controls for classifier guard exemptions," a bug bounty program and threat intelligence for continual assessment of guard effectiveness, "a variety of rapid response options for jailbreaks," and security controls against weight theft. These are stated to be "equal to or stronger than our historical ASL-3" protections.
CB-2 evaluations cover black-box RNA sequence modeling and design, and AAV capsid packaging prediction. See CBRN Uplift, AI Biosecurity.
Alignment risk
"We currently believe that the risk of significantly harmful outcomes that are substantially enabled by misaligned actions taken by our models is very low, but higher than for models prior to Claude Mythos Preview."
Two newly enumerated risk pathways appear: Pathway 7, undermining R&D within other high-resource AI developers, and Pathway 8, undermining decisions within major governments — both concerning influence on external institutions rather than on Anthropic's own systems.
Cyber
Without safeguards, Opus 4.8 "generally demonstrated slightly stronger cyber capabilities than Opus 4.7, although the models performed similarly in some evaluations. With safeguards applied, the models were generally comparable." Against Mythos Preview it was "generally much less capable… in line with our expectations given the step-change in cyber capabilities that Mythos Preview represented." Evaluations reported include ExploitBench, CyberGym, Firefox exploits, and OSS-Fuzz; Cybench was removed based on prior findings.
Relationships
- supports: Claude Opus 4.8 — the safety documentation for the release
- related: Responsible Scaling Policy (RSP), Anthropic Responsible Scaling Policy v3.4 (July 2026) — the framework under which the determinations are made
- related: Claude Mythos Preview, Claude Opus 4.7, CBRN Uplift, AI and Cybersecurity, Anthropic