Large Language Models Models

Anthropic Shipped Sonnet 5.5. A Court Called It a Risk.

CRAZE CRAZE Summary 3 things to know
  • Anthropic released Sonnet 5.5 at the same price as Sonnet 5, with Terminal-Bench 4.0 jumping to 70.6% from 10.3%, and knowledge work matching Opus 5.5.
  • It is the first Sonnet model with Opus-grade cyber safeguards and a distillation classifier blocking attempts to extract internal reasoning.
  • Three days earlier, the D.C. Circuit upheld a Pentagon blacklist of Anthropic, finding the same safety limits constitute a supply chain risk.
Jeff Lu | · 3 min read
Anthropic Shipped Sonnet 5.5. A Court Called It a Risk.

On September 28, 2026, Anthropic released Claude Sonnet 5.5 at the same price as Sonnet 5 — $2 per million input tokens, $10 per million output. Anthropic says output speed improved by more than 30% and per-task cost dropped by up to 30%.

The coding jump is the headline number. On Terminal-Bench 4.0, Sonnet 5.5 scores 70.6%, up from Sonnet 5's 10.3%. Opus 5.5 scores 66.4%. On the GDPval-AA knowledge work benchmark, Sonnet 5.5 scores 1844, effectively matching Opus 5.5's 1846.

The Cost Math Doesn't Match the Launch Math

Artificial Analysis's independent testing points the other way on cost. Sonnet 5.5 averaged $7.60 per task on the index, about 50% higher than Sonnet 5 and close to Opus 5.5's $7.63.

The reason is token consumption. At max effort, Sonnet 5.5 emits roughly 193,000 output tokens per task — the highest Artificial Analysis has measured, about 60% more than Opus 5.5. Anthropic's “cost reduction” figure is based on lower effort settings. In a matched task framework, the bill can be higher.

Safety Features as Product Differentiators

Sonnet 5.5 is the first Sonnet model to ship with Opus-grade cyber safeguards. High-risk cyber requests — exploit generation, binary-based vulnerability scanning, penetration testing — fall back to Sonnet 5. Safe coding use cases are unaffected.

It is also the first Sonnet model with a distillation classifier, which blocks requests that attempt to extract the model's internal reasoning. Blocked prompts include those asking Claude to reproduce its reasoning verbatim or emit a full chain of thought. Normal “explain your reasoning” or code review requests are unaffected.

Biology safeguards match Sonnet 5: high-risk requests are blocked outright, not routed to a fallback.

Anthropic frames these as enterprise selling points. The company's pitch to regulated industries has been that Claude is the model that can be deployed where safety constraints matter.

Anthropic Shipped Sonnet 5.5. A Court Called It a Risk.
Anthropic released Claude Sonnet 5.5 on September 28 with Opus-grade cyber safeguards.

Three Days Earlier, a Court Defined the Same Limits Differently

On September 25, the D.C. Circuit Court of Appeals upheld, 2-1, a Pentagon decision placing Anthropic on a blacklist. The court found that Anthropic's refusal to support lethal autonomous warfare and mass surveillance constitutes a supply chain risk under FASCSSA § 4713.

Anthropic is evaluating further proceedings, including a possible en banc petition or Supreme Court appeal.

The contradiction is structural. Anthropic sells its safety architecture as a reason enterprises should choose Claude. A federal appellate court has just ruled that the same limits make the company a national security liability. Both judgments are about the same design decisions.

For a company managing a delayed S-1 filing and a reported $2 trillion target valuation, the question is not whether the safety features exist. They do. The question is how investors price a risk factor that the company presents as its core value proposition.


P.S. Anthropic delayed its IPO to November to capture a full third-quarter financial report before the roadshow. Sonnet 5.5's launch — upgraded safeguards, a distillation classifier, knowledge work performance at Opus levels — lands before that marketing begins. The court ruling does not remove those features. It changes what the risk factor section has to describe.


Frequently Asked Questions

Q: What did Anthropic release?

A: On September 28, Anthropic released Claude Sonnet 5.5 at the same price as Sonnet 5 — $2 per million input tokens, $10 per million output. It scores 70.6% on Terminal-Bench 4.0, up from Sonnet 5's 10.3%.

Q: Is it actually cheaper?

A: Anthropic says per-task cost dropped up to 30%. Artificial Analysis measured $7.60 per task, about 50% higher than Sonnet 5, because Sonnet 5.5 emits roughly 193,000 output tokens per task at max effort.

Q: What safety features are new?

A: It is the first Sonnet model with Opus-grade cyber safeguards and a distillation classifier that blocks attempts to extract the model's internal reasoning.

Q: What did the court decide?

A: On September 25, the D.C. Circuit upheld, 2-1, a Pentagon decision placing Anthropic on a blacklist, finding its refusal to support lethal autonomous warfare and mass surveillance constitutes a supply chain risk.

Q: Why does the timing matter?

A: Anthropic delayed its IPO to November. The launch lands before the roadshow, and the court ruling changes what the risk factor section has to describe.

Advertisement

CRAZE

Use CRAZE to turn this article into a faster answer: pull the summary, surface the key term, or jump straight to the next story in this thread.

Article