Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Anthropic's system card for Claude Sonnet 4.5, a technical disclosure document describing how the model is built, evaluated, and constrained. The document states that certain behaviors are hardcoded and cannot be unlocked by operators or users, including refusal to generate content that provides serious uplift toward weapons capable of mass casualties or sexual content involving minors. The document also discloses that Claude Sonnet 4.5 has been evaluated for agentic and multi-agent task risks, and that residual safety risks remain, particularly in adversarial prompting scenarios.
This document is the Claude Sonnet 4.5 (Claude Sonnet 5) System Card published by Anthropic, governing the design, evaluation, safety posture, and known limitations of a specific large language model release. The system card states that Claude Sonnet 4.5 is trained to balance capability and safety through a layered framework of hardcoded and softcoded behaviors, with the document asserting that certain absolute restrictions (such as refusal to assist with weapons of mass destruction or CSAM) cannot be overridden by any operator or user instruction. Notable provisions include the model's agentic use guidelines, which establish that Claude is designed to apply particular caution in multi-step autonomous tasks where actions may be difficult to reverse, and the document discloses evaluations for catastrophic risk categories including CBRN uplift and cyberweapon development. The document engages with the EU AI Act's high-risk and general-purpose AI provider requirements, the FTC's AI accountability guidance, and emerging frameworks for frontier AI safety governance, with applicability of specific compliance obligations depending on deployment jurisdiction, operator classification, and use-case context. Material compliance considerations include third-party operator reliance on Anthropic's usage policies, the allocation of safety responsibility between Anthropic and API operators, and the model's disclosed residual risks in jailbreak resistance and agentic task execution.
The system card establishes that certain model behaviors are fixed regardless of operator or user instructions, meaning users cannot prompt Claude Sonnet 4.5 to perform actions in hardcoded refusal categories such as assisting with weapons of mass destruction or generating CSAM. Under these terms, operators who access Claude via Anthropic's API are responsible for deploying the model within Anthropic's published usage policies, and downstream users operate under both Anthropic's and the operator's permission layers. The document discloses that residual risks exist in adversarial prompting and agentic task contexts, which users and operators should account for in high-stakes deployments.
Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.
1 important change detected
4 versions captured · Last updated: July 2026
Anthropic has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.
Cross-platform context
See how other platforms handle Agentic Task Minimal Footprint Principle and similar clauses.
Compare across platforms →Anthropic is more transparent than most AI companies about data retention. Here's exactly what happens when you delete your data, and how t…
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.