Claude Sonnet 5 is Anthropic's newest AI model, and it beats its predecessor on every benchmark the company tested while closing much of the gap to the pricier Opus 4.8 — even edging past it on one real-world knowledge-work test. Anthropic calls it the most agentic Sonnet yet, capable of building its own plans and reaching for tools like browsers and terminals with less hand-holding than before.

Claude Sonnet 5 announcement graphic

Benchmarks show a clear jump over Sonnet 4.6

Anthropic's published results show Sonnet 5 outperforming Sonnet 4.6 across the board. On agentic coding (SWE-bench Pro), Sonnet 5 hits 63.2%, up from Sonnet 4.6's 58.1%; Opus 4.8 still leads at 69.2%. On Terminal-Bench 2.1, Sonnet 5 scores 80.4% versus 67.0% for its predecessor. On Humanity's Last Exam, a multidisciplinary reasoning test, Sonnet 5 reaches 57.4% with tool use, nearly matching Opus 4.8's 57.9%. On computer-use benchmark OSWorld-Verified, Sonnet 5 posts 81.2%, ahead of Sonnet 4.6's 78.5%.

The standout result is GDPval-AA v2, a benchmark testing AI on real-world knowledge work. There, Sonnet 5 actually edges out the larger Opus 4.8, scoring 1,618 to Opus's 1,615. Anthropic says early-access partners reported the same pattern in practice, particularly in how the model handles agentic search tasks.

Cybersecurity concerns take a back seat this time

The Sonnet 5 launch arrives with an unusual backdrop: the U.S. government is currently blocking Anthropic's two most capable models, Mythos 5 and Fable 5, over cybersecurity concerns. Anthropic appears eager to avoid a repeat with Sonnet 5, noting the model wasn't trained specifically on cybersecurity tasks and scores far below both Opus 4.8 and Mythos 5 on tests for risky capabilities like writing exploit code.

Sonnet 5 does score somewhat higher than Sonnet 4.6 on those same risky-capability tests, so Anthropic has switched on real-time cyber safeguards by default — the same protection level already applied to Opus 4.7 and 4.8, though lighter than the guardrails on Fable 5, which drew user complaints over inadvertently throttling legitimate security researchers. Anthropic says it views Sonnet 5's overall cybersecurity risk as low. On the broader safety front, the company says the model is better than Sonnet 4.6 at declining malicious requests, resisting prompt-injection attacks, and avoiding both hallucinations and sycophantic responses.

Pricing and availability for Claude Sonnet 5

Claude Sonnet 5 is live now across Anthropic's AI platforms and is the new default model for Free and Pro users; Max, Team and Enterprise subscribers can access it as well, and developers can plug it into Claude Code or the Claude Platform under the API name "claude-sonnet-5." The model has a training cutoff of January 2026 and a one-million-token context window.

Through August 31, 2026, Anthropic is charging an introductory $2 per million input tokens and $10 per million output tokens; after that, pricing rises to the standard Sonnet rate of $3 and $15. Real-world costs may not track the sticker price exactly, though: because Sonnet 5 works more agentically, it's likely to consume more tokens per task, a pattern Anthropic also saw when Opus moved from version 4.6 to 4.7. For teams evaluating enterprise AI tools, that means testing actual task costs matters as much as comparing per-token rates.

Claude Sonnet 5: quick answers

How much does Claude Sonnet 5 cost?

Introductory API pricing is $2 per million input tokens and $10 per million output tokens through August 31, 2026, rising to $3 and $15 afterward — the same as previous Sonnet models.

Is Claude Sonnet 5 a cybersecurity risk?

Anthropic says no. The model wasn't trained on cybersecurity tasks and scores well below Opus 4.8 and Mythos 5 on tests for risky capabilities like exploit-writing, and it ships with real-time cyber safeguards enabled by default.