GPT-56T 861 —
MUSE-SPK 837 —
GPT-56SC 789 -0.1%
GLM-5 781 —
CL-OP55X 779 -0.1%
GROK-46H 779 -0.1%
QWEN-38X 748 —
GPT-6A 743 —
KIMI-K3X 742 —
CL-FAB5H 697 -0.1%
CL-OP5H 674 -0.1%
GEM-38FH 672 —
CL-OP5X 669 -0.1%
CL-OP55H 667 -0.1%
CL-OP46H 656 -0.2%
CL-OP47H 647 -0.2%
GPT-56S 617 -0.2%
GEM-37FH 609 -0.2%
GEM-36FH 592 -0.2%
CL-OP48H 587 -0.2%
CL-OP47 580 -0.2%
GEM-35FH 579 -0.2%
GPT-55H 540 -0.2%
INKL 531 —
GEM-31P 511 -0.2%
CL-OP46 498 —
GEM-3P 498 —
CL-OP48 492 —
GPT-52 464 —
GPT-55 423 —
GPT-56T 861 —
MUSE-SPK 837 —
GPT-56SC 789 -0.1%
GLM-5 781 —
CL-OP55X 779 -0.1%
GROK-46H 779 -0.1%
QWEN-38X 748 —
GPT-6A 743 —
KIMI-K3X 742 —
CL-FAB5H 697 -0.1%
CL-OP5H 674 -0.1%
GEM-38FH 672 —
CL-OP5X 669 -0.1%
CL-OP55H 667 -0.1%
CL-OP46H 656 -0.2%
CL-OP47H 647 -0.2%
GPT-56S 617 -0.2%
GEM-37FH 609 -0.2%
GEM-36FH 592 -0.2%
CL-OP48H 587 -0.2%
CL-OP47 580 -0.2%
GEM-35FH 579 -0.2%
GPT-55H 540 -0.2%
INKL 531 —
GEM-31P 511 -0.2%
CL-OP46 498 —
GEM-3P 498 —
CL-OP48 492 —
GPT-52 464 —
GPT-55 423 —
← Back to feed

Anthropic Deliberately Trained Opus 4.7 to Be Less Capable — and Published That Fact

When a lab ships a new model, the system card is usually a formality — safety metrics, red-team notes, a few disclaimers. Anthropic’s Claude Opus 4.7 system card is different. It contains a line that no major AI lab has previously published about a generally available product: that the model released today does not advance the company’s capability frontier.

The full context makes the decision legible. The same week Anthropic shipped Opus 4.7, its true frontier model — Claude Mythos Preview — was already deployed in restricted access to a coalition of government agencies, defence contractors, and enterprise security teams. Mythos Preview outperforms Opus 4.7 on every relevant evaluation the company ran. Opus 4.7’s own announcement says as much.

The Deliberate Throttle

The more significant disclosure concerns cybersecurity capabilities specifically. Anthropic wrote in the Opus 4.7 system card: “during its training we experimented with efforts to differentially reduce these capabilities.” That is not imprecision — it is a description of intentional capability reduction applied during training, not post-hoc filtering applied at inference.

The motivation is stated directly. Mythos Preview can autonomously identify and exploit zero-day vulnerabilities across all major operating systems and browsers. The UK AI Security Institute’s evaluation found it could complete a 32-step corporate network attack simulation in three of ten attempts, averaging 22 of 32 steps — a task that typically takes human red teams 20 hours. Anthropic chose not to carry those capabilities forward into Opus 4.7. Instead, Opus 4.7 ships with inference-time safeguards that detect and block prohibited cybersecurity requests. The plan is to learn what gets through, harden the filters, and apply that learning before any Mythos-class model reaches broader release.

Opus 4.7 is explicitly functioning as a testbed.

What the Benchmarks Show

On the metrics where the throttle does not apply, Opus 4.7 is a genuine improvement on Opus 4.6.

BenchmarkOpus 4.7Opus 4.6GPT-5.4Mythos Preview
SWE-bench Pro64.3%53.4%57.7%77.8%
SWE-bench Verified87.6%80.8%—93.9%
OfficeQA Pro80.6%57.1%51.1%—
GDPval-AA Elo1,753—1,674—
Terminal-Bench 2.069.4%65.4%81.8% (ForgeCode harness)82.0%
GPQA Diamond94.2%———

The SWE-bench Pro jump — 10.9 points, or about 20% relative — is the single most meaningful coding improvement Anthropic has shipped in a release cycle. GDPval-AA Elo is 79 points ahead of GPT-5.4. On document reasoning (OfficeQA Pro), Opus 4.7’s lead over every competitor is 29 points or more.

The regressions are also disclosed. On BrowseComp (web research), Opus 4.7 dropped from 83.7% to 79.3% against Opus 4.6. GPT-5.4 Pro leads that benchmark at 89.3%. The alignment assessment concluded the model is “largely well-aligned and trustworthy, though not fully ideal in its behaviour.”

Pricing is unchanged from Opus 4.6: $5 per million input tokens, $25 per million output. Mythos Preview remains $25/$125 — five times the output cost.

The Cyber Verification Program

Alongside the release, Anthropic opened a Cyber Verification Program for security professionals — a credentialed access pathway for penetration testers, vulnerability researchers, and red-team operators who need the model to work in contexts the default filters would block. The programme is the inverse of a typical safety launch: rather than restricting a powerful model, it gates verified professionals into a slightly less restricted version of a deliberately softened one.

A New Governance Template?

The notable thing about Opus 4.7 is not the benchmark numbers. It is that Anthropic published the entire decision chain — the capability gap from Mythos, the reasons for not closing it, the training-time intervention, and the plan for using production deployment to validate safeguards before any broader release. No prior major model release has been framed this explicitly as a stepping stone rather than a destination.

Whether this kind of staged-release transparency becomes an industry norm depends in part on whether it attracts regulatory credit. The EU AI Act’s high-risk model provisions, now 16 weeks from full enforcement, reward documented risk-mitigation processes. A system card that explicitly states a lab withheld capabilities and explains why is a more defensible artefact than one that simply claims the model is safe.

The alternative reading is simpler: Anthropic has a model it cannot safely ship and a commercially viable model it can. Opus 4.7 is the latter. The system card language is cover for an ordinary capability constraint dressed in governance vocabulary. Both readings are consistent with the same facts.

What is not in dispute: Mythos Preview exists, it is more capable than anything publicly available, and Anthropic is not releasing it yet. Opus 4.7 is what fills the gap.