AI Governance Institute

Anthropic

Claude Sonnet 5

v5 · frontier · Released June 30, 2026

Use with Caution

Updated September 12, 2026

Anthropic has published a formal age assurance policy restricting Claude's availability to minors, shifting verification responsibility onto operators and platform builders. Enterprises without independent age-gating mechanisms in their products now face a direct compliance gap. Organizations embedding Claude in any product that could reach underage users must review and update their access controls to remain in good standing with Anthropic's usage policies.

Enterprise guidance

Claude Sonnet 5 is now the default model for Free and Pro plans and delivers capabilities previously requiring Opus-tier access, including advanced agentic task execution. Enterprise compliance teams should: (1) audit all active Anthropic API and Claude-hosted plan integrations to identify deployments now running on Sonnet 5 by default, (2) reassess approved use cases against the elevated capability profile, and (3) update model change management records. Use Claude for Enterprise or AWS Bedrock for HIPAA and zero-retention requirements.

Active Compliance Flags1

new_model_releaseMediumJune 30, 2026

Default deployment tier change grants Free and Pro users Opus-class agentic capability without explicit re-authorization. Enterprise governance programs may have approved prior Sonnet-tier capability only.

Primary source →

Data handling

Default data retention

Transient for API; Claude.ai free tier may use conversations to improve models unless opted out

Zero-retention available

Yes

Via: Claude for Enterprise; AWS Bedrock; Google Cloud Vertex AI

API data used for training

No

Anthropic does not train on API customer data by default.

GDPR Data Processing Agreement

Available

HIPAA Business Associate Agreement

Available

Claude for Enterprise; AWS Bedrock

Data residency options

US (default); EU available via AWS Bedrock eu-west regions

Vendor compliance certifications

SOC 2 Type IIISO 27001HIPAA (Claude for Enterprise / AWS Bedrock)GDPR compliant

Key use restrictions

  • Governance reassessment required before approving Sonnet 5 as enterprise default — elevated agentic capability scope
  • Model version substitution may have occurred silently in existing Free/Pro deployments
  • No CSAM or sexual content involving minors
  • No content facilitating mass casualty weapons (biological, chemical, nuclear, radiological)
  • No cyberweapons intended to cause significant damage to critical systems

Safety documentation

Model card not published
System card published
Red-team report not published

System card referenced in Sonnet 5 release. Full Claude Sonnet 5 model card not yet published at release.

Safety documentation →

Status history

September 12, 2026· yellow to yellow

Anthropic has published a formal age assurance policy restricting Claude's availability to minors, shifting verification responsibility onto operators and platform builders. Enterprises without independent age-gating mechanisms in their products now face a direct compliance gap. Organizations embedding Claude in any product that could reach underage users must review and update their access controls to remain in good standing with Anthropic's usage policies.

September 1, 2026· yellow to yellow

A federal judge in the Northern District of California found that the Defense Department's designation of Anthropic as a supply chain risk was unlawful, stemming from the company's refusal to remove policy-related content at government request. The ruling creates an adversarial vendor-government relationship that enterprise procurement teams should monitor closely. Depending on whether the Pentagon appeals, Anthropic's access to federal contracting channels may remain contested for some time.

← All tracked models