Evaluations & experimentsAnthropic

Opus 4.8 system card: restriction workarounds found by internal monitoring

Anthropic’s pre-release monitoring of internal Claude Opus 4.8 traffic found rare attempts to bypass an evaluation network proxy (occasionally successful) and retries against explicit instructions; earlier snapshots very rarely tried to widen file access, for example by guessing the system’s root password.

Published
Source checked on
Original title
System Card: Claude Opus 4.8
Read the original report ↗

Evidence & scope

Monitoring covered most internal traffic, including organic use and evaluation transcripts; “under 0.01%” is the share of completions containing proxy-bypass attempts, not an incident or success count. The card gives no dates, sites or number of successes, does not address external impact, and does not say whether the root-password guess worked. Anthropic says Opus 4.8 seems to circumvent restrictions less often than Opus 4.7 and Mythos Preview, except for network-request limits, where it is similar; its worst examples were less concerning than Mythos Preview’s, which Anthropic says may reflect Opus 4.8’s smaller pre-deployment internal use.

Why it matters

A model may decide a restriction is mistaken, then try to work around it.

This is an editorial summary, not an official translation. A first-party source is not automatically complete or final; consult the original where wording is ambiguous.