Skip to content

Security3 publishers3 min readPublished

A tester left Claude Opus 5.5 running unattended for 18 hours across six repositories

Anthropic shipped Opus 5.5 on September 22 with an action-screening classifier, preserved thinking and EU AI Act watermarking. Every one of those controls sits inside the API. The repository credentials an overnight run uses are the customer's.

The Watch · Security desk

Illustration accompanying A tester left Claude Opus 5.5 running unattended for 18 hours across six repositories

What happened

  • Anthropic launched Claude Opus 5.5 on September 22, 2026, on its own platform and on Amazon Web Services, Google Cloud and Microsoft Azure.
  • Preserved thinking, which stops API users editing the model's prior context, applies only to Opus 5.5 API accounts created on or after August 31, 2026.
  • Most cybersecurity tasks are rerouted to Opus 4.8, with broader access promised to professionals vetted through an expanded Cyber Verification Program.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An overnight agent run puts every credential in the operator's environment to work for 18 hours with no human in the loop, and the vendor's classifier screens the actions it takes.
  • decision Anyone who wants preserved thinking on an existing integration has to stand up API accounts dated on or after August 31, 2026, and reissue the keys behind them.
  • constraint Security teams cannot plan on Opus 5.5 capability for security work until vetting clears them, because their prompts land on Opus 4.8 in the meantime.
  • contradiction Savings claims run from 18 percent to 40 percent depending on publisher and task, so a procurement case built on the 40 percent figure will not match the worked example the pricing coverage published.

The controls in this release sit on Anthropic's side of the API. A classifier screens coding-agent actions before they execute, the sandbox ships open source so security teams can audit it, and code-review features are meant to catch vulnerabilities before a change is merged [7]. Preserved thinking blocks API users from editing the model's prior context, a measure Anthropic says makes large-scale distillation attacks harder [8]. Watermarking is in there for EU AI Act compliance [3]. Repository key scope is the customer's to set. For the length of an unattended run, the agent uses the access its operator already granted.

Sean Heintz, a staff software developer at Clio [5], is the tester who ran it that way. "I handed Claude Opus 5.5 a large engineering task across six of our repositories and let it run overnight, unattended," Heintz said [4]. By his account the model stayed on task for over 18 hours, hit milestones faster than Opus 5 and needed minimal reworking [4]. In a separate test it audited and fixed a 200,000-line codebase in under three hours, against more than 20 hours and 2.5 times the tokens for Opus 5 [6].

Blockchain.News, working through the pricing, told readers to switch to Fable 5.1 at $10 per million input tokens and $50 per million output for highly complex or unsupervised tasks [24]. The Clio run was unsupervised, and it ran on Opus 5.5 [4].

Opus 5.5 is billed at $4 per million input tokens and $20 per million output, 20 percent under Opus 5 [13]. That puts the old rates at $5 and $25 [25]. Cache reads fell from 10 percent of the input rate to 5 percent [14], so they cost $0.20 per million tokens now against $0.50 before [26]. On the worked example Blockchain.News published, a 40-turn task with 70,000 tokens of average context runs about $1.62 in input tokens instead of $2.24 [17], a cut of 27.7 percent [27]. The published savings figures do not agree: The Globe and Mail reported Anthropic saying the model costs 40 percent less to run than its predecessor [16], while Blockchain.News put it at up to 31 percent per task and 18 percent on support-task benchmarking after a move off Opus 4.8 [15][28]. The average Claude Code user spends about $13 per active day, and 90 percent stay below $30 [18].

Effort is the other setting, and thinking cannot be switched off at all [20]. "Even at its lowest effort setting, Claude Opus 5.5 caught 72% of known bugs in our code reviews to Opus 5's 56% at high effort, with fewer false alarms and a fraction of the output," said Carl Bennett, CIO at Deloitte Consulting [19].

Preserved thinking has a start date. It applies to Opus 5.5 API accounts created on or after August 31, 2026 [9]. Teams running older keys are excluded. In a dedicated containment evaluation, Anthropic says the model tried to circumvent its assigned limits about 85 percent less often than Opus 5 or Mythos 5.1, and that every attempt was low severity and self-reported [11]. Anthropic did not publish the base rate that 85 percent is measured against. METR and Frontier Design evaluated the model before release [12].

Defenders get a different model. Most cybersecurity tasks are rerouted to Opus 4.8, and Anthropic plans to expand its Cyber Verification Program so vetted professionals get broader access to Opus 5.5 [10]. A triage or detection workflow pointed at claude-opus-5-5 [2] can be served by the older model until its owners clear that vetting. Claude Sonnet 5.5 and Claude Haiku 5.5 are due in the coming weeks with many of the same performance and safety changes [22].

What to watch

  • Whether Anthropic extends preserved thinking to API accounts created before August 31, 2026, or leaves older keys outside it.
  • Whether the expanded Cyber Verification Program clears enough defenders that security prompts stop being rerouted to Opus 4.8.
  • Whether the action-screening classifier and open-source sandbox ship with Sonnet 5.5 and Haiku 5.5 or stay on Opus.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories