Last updated: September 2026
What changed in Claude Sonnet 5.5, and should your team switch from Sonnet 5?
Claude Sonnet 5.5 is Anthropic's new mid-tier model, released on September 28, 2026. It keeps Sonnet 5's price of $2 per million input tokens and $10 per million output tokens, generates outputs more than 30% faster, and costs up to 30% less per task because it uses fewer tokens and tool calls. It is also the first Sonnet to ship with frontier-style cyber safeguards and anti-distillation classifiers.
The catch is on the security and integration side: some cyber requests now fall back to Sonnet 5, thinking blocks are bound to your account, and several API behaviors break. This guide covers only what is new in 5.5. For the Sonnet 5 system card, read our Claude Sonnet 5 security and safety review.
TL;DR: Key Takeaways
- Same price, faster output: $2 / $10 per million tokens and $0.20 cache reads, like Sonnet 5, with outputs "30%+ faster", per Anthropic's launch page.
- Lower cost per task: up to 30% lower, per Anthropic. CodeRabbit measured $0.47 per review versus $1.16 on Sonnet 5 in its independent review.
- Near-Opus benchmarks: Sonnet 5.5 scores 70.6% on Terminal-Bench 4.0 (Sonnet 5: 10.3%, Opus 5.5: 66.4%) (Anthropic-reported).
- New cyber safeguards: higher-risk cyber requests "visibly fall back to Sonnet 5", per the Sonnet 5.5 system card.
- Anti-distillation: the first Sonnet with reasoning-extraction classifiers; thinking blocks work only in the producing account, per the preserved thinking docs.
- Prompt injection: Gray Swan attack success at 15 attempts fell to 3.4%, from 6.7% on Sonnet 5, per the system card.
Sonnet 5 vs Sonnet 5.5: What Changed
Sonnet 5.5 changes speed, token efficiency, capability and safeguards while keeping Sonnet 5's price, context window and output limit. The table lists every change that affects cost, performance or governance.
| Claude Sonnet 5 | Claude Sonnet 5.5 | |
|---|---|---|
| Release date | June 30, 2026 (now legacy) | September 28, 2026 |
| API price (input / output per 1M) | $2 / $10 | $2 / $10 (unchanged) |
| Cache reads / 5-minute cache writes | $0.20 / $2.50 | $0.20 / $2.50 |
| Minimum cacheable prompt | 1,024 tokens | 512 tokens |
| Output speed | Baseline | 30%+ faster |
| Cost per task | Baseline | Up to 30% lower (vendor-reported) |
| Context window / max output | 1M / 128K | 1M / 128K |
| Knowledge cutoff | January 2026 | June 2026 |
| Terminal-Bench 4.0 | 10.3% | 70.6% |
| Cyber safeguards | Sonnet-class | Similar to Opus; higher-risk cyber requests fall back to Sonnet 5 |
| Reasoning-extraction classifiers | No | Yes, block with no fallback |
| Thinking blocks | Not account-bound | Work only in the producing account |
Sources: Sonnet 5.5 overview; Sonnet 5 overview; What's new in Sonnet 5.5; Anthropic.
Speed: 30% Faster Outputs and Recalibrated Effort
Sonnet 5.5 generates output more than 30% faster than Sonnet 5, which Anthropic calls its fastest Sonnet to date. It also reaches answers in fewer steps, so agent tasks can finish even faster.
Where the speed shows up
In Anthropic's announcement, Box says Sonnet 5.5 was "2.4x faster" and used 12% fewer total tokens, and Zendesk says "tickets were processed 20% faster". In CodeRabbit's independent test, mean review time fell from 9:55 to 5:27 on its hardest benchmark, according to CodeRabbit (2026).
Effort defaults you should re-test
Claude Code and the Claude apps default to Medium effort, while the Claude API defaults to High. The migration guide says levels "are recalibrated" and recommends High for general use and Medium for agentic or latency-sensitive work. Re-run your effort sweep before production.
Claude Sonnet 5.5 Pricing and Cost per Task
Claude Sonnet 5.5 pricing is identical to Sonnet 5: $2 per million input tokens, $10 per million output tokens and $0.20 per million cached reads. Savings come from using fewer tokens and tool calls, and depend on your workload.
API price list
| Per 1M tokens | Sonnet 5 | Sonnet 5.5 | Opus 5.5 | GPT-6 Sol |
|---|---|---|---|---|
| Input | $2 | $2 | $4 | $2 |
| Output | $10 | $10 | $20 | $10 |
| Cache read | $0.20 | $0.20 | $0.20 | $0.20 |
| Cache write (5 min) | $2.50 | $2.50 | $5 | $2.50 |
| Batch discount | 50% | 50% | 50% | 50% |
Sources: Claude pricing; Claude model overview; OpenAI GPT-6 Sol model docs. US list prices, September 2026.
Sonnet 5.5 halves the minimum cacheable prompt to 512 tokens, so shorter prompts now qualify for cache reads. GPT-6 Sol charges 2x input and 1.5x output rates above 272K input tokens, per OpenAI's model documentation.
How much less per task
At Medium effort, Sonnet 5.5 "far exceeds Sonnet 5's best score for less than a tenth of the cost per task" on Terminal-Bench 4.0. Customer data adds absolute numbers.
| Source | Sonnet 5 | Sonnet 5.5 | Change |
|---|---|---|---|
| CodeRabbit, cost per code review | $1.16 | $0.47 | About 60% lower |
| CodeRabbit, output tokens per review call | 21.6K | 5.8K | About 73% fewer |
| Balyasny, tokens per finance answer (2,441 tasks) | 497K | 121K | About 76% fewer |
| Lovable, tool calls per coding task | Baseline | A third fewer | Half the shell runs |
Sources: CodeRabbit; customer quotes on Anthropic's launch page. Customer figures are self-reported.
According to VentureBeat (2026), the gain comes because the model "uses fewer tokens and fewer tool calls", per its launch report. For budget controls, see our AI token optimization guide.
Claude Sonnet 5.5 Benchmarks vs Sonnet 5, Opus 5.5 and GPT-6 Sol
Claude Sonnet 5.5 lands within a few points of Opus 5.5 on most of Anthropic's published benchmarks and beats it on Terminal-Bench 4.0. Every score below is Anthropic-reported, not independently reproduced.
| Benchmark | Sonnet 5 | Sonnet 5.5 | Opus 5.5 | GPT-6 Sol |
|---|---|---|---|---|
| Terminal-Bench 4.0 | 10.3% | 70.6% | 66.4% | Not reported |
| CursorBench 4.0 | 34.1% | 55.5% | 57.8% | Not reported |
| FrontierCode 1.1 (Max) | 42.4% | 46.2% (52.1% at Xhigh) | 54.4% | 49.3% |
| GDPval-AA v2.1 (Elo) | 1449 | 1844 | 1846 | 1487 |
| OSWorld 2.1 (partial credit) | 57.0% | 80.1% | 81.8% | Not reported |
| Humanity's Last Exam (with tools) | 54.9% | 64.5% | 67.7% | Not reported |
| Chartography (no tools) | 15.6% | 61.6% | 64.4% | 53.6% |
Source: Anthropic, Introducing Claude Sonnet 5.5 (September 28, 2026). All scores vendor-reported.
Reading the numbers with care
According to The Decoder (2026), "independent testing still needs to confirm these claims", and Sonnet 5's 10.3% on Terminal-Bench 4.0 looks unusually low. The same report notes that Sonnet 5.5 scores lower on FrontierCode at Max than at Xhigh because of timeouts.
Comparison with GPT-6 Sol
OpenAI released GPT-6 Sol on September 22, 2026, at the same $2 / $10 list price, according to VentureBeat. OpenAI reports 68.8% on DeepSWE 1.1 and 60.5% on OSWorld 2.0 for Sol in its launch post. Those benchmark versions differ from Anthropic's, so they cannot be compared directly.
How we compared
We used only published, dated sources: vendor pages, the system card, API docs, one independent review and tech press. Vendor-reported scores are labeled. We ran no private tests.
The New Cyber and Anti-Distillation Safeguards
Sonnet 5.5 is the first Sonnet that Anthropic ships with Opus-style cyber blocking. Higher-risk cyber requests fall back to Sonnet 5, attempts to extract hidden reasoning are blocked outright, and thinking blocks stop working outside the account that created them.
Why the cyber safeguards arrived now
On CyScenarioBench, Sonnet 5.5 completed 46.1% of challenges against 0.7% for Sonnet 5, and it produced 50 control-flow hijacks in binary exploitation tests against 3, per the system card. Anthropic calls its cyber capabilities "a large improvement over Sonnet 5's" and deploys "safeguards similar to those on Opus 5.5". The system card compares its classifiers' recall with those on Opus 5.
How the fallback works
Routine bug fixing still runs on Sonnet 5.5. Flagged higher-risk cyber requests go to Sonnet 5, and blocks "do not covertly change model responses".
| Refusal category | What triggers it | Automatic fallback |
|---|---|---|
cyber | Could enable cyber harm | Yes, to Sonnet 5 (opt-in on the API) |
frontier_llm | Could assist competing AI model development | Yes, to Sonnet 5 (opt-in on the API) |
reasoning_extraction | Asks the model to reproduce its internal reasoning | No |
bio and general_harms | Biological harm and other usage policy areas | No |
Source: What's new in Claude Sonnet 5.5 (September 2026).
On the API, a block returns stop_reason: "refusal" with a category in stop_details. Server-side fallback is an opt-in beta (fallbacks: "default") on the Claude API only. The system card warns that traffic "via other platforms and providers may experience different behavior", so test separately on Amazon Bedrock, Google Cloud or Microsoft Foundry.
Defenders who need more room can apply to the expanded Cyber Verification Program, which Sonnet 5.5 will join "in the near future". Organizations on zero data retention are not eligible, per Anthropic's cyber safeguards article.
Anti-distillation and account-bound thinking
Distillation attacks use "thousands of fake accounts to extract a model's capabilities at industrial scale", according to Anthropic. Sonnet 5.5 is the first Sonnet with classifiers that block reasoning extraction, with no fallback model.
Its thinking blocks are also account-bound: they "work only in the account that produced them, or in an account linked to it". If another account sends one, the API drops it and the request still succeeds. In August 2026, researchers decoded 315,320 thinking blocks from 6,708 public agent traces and recovered 62 API keys and 7 private keys, according to The Hacker News.
What Developers Must Change When Migrating
Moving from Sonnet 5 to Sonnet 5.5 is not a drop-in swap. Test these breaking changes before switching the model ID.
| Change | Impact | What to do |
|---|---|---|
| Forced tool use removed | tool_choice "any" or a named tool returns 400 | Use auto with strict: true tools |
| Sampling parameters rejected | Non-default temperature, top_p, top_k return 400 | Remove them |
| Append-only conversations | Editing earlier history invalidates thinking | Keep history append-only, or use drop_block |
| Quieter streaming | Text between tool calls returns in thinking blocks | Update UIs that stream progress text |
Sources: Migration guide; What's new in Sonnet 5.5.
A proxy that rewrites or redacts earlier messages can break thinking continuity, so plan for it in your LLM model routing design.
Security and Governance: Running Sonnet 5.5 Agents Safely
Sonnet 5.5 is harder to hijack than Sonnet 5, but model-level defenses do not replace controls on what your agents can reach. Data leakage and tool misuse remain your problem once an agent holds real credentials.
What the system card shows
| Prompt injection test | Sonnet 5 | Sonnet 5.5 |
|---|---|---|
| Gray Swan indirect injection, success at 1 / 10 / 15 attempts | 0.7% / 5.1% / 6.7% | 0.4% / 2.7% / 3.4% |
| Coding, adaptive attacker, no safeguards | 19.47% | 3.01% |
| Computer use, all attempts, no safeguards | 2.25% | 0.07% |
| Benign requests refused (API / claude.ai) | 0.59% / 1.54% | 0.02% / 0.20% |
Source: Claude Sonnet 5.5 System Card (September 28, 2026). The coding test was rewritten in August 2026, so Sonnet 5's figure differs from its original card.
Anthropic treats Sonnet 5.5 as meeting its CB-1 and Autonomy-1 thresholds and says it "does not cross any new RSP thresholds". Our Sonnet 5 analysis covers the baseline, including under 1% browser-use injection success and zero complete ExploitBench exploits.
The risks that remain yours
- Prompt injection (OWASP LLM01): prompts that "alter the LLM's behavior or output in unintended ways", including hidden instructions in files and web pages, per OWASP LLM01:2025. A 3.4% success rate is low, not zero. Our indirect prompt injection guide maps the attack path.
- Data leakage and tool misuse: according to Gartner (2026), 25% of enterprise GenAI applications will face at least five minor security incidents a year by 2028, up from 9% in 2025, per its April 2026 release.
- Governance gaps: Gartner also predicts that by 2027, 40% of enterprises will demote or decommission autonomous agents over governance gaps found only after incidents, per its May 2026 release.
How NeuralTrust secures Sonnet 5.5 deployments
NeuralTrust's Runtime Security Mesh adds controls that do not depend on which Claude version you run:
- Agent Gateway (TrustGate): routes Sonnet 5.5, its Sonnet 5 fallback and other models through one policy point with identity-based access control and a single audit trail. TrustGate ships with 200+ pre-built MCP servers.
- Agent Runtime Security (TrustGuard): inspects prompts, tool calls and responses in real time to block injection, secret leakage and destructive commands.
- AI Red Teaming (TrustTest): tests your own Sonnet 5.5 agents against injection and extraction attacks before release, so you measure your exposure, not lab numbers.
Sonnet 5.5, Opus 5.5 or GPT-6 Sol: Which Should You Choose?
Choose Sonnet 5.5 for most production agent work, where it nearly matches Opus 5.5 at half the token price. Keep Opus 5.5 for the hardest reviews and architecture tasks; our Opus 5.5 enterprise guide covers the flagship. Evaluate GPT-6 Sol if you want a second vendor at the same list price.
| If you are... | Choose | Why |
|---|---|---|
| Running high-volume agents on Sonnet 5 | Sonnet 5.5 | Same price, 30%+ faster, fewer tokens per task |
| Doing complex code review or system design | Opus 5.5 | 8 of 13 hard review cases caught vs 6 for Sonnet 5.5 (CodeRabbit) |
| A terminal-heavy coding team | Sonnet 5.5 | 70.6% on Terminal-Bench 4.0, above Opus 5.5 (vendor-reported) |
| A security team doing offensive research | Cyber Verification Program access | Higher-risk cyber work falls back to Sonnet 5 until you are verified |
| An app that edits or replays chat history | Refactor first, or use drop_block | Sonnet 5.5 thinking expects append-only history |
| A CISO standardizing across models | Any, behind one gateway | One policy and audit trail across fallbacks and vendors |
Conclusion
Claude Sonnet 5.5 is a straightforward upgrade on cost: same list price, 30%+ faster output and up to 30% lower cost per task, with benchmarks close to Opus 5.5. The real changes are in security and integration. Cyber fallback, anti-distillation classifiers and account-bound thinking change how refusals, logs and routing behave. Test your effort settings and breaking changes first, then migrate.
Secure Sonnet 5.5 Agents in Production with NeuralTrust
Run Sonnet 5.5, its Sonnet 5 fallback and every other model behind one policy layer, with real-time protection for each prompt and tool call.
Related Comparisons
FAQs about Claude Sonnet 5.5
1. When was Claude Sonnet 5.5 released?
Anthropic released Claude Sonnet 5.5 on September 28, 2026. It is available on every Claude plan, including Free, in Claude Code, on the Claude API as claude-sonnet-5-5, and on Amazon Bedrock, Google Cloud and Microsoft Foundry. Sonnet 5 is now a legacy model, with retirement not before June 30, 2027.
2. How much does Claude Sonnet 5.5 cost?
Sonnet 5.5 costs $2 per million input tokens and $10 per million output tokens, the same as Sonnet 5. Cache reads cost $0.20 per million tokens, 5-minute cache writes $2.50, and batch processing is 50% off. Anthropic says it costs up to 30% less per task because it needs fewer tokens and tool calls.
3. Is Sonnet 5.5 better than Sonnet 5?
On Anthropic's benchmarks, yes, by wide margins: 70.6% versus 10.3% on Terminal-Bench 4.0 and 80.1% versus 57.0% on OSWorld 2.1. CodeRabbit's independent test found it caught more hard bugs at about 60% lower cost per review.
4. Is Sonnet 5.5 better than Opus 5.5?
Mostly no, but it comes close. Opus 5.5 leads on CursorBench 4.0 (57.8% versus 55.5%), FrontierCode and Humanity's Last Exam, while Sonnet 5.5 leads on Terminal-Bench 4.0 (70.6% versus 66.4%). Sonnet 5.5 costs half as much per token, at $2 / $10 versus $4 / $20.
5. What are the new cyber safeguards in Sonnet 5.5?
Sonnet 5.5 uses blocking classifiers similar to those on Anthropic's Opus models. Routine bug fixing runs normally, but higher-risk cyber requests visibly fall back to Sonnet 5. On the API, fallback is an opt-in beta. Verified defenders will get broader access through the Cyber Verification Program.
6. What does anti-distillation mean in Sonnet 5.5?
Distillation means using many accounts to copy a model's capabilities, often by extracting hidden reasoning. Sonnet 5.5 is the first Sonnet with classifiers that block reasoning extraction, with no fallback. Its thinking blocks also work only in the account that produced them.
7. How does Sonnet 5.5 compare with GPT-6 Sol?
Both cost $2 / $10 per million tokens. Anthropic reports Sonnet 5.5 ahead on GDPval-AA (1844 versus 1487) and FrontierCode (52.1% at Xhigh versus 49.3%). OpenAI reports 68.8% on DeepSWE 1.1 for Sol, which Anthropic did not test.
About the Author
Roger Howroyd is Head of Global SEO and AI at NeuralTrust, where he leads the company's search strategy across SEO, AEO, GEO, and LLM optimization. He specializes in AI-powered search, content strategy, and SEM. Connect on LinkedIn.
NeuralTrust is the leading platform for securing and scaling AI agents. Named a Pioneer in the Gartner Emerging Market Quadrant for AI Application Security 2026, recognized across four Gartner Hype Cycle reports in 2026, and featured in the Gartner Market Guide for Guardian Agents 2026, the Gartner Market Guide for AI Gateways 2025 and the KuppingerCole Leadership Compass for Generative AI Defense 2025. Headquartered in Barcelona with offices in London and New York. ISO 27001 certified.
Sources
- Anthropic: Introducing Claude Sonnet 5.5 (September 28, 2026)
- Anthropic: Claude Sonnet 5.5 System Card (September 28, 2026)
- Claude Docs: Claude Sonnet 5.5 overview (September 2026)
- Claude Docs: What's new in Claude Sonnet 5.5 (September 2026)
- Claude Docs: Sonnet 5.5 migration guide (September 2026)
- Claude Docs: Preserved thinking (September 2026)
- Claude Docs: Claude Sonnet 5 overview (September 2026)
- Claude: Pricing (September 2026)
- Claude Help Center: Real-time cyber safeguards (September 2026)
- Anthropic: Introducing Claude Opus 5.5 (September 22, 2026)
)
)
)
)
)
)
)