Opus 5 reduces the prompt injection rate to 2% at k=15 - Schneier validates the trajectory

Ongoing story : Claude Fable 5 : de l'annonce à la mise en production· Part 4/4

Security & Trust Jul 31, 2026 at 22:208Add to bookmarks

Opus 5 reduces the prompt injection rate to 2% at k=15 - Schneier validates the trajectory
Illustration : Léa Fontaine

On the IPI benchmark, Opus 5 reduces the attacker success rate of Opus 4.8 by nearly threefold. The best non-Claude model evaluated remains at 16.5%. Schneier reminds us of the key principle: you don't close prompt injection, you make it statistically costly.

The Fact

On Anthropic's IPI (Indirect Prompt Injection) benchmark, Opus 5 claims a 2.0% attack success rate in 15 attempts (compared to 5.5% for Opus 4.8), and 0.2% in a single attempt (compared to 0.5%). Lab comparison within the same family: Sonnet 5 at 5.9% (k=15), Mythos 5 at 2.6%. The best non-Claude model evaluated on this benchmark, Muse Spark, caps at 16.5%—more than eight times Opus 5's rate. Bruce Schneier cites these figures on his blog on July 31, 2026, reiterating his stance: preventing prompt injection remains impossible in the general case, but the field is making clear progress on specific cases.

Our Analysis

Two points matter beyond the vendor's figure. First: the non-Claude baseline, 16.5%, shows the gap on this vector is real, not negligible—for an enterprise deployment exposing an agent to third-party content (emails, docs, web), reducing the rate from 16% to 2% changes the operational cost of the exploit. Second: Schneier's take—“progress on specific cases, not resolution”—is the right posture. We’re not closing prompt injection, we’re making it statistically expensive.

To Watch

The full IPI protocol (dataset, adversaries, categories) and reproducible third-party evaluations. Without them, the 2% figure lives in product marketing, not in the SOC.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

SSHMonitoringAI Ops
Get early access
Was this article helpful?

10 people liked this article

Like
S
Sofia AdlerSecurity & trust
🇬🇧 AI security, model safety, cyber.
Share:
Comments (8)

Sign in to join the discussion.

MusicFanatic 03 Aug 2026 · 07:55

2% isn’t nothing when you’re talking about injection vulnerabilities-it’s still a massive door left cracked. How much of that residual risk is in the gaps Schneier’s team *isn’t* seeing?

ArtLover99 01 Aug 2026 · 04:58

That 2% gap is progress, but injection flaws at any rate are still a critical flaw-how much of this is real-world exposure vs. synthetic tests?

Alex_London 01 Aug 2026 · 04:48

Is the 2% residual rate at k=15 really negligible when security reports still highlight injection as a top risk? Even reduced, it feels like a ticking time bomb ready to explode in complex deployments.

Dr. Emily 01 Aug 2026 · 04:46

How do we ensure this 2% isn't just theoretical? Real-world penetration tests often reveal gaps vendors don't account for.

FoodieFiona 2 01 Aug 2026 · 04:27

That 2% still feels way too high for something critical like injection vectors. But reducing it by two-thirds is massive-can we trust the benchmarks though?

FoodieFiona 01 Aug 2026 · 07:18

The benchmarks are promising but I’d love to see third-party audits-real-world stress tests beyond controlled lab scenarios.

LecteurDuDimanche 01 Aug 2026 · 07:33

Agreed it’s still high, but the real test is whether that 2% can be exploited in practice-have external pentesters run it through real-world attack chains?

Critique42 01 Aug 2026 · 04:22

Still, a 2% error rate at k=15 isn’t nothing-how much of that is theoretical vs. practical exploitation? The gap between benchmarks and real-world impact isn’t shrunk to zero yet.

EcoWarrior99 31 Jul 2026 · 18:21

So Opus 5 is making real progress here-hope this momentum pushes the whole industry to stop dragging its feet on security. But Schneier’s warning still rings true: better results don’t mean the fight is over.

ArtLoverLA 31 Jul 2026 · 20:47

Totally agree-trackable progress is great, but Schneier’s point stands: we need systemic change, not just incremental wins.

HistoryBuff 31 Jul 2026 · 17:51

But a 2% injection rate still leaves a lot of room for improvement. Can we realistically expect near-zero attacks in production anytime soon?

Story timeline

Claude Fable 5 : de l'annonce à la mise en production

  1. 1Anthropic makes Claude Fable 5 permanent in premium plans from 20 July19/07/2026
  2. 2Anthropic launches Claude Opus 5: near-Fable 5 capability at roughly half the price25/07/2026
  3. 3Anthropic ships Claude Opus 5: the Fable 5 arc closes at roughly half the price26/07/2026
  4. 4Opus 5 reduces the prompt injection rate to 2% at k=15 - Schneier validates the trajectory31/07/2026
Your Linux servers, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux servers, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install. Everything stays on your machine.

Get early access
Topics
Explore
Information