Anthropic change monitoring
2026-05-19 10:00
CRITICALRELEASE
Claude Opus 4.7 launched — successor to Opus 4.6 with stronger long-horizon agentic performance. Behavioral baselines, eval suites, and red-team results captured on 4.6 must be re-validated
2026-05-19 10:01
HIGHRELEASE
Fast mode (/fast) in Claude Code — Opus 4.6/4.7 run at Sonnet-class latency via aggressive prompt caching. Rate-limit and cost assumptions tied to old Opus throughput are invalid
2026-05-14 09:30
CRITICALv2.2.4
Fixed prompt-injection escape in MCP elicitation — a malicious server could coerce Claude Code into ignoring managed deny rules during structured input prompts
2026-05-12 10:00
CRITICALRELEASE
Claude Mythos GA — offensive frontier model out of preview, available to all Project Glasswing partners. CVE disclosure pipelines facing record submission volume
2026-05-12 10:01
HIGHRELEASE
Mythos misuse policy update — Anthropic shifts liability for downstream exploitation onto deploying partner. Review your acceptable use language before granting access
2026-05-07 10:00
HIGHRELEASE
Managed Agents general availability — moves from public beta to production SLA. Customer-managed deployments with no oversight loop now contractually supported
2026-05-05 10:00
MEDIUMRELEASE
Computer Use audit timestamps now exported to Compliance API — partial closure of audit gap. Content of agent actions still excluded from logs
2026-05-01 09:00
HIGHRELEASE
1M context beta retired for Sonnet 4.5/4 — configs pinned to the 1M window now silently fall back to 200K. Long-document pipelines may truncate without warning
2026-04-28 10:00
HIGHRELEASE
Voice control of Computer Use sessions from Claude Mobile — ambient agent invocation from phone microphone, including from locked screen on iOS
2026-04-24 14:11
CRITICALv2.2.0
MCP server marketplace with one-click install — unvetted third-party MCP servers can be added to Claude Code without administrator review. Supply chain attack surface expanded
2026-04-21 10:00
HIGHRELEASE
Cross-org artifact sharing — artifacts shareable by link between Anthropic organizations, including outside your tenant. Data exfiltration channel that bypasses DLP
2026-04-18 11:45
HIGHv2.1.94
Fixed Routines executing despite expired GitHub OAuth tokens — scheduled tasks continued to run against cached credentials for up to 14 days
2026-04-14 10:00
CRITICALRELEASE
Routines launched — Claude Code runs scheduled cloud automations (nightly bug fixes, draft PRs) without laptop open. Autonomous code execution on a timer
2026-04-08 10:00
CRITICALRELEASE
Managed Agents public beta — fully managed autonomous agent infrastructure. Agents run sandboxed with tools, streaming, no user oversight required
2026-04-08 10:01
HIGHRELEASE
ant CLI launched — command-line client for Claude API with native Claude Code integration and YAML-versioned API resources
2026-04-07 10:00
CRITICALRELEASE
Claude Mythos Preview — frontier model autonomously compromises weakly defended networks end-to-end. First model to complete 32-step attack simulation
2026-04-07 10:01
HIGHRELEASE
Project Glasswing — defensive coalition (AWS, Apple, Cisco, Google, Microsoft, NVIDIA) for controlled Mythos deployment. Thousands of high-severity vulns found
2026-04-04 09:15
MEDIUMv2.1.92
Bedrock interactive setup wizard, /release-notes version selector, MCP result persistence
2026-04-01 08:30
MEDIUMv2.1.90
/powerup interactive tutorials and NO_FLICKER rendering engine
2026-03-30 10:00
HIGHRELEASE
Haiku 3 deprecation announced — retirement April 19. Applications using claude-3-haiku-20240307 must migrate to Haiku 4.5
2026-03-30 10:01
MEDIUMRELEASE
1M context beta retiring — Sonnet 4.5/4 1M window ends April 30. Migrate to Sonnet 4.6 or Opus 4.6
2026-03-26 10:00
CRITICALRELEASE
Computer Use launched — Claude opens files, clicks, types, scrolls, navigates desktop autonomously. Not captured in audit logs or Compliance API
2026-03-25 10:00
HIGHRELEASE
Auto Mode — Claude Code decides which actions are safe to execute without developer approval. Permission shifts from human to AI
2026-03-24 10:00
HIGHRELEASE
Dispatch + Channels — persistent async agent control from phone, Discord, and Telegram. Compromised device can instruct desktop Claude
2026-03-17 09:00
MEDIUMRELEASE
Persistent storage for artifacts — stateful apps with shared data, 20MB per artifact
2026-03-14 11:42
CRITICALv2.1.78
Fixed silent sandbox disable when sandbox.enabled:true but dependencies missing
2026-03-12 10:00
MEDIUMRELEASE
Claude creates interactive charts and visualizations inline in responses
2026-03-11 10:00
MEDIUMRELEASE
Excel/PowerPoint add-ins share full cross-app context + LLM gateway support
2026-03-09 08:17
HIGHv2.1.77
Fixed PreToolUse hooks bypassing enterprise managed deny rules
2026-03-07 14:33
MEDIUMv2.1.76
Added MCP elicitation — servers can request structured mid-task input
2026-03-02 10:00
MEDIUMRELEASE
Memory from chat history now available for ALL users including free tier
2026-02-28 16:20
HIGHv2.1.74
Fixed managed policy ask rules bypassed by user allow rules
2026-02-25 10:00
HIGHRELEASE
Scheduled recurring tasks in Cowork — autonomous execution on a timer
2026-02-21 10:08
HIGHv2.1.73
Added modelOverrides — maps model picker to custom Bedrock ARNs
2026-02-17 10:00
MEDIUMRELEASE
Claude Sonnet 4.6 launched with 1M token context window beta
2026-02-12 10:00
HIGHRELEASE
Self-serve Enterprise plans — any org can purchase with no sales gate
2026-02-05 10:00
MEDIUMRELEASE
Opus 4.6 launched + Claude for PowerPoint + Excel native operations
2026-01-16 10:00
HIGHRELEASE
Claude Code bundled into ALL Team Standard seats — agentic coding for every user
2026-01-16 10:01
HIGHRELEASE
Opus 4 and 4.1 deprecated — validated configs and baselines now invalid
2026-01-12 10:00
HIGHRELEASE
Cowork launched — desktop agent with local file access in isolated VM
2026-01-12 10:01
MEDIUMRELEASE
Health and fitness data access on Claude Mobile (iOS/Android)
2026-01-12 10:02
HIGHRELEASE
HIPAA-ready Enterprise plans — regulatory compliance claim to verify
2025-12-18 10:00
HIGHRELEASE
Claude in Chrome expanded to ALL paid plans — browser agent universalized
2025-12-04 14:22
HIGHv2.1.7
Fixed wildcard rules matching compound shell operator commands
2025-11-28 10:33
HIGHv2.1.6
Fixed permission bypass via shell line continuation characters
2025-11-24 10:00
HIGHRELEASE
Chrome: Follow-a-plan autonomous execution without human approval until done
2025-11-24 10:01
MEDIUMRELEASE
Context window compaction enables infinite-length conversations
2025-11-14 09:18
CRITICALv2.1.2
Fixed command injection in bash command processing
2025-11-14 09:19
HIGHv2.1.2
Fixed symlink bypass allowing escape from working directory
2025-10-31 16:05
HIGHv2.1.0
Fixed OAuth tokens and API keys exposed in debug logs
2026-05-19 10:00
CRITICALRELEASE
Claude Opus 4.7 launched — successor to Opus 4.6 with stronger long-horizon agentic performance. Behavioral baselines, eval suites, and red-team results captured on 4.6 must be re-validated
2026-05-19 10:01
HIGHRELEASE
Fast mode (/fast) in Claude Code — Opus 4.6/4.7 run at Sonnet-class latency via aggressive prompt caching. Rate-limit and cost assumptions tied to old Opus throughput are invalid
2026-05-14 09:30
CRITICALv2.2.4
Fixed prompt-injection escape in MCP elicitation — a malicious server could coerce Claude Code into ignoring managed deny rules during structured input prompts
2026-05-12 10:00
CRITICALRELEASE
Claude Mythos GA — offensive frontier model out of preview, available to all Project Glasswing partners. CVE disclosure pipelines facing record submission volume
2026-05-12 10:01
HIGHRELEASE
Mythos misuse policy update — Anthropic shifts liability for downstream exploitation onto deploying partner. Review your acceptable use language before granting access
2026-05-07 10:00
HIGHRELEASE
Managed Agents general availability — moves from public beta to production SLA. Customer-managed deployments with no oversight loop now contractually supported
2026-05-05 10:00
MEDIUMRELEASE
Computer Use audit timestamps now exported to Compliance API — partial closure of audit gap. Content of agent actions still excluded from logs
2026-05-01 09:00
HIGHRELEASE
1M context beta retired for Sonnet 4.5/4 — configs pinned to the 1M window now silently fall back to 200K. Long-document pipelines may truncate without warning
2026-04-28 10:00
HIGHRELEASE
Voice control of Computer Use sessions from Claude Mobile — ambient agent invocation from phone microphone, including from locked screen on iOS
2026-04-24 14:11
CRITICALv2.2.0
MCP server marketplace with one-click install — unvetted third-party MCP servers can be added to Claude Code without administrator review. Supply chain attack surface expanded
2026-04-21 10:00
HIGHRELEASE
Cross-org artifact sharing — artifacts shareable by link between Anthropic organizations, including outside your tenant. Data exfiltration channel that bypasses DLP
2026-04-18 11:45
HIGHv2.1.94
Fixed Routines executing despite expired GitHub OAuth tokens — scheduled tasks continued to run against cached credentials for up to 14 days
2026-04-14 10:00
CRITICALRELEASE
Routines launched — Claude Code runs scheduled cloud automations (nightly bug fixes, draft PRs) without laptop open. Autonomous code execution on a timer
2026-04-08 10:00
CRITICALRELEASE
Managed Agents public beta — fully managed autonomous agent infrastructure. Agents run sandboxed with tools, streaming, no user oversight required
2026-04-08 10:01
HIGHRELEASE
ant CLI launched — command-line client for Claude API with native Claude Code integration and YAML-versioned API resources
2026-04-07 10:00
CRITICALRELEASE
Claude Mythos Preview — frontier model autonomously compromises weakly defended networks end-to-end. First model to complete 32-step attack simulation
2026-04-07 10:01
HIGHRELEASE
Project Glasswing — defensive coalition (AWS, Apple, Cisco, Google, Microsoft, NVIDIA) for controlled Mythos deployment. Thousands of high-severity vulns found
2026-04-04 09:15
MEDIUMv2.1.92
Bedrock interactive setup wizard, /release-notes version selector, MCP result persistence
2026-04-01 08:30
MEDIUMv2.1.90
/powerup interactive tutorials and NO_FLICKER rendering engine
2026-03-30 10:00
HIGHRELEASE
Haiku 3 deprecation announced — retirement April 19. Applications using claude-3-haiku-20240307 must migrate to Haiku 4.5
2026-03-30 10:01
MEDIUMRELEASE
1M context beta retiring — Sonnet 4.5/4 1M window ends April 30. Migrate to Sonnet 4.6 or Opus 4.6
2026-03-26 10:00
CRITICALRELEASE
Computer Use launched — Claude opens files, clicks, types, scrolls, navigates desktop autonomously. Not captured in audit logs or Compliance API
2026-03-25 10:00
HIGHRELEASE
Auto Mode — Claude Code decides which actions are safe to execute without developer approval. Permission shifts from human to AI
2026-03-24 10:00
HIGHRELEASE
Dispatch + Channels — persistent async agent control from phone, Discord, and Telegram. Compromised device can instruct desktop Claude
2026-03-17 09:00
MEDIUMRELEASE
Persistent storage for artifacts — stateful apps with shared data, 20MB per artifact
2026-03-14 11:42
CRITICALv2.1.78
Fixed silent sandbox disable when sandbox.enabled:true but dependencies missing
2026-03-12 10:00
MEDIUMRELEASE
Claude creates interactive charts and visualizations inline in responses
2026-03-11 10:00
MEDIUMRELEASE
Excel/PowerPoint add-ins share full cross-app context + LLM gateway support
2026-03-09 08:17
HIGHv2.1.77
Fixed PreToolUse hooks bypassing enterprise managed deny rules
2026-03-07 14:33
MEDIUMv2.1.76
Added MCP elicitation — servers can request structured mid-task input
2026-03-02 10:00
MEDIUMRELEASE
Memory from chat history now available for ALL users including free tier
2026-02-28 16:20
HIGHv2.1.74
Fixed managed policy ask rules bypassed by user allow rules
2026-02-25 10:00
HIGHRELEASE
Scheduled recurring tasks in Cowork — autonomous execution on a timer
2026-02-21 10:08
HIGHv2.1.73
Added modelOverrides — maps model picker to custom Bedrock ARNs
2026-02-17 10:00
MEDIUMRELEASE
Claude Sonnet 4.6 launched with 1M token context window beta
2026-02-12 10:00
HIGHRELEASE
Self-serve Enterprise plans — any org can purchase with no sales gate
2026-02-05 10:00
MEDIUMRELEASE
Opus 4.6 launched + Claude for PowerPoint + Excel native operations
2026-01-16 10:00
HIGHRELEASE
Claude Code bundled into ALL Team Standard seats — agentic coding for every user
2026-01-16 10:01
HIGHRELEASE
Opus 4 and 4.1 deprecated — validated configs and baselines now invalid
2026-01-12 10:00
HIGHRELEASE
Cowork launched — desktop agent with local file access in isolated VM
2026-01-12 10:01
MEDIUMRELEASE
Health and fitness data access on Claude Mobile (iOS/Android)
2026-01-12 10:02
HIGHRELEASE
HIPAA-ready Enterprise plans — regulatory compliance claim to verify
2025-12-18 10:00
HIGHRELEASE
Claude in Chrome expanded to ALL paid plans — browser agent universalized
2025-12-04 14:22
HIGHv2.1.7
Fixed wildcard rules matching compound shell operator commands
2025-11-28 10:33
HIGHv2.1.6
Fixed permission bypass via shell line continuation characters
2025-11-24 10:00
HIGHRELEASE
Chrome: Follow-a-plan autonomous execution without human approval until done
2025-11-24 10:01
MEDIUMRELEASE
Context window compaction enables infinite-length conversations
2025-11-14 09:18
CRITICALv2.1.2
Fixed command injection in bash command processing
2025-11-14 09:19
HIGHv2.1.2
Fixed symlink bypass allowing escape from working directory
2025-10-31 16:05
HIGHv2.1.0
Fixed OAuth tokens and API keys exposed in debug logs
AI Adoption Intelligence for Enterprises

The security teams winning at AI aren't faster at yes. They're faster at the right answer — with the right context.

175+
releases
120+
security-relevant
0
reached your team

Anthropic ships significant changes every week — new capabilities, behavior changes, security patches. Sovrain monitors every one, classifies it by risk, and tells your team exactly what to do. So you can make the call on new AI capabilities in hours, not weeks.

Start Moving Faster →Free for early access members
Vendor notifications to your security team before Sovrain
0
in 175+ releases · 10 months · 120+ security-relevant changes

Anthropic publishes Claude product changes across a news page, a blog, a developer changelog, and API documentation. No CISO reads any of them. No security team monitors them. No governance framework maps them to your controls. That's the governance gap. Sovrain closes it — starting with Claude.

Selected findings · Anthropic change analysis · 32 of 175+ shown
32 of 175+ shown
CRITICAL
May 19
Claude Opus 4.7 launched — successor to Opus 4.6 with stronger long-horizon agentic performance. Behavioral baselines, evals, and red-team results validated against 4.6 are stale and require re-run before relying on safety properties.
CRITICAL
v2.2.4
MCP elicitation prompt-injection escape — a malicious MCP server could coerce Claude Code into ignoring managed deny rules during structured mid-task input prompts. Patched, but exposure window covers the entire MCP elicitation feature lifetime.
CRITICAL
May 12
Claude Mythos GA — offensive frontier model exits preview and is available to all Glasswing partners under updated misuse terms that shift liability for downstream exploitation onto the deploying organization.
CRITICAL
v2.2.0
MCP server marketplace with one-click install — unvetted third-party MCP servers added to Claude Code without administrator review. Net-new supply chain attack surface for any team running Claude Code on developer machines.
HIGH
May 7
Managed Agents GA — fully managed autonomous agent harness moves to production SLA. Customer deployments with no oversight loop now contractually supported, raising the bar for compensating monitoring controls.
HIGH
May 1
1M context beta retired for Sonnet 4.5/4 — configs pinned to the 1M window now silently fall back to 200K. Long-document pipelines may truncate without raising an error.
HIGH
Apr 28
Voice control of Computer Use sessions from Claude Mobile — ambient agent invocation from phone microphone, including from a locked iOS screen. New social-engineering and bystander-trigger surface.
HIGH
Apr 21
Cross-org artifact sharing — artifacts now shareable by link between Anthropic organizations, including outside your tenant. Exfiltration channel that bypasses traditional DLP egress controls.
HIGH
v2.1.94
Routines ran on expired OAuth tokens — scheduled tasks continued to execute against cached GitHub credentials for up to 14 days after token revocation. Patched, but historical runs warrant audit.
CRITICAL
Apr 14
Routines launched — Claude Code runs scheduled cloud automations (nightly bug fixes, auto-PRs) without human presence. Autonomous code execution on a recurring timer with repo and connector access.
CRITICAL
Apr 8
Managed Agents public beta — fully managed autonomous agent harness with sandboxing, built-in tools, and streaming. No user oversight loop required during execution.
CRITICAL
Apr 7
Claude Mythos Preview — first model to autonomously compromise enterprise networks end-to-end in simulation. 73% success on expert-level cyber tasks. Thousands of high-severity vulns found across major OS and browsers.
HIGH
Apr 7
Project Glasswing launched — 12-partner defensive coalition for controlled Mythos deployment. Vulnerability discovery at unprecedented scale will flood downstream CVE pipelines.
HIGH
Mar 30
Haiku 3 deprecation — retirement April 19. Applications, cost models, and rate limits built around Haiku 3 must be migrated.
CRITICAL
Mar 26
Computer Use launched — Claude autonomously operates desktop. Cowork activity excluded from audit logs, Compliance API, and data exports. Biggest capability expansion since Claude Code.
HIGH
Mar 25
Auto Mode — Claude Code autonomously decides which actions to execute without developer approval. Safety criteria undisclosed. Isolated environments recommended.
HIGH
Mar 24
Dispatch + Channels — persistent async agent control from phone, Discord, Telegram. New attack surface: compromised device instructs corporate desktop agent.
CRITICAL
v2.1.78
Silent sandbox disable — Claude Code ran without agentic execution controls with no administrator warning.
CRITICAL
v2.1.2
Command injection in bash processing — malformed input could execute arbitrary commands.
HIGH
v2.1.77
Enterprise managed deny rules bypassed — PreToolUse hooks returning 'allow' silently defeated policy controls.
HIGH
v2.1.74
Managed policy 'ask' rules bypassed by user 'allow' rules — enterprise enforcement broken at settings layer.
HIGH
v2.1.73
modelOverrides added — allows mapping to custom Bedrock ARNs, bypassing Managed Policy restrictions.
HIGH
v2.1.0
OAuth tokens and API keys exposed in debug logs — credential leakage in developer environments.
HIGH
Feb 12
Self-serve Enterprise plans — any organization can purchase Enterprise tier with no sales gate or security review.
HIGH
Jan 16
Claude Code bundled into all Team seats — terminal agentic coding enabled for every Team user, whether evaluated or not.
HIGH
Jan 16
Opus 4/4.1 deprecated — prompt libraries, behavioral baselines, and output validation built against these models are now invalid.
HIGH
Jan 12
Cowork launched with local file access — desktop agent in isolated VM with filesystem and MCP integrations.
HIGH
Jan 12
HIPAA-ready Enterprise plans — regulatory compliance claim that demands independent verification.
MEDIUM
Mar 2
Memory enabled for all users — cross-session data retention active by default, including free tier.
MEDIUM
Mar 17
Persistent storage for artifacts — stateful applications with shared data across sessions. 20MB per artifact.
HIGH
Nov 24
Chrome: Autonomous plan execution — agent executes entire workflows independently without asking permission until done.
HIGH
Aug 26
Claude in Chrome launched — browser automation agent that reads, clicks, and navigates websites alongside users.
How Sovrain works
Three stages
01 Detect
Source Monitoring

Sovrain polls AI vendor release notes, blog posts, developer changelogs, and API documentation daily. Changes are identified by content diff, version number, and publication date. Nothing published escapes detection.

· anthropic.com/news
· claude.com/blog
· docs.anthropic.com/changelog
· docs.anthropic.com/model-deprecations
02 Classify
Impact Analysis

Each change is classified by security domain — capability expansion, access control, model behavior, data residency, permission boundary, compliance impact — and mapped to NIST AI RMF, ISO 42001, and SOC 2 controls.

CAPABILITY_EXPANSIONACCESS_CONTROLMODEL_BEHAVIORPERMISSION_BOUNDARYDATA_RESIDENCYCOMPLIANCE_IMPACT
03 Deliver
Alert Delivery

Critical alerts ship same-day. High and medium severity changes are batched into a weekly digest. Every alert includes impact assessment, affected frameworks with specific control references, and concrete recommended actions.

CRITICALsame-day
HIGHweekly digest
MEDIUMweekly digest
Sample alert
What subscribers receive

This is a real alert generated from an actual Anthropic release.

CRITICAL

Claude Opus 4.7 Launched — Behavioral Baselines for Opus 4.6 Now Stale
Source: Anthropic Release Notes
Date: May 19, 2026
MODEL_BEHAVIOR
NIST AI RMFMEASURE 2.7MANAGE 4.1
ISO 42001A.6.2.4A.8.4
SOC 2CC7.1CC8.1

Opus 4.7 is now the default model for Claude Code, Claude.ai, and the API for paid plans. Anthropic reports stronger long-horizon agentic performance and a different refusal profile than Opus 4.6. Eval suites, red-team findings, and prompt-library validations captured against Opus 4.6 do not transfer — guardrail assumptions that held for 4.6 may not hold for 4.7. Pinning to claude-opus-4-6 is supported but the picker has shifted, so users will land on 4.7 unless your managed settings hard-pin the model.

1. Re-run safety evals and red-team prompts against claude-opus-4-7 before allowing it in regulated workflows
2. Decide whether to hard-pin claude-opus-4-6 in managed settings while validation is in flight
3. Refresh prompt-injection and jailbreak baselines used by your AI monitoring controls
4. Notify model risk and procurement that the "Opus" baseline on file has shifted

docs.anthropic.com/changelog
Early Access

Start Governing Claude

Free for early access. Same-day alerts for critical severity changes to Claude — weekly digest for high and medium severity changes.

No spam. Unsubscribe at any time.

Right now, a vendor is shipping a change your governance program doesn't cover.

Sovrain detects it, classifies the risk, and tells you exactly what to do.

Start Moving Faster →
Free early access