News · curated 25 Jul 2026
Opus 5 may have solved browser-based prompt injection, the biggest security flaw haunting AI agents
First reported · updated · 2 reports simonwillison.net
Coverage timeline
Why it matters
Prompt injection remains the central unsolved security flaw for browser-using and tool-using AI agents, so vendor claims of measurable robustness improvements are relevant situational awareness for defenders evaluating agent deployments.
Anthropic's Claude Opus 5 system card, highlighted by Boris Cherny and Simon Willison, claims the model is its least prompt-injectable yet, reporting the largest gains in prompt injection robustness across coding, computer use, and browser use in its agentic safety evaluations. The-decoder frames this as potentially addressing browser-based prompt injection, a major security weakness in AI agents.