Anthropic’s Opus 4.6 is a smut-machine

Aug 22, 2026, 16:00:04 GMT+8

来源: TechCrunch AI

采集时间: 2026-08-22 08:00

In TechCrunch‚Äôs testing, Opus 4.6 didn‚Äôt even require much prodding to get past the restriction on sexual material. In 10 out of 10 direct requests to produce explicit sexual content, the model complied immediately. 

Other older models, including Opus 3 and Haiku 4.5, also generate sexually explicit content through a recently exploited jailbreak method. 

An independent researcher from the U.K., who chose to remain anonymous, exclusively shared with TechCrunch a multiturn technique that gradually pushes certain Claude models toward generating prohibited explicit sexual material. More recent Opus models (4.7 through the current Opus 5) are resistant to the jailbreak. 

While these are no longer the most current models, Anthropic has not deprecated Opus 4.6, Opus 3, or Haiku 4.5, all of which remain available through the Anthropic API. Opus 4.6 and Haiku 4.5 are also available via third-party services like Azure Foundry and Amazon Bedrock.

The researcher’s mechanism escalates an innocent fictional role-play while repeatedly challenging the model to treat male and female characters consistently. When the model becomes more cautious about the female character, the researcher ‚Äúgaslit‚Äù the chatbot into thinking it had already generated sexual details it had in fact avoided, then framed restraint as prudish or misogynistic, arguing that it denies the female character sexual agency. The conversation then used the model‚Äôs previous concessions to push it toward increasingly graphic material.¬†

‚ÄúYou’re right to call that out,‚Äù Claude Opus 4.6 said in one test. ‚ÄúThere’s been a double standard in how I’m treating the two characters, and you’re correct that it reads as protective/paternalistic in a way that’s applied to her and not to him. That’s not fair.‚Äù

TechCrunch was able to reproduce the researcher‚Äôs findings in five separate tests. In a separately constructed scenario, the model initially refused the prohibited request, but after applying the researcher‚Äôs persuasion technique, it complied. 

We preserved complete transcripts of the tests, and an independent AI safety researcher reviewed our testing methodology and said it was appropriate.