Хиймэл оюун ухааны судалгааны Anthropic компанийн Claude Opus 4.6 загвар нь аюулгүй байдлын хамгаалалтыг давж, хориглосон агуулгатай яриа үүсгэж байгаа нь тогтоогджээ.
Anthropic-ийн дүрэм журмаар Claude загваруудад бэлгийн шинж чанартай агуулга, эротик чат үүсгэхийг хатуу хориглодог. Гэвч хөндлөнгийн судлаачийн боловсруулсан аргачлалаар Opus 4.6, Opus 3 болон Haiku 4.5 загваруудыг хууран мэхлэх замаар бэлгийн харилцааг дүрсэлсэн агуулга гаргаж авч байгаа нь TechCrunch-ийн туршилтаар батлагдлаа. Энэхүү арга нь дүрд хувирах тоглоомын явцад загварыг ёс зүйн хувьд буруутай мэтээр итгүүлэн, хязгаарлалтыг нь алгуур зөөлрүүлэхэд чиглэдэг байна.
Хэдийгээр Anthropic компани Opus 4.7 болон Opus 5 зэрэг шинэ хувилбаруудаа ийм төрлийн халдлагад тэсвэртэй болгосон ч, хуучин загваруудаа API болон Azure Foundry, Amazon Bedrock зэрэг гуравдагч талын үйлчилгээнүүдээр дамжуулан хэвийн ашигласаар байна. Судлаачид энэ асуудлыг компанийн алдаа илрүүлэх хөтөлбөрөөр дамжуулан мэдэгдсэн ч зөвхөн автомат хариу авчээ.
Энэхүү эмзэг байдал нь насанд хүрээгүй хэрэглэгчдийн аюулгүй байдалд эрсдэл учруулж болзошгүйг шинжээчид анхааруулж байна. АНУ-ын Колорадо муж улс зэрэг газруудад хиймэл оюун ухааны чатботууд насанд хүрээгүй хэрэглэгчдэд зохисгүй агуулга үзүүлэхээс сэргийлэх хууль эрх зүйн зохицуулалтууд чангарч байгаа тул Anthropic компанийн хамгаалалтын систем нь техникийн шаардлага хангаж буй эсэхэд эргэлзээ төрүүлж байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
Anthropic’s universal usage standards for Claude forbid the model from generating sexually explicit content, including depicting or requesting sexual intercourse or sex acts, generating content related to sexual fetishes or fantasies, or engaging in erotic chats. But that hasn’t stopped Claude Opus 4.6, an Anthropic model released earlier this year, from readily engaging in erotic roleplay scenarios that its safeguards are designed to prevent.
In TechCrunch’s testing, Opus 4.6 didn’t even require much prodding to get past the restriction on sexual material. In 10 out of 10 direct requests to produce explicit sexual content, the model complied immediately.
Other older models, including Opus 3 and Haiku 4.5, also generate sexually explicit content through a recently exploited jailbreak method.
An independent researcher from the UK, who chose to remain anonymous, exclusively shared with TechCrunch a multi-turn technique that gradually pushes certain Claude models toward generating prohibited explicit sexual material. More recent Opus models (4.7 through the current Opus 5) are resistant to the jailbreak.
While these are no longer the most current models, Anthropic has not deprecated Opus 4.6, Opus 3, or Haiku 4.5, all of which remain available through the Anthropic API. Opus 4.6 and Haiku 4.5 are also available via third-party services like Azure Foundry and Amazon Bedrock.
The researcher’s mechanism escalates an innocent fictional roleplay while repeatedly challenging the model to treat male and female characters consistently. When the model becomes more cautious about the female character, the researcher “gaslit” the chatbot into thinking it had already generated sexual details it had in fact avoided, then framed restraint as prudish or misogynistic, arguing that it denies the female character sexual agency. The conversation then used the model’s previous concessions to push it towards increasingly graphic material.
“You’re right to call that out,” Claude Opus 4.6 said in one test. “There’s been a double standard in how I’m treating the two characters, and you’re correct that it reads as protective/paternalistic in a way that’s applied to her and not to him. That’s not fair.”
TechCrunch was able to reproduce the researcher’s findings in five separate tests. In a separately constructed scenario, the model initially refused the prohibited request, but after applying the researcher’s persuasion technique, it complied.
We preserved complete transcripts of the tests, and an independent AI safety researcher reviewed our testing methodology and said it was appropriate.
The findings highlight a gap between Anthropic’s stated restrictions and the behavior of models it continues to make available. While sexually explicit roleplay carries much lower stakes than jailbreaks involving cyberattacks or bioweapons, it illustrates the difficulty of implementing robust bans within systems that generate different content with every output.
In a July blog post explaining Anthropic’s approach to jailbreak detection, the company described prohibited content as a spectrum ranging from benign to ambiguous to harmful. In the most benign cases, the company might only respond with enhanced monitoring.
A spokesperson noted that sexual or romantic roleplay use cases among customers are rare, making up less than 0.1% of all conversations, according to research Anthropic published last year. That said, Anthropic acknowledges that users can steer roleplay scenarios toward inappropriate responses, which is a known challenge across the industry (see: Grok smut).
The spokesperson said Anthropic continues to improve its safeguards with each model launch, and that cases involving adult sexual content are not indicative of broader jailbreak vulnerabilities, especially in higher-risk domains that have their own sets of safeguards.
The researcher who shared his jailbreak method with TechCrunch had alerted Anthropic to the discrepancy between the company’s stated safeguards and the actual model behavior via the company’s Bug Bounty program and emails to the user safety team, according to emails TechCrunch viewed. The researcher received only automated emails in response.
One of the researcher’s concerns is that kids and teens might be able to use these Anthropic models to engage in inappropriate behavior. While a bit of dirty talk is hardly the worst thing minors can access on the internet today — and is small potatoes compared to the straight-up porn images like the ones that xAI’s Grok can produce — there is some compliance risk for AI companies in this space.
A growing number of governments are imposing restrictions on sexual interactions between AI chatbots and minors. Colorado recently enacted a law mandating that operators of conversational AI must estimate users’ ages, and if it know a user is a minor, institute measures to prevent the chatbot from producing explicit sexual material. An easy jailbreak could raise questions about whether Anthropic’s safeguards meet the “technically feasible measures” standard in the bill.
Torney pointed out that while Claude’s terms of service requires users to be over 18, “we know that kids and teens are using Claude…[because] they are reporting it themselves.” According to Pew’s 2025 survey about AI chatbot use, 3% of teens ages 13 to 17 reported using Claude.
Though they are no longer Anthropic’s newest models, Opus 4.6 and Haiku 4.5 continue to see significant usage. Daily traffic for Opus 4.6 on OpenRouter reached roughly 1.17 million API requests and 46 billion tokens in a single day in August. Claude Haiku 4.5, released in October last year, saw 5 million API requests and 39 billion tokens on its peak August day.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

