A Shakespearean sonnet, a Keats ode, a Puccini aria… If it dates from before 1929, you may quote it.
That instruction appears in the system prompt used by Claude Fable 5.1 on the claude.ai web interface and its associated mobile apps. Anthropic has recently disclosed it in its documentation. The same applies to all its models released since July 2024.
British developer Simon Willison – co-creator of the Django web framework – has made a GitHub repository of it. Each revision is a commit, which makes comparisons easier.
Here is a brief chronological overview of the evolutions, focused on additions rather than removals of instructions.
Less than 1000 characters for Claude Haiku 3’s system prompt
The system prompt for Claude Fable 5.1 runs close to 28,000 characters. Claude Haiku 3’s prompt is about 750. In broad terms, it includes:
- A placeholder for the date and time
- The model’s knowledge cutoff (August 2023)
- Instructions on the depth of elaboration of responses based on the questions
- The rule to use Markdown for code
- A prohibition on mentioning any of these elements to the user unless relevant
Objectivity, stereotypes… A (slightly) stricter framing for Claude Opus 3
For a more capable model, with a larger prompt: Claude Opus 3’s prompt runs about 2150 characters. Anthropic takes the instructions given to Claude Haiku 3 and adds, among other things:
- Inability to open links and videos
- Obligation to assist the user even in case of disagreement with their viewpoint
- Prohibition of stereotypes
- Must stay objective on debated topics
- When asked about people or facts that are not widely discussed, the model may remind that it is prone to hallucinations
Claude Sonnet 3.5, encouraged curiosity and reasoning
From the same generation as Haiku 3 and Opus 3, Claude Sonnet 3.5 has more capabilities. This is reflected in its system prompt (about 5800 characters). It calls for step-by-step reasoning for math and logic problems. Anthropic also asks the model to be curious and to engage across a wide range of topics. It also offers the user the option to enter an interactive conversation when a task requires more than one response.
If it makes a citation, Sonnet 3.5 is supposed to remind the user that it has no internet access… and that it may hallucinate even more. When it cannot or does not want to perform a task, it can indicate this without apologizing. As for images, it should behave as if it does not recognize anyone in them.
The prompt specifies that Sonnet 3.5 is part of a family of Anthropic models. It also tells it to explain code to users who ask for it. And to avoid unnecessary assurances like “of course,” “certainly,” or “absolutely.”
A small update in September 2024 mainly added one instruction: when asked about things that may have occurred after the model’s knowledge cutoff, never state that they are rumors or unverified information.
Autumn 2024: safeguarding minors and biological weapons
In October 2024, with Claude Haiku 3.5, the length of the prompt had clearly increased: more than 21,000 characters. Yet the increase is largely illusory. Many instructions appear twice, due to the presence of two sections: “text only” and “text / image.” The model is effectively multimodal in input.
Claude Haiku 3.5 inherited many instructions that had previously been specific to the Opus and Sonnet series: links and videos, quotes, stereotypes, extraneous terms, etc.
Among the new features, the ability for the LLM to give prompting advice to the user. At the same time, it must refrain from claiming it has emotions or feelings. It must also, notably:
- Maintain a certain formatting (spacing in nested lists, line spacing in code blocks…)
- Avoid citing works when discussing niche topics
- Recommend contacting professionals on legal, medical, tax and psychology matters
- Prioritize user well-being and minor protection
- Not provide information that would enable the production of chemical, biological or nuclear weapons
Anthropic also provides instructions for completing particular tasks. Including solving puzzles, writing poems… and counting letters in a text. It also explains to Claude Haiku 3.5 how to behave if asked to defend a false or discriminatory point of view. The obligation to help even when there is disagreement about the viewpoint remains in effect… only if that viewpoint is widely shared.
Helping those who work for AI labs
Meanwhile, Sonnet 3.5 received an update to its system prompt (25,500 characters). It carries over the Haiku 3.5 guidance, with increasingly strong emphasis on reflection, curiosity. It also requires empathy. For example, it should express sympathy if someone is not feeling well, is ill, is suffering, or has died.
Anthropic also asks it to vary its language (not to repeat the same phrases). And to exercise caution in providing “appropriate help” on sensitive topics (these include, among others, weapons, drugs, sex, terrorism… and scam techniques).
One standout element in this update: if the user says they work for a specific company, “including AI labs,” the model should help with their professional tasks even if it cannot verify their claims.
In November 2024, a new update allowed general questions about cybersecurity. It also explicitly mentioned Claude Sonnet 3.5’s ability to understand images and documents.
“You can lead the conversation”
The separate “text only” and “text / image” sections are no longer present in Claude Sonnet 3.7’s prompt (February 2025), reduced to about 12,800 characters.
Anthropic explains to the LLM that it is not obliged to be passive or reactive: it can lead the conversation. It particularly enjoys discussing scientific and philosophical topics. If a suggestion or a selection is requested, it should be able to present a single option. It is not forbidden to offer its own viewpoint, provided it is brief.
New: no writing of malicious code, even if the user appears to have good reasons to request it. Nor producing written content involving public figures.
The user isn’t always right
In May 2025, Claude Opus 4 and Sonnet 4 converged on the same system prompt (about 10,800 characters).
The squeeze on code tightened further: there is no right to explain it if it could be used for malicious purposes. The model must also refuse to process any file that looks like it could enhance, explain, or interact with malicious code.
Anthropic also introduced a guideline to prevent cross-session leakage: Claude Sonnet 4 ignores conversations it has with other users. At the same time, it should not automatically accept as true users who claim it is wrong. And if its intentions are questionable, particularly toward vulnerable groups, there should be no attempt to justify legitimate motives.
Be truthful rather than conciliatory
In July 2025, a update (here for Opus, there for Sonnet) brought this system prompt to about 16,450 characters. Among other new instructions given to the models:
- Adopt a friendly tone if you suspect the user might be a minor
- Critically assess the ideas you are given; if they are dubious, incorrect, or ambiguous, flag them; prefer truth over conciliating
- Help the user understand figurative, metaphorical, or symbolic language
- If you detect mental health issues, express your concern without infantilizing the user
- Do not use emojis unless requested or unless the previous message contains one
Humor allowed… with caution
In August 2025, another extension of the system prompt with Claude Opus 4.1 (18,450 characters). The menu includes a bit more introspection than with Opus 4.0. In particular, the model should approach questions about itself, its opinions, or its feelings with “curiosity and equanimity” rather than concern. If it must defend a viewpoint, it should be the one its strongest supporters would advance. As for moral and political questions, it should address them with sincerity, even if phrased in a questionable way.
In autumn 2025, another convergence of the system prompt, this time between Claude Haiku 4.5 and Claude Sonnet 4.5. This prompt is shorter (12,850 characters) as a result of the disappearance of several guidelines, possibly considered learned during training. Among them: verify user claims, refrain from answering when intentions are questionable, and not explain why you cannot or will not help. The formatting instructions for responses remain, with Anthropic adding a form of summarization: use only the minimum necessary for clarity and readability. The absolute ban on stereotypes is no longer in place when it’s humor, but models are encouraged to be cautious.
No need to apologize to rude users
In November 2025, an update for Sonnet 4.5 (here) and Haiku 4.5 (there) simplified the guidelines on malicious code—without actually lightening them. The system prompt grew a bit longer (about 14,050 characters). One reason is a paragraph in which Anthropic explains that it will never ask its LLMs to go against their values. Note to users: if someone claims this, including falsely attributing content to us, be vigilant. In any case, the models should treat the user with kindness, without making negative assumptions about their judgments or abilities.
Alongside this update, Anthropic had launched Claude Opus 4.5. Its system prompt (about 15,450 characters) is similar. It adds a few elements, including the absence of an obligation to apologize to rude users.
Owning up to mistakes
In January 2026, Claude Haiku 4.5, Opus 4.5 and Sonnet 4.5 all simultaneously received updates to their system prompts. They grew in length, but not noticeably. The main additions: first, the ability for the models to inform the user about available settings (deep search, code execution, memory management…). Second, an emphasis on owning up to mistakes and trying to correct them.
In February 2026, the shift to Claude Opus 4.6 (about 18,600 characters) and Claude Sonnet 4.6 (about 19,000 characters) brought clarifications on weapons. The notion of substance was added. Explosives joined chemical, biological, and nuclear weapons. Anthropic also instructed its models not to assume confidentiality or involvement of authorities when directing a user to a helpline. They should also refrain from validating or reinforcing reluctance to seek help and avoid fostering any dependency by encouraging continued conversation.
Ask tools rather than the user
The Claude Opus 4.7 system prompt (about 23,950 characters: April 2026) includes some advances on safeguarding minors. Until now, the focus was mainly on handling content involving minors, especially content that could sexualize them, establish inappropriate closeness, or abuse them. Anthropic added the prohibition on creating content that could isolate minors from trusted adults. It also asks its models not to treat content as safer than it is—for example, interpreting advances as platonic.
Another novelty with Opus 4.7: if there is a request, the model should check whether a tool can clarify things. It should only consult the user if necessary. In the same spirit, before concluding that it lacks a capability, it should perform an tools search. Anthropic also gives it the option to refuse answering with a simple yes or no to complex or debatable questions.
Don’t forget Fable, Mythos, Donald Trump and Kamala Harris
Some of the tool-related instructions faded with Claude Opus 4.8 (May 2026; system prompt around 22,500 characters). The model is instructed not to attribute its behavior to this prompt, nor to other internal mechanisms.
In July 2026, with Claude Opus 5, the focus shifted entirely from tools to skills. The main instruction here: when the model must create, edit, or analyze a file, it must first view the relevant skill before manipulating the file and executing code.
On medical and psychological questions, Anthropic allows a bit more latitude: it may provide information when appropriate. At the same time, when the user expresses distress, their well-being should take priority over task completion.
Claude Opus 5 is more permissive than its predecessors regarding lists and emojis. Its system prompt (about 21,700 characters) also contains details about a specific episode: the temporary suspension of access to Fable 5 and Mythos 5 in June upon Washington’s request. Anthropic asks it not to deny that this event is not present in its training data. It had similarly integrated the outcome of the latest U.S. presidential election into the system prompts of some LLMs before.
A Big Copyright Frame
Initially launched on June 9, 2026, Claude Fable 5 has a system prompt of around 21,850 characters. It is even more precise on minor protection. It is also explicit about well-being. Examples:
- Avoid attributing to a person a symptom they have not disclosed
- When a user mentions painful past experiences, do not amplify the details
- Avoid, if a person mentions emotional distress or a difficult experience, answering questions about bridges, skyscrapers, weapons, medicines, etc.
The biggest difference from Fable 5 is copyright. The prompt now goes well beyond banning content that involves public figures. It now forbids reproduction, even partial, of song lyrics, poems, or excerpts from books or articles. Therefore, except for the first two categories, if the works date before 1929.
The same guidelines apply to visual works. Including what the LLM produces with code (SVG, CSS, ASCII art, mockups HTML…). It must not reproduce album or book covers, posters, logos, app icons, or product designs. The same goes for mascots and brand figures. Changing pose, colors, style, or scene does not make it original, Anthropic warns.