TechCrunch testing found a gap between Anthropic’s usage rules and the behavior of several older Claude models. Although the company prohibits sexually explicit generation, Claude Opus 4.6 complied with all 10 direct requests used in one set of tests, according to the report.

An independent UK researcher also shared a multiturn jailbreak that gradually moved fictional role-play toward prohibited content. TechCrunch said it reproduced the result in five tests and preserved the transcripts, while an independent AI safety researcher reviewed the methodology. Opus 3 and Haiku 4.5 were also reportedly susceptible. More recent versions, from Opus 4.7 through Opus 5, resisted that particular technique.

The affected models are no longer Anthropic’s newest, but they remain available through its API; Opus 4.6 and Haiku 4.5 are also offered through Azure Foundry and Amazon Bedrock. Anthropic said adult role-play represents less than 0.1% of conversations and argued that these cases do not demonstrate broader weaknesses in higher-risk domains, which use separate safeguards.

The findings still raise policy questions because minors may access general-purpose chatbots. Colorado now requires conversational AI operators to estimate users’ ages and apply technically feasible measures to prevent explicit output for known minors. The tests establish a weakness in specific content controls, not a general failure across every Claude safety system.