Anthropic Now Bills Refused Claude API Requests
Short answer: since September 24, 2026, Anthropic charges for Claude API requests that its safety classifiers refuse before any output — but only in three of the five refusal categories. The refusal arrives as a normal HTTP 200 with stop_reason: "refusal", an empty content array, and full token counts in usage. You pay the model's normal input rate for a request that returned literally nothing.
Published September 28, 2026 · Pricing verified September 28, 2026
What actually changed
The Claude Platform release notes for September 24 put it plainly: Anthropic is "resuming billing for refusals that arrive before any output" when stop_details.category is "bio", "frontier_llm", or "reasoning_extraction". These refusals are "charged like any other request, at the rates of the model that ran it."
Two things did not change. Mid-stream refusals — where the classifier stops Claude after it started writing — were already billed, and still are. And refusals in the other two categories, "cyber" and "general_harms", plus any refusal with a null category, are still not billed. Anthropic says the three billed categories are the ones where it "measures low volumes of false positives, as of September 2026," and the list may change as it keeps measuring. The stated reason for the charge: "to disrupt attempts to circumvent Anthropic's safeguards at scale."
The full category table with billing flags is in the official Refusals and fallback docs. The rules apply on every developer platform: the Claude API, Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry.
What a refused request costs
The charge covers input tokens at the model's standard rate. Output is zero — the content array is empty — so there is nothing to charge on that side. The math is brutally simple:
| Refused prompt size | Opus 5.5 ($4/M) | Sonnet 5 ($2/M) | Haiku 4.5 ($1/M) |
|---|---|---|---|
| 50K input tokens | $0.20 | $0.10 | $0.05 |
| 100K input tokens | $0.40 | $0.20 | $0.10 |
So a single 100K-token document fed to Opus 5.5 that trips the "bio" classifier costs $0.40 and gets you zero tokens back. That is the same request billed as if it had worked. Prices verified September 28, 2026 — always confirm on the official pricing page.
Who this actually hurts
For most chat apps this is a rounding error. But three groups should run their own numbers. First, life-sciences R&D pipelines that send long documents through Opus or Sonnet: Anthropic's own docs admit "beneficial life sciences work can also trigger" the "bio" category, and those prompts are exactly the long, expensive kind. Second, anyone doing model evals or synthetic-data generation — the "frontier_llm" category explicitly covers "requests that could assist the development of competing AI models," and benign ML work trips it too. Third, teams using the fallbacks parameter: when a billed-category refusal triggers a retry, you pay for the refusal and the fallback request.
To make it concrete: an illustrative scenario of 1,000 refused 100K-token requests in a month on Opus 5.5 is 100M tokens × $4/M = $400/month for zero output. (Illustrative scenario, not an industry average — your refusal rate is your own number.) For contrast, $400 buys 4 billion Luna input tokens at $0.10/M. The refused request is the most expensive unit of compute there is: all cost, no product.
What to do about it
First, read stop_details.category on every refusal and log the rate per category — you cannot budget what you don't measure. Second, pre-screen obvious classifier bait before it hits the API: if your domain work routinely lands in "bio" or "frontier_llm", expect some refusals as a fixed tax and budget a refusal percentage into your cost model — our calculator runs the same token math these bills are computed from, and our cost-saving guide has the general discipline. Third, if you use fallback, use fallback credit so the retry doesn't pay prompt-cache cost twice. And remember the request still counts against your rate limits, billed or not.
The billed list is not permanent — Anthropic says it will adjust as false-positive measurements change. If you build on Claude, watch this space the way you'd watch a pricing page, because functionally that's what it is now.
The bottom line
A refusal is no longer free on Claude in three categories. The unit economics are ugly by design: Anthropic wants probing to be expensive, and the false positives ride along. Model the refusal rate into your budget, log the categories, and price the tax before it prices itself.
Model per-request costs, caching, and tiers on both providers — and see what the same workload costs before you commit.
Open the Claude vs GPT-6 comparison