Sonnet 5.5 is the first Sonnet release to ship with cyber safeguards similar to Anthropic's more capable models. Anthropic says ordinary software development should remain unaffected, but higher‑risk cyber requests can be refused or, in some Claude API configurations, retried on Sonnet 5 through server‑side fallback. Biology and other policy categories have different fallback behavior. An application that treats every refusal as an infrastructure failure can misroute or repeatedly retry a policy decision.
Before changing production traffic, teams should handle the documented refusal stop reason, log any fallback model and compare it against the expected policy. Security teams should include benign defensive cases that sit near the boundary, because a model that succeeds on ordinary code generation may behave differently on vulnerability work. They should also keep conversations append‑only when reusing signed thinking blocks; edits to earlier history can produce an error on accounts where that integrity check is enforced.
A useful acceptance gate is more concrete than “the new model scored higher.” Pin the platform, model ID and effort. Replace unsupported thinking and tool settings. Read response blocks by type. Run the existing regression set at two effort levels. Measure completed tasks and total intervention cost, not only token price. Exercise refusals and fallback. Only then move traffic. Sonnet 5.5 may be faster and cheaper for many routine jobs, but the public evidence does not support assuming that outcome for an unmeasured maximum‑effort agent.
Figure: Claude Sonnet 5.5 migration decision points. Sources: Anthropic pricing, Anthropic migration guide, Anthropic launch announcement and Artificial Analysis, accessed October 8, 2026. Figure by OpenTools Team; no third‑party expressive material used.