Opus 5.5 hands cyber tasks to Opus 4.8: log the model id

Anthropic says Opus 5.5 re-routes most cybersecurity tasks to Opus 4.8. Keep the model id that served each Sume Format run in your logs to explain odd results.

5 min readSume
All posts

A request that Opus 5.5 treats as cybersecurity work may be answered by a different model. Anthropic's launch post says most cybersecurity tasks will be re-routed to Opus 4.8 (read 2026-10-04). Most video, image and ad work never touches that path, but if a run about, say, a security product demo comes back different from the rest, that is a place to look.

The way to know is to record which model answered, and Sume already gives you a field for part of that.

What does Sume echo back?

Sume's Create a run page says the receipt echoes the model id that ran. That is the orchestrator id Sume used for the run. It is the one you chose, or the default when you left the field out. It does not describe a vendor-side hand-off inside a provider's own service, which Sume's docs do not cover.

What to log per run, from the Create a run docs and Anthropic's post, read 2026-10-04.
FieldWhy log it
Run idJoin to the status and result
model on the receiptWhich orchestrator you asked Sume to use
Your instruction topic tagSpot a pattern across cybersecurity wording
DateModels change; results are dated

How do I use it?

Treat a surprising result as a hypothesis to test, not a verdict.

  • Re-run the same input once with a different model id and compare.
  • Reword the instruction to what you actually want made, since security vocabulary can change handling.
  • Keep the failing run id when you contact support.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume