All posts
Architecture Published 15 min

Copilot local sandbox GA and Claude Haiku 5.5: the October 7 agent ops board

On October 7, 2026 GitHub made Copilot local sandboxing generally available, Anthropic shipped Claude Haiku 5.5, and Copilot added Haiku plus Ollama model discovery. This guide shows how enterprises should harden agent tool execution and retier high-volume subagent lanes.

Jigar JoshiJigar JoshiAgentic AI Architect and Consultant
In this post (8 sections)

Introduction

Late September filled the Copilot model picker with GPT-6 Sol, GPT-6 Luna, Opus 5.5, and Grok 4.7. October 7 answers a different question: how much autonomy those models get on a developer laptop, and which SKU should run the high-volume subagent fan-out. Local sandboxing moves from preview posture to a general-availability control plane. Haiku 5.5 gives teams a priced worker that Anthropic and GitHub both position for subagents rather than as a planner replacement.

Primary sources: local sandboxing GA, Haiku 5.5 in Copilot, local models in Copilot CLI, Claude Haiku 5.5, and Copilot agent metrics IDE fix. Adjacent routing: GPT-6 Sol, Opus 5.5, Grok 4.7 and Copilot computer use.

What local sandboxing GA changes

GitHub’s changelog is explicit: tools and commands initiated by Copilot run with restricted access to the filesystem, network, credentials, and other system capabilities under developer or organization policy. MXC translates one policy into native OS controls on Windows, macOS, and Linux. Local MCP and language servers can sit inside that boundary where supported. Model choice and tool isolation stay separate: sandbox policy applies regardless of which model Copilot uses.

Copilot agent control surfaces after October 7, 2026
SurfaceStatusOwner action
Local sandboxing (CLI, app, Agent Host)Generally availableRequire via enterprise-managed settings; document allowed paths and network egress
Computer use (CLI, app)Public preview (Oct 1)Keep off by default in managed fleets; approval before GUI control
Cloud / remote sandboxesExisting productKeep for CI and shared runners; do not confuse with local MXC policy
Agent usage metrics (VS Code 1.139+)Attribution fix rolling outEnforce minimum IDE versions so agent LOC is not silently dropped

Claude Haiku 5.5 as the volume worker

Anthropic’s Haiku 5.5 announcement targets the work Opus and Sonnet should not monopolize: summaries, compaction, classification, database queries, and coding subagents. Official list pricing under 100K prompt tokens is $0.10 input, $0.50 output, and $0.01 cache reads per million tokens. Anthropic reports roughly 75% lower average run cost versus Haiku 4.5 after tokenizer and usage mix, and halves Sonnet 5.5 cache reads to $0.10 so many agentic Sonnet jobs land about 20% cheaper. Haiku 5.5 adds adjustable effort; Anthropic still points Terminal-Bench-class coding at Sonnet 5.5 or Opus 5.5.

Official Haiku 5.5 list rates (per 1M tokens)
Token typePrompts ≤100KPrompts >100K
Input$0.10$0.50
Output$0.50$2.50
Cache reads$0.01$0.05
Cache writes$0.125$0.625

GitHub’s Copilot changelog adds the same model across Pro through Enterprise surfaces, including cloud agent and CLI, under usage-based provider pricing. Business and Enterprise admins control enablement through Copilot model policy. Early Copilot testing cited by GitHub said Haiku 5.5 matched Sonnet 5 on many coding tasks while using fewer tokens and steps; treat that as a vendor signal and re-run the org harness before changing defaults.

Local models in Copilot CLI

CLI 1.0.94-0 exposes `/model` discovery against a running Ollama instance. Operators still install Ollama and pull weights themselves. Models must support tool calling and streaming. Choosing a local model does not flip offline mode; `COPILOT_OFFLINE=true` remains a separate switch, and GitHub notes that a remote provider can still receive prompts even when offline mode is set if misconfigured. Pair local models with required local sandboxing so a tool-calling local worker cannot roam the host.

What this means for developers

  • Turn on local sandboxing in CLI and Agent Host before expanding autonomous tool loops.
  • Route compaction, triage, and fan-out subagents to `claude-haiku-5-5`; keep Opus 5.5 or Sonnet 5.5 on merge-critical planning.
  • Update VS Code to 1.139+ so agent activity returns to usage metrics.
  • If piloting Ollama, verify tool calling and streaming, then confirm Add in `/model` without assuming offline privacy.
  • Re-run the sandbox-escape checklist after MXC policies change path or network allowlists.

What this means for businesses

  • Local sandboxing GA is the moment to make agent tool isolation a required control, not an optional developer preference.
  • Haiku 5.5 plus cheaper Sonnet cache reads change the cost board for multi-agent graphs that call a worker ten times per planner turn.
  • Agent metrics were undercounted during the SDK transition. Do not make headcount or license decisions on broken agent LOC until fleets are on fixed IDE versions.
  • Computer use remains preview. Sandbox GA does not equal desktop control approval.

Ops checklist

  1. 01
    Require local sandboxing
    Enterprise-managed Copilot settings: filesystem, network, and credential policies that developers cannot weaken.
  2. 02
    Enable Haiku 5.5 in model policy
    Name an owner, spend cap, and default subagent mapping. Leave planner SKUs unchanged until evals finish.
  3. 03
    Pin IDE minimums
    VS Code 1.139.0+ now; track Visual Studio 18.12 and JetBrains/Eclipse/Xcode plugin dates through November.
  4. 04
    Pilot local models narrowly
    One team, one Ollama model with tool calling, sandbox required, offline mode documented separately.
  5. 05
    Re-score the routing board
    Compare Haiku 5.5 worker cost and quality against Luna, Sonnet 5.5, and GPT-6.1 Sol on the same harness.

Conclusion

October 7 did not retire frontier planners. It made laptop agent autonomy enforceable and made the cheap worker lane credible again. Teams that enable Haiku without sandboxing buy speed without a boundary. Teams that enable sandboxing without retiering volume work leave money on Sonnet and Opus. Do both, measure agent metrics on fixed IDEs, and keep computer use gated.

Sources: github.blog ; github.blog — 2026 10 07 claude haiku 5 5 in github copilot ; github.blog ; Anthropic ; github.blog

The weekly take

Agentic AI patterns, delivered Thursdays

What I am shipping, watching, and pruning out of client stacks each week. One email. No fluff.

Shipping an agentic AI project this quarter?
Book a 30-min consult
Frequently asked

Questions readers ask about this post

Share this post
LinkedIn Facebook WhatsApp