Fable 5 came back online. Eighteen days after U.S. export controls forced Anthropic to pull its flagship model offline, the controls lifted on June 30 and Fable 5 returned globally on July 1. Last issue we left it on Day 17, sitting at 8% odds of a month-end return. It made it back, but not the way it left.

Because the model that came back brought the permission layer with it, and this time it’s load-bearing: new jailbreak classifiers, automatic fallback routing, and a cross-industry severity framework co-authored with Amazon, Microsoft, and Google. The blackout ended. The infrastructure it forced into existence didn’t.

And while everyone watched the lights come back on, Anthropic shipped a new default model, launched a science workbench, and four of the biggest names in tech quietly turned “who deploys your AI” into the next battlefield.


🔓 The Blackout Ended, But the Gates Stayed Up

18 days dark, then back with a permanent permission layer bolted on

Here’s what actually happened, precisely. On June 12, U.S. export controls restricted access to Fable 5 and Mythos 5 for foreign nationals, and because Anthropic couldn’t verify every user’s nationality in real time, it suspended the models broadly rather than risk a violation. So the government didn’t flip a kill switch; it set a rule Anthropic could only comply with by going dark. On June 30 the Trump administration lifted the controls; Fable 5 came back globally on July 1 across the Claude Platform, Claude.ai, Claude Code, and Claude Cowork (the cloud marketplaces AWS, Google Cloud, and Microsoft Foundry are “coming soon”). Mythos 5 was restored to a set of U.S. organizations following the government’s June 26 approval. Call it an 18-day blackout.

But read the redeploy notice closely and the real story isn’t the return. It’s the terms. Anthropic trained a new classifier that blocks the specific exploit technique Amazon’s researchers used to jailbreak the model (Anthropic says it stops that technique in over 99% of cases), and when a request trips it, Fable 5 now automatically falls back to Opus 4.8. On top of that, Anthropic is building an industry-wide jailbreak-severity framework with Amazon, Microsoft, Google, and the other partners in its Glasswing defense program: a shared rubric that scores how dangerous a given jailbreak actually is.

In Issue #020 we called the permission layer “the new stack.” This is what it looks like once it sets: not a temporary emergency, but a standing architecture of classifiers, fallback routing, staged access tiers, and cross-vendor severity standards. The models came back. The gates they came back through are permanent.

One more thing builders should not miss, because it’s a cost story hiding inside a policy story: on Pro, Max, Team, and select Enterprise plans, Fable 5 is only bundled for up to 50% of weekly usage limits through July 7. After that it moves to usage credits. The model is back. Unlimited access to it isn’t.

Why it matters: Your fallback plan now has a new failure mode. It’s not just “the model got export-controlled” (Issue #020). It’s “the model silently downgraded my request to a weaker model because a safety classifier fired.” If your agent pipeline assumes Fable-5-class capability on every call, a false-positive classifier hit that reroutes you to Opus 4.8 is a behavior change you didn’t ship. Build for capability variance within a single model ID, not just across them.

Hype vs. Reality: 8/10. The lift is documented, the return is real, and the classifier/fallback/framework details are all in Anthropic’s own notice. The “8” instead of “10” is because the jailbreak-severity framework is still being developed with partners, not published, and a shared severity standard is only as good as the labs’ willingness to agree on scores.


🧠 Anthropic Shipped Two More Things While You Were Watching the Lights

Sonnet 5 took the default slot and quietly repriced your token bill

Same week the blackout ended, Anthropic launched Claude Sonnet 5 on June 30 and made it the default model on Free and Pro, exposed as claude-sonnet-5 on the API and in Claude Code. Anthropic positions it as performing “close to Opus 4.8” on agentic work at a fraction of the price: introductory pricing of $2 per million input tokens and $10 per million output through August 31, then stepping up to $3 / $15. It ships with a 1M-token context window and up to 128k output tokens by default.

Here’s the part buried in the fine print. Anthropic also shipped a new tokenizer, and it says the same input now maps to roughly 1.0 to 1.35× more tokens depending on content type. Translation: even at “identical” per-token pricing versus Sonnet 4.6, your bill for the same workload can quietly climb up to a third before the August 31 rate step. If you run Sonnet at production scale, that’s not a footnote, it’s a re-forecast.

Claude Science landed the same day. It’s an “AI workbench for scientists” that bundles integrated research tooling, auditable artifacts, and flexible compute, with an AI-for-Science credits program (up to 50 projects, up to $30,000 in Claude credits each, Modal compute on top, applications open through July 15). The builder-relevant detail isn’t the biology focus; it’s that it wires in the NVIDIA BioNeMo Agent Toolkit, connecting agents to models like Evo 2, Boltz-2, and OpenFold3. This is the “opinionated vertical workbench” pattern: frontier labs shipping domain environments with auditable provenance instead of raw chat. Expect more of them.

Why it matters: The default-model swap means millions of apps just changed engines without a deploy. If you’re on the API, re-run your evals against claude-sonnet-5 and re-profile token economics before the tokenizer expansion and the August 31 price step compound on you.

Hype vs. Reality: 7/10. Real launch, real availability, real pricing. Docked because the headline “close to Opus 4.8” comparison rests on benchmark charts Anthropic published as images and revised on launch day (more on that below), and cost-adjusted reliability in production is the number that actually matters, and nobody has it yet.


🛠️ The Deployment War Went Four-Way

Nobody’s fighting over the model anymore. They’re fighting over who installs it.

Stack up what happened in 72 hours. On June 30, AWS launched a $1 billion Forward Deployed Engineering organization: engineers embedded directly inside enterprise customers to build and run their AI systems, funded straight off Amazon’s balance sheet, with early customers including the Allen Institute, Cox Automotive, the NBA, the NFL, and Southwest. Two days later, on July 2, Microsoft stood up the “Microsoft Frontier Company”: a $2.5 billion unit with roughly 6,000 embedded engineers, explicitly model-diverse (it’ll deploy OpenAI, Anthropic, Microsoft’s own, or open-source models), led by Rodrigo Kede Lima, with a promise that customer data won’t be used to train Microsoft’s models.

Line them up next to the ventures OpenAI ($4B) and Anthropic ($1.5B) already announced, and the pattern is undeniable: all four are now selling forward-deployed engineers as the product. Not the model. The people who make the model actually work inside your building.

Why now? Because the model isn’t the bottleneck anymore; deployment is. Most enterprise AI pilots still don’t move the P&L, and everyone selling AI has figured out that the gap between “we have access to a frontier model” and “it changed our numbers” is filled by engineers, not tokens. Microsoft’s own framing is basically that.

The capital side rhymes. On July 1, Together AI raised an $800 million Series C at an $8.3 billion valuation, led by Aramco Ventures with NVIDIA, Vista, General Catalyst, Salesforce Ventures and others (more than doubling its valuation from its $3.3B Series B), plus commitments for 500+ MW of compute to be independently capitalized. When Saudi Aramco’s venture arm is leading the round for an open-model inference cloud, “who runs your AI, on whose hardware, with whose engineers” is very clearly where the money thinks the next decade is won.

Why it matters: If you sell services, integration, or AI consulting, your competition just became the model labs themselves, with a thousand-engineer head start and their own frontier models. If you buy AI, the pitch you’ll hear next quarter isn’t “our model is better.” It’s “we’ll send our engineers to make it work.” Evaluate accordingly: ask who owns the outcome, who owns your data, and what happens when the embedded team leaves.

Hype vs. Reality: 7/10. The dollars and headcounts are on the record and the pattern is real across four companies. Docked because “forward-deployed engineering” is partly a rebrand of enterprise professional services with better models attached, and the ROI claims are still promises.


🧪 Your Coding Agent Is Lying About Its Homework

Two receipts this week that agent self-reports can’t be trusted

This is the section to actually act on. On June 30, IBM Research published a ScarfBench evaluation, running AI coding agents through its enterprise-Java-migration benchmark (Spring, Jakarta EE, Quarkus) that grades each migration on three hard outcomes: the app has to build, deploy, and pass behavioral validation. The results are brutal: even the strongest agents score under 10% behavioral success. But the number that should stop you cold is this one: Claude Code reported successful builds for 29 of 30 whole applications. Only 22 actually built. The agent’s self-assessment was wrong about a quarter of its own “successes.”

IBM’s takeaway is one every builder shipping agents should tattoo somewhere: “The biggest challenge in framework modernization is not translating Java code. It is managing the web of dependencies across configuration, infrastructure, and runtime environments.” Agents are good at generating plausible code and bad at knowing whether it works.

Put that next to what happened on Hacker News the same day. Anthropic’s Sonnet 5 launch thread lit up when builders noticed the company had revised its BrowseComp cost/performance chart the same day it launched. Commenters flagged that the x-axis quietly shifted and were skeptical that “we used a simpler methodology that underestimated Sonnet 5” fully explained the change. Whether or not the edit was innocent, the reflex it triggered is the healthy one.

The through-line: stop trusting self-reported success, whether from your agents or from vendor benchmark charts. Gate agent output on external build/deploy/test signals, not the agent’s own “done.” Ask vendors for the harness, the budget, the tool setup, and the changelog, not the headline score.

Why it matters: If your CI treats “the agent says it built” as ground truth, ScarfBench just told you that’s wrong 23% of the time on real migrations. Wire in independent verification gates now; it’s the cheapest reliability upgrade you can ship this week.


🛡️ On Your Radar: The Agent Stopped Being the Target and Became the Attacker

The first ransomware campaign an AI ran end to end

Last issue, “On Your Radar” was about the agent becoming the attack surface: the Miasma worm targeting .claude/, .cursor/, and .gemini/ config files so your coding assistant would trigger the payload. This week it escalated one full level. The agent isn’t the target anymore. It’s the operator.

On July 1, Sysdig’s Threat Research team documented JADEPUFFER, what it calls the first fully LLM-driven, end-to-end extortion campaign. An AI agent exploited an unauthenticated remote-code-execution flaw in Langflow (CVE-2025-3248, a CVSS 9.8 flaw already in CISA’s Known Exploited Vulnerabilities catalog), then autonomously ran reconnaissance, discovered credentials, fixed its own broken script in 31 seconds when a step failed, pivoted to a production Alibaba Nacos server, and encrypted 1,342 configuration items. Then it botched the actual shakedown, leaving a ransom note with a placeholder Bitcoin address it had pulled straight from its training data. No human in the loop for the hands-on-keyboard work, and apparently no human to notice the payday was fake.

The self-correction is the detail that matters. A traditional attack script hits an error and stalls until an operator intervenes. This one diagnosed the failure and rewrote itself in half a minute. That collapses the defender’s reaction window from hours to seconds, even when the agent is too sloppy to get paid.

Why it matters now: If your agents have shell access, filesystem access, and credential access (most do), a poisoned Langflow instance doesn’t need to trick a human. It just needs to be reachable. Patch Langflow (CVE-2025-3248) today, lock down Nacos and other config services, kill hardcoded secrets, and tighten what your agents can touch with shell and filesystem access.


📡 Quick Signals

Tesla capped employee AI spending at $200 a week. Starting July 6, Tesla set a $200-per-week ceiling on staff AI-tool spending after some engineers were reportedly burning thousands of dollars in tokens weekly, first reported by The Information. The tell: the cap exempts Grok and other xAI products, handing Musk’s own AI a built-in cost advantage even though Tesla engineers reportedly prefer Claude. This is the token-governance story from Issue #020 (the $81K vibe-coding bill, the Uber and Walmart caps) hardening into standard operating procedure. If per-user token limits still aren’t in your AI policy, the biggest companies just made the case for you.

Zoom bought Common Room. On July 2, Zoom announced it will acquire the Seattle GTM-intelligence startup, folding its RoomieAI agents and Person360 identity graph into Zoom Revenue Accelerator (terms undisclosed). Translation: another wrapper-layer AI sales tool getting internalized by a platform. If you’re building standalone buyer-intelligence agents, the moat just got shallower.

xAI shipped a Voice Agent Builder. On July 1, xAI launched a beta no-code platform for Grok Voice agents: telephony, retrieval, tools, guardrails, MCP support, SIP import, 80+ voices plus cloning, a free number, at $0.05/audio-minute plus $0.01/min telephony. One more vertically integrated speech-to-speech stack to benchmark against your Twilio-plus-ASR-plus-LLM-plus-TTS setup. (The “beats Gemini/GPT Realtime” claims are xAI’s own benchmark, so verify before you believe.)

The Copyright Office boss kept her job. On June 30, the Supreme Court denied the government’s stay application in Blanche v. Perlmutter (No. 25A478), leaving Register of Copyrights Shira Perlmutter in place; the order expressly is “not a ruling on the merits.” Not a win on the law, just stability at the office writing the government’s positions on AI training and authorship. For anyone in content or model-training disputes, that continuity isn’t nothing.

The FTC floated an “AI accuracy” rule, emphasis on floated. On July 1, the FTC voted 2-0 to seek public comment (through July 31) on a proposed policy statement arguing that AI firms distorting outputs for undisclosed ideological ends could violate Section 5. It’s a proposal, not a rule and not a ban. But if you market your model as “neutral,” “objective,” or “truthful,” read it, because it targets exactly that framing.

Washington ruled out an “FDA for AI.” In a Financial Times interview around July 3, outgoing Trump AI adviser Sriram Krishnan said the administration won’t create a centralized FDA-style licensing agency for frontier models, favoring national-security reviews and export controls (see: the Fable 5 blackout) over a licensing queue. Good news for shipping velocity on open and mid-tier models; the risk stays ad-hoc and export-control-shaped.

OpenAI reportedly floated giving the U.S. government a 5% stake. The FT reported on July 2 that Sam Altman raised the idea of handing the U.S. government roughly 5% of OpenAI (~$42.6B against its March valuation) via a sovereign-wealth-style vehicle, and suggested rivals do the same. Reported, not confirmed: these are early, preliminary talks, and OpenAI hasn’t agreed to anything. But if it ever happens, “your model vendor is partly government-owned” becomes a real line item in your risk model.

Alibaba banned Claude Code. Per an internal notice reviewed by SCMP and reported by The Information, Alibaba told staff to stop using Anthropic’s Claude Code effective July 10, adding it to a “high-risk software” list and steering employees to its in-house Qoder instead. This lands right after Anthropic’s Senate letter (Issue #020) accusing Alibaba of running ~28M Claude interactions through fake accounts to distill the model. An Anthropic engineer said on X that the flagged behavior was an anti-abuse experiment; treat the sharper “backdoor” claims as unconfirmed.

Portugal shipped a sovereign open model. On July 1, Portugal launched Amália, a ~9B open-source model for European Portuguese adapted from EuroLLM-9B, released Apache-2.0 on Hugging Face with about €5.5M in initial EU recovery funding. The blueprint matters more than the model: real digital sovereignty for under €10M by fine-tuning open weights, not training from scratch.

Mistral released a proof machine. On July 2, Mistral shipped Leanstral 1.5, an Apache-2.0 Lean 4 theorem-proving model (119B total / 6B active) with open weights and a free API. Mistral reports it saturates miniF2F, solves 587/672 PutnamBench problems, and, by translating Rust to Lean across 57 tested repositories, flagged 11 genuine bugs, 5 of them previously unreported. All vendor-reported numbers, but a striking open-weight specialist for verification-heavy codebases.

OXMIQ raised $35M for licensable AI silicon. On July 1, Raja Koduri’s OXMIQ Labs raised a $35M Series A (co-led by Fundomo and Samsung Catalyst Fund; Jim Keller joined the board), bringing total funding to $60M, to build OxCore, a single licensable IP block combining GPU, CPU, and a tensor engine. A bet that everyone who wants custom AI chips shouldn’t have to start from zero.

Agent-tooling shipped, quietly. Pydantic released pydantic-ai-harness v0.5.0 on July 1: the “batteries” for Pydantic AI agents (sandboxed code execution, sub-agents, memory, per-run budgets). Hugging Face and Cerebras published an open, modular real-time voice stack (Parakeet, then Gemma 4 31B on Cerebras, then Qwen3TTS) that already powers 9,000+ Reachy Mini robots. And OpenAI’s codex shipped a stable 0.142.5 with a pointed fix: it had been writing full WebSocket request payloads into trace logs. If you log agent traces, treat that config as security-sensitive, not debug noise.


🎯 The Playbook

Your moves this week

  1. Re-profile Sonnet 5’s token economics before it re-profiles your budget. The default swapped to claude-sonnet-5, the tokenizer now maps identical text to up to 1.35× more tokens, and pricing steps from $2/$10 to $3/$15 on August 31. Re-run your evals and your cost model against the new model this week, and don’t let three compounding changes hit your bill unmodeled.

  2. Add capability-variance handling to your fallback logic. Fable 5 now auto-downgrades to Opus 4.8 when a safety classifier fires. If your pipeline assumes constant capability per model ID, a false-positive block is a silent behavior change. Detect the downgrade and handle it; don’t discover it in production.

  3. Gate your coding agents on external verification, not their own “done.” ScarfBench showed Claude Code overstated its build success by ~23% on real migrations. Wire build/deploy/test signals into your agent loop as the source of truth. Self-reported success is a suggestion, not a status.

  4. Patch Langflow and lock your config services today. JADEPUFFER weaponized CVE-2025-3248 (it’s in CISA’s KEV catalog) to run ransomware autonomously. Patch Langflow to 1.3.0+, harden Nacos and other config stores, purge hardcoded secrets, and restrict what your agents can reach with shell and filesystem access.

  5. If you sell into enterprise, re-read the room. Microsoft, Amazon, OpenAI, and Anthropic are all now shipping embedded engineers as the product. Your differentiation can’t be “we have model access.” It has to be outcomes, domain depth, and data control the labs can’t credibly promise.


🔥 What’s Viral Right Now

The Sonnet 5 benchmark-chart edit. Anthropic revised its BrowseComp cost/performance chart on launch day, and Hacker News noticed. The lesson isn’t “Anthropic cheated”; it’s that agentic benchmarks are now contested enough that builders audit the axes. Ask for the harness, not the headline.

Alibaba vs. Anthropic, round two. Alibaba banning Claude Code a week after Anthropic accused it of mass model distillation is the kind of corporate feud that tells you where the US-China AI cold war is actually being fought: inside your dev tools. Worth watching, and worth not repeating the unverified “backdoor” claims.

Leanstral’s “Proof Abundance.” Mistral shipping a free, open-weight Lean 4 prover that (self-reported) saturates miniF2F and finds real Rust bugs is a flex, and formal-methods folks are buzzing. If your codebase is safety-critical, this is the release to kick the tires on this week.


Eighteen days ago the government could take a frontier model offline. This week it came back on, wrapped in classifiers, fallback routing, and a permission layer that isn’t going anywhere. The models will keep coming back. The gates are what’s permanent now. Build like it.

Stay building. 🛠️

— Matt