Claude Training

Claude Watch, July 2026: The Model Came Back. The Conditions Stayed.

Claude Fable 5 came back online July 1 after a 19-day export-control suspension — but restoration came with standing commitments to the US government and a new industry jailbreak-severity framework, which means model availability is now coupled to policy, not just engineering. The same window brought Claude Sonnet 5 with a tokenizer that produces roughly 30% more tokens for the same text, a Responsible Scaling Policy revision to v3.4, write access to Microsoft 365 from Claude's connector, new enterprise admin controls (model entitlements, Admin API user management, API key expiration, self-serve HIPAA configuration), and a month of Claude Code releases dominated by permission-engine hardening.

Zack Jones ·
Claude TrainingAnthropicAI GovernanceClaude Watch

Claude Watch is our monthly read on what shipped at Anthropic and what it means for security and compliance teams using Claude in regulated work. We read the release notes, the changelogs, and the policy pages so you can track what actually changes the controls.

On July 1, Claude Fable 5 came back. The US Department of Commerce lifted the export-control directive that had forced Anthropic to switch off its two most capable models — Fable 5 and Mythos 5 — for every customer worldwide on June 12, nineteen days earlier. Mythos 5 access had already been restored for select US organizations under a government approval granted June 26. CNBC’s report captures the resolution; our earlier piece on Fable 5’s governance profile covers the model itself.

The models are back. The governance story is what came back with them.

Restoration came with standing commitments

Anthropic’s own announcement lays out what it agreed to as part of the resolution: pre-release government access to models and safeguards for independent testing, rapid notification of significant jailbreaks and misuse patterns, threat-intelligence sharing ahead of publication, expanded joint safety research, and work toward a shared, voluntary security and evaluation standard for frontier model providers.

Alongside that, Anthropic proposed an industry framework for scoring jailbreak severity, developed with Amazon, Microsoft, Google, and other Project Glasswing partners. It scores a jailbreak on four criteria — capability gain over existing tools, breadth across offensive tasks, ease of weaponization, and discoverability — with the most severe findings triggering immediate preliminary mitigations and around-the-clock monitoring of submission channels. Anthropic also deployed a new safety classifier targeting the reported bypass technique that preceded the directive, stating over 99% effectiveness against that method and explicitly accepting more false positives in routine coding work as the tradeoff.

Two things are worth stating plainly. First, none of this is regulation — the framework is voluntary and industry-authored, and the commitments are terms of a resolution with one government, not law. Second, it doesn’t need to be regulation to matter. The June suspension established that frontier-model availability can be revoked by policy overnight; the July restoration establishes that availability now travels with negotiated conditions. If your continuity planning treated June as a one-off, the durable lesson is the opposite: model availability is coupled to a policy layer your uptime SLA does not cover. If the suspension prompted you to design a fallback model and document a contingency, keep both — you don’t retire the fire drill because the fire went out.

Sonnet 5 changes your token math

Claude Sonnet 5 launched June 30 (claude-sonnet-5): 1M-token context window, 128K max output, introductory pricing of $2/$10 per MTok through August 31, then $3/$15. It became the default model in Claude Code the same day.

For anyone migrating workloads, the platform release notes list three breaking changes: adaptive thinking is on by default and manual extended thinking now returns a 400 error, non-default sampling parameters (temperature, top_p, top_k) return a 400 error, and Priority Tier is unavailable.

The governance item hides in one sentence: Sonnet 5 uses a new tokenizer that produces roughly 30% more tokens for the same text. Every token budget, context estimate, cost alert, and per-engagement pricing assumption calibrated on earlier models is now miscalibrated for this one — the sticker price went down while the meter runs faster. If you charge clients for AI-assisted work or cap spend by tokens, re-baseline before you migrate, not after the first surprising invoice.

Also in the lineup: fast mode was removed for Opus 4.6 on June 29 — and requests don’t error, they silently run at standard speed. Opus 4.7’s fast mode follows on July 24. Silent behavior changes on pinned identifiers are exactly why model lifecycle belongs in your change-management process.

Enterprise controls, on both sides of the platform

The API side and the claude.ai side each picked up controls this month. From the platform release notes:

  • User management via the Admin API (July 14, beta). Claude Enterprise organizations can now list members, change roles, remove members, manage invites and groups, and read custom roles programmatically. That turns joiner-mover-leaver evidence for Claude from a screenshot exercise into an auditable API workflow.
  • API key expiration (July 8). Keys can now carry an expiration date, with email notice before expiry and an expires_at field in the Admin API. Standing non-expiring keys are a common finding in platform security reviews; there is now no reason to have one.
  • Access Transparency documentation (July 10). Content-preservation events (cmek_preserve) now have documented reason codes, and the docs clarify that a preservation event is written whether a human reviewer or an automated safety pipeline initiated it. If you operate under customer-managed keys, these events belong in your monitoring.

And from the Claude Apps release notes:

  • Model entitlements (July 1, beta). Enterprise admins can now control which models — and which effort levels — members can use in the Claude apps. Paired with Claude Code’s managed model allowlists, model policy is now enforceable across both the API and the app surface.
  • Self-serve HIPAA configuration (July 14). Eligible Claude Enterprise and API admins can review the Business Associate Agreement, download implementation guides, and enable HIPAA configuration without a sales cycle. If you serve healthcare clients, the eligibility and configuration review just became a concrete assessment item rather than a contract negotiation.
  • Microsoft 365 connector write tools (July 7). This is the one to slow down on. Claude’s M365 connector can now draft and send email, manage calendar events and mailbox settings, and create or update OneDrive and SharePoint files — Teams stays read-only, and attachments aren’t supported. Credit where due: it ships off by default and double-gated. A Microsoft Entra administrator must consent to the connector’s updated Graph permission set — even tenants that consented before the launch must re-approve — and an org admin must then enable write tools before anyone can use them; until both happen, the integration stays read-only, and writes always run within each member’s existing M365 permissions. That consent step is your control point: treat it like any other enterprise app permission grant, with the same pre-deployment review you’d run on a Copilot rollout. Read access surfaces your permission sprawl; write access acts on it.
  • Trusted devices for Remote Control (June 25). Team and Enterprise admins can require device verification before a member views or steers a local Claude Code session remotely — closing an unmanaged-device gap in the remote-steering feature.

Smaller app-side notes: Claude can now be tagged in Slack to take on tasks (June 23), and Claude Cowork expanded to web and mobile with sessions running remotely and files saved to Claude accounts (July 7) — the latter worth a look if your data-residency posture assumed desktop-local sessions.

Governance and safety signals

The Responsible Scaling Policy moved to v3.4, effective July 8. Six weeks after v3.3. Per the policy page, the revision adjusts the automated AI R&D capability threshold to better track its threat model, changes how unredacted internal Risk Reports are distributed, lets reports analyze risk as of a stated coverage date, requires public Risk Reports to indicate where material was redacted, and allows multiple external reviewers to split coverage of unredacted sections. If your AI-governance documentation pins Anthropic’s RSP as an upstream reference, it should now cite v3.4 — and the cadence itself is the lesson: two revisions in six weeks means “check the version” belongs in your quarterly review, not your annual one.

From the corporate layer: Ben Bernanke joined Anthropic’s Long-Term Benefit Trust on July 9 — relevant if your vendor-risk file tracks who oversees the company behind your models. The Usage Policy is unchanged (still the September 15, 2025 version), and no new system cards or transparency reports landed in the window.

Claude Code changelog digest

New standing section. Claude Code ships several releases a week; each month we digest what’s new and pull out what changes your controls. This month: versions 2.1.186 through 2.1.214, June 22 to July 18, from the changelog.

New features, briefly. Sonnet 5 became the default model (2.1.197). Subagents now run in the background by default and Claude in Chrome is generally available (2.1.198). Long-running MCP tool calls auto-background instead of blocking the session, and runaway loops hit new per-session caps on searches and subagent spawns (2.1.212). A screen reader mode landed (2.1.208), /doctor became a full setup checkup (2.1.206), and the default permission mode is now named “Manual” (2.1.200).

What changes your controls:

  • Model policy is now fully administrable. Organization-configured model restrictions apply across the picker, --model, and environment variables (2.1.187), and admins can set an org-wide default model (2.1.196). Combined with the managed allowlist enforcement that shipped in June, model choice in Claude Code is now something you can enforce, not just document.
  • A sustained permission-hardening run. The month closed with a batch of fail-closed fixes: a permission-check bypass in Windows PowerShell 5.1 sessions, redirect forms that parsed differently than the permission analyzer, over-length commands that skipped analysis, and help/man invocations that could smuggle unsafe options (2.1.214). Earlier releases fixed plan mode auto-running file-modifying commands without a prompt (2.1.212) and permission previews that could be visually spoofed with zero-width and look-alike characters (2.1.211). Read this as a positive signal with a sharp edge: the vendor is fixing bypass classes fast, which means the version you run determines the permission model you actually have. Version pinning plus a prompt update cadence is the control.
  • Auto mode grew up — and turned on. Auto mode no longer requires an opt-in flag on Bedrock, Vertex AI, and Foundry (2.1.207). If you run Claude Code through a cloud provider, autonomous-execution posture is now a decision you have to make explicitly rather than a default you inherit. The guardrails matured in the same window: an auto-mode rule blocks tampering with session transcripts, and background-task notifications now explicitly state that no human input occurred, cutting off fabricated in-transcript approvals (2.1.205). Catastrophic removals prompt even in bypass-permissions mode (2.1.208).
  • Credential and supply-chain tightening. A new sandbox.credentials setting blocks sandboxed commands from reading credential files and secret environment variables (2.1.187). MCP servers self-approved by a repository’s committed settings no longer auto-spawn (2.1.196), and plugin configuration was closed as a shell-injection path (2.1.207).
  • Telemetry with a catch. OpenTelemetry can now log the model’s response text — redacted by default, but deployments that already log user prompts start receiving response content on upgrade unless they set OTEL_LOG_ASSISTANT_RESPONSES=0 (2.1.193). If your logging pipeline feeds a retention system, check this before the upgrade checks it for you. On the useful side, new message-level correlation and tool-provenance attributes (2.1.214) make agentic sessions genuinely reconstructable from telemetry.

What to do

  • Keep the fallback-model contingency you built in June. Restoration under conditions is not the same as unconditional availability; record both suspension and restoration dates in your AI inventory.
  • Before migrating anything to Sonnet 5: re-baseline token budgets and cost alerts for the ~30% tokenizer increase, and test for the extended-thinking and sampling-parameter 400s.
  • Re-pin any governance documentation that cites Anthropic’s RSP to v3.4 (effective July 8).
  • If Claude’s Microsoft 365 connector is in use — or requested — decide your write-tools posture before someone asks for it: the Entra admin consent to the updated permission set is the control gate, so review the Graph scopes, audit logging, and who may enable it as a formal change.
  • Set expirations on Claude API keys, evaluate the Admin API user-management beta for joiner-mover-leaver evidence, and turn on model entitlements if members shouldn’t have every model.
  • Healthcare clients: review the new self-serve HIPAA configuration path and its implementation guide before anyone enables it ad hoc.
  • If you run Claude Code via Bedrock, Vertex, or Foundry, decide your auto-mode posture explicitly — it’s now available by default.
  • Update Claude Code to current and hold it there with version pinning; this month’s permission fixes are the argument for both.
  • If you export OpenTelemetry from Claude Code and log prompts, set your assistant-response logging preference before upgrading past 2.1.193.

Genesis builds and governs Claude workflows for security and compliance teams: the model inventory, the data-retention review, and the enforced Claude Code configuration that keeps agentic work inside your controls. Contact us to talk through how Claude fits your governance program.

FAQ

Frequently asked

Is Claude Fable 5 available again?
Yes. The US Department of Commerce lifted the June 12 export-control directive, and Anthropic restored Fable 5 globally on July 1, 2026 across the API, claude.ai, and Claude Code. Mythos 5 access was restored earlier for select US organizations under a government approval granted June 26. Restoration came with commitments: pre-release government access to models and safeguards, rapid sharing of significant jailbreaks and threat intelligence, joint research, and work toward a shared voluntary security and evaluation standard for frontier model providers.
What should I check before migrating workloads to Claude Sonnet 5?
Three breaking changes and one budget change. Manual extended thinking returns a 400 error (adaptive thinking is on by default), non-default sampling parameters (temperature, top_p, top_k) return a 400 error, and Priority Tier is not available. The budget change: Sonnet 5 uses a new tokenizer that produces approximately 30% more tokens for the same text, so token budgets, context estimates, and cost alerts calibrated on earlier Sonnet models need re-baselining even though the introductory price is lower ($2/$10 per MTok through August 31, 2026, then $3/$15).
What governance controls did Claude and Claude Code add in July 2026?
On the platform: user management for Claude Enterprise organizations via the Admin API (beta), API key expiration with pre-expiry email notice, and documented content-preservation event codes under Access Transparency. In the Claude apps: model and effort-level entitlements for Enterprise admins (beta), trusted-device verification for Remote Control, and self-serve HIPAA configuration. In Claude Code: organization-configured model restrictions and org default models, a sandbox setting that blocks access to credential files, auto-mode availability by default on Bedrock, Vertex, and Foundry, and a sustained run of permission-check hardening — including fixes for several classes of permission-prompt bypass. Separately, Anthropic's Responsible Scaling Policy moved to v3.4, effective July 8, 2026.