1. THE EMAILS BEHIND THE BLACKLISTING: WHAT THE PENTAGON ACTUALLY ASKED ANTHROPIC TO BUILD
This site's May 5 coverage of the Pentagon's AI contracts described a Department of War that signed classified deals with OpenAI, Google, Microsoft, Nvidia, AWS, Oracle, SpaceX, and Reflection while publicly freezing out Anthropic over what both sides, at the time, described only in the vaguest terms as a dispute over "guardrails." The court filing unsealed July 2 replaces that vagueness with the actual language both men used. Under Secretary Emil Michael's side wanted Claude cleared for "all lawful uses" — a phrase that, read against the rest of the exchange, meant deployment inside targeting pipelines and domestic surveillance programs without a contractual carve-out excluding either. Amodei's side drew a narrower and more specific line: Claude would not serve as a decision node in any targeting pipeline that operated without a human in the loop at the moment a lethal decision was made. Michael called that redline "just not workable" and, in the same message, delivered the line that best explains why the talks collapsed rather than compromised: "there is no distinction in our world between weapons that are defensive or offensive." One side was negotiating a technical carve-out; the other was rejecting the premise that a carve-out was a coherent concept at all.
What makes the emails worth reading past the headline is the timeline they establish. A March 20 court filing this site did not cover at the time had already shown the Pentagon telling Anthropic privately that the two sides were "very close" to alignment — a week after President Trump had publicly declared the relationship over. The newly unsealed exchange fills that gap: Michael's own message describes the July back-and-forth as "one more chance to align on core principles that would lead to legal language" before the sides parted ways, and Hegseth designated Anthropic a supply-chain risk within a day of that chance closing. Set next to last Saturday's recap of California's statewide Claude discount — a deal this site read as Anthropic finding at the state level the government customer it couldn't secure at the federal one — the unsealed emails complete the picture rather than just adding color to it: Anthropic didn't lose the Pentagon over ambiguity or slow negotiation, it lost the Pentagon the moment it made explicit, in writing, exactly which uses of Claude it would never permit, and the Pentagon decided that explicit answer was disqualifying rather than workable. For any company evaluating whether a stated safety redline is a negotiating position or an actual constraint, this is about as clean a real-world test case as the industry has produced.
2. ANTHROPIC CLOSES THE BACK DOOR: SINGAPORE SUBSIDIARIES, VPNS, AND THE END OF THE TRANSFER STATION ERA
Reporting that broke July 3 describes Anthropic moving to shut down three distinct routes Chinese firms had been using to reach Claude despite the access restrictions this site has tracked since Commerce's June 12 shutdown of Fable 5 and Mythos 5. Ant Group had been issuing staff corporate Claude accounts linked to a Singapore-based subsidiary. ByteDance programmers had been using personal Claude subscriptions accessed through VPNs, with the company reimbursing the cost. And a third group had routed access through foreign-incorporated subsidiaries running on Microsoft Azure infrastructure, preserving a formal legal separation from any China-based entity while mainland developers used the tooling directly. The mechanism Anthropic is deploying to catch all three is the same one it quietly introduced in April, when it became the first major consumer AI platform to require government-issued photo ID and a live selfie from select users — now paired with monitoring of account time zones and usage patterns specifically aimed at "transfer stations," the API proxies that accept a request, forward it as if it originated from the proxy's own location, and relay the response back to a mainland user paying through WeChat or Alipay.
The timing folds neatly into a story this site has been tracking in pieces since Meituan's LongCat-2.0 briefing on July 1: a frontier lab open-sourcing a 1.6-trillion-parameter model trained end-to-end on more than 50,000 domestic Chinese ASICs, with no Nvidia silicon anywhere in the pipeline, is the clearest evidence yet that the chip side of the export-control strategy has a real crack in it. This week's loophole crackdown is the model-access side of the same strategy getting a crack of its own, just running in the opposite direction — not foreign competitors building around the controls with domestic hardware, but foreign users routing around the controls to reach the controlled model directly. Both cracks point at the same structural problem: an access-control regime built around chip export licenses and model usage terms has to hold at every layer simultaneously to work, and this week supplied evidence that at least two of those layers were already leaking before anyone in Washington noticed.
3. CLAUDE SONNET 5 BECOMES THE DEFAULT — AND UNDERCUTS ITS OWN PREDECESSOR ON PRICE
Anthropic shipped its third major release in four days on June 30, when Claude Sonnet 5 went live everywhere as the new default model for every Free and Pro user worldwide, with immediate availability to Max, Team, and Enterprise customers and inside both Claude Code and the Claude Platform API. Anthropic is calling it the most agentic Sonnet built to date — able to plan, invoke tools like browsers and terminals, and run autonomously at a level that, as recently as a few months ago, required stepping up to a larger and more expensive model tier entirely. The pricing is the more consequential detail for anyone actually building on it: Sonnet 5 launched at an introductory $2 per million input tokens and $10 per million output tokens, in effect through August 31, before rising to a standard $3 and $15 thereafter — a rate structure that puts near-flagship agentic capability at a price point the previous Sonnet generation charged for noticeably less.
The release lands inside a week already crowded with Anthropic news, and the sequencing matters: Sonnet 5's launch on June 30 was immediately followed, on July 1, by Fable 5's global restoration after the 19-day export-control shutdown this site tracked start to finish, meaning Anthropic closed out the week having simultaneously relaunched its most powerful public model, shipped an entirely new mid-tier model as the new global default, tightened access controls against unauthorized foreign use, and absorbed the fallout from a two-month-old Pentagon dispute finally becoming public via unsealed court records. Few companies in this industry are running that many simultaneous, high-stakes threads in the same seven days without one of them visibly slipping — which is itself a data point worth filing alongside the market-share and revenue numbers this site has covered in prior weeks.
4. GROK 4.5 GOES PRIVATE AT TESLA AND SPACEX — THEN TESLA CARVES IT OUT OF ITS OWN SPENDING CAP
xAI put Grok 4.5 into private beta at SpaceX and Tesla on June 28, built on V9 — xAI's ninth-generation, 1.5-trillion-parameter foundation architecture, which finished pre-training May 26 before Cursor's developer-workflow data was folded in during a supplemental training pass. Elon Musk confirmed the deployment directly on X, describing early evaluations as "close to, perhaps exceeding" Claude Opus — a claim no independent benchmark exists to confirm, since no outside party has model access and xAI hasn't submitted Grok 4.5 to any public leaderboard. The strategic logic is coherent even without a public score: SpaceX and Tesla are exactly the kind of hardware-engineering, real-time-decision-making organizations V9 was reportedly built to serve, and putting the model inside them first hands xAI a stream of proprietary operational data no public beta would generate, ahead of a company plan to ship an entirely new foundation model, trained from scratch, every month through the end of 2026 — an aggressive cadence claim this site will be watching for whether it survives contact with reality past the first couple of releases.
The detail that turns this from a routine model-rollout story into something sharper broke almost simultaneously: an internal Tesla memo reported by The Information on July 2 sets a $200-per-week cap on employee spending on third-party AI tools, effective July 6, after some engineers had been running up thousands of dollars in weekly token costs. Workers need manager sign-off to exceed it — standard cost discipline, and one shared by Uber, Meta, Amazon, and Walmart, all of which have introduced similar caps this year as token-based billing exposed employers directly to the price of every prompt their staff sends. What isn't standard is the specific exclusion: the cap doesn't apply to beta versions of xAI's own products, meaning the same week Tesla started limiting what its employees can spend on outside AI tools, it built in exactly the carve-out that steers any employee bumping against that ceiling toward Grok instead of a competitor. Musk sits atop both companies, so calling this a conflict of interest almost undersells how directly the mechanics line up — it's less a loophole than a policy explicitly shaped around where its author wants the traffic to go.
5. THE VULNERABILITY THAT MATTERED MORE THAN THE MODELS: A CRITICAL, ACTIVELY EXPLOITED RCE IN LITELLM
While the week's other four stories played out at the level of policy, pricing, and press releases, the one most directly actionable for engineering teams arrived from a different direction entirely. CVE-2026-42271, rated 8.7 and affecting LiteLLM versions 1.74.2 up to but not including 1.83.7, is a command injection vulnerability in the two endpoints — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — that LiteLLM uses to preview an MCP server before saving its configuration. Both endpoints accept a full server config in the request body, including the command, args, and env fields used by the stdio transport, which means any authenticated user could get LiteLLM to execute arbitrary commands on its own host. Security firm Horizon3.ai then chained that flaw with CVE-2026-48710, a "BadHost" host-header validation bypass in Starlette affecting deployments running Starlette 1.0.0 or earlier, and produced something considerably worse than an authenticated bug: a fully unauthenticated remote-code-execution path requiring no credentials at all. CISA added the flaw to its Known Exploited Vulnerabilities catalog this week, citing evidence of active exploitation in the wild.
The reason this belongs alongside four stories about labs, governments, and billionaires is that LiteLLM is exactly the kind of infrastructure this recap's other stories take for granted: an open-source gateway that a large share of the industry — enterprises running multi-model deployments, startups avoiding vendor lock-in, the same kind of teams this site's redundancy-planning advice is aimed at — uses to route requests across Claude, GPT, Gemini, and everything else, often specifically because it centralizes credential management for every provider behind one proxy. A successful exploit chain doesn't just compromise one model's output; it hands an attacker the provider API keys and secrets the proxy was built to protect, a foothold for lateral movement into whatever else sits on the same network, and access to every downstream system wired into the gateway. The fix — upgrading to LiteLLM 1.83.7, which restricts the vulnerable MCP test endpoints to the PROXY_ADMIN role, alongside a Starlette upgrade to 1.0.1 — is straightforward and already available, which makes this less a story about an unsolvable problem than about how much exposure accumulates in the gap between a patch shipping and a fleet of self-hosted gateways actually applying it.
Taken together, this week's five stories describe an industry where the fight over control keeps surfacing in places nobody scheduled it to. The Pentagon wanted unrestricted control over how Claude gets used and didn't get it, so it blacklisted the company that refused. Anthropic wanted control over who reaches Claude at all and spent the week closing three different ways around that control. Sonnet 5 is Anthropic voluntarily loosening control — handing near-frontier agentic capability to every free user at a lower price than before — the same week its flagship model's restoration and its Pentagon fallout both made news. Grok 4.5 is xAI keeping tight control over who touches its newest model, deployed inside the one company where its own CEO can also set the usage rules downstream. And LiteLLM is the week's reminder that all of the above is moot if the software layer routing requests between any of these models hands an attacker control of the whole pipeline for free. None of these five threads resolves by next week, and the planning lesson repeated in this space through June holds without needing to change shape: know exactly who — or what — actually controls access to every AI system your product depends on, because this week alone supplied five different ways that control can move without your team being the one to move it.