Skip to content
Tech17 Jul 2026

Fable 5 is back online, GLM 5.2 opens its weights, Claude's "subconscious" and the first new HTTP method in 16 years

Nineteen days of blackout for Anthropic's most powerful model, a top open-weights Chinese model, Claude's "subconscious" and RFC 10008.

By Stefano Righini

In short: four stories from June and July 2026 tell the same thing from four different angles: who decides what we can access. A government that switches off the most capable model ever released to the public for nineteen days. A Chinese lab that publishes free weights at the top of the open leaderboard. A research team that opens a window onto what a model thinks and does not say. And a standards committee that, after sixteen years, adds a new method to the protocol the web runs on.

The 4 stories in 30 seconds

  • Claude Fable 5 came back on 1 July, after nineteen days of total suspension imposed by an export control order from the US Department of Commerce. Mythos 5, its twin with fewer safeguards, remains available only to a group of US organisations.
  • Z.ai's GLM 5.2 is the strongest open-weights model you can download today: MIT licence, one-million-token context, frontier-level performance on agentic coding at about a sixth of the cost of the American alternatives.
  • Anthropic has found a kind of "conscious workspace" inside Claude: a small internal area, called J-space, that the model can report on and use to reason, immersed in a much larger ocean of computation it has no awareness of.
  • The IETF has published RFC 10008, which defines the HTTP QUERY method: the first truly new method since PATCH in 2010. It has the body of POST and the safe, idempotent semantics of GET.

1. Fable 5: nineteen days of blackout and what they teach

On 9 June 2026 Anthropic released Claude Fable 5 and Claude Mythos 5. They share the same base model, but Fable 5 came out with stronger safeguards for general use, while the less constrained Mythos 5 went only to a small number of trusted partners in the Project Glasswing programme, for defensive cybersecurity.

Three days later, on 12 June, the US government imposed an export control order. The cause: a report by Amazon researchers had shown a way to get around Fable 5's safeguards, leading it to identify software vulnerabilities and, in one case, to produce code demonstrating how to exploit them. The directive required restricting access for non-US citizens, inside and outside the USA.

Here comes the most interesting operational detail of the whole story: the order took effect immediately, and Anthropic had no way to verify users' nationality in real time. The result: access suspended for everyone, American citizens included.

The timeline

DateWhat happened
9 JuneRelease of Fable 5 (general) and Mythos 5 (Glasswing partners)
12 JuneUS export control. Anthropic suspends access to both models
26 JuneThe government approves restoring Mythos 5 for a group of US organisations
30 JuneThe export controls are lifted
1 JulyFable 5 is available globally again

On its return, Fable 5 is back on Claude Platform, Claude.ai, Claude Code and Claude Cowork. On the Pro, Max and Team plans and on some Enterprise plans, up to 50% of the weekly usage limits was included until 7 July, after which it moves to pay-as-you-go credits. Reactivation on AWS, Google Cloud and Microsoft Foundry was announced as gradual. Before restoring access, Anthropic strengthened its cybersecurity protections, working with the US government, Amazon and other partners.

Why it matters even if you don't use Fable 5

Because it is the first case in which the release of a frontier model looks less like a product launch and more like a negotiated deployment under national security review. Anyone who had built production workflows on top of that model found themselves without access overnight, with no warning.

The architectural lesson is concrete: abstract the provider. A routing layer that lets you redirect critical pipelines to an alternative model, even a self-hosted one, is no longer a nicety for fussy engineers. It is operational continuity, and it is one of the topics we address when we design AI and automation solutions for our clients. Which leads straight to the second story.

2. GLM 5.2: the open-weights model that changed the maths

While Fable 5 was offline, the Chinese company Z.ai (formerly Zhipu AI, a spin-off of Tsinghua University listed in Hong Kong in January 2026) released GLM 5.2. The initial rollout was on 13 June, with the official blog and weights on Hugging Face on the 16th.

The difference from OpenAI's and Anthropic's models is not in the benchmarks: it is in the distribution regime. GLM 5.2 is open weights under an MIT licence. Anyone can download it, fine-tune it and serve it on their own infrastructure.

The numbers

  • Mixture-of-Experts architecture, about 750 billion total parameters with about 40 billion active per token (sources vary between 744B and 753B)
  • 1 million token context
  • API price around $1.40 / $4.40 per million tokens input/output: about a sixth of the Western alternatives
  • First open-weights model to exceed 80% on Terminal-Bench
  • At launch, the first open model on the Artificial Analysis Intelligence Index, behind Claude Opus 4.8 and ahead of GPT-5.5 on several long-horizon coding evaluations

Development environments integrated it immediately, with more than twenty third-party coding tools on day one. Vercel's CEO said he was almost stunned by the model's quality on code.

The real point

It is not "a strong Chinese model". It is that frontier capability has started to spread through a channel that no administrative order can switch off. The timing coincidence with the Fable 5 block is chance, but it is chance that says a lot: on one side, a capability declared too risky for a wide release, on the other, a comparable capability that anyone with an internet connection can download.

For a European company, the operational consequence is twofold: a real option to cut costs on high-volume workloads, and a sovereign plan B for workloads that cannot depend on a single supplier: a logic not far from the one that leads us to release open source software. With a methodological caveat: many of the numbers in circulation come from different test harnesses, and are not directly comparable across vendors.

3. Does Claude have a subconscious too? The J-space research

On 6 July 2026 Anthropic published an interpretability study: the field that tries to understand the internal mechanisms of LLMs, which remain largely opaque even to those who build them. The popular title is A global workspace in language models; the full technical paper, on transformer-circuits.pub, is called Verbalizable Representations Form a Global Workspace in Language Models.

The starting analogy is global workspace theory from neuroscience: specialised systems working in parallel and almost all in silence, and a small shared area where information becomes accessible and is redistributed to the rest of the brain.

Inside Claude the researchers found something analogous, which they call J-space: a small privileged set of internal representations, identified with a new method, the Jacobian lens (J-lens). Its characteristics:

  • it occupies a modest fraction of the network's activity (on the order of a few percentage points of the variance of the activations) and holds a few dozen concepts at a time;
  • the model can report what it contains;
  • it is modulable: you can inject or replace a concept, swap "France" for "China", and see the downstream reasoning change accordingly;
  • it is causally necessary for flexible multi-step reasoning: ablate it, and reasoning abilities get worse;
  • it is not used for automatic, fluent processing, such as grammar or simple classifications.

Watch out for the reversal, because almost all the coverage gets it wrong: J-space is not Claude's subconscious. It is the functional analogue of conscious access. The subconscious is everything else: the ocean of computation, overwhelmingly the majority, that the model cannot report anything about.

Why it matters outside research

Because it opens a path to monitoring. In deception tests, the J-lens brought out silent internal concepts (things like "fake", "manipulation") while the visible output stayed perfectly cooperative. In other words: there is a channel where some safety-relevant intentions appear before reaching the surface.

Anthropic was explicit about what the research does not show: it is not proof that Claude has subjective experience. The claim is narrower and more useful: a functional mechanism that resembles conscious access, not phenomenal consciousness.

The work is verifiable: the J-lens code was published under the Apache-2.0 licence, there is an interactive demo built with Neuronpedia on open-weights models, and the publication was accompanied by invited commentaries from external researchers in neuroscience, philosophy and interpretability, including the authors of global workspace theory.

4. HTTP QUERY: the first new HTTP method in sixteen years

On 15 June 2026 the IETF published RFC 10008, which defines the QUERY method. It is a Proposed Standard on the Standards Track, twenty-four pages, authored by Julian Reschke (greenbytes), James M. Snell (Cloudflare) and Mike Bishop (Akamai), produced by the HTTP Working Group. It is the first truly new HTTP method since PATCH, which was RFC 5789 in March 2010: a sixteen-year gap.

The problem it solves

Every backend developer has been here. You need to read data with complex parameters and you have two options, both imperfect.

GET is safe, idempotent and cacheable, but puts everything in the URI. And there the problems are four, listed by the RFC itself: nobody knows the real length limit in advance, because the request crosses uncoordinated intermediaries (RFC 9110 recommends 8000 octets only as a minimum threshold); structured data (nested filters, arbitrary JSON) is awkward and expensive to encode into a URI-safe string; and URIs end up in logs far more easily than bodies do, so sensitive data ends up in them.

POST solves the body but loses the guarantees: nothing in the protocol signals that the operation is read-only, so caches and proxies treat it accordingly and no automatic retry is safe.

What QUERY does

QUERY asks the server to process the content of the request in a safe and idempotent way and return the result. It has the shape of POST and the guarantees of GET: a QUERY request can be repeated or automatically retried with no risk of partial state changes. And it is explicitly cacheable.

QUERY /users HTTP/1.1
Host: example.org
Content-Type: application/json

{ "role": "admin", "sort": "name", "page": 1 }

It is not a generic replacement for GET: for short, simple queries the RFC itself recommends sticking with the traditional method.

The three things to check before adopting it

  1. Cache. QUERY is cacheable, but the cache key must include the body. Caches that normalise or hash the body incorrectly open the door to cache poisoning and cache deception.
  2. Allowlisted methods. WAFs, API gateways, CDNs and CSRF middleware have policies written in terms of GET, POST, PUT, DELETE, PATCH. Allowlists written before June 2026 do not mention QUERY: some stacks will reject it, others will route or inspect it differently from POST.
  3. Browsers and CORS. QUERY is not a CORS-safelisted method, so JavaScript in the browser has to preflight. On support: Node.js has parsed it natively since early 2024, OpenAPI 3.2 documents it, Spring had not yet released it as of July 2026 and browsers are evaluating it.

The sensible rollout path is to put QUERY alongside a search endpoint that is already POST-based, announce it through the Accept-Query header and let clients migrate when their tooling supports it. Don't make it the only way into an endpoint until the infrastructure has caught up.

The common thread: who controls access

Four stories, one question.

Fable 5 shows that access to frontier capability can be revoked by decree, in an afternoon. GLM 5.2 shows that the same capability, or something very like it, is spreading through a channel no decree reaches. J-space shows that we are starting to have tools to look inside models instead of trusting their output. And RFC 10008 is a reminder that the foundations all this runs on are still moving, on decade timescales and through public processes.

For those who build software, the practical translation comes in three points. Abstract the model provider, because depending on a single endpoint is now also a regulatory risk. Invest in observability, because trusting a system you cannot inspect is not a strategy. And read the standards, because the elegant solution to the problem you have been working around for years sometimes already exists, in an RFC published last month.

Frequently asked questions

Why was Claude Fable 5 suspended? On 12 June 2026 the US government imposed an export control order on the Fable 5 and Mythos 5 models, after a report by Amazon researchers showing how to get around the model's safeguards to make it identify software vulnerabilities. The order required restricting access for non-US citizens; unable to verify nationality in real time, Anthropic suspended access for everyone.

Is Fable 5 available again? Yes. The export controls were lifted on 30 June 2026 and Fable 5 has been available globally again since 1 July on Claude Platform, Claude.ai, Claude Code and Claude Cowork. Mythos 5, on the other hand, remains limited to a group of approved US organisations.

What is the difference between Fable 5 and Mythos 5? They share the same base model. Fable 5 was released with stronger safeguards for general use, while Mythos 5 has fewer and is reserved for a small number of selected partners in the Project Glasswing programme for defensive cybersecurity work.

What does it mean that GLM 5.2 is open weights? That the model's weights are publicly downloadable, in the case of GLM 5.2 under an MIT licence on Hugging Face, and that anyone can run it on their own infrastructure, fine-tune it or serve it as a provider. It is different from OpenAI's and Anthropic's models, which are accessible only via API.

Is GLM 5.2 better than Claude Opus 4.8? No. On long-horizon coding evaluations GLM 5.2 remains behind Opus 4.8, while beating GPT-5.5 on several of them. Its advantage is the ratio of quality to cost, about a sixth, and freedom of deployment.

What is Claude's J-space? A small privileged set of internal representations, identified by Anthropic's research of 6 July 2026 using a method called the Jacobian lens. The model can report what it contains, it can be modified from outside and it serves flexible multi-step reasoning. It is not the chain of thought, which is text produced as output.

Does the global workspace research prove Claude is conscious? No, and Anthropic explicitly rules it out. The claim is that there is a functional mechanism that resembles conscious access, meaning that some information is available for reasoning and reportability, not that the model has subjective experience.

What is the HTTP QUERY method? An HTTP method defined by RFC 10008, published by the IETF on 15 June 2026, that lets you send a request with a body like POST while keeping the guarantees of GET: safe, idempotent and cacheable. It is for complex read queries that don't fit comfortably in a query string.

What was the last new HTTP method before QUERY? PATCH, defined by RFC 5789 in March 2010. Between the two there are sixteen years.

Can I use QUERY in production today? With caution and not as the only way into an endpoint. Node.js parses it natively and OpenAPI 3.2 documents it, but support in browsers, proxies, WAFs and frameworks is still uneven. The recommended approach is to put it alongside an existing POST endpoint and announce it with the Accept-Query header.

Sources

  1. Anthropic: Redeploying Claude Fable 5
  2. Anthropic: Claude Fable 5 and Claude Mythos 5
  3. Anthropic: Fable and Mythos access
  4. CNBC: Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5
  5. Z.ai: GLM 5.2
  6. Artificial Analysis: GLM 5.2 page
  7. VentureBeat: Z.ai's open-weights GLM-5.2 beats GPT-5.5 on multiple long-horizon coding benchmarks
  8. Anthropic: A global workspace in language models
  9. IETF: RFC 10008: The HTTP QUERY Method
  10. IETF Datatracker: RFC 10008

Did we make you curious?

If you have a problem, an idea or just a curiosity: let us talk. Half an hour, no strings attached.

Get in touch

Related articles