On Friday 12 June, at 5:21pm Eastern, Anthropic received a letter from the United States Commerce Department. By the end of the evening the company had disabled its two most capable models, Fable 5 and Mythos 5, for every customer worldwide. A government had ordered two frontier models withdrawn, and the firm that built them complied within hours. If your operations now depend on a frontier model you reach through someone else’s cloud, you have just watched a failure mode you almost certainly did not price.
Focus On: The Off Switch Was Always There
Begin with what the order actually said, because the mechanism is the lesson. The directive did not question the quality of Anthropic’s product. It named a category of user. Access to Fable 5 and Mythos 5 was to be suspended for any foreign national, whether inside or outside the United States, and that included Anthropic’s own non-citizen employees. No provider can sort foreign nationals from American citizens at the moment of inference (there is no citizenship field on an API call), so compliance left a single option: switch the models off for everybody. The stated trigger was a reported technique for bypassing Fable’s safeguards in cybersecurity, a finding Anthropic reviewed, disputed as narrow, and observed could be reproduced on other public models that carry no equivalent restriction.
Hold on that last detail, because it is where planning and politics part company. Whether the security rationale was proportionate is a fair question, and Anthropic has said plainly that it was not. For an executive deciding how to run a business, it’s the wrong question. The action was lawful and deliberate. It reached beyond America’s borders to people who had nothing to do with the alleged flaw. And it was used. No government had previously forced a publicly deployed frontier model off the open market. The precedent now exists, and precedents are easier to follow than to set.
None of this should surprise a reader of this newsletter. Last November I wrote that sovereign AI was becoming national infrastructure, and that corporates should pay attention even when they sat outside the blast radius. The framing then was deliberately distant: a weather system forming over the horizon, real but not yet local. In March I argued that the cloud calculus for AI had reversed, and that open-weight models running on infrastructure you control were becoming the rational choice on two grounds, confidentiality and cost. I priced the leak and I priced the tokens. I was making an argument about money and secrecy.
I underweighted the third pillar. Availability. When I wrote about keeping open-weight models on standby, I cast it as insurance against exhausting your quota in the middle of a project, a usage problem. The real exposure was never the meter; it was the jurisdiction that grants the access in the first place and can withdraw it.
Friday forces a harder reframe than either of those earlier pieces reached for. Access to a frontier model is not infrastructure you own; it is a licence, exercised at the discretion of the jurisdiction that issued it. You hold that access de jure, through a contract with a vendor. The same access is revocable de facto by a government, which may not even be your own. The contract is real. Its enforceability against a sovereign export order is not.
Machiavelli was clear about this kind of dependence five centuries ago, and he was not writing about software. His warning concerned auxiliary arms, the troops a ruler borrows from a more powerful ally. Win with them and you become the ally’s prisoner; lose with them and you are finished. Their loyalty runs to their own prince, not to you. A frontier model reached through a foreign provider is auxiliary arms for the cognitive layer of your business. On Friday the lender exercised his prerogative, and every borrower learned the terms of the loan at the same moment.
The three risks fail in different ways, and that is why the third one ambushes people. Cost arrives gradually; you watch the invoice climb and you have time to respond. A confidentiality breach is silent; the harm is done before you notice, yet it touches specific data, not your capacity to function. The loss of access is different in kind: sudden and total, and indifferent to how well you managed the other two. A team can run a disciplined token budget and a faultless data-governance regime and still find, on a Friday evening, that the engine it built its week around is simply gone.
The Decision This Forces
On-prem migration is a separate argument, and I made it in March; it stands on its own merits. What Friday forces is narrower and more urgent. Model-agnosticism has become a governance requirement.
The requirement is concrete. For every workflow your revenue or your operations cannot survive without, there must exist an open-weight equivalent you can run on infrastructure beyond the reach of any single government’s export regime, and it must be tested rather than assumed. In practice that means the model artefact sitting with you: downloaded weights on hardware you own, or hosted in a jurisdiction you have chosen on purpose, not reached through an access tap a third party controls. The fallback is no longer hypothetical or second-rate. As I wrote in January, a capable model can now be trained for single-digit millions rather than the hundreds it once demanded, and the open-weight ecosystem is being fed deliberately, partly because rival states have no wish to see one country holding the only off switch. The intelligence you would fall back to is, for most enterprise tasks, a version of the frontier from a few months ago. That is enough to keep the business running.
Christopher Penn has made the same case from the practitioner’s side for over a year: anyone whose work now runs on generative AI needs a private instance on standby, because cloud access is contingent on a government’s continued permission. Friday converted his counsel from prudent to obvious.
What this asks of the C-suite is a reclassification. You have likely sorted your AI workloads by cost and by sensitivity already. Sort them again, by a third test: can this process tolerate the abrupt, indefinite loss of one named model? The processes that cannot are your exposed surface. They need a portable equivalent, provisioned and rehearsed, with a named owner accountable for switching to it. Treat that the way you would any other single point of failure in a system the business depends on, because that is precisely what it has become.
Put one question to your AI council this week, more useful than which model tops your benchmarks and far longer-lived in its answer: if our primary model were removed from the market by government order at five o’clock on a Friday, what stops on Monday morning, and who in this room owns restoring it?
The question will be asked again in earnest before long. The next directive may come from a different capital, name a different model, and give less warning than this one did. The enterprises that built an open-weight fallback while it still looked like a cost optimisation will find they had quietly bought a continuity control. The ones that treated portability as a luxury will learn, in an afternoon, which of their workflows were borrowing their intelligence all along.
Which of your critical workflows would stop if a single model were pulled tomorrow, and have you tested the fallback, or only assumed it exists?
Follow me
That’s all for this week. To keep up with the latest in generative AI and its relevance to your digital transformation programs, follow me on LinkedIn or subscribe to this newsletter.
Disclaimer: The views and opinions expressed in Chronicles of Change and on my social media accounts are my own and do not necessarily reflect the official policy or position of S&P Global.
Disclosure: S&P Global maintains commercial relationships with multiple providers of AI technology, including Anthropic. The analysis above is my own and is neither an endorsement of nor a comment on any of those relationships.
