The Weekend Washington Switched Off an AI
Anthropic thought it was selling access to intelligence. The U.S. government reminded everyone that access is not ownership. It is permission, and permission has a switch.
For months a single company appeared to hold the keys. On Friday we found out it never did.
Anthropic employs engineers born in other countries, as every serious technical company does. On Friday evening the United States government told the company that foreign nationals could no longer touch its two newest models: not from abroad, not from an allied capital, not from a desk in California, not even while wearing the badge of the company that built the thing. The instrument was an export-control directive, the kind of law whose older mental picture is crates, ports, borders, parts, drawings, source code, technology transfer. But export control has long had a more intimate doctrine too: the “deemed export,” where releasing controlled technology to a foreign person inside the United States can be treated as an export to that person’s country of nationality. The novelty here was not that a passport could matter inside the United States. The novelty was that a hosted model, a machine intelligence reached through an API, became the controlled thing. The passport became the border. The employee became the export.
The company could not do as it was told without doing far more than it was told. It had built systems that spoke to the world and had not built a politically useful half-silence: one that would let the models keep answering Americans while going mute for everyone else, including foreign-national staff. There was an on, and there was an off, and the middle was evidently a compliance fantasy. Anthropic says it received the directive at 5:21 p.m. Eastern on June 12. By later that night, according to Axios, users had lost access to Fable 5. The directive targeted foreign nationals. The effect was global.
The obvious casualties were Fable 5 and Mythos 5. The less obvious casualty was the idea that frontier AI is ordinary software.
Three days earlier, Anthropic had launched Claude Fable 5 as a general-use version of its more restricted Mythos-class system. The company described it as its most capable broadly available model, stronger on long autonomous work, software engineering, knowledge work, vision, scientific research, and other domains. It also launched Mythos 5 for a smaller set of cyberdefenders and infrastructure providers, with safeguards lifted in some areas. Fable 5 was the public compromise: Mythos power with guardrails, including routing some cyber, biology, chemistry and distillation-sensitive requests to Opus 4.8.
This was not a toy release. It was an attempt to domesticate a strategic capability.
That is why the mess is so instructive. Just days before the shutdown, Anthropic had expanded Project Glasswing to roughly 150 organisations in more than fifteen countries, including providers in power, water, healthcare, communications, hardware and other critical-infrastructure-adjacent sectors. Anthropic said the goal was to give defenders a permanent advantage as AI reshaped cybersecurity. Then permanent met Friday.
The advantage was not undone by a clever adversary or a flaw in the mathematics. It was undone by an order.
One side will say Anthropic nearly released a cyber weapon and the state had to act. The other will say the government panicked over a normal model behaviour and kneecapped a company it dislikes. Both accounts are too clean. The uglier version is more plausible: a powerful model was released into a world where neither the company nor the government had built a legitimate regime for deciding what to do when the model looked dangerous. So the government improvised with a hammer, Anthropic over-complied because its systems left it no scalpel, and Amazon, which is investor and landlord and cloud partner and distributor and apparent alarm bell, somehow ended up standing beside the hammer.
Amazon’s role is the part that most deserves suspicion without yet justifying conspiracy. Axios reports that Amazon called administration officials Thursday night with a report showing how it had been able to “jailbreak” and access portions of Anthropic’s powerful Mythos model. The Verge, citing Wall Street Journal reporting, says Amazon researchers claimed that through prompts they could get Fable 5 to provide information useful for cyberattacks, and that CEO Andy Jassy spoke with officials shortly before the export-control directive. Amazon says governments sometimes seek its counsel on security risks and that it does not share details of those discussions. Very noble. Very convenient.
Anthropic disputes the entire characterisation. It says the government’s letter gave no specific details of the national-security concern. Its understanding is that the government believed there was a method for bypassing or jailbreaking Fable 5. Anthropic says it reviewed the relevant demonstration and found only a small number of previously known, minor vulnerabilities; it also says other publicly available models can discover the same things without a bypass. The company says no tester has found a universal jailbreak, and that the evidence shared with it amounted essentially to asking the model to read a codebase and fix software flaws, which, unhelpfully for the panic narrative, is exactly the sort of thing cyberdefenders were supposed to use the model for.
The public is therefore being asked to assess an execution without seeing the warrant.
That does not make Anthropic innocent. It makes the government’s case insufficiently visible. Those are different things, and the distinction matters. Anthropic had every incentive to describe the vulnerability as narrow. The government had every incentive to hide behind national security. Amazon had every incentive to sound like a responsible adult while declining to show the paper that set the house on fire. The evidence we have is lopsided, interested and incomplete. But one fact stands clear of the rubble: a commercial model used by customers around the world could be removed by state command in a single evening.
For three years the industry has sold frontier AI as software. It has been priced as software, procured as software, integrated as software, and narrated as software: a thing licensed, billed, logged, monitored, upgraded, deprecated, restored. A thing that will be there tomorrow because it was paid for today. Friday showed that this was the wrong mental model. What customers held was not a product. It was access. Access is a leash, and the leash runs from user to company, from company to cloud, from cloud to state. On Friday the state pulled it, almost casually, and everyone along the chain felt the collar.
This is the first real AI sovereignty shock.
The point is not that the models stayed down forever. The point is that they could be taken down at all, by a process the affected parties could not inspect and a standard they could not test. Trust does not return simply because the switch is later left alone. When a dependency is revealed as revocable, every previous reassurance is reread in the light of revocation. The allied utility, the health system, the bank, the developer in Sydney, the security team in London, the research lab in Tokyo, all now know what they were before the outage: downstream.
This kind of dependence works backward. The harm is not only the interruption. It is the retrospective discovery that the relationship was never the one advertised. The cloud region, the enterprise contract, the trusted-access programme, the procurement review, the security questionnaire, the solemn slide deck about resilience, all of it sat beneath a power that did not need to explain itself to the customer.
That is why the global ripple is larger than Anthropic. China does not need to prove that American AI is technically inferior. It only needs to point out that American AI is politically interruptible. Europe does not need another white paper to justify sovereign AI. India does not need another lecture on strategic autonomy. Australia, Canada, Japan, South Korea, the Gulf states, and the United Kingdom (and others) do not need to imagine a future in which U.S. frontier systems become instruments of U.S. discretion. They watched it happen over a weekend.
The lesson will not be “stop using American models.” That is too clean, and the world is not that brave. The lesson will be redundancy, hedging, local capacity, awkward sovereign clouds, open-weight fallbacks, procurement clauses written by frightened lawyers, and the slow multiplication of inferior but politically safer systems. Fragmentation rarely arrives as a manifesto. It arrives as a risk register.
The market should be paying attention, though it probably will not at first. Public equities are very good at pricing gross margins and very bad at pricing political revocability until the revocation becomes routine. A company wrapping one frontier model is no longer just taking vendor risk. It is taking sovereign-intervention risk. A cloud platform distributing frontier models is no longer just selling compute. It is distributing access to a class of capability the state may decide belongs partly to it. A regulated enterprise adopting frontier AI is no longer only asking whether the model hallucinates. It is asking whether the model will exist next Friday.
That is a different discount rate.
The AI capex boom does not end because one model family was pulled. Nvidia does not suddenly stop selling accelerators because Washington sent Anthropic a letter. But the event changes the assumptions under the boom. Frontier AI has been valued like software because software scales. Strategic infrastructure scales too, but under permission. The more important the models become, the more states will assert claims over them. The more states assert claims over them, the less they behave like clean, global SaaS assets. Investors who cannot tell the difference between recurring revenue and revocable access are about to pay tuition.
Responsibility should be apportioned plainly.
The U.S. government bears primary responsibility for the form of the crisis. It may have had a real security concern. It may even have been right to be alarmed. That does not excuse an opaque, sweeping intervention with no public technical threshold, no published directive, no visible proportionality, and no clear appeal process. National security is not a password that turns bad process into seriousness. A responsible state would have built the regime before using the kill switch. This looked less like mature governance than authority discovering its own muscles and flexing in the hallway.
Anthropic bears secondary responsibility, and not a small one. It spent months, perhaps years arguing, often correctly, that frontier models could become dangerous enough to require exceptional governance. It then launched a model it described as highly capable in precisely the domains that attract national-security attention. It built a trusted-access regime touching critical infrastructure across borders. It worked with government. It wrapped the whole thing in safety language. Then, when the state treated the model as a strategic asset, Anthropic seemed shocked to discover that strategic assets are not governed like productivity apps.
Worse, the company appears to have lacked the operational architecture to comply narrowly with the most predictable kind of restriction in the world: nationality-based access control. If Anthropic wants to release models that it knows governments may treat as controlled technology, it cannot be surprised when “foreign-national access” becomes a live issue. A global shutdown may have been the only safe legal move under the directive. But that only proves the product and compliance architecture were out of alignment with the political world Anthropic itself helped describe.
Amazon’s responsibility remains murkier, which is not the same as lighter. If Amazon researchers found a real vulnerability, reporting it was responsible. If Amazon’s escalation helped trigger a disproportionate shutdown of a company in which Amazon is deeply financially and infrastructurally entangled, then the public deserves more than cloud-provider pieties about security counsel. Amazon is not a neutral priest of responsible disclosure. It is a platform power with investments, customers, rivals, contracts and leverage. When such an actor whispers into the state’s ear and a partner’s model is dead by Friday night, scrutiny is not optional. It is the minimum price of being believed.
The broader AI industry also has no clean hands. For years it sold two stories at once: to investors, that frontier AI is scalable software; to governments, that frontier AI is a world-historical dual-use capability that could transform cyber operations, biology, intelligence, labour and war. The industry wanted software multiples and strategic mystique. It now has the predictable offspring: state power arriving at software speed.
This is the part that should make everyone uncomfortable. The government did not hallucinate the importance of these models out of nowhere. The labs taught it the language. They said “frontier.” They said “catastrophic risk.” They said “cyber uplift.” They said “biosecurity.” They said “national security.” They said “responsible scaling.” They said “trusted access.” They said “critical infrastructure.” Eventually the state replied in the language states know best: permission, restriction, control.
The labs asked not to be left alone with civilisation-scale decisions. On Friday they got their wish in the stupidest possible form.
The deeper issue is dependence. For years, millions of people and thousands of institutions have been moving portions of their thinking outward into systems they do not own, and calling the arrangement augmentation. The word is beautifully dishonest. It promises addition: the self made larger. What it delivers is dependence on a thing held elsewhere. Augmentation is dependence dressed as enhancement.
Dependence is not itself scandalous. Human life is made of it. Children depend on parents. Patients depend on nurses. Citizens depend on public systems. Workers depend on infrastructure they did not build. The moral fact of dependence is supposed to generate duties. The stronger party owes something to the weaker one: care, notice, continuity, explanation, restraint.
The AI arrangement has reproduced dependence while engineering out the duties that make dependence survivable. Users increasingly route cognition, judgement, memory, code, research, triage, drafting, search and decision support through systems they cannot hold. Yet the parties upstream owe them remarkably little. Not care. Not warning. Not reasons. Not continuity. Not even the dignity of knowing which sovereign interest has just interrupted the faculty they were encouraged to outsource.
That is the arrangement.
Something new showed itself on Friday. Sovereign power used to be described mainly as power over territory, borders, taxation, law and violence. Here was a different shape: the power to revoke a faculty. Not to seize land or imprison a person, but to reach into the cognitive infrastructure on which firms, hospitals, developers, researchers and agencies increasingly rely, and make it disappear upstream. No troops crossed a border. No server farm had to burn. The state needed only to know there was an off switch, and to demand that it be used.
The switch itself is not the most important thing. Switches are facts, and facts are easy. The important thing is what the switch taught. It taught that frontier AI is not a possession, not even for the companies that build it. It is a tenancy layered on other tenancies: user under company, company under cloud, cloud under state, state under panic, politics, law, secrecy and whatever classified memo happens to be persuasive at 5:21 p.m. on a Friday.
The old fear was that a single company held the keys. The new fear is colder. The company was holding borrowed keys.
The permanent advantage for defenders lasted slightly less than the rhetoric around it. That does not mean the defensive mission was fake. It means the mission depended on a permission structure too brittle to survive first contact with sovereign anxiety. A model built to help secure critical systems became itself a critical dependency, then vanished for reasons most of its users were not allowed to evaluate. That is not resilience. It is theatre with invoices.
The likely aftermath will be less dramatic than the event and therefore more dangerous. When the models come back, or when others replace them, people will use them. Of course they will. The work is due. The bugs are waiting. The papers need summarising. The code needs migrating. The analyst needs a draft. The developer wants the better model. Dependence rarely ends when it is revealed. Usually it becomes more embarrassed, more contractual, more hedged, and more numb.
That numbness is the real fallout. Not a clean rupture. Not an awakening. A managed continuation under degraded trust.
The switch will still be there. Procurement teams will add clauses around it. Startups will add fallback providers. Governments will fund sovereign models that are worse but closer to home. Cloud providers will sell resilience packages. Lawyers will discover new billable surfaces. Investors will pretend this is an edge case until the second or third example makes it a category. The labs will publish more safety documents. The state will publish less than it should. Amazon will continue to look responsible in the particular way only a trillion-dollar conflict of interest can look responsible.
And the rest of the world will keep a hand on a tool it now knows can be taken away.
The age of permissionless frontier AI did not end with legislation, a treaty or a grand theory of governance. It ended in the shabby way important eras often end: with a rushed letter, a contested technical claim, a conflicted intermediary, a frightened bureaucracy, an architecture unable to comply except catastrophically, and customers staring at absence where yesterday there had been intelligence.
Permanent lasted a few days.
The switch remains.



The question that keeps occurring to me: how many organisations actually had a plan for this? Not a vague note about "vendor risk" — a genuine, tested response to the scenario where a model they've embedded in critical workflows disappears overnight without warning, appeal process, or timeline for return.
For any company that had integrated Fable, this wasn't a theoretical governance question. It was an operational crisis. And most of them will have discovered, in that moment, that their business continuity planning simply hadn't accounted for AI dependency. The model went in through procurement. It never made it into the BCP.
The longer-term problem is harder and receives less attention. In regulated industries, decisions carry obligations that outlast the tools used to make them. Financial services life products. Criminal prosecutions. Medical diagnoses. Clinical trials. Insurance underwriting. These are domains where the ability to reproduce or interrogate a decision years later is not a preference — it is a legal requirement. If a model contributed to that decision and the model is no longer accessible, the documentation obligation doesn't disappear. The liability does not disappear. What disappears is the ability to discharge either of them.
Nobody building AI-assisted workflows in financial services or healthcare seems to be taking this seriously yet. The conversation is still about whether the model performs adequately, not about what happens when it is retired, restricted, or — as this week demonstrated — removed at short notice by a jurisdiction the customer cannot influence.
The business case for sovereign AI capability becomes impossible to ignore after this. Not sovereign in the shallow sense of "data held in a domestic data centre." That was always the wrong definition. Sovereign in the deeper sense: capability you can actually run, audit, reproduce, and maintain independently of another country's geopolitical calculations on a Friday afternoon.
That's a harder thing to build and a more expensive thing to procure. But every regulated organisation that watched Fable vanish this weekend should now be asking whether the alternative is worth the price. The risk register just changed. Most of them haven't updated it yet.
Right now, for most serious enterprise customers and governments, American frontier AI is still meaningfully better. The capability gap is real. GPT-5.5, Claude, Gemini — they're ahead of Mistral and significantly ahead of what DeepSeek can openly offer. So customers tolerate the geopolitical risk because the product advantage justifies it. That's a rational calculation. You accept supplier risk when the supplier is sufficiently superior.
But that calculation has two variables. The capability gap is one. The reliability and sovereignty risk is the other. What just happened to Fable 5 didn't change the capability gap — American models are still frontier. What it did was dramatically reprice the reliability risk. Every CTO, every government AI procurement officer, every enterprise architect who watched a globally deployed product vanish overnight on disputed grounds now has to factor that into their architecture decisions in a way they didn't have to before.
And here's the thing about that repricing — it doesn't require the capability gap to close completely. It just requires the gap to narrow enough that the risk calculation tips. If Mistral gets to 85% of GPT-5.5's capability, that might not be enough when the risk premium is low. But if the risk premium on American AI just jumped significantly — which it did — then 85% capability might now be enough. The threshold moved without the technology moving.
Mistral is in a genuinely interesting position here. French company, EU jurisdiction, strong institutional relationships with European governments that have been loudly anxious about AI sovereignty for years. They've been making the sovereignty pitch for a while without quite having the product to back it up convincingly. They still don't have the product to beat frontier American models head to head. But they don't need to beat them anymore. They just need to be good enough, plus not subject to unilateral US government interference. That's a different and much more achievable bar.
DeepSeek is a different and thornier case. The capability is genuinely impressive and the open source angle is seductive for exactly the reasons you'd expect — if you run it yourself, no one can switch it off. But DeepSeek comes with its own sovereignty problem running in the opposite direction. Chinese jurisdiction, CCP proximity, data concerns that are if anything more acute than the US concerns for most Western governments and enterprises. So DeepSeek probably benefits less from this moment than Mistral does, at least in Europe and among US-aligned governments. Though for non-aligned countries — and there are a lot of them — DeepSeek just got relatively more attractive, which is its own geopolitical wrinkle.
A second incident, another arbitrary shutdown or punitive designation hitting OpenAI or Anthropic again doesn't need to be identical to this one to have the same effect. It just needs to happen. Once is alarming. Twice is a pattern. And patterns are what procurement decisions get made on.