Two weeks after the American directive of June 12, access to Fable 5 and Mythos 5 has still not been restored, despite the promise of an imminent return.
On June 12, the US Commerce Department invoked its export control prerogatives, in the name of national security, to prohibit Anthropic from providing two of its most advanced models, Fable 5 and Mythos 5, to any foreign national, inside or outside the United States, including its own non-US employees. Unable to filter its customers by nationality, the company deactivated the two models for everyone that same evening, the others remaining available. This is the first time that export control targets not the chips, but the models themselves.
Two weeks later, access has still not returned. An Anthropic manager assured ten days ago, from Seoul, of a recovery in the coming days. On the thirteenth day, the company’s teams confirmed, on the contrary, zero traffic on the two models and denied the rumors of a return, born from a simple display bug. First lesson for those managing critical dependencies: the duration of an outage of this type cannot be deduced either from the intentions of the supplier or from its public optimism.
The word to remember in this case is not “suspension”. It’s “foreign national”. What triggered the exclusion was neither the customer’s security posture, nor the solidity of their contract, nor their behavior. It is its nationality, that is to say a parameter over which no purchasing or compliance department has the slightest influence.
A variable that the supplier risk analysis does not note
Most third-party assessment systems note what is measured: certifications, service level commitments, data localization, continuity plans. They very rarely note the supplier’s exposure to its own state’s export and sanctions regime. However, it is exactly this variable which has just set access to zero, independently of everything else.
The consequence is uncomfortable. A data residency clause, a well-drafted DPA, a binding SLA do not survive a national security directive taken in the provider’s jurisdiction. The contract organizes the commercial relationship, not the sovereign balance of power which overlooks it. We find the difference, familiar to practitioners, between compliance and resilience: a perfectly compliant, certified and contractually locked relationship can be interrupted overnight by a decision that does not appear in any audit framework. The dashboard remains green until the cutoff.
The emerging outcome is more structuring than the breakdown
This is the point that the last two weeks have made, and it matters more than the incident itself. The official motive has hardened. Initially, the government talked about a simple workaround allowing the model to read a code base and find flaws, which Anthropic describes as a minor and already known flaw that other public models also find. Since then, according to press information to be confirmed, the justification put forward would be of a completely different order, linked to the cyber capabilities of the underlying model. Anthropic strongly contests the framing. But for a decision-maker, the main thing is elsewhere: when a State qualifies a capability as a threat to national security, the measure ceases to be a misunderstanding which dissipates in a few days.
Above all, the path of return that is emerging is not a simple recovery. Anthropic’s new privacy policy, effective July 8, provides for the collection of official identification and biometric data. The likely mechanism is therefore not the lifting of the directive, but access reserved for verified American users, with international users remaining limited to the lower model. As for the cutting-edge model, access now requires a dedicated program bringing together around one hundred and fifty selected partners, major American players and a few Asian manufacturers. Border capacity becomes a club to which the United States holds the door. For a European organization, the question is no longer “when will access return”, but “do we accept a dependency whose access is conditional on nationality and membership in an American program”.
Mensch described the mechanism in mid-May
A few weeks before the cut, Arthur Mensch was interviewed at the National Assembly by a commission of inquiry into digital dependencies. His thesis was contained in one word: lever. Stop thinking of sovereignty as isolationism, and think of it as a balance of power. In a world where you import all of your digital services, you have no leverage over the supplier, and anyone who does not have leverage can have access cut off, which becomes critical for everything related to government and defense. His final words, in front of the deputies, were “vassal state”.
The cyber passage sheds light on what follows. Asked about the dangerousness of the models, Mensch dismissed the fear marketing of an American competitor, presumably the one whose models had just been cut. His argument: this ability to discover vulnerabilities progresses in a linear and predictable way, everywhere at the same time, and its own models find the same flaws. Anthropic is not saying anything different when it points out that other public models do the same thing. The capacity is therefore banal, the control locks nothing, and all that remains of the measure is its exclusion effect, which is very real.
The crypto wars, the same film thirty years ago
This scenario is nothing new. In the 90s, the weapon the United States wanted to keep to itself wasn’t AI, it was encryption. Strong cryptography was on the list of munitions, along with missiles, and exporting good code legally amounted to exporting military equipment. Phil Zimmermann, author of PGP encryption software, was sentenced to three years of federal criminal investigation for arms trafficking, with intelligence explaining that his software was mainly used by criminals. It is, thirty years later, the same register as that denounced by Mensch.
Two details from the era resonate today. In 1995, the RSA algorithm printed on a t-shirt was ammunition that was prohibited from showing to a foreign national. And the browsers were circulating in two versions: an American one in 128 bits, an international one deliberately weakened to 40 bits. Foreigners were entitled to junk encryption. The exit that is taking shape for Fable, full access for verified Americans and an inferior model for others, recreates this divide step by step, identity document and biometrics version. However, these controls ended up failing: the courts recognized the code as protected expression, the restrictions collapsed in 2000, and their only lasting effect was to push development towards openness and to create competitors beyond American reach. This is precisely the bet of Mistral’s open models, which a published file size makes as little recallable as an encryption library.
What this imposes on a European organization
The operational consequence is simple to formulate and costly to process. The supplier’s jurisdiction must become a risk variable in its own right, just like its security posture, and be explicitly included in the assessment of critical third parties. For each strategic dependency, you need to know what happens the day access is cut for a reason unrelated to you: is there an activatable alternative, an open self-hosted fallback model, an abstraction layer allowing you to switch without rewriting everything. And we must now integrate one more hypothesis, which the episode makes credible: a recovery which does not restore you, because it will be reserved for others than you.
The trap is that this work is not done urgently. Looking for an alternative the day after an outage, under constraint and on a timetable dictated by a third party, is no longer sovereignty, it is dependence suffered. Everyone knows the risk, few organizations have financed the redundancy that covers it, because it seems useless until the outage has taken place. This is the classic gap between awareness of a risk and the decision to deal with it: it is never closed by awareness, only by a prepaid decision, or else someone closes it for you by turning off the switch.
There remains a useful irony to keep in mind. The quality of a supplier says nothing about your exposure. Anthropic is the laboratory that refused to supply the US military with fully autonomous weapons systems, causing it to be classified by the Pentagon as a supply chain risk, a label usually reserved for hostile powers. The most scrupulous service provider became in one evening the single point of failure for its European customers. Dependence does not pass through him, it passes through his jurisdiction. As long as the managements have not included this distinction in their governance, sovereignty will remain a discourse that comes out after the breakdown, and the switch will remain on the other side of the Atlantic.