The Vendor Who Disappears
Anthropic's Fable lockout proved a closed AI model can be switched off by a government overnight - for who you are, not what you did. It's a sovereignty risk, not a vendor one.
On June 12, at 5:21 in the evening Eastern time, a directive landed in Anthropic’s inbox. By the end of that night, every company that had built on its newest AI models had no model. Not a breach. Not an outage. Not a price hike, and not a deprecation notice with a year of runway. The US government ordered the vendor to cut off access, and the vendor complied. The engines that thousands of products ran on were simply gone, on a Friday night.
I want to sit with that, because most of how we think about vendor risk doesn’t have a category for it. We vet vendors for security. We check their funding, their SOC 2, their uptime history, their breach record. We do all of that to answer one question: can we trust this company to keep doing its job? Anthropic was doing its job. It is well run, well funded, and about as secure as a software company gets. And the model still vanished. The failure didn’t come from inside the vendor; it came from above it. This wasn’t really a shutdown - it was closer to a rendition: a vendor seized by a government, the legality still being argued in court, and gone regardless of how the argument ends.
This is the kind of risk we know how to diligence in a physical supply chain and somehow forget to in a digital one. And underneath it sits a bigger question than continuity, one most founders have never thought to ask of a software vendor: who actually controls the AI your product depends on?
What actually happened to Fable and Mythos?
Anthropic launched Claude Fable 5 and Claude Mythos 5 on June 9, its most capable models to date. Three days later, on June 12, the US Commerce Department issued an export-control directive ordering the company to suspend access for all foreign nationals, wherever they were located, including Anthropic’s own employees. The stated reason was a reported method of “jailbreaking” the model, which in practice meant asking it to read a codebase and point out exploitable flaws. Anthropic disputed that a narrow, non-universal jailbreak justified pulling a widely used commercial model, but the directive stood.
Here is the part that turned a targeted order into a global blackout. Anthropic had no reliable way to verify a user’s nationality in real time at the model level. So to comply with an order aimed at some users, it had to disable both models for every user on earth. As Time magazine put it, any enterprise that had built automation on Fable 5 lost its engine in an afternoon.
The lockout timeline. Weeks on, there is still no clean “it’s back.”
Weeks later, there is still no straight answer to a simple question: is it back? Reports of a limited, conditional return - gated by nationality, downgraded to an older model, pushed off the standard subscription plans toward pay-as-you-go API access - sit alongside reports that it is still dark. What no one describes is a clean restoration. The reported route back is telling on its own. Anthropic updated its privacy policy to begin collecting government-issued ID and biometrics, the likeliest path to restoring access for verified US citizens. Sit with who that leaves out. It would bring back only Americans, and only the ones willing to hand a private company their passport and their face. Everyone else stays on an older model, or locked out.
It isn’t even clear how that fix reaches the customers who actually built on these models. Fable and Mythos run across dozens of environments - the Claude API, AWS Bedrock, Google Cloud, Microsoft Foundry - where a user’s nationality can’t be checked in real time, which is why Anthropic had to disable everything in the first place. An API key has no passport. A corporate account spread across a dozen engineers, some of them foreign nationals, has no single face to scan. The fix for an access problem turns out to be: prove your nationality, surrender your biometrics, and even then, only if you’re American.
Why no vendor questionnaire would have caught this
Run the Fable lockout through your standard vendor security review and watch it sail through clean. Financials: excellent. Security posture: strong. Breach history: none relevant. Uptime SLA: met, right up until the government intervened. Every box you know how to check would have been green the morning of June 12.
That’s because the security questionnaire measures the wrong axis for an AI dependency. It scores whether the vendor is trustworthy and competent. It has no field for whether the vendor can be ordered, overnight, to stop serving you by a government you have no relationship with. And where a contract addresses export controls or government action at all, it usually does so with a force majeure clause that excuses the vendor and leaves you without the service. The paperwork that was supposed to protect you is the same paperwork that lets the vendor walk away clean.
None of that means the risk is undiligenceable. We do this kind of analysis all the time for physical things. If your systems integrator runs a heavy engineering team in a country at war, you ask hard questions about how they are managing that exposure. If a critical component ships from a single factory in Taiwan, you map the concentration and the geopolitics wrapped around it. That is ordinary supply-chain risk management, and good security teams are fluent in it. We just haven’t pointed it at the AI layer, because a model feels like a utility you switch on rather than a supplier with a country of origin and a government that can reach it.
So the real exposure was never “is this vendor reliable?” It was concentration. One closed model, wired straight into the product, with no path to anything else if it went away. I have watched teams hardwire a single model into the core of a product with no fallback behind it, the same way teams once pinned everything to one payment processor or one cloud region - not out of carelessness, but because it worked and shipping fast mattered more. That is a single point of failure no security questionnaire will surface, because the thing that can break it sits a layer above the company you’re auditing.
Who actually controls your AI?
Not you. And as Fable showed, maybe not even your vendor.
Most of the frontier models a startup reaches for by default - Claude, GPT, Gemini, Llama - sit under US jurisdiction. That isn’t a quirk of any one company. It’s a fact of where these labs are incorporated, and it means a US policy decision can reach through the vendor and touch your product directly. The European labs building sovereign alternatives, like Mistral, exist precisely because that fact has become a strategic problem. When you build on a US model, you are not a citizen of the platform. You are a guest on a visa.
That distinction is the whole point. A visa is permission, granted by a government and revocable by that same government, often for reasons that have nothing to do with you. The companies hit by the Fable order did nothing wrong. Their mistake, if you can call it that, was being foreign, or serving foreign users, while holding a visa they didn’t know they were holding. They followed every rule, and the rules changed between two governments overnight.
This is no longer a fringe worry. In November 2025, all 27 EU member states signed the Declaration for European Digital Sovereignty, formally naming technological dependency as a strategic risk. When the Fable lockout hit, European commentators read it almost unanimously as the wake-up call: dependency means access can be cut off overnight. If you are building outside the United States, or serving customers who are, your access to the best AI is now partly a function of geopolitics you don’t vote in. That is a sovereignty risk wearing a vendor’s clothes, and it belongs on your risk register as exactly that.
What does a real hedge look like?
Architectural, not contractual. You cannot write a clause that overrides an export-control order, so you stop trying to paper over the risk and start engineering around it. The goal isn’t independence. Full-stack AI sovereignty is infeasible for almost anyone, since the stack runs through minerals, compute, energy, and networks no single company controls. The goal is narrower and achievable: remove the single points of foreign-sovereign control from the handful of paths that would sink you if they went dark.
If a visa is permission you can lose, open weights are a passport. The model is yours to run, on your own infrastructure, in your own jurisdiction, and no directive can deport it. That ownership costs you something real: open models trail the frontier on raw capability, and self-hosting carries ops overhead a small team feels. So you don’t self-host everything. You self-host what is existential, and you rent the rest. The Fable shock is precisely why open-weights momentum surged in its wake. Companies looked at their dependency and decided that for the paths they couldn’t afford to lose, they wanted a model they could download and keep.
What should you do this week?
Start with one list: where is a single AI model load-bearing in your product with no fallback behind it? That list is your exposure. Then work it down.
Map the dependency. Know exactly which features die if your primary model disappears.
Add an abstraction layer. Get the model behind an interface so swapping it is a config change, not a rewrite.
Stand up and test one fallback. Not “we could switch in theory.” A second model you have actually run, ideally from a different jurisdiction.
Pick your existential paths. Identify the one or two workflows that justify open weights, and move those to a model you own.
Write the runbook. One page: if the model goes dark tomorrow, who does what, which switch flips, and how fast.
None of this is exotic. It’s the same continuity thinking you’d apply to any critical supplier, finally extended to the AI layer most teams have been treating as a permanent utility rather than a dependency that can vanish.
The guest and the citizen
The Fable customers learned the difference between a guest and a citizen the hard way, on an afternoon’s notice. You can do everything right - vet the vendor, sign the contract, monitor the uptime - and still discover that your standing on the platform was never yours to keep. It was permission, and permission can be withdrawn.
The fix isn’t to distrust your vendor. Anthropic didn’t betray anyone; it got caught between its customers and its government. The fix is to stop confusing a visa for a passport. Build so that the model you rent can vanish without taking your company with it, and own outright the few things you truly cannot lose.
Which of your products would still run tomorrow if your model vendor were ordered offline today? If you don’t know, that’s the first thing to find out.


