The US government just proved it can kill your AI infrastructure overnight

On June 12, 2026, the US Commerce Department ordered Anthropic to shut down Fable 5 and Mythos 5 for every user on earth. Three days after launch, the models went dark. API calls returned errors. Every company that had built products on those models lost their AI infrastructure instantly, with no warning and no fallback.
What happened
On June 9, 2026, Anthropic launched Fable 5 and Mythos 5, its most capable models to date. Three days later, the Commerce Department issued an export control directive ordering Anthropic to suspend all access for any foreign national, inside or outside the United States, including foreign-national Anthropic employees. Because Anthropic could not reliably verify the nationality of every user in real time at scale, the only way to comply was to shut the models down entirely.
Both models went offline on June 12-13. Existing sessions ended. Claude Code and Claude.ai defaulted to older models. Andrej Karpathy, one of Anthropic's own senior AI scientists, was barred from accessing the models because he is not a US citizen.
The stated justification was a narrow jailbreak reported to the Commerce Department by Amazon - Anthropic's own largest investor and cloud partner. Anthropic stated the same capability is already available from GPT-5.5 and is used daily by security engineers. The government has not responded to that argument.
The precedent this sets
Before June 12, the idea that a government could force a live, globally-deployed commercial AI service offline overnight was theoretical. It is now demonstrated fact.
US export controls on AI previously targeted physical goods: chips and model weights. The Fable 5 directive is different. It targets a deployed commercial service running on US servers, served via API to users globally. The model weights were not being transferred anywhere. The service was simply made unavailable. This is closer to a product recall than a traditional export control, and it is the first time this tool has been applied to a live AI service at this scale.
The legal authority invoked is broad: "national security authorities" under the Export Administration Regulations. The grounds do not need to be written, formally disclosed, or technically verified before action is taken. A verbal assertion by a third party claiming they found a jailbreak was sufficient.
What this means for EU companies
If your product relies on an American AI provider, your infrastructure is subject to US government veto. This is not a hypothetical risk. It just happened.
| Risk | What the Fable 5 ban demonstrated |
|---|---|
| Service termination | A model can be forced offline globally within 72 hours of launch |
| No technical remedy | The directive was not based on a technical standard Anthropic could meet |
| No due process | The order was issued without written justification or formal disclosure |
| No geographic limit | Foreign nationals inside the US were also barred |
| No provider recourse | Anthropic could not comply selectively, so everyone lost access |
| Competitive asymmetry | GPT-5.5 offers the same capability but was not targeted |
For EU companies, the implications are direct. Under GDPR Article 28, data controllers must ensure processors provide "sufficient guarantees" to meet GDPR requirements. A processor that can be compelled to terminate service overnight by a foreign government does not provide sufficient guarantees. Under DORA Article 11, financial entities must have "ICT business continuity plans" that account for "severe business disruptions." A model shutdown with zero notice, zero migration path, and zero domestic alternative is the definition of a severe business disruption.
The concentration problem
The Fable 5 ban exposes a structural risk that EU regulators have been warning about but that most companies have ignored: AI concentration risk.
When your entire AI capability depends on a single provider's API, you have outsourced your learning loop. Satya Nadella identified this directly: companies that were dependent on Fable 5 as their AI capability, with no proprietary capability of their own, found themselves with nothing when the model went offline. Their AI capability existed entirely in someone else's system.
This is not just a vendor lock-in problem. It is a jurisdictional lock-in problem. Even if you have a contract with the provider, the provider itself is subject to government orders it cannot refuse. Your SLA does not override the Export Administration Regulations.
| Single-provider dependency | Multi-provider resilience |
|---|---|
| One model goes dark, everything stops | Fallback routing continues with other models |
| Subject to one government's export controls | No single jurisdiction controls all paths |
| No migration path when service is terminated | Same API, different backend, zero code changes |
| DORA concentration risk flag | DORA-compliant diversification |
The CLOUD Act dimension
The Fable 5 ban operates through export controls, but the CLOUD Act provides a parallel mechanism. Under the Clarifying Lawful Overseas Use of Data Act, US providers can be compelled to disclose data stored on servers anywhere in the world. The combination is sobering: the US government can both access your data and terminate your service, regardless of where your data is physically stored.
After Schrems II (C-311/18), EU companies were supposed to assess US surveillance risks when transferring data. The Fable 5 ban adds a new dimension to that assessment: not just "can the US government read my data?" but "can the US government turn off my infrastructure?"
What EU companies should do
The lesson from Fable 5 is straightforward: if your AI infrastructure is subject to US jurisdiction, it can be taken away without notice, without due process, and without a technical standard you can meet to restore it.
The structural answer is to ensure your AI inference runs within EU jurisdiction, on EU-incorporated infrastructure, under EU legal framework. This means:
- Using providers incorporated in the EU, operating data centers in the EU, and subject to EU courts rather than US export control orders
- Ensuring Zero Data Retention so that even if a provider is compelled to disclose data, there is nothing to disclose
- Routing through multiple providers so that no single government directive or provider failure can shut down your entire AI capability
- Demanding published subprocessor lists and data processing agreements that are enforceable under EU law
ozeye provides exactly this architecture: EU-only inference with multi-provider fallback routing, Zero Data Retention across the entire network, and an OpenAI-compatible API that requires no code changes to switch providers. The full subprocessor list and data processing agreement are published and enforceable under EU jurisdiction.
The perverse incentive
There is one more layer worth noting. Anthropic was unusually transparent in Fable 5's system card, honestly disclosing its safeguard architecture and limitations. TechCrunch observed that this transparency may have supplied the evidence the government used to justify the ban. Providers that publish less about their models' limitations create less regulatory surface area for government action.
This is a perverse incentive: honesty about safety limitations invites regulatory action, while opacity is rewarded. For EU companies choosing providers, this means that the providers most forthcoming about their risks may be the ones most likely to be targeted. Choosing a provider that is honest about its limitations is ethically preferable but operationally riskier under the current US regulatory dynamic.
The only structural answer is to remove US jurisdiction from the equation entirely.