{"id":374,"date":"2026-06-17T15:00:00","date_gmt":"2026-06-17T14:00:00","guid":{"rendered":"https:\/\/www.auravere.com\/insights\/?p=374"},"modified":"2026-06-17T12:49:48","modified_gmt":"2026-06-17T11:49:48","slug":"tool-today-gone-tomorrow-ai-risk","status":"publish","type":"post","link":"https:\/\/www.auravere.com\/insights\/tool-today-gone-tomorrow-ai-risk\/","title":{"rendered":"Tool today, gone tomorrow"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">On Friday 12 June, at 5:21pm Eastern US Time, Anthropic received a letter from the US government. By that evening, two of its AI models, Fable 5 and Mythos 5, were unavailable to every customer, everywhere, with no advance warning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Five days later, they still are not available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The directive itself was narrower than the outcome it produced. The US government, citing national security concerns, ordered Anthropic to suspend access to the two models for any foreign national, whether inside or outside the United States, including Anthropic&#8217;s own foreign national employees. That is a targeted instruction. What it produced was a global shutdown.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reason for that gap between the order and its effect is worth sitting with, because it is the part of this story that matters most to anyone running enterprise IT.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anthropic could not comply with a nationality-based restriction because it does not have the data to do so. To filter access by nationality in real time, across every customer, every integration, every cloud platform from AWS Bedrock to Google Cloud to Microsoft Foundry, a provider would need to know who its users are at a level of identity verification that most AI platforms are deliberately not built to collect. Anthropic does not appear to maintain that data. That is not a compliance failure. It is, in most other contexts, exactly what privacy-conscious design looks like. You do not collect what you do not need.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Except in this instance, not having it meant there was no way to comply narrowly. The only available lever was to turn the whole thing off for everyone, everywhere, and sort out the detail afterwards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is the moment worth pausing on, because it is not really a story about Anthropic, or about the specific technical dispute over whether a jailbreak existed and how serious it was. Anthropic has stated publicly that the issue it understands the government to be citing is narrow in scope. Other reporting suggests the government&#8217;s position is firmer than that characterisation. Neither position has been independently settled, and it is not the part of this story that we as IT leaders need to resolve.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The part that matters is this: a major AI vendor, serving enterprise customers across finance, healthcare, software, and critical infrastructure, had two flagship products switched off by a government directive, with zero notice, and no published timeline for when or whether access returns.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your organisation had built a workflow, a customer-facing feature, or an internal process around either of those models, you found out it was gone at the same time as everyone else. There was no contractual cure period. There was no negotiated wind-down. There was a letter on a Friday afternoon, and then there was not a product.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Most business continuity plans are not written for this. They are written for the vendor going down. They are written for a data centre outage, a ransomware incident at a supplier, a contract dispute that ends in a managed transition. They are not written for a sovereign government instructing a vendor to disable a product line overnight, for reasons unrelated to the vendor&#8217;s performance, with the vendor itself contesting the justification.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is a different category of risk to the ones most procurement and resilience frameworks were built around. It does not require the vendor to fail. It does not require an attacker. It requires a regulator, in any jurisdiction the vendor operates in, to decide that a capability needs to stop existing for a population it cannot precisely define, and the vendor finding that the only way to comply is to stop it for everyone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not unique to Anthropic, and it is not unique to AI. Export controls have shaped technology availability before, in cryptography, in semiconductors, in dual-use software. What is new is the speed and the breadth. A semiconductor export restriction takes months to bite. A frontier AI model can be switched off in an afternoon, for every customer on every continent, because the entire product is a network call away rather than a physical shipment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organisations least exposed to this kind of event are the ones that built genuine flexibility into how they consume AI capability. Multiple providers where that is feasible. Architecture that does not hardcode a single vendor&#8217;s API into critical paths without an alternative. A clear answer, written down somewhere, to the question of what happens operationally if a core AI dependency disappears without warning.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organisations most exposed are the ones that have not asked the question at all, because eighteen months ago a directive like this would have seemed implausible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is no longer implausible. It happened on a Friday evening in June, to a major vendor, with no notice, and the resolution timeline is still unknown.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The decision has not gone unchallenged. Parts of the security research community have pushed back publicly, arguing that the technical basis for the suspension may not hold up to independent scrutiny. That dispute remains unresolved, and I am not going to adjudicate it here. But it points to a principle that applies well beyond this one case, and it is one every IT leader will recognise from their own organisation: decisions made quickly, on evidence that has not been independently verified, tend to produce consequences that are harder to walk back than the decision was to make. That is true whether the decision is shutting off a software vendor, isolating a network segment, or pulling a product from production. The instinct to act fast is not the problem. Acting fast on a perspective that has not been tested is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The story is not about Anthropic, or about whether the government&#8217;s justification was sound. It is about what belongs in your business continuity plan now that did not belong there before. Tool today, gone tomorrow, is no longer a hypothetical risk category. It is a documented event with a date on it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On Friday 12 June, at 5:21pm Eastern US Time, Anthropic received a letter from the US government. By that evening, two of its AI models, Fable 5 and Mythos 5, were unavailable to every customer, everywhere, with no advance warning. Five days later, they still are not available. The directive itself was narrower than the&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"A major AI vendor had two products switched off overnight by government directive with no notice. Most BCPs were not written for this risk.","jetpack_seo_html_title":"Tool Today, Gone Tomorrow: Enterprise AI Risk | Auravere","jetpack_seo_noindex":false,"jetpack_seo_schema_type":"","_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[25,7,24,60,56,70,4,23],"tags":[26,14,9,71,72,15],"class_list":["post-374","post","type-post","status-publish","format-standard","hentry","category-artificial-intelligence","category-governance","category-information-security","category-it-leadership","category-national-security","category-privacy","category-regulatory","category-security-leadership","tag-artificial-intelligence","tag-cissp","tag-information-security","tag-privacy","tag-risk","tag-security-leadership"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/374","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/comments?post=374"}],"version-history":[{"count":1,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/374\/revisions"}],"predecessor-version":[{"id":375,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/posts\/374\/revisions\/375"}],"wp:attachment":[{"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/media?parent=374"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/categories?post=374"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.auravere.com\/insights\/wp-json\/wp\/v2\/tags?post=374"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}