ao link
Menu
Business Reporter
Business Reporter

Your Business Continuity Plan now depends on someone else's AI export policy

Few businesses have a playbook for a government switching off the AI model their business runs on. Uditha Atukorala at Felk explores a problematic issue

Linked InXFacebook

Every security leader I know has a plan for what happens when the internet goes down, when a supplier gets breached, or when ransomware locks up the file server on a Friday afternoon. We drill for these things, insure against them, rewrite and playbook once a year. 

 

Almost none of us have a plan for what happens when a government switches off the AI model our business runs on.

 

That sentence would have sounded paranoid a year ago. It doesn’t anymore. On 12 June 2026, the US Commerce Department ordered Anthropic to cut off access to its newest AI models, Claude Fable 5 and Mythos 5, for every non-US national on the planet, effective immediately, with no advance warning. Anthropic had no reliable way to check every user’s citizenship in real time, so it pulled both models for everyone, everywhere, until the order was lifted eighteen days later. Businesses that had built workflows, products, and customer commitments around those models simply lost access, overnight, by regulatory decree rather than any failure of their own.

 

I don’t think this was a one-off. I think it’s a preview.

 

 

A new kind of single point of failure

I spend my working life thinking about operational resilience, because that’s what cybersecurity actually is underneath the jargon: making sure the things your business depends on keep working when someone or something tries to stop them. We’ve gotten reasonably good, as an industry, at planning for attackers. We are not remotely prepared for the idea that the dependency itself — the AI model sitting at the centre of your product, your support desk, your engineering pipeline — could be switched off by policy rather than by an adversary.

 

Look at what happened to Jaguar Land Rover last year. A cyber-attack in September took its systems down for five weeks. The Cyber Monitoring Centre now estimates the UK economic impact at somewhere between £1.6 and £2.1 billion, and recently JLR confirmed hundreds of UK job cuts as it continues digging out from under the recovery costs. That is what happens when an operationally critical system disappears from under a company with no warning. Nobody in that story has a “the regulator did it” excuse to fall back on, but the operational shape of the disaster — sudden, total, unplanned loss of a system the business had quietly become dependent on — is exactly what happened to every non-US Fable and Mythos user in June, just for a policy reason instead of a criminal one.

 

The difference matters less than you’d think. Your customers don’t care why your AI-powered support system went dark. They care that it did.

 

 

The sovereignty question nobody’s budgeted for

There’s a bigger question sitting underneath this, and it’s one I think European businesses have been slow to take seriously: whose model are you actually running on, and what happens to your business if that company’s home government decides it doesn’t like where the model is going?

 

Most European companies are almost certainly dependent on a US frontier model, because that’s where the capability has been. The June episode showed that dependency comes with a rider nobody reads: a single US regulatory order can suspend access for the entire non-US world in an afternoon. That’s not a criticism of Anthropic’s compliance — it did what it was legally required to do, fast. It’s a structural observation about building your business on infrastructure a foreign government can switch off with a letter. 

 

The alternative isn’t obviously better. Chinese open-weight models have gone from a curiosity to genuine infrastructure with startling speed — by some measures they now account for the majority of tokens processed on major model-routing platforms. For a nervous UK or EU company, it can look like an escape hatch, but it swaps one set of unknowns for another: different data handling norms, different government relationships, and no way to verify what a foreign-government-adjacent model is doing with the data flowing through it. I won’t pretend to know whether a regional variant could someday be tuned to behave differently outside its home market — nobody has shown me evidence of that today. But the incentive is there on both sides of the Pacific, and “we’ll find out eventually” is not a security strategy.

 

To be fair to the US side of this story: the stated rationale for the Fable/Mythos order was a jailbreak finding that suggested the model could be prompted into producing security-relevant exploit code. Whether that justified a total, unannounced, worldwide suspension is contested — Anthropic itself pushed back, arguing the same technique worked on several other, unrestricted models. I don’t think the answer is “governments should never intervene in frontier AI.” I think it’s that nobody — not the companies, not their customers, not the governments intervening — has a clear, predictable process for how that intervention happens.

 

That unpredictability is the real risk, and it’s already spreading: That unpredictability is the real risk, and it’s already spreading: the White House separately asked OpenAI to limit release of its next model to a small number of vetted partners, suggesting a pattern rather than a one-off.

 

 

What I’d actually do about it

I’m not writing this to sell doom. The practical response is more boring, and more achievable, than the geopolitics suggests.

 

First: know your dependency. If a frontier AI model sits anywhere in your critical path, write down what breaks if it disappears for three weeks, the way Fable did. Most companies have never done this exercise for AI the way they’d do it for a cloud provider.

  

Second: build in a fallback, even a degraded one — a secondary model provider, or just knowing which processes revert to manual and how fast.

 

Third: invest in the people, not just the tooling. Every business I’ve seen get hit hard by an incident gets hit hard because nobody knew what “normal” looked like well enough to notice things going wrong — the same blind spot that let JLR’s five-week shutdown cascade through 5,000 other UK businesses. Training your team to understand the systems they depend on is the cheapest resilience investment most companies aren’t making.

  

The Fable episode will fade from the news cycle within a few weeks. The underlying condition it exposed won’t. AI models are becoming as operationally critical as the cloud was a decade ago, and we’re collectively about a decade behind on planning for what happens when access to one gets pulled. I’d rather start now, while the stakes are an inconvenient three-week gap, than after they’re a £2 billion one. 

 


 

Uditha Atukorala is CEO of Felk, a Cyber-security as a Service (CSaaS) provider helping fast-growing SaaS companies stay secure, compliant, and enterprise-ready

 

Main image courtesy of iStockPhoto.com and Just_Super

Linked InXFacebook
Business Reporter

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Business Reporter

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@business-reporter.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543

Close