Enterprise Field Notes · Issue #13

Two AI Models Went Dark Worldwide in June. Yours Could Be Next.

The model your company runs on is no longer a technology choice. It is a political one, and it can be switched off by people you will never meet. Here are the four moves that keep you running when it is.

By Ben Pickett · July 16, 2026

New here? Subscribe to Enterprise Field Notes, one new issue every week.

Draw the models you run on. Circle the one you cannot replace. That circle is your exposure.
Draw the models you run on. Circle the one you cannot replace. That circle is your exposure.

By Ben Pickett

It was a phone call. People do not pick up the phone for a passing thought. He spent his career in telecom, back when the argument was about whether the company that owned the pipe should get to decide what flowed through it. We landed, mostly, on no. The pipe stays neutral. Nobody at the middle of the network gets to pick which traffic wins.

That decision is easy to take for granted, so it is worth saying what it bought us. The internet became the thing it became because access to it was open and permissionless. A student could launch something from a dorm room and reach the same audience as a company with a building full of lawyers. No gatekeeper got to decide, in advance, which ideas deserved a connection. Almost everything we now call the modern economy grew in that open field. Take the field away and you get a smaller, more permissioned internet, shaped by whoever owns the gates.

Let me be honest about the analogy, because my friend was the first to poke at it. Net neutrality was a rule we forced onto the companies that owned the pipes, telling them not to play favorites with other people’s traffic. What is happening to AI is almost the reverse, a maker restricting its own product under government and security pressure. The mechanism is different. The shape is the same. While the technology is young and still deciding what it will be, a few large actors are quietly deciding who gets to use which parts of it. I set the thought aside and wrote about something else. Then in June made it impossible to ignore.

A strange few weeks

Any one of these is a headline. Together they are a pattern.

In June, a US export-control order restricted access to two of Anthropic’s frontier models, Fable 5 and Mythos 5. In a June letter to the US Senate, Anthropic accused entities affiliated with Alibaba of using tens of thousands of fraudulent accounts to pull capability out of its models at scale. Weeks later, in July, Alibaba classified Anthropic’s Claude Code as high-risk software and told its people to stop using it, after researchers found the tool inspecting a user’s environment in a way that could flag Chinese users. Anthropic said that code was a spring anti-abuse experiment aimed at resellers and distillation, and that it had already been replaced. Then, around July 7, China’s Ministry of Commerce sat down with its own leading model makers, including Alibaba and ByteDance, to discuss restricting overseas access to Chinese AI, including models not yet released.

I am not going to tell you who is in the right, and I want to be careful, because I have readers and colleagues on every side of this and a team that spans several countries. I will only point at the shape. Anthropic has a genuine distillation problem to defend against. Alibaba has a genuine reason to distrust code that fingerprints its users. Governments have real security concerns on both sides. Nobody has to be the villain for the outcome to land on you.

It already lands on you

If that sounds abstract, it is not. Anthropic had just launched Fable 5, a new frontier model, when a US export-control order pulled it and Mythos 5 both. Anthropic said it could not reliably tell foreign users from domestic ones in real time, so rather than gate access user by user, it switched the models off for everyone. One export order, two frontier models, every enterprise on earth, dark for nearly three weeks. Not one of those companies had done anything wrong. Canada’s prime minister, Mark Carney, called it a warning about depending on a handful of American providers. AI, he said, has become a utility, like the power grid, and it is never a good idea to have one option. European executives said the quiet part out loud almost immediately: Orange told Reuters the episode made “patently clear” how important it is to have AI that Europe can control and that will not be “switched off on a whim.”

Go back a year and it runs the other way just as easily. After DeepSeek’s breakout, the model was pulled from government devices by more than a dozen US states, the Navy, and NASA, then by Australia and Taiwan, and inside companies like Microsoft and Toyota. Whichever direction you think your risk comes from, someone has already been told: stop using that model, today.

How a reliability person reads this

My work has been in reliability engineering, leading the teams whose whole job is keeping large systems from falling over. You learn to see the world as a set of dependencies, and to ask about each one the same rude question. What happens the day this goes away, and how fast can I stand back up without it. So this newsletter is me asking that question out loud about the whole AI supply chain, because the honest answer for most companies right now is that they have no answer.

For most of the last few years, being able to switch models was a nice-to-have. You did it to save money, or to grab a few points of quality on a task. The teams that hard-wired one vendor’s API into everything were optimizing for a world that held still. That world is not holding still. When a model can be pulled by an export order or a corporate ban made an ocean away, the ability to move off it turns into something bigger than efficiency. It is continuity planning, the same category as a backup site or a second supplier, and it belongs in that binder.

The only neutrality you can actually guarantee is your own.

So what do you actually do

This is the question my friend and I circled for an hour, and it has real answers. None of them is exotic, and you can build all of them yourself.

First, stop calling one vendor’s endpoint from a hundred places in your code. Put a routing layer in between, so that changing models is a configuration change rather than a rebuild. The companies that designed this in from the start have swapped providers with a fraction of the effort of the ones that wired themselves to a single API. The migration bills people quietly eat when they have to move later are not small.

Second, keep a real second model, from a different vendor and, the part in June underlined, a different country. One you have actually tested carrying your load, run in anger against real traffic. This is already normal at scale. Executives at Siemens, Renault, and Orange told Reuters they deliberately run a mix of American, Chinese, and European models so no single provider can strand them. Siemens runs models from DeepSeek, Alibaba’s Qwen, and Nvidia’s Nemotron alongside others; Renault mixes Google, Microsoft, Mistral, and DeepSeek. These are not hobby projects. They are hedges built on purpose.

Third, hold one open-weight model you can run yourself. This is the one nobody can revoke, because the weights sit on your own hardware. It is more work to stand up than calling an API, which is exactly why you do it before you need it rather than during the week you lose your primary. It does not have to be your daily driver. It has to be the thing you fall back to when a model you rent is taken off the table by someone else’s government.

Fourth, put it in the contract. The right to export your data and everything you have built on top of it, on demand and in a usable format, not as a favor granted at the end. Portability you cannot actually exercise is worth very little.

I should disclose an interest, because leaving it out would be exactly the move I distrust in other people. The company I helped start, Swa, works on model portability. That is my bias, on the table. It is also the reason I have spent the last year thinking about this problem, and every one of those four moves stands whether you ever look at what we make or not. The principle underneath them is not for sale: do not let anything you cannot run without live at a single address that a stranger is allowed to close.

One thing to do this week

Take ten minutes and a single sheet of paper. Draw the models your business runs on, one box each. Next to every box, write the name of the alternative you have actually tested carrying that load. Most boxes will have nothing beside them. Those blanks are your exposure, drawn to scale, and now you can see it.

Then pick the box you would least want to lose, and put a number on it. If it went dark tomorrow, still working perfectly, because a government or a vendor decided you could no longer use it, how many days until you were running on the alternative. If there is no number, because there is no alternative, you have just found this week’s work.

My friend helped keep the middle of the network neutral, and mostly we won, and then most of us forgot why it mattered. AI may not get the same ending. The blocs are already forming, and you and I do not get a vote on whether the field stays open. The only neutrality you can actually guarantee is your own, the ability to put one model down and pick up another without rebuilding your company around it. The firms that come through the next few years intact will not be the ones that bet on the right model. They will be the ones that never had to.


References

  1. Alibaba classifies Claude Code as high-risk and directs staff to its own tool. TechCrunch, “Alibaba reportedly bans employees from using Claude Code”.
  2. The Alibaba ban, the environment-inspecting code, and Anthropic’s explanation. CNBC, “China’s Alibaba bans Anthropic AI for employees after ‘distillation attack’ accusation”.
  3. China weighs restricting overseas access to its most advanced AI models. Fortune, “China mulls limiting foreign access to advanced AI models”.
  4. US export-control order disables Anthropic’s Fable 5 and Mythos 5 worldwide. Forbes, “Anthropic disabled Fable 5 and Mythos 5 after a US export-control order”.
  5. Canada’s Prime Minister Mark Carney warns the restrictions show the danger of over-relying on a handful of American AI providers, comparing AI to a utility. Fortune, “Canadian Prime Minister Mark Carney warns U.S. restrictions on new Anthropic AI models show danger of relying too much on American providers”.
  6. European firms spread AI risk across US, Chinese, and European models; Siemens, Renault, Orange, and the “switched off on a whim” quote. Reuters, “US curbs on AI spur European firms to spread the risk”.
  7. Governments and companies restrict DeepSeek. TechCrunch, “DeepSeek: the countries and agencies that have banned the AI company’s tech”; Al Jazeera, “Which countries have banned DeepSeek and why?”.

About the author

I'm Ben. I write Enterprise Field Notes, and by day I'm COO at Swa, after years running reliability, data protection, and database operations at Nike. The lesson that keeps proving itself: anything you cannot run without, and cannot walk away from, is a risk you have not priced yet. What is yours?

Header artwork generated with Swa.

Read more of Ben's Enterprise Field Notes at benpickett.com.