RSS Amplifier

The AI Value Gap · Jun 22, 2026

No.32: The Off Switch

0
Sign in to vote or save

The AI Value Gap · The AI Value Gap

The US government pulled Anthropic's Fable and Mythos off the market with an export-control order that nobody can quite explain, two weeks after signing an executive order that promised not to do this exact kind of thing. Anthropic leaders, who had spent this year insisting their models were too dangerous to release, called the move a misunderstanding. This episode confirmed what everyone already knew but had not acted on: frontier AI has an off switch, and unless you’re called Trump the hand on it isn't yours. The only durable response, whether you run a country or a company, is to own the part of the stack you cannot afford to lose.

For three days in June, the most capable AI model in the world (by a margin) was available to anyone with a credit card. Then one of Anthropic’s own investors (spoiler alert: Amazon) made a phone call, and Fable 5 was gone. Pulled not only from American users but from everyone.

Anthropic has made danger, or what it calls safety, central to its pitch. Behind closed doors, Politico reports officials had heard Amodei liken the technology to a nuclear bomb. So when Commerce reached for the bluntest instrument in the cabinet and took the model down, the self-described safety company’s response was that the whole thing was a misunderstanding and the risk had been overstated. When you build your brand on taking the apocalypse seriously, acting wounded when the government takes you at your word is… a tough look to pull off.

This doesn’t mean the execution is easier to defend. Two weeks before the takedown, the administration had signed an executive order that explicitly barred any mandatory licensing, pre-clearance, or permitting regime. What landed is pretty much exactly that in everything but name, minus due process. When I covered that order, I argued mandatory controls were the obvious next step, although the timing has caught me and everyone off guard. With a capability jump this large, strategic control over who gets access and on what terms is far too valuable to leave to a voluntary framework.

Export controls were built for physical hardware, weapons and source code: things that can be shipped, copied, transferred, or handed over across a border. A model queried through a remote service never changes hands. Even sympathetic trade lawyers have struggled to name the authority being invoked for blocking foreign nationals from logging into a cloud service. The “deemed export” framing makes compliance operationally unworkable: you cannot geofence a foreign-born engineer sitting in your San Francisco office, which is why Anthropic had to switch the model off for everybody.

A warning became a Commerce-wide ban inside 48 hours. Andy Jassy, whose company is both an Anthropic investor and a major supplier of its compute, raised the alarm on Thursday night, by some accounts responding to a request for feedback. The government’s “evidence” was an NSA review of findings Amazon had brought to it. Katie Moussouris of Luta Security, the only outside expert to have read the underlying paper, found the alarming "jailbreak" amounted to the model fixing bugs in code: something the guardrails were never meant to block. Some in the White House appeared unaware Fable had any cyber capabilities at all. The official rationale then kept moving… From the jailbreak on Friday it became, by Saturday, China, then Korea on the basis of suspected China ties. Hard to follow, harder to defend.

Whatever the merits, Anthropic’s posture toward Washington has been a strategic miscalculation, and some of the damage here is self-inflicted. But the government clearly abused the moment, and if it is to hold a kill switch over American AI labs, it needs a clear legal basis and actual expertise in the room. It had neither.

Anthropic’s argument, made in language that was clearly not calibrated for the people receiving it, was that perfect jailbreak resistance is not currently possible for any provider. The capability the government found so alarming, the company added, is “widely available from other models (including OpenAI’s GPT-5.5)” and used every day by the defenders who keep systems safe - a defence sitting awkwardly against the marketing, but hey.

A week in, the standoff is thawing. Talks have moved from “fix the jailbreak” to designing a framework that grades the severity of a security flaw. That is a tacit admission from both sides that no model is perfectly secure and that the argument was always about degree. Anthropic’s managing director for international said in Seoul he was “very confident” the models would return within days.

The relief is real but the precedent is far from reassuring. As Dean Ball put it, post-Mythos the United States has an informal licensing regime for AI - no published rules, no firm limits on state power, just a discretion that can be pointed at any lab that becomes inconvenient.

Days later, G7 leaders who came to coordinate against China found themselves asking whether they could still count on access to American models at all.

Amodei used the moment to tell leaders to “resist the temptation to splinter,” and drew open support from Sam Altman and Demis Hassabis, who argued cyberdefence tools should be available to everyone in the room and pushed for a US-led coalition with structured access to frontier models and a chip bloc that excludes China. But a managed-access club means memberships are granted and therefore revocable.

Macron said the episode had “clarified the stakes,” and warned that if Washington can “turn off the switch” from one day to the next, it damages the very US companies leading the race. Modi tied model access to protecting critical infrastructure. Mistral’s Arthur Mensch (who couldn’t have dreamed of a better timing) noted: “when your supply chain is intertwined, can you be sure your counterparts can’t cut you off?” The European mood was, by every account, particularly sour - allies who came to strategise left having pleaded for carve-outs, with the UK’s reportedly denied.

The silver lining: a sovereignty question that was abstract just became concrete. A country’s access to the frontier is a favour that can be withdrawn; a precedent that will certainly outlast this dispute.

Europe has lived this once already with defence. For decades it leaned on the American security umbrella and treated its own military budgets as a top-up to US capability, until Trump’s pressure on NATO and war on its border turned rearmament from a white-paper ambition into real spending. AI sovereignty has sat in the same drawer, the question is what happens now.

Stripped down, sovereignty means independence from the American stack - and by that measure exactly one country has it: China. It built its own the hard way and early: domestic chips, open-weight models, applied AI at the heart of industrial policy, and a homegrown ecosystem for every layer the US dominates elsewhere. China answers to no US export licence, and guards the exits just as hard. When the startup Manus tried to relocate to Singapore and sell itself to Meta, Beijing barred its founders from leaving the country and opened a national-security review; senior researchers at Alibaba and DeepSeek now need sign-off to travel abroad.

Everyone else is on the dependent side of the line, telling themselves a different story about why it won’t bite. The friends of the US are betting that money buys access - Stargate-style infrastructure deals, nationwide ChatGPT rollouts like the UAE’s, enough spend with American labs to earn a seat at the table; the This Week in AI essay points to the “let’s buy GPT subscriptions and call it a policy” club. Europe likes to think it has an angle in Mistral, but its champion leans heavily on American venture capital and even at a ~$20bn valuation it has barely dented the market, for want of the ecosystem that makes a model stick. Below them, everyone else takes whatever the top tier decides to make available.

With a full stack strategy realistically now off the table, the achievable goal is the last mile: the layer that touches citizens directly, in their language and context, with the evals and public-sector knowledge that accumulate on top of whichever model sits underneath. The reason it has to be yours is cultural as much as technical: a model trained predominantly on English-language data carries English assumptions, reasoning styles and defaults baked in at the architecture level, so a government that deploys a foreign model imports a worldview along with the tool. India built UPI without building the smartphone; Kenya built M-Pesa without building the operating system. Sovereign nations must own the part the citizen meets - which happens to be a near-total US dependence as of now:

Owning that layer does not, on its own, stop a cutoff - the Fable lesson is precisely that the engine underneath can be switched off. What it buys you is the ability to change engines. If the interface, custom logic and the institutional knowledge are yours and model-agnostic, a revoked American model means re-pointing rather than rebuilding: run the same workload on an open-weight model you host yourself, a domestic system or a second vendor, and the lights stay on. The insurance: never depend on a single frontier you don’t control.

From Stanford’s 2026 AI Index Report, reproduced by This week in AI who ask: “If AI is a national asset - where is the rest of the world in building the compute and capability to back that claim?”

The logic that applies to governments applies to every organisation that has started to depend on frontier intelligence - which, at this point, means any enterprise. Satya Nadella’s (well-timed) essay, seen 65 million times since it landed this week, is the corporate version of the same argument. It arrives in the middle of Microsoft’s own pivot beyond OpenAI: in-house models and a model-agnostic Copilot. He splits a firm’s value in two - human capital, and the token capital it builds and owns - and argues the winners build a learning loop on top of models that accrue into something a model swap can’t take with it. You can offload a task or a job, he writes, but you can never offload your learning.

Nadella’s warning is blunt: don't let a handful of models capture all the value and hollow out entire industries, the way globalisation hollowed out manufacturing. Ben Thompson's sharper point is that the labs’ economic imperative is to climb up to the user, swallow the usage data, and replace the software layer above them - the layer where Microsoft lives. The warning is therefore a software giant defending its own turf… but Anthropic's own launch behaviour for Fable 5 showed the instinct in miniature: a 30-day data retention forced onto enterprise customers, and an initial plan to degrade Fable when it was used for AI research. A company that will tune its model to serve its own policy preferences is a company you do not want owning your institutional memory.

Operators are already building the alternative. Aaron Levie (Box CEO) calls it the “applied layer”: bridging features between intelligence and workflow, routing between frontier and cheap models on real evals, driving change management through field engineers, building domain-specific go-to-market applications. Gabe Pereyra (Harvey co-founder) translates it into law: own the cognitive loop, a self-improving human-agent system that runs a client matter end-to-end, and as token costs approach labour costs, expect firms to bill for digital intelligence by the token and by the hour.

The intelligence your country and your company are coming to depend on can still be switched off by people whose interests are not yours.

No country will out-compute the US or China. No company will out-spend Microsoft or the big labs. What both can do is decouple their institutional intelligence from any single frontier they don't control - build the cognitive loop, the portable added knowledge, the last mile that survives a vendor change or a policy whim. For enterprises: in practice that means investing in your own infrastructure and orchestration layer, building your own agents, ensuring the data and business logic they run on is kept secure and in-house, and a proprietary application layer built on top of a model router. Vendor lock-in used to mean switching costs and contract friction; in the age of AI it means every institutional insight, every agent you put to work sitting in someone else's system, on someone else's terms. The cognitive equivalent of never writing anything down.

About

I analyse AI progress beyond the headlines, focusing on enterprise execution, incentives, and real-world economic impact.

No posts

Read the original on aminmrini.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.