AI Policy

Washington Proved It Can Switch Off Any AI Model on Earth

Illustration of a global power switch representing US AI export controls over a world map
AI export controls set a precedent the world is still reacting to

Washington used AI export controls to prove, on June 12, 2026, that a single government letter can take the world’s most capable AI models offline for every user on the planet within hours. Nineteen days later it reversed that order, but the reversal did not undo the lesson. The episode, now widely discussed as the first real test of AI export controls applied to a deployed software model rather than physical hardware, left allied governments from Paris to Ottawa to Vienna with the same conclusion: the country hosting the leading AI labs can unplug them from the rest of the world on a private directive, with no hearing, no warning and no vote.

The models affected were Claude Fable 5 and Claude Mythos 5, Anthropic’s most advanced systems, released to the public on June 9. Three days later the Commerce Department’s Bureau of Industry and Security invoked the same export control law that normally targets semiconductors, applying AI export controls to a commercial software product for what specialists say is the first time. The order cut off access for any foreign national anywhere, including the company’s own non-citizen staff. Because Anthropic had no way to verify a user’s nationality in real time, it disabled both models worldwide rather than risk violating the order.

According to Anthropic’s own statement on the directive, the stated trigger was a disputed jailbreaking technique the company said produced only minor findings already achievable on other publicly available models.

Why AI Export Controls Rattled Allies More Than a Simple Product Ban

The scale of the diplomatic reaction is what outlasted the three-week shutdown. French President Emmanuel Macron told a G7 gathering days after the order that the move was a wake-up call about AI dependence, while also describing the reaction to it as strictly nationalist, according to Al Jazeera’s reporting from the summit. Canadian Prime Minister Mark Carney warned that accepting single-country dependence on US AI infrastructure would itself become the mistake if allies failed to diversify. Former UK security minister Tom Tugendhat wrote that the episode showed sovereignty was becoming a matter of code rather than cannons.

These were not routine trade complaints. They were G7 leaders describing a commercial product shutdown in language normally reserved for energy or defence dependence, and every one of them now treats AI export controls as a standing risk rather than a one-off dispute.

That reaction has not faded now that access has returned. Austria has formally asked the European Commission to explore hosting Anthropic within EU borders, arguing that only relocating the legal jurisdiction controlling a model’s access, not the company’s headquarters, would put the kill switch outside the reach of US AI export controls. The proposal is unlikely given how deeply Anthropic’s compute, capital and cloud partnerships are anchored in the United States. But a national government raising it within three weeks of the shutdown shows how seriously European capitals are pricing in the risk of relying on a single supplier for frontier AI.

A Familiar Pattern, Applied to Software for the First Time

Governments outside the US were primed to read the new AI export controls as a pattern rather than an anomaly because a version of this had already played out with hardware. Washington spent much of the past three years tightening and loosening chip rules aimed at China, including the on-again, off-again restrictions around Nvidia’s advanced AI chips, which showed allies and rivals alike that US export authority over compute could be switched on or off depending on the political moment.

What changed on June 12 was the target. For the first time, export authority reached beyond physical chips to control access to a deployed software model, opening a genuinely untested legal question: whether serving an AI model from a US company’s own servers to a customer abroad even counts as an export at all. The timing compounded the anxiety. The order landed one week before the heads of the Five Eyes cybersecurity agencies issued a joint warning that frontier AI would reshape the cyberattack landscape within months, not years.

Read together, the two events told the same story from opposite directions. Intelligence agencies were telling the world that powerful AI had become critical security infrastructure, just as one of those agencies’ own governments demonstrated it could remove a piece of that infrastructure from the rest of the world overnight through a single application of AI export controls.

What This Means for You

If your business runs workflows, products or research on a frontier US model, the practical lesson of June and July is not that the models are unsafe. It is that access itself is now a variable outside your control, subject to a government decision under AI export controls that you will not see coming and cannot appeal. Anthropic has since proposed an industry-wide framework, alongside Amazon, Microsoft and Google, for scoring jailbreak severity so future disputes are resolved against agreed criteria rather than a single unexplained letter, an acknowledgment from inside the industry that the current process left everyone exposed.

Until frameworks like that are tested, any organisation building on frontier AI outside the US should treat model access the way it treats a single supplier relationship in a critical supply chain: worth mapping, worth having a contingency for, and no longer worth assuming is permanent.

The Chilling Effect Is Already Reshaping Where Attention Goes

The clearest sign the precedent outlived the three-week shutdown is where policy attention has moved since. Germany and France’s