On June 12, 2026, Anthropic officials got a phone call from the U.S. government with an extraordinary message: take its newest AI models offline in 90 minutes.
The government cited a national-security threat involving Claude Fable 5 and Mythos 5. According to Axios, Anthropic was told at roughly 1 p.m. ET to roll back the models or face licensing restrictions. Later that afternoon, Anthropic says it received a formal export-control directive prohibiting access to the models by any foreign national, whether located inside or outside the United States, including Anthropic’s own foreign-national employees.
There was an immediate practical problem.
Anthropic had no reliable way to determine the nationality of every person making an API call.
So it did the only thing it could do to ensure compliance: it shut the models down for everyone.
One moment, companies around the world could build products and workflows on one of the most capable AI models available.
A few hours later, they couldn’t.
The government lifted the restrictions 18 days later, and Anthropic restored global Fable 5 access July 1 after implementing additional safeguards, including a classifier designed to block the behavior that had triggered the government’s concern.

There are plenty of interesting questions about whether the government was right, whether the restriction was proportionate, and what standards governments should use before ordering a frontier model offline.
If you are a company using AI rather than building frontier models, there is another critical question:
What would you have done if Fable 5 had been running your most critical business functions?
AI Models Are Becoming Infrastructure
For the past few years, companies have considered AI models like software vendors.
You evaluate OpenAI. You evaluate Anthropic. Maybe Google. Maybe an open-weight model. You run a bake-off, pick the model that performs best, negotiate pricing and security terms, integrate the API, and move on.
That mindset is inadequate.
As AI becomes embedded in underwriting, fraud detection, customer service, coding, research, document review, compliance and operations, models function less like software and more like critical infrastructure.
Sure, critical infrastructure fails.
Cloud regions go down. Telecommunications networks fail. Data centers lose power. Banks lose payment processors. Cyberattacks disable systems. Vendors go bankrupt.
We’ve spent decades learning how to design around these risks with backups, continuity plans, availability zones, and simulated attacks.
We don’t do this because we expect catastrophe every Tuesday.
We do it because building a contingency plan during the catastrophe is far costlier than planning ahead.
AI should be treated the same way.
The Anthropic episode revealed a new category of enterprise risk: Model availability risk.
Model availability can disappear for reasons having nothing to do with whether the vendor’s servers are working.
We learned that a model can be operational but legally unavailable.
Your Best Model May Not Always Be an Available Model
Imagine that your company has spent 18 months building an AI agent around one model.
You’ve optimized the prompts, tuned retrieval, built evaluation datasets, created guardrails, and trained employees.
Compliance approved it. Security approved it. Your customers are using it.
Then, somebody walks into the CIO’s office and says:
“We have 90 minutes.”
What happens next?
For many companies, the answer is uncomfortable.
Switching to a different model on the fly won’t work for many reasons. So, how does a company prepare?
Multi-Model Should Become the AI Equivalent of Model Disaster Recovery Plan
The solution isn’t necessarily to route every request randomly between five AI providers.
Different models have different capabilities, economics, latency profiles and security characteristics. Standardizing everything around the lowest common denominator can sacrifice some of the advantages that made you choose a particular model in the first place.
But organizations running important AI workloads should know something much more basic:
If our primary model disappeared tomorrow, where would we turn?
That requires continuous evaluation of multiple model families rather than a one-time vendor selection.
If Anthropic is your primary provider, perhaps OpenAI is your secondary. If OpenAI is primary, perhaps Google or Anthropic is the fallback. Some organizations may want an open-weight model hosted in their own environment as an additional layer of resilience.
It’s not important which combination you select, but rather that the alternative has already been tested.
Your organization should know whether the substitute model can perform the task, how much performance deteriorates, which workflows break, whether compliance controls still function, and how quickly traffic can be redirected.
Think of it as a Model Disaster Recovery Plan.
Five questions you must answer in your Model Disaster Recovery Plan
A mature plan should answer five questions.
What is our fallback model? Every material AI use case should have a designated alternative rather than a vague assumption that “we could probably use another LLM.”
Have we actually tested it? Run the same evaluation suite against your primary and backup models. Know where the backup performs better, where it performs worse and where it simply cannot substitute.
Can we switch technically? Abstract model calls wherever practical so applications aren’t unnecessarily welded to the syntax, tools or proprietary features of a single provider.
Can we switch legally and operationally? Security reviews, data-processing agreements, privacy assessments, model-risk reviews and procurement approvals shouldn’t begin for the first time after your primary model disappears.
How quickly can we recover? The relevant metric may eventually look a lot like the recovery-time objectives companies already use in business continuity planning: if Model A disappears, are you back online in 90 days, 90 hours, or 90 minutes?

Regulated Industries Should Pay Particular Attention
Suppose an AI system helps generate adverse-action reasons, investigate suspicious transactions, assist call-center representatives, or perform compliance reviews.
Switching models isn’t merely an engineering decision.
The substitute may need to satisfy the same validation standards as the original. Its outputs may need to be tested for accuracy, consistency, explainability, fairness, privacy and regulatory compliance.
That creates an awkward possibility.
A company may have technical redundancy without compliance redundancy.
The engineering team can switch models in an afternoon, but risk and compliance cannot approve the replacement for six weeks.
That isn’t disaster recovery.
A serious AI resilience program must test the whole system around the model, and not merely whether another API returns an answer.
Concentration Risk Is Coming to AI
There is a broader issue here.
Most enterprises aren’t training frontier models. They are renting intelligence from a relatively small number of companies.
That creates enormous efficiencies. It also creates concentration risk.
Your AI provider can suffer an outage, change its pricing, change a model, retire a model. A cloud partner can stop carrying it, a regulator can restrict it, a government can impose export controls. Or a national-security concern can suddenly transform yesterday’s production architecture into today’s prohibited dependency.
The lesson of June 12 isn’t that companies should distrust Anthropic.
In fact, the same underlying risk applies to virtually every frontier-model provider.
The lesson is that dependence on any single model is dependence on a system you do not entirely control.
That deserves the same sort of resilience planning companies already apply to cloud computing, payments, telecommunications and other critical technology infrastructure.
Don’t Write the Model Disaster Recovery Plan During the Disaster
There is an old principle in emergency management: the middle of the emergency is a terrible time to design the emergency plan.
The Anthropic shutdown provided an unusually vivid demonstration.
The initial government demand reportedly gave one of the world’s most sophisticated AI companies roughly 90 minutes to react. The formal restrictions ultimately made the models unavailable globally because there was no practical mechanism to distinguish permitted users from prohibited ones.
We can’t predict which company or technology will fall victim to the next incident, but the specific failure mode almost doesn’t matter.
What matters is whether your organization has already answered the question:
If the AI model we depend on disappears tomorrow, what do we do?
Because one day, you may not get six months to figure it out. You may get 90 minutes.



