Skip to Content

AI: Power Is Not Governance

22 June 2026 by
Arnaud Couvreur

Power Is Not Governance
What the Fable 5 shutdown reveals about digital dependency, and what Australia and Europe are not yet building

At 5:21 PM Eastern Time on Friday the 12th of June, a letter arrived at Anthropic's offices. It came from Howard Lutnick, the United States Secretary of Commerce, under national security authorities, and it required immediate compliance: suspend all access to Fable 5 and Mythos 5 for any foreign national, whether inside or outside the United States, including Anthropic's own foreign-national employees. No technical explanation was provided. No prior warning had been given. The models had launched three days earlier, after thousands of hours of red-teaming by the US government, the UK's AI Security Institute, and third-party organisations, none of which had surfaced the concern now cited as justification. By Friday evening, both were offline for every customer worldwide.

Within forty-eight hours, former French Prime Minister Édouard Philippe had called for France to "rearm our technological power." A British lawmaker described researchers, hospitals, and companies losing access overnight, and said: "This isn't an AI story. It's the story of every industry we used to lead." In Korea, Singapore, and across the Gulf, institutional investors and government officials quietly confronted a question most had been deferring for years. The Australian legal AI company Isaacus, operating across eight jurisdictions, pledged immediately to double down on self-hostable, air-gapped sovereign deployment. The reactions were geographically uniform because the experience had been: whoever you were, wherever you were, and whatever your government's relationship with Washington, you lost access at the same moment.

The Fable 5 shutdown has been covered primarily as a story about Anthropic, about jailbreaks, about the unusual adversarial relationship between a safety-focused AI company and a defense establishment that wanted fewer constraints on its tools. All of those threads are real. But the most important thing this event says, from where I sit (at the intersection of European regulatory tradition and Australian governance questions), is simpler and more consequential: this was not governance. Countries with the institutional capacity to have drawn that line are about to discover what it costs to leave it undrawn.

Governance has a recognisable architecture. It involves prior notice, stated criteria, proportionality assessment, and the possibility of meaningful challenge before damage is done. Any governance worth the name answers to something outside itself, whether a legislature, a court, or an independent regulator. In a specific case like this (a claimed jailbreak in a deployed commercial model), genuine governance would have required, at minimum, technical disclosure of the identified concern, proportionality assessment against capability already available elsewhere, and a mechanism for challenge before a compliance order with immediate effect. None of those were present in what arrived at 5:21 PM ET. What arrived was an executive administrative order, issued without disclosed technical basis, without process, without right of prior appeal, effective immediately. Anthropic complied, under protest, and stated publicly: "We disagree that the finding of a narrow potential jailbreak should be cause for recalling a commercial model deployed to hundreds of millions of people." That statement changed nothing operationally; the models stayed offline.

The distinction matters because a great deal of AI governance advocacy, including Anthropic's own, has proceeded on the assumption that "more governance" is a straightforwardly safer outcome than the current regulatory vacuum. That assumption deserves examination now. Anthropic spent years building the political and conceptual case for structured state oversight of AI: these systems are powerful enough to cause harm, the state needs legitimate oversight capacity, the industry should welcome rather than resist that capacity. The Trump administration then used exactly that framing (dangerous capability, national security risk, emergency powers) to justify a shutdown that had none of the attributes the safety advocates actually meant by governance. The company's own safety discourse created the legitimacy for state intervention; the state intervened without the constraints the discourse assumed. What some analysts are calling Anthropic's regulation boomerang carries a lesson that goes beyond irony. Advocating for governance while the architecture of governance remains undefined is not a neutral act. The call arrives; the question is who answers it, and on what terms.

The specific legal mechanism used here extends state power into territory it has not formally occupied before, and the extension is worth understanding precisely. The "deemed export" doctrine predates AI by decades. It was designed for physical technology: if you show a foreign scientist your missile guidance schematics inside a US laboratory, you have exported that technology to their home country regardless of geography. Applying this doctrine to a cloud-based AI accessed via API means the state is now treating digital access to a software model as equivalent to handing someone a technical schematic. The practical consequence was that Anthropic's own engineers, born outside the United States and working in San Francisco, were legally barred from interacting with systems they had built. Access to compute in US-based infrastructure, through US-hosted endpoints, is now construed as presence within US export control jurisdiction. For any organisation outside the United States that has embedded frontier AI into operational systems, what happened on June 12th has a specific meaning: they do not hold the infrastructure; they borrow access to it; and that access is revocable at administrative discretion.

The reach of this matters particularly for organisations that believed their geopolitical positioning offered some insulation. It offered none. The Centre for European Policy Network (a Brussels-based policy analysis body) observed that the directive arrived days after new EU technological sovereignty initiatives had been announced, and drew the logical conclusion: whatever Europe's current ambitions, Washington's demonstration of capacity to withdraw frontier AI access overnight carries a message directed at allies as much as adversaries. Frontier AI, the directive confirmed, remains subject to US strategic control regardless of alliance status.

The stakes hovering over this observation were framed with unusual precision by François Miquet-Marty (president of Les Temps Nouveaux and author of a forthcoming study on civilisational transformation) in Les Échos in the days following the shutdown. Drawing on the competing theses of Amodei and Altman alongside the dissenting analysis of Yann Le Cun (founder of AMI Labs, whose recent essays contest the imminence of AI surpassing human cognitive performance across domains), Miquet-Marty identifies a convergence their surface disagreements tend to obscure. Both project AI creating power and wealth differentials of such magnitude that control of these systems becomes the central political question of the coming decades. Two paths then present themselves: regulated distribution of AI's gains across societies and between states, or power rivalries that risk generating conflicts without modern precedent. The real stake, Miquet-Marty writes, is human rather than technological. The printing press accelerated the Protestant challenge to the old Catholic order in the sixteenth century; AI, simultaneously touching security, labour, and institutional power, may recompose societies and geopolitics on a comparable scale. The more immediate danger, on this reading, is not machines eventually achieving dominance over humans, but AI amplifying thoroughly human rivalries between those who control these systems and those permanently excluded from access to them. The question the June 12th directive poses for every government outside the United States is what they are actively building that could constitute a meaningful answer.

Australia's situation deserves specific examination, because the implications here are not abstract. AUKUS (the trilateral security arrangement between Australia, the United Kingdom, and the United States, which carries significant commitments in AI and advanced technology) commits Canberra to deep alignment with US technology development. The Five Eyes intelligence partnership (the signals intelligence-sharing arrangement among Australia, Canada, New Zealand, the United Kingdom, and the United States) runs through the substrate of every serious Australian national security institution. These are real commitments with real value in other domains. But they are alliance relationships, not governance architectures, and the Fable 5 shutdown demonstrated the difference. Australian researchers studying the model, Australian companies running it in commercial products, Australian hospitals piloting it in clinical workflows: all of them lost access simultaneously, on a Friday evening, without warning and without recourse, at the same moment as users in France, India, and Singapore. Alliance status is not a call option on American AI infrastructure. It was never designed to be, and is now demonstrably not.

The backstory of the Anthropic-Washington conflict makes the governance failure more specific, and more troubling. The Lutnick directive did not arrive in a neutral context. In February 2026, Anthropic declined to allow Claude to be deployed for mass domestic surveillance or fully autonomous weapons systems, maintaining the usage restrictions it had built into its models. The Pentagon designated Anthropic a "supply chain risk" three weeks later, a label historically applied to foreign adversaries. Anthropic filed two separate lawsuits, one in California federal court and one in the federal appeals court in Washington DC, characterising the designation as unlawful retaliation for constitutionally protected speech. A federal judge found this characterisation plausible enough to issue a temporary stay while the litigation proceeded. The directive arrived while that litigation was active. The day after Fable 5 went offline, Defense Secretary Pete Hegseth posted on X that "every passing day" proves the blacklisting was "the right move." High-level talks in Washington on Monday produced no resolution.

The question of whether the Lutnick directive was a genuine, urgent response to a national security jailbreak risk, or a continuation of administrative pressure on a company that refused to meet the Pentagon's requirements, is live and legally contested. Anthropic's characterisation of the technical basis is precise: a narrow, non-universal prompting technique, involving asking the model to read a codebase and identify software vulnerabilities, producing capability levels already present in other publicly available models including OpenAI's GPT-5.5. OpenAI, which reached agreement with the Pentagon, has not faced comparable administrative action. That parallel does not establish the retaliation hypothesis as fact, though no honest account of the sequence can simply ignore it.

When executive power is exercised without process, without disclosed technical criteria, and without any mechanism for external verification, the difference between legitimate security action and political punishment becomes impossible to determine from outside the decision. What arrived at 5:21 PM ET was executive discretion, not a governance act, regardless of the language in which it was framed. The fact that Anthropic disagreed publicly, and that litigation continues, changes nothing about the immediate operational reality for every user who lost access.

The contrast with the EU AI Act is sharper than it first appears. The Act is ex-ante: its requirements apply before deployment, through a legislated framework, with defined risk categories, proportionality obligations, and right of appeal. It moves slowly, and its critics argue with some justification that it risks imposing regulatory weight before demonstrable harm has occurred. Some EU analysts, reacting to the shutdown, suggested that Europe should concentrate less on ex-ante rules and more on building sovereign capability, on the basis that real governance power now lives in export controls rather than formal legislation. That observation accurately describes what happened on June 12th. The lesson is that Europe's model only protects European users and companies if the models they depend on are not hosted in jurisdictions where a different model applies. Following export-control logic as a governance model would mean accepting that the standard for intervention is whatever the US executive branch decides, without criteria, at speed, without appeal.

France at least has assets to name: Mistral's foundation models, OVHcloud's compute infrastructure, Scaleway's sovereign cloud hosting. Philippe was right to invoke them, and right to note that invoking them is not enough. The Lutnick directive demonstrated, within forty-eight hours, what sovereignty ambitions are worth in the absence of deployed capability at scale. Australia's situation is more exposed. There is no domestic frontier model operating at comparable scale. The government has invested in AI ethics frameworks, responsible AI principles, and technology partnerships with US infrastructure. These investments describe a disposition toward good practice. A disposition can be overridden by a directive issued at close of business in Washington; capability cannot.

Sovereign AI architecture is more specific than the phrase implies. At minimum, it requires domestic foundation models that sit outside American jurisdiction, sovereign compute at hyperscaler scale (data centres, GPU clusters, hosted infrastructure sufficient for national and institutional workloads without routing through US-controlled endpoints), and procurement frameworks that treat geographic AI dependency as a formal risk category, the way single-vendor concentration is already handled in critical infrastructure governance. Europe has nascent capacity on the first element; neither region has the second at operational scale; and neither has yet embedded the third as a binding requirement rather than an aspiration.

One observation tends to be avoided in coverage framing this primarily as a story about Anthropic. The company that was shut down is also the company that argued most consistently, and with the most technical credibility, that AI systems powerful enough to affect national security ought to be subject to meaningful state oversight. Anthropic designed its models with safety constraints other frontier labs have not applied as stringently, refused to remove those constraints when the Pentagon asked, and has since been designated a supply chain risk, had its most capable commercial models removed from circulation, and entered federal litigation on two fronts simultaneously. The sequence sends a clear message to every other frontier AI developer. Cooperate with state military and surveillance requirements, and you operate without interference. Decline, and you may find your commercial products subject to emergency export controls administered by the same officials whose requirements you declined to meet.

If that reading is correct (and Anthropic's own litigation asserts that it is), the Fable 5 shutdown resolves into something more specific than a national security dispute: the state using power to enforce a particular vision of what AI should be for. That raises a governance question of the first order. For Australia and for Europe, the question is whether their own governance frameworks have anything useful to say when the answer they would give is different from Washington's.

They do not, at present. The town of Évian built its global reputation on a single promise: "Protégeons la vie à sa source" (protect life at its source). Sovereign AI architecture is, in the end, a version of that same question asked in a different register: who actually controls the source, and who has simply been borrowing access to it, on terms that can be revised without notice, at administrative discretion, on a Friday afternoon.


For several years, working between European regulatory tradition and Australian governance questions, I have watched organisations mistake activity for accountability and strategy for architecture. The distinction matters more now than it did last year, and more next year than it does today. I am looking for an organisation ready to treat that distinction as a foundation rather than a footnote. If that describes yours, I would welcome the conversation -> contact

Arnaud Couvreur 22 June 2026
Share this post
When the Org Chart Goes to Work for the Algorithm