In June, Anthropic released two new AI models. Days later, the US government ordered the company to cut off access for all users outside the country, citing national security concerns. Anthropic lacked reliable methods to verify user locations, so it suspended the models entirely, including for American customers. Two and a half weeks later, the controls were lifted for one model, while the other remains restricted to approved US organizations.
The June Shutdown and Its Aftermath
That sequence of suspend, restore, and partial restriction is a reference point for discussions about AI sovereignty. However, the mistake would be treating it as an isolated event tied to one vendor and one month. The pattern was already visible before June: critical AI capability is concentrated among a small number of providers whose commercial, policy, or regulatory position can shift with limited warning.
Export control regimes on frontier AI are not yet settled. Several governments have accelerated sovereign AI investments in recent months rather than waiting to see whether such risks repeat. For businesses, the practical lesson is not to predict the next disruption but to assume that AI access, functionality, and governance requirements will keep evolving, sometimes abruptly.
Why This Matters
The real impact of this episode extends beyond Anthropic and June. It exposes a fundamental vulnerability for any organization that has embedded AI tools into critical processes. When a single government order can force a vendor to restrict access globally, businesses lose control over their own operations. This risk is amplified by the lack of independent oversight. After the export controls were lifted, Anthropic and the US government agreed on future risk flagging, but terms were set behind closed doors. OpenAI's response to its own security incident followed a similar pattern of self-regulation.
Businesses cannot rely solely on vendor or government assurances. They need their own capability to question what they are told. Initiatives like the International Network of AI Safety Institutes aim to provide independent validation, but these bodies remain government-led and not yet mature enough to replace corporate due diligence.
Building Resilience Through Visibility
The starting point for resilience is visibility. Without a complete inventory of AI technologies across the organization, securing or governing them is impossible. Adoption often happens department by department, officially or not, with data flowing without central records or controls. This is the gap that events in June exposed most clearly.
For each AI tool in use, a working inventory must answer these four questions. That last point is the one the June events exposed most acutely. Organizations that could answer those questions were in a materially better position than those still working it out as the news broke. Visibility of this kind turns a scramble into a known, manageable problem around which parts of the business are affected.
The fundamentals of security and a tested business continuity plan will matter more than anything else in the coming months. Regulation remains highly unpredictable, and the only thing properly within a security leader's control is how well they have covered the basics of visibility and governance.



