On June 12, 2026 — just two days after I spoke at the ILA Tech Governance Conference on AI governance — a US government export control directive ordered Anthropic to suspend access to its two most capable models for any foreign national, inside or outside the United States. Effective immediately. No prior notice.

Anthropic complied within hours. Every customer worldwide lost access, not because they had done anything wrong, but because the US government made a decision, and Anthropic had no choice but to execute it.

For boards of directors in Luxembourg and across Europe, that single event should reframe a question that has been treated as a long-term strategic consideration into an immediate governance priority.

The question boards need to answer is no longer abstract: who controls the AI your organisation depends on and what happens when that control is exercised against you?

This is not a hypothetical. It happened last week. And it will happen again.

The Anthropic suspension is the clearest illustration yet of a structural dependency that most European boards have not yet priced into their risk frameworks. That is not a technology risk. It is a geopolitical concentration risk. And it belongs on the board agenda alongside counterparty risk, liquidity risk, and operational resilience.

What Actually Happened And What It Means

The directive arrived at 5:21pm ET on June 12. It instructed Anthropic to suspend all access to Claude Fable 5 and Claude Mythos 5 by any foreign national — including foreign national Anthropic employees. Anthropic could not filter users by nationality in real time. So it shut both models down for every customer globally to ensure compliance.

The practical implication: access was lost instantly with no remediation window, no transition period, and no contractual recourse.

The stated concern was specific: the US government believes a method exists to bypass the model’s safeguards and use it to identify software vulnerabilities. For boards, that detail matters. A frontier AI model potentially exploitable for offensive vulnerability scanning is a direct threat to the very infrastructure your organisation depends on.

What this reveals is the nature of a dependency that most European organisations have built without the board fully understanding what it means when it is tested.

The Warning That Came First

The Anthropic suspension did not arrive without warning. One month earlier, Arthur Mensch, CEO of Mistral AI, appeared before the French National Assembly and delivered a clear assessment: Europe has a two-year window to build independent AI infrastructure before facing permanent technological dependence on the United States.

His exact framing: “In a world where you import all digital services from the United States, you have no leverage against the US.”

Mensch’s warning is not protectionism. It is risk management. The question he is raising — and that boards should now be asking — is whether the efficiency gains from deploying US frontier AI models are being weighed against a dependency risk that has no precedent in traditional vendor management frameworks.

The answer, in most organisations, is no. Because most vendor risk frameworks were not designed for a world where a government directive can suspend your critical AI infrastructure with a few hours’ notice.

A New Question for the Board Decision Framework

In my previous article, I proposed three questions every board should be able to answer before approving an AI deployment: who orchestrates, where are the circuit breakers, and what is irreversible.

The Anthropic suspension adds a fourth question, one that applies not just to new deployments, but to every AI system currently in production: what is the organisation’s exposure if a model or provider becomes unavailable tomorrow — by commercial decision, regulatory action, or government directive? That question has three practical dimensions.

The first is concentration risk. When critical AI workflows depend on a single US-based provider, the operational resilience plan must account for scenarios no SLA covers: government intervention, export controls, or geopolitical disruption.

The second is substitutability. If the primary AI provider became unavailable today, the board should know the fallback, the transition timeline, and which processes would stop. DORA requires operational resilience to be tested: AI provider dependency is no different.

The third is data sovereignty. Where is the data processed, and under which jurisdiction? Sensitive client data, regulatory filings, or proprietary models processed on US infrastructure carry exposure that becomes material the moment that infrastructure is no longer accessible or is subject to foreign government access.

The question boards have been asking about AI is: should we move fast or think first?

This weekend added a dimension that changes the framing. The question is no longer only about the pace of adoption. It is about the architecture of dependency that adoption creates and whether that architecture is one your board has consciously chosen, or one that has accumulated by default.

The most capable AI in the world, deployed without a sovereignty strategy, is also the most concentrated operational risk in your portfolio.

That is a board decision. Not a management default.


Alexandre Castaing is Managing Director of Axon Advisory & Consulting, specialising in digital resilience, AI governance, and regulatory compliance.

#AIGovernance #DigitalSovereignty #BoardLeadership #DORA #EUAIAct #ILA #TechGovernance #OperationalResilience #Luxembourg