2026-06-14OPINION · AIGOVERNANCE · SUPPLYCHAINRISK · CRITICALINFRASTRUCTURE · EXPORTCONTROLS · ENTERPRISEAI6 MIN READ READ
FILED UNDER

Who Controls the Off Switch on Your AI Strategy?

How rapid AI adoption created a supply chain exposure that most boards have not yet named, let alone managed.

The Assumption Your AI Strategy Was Built On Is Wrong

Every enterprise AI roadmap approved in the last two years contains a hidden assumption: that access to frontier AI models is a stable, scalable, commercially governed resource — available when you need it, constrained only by cost and internal adoption speed. That assumption is now demonstrably false.

Last week, Anthropic announced it would “abruptly disable” its most advanced AI models for all users after the US government ordered it to suspend access for foreign nationals, citing national security concerns. According to The Guardian, Anthropic received an export control directive covering its Fable 5 and Mythos 5 models without being given specific details of the national security concern. No warning. No transition period. No negotiation with enterprise customers whose workflows depend on these capabilities. One directive, and the models go dark.

If your organisation is among the thousands that have embedded US-hosted frontier AI models into business-critical processes, this is not a technology story. It is a governance failure waiting to be named.

This Is a Supply Chain Risk, Not a Vendor Risk

Boards and risk committees have spent the last several years developing frameworks for third-party vendor risk. Those frameworks ask the right questions — concentration risk, contract terms, data residency, exit clauses. But they were built for a world where vendor failure means financial distress, acquisition, or service degradation. They were not built for a world where a vendor’s product can be switched off by government order, overnight, for geopolitical reasons that your vendor cannot disclose to you and may not fully understand themselves.

That distinction matters. Third-party risk frameworks give you leverage over your vendor. They give you no leverage over the US Department of Commerce.

What happened to Anthropic’s enterprise customers this week is structurally identical to what would happen to an Australian organisation that discovered its critical logistics software was subject to US export controls it had no visibility of. The dependency existed. The risk was real. Nobody had named it as a supply chain risk because the product looked like a subscription service.

Frontier AI models are not subscription services. They are capability infrastructure subject to US sovereign control. Australian organisations need to start treating them that way.

SOCI and CPS 234 Were Not Written for This — But the Obligation Still Applies

Australia’s critical infrastructure legislation and APRA’s prudential standard CPS 234 both require regulated entities to manage material dependencies on third parties. The intent is clear: if something outside your direct control can materially disrupt your operations, you are responsible for identifying it, assessing it, and having a plan.

Neither the SOCI Act nor CPS 234 specifically contemplated that a US export control directive could simultaneously remove access to AI capability across every Australian organisation using a particular model. But that is precisely what happened. The absence of explicit regulatory language does not reduce the exposure — it just means regulators and boards alike are currently under-accounting for it.

For entities regulated under CPS 234, the question is blunt: if your AI-assisted processes — credit decisioning, fraud detection, document processing, customer triage — depend on models that can be disabled without notice by a foreign government, is that dependency disclosed and managed? If the answer is no, that is a gap in your information security capability register, not a theoretical risk for the next planning cycle.

For critical infrastructure sectors under SOCI, the question is whether AI model dependency has been assessed as part of your System Security Plan. In most organisations, it has not, because AI adoption moved faster than risk governance caught up.

The Architectural Problem Nobody Wants to Admit

The enterprise AI market sold itself on simplicity. API access, pay-per-use pricing, no infrastructure overhead. The pitch worked because it was genuinely convenient, and because the organisations buying had not yet thought carefully about what they were actually depending on.

What they were depending on was this: a small number of US-based AI companies, operating under US law, providing capabilities that no equivalent exists for elsewhere, with no contractual obligation to maintain access for non-US users if the US government decides otherwise.

That is not a vendor relationship with manageable risk. That is a concentrated geopolitical dependency with the illusion of vendor risk management wrapped around it.

The architectural decisions made during rapid AI adoption — choosing hosted frontier models over local deployment, consolidating on single-vendor APIs, building workflows that assume continuous model availability — have created a category of operational dependency that sits outside most organisations’ risk vocabulary. It is not IT risk. It is not vendor risk. It is not cyber risk in the conventional sense. It is supply chain risk, and it is currently invisible in most enterprise risk registers.

What Boards Should Be Asking Now

This is not a call for AI abstinence or a retreat to on-premise systems. That framing misses the point. The question is not whether to use frontier AI — it is whether your governance structures have honestly accounted for what using frontier AI actually means.

A board risk committee conducting a genuine review of AI supply chain exposure should be asking:

Which of our operational processes now have material dependencies on US-hosted frontier AI models, and have those dependencies been assessed for availability risk — not just data risk?

Does our business continuity planning assume AI capability continuity? If those models were disabled tomorrow, which processes would break, how quickly, and what is the recovery path?

Have we disclosed AI model dependency as a material third-party risk to APRA, ASD, or relevant sector regulators where that obligation applies?

Do our contracts with AI vendors contain any meaningful protections against government-directed suspension — and if not, do we understand what that absence actually means?

These are not hypothetical questions for a future risk workshop. Anthropic’s enterprise customers were asking versions of these questions this week under duress. Your organisation has the opportunity to ask them before the next directive lands.

The Honest Takeaway

The AI adoption wave was sold — and in many cases internally championed — on the premise that the direction of travel was one way. Capability would increase, access would broaden, the models would only get better. That premise shaped investment decisions, architecture choices, and risk appetites.

What the Anthropic directive exposes is that the direction of travel is not solely determined by technology development. It is also determined by US national security policy, export control law, and geopolitical judgements that Australian organisations have no seat at the table on and no advance visibility into.

The boards and executives who approved AI adoption strategies have an obligation to revisit those strategies with the same seriousness they would apply to any other situation where a foundational assumption turned out to be wrong. Not to reverse course, but to build the governance, redundancy, and disclosure architecture that the original adoption decisions skipped.

The risk did not arrive this week. It was always there. This week, it simply became impossible to pretend otherwise.

Next dossier
Australian Enterprises Have Open Source Debt They Cannot See →
Engage the author
Adam van Vliet is currently taking on briefs for FY26.
Brief Adam
Share