2026-06-14OPINION · AIGOVERNANCE · SUPPLYCHAINRISK · CRITICALINFRASTRUCTURE · EXPORTCONTROLS · ENTERPRISEAI5 MIN READ READ
FILED UNDER

Who Controls the Off Switch on Your AI Strategy?

How rapid AI adoption created a supply chain exposure that most boards have not yet named, let alone managed.

The Assumption Your AI Strategy Was Built On Is Wrong

Every enterprise AI roadmap approved in the last two years contains a hidden assumption: that access to frontier AI models is a stable, scalable, commercially governed resource — available when you need it, constrained only by cost and internal adoption speed. That assumption is now demonstrably false.

Last week Anthropic announced it would “abruptly disable” its most advanced models for all users after the US government ordered it to suspend access for foreign nationals on national security grounds. According to The Guardian, the export control directive covering its Fable 5 and Mythos 5 models arrived without specific details of the concern behind it. No warning, no transition period, and no conversation with the enterprise customers whose workflows run on those capabilities. One directive, and the models go dark.

For the thousands of organisations that have embedded US-hosted frontier models into business-critical processes, this is a governance exposure that has not yet been named, let alone managed.

This Is a Supply Chain Risk, Not a Vendor Risk

Boards and risk committees have spent the last several years developing frameworks for third-party vendor risk. Those frameworks ask the right questions — concentration risk, contract terms, data residency, exit clauses. But they were built for a world where vendor failure means financial distress, acquisition, or service degradation. They were not built for a world where a vendor’s product can be switched off by government order, overnight, for geopolitical reasons that your vendor cannot disclose to you and may not fully understand themselves.

That distinction matters. Third-party risk frameworks give you leverage over your vendor. They give you no leverage over the US Department of Commerce.

What happened to Anthropic’s enterprise customers this week is structurally identical to what would happen to an Australian organisation that discovered its critical logistics software was subject to US export controls it had no visibility of. The dependency existed. The risk was real. Nobody had named it as a supply chain risk because the product looked like a subscription service.

Frontier AI models are not subscription services. They are capability infrastructure subject to US sovereign control. Australian organisations need to start treating them that way.

SOCI and CPS 234 Were Not Written for This — But the Obligation Still Applies

Australia’s critical infrastructure legislation and APRA’s prudential standard CPS 234 both require regulated entities to manage material dependencies on third parties. The intent is clear: if something outside your direct control can materially disrupt your operations, you are responsible for identifying it, assessing it, and having a plan.

Neither the SOCI Act nor CPS 234 specifically contemplated that a US export control directive could simultaneously remove access to AI capability across every Australian organisation using a particular model. But that is precisely what happened. The absence of explicit regulatory language does not reduce the exposure — it just means regulators and boards alike are currently under-accounting for it.

For entities regulated under CPS 234, the question is blunt: if your AI-assisted processes — credit decisioning, fraud detection, document processing, customer triage — depend on models that can be disabled without notice by a foreign government, is that dependency disclosed and managed? If the answer is no, that is a gap in your information security capability register, not a theoretical risk for the next planning cycle.

For critical infrastructure sectors under SOCI, the question is whether AI model dependency has been assessed as part of your System Security Plan. In most organisations, it has not, because AI adoption moved faster than risk governance caught up.

The Architectural Problem Nobody Wants to Admit

The enterprise AI market sold itself on simplicity. API access, pay-per-use pricing, no infrastructure overhead. The pitch worked because it was genuinely convenient, and because the organisations buying had not yet thought carefully about what they were actually depending on.

What they were depending on was a handful of US companies, operating under US law, offering capabilities with no real equivalent elsewhere and no contractual obligation to keep serving non-US users once Washington decides otherwise. That is a concentrated geopolitical dependency with the vocabulary of vendor risk management wrapped around it.

The architectural choices made during rapid adoption — hosted frontier models over local deployment, consolidation onto a single vendor’s API, workflows built on the assumption of continuous availability — produced a class of operational dependency that most risk registers have no category for. It is not IT risk, or vendor risk, or cyber risk in the conventional sense. It is supply chain risk, and almost nobody has it written down.

What Boards Should Be Asking Now

None of this is an argument for AI abstinence or a retreat to on-premise systems. Whether to use frontier models is not the live question. Whether your governance has honestly accounted for what using them entails very much is.

A risk committee conducting a real review of AI supply chain exposure has four questions to work through.

Which of our operational processes now have material dependencies on US-hosted frontier AI models, and have those dependencies been assessed for availability risk — not just data risk?

Does our business continuity planning assume AI capability continuity? If those models were disabled tomorrow, which processes would break, how quickly, and what is the recovery path?

Have we disclosed AI model dependency as a material third-party risk to APRA, ASD, or relevant sector regulators where that obligation applies?

Do our contracts with AI vendors contain any meaningful protections against government-directed suspension — and if not, do we understand what that absence actually means?

None of that is material for a future risk workshop. Anthropic’s enterprise customers spent last week working through versions of these questions under duress. You have the option of doing it beforehand.

The Honest Takeaway

AI adoption was sold, and in a lot of organisations internally championed, on the premise that the direction of travel ran one way: capability increasing, access broadening, models improving. That premise shaped investment decisions, architecture and risk appetite alike.

The directive shows that the direction of travel is also set by US national security policy, export control law and geopolitical judgements made in rooms where Australian organisations have no seat and no advance sight.

Anyone who approved an AI strategy on the old premise owes it the same review they would give any other decision resting on an assumption that turned out to be wrong. Not a reversal — the governance, redundancy and disclosure work that the original adoption skipped past.

The risk was there the whole time. Last week just made it impossible to keep not looking at it.

Next dossier
Australian Enterprises Have Open Source Debt They Cannot See →
Engage the author
Adam van Vliet is currently taking on briefs.
Brief Adam
Share