A darkened server room lined with network racks.

What Anthropic Taught Us About Digital Sovereignty

Niclas Hedam

PhD, Computer Science

· 9 min read · 5 sources · Corrected 17 July 2026

  • On 12 June 2026, US national-security authorities ordered Anthropic to suspend Fable 5 and Mythos 5 for every foreign national, including its own foreign staff. Anthropic switched the models off for all users, which was the easiest and the most sensible way to comply.
  • The capability that got the model banned, reading a codebase to find its security flaws, is the one defenders use to find the hole before an attacker does. Pulling it does not close those holes. It leaves them sitting there, in everyone's software at once.
  • Washington spent years warning that a state could reach into a private tech company and bend it across borders. The lesson of 12 June is that the risk was never unique to rivals: an ally can hold the same off-switch, and just did.

I work with defensive security in government, and a lot of that job comes down to one unglamorous question: what can an institution safely depend on, and what can it not? You weigh a system, a vendor, a supplier, and decide whether the organisation can afford to lean on it. It is slow work, done one piece at a time, and you tend to notice it only when the answer turns out to be wrong. This month, the answer was handed to all of us at once, in a single letter none of us had any part in.

In the name of national security, a NATO ally switched off a tool that security professionals all over the world had started to rely on, and drew the line so that everyone outside the United States — my own country, a decades-old ally, included — came down on the wrong side of it. Not an adversary. An ally.

The Letter

On 12 June 2026, at 5:21pm Eastern, Anthropic received a letter from US national-security authorities ordering it to suspend access to its two most capable models, Fable 5 and Mythos 5, for any foreign national, inside or outside the United States, including Anthropic’s own foreign-national staff. The reported trigger was a jailbreak, which on inspection turns out to mean asking Fable 5 to read a codebase and point out the security flaws in it. In other words, code review.

The order named foreign nationals. Anthropic switched the models off for everyone, which is both the easiest thing to do and, in fairness, the most sensible, because you cannot reliably sort a global user base by passport between one afternoon and the next. So a rule aimed at non-Americans took the tool from Americans too, the same day, and the company complied while saying plainly that it disagreed.

The flaw was demonstrated by researchers at Amazon — at once a major investor in Anthropic and one of its competitors — and Amazon’s chief executive raised it with the White House shortly before the directive arrived. That is the fullest account of the trigger, but not the only one; the details are still disputed.

Statement on the US government directive to suspend access to Fable 5 and Mythos 5 — Anthropic’s account of the directive it received on 12 June, ordering it to suspend access for any foreign national, including its own foreign-national staff, over a jailbreak the company describes as narrow and tied to a small number of already-known, minor vulnerabilities.

U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals — Reporting on the order, including competing accounts of what prompted it: research by Amazon and concerns its chief executive raised with the White House, a rival description of the tester as an unnamed trusted partner, and a separate report tying the decision to fears of access by a group linked to China.

What They Actually Banned

What they banned is, in the end, a defender’s tool. A model that reads code and flags its weaknesses is, pointed at your own software, just how you find the hole before an attacker does. And the capability was never Fable 5’s alone: point any capable model at a codebase and it will do much the same. So the ban does not take the technique out of the world. It takes it away from the people who follow the rules, and leaves the holes sitting there for everyone who does not.

Who Got to Decide

But the security details are almost beside the point. The part worth sitting with is who got to make the call. I wrote about this a few weeks ago, after a security conference where not one serious vendor would let me run their product on-prem, and the name for the worry was, among other things, digital sovereignty. It was easy, then, to treat as theoretical. The CLOUD Act has let Washington compel American providers for years, whatever country the data sits in and whoever it belongs to, and the usual reply was that this was lawyers’ paranoia. But it was probably never theoretical. It simply happened quietly, under sealed orders, where none of us had to look at it. What changed on 12 June is that it happened in the open: not a sealed demand for data, but the product itself, switched off in plain view, because a government on another continent sent a letter.

Clarifying Lawful Overseas Use of Data Act — The US law requiring American communications providers to disclose data in their possession, custody or control on lawful US request, regardless of whether it is stored inside or outside the United States.

And the unease is no longer only mine. The service whose job is to study exactly these risks for Denmark, the Danish Defence Intelligence Service, judged in its 2025 assessment that the United States now uses its economic and technological strength as an instrument of power, including towards allies and partners. The way the US, China and Russia each wield power has bred mistrust even between traditional partners and allies, the assessment found. When the people paid to be unsentimental about this conclude that the ally now treats technology as leverage, a model switched off by letter stops looking like an accident and starts looking like the pattern.

Udsyn 2025 — The Danish Defence Intelligence Service’s 2025 intelligence risk assessment of the external conditions for the Kingdom of Denmark’s security, which finds that the United States now wields its economic and technological strength as an instrument of power towards allies as well as rivals, and that mistrust has grown even between traditional partners and allies.

We Have Heard This Before

There is an irony here that is hard to miss. The case the United States spent years building against TikTok rested on exactly this principle: that a state able to reach into a private technology company and bend it to its own ends, across borders and over the heads of the people relying on it, is a danger in its own right. I think that case was largely sound. A government really can capture a private platform and point it where it likes, and a country is right to think hard about depending on one inside a rival’s reach.

Transcript: TikTok CEO Testifies to Congress — The transcript of the House Energy and Commerce hearing, at which US lawmakers pressed the case that a platform within reach of a foreign government is a national-security risk in itself.

What 12 June showed is that the principle does not stop at rivals. The government that pressed it hardest has now produced the same result with none of the trappings: no ownership stake, no statute quoted in public, just a letter on a Friday afternoon and a company that complied the same day.

A Move Shown in Use

None of this is settled, and it is worth saying so plainly. Anthropic says it is working to restore access, and it may well succeed; the suspension could be narrowed, lifted, or quietly walked back next week. If you are waiting for a clean, permanent outcome before you decide what to make of it, you may be waiting a while.

So read it for what it is: a move, put on display. In a negotiation you do not need to hold the switch off forever; you need the other side to have seen, once, that you can throw it. That has now happened, in public, and no later restoration undoes it. Access can be handed back; the knowledge that it can be taken away cannot.

The risk we had filed under theoretical did not stop being theoretical because someone wrote it up. It stopped because we watched it run, in real time, in front of us. Whatever happens to Fable 5 next, that lesson does not reset.

Trust Is a Spectrum

So here is the lesson, once the noise dies down and Fable 5 is either back or gone for good. Anything you depend on that lives beyond your own borders can, in the end, be taken away from you. That is no longer a claim to argue about. It is a thing that happened.

Trust runs on a spectrum. At one end is yourself: what you build and host and control, where the only hand on the switch is your own. At the far end is your fiercest rival, trusted with nothing. Everything else — your institution, your country, your allies, a friendly vendor, a foreign cloud — falls somewhere along that line, and the further from yourself a thing sits, the less of it is really in your hands. An ally sits a long way towards the trusted end. It does not sit at the end, and 12 June was a reminder of how far it still is from you.

Risk appetite is nothing more than deciding where on that line you are willing to place the things you cannot afford to lose. For two decades, most of Europe treated the United States as trustworthy enough to carry almost anything: our data, our clouds, and lately our most capable tools. That judgement is now being revised, and the intelligence services are saying so plainly. Denmark and the rest of Europe are dialling the trust back, pulling what matters closer to home. Calling that paranoia, or anti-Americanism, misreads it: it is what risk appetite is for. You move when the evidence moves, and the evidence just moved, with a timestamp. All that remains is a matter of degree: how far each country pulls back, and whether it does so deliberately now or in a scramble after the next letter.

  • Softened the account of how the flaw reached Washington so it no longer presents the Amazon research as the settled trigger. The cited source also carries a rival account naming only a trusted partner, and a separate report tying the order to fears of access by a group linked to China.

The views and perspectives expressed here are the author's own and do not represent any employer or affiliated organisation. The writing draws on public sources and the author's own experience, never on confidential information. Artificial intelligence is used on some posts to identify sources, draft structure, and assist with quality assurance; the final article is always the author's own work. The AI assists, but never authors.

Niclas Hedam

PhD, Computer Science

Niclas Hedam holds a PhD in Computer Science from the IT University of Copenhagen. He is passionate about educating others on the importance of safeguarding personal information online.

A phone with a bunch of notifications for social media apps.

The Retention Economy: Kept at All Costs

· 19 min read · 11 sources

A recommendation feed is not trying to entertain you. It is trying to keep you watching, and it drifts towards whatever version of you is easiest to hold on to.