
On June 12, the Commerce Department's Bureau of Industry and Security called Anthropic and gave the company 90 minutes to comply with an export-control directive. The order required Anthropic to suspend access to Fable 5 and Mythos 5 for "any foreign national" — anywhere in the world, including people working lawfully inside the United States. Anthropic had no way to verify nationality in real time. So it turned both models off. For everyone.
Eleven days later, Legion LegalTech sued the federal government. The San Jose company builds drafting and case-management software for lawyers, and the shutdown had locked its Canadian engineers out of the models its platform runs on. The complaint called the harm "immediate, irreparable, and existential."
The government rescinded the directive before any court could rule. Anthropic restored access, and Legion dismissed its case without prejudice, which means it can refile. Its chief executive, Arthur Rothrock, explained afterward why the company had gone to court at all: a federal agency had claimed the power to disable commercial AI models with 90 minutes' notice, no evidence, and no process.
Three weeks, start to finish. That's the part everyone will use to reassure themselves — it was brief, it got fixed, the system worked. It didn't. A government order changed the operating conditions of a private software company within hours, on evidence the company itself described as verbal, and a firm with no connection to the underlying dispute nearly went under waiting for it to be lifted. The speed isn't the consolation. It's the whole problem.
The government never published its reasoning, which is itself worth sitting with. Here is what emerged from Anthropic's statements. Researchers at Amazon found a way past one of Fable 5's safeguards, one that let the model identify software vulnerabilities and, in a single demonstration, generate code showing how one could be exploited. Amazon reported this to the government. Reading the sequence closely, it appears the government heard about it before Anthropic did — a researcher at one company routing a safety finding to a federal agency ahead of the company that built the model. However that decision gets defended, it is not how responsible disclosure is supposed to work.
And then the response ran wildly ahead of the finding. Anthropic said the government offered only verbal evidence of a narrow, non-universal jailbreak — no written analysis, no demonstrated universal exploit, a bug of the kind expert red-teamers surface in every frontier model, including the competitors' models that can do the same thing. On that basis, the government ordered a worldwide shutdown of a system deployed to hundreds of millions of people. Anthropic's own response was the sober one: recalling a model this broadly over a narrow finding would, applied consistently, halt every new model release in the industry. They're right. The remedy wasn't proportional to the problem, and a regulator acting in good faith would have known that.
Which raises the question the official record avoids. This is the same administration that put Anthropic on a supply-chain blacklist earlier in the year, after the company refused to let its models be used for domestic surveillance and fully autonomous weapons. A thin justification, a punitive remedy, and a target that had recently told the government no on exactly the uses the government wanted most — I don't think those three facts are unrelated. I can't prove motive from a Reuters timeline, and I won't pretend to. But when the evidence is this weak and the target is this specific, "national security" starts to read as the label rather than the reason.
The whole thing resolved the way these things actually resolve: not in a courtroom, in a letter. Anthropic added a safeguard that routes blocked requests to its older Opus 4.8 model, agreed to protocols for current and future releases, and committed to reporting malicious activity. Commerce Secretary Howard Lutnick lifted the controls — and reserved, in writing, the right to reimpose them. The switch is back on. The government made sure everyone can see its hand still resting on it.
Legal-tech vendors look self-contained from the outside. They design the interface, shape the workflow, hold the customer relationship, and add the legal knowledge that turns a general model into something a lawyer can use. The reasoning underneath comes from someone else — from a provider whose infrastructure and government obligations sit entirely outside the vendor's control.
I want to be careful here, because there's a lazy criticism waiting to be made, and it's wrong. Nobody should fault Legion for building on top of someone else's model. That's how software has always been built — on operating systems you didn't write, databases you didn't design, APIs you don't control. A legal-tech company using a frontier model as its reasoning layer is doing the normal, correct thing. The problem was never the dependency. The problem is that this particular dependency can now be severed by a government on 90 minutes' notice, and that is a new fact about an old and sensible practice.
Because frontier models are genuinely hard to swap under pressure. Each one refuses differently, handles long documents differently, fails differently. A workflow tuned around one system behaves like a different product after a hurried substitution — prompts need rewriting, evaluations have to be rerun, and users hit changes that looked cosmetic in development and are anything but in a motion due Thursday. The industry calls this "portability," and the word is doing too much work. A second API key restores access to a model. It does not restore the product. A real replacement is one you've already tested against your own documents, deadlines, and professional standards. Anything else is a backup plan on a slide.
The directive introduced a category that belongs on no architecture diagram I've ever seen: the citizenship of the person calling the API.
Technology companies distribute work across borders because the talent is distributed. A U.S. corporation employs Canadian developers, European researchers, foreign nationals working lawfully in American offices. A restriction covering "any foreign national" splits that workforce into permitted and prohibited users overnight — and most corporate identity systems can't even perform the split, because they verify role and location, not passport. One former White House official put it plainly at the time: you should now expect to prove your citizenship to use Anthropic's models.
Export controls have long governed sensitive hardware and defense-related data. What changed on June 12 is that the control landed on a hosted commercial service already woven into ordinary business operations, and it landed in hours instead of through rulemaking. The reversal restored access. It did not remove the precedent. Nationality is now something an AI provider can be ordered to enforce, and the sheer impossibility of enforcing it cleanly is what forced the provider into the broadest possible shutdown.
I watched this land on European clients directly. To a company running production work through these models from Frankfurt or Amsterdam, "any foreign national, worldwide" isn't an abstraction about export policy — it's the entire team, cut off in an afternoon, by a government that isn't theirs, over a threat nobody would describe to them. That is the experience this episode actually produced, and it is why the lesson traveled faster in Europe than anywhere else.
Legal work gives the continuity problem its sharpest edges. Court schedules, discovery obligations, and client commitments keep running while a vendor rebuilds around a substitute model — and the lawyer, not the vendor, stays professionally responsible for whatever the tool produced during the scramble.
Firms already vet AI products for confidentiality, privilege, and security before adoption. Model availability belongs on that list now, and mostly it isn't there. A product can pass every security review and still fail as an operational dependency the moment access rules change upstream. Legion wasn't an edge case. An external model supplier and an international engineering team are ordinary features of a modern software company. They were unremarkable right up until a government drew a nationality line through the middle of both.
Enterprise customers reach for the usual protections: service levels, notice requirements, termination rights. Useful, inside the commercial relationship. A government order sits outside it. The contract can allocate losses after a cutoff; it can't restore lawful access. An availability guarantee says nothing about a compliance shutdown. Advance notice is a fiction when the provider itself got 90 minutes. A substitution clause is comfort only if the substitute has ever run inside your actual workflow.
So, the real protection is architectural, and I'll say the part vendors don't love to hear out loud: use more than one model provider and make sure at least one of them sits outside the United States. Not as a political gesture — as continuity engineering. The entire failure mode here was single-jurisdiction concentration. One government reached one provider and every product downstream went dark. A company running critical work through a single U.S. frontier model has accepted that a U.S. agency can switch its business off on a Friday afternoon, and after June 12 nobody gets to call that risk theoretical.
The rest is unglamorous and necessary. Know which provider supplies each critical capability. Check whether your vendor diversity is real or whether five products quietly sit on the same foundation model. Set access rights around the workforce that actually builds the thing, contractors included. Put legal in the room early enough to map jurisdictional exposure while it's still a planning exercise instead of an incident. All of it looks like wasted effort while the preferred model keeps working — right up to the eleventh day, when Legion was in federal court arguing for its survival.
Frontier AI is geopolitical infrastructure now, and every customer of a frontier model inherits a piece of the provider's relationship with its government — even when the customer's own work has nothing to do with national security. Legion drafts motions. That was enough.
The lawsuit ended before any judge could define the limits of the government's authority, so the only precedent this episode produced is operational: a hosted model was disabled worldwide on 90 minutes' notice, on evidence its own maker called verbal, and restored under a letter that expressly reserves the right to do it again. I don't read that as the system working. I read it as a warning that arrived cheaply. The next directive may last longer, cover more systems, or land on a sector with no alternatives at all — and the companies treating these models as critical infrastructure should build now for the border that can appear inside their software without notice. It already did once, on a hunch, and the people who paid for it had done nothing wrong.