Accelerate AI, but not into a wall
Another entry in our series about sovereign AI; the risks and the rewards
On 1 Jul the model came back. The export controls lifted the day before, access was restored, and the capability I had written about losing was on again as though nothing had happened.
I was relieved; I had been leaning on it harder than I admitted.
Seven weeks, one product, and none of the decisions were mine. On 12 Jun the US Department of Commerce applied export controls to Anthropic’s newest models, Claude Fable 5 among them, and because the order took effect immediately and nationality could not be verified in real time, access stopped that day for everyone, everywhere. On 30 Jun the same department lifted the controls. On 1 Jul the model came back, on different terms: included in subscription plans only until 7 Jul, and priced by usage credits after that. The software did not change once in that time. What changed was who had decided, that week, what I was allowed to have and what it would cost me.
None of that was a fault. Nothing broke.
I spent the rest of June building a box. I have written about that already: the parts, and the careful version of me that showed up to build them. It now runs models under my desk on weights I hold, mostly on sunlight, and it has already ridden through one blackout without waking anyone. I thought I was solving a dependency problem. The box solved my dependency problem, but my dependency problem is small.
Here is what I can do that most of my clients cannot. I can break things. If I run something bleeding edge and it fails, it costs me a weekend and a rebuilt machine. I lose my own time. Nobody’s records leave the building, no member gets a letter, no regulator asks me to explain myself. My appetite for risk looks bold from the outside. From the inside it is calculated risk: I know exactly what a failure costs me, and I can afford it.
An organisation holding thousands of members’ records cannot make the same trade with any level of enthusiasm. Same behaviour, same tools, completely different consequences. What matters is what a failure costs and whether it can be undone.
So the first question I now ask any organisation about AI is what a failure would cost them. I expected that question to make me the person who slows everyone down. As often as not it has done the opposite: plenty of organisations convinced they are dangerously behind turn out to be moving at the right speed for what they carry. Others have governance in place so tight it stifles innovation and safe experimentation.
Because there are two ways to get hurt here, and only one of them ever shows up in a risk register. The obvious one is speed without brakes: tools in the hands of staff, client data in a consumer tier that trains on it, nobody able to say which systems would stop if a vendor changed the terms on a Tuesday. The other is a full stop. Banned the tools, wrote the policy, filed it, and watched three years of compounding practice go to a competitor who did not.
Frontier work at least forces the conversation. The quiet middle never confronts it: AI use small enough to be invisible, ungoverned because it flies under the radar. Accelerating deliberately would serve them far better than the drift.
If you want to know which of those describes your organisation, four questions will get you most of the way there.
What work stops tomorrow if a capability you rely on goes behind a door for three weeks? I could not fully answer this for my own one-person practice until June.
Where does your data sit while that work happens, and who can be compelled to hand it over? Not which country the data centre is in. Who holds the keys, and which government can lean on them.
Which of your AI controls has ever actually stopped anything? A policy nobody has tested is a document. A control that works has a log, an owner, and at least one blocked attempt behind it.
Who decided your current risk appetite, and when? If the honest answer is that nobody decided it and it accumulated, you want to know that before somebody outside your building decides it for you.
Your answers place you somewhere, and it helps to see the whole map.
Anyone who has spent a summer in this country knows what a firebreak is. Cleared ground, cut before the season while the weather is kind, maintained because the day you need it is the wrong day to start. It does not stop fires, and it was never meant to. It decides in advance what a fire can take. Clearing one is neither a ban on fire nor a hope that fire behaves. It is knowing where the fuel is, and choosing what you are prepared to lose.
I map organisations the same way, on a grid I have come to think of as the firebreak grid: how consistently AI is used, against how far the controls have got past paper.
A few things the grid keeps teaching me.
Nobody is at zero. Every organisation I have looked at that believed it had no AI use turned out to have some: individuals, consumer tools, invisible from the top. That is the Shadow square, and organisations do not place themselves in it, because from inside it looks empty.
The middle band is Paper, and it runs the full width for a reason. A written policy puts you there whatever your adoption looks like, and staying there is comfortable, because documents are cheap and audits of documents pass. The climb out is a different kind of evidence: a control that has actually stopped something, with the log to show it.
The dangerous square is not the fast one. It is small, ungoverned use with real data in it. And Locked down is a real square too, not a safe one: the ban is a control that works, protecting an organisation that is quietly falling behind.
The distinction I care most about sits in the top right corner, between Effective and Resilient, and it is the reason this series exists. Effective means your controls bind and your AI use earns its keep. Resilient means all of that, plus you have already decided what happens when someone else changes the terms. The gap between those two squares is exactly the seven weeks this piece opened with. You can be genuinely effective and still be one export control, one changed term, one vendor reflex away from a stop-work, and nothing on your risk register will have warned you.
I am not selling you the frontier. I run the frontier here, on my own hardware, at my own cost, precisely so a client never has to. The lessons in this series were cheap for me to learn. On your members’ data, they would not have been.
In seven weeks, three decisions were made about a tool I use, by two parties, neither of whom has heard of me: switched off, switched back on, returned at a different price. None of them were existential, because the parts of my stack they could reach were the parts I could afford to lose. That position is what I want for you. Not my hardware, and not my risk appetite. The ground cleared before the season, so that somebody else’s decision about your tools is a news item, and nothing more.
If you would like help finding your square, and clearing the ground, you can find out more about Firebreak here.
Alex



