On June 12 at 5:21pm Eastern, the US government told Anthropic to cut its two most capable models, Fable 5 and Mythos 5, off from every foreign national, meaning anyone who is not a US person, whether they were sitting in San Francisco or halfway around the world. The reason it gave was a jailbreak, which the order described as a trick that "essentially consists of asking the model to read a specific codebase and fix any software flaws." The most capable commercial models on the planet, flagged for being too good at fixing code.
There was no clean way for Anthropic to do what it had been asked. You cannot reliably sort hundreds of millions of users by citizenship and pull a product from some of them while leaving it running for the rest. Stuck with a demand it could only half-comply with, the company did the one thing the order actually left open to it and switched Fable 5 and Mythos 5 off for everybody, everywhere, its own engineers included. An instruction aimed at foreigners ended up taking the models away from Americans too, because the only lever Anthropic had to pull was the global one.
You can read all of this as a safety measure and argue about whether it was proportionate. I think that misses the more interesting thing that happened. This was not really a verdict on one model. It was a live demonstration of where frontier capability goes the moment someone tries to pin it in place, and the answer should worry the labs and interest Europe a good deal more than it currently seems to.
The part worth slowing down on
The order worked because there was a switch to throw. A closed model sits behind an API that one company owns, meters, and can shut at will, and that is what made a Friday-evening directive enforceable by Friday evening. Closed means controllable, which sounds like a compliment until you notice what travels with it.
Controllable also means throttleable. Once a capability is good enough to trigger an emergency recall, no rational lab keeps sprinting toward more of it. You start treating your best work the way a utility treats a liability, something to price, cap and hedge rather than push. A model that a non-market actor can switch off overnight is a stranded asset, and nobody builds a roadmap around assets that strand.
Open weights carry none of that exposure. There is no API to meter, nobody to spook into a recall, no single name for an order to land on. Weights that are already mirrored across a hundred machines cannot be recalled, because there is no longer an 'it' to recall. So the capability the government wanted to suppress does not vanish. It moves to the one place the whole control regime cannot see into. Regulation aimed at the labs it can see pushes the frontier into the part of the map it can't.
And the loop tightens on itself. The harder the state leans on the closed frontier, the stronger the case for capping the closed frontier, and the faster the real work drifts into the open ecosystem nobody can switch off.
The cash register and the kill switch are the same switch
A good part of my career has sat on the commercial side of enterprise software, some of it close to companies whose business runs on open source. It teaches you something quickly: the open project itself was never where the control lived. Nobody can switch off Postgres or Apache Flink. What gets sold, and what gets controlled, is the convenient, metered, accountable layer wrapped around them. The money and the leverage sit in the same place because they are the same thing.
Frontier AI rebuilt that structure and then misplaced the lesson buried in it. To charge for a model on your own terms, by the token or the seat or the tier, you have to build a chokepoint, a single pipe that every request passes through and that you can measure against. That pipe is the business model. It is also, unavoidably, the thing a government can pick up and use. The cash register and the kill switch are the same switch, and you cannot build one without building the other.
So the commercial logic that makes a closed model attractive, that you own the surface, set the price and keep the value, is the very thing that leaves it open to export control. A model you can bill for is a model someone can switch off. Open weights give up both at once: you cannot meter them and you cannot recall them, and that is one property, not two.
It does not even matter much whether the recall was wise. Maybe it was careful and justified. Maybe it was a blunt grab for the nearest available lever, dressed up in reasons that have little to do with the real ones. The incentive lands the same either way. The closed lab is the one that built the lever, and whoever holds the law gets to pull it, which leaves the lab with a blog post and a grievance.
What it does to the labs
Quietly, the frontier labs are being sorted into the governable tier, and governable is turning into a polite word for capped. The closed frontier will not disappear. It will just pick up a ceiling drawn by what the state will tolerate rather than by what the science can reach. That is an odd place to run a company from. You carry the cost and the liability of the most capable models, and you are discouraged, structurally, from shipping your most capable work.
Every closed lab now faces the same awkward choice. It can settle into being the safe, audited, throttled utility, the AI equivalent of a regulated power company, and there is a real and durable business in that. Or it can watch its best work get out-iterated in the open by models it is no longer free to match. It cannot do both at once, and the recall turned that from a thought experiment into a live question.
Europe's two reflexes are both wrong
Brussels will react to this, and its first two instincts will quietly rebuild the trap.
The first instinct is to fund a closed sovereign champion to stand toe to toe with the American labs. It will not hold, because 'sovereign' today is mostly a European skin stretched over American infrastructure. The chips are American, the cloud underneath is largely American, the methods are American-derived. The first time it genuinely matters, an order can route through the silicon vendor or the hosting layer no matter where the model was fine-tuned. A champion built on borrowed foundations stays sovereign right up until someone in Washington decides otherwise.
The second instinct is to govern frontier models by copying the American design: licensed providers, central oversight, one accountable pipe. That just rebuilds the same blind spot at home. You would be constructing your own kill switch, congratulating yourself on the diligence, and pushing your own frontier into the open ecosystem you had just announced you wanted to govern. A switch of your own is still a switch you can lose the day someone else's outranks it.
The recall is an industrial-policy gift
Here is the turn. If the control regime keeps pushing capability into open weights, and Europe cannot win the closed-champion race anyway, then the smart move is not to fight for the chokepoint. It is to become the place the frontier moves to.
Most of the scaffolding is already there, half-built. The Draghi report put reducing foreign technological dependence at the center of European competitiveness, and the tech-sovereignty package that followed it carries a dedicated open-source strategy alongside the Cloud and AI Development Act. What none of it quite says out loud is the conclusion its own logic points at. In a world where the most capable closed models are also the most revocable, open frontier weights stop being a consolation prize for losing the closed race and start being the lever, the one asset class the United States is busy making harder for itself to hold. Europe keeps framing open source as a hedge against dependence. It should be framing it as the play.
Europe drifted into an open-leaning posture partly by losing the closed race in the first place, with Mistral and the wider open-weights tilt owing as much to circumstance as to strategy. The recall just turned that accident into an advantage worth pressing. Three moves follow from it, and none of them require outspending the United States.
The first is to be the place where open weights are built and run. The legal groundwork already exists: the EU AI Act carves out real exemptions for free and open-source models and saves its heaviest obligations for systemic-risk and closed systems. Lean into that rather than apologize for it. Predictable, light-touch rules for open models, plus compute and tax incentives that make Europe the obvious address to release and host frontier weights from. The American regime is generating refugees of capability. Somebody should build the harbor.
The second is to treat sovereignty as un-recallability rather than ownership. You do not need to build the model. You need to never be switched off. Europe's purchasing power is enormous and badly underused here. Make weight-escrow and continuity rights a condition of any frontier model embedded in critical infrastructure, so that a foreign recall trips an automatic fallback to self-hosting on European soil. That is the kind of sovereignty a realist can actually deliver. It is insurance against the next 5:21pm directive, and it costs a contract clause rather than a chip fab.
The third is to contest the one layer that is genuinely contestable. You will not out-fabricate the United States this decade, so stop treating chips as the battlefield. Hosting is the battlefield. Pool EuroHPC into a real public option for training and serving open-weights models, so that even on imported silicon the frontier runs under European jurisdiction. Partial sovereignty you can actually build beats total sovereignty you can only daydream about.
The honest cost
None of this comes free, and I would distrust anyone who pitched it as if it did. The same un-recallability that makes open weights sovereign also makes that jailbreak permanent. There is no central party to ship the fix, because there is no central party at all. Going long on open weights means choosing which problem you would rather live with, revocability or unfixability, and then actually living with it. It means owning proliferation questions that closed labs can at least pretend to keep behind glass.
So the claim is not that open weights are safe. It is that the control regime has already made them inevitable, and the only choice Europe really gets is whether to host that inevitability or import it.
What to watch
The next recall will tell you whether June 12 was an incident or a pattern. The first European procurement contract with a continuity clause in it will tell you whether anyone in Brussels is paying attention. The first genuinely frontier-grade open-weights model shipped from European soil will tell you whether the harbor got built in time.
The United States has just shown the world that its most capable models are also its most revocable. The opening it leaves Europe is a frontier with no kill switch at all, and the only question that matters now is whether Europe builds it before the moment closes.