The Great AI Rollback

[NAVIGATION LINKS]


The two largest AI accountability frameworks in the world retreated in the same month that a United States government directive pulled frontier AI from global access in hours. That is not a coincidence. It is a structural pattern, and enterprise leaders need to understand what it means.

Two things happened in May 2026. They were supposed to be the story.

Eleven days apart, the governor of Colorado and the European Parliament both stepped back from their most ambitious AI accountability commitments.

Colorado had been first. In May 2024, Governor Jared Polis signed the Colorado AI Act, the first United States state law to impose a duty of care on organisations using AI to make consequential decisions about people's lives. Credit applications, employment decisions, healthcare access, housing: if an automated system materially influenced the outcome, the deploying organisation was obligated to assess discrimination risk, align risk management to NIST or ISO standards, conduct annual impact assessments, and self-report algorithmic discrimination incidents to the Attorney General.

Two years of stakeholder consultation, legal challenges, and legislative deadlock followed. On 14 May 2026, Governor Polis signed SB 26-189, repealing and replacing that framework entirely. What the replacement eliminated is the point: the duty to avoid algorithmic discrimination is gone. The obligation to run NIST-aligned risk management programmes is gone. Impact assessments are gone. Self-reporting to the Attorney General is gone. What remains is narrower. Tell people when automated decision-making technology affected a consequential decision. Give them a plain-language explanation within thirty days of an adverse outcome. Allow them to request human review. Transparency obligations, then. No prospective risk management. No accountability for the pattern of decisions, only the individual outcome.

Five days earlier, the European Union had confirmed that its Annex III high-risk AI obligations, the requirements that would have forced developers of AI used in employment, education, and critical infrastructure to conduct conformity assessments, register their systems publicly, and maintain detailed technical documentation, would not apply until December 2027. A sixteen-month deferral of the most demanding compliance architecture in the world's most ambitious AI law. On 16 June 2026, the European Parliament voted in plenary to approve the Digital Omnibus text that formalises the deferral. Formal Council adoption is expected before August. Until that adoption is complete, the original 2 August 2026 obligations technically still stand, and organisations should not demobilise compliance programmes in anticipation.

Both retreats were described as pro-innovation. Both were welcomed by the technology industry. Neither was accompanied by a governance alternative of comparable force.

Those were the two stories. Then a third thing happened.


The control that did not retreat

On the evening of 12 June 2026, in the same month that had seen the Colorado governor and the European Parliament both step back, a United States Commerce Department directive arrived at Anthropic's headquarters at 5:21 PM Eastern time. Within hours, Fable 5 and Mythos 5, the company's two most capable publicly available models, were offline for every customer on Earth.

No grace period. No advance warning. No exception for paying enterprise customers. No exception for Five Eyes allies. According to New Zealand trade publications, there was also no exception for the NCSC and GCSB, reported as a named participant in Project Glasswing, Anthropic's restricted programme providing access to Mythos-class capabilities for cybersecurity organisations. That participation has not been confirmed by any primary statement from the agency and should be read as trade-press reporting, not as established fact. The structure of the event does not depend on it. One directive. One global suspension. Three days after the most ambitious AI model launch of the year.

The legal instrument was a Bureau of Industry and Security "is informed" letter, issued under the Export Controls Reform Act of 2018. A BIS "is informed" letter is a unilateral administrative instrument. It carries no defined evidentiary standard, no notice-and-comment requirement, and no administrative appeal mechanism. It is structurally different from a formal rule: faster to deploy, harder to challenge, and subject to no procedural safeguards. Legal analysts at Lawfare described it as operating through standardless administrative action based on contested technical facts.

The directive's stated basis was a jailbreak. The government understood that a user could ask Fable 5 to "fix this code" to identify software vulnerabilities in a way that bypassed the model's refusal to "review this code for security issues." Anthropic characterised the same technique as standard defensive security practice. Katie Moussouris, described in reporting as the only outside expert to review the original paper, found no guardrail bypass and noted that the technique is the same find-fix-test loop defenders run daily. That "only outside expert" characterisation rests on a single outlet and is reported here with attribution rather than asserted as settled. More than 100 cybersecurity professionals signed an open letter against the suspension. As of 19 June 2026, both models remain offline.

The structural significance is not the political dispute about the trigger. It is the mechanism. AWS Bedrock, Google Cloud, Microsoft Foundry, Snowflake, Box, and the direct Claude APIs were simultaneously affected. The suspension reached users at the point of consumption, not at the point of distribution. That has not happened before.


The asymmetry is not accidental

The governance movements of May and June 2026 form a coherent directional pattern when read together.

Retreating: the duty of care against algorithmic discrimination (Colorado, eliminated). Mandatory NIST-aligned risk management (Colorado, eliminated). High-risk AI conformity assessments (EU Annex III, deferred sixteen months). Federal AI safety risk assessments (United States Executive Order 14110, revoked January 2025). The common thread is that these are all obligations that require ongoing compliance architecture from the organisations deploying AI systems.

Tightening: export-control access restrictions on frontier AI API endpoints (Fable 5 and Mythos 5, immediate and global). Mandatory AI use-case registers with named accountable owners (Australia, ninety-four agencies compliant as of 15 June 2026). The European Union's Article 50 transparency obligations for AI-generated content and AI-human interaction (unchanged, operative from 2 August 2026 as scheduled).

The logic of that asymmetry is worth sitting with. Consumer-protection controls are complex, costly, contested in court, and slow to verify. Access and identity controls are binary, fast, and technically enforceable without procedural burden. The former requires ongoing compliance architecture from thousands of deploying organisations; the latter requires a single directive to a handful of model providers. As frontier model capability crosses into nationally significant territory, governments are reaching for the second type of control. The asymmetry is not ideological. It is structural. One type of control is easier to operate at the speed of a capability event.

This is the governance pattern of 2026. Regulators are retreating from what AI does to people. They are tightening on what AI can do for states.


The access-control escalation ladder

The Fable 5 directive is not an isolated event. It is the latest step in a systematic extension of export-control authority over AI capabilities, and understanding that ladder matters for enterprise strategy.

The Biden administration's January 2025 BIS framework created export-control classification ECCN 4E091 for closed-weight model files trained using more than 10^26 computational operations. The Trump administration revoked that framework in May 2025, describing it as overly complex. The June 2026 directive demonstrates a different mechanism. Rather than controlling the distribution of model files, BIS asserted authority over a deployed model's live API access, a control surface that reaches users at the point of consumption. Each step in the progression moves closer to the end user: hardware controls (chips); compute controls (access to large training runs); model-weight controls (export of trained files); API access controls (live endpoint availability to foreign nationals). The June 2026 event is the first confirmed deployment of the fourth type.

The mechanism has no precedent in commercial software regulation. A United States government directive has never before pulled a globally deployed commercial software product's API from every customer simultaneously, on hours' notice, based on contested assessments of a security technique's risk profile. Enterprises that built production workflows assuming the commercial availability of frontier AI models were, in practical terms, operating without a continuity plan for this scenario. Most still are.


What this means for enterprise governance: three gaps, one week

For enterprise leaders in New Zealand and similar small open economies, the May and June 2026 events exposed a three-dimensional governance gap.

The first dimension is familiar. Organisations are deploying AI faster than they are governing it. Gartner, forecasting in May 2026, predicted that by 2027 roughly forty per cent of enterprises will demote or decommission autonomous AI agents after production incidents attributable to governance failures. That gap is internal, and this series has been covering it since Part 5.

The second dimension is regulatory. New Zealand's AI Strategy, "Investing with Confidence" (MBIE, July 2025), is explicitly light-touch and principles-based, relying on existing legislation rather than AI-specific law. MBIE's Responsible AI Guidance for Businesses is voluntary. There is no dedicated AI regulator and no binding AI-specific obligation on the private sector as at 19 June 2026. That posture reflected a deliberate policy choice about where the regulatory burden should fall. It also reflected, implicitly, an assumption about access stability.

The third dimension is geopolitical, and the June 2026 events named it directly. Any New Zealand organisation that has built production workflows around frontier AI APIs has implicitly accepted a dependency on a commercial arrangement that a foreign government can terminate in hours, with no advance notice, no New Zealand regulatory protection, and no fallback requirement. The MBIE guidance encourages governance structures. It does not require the contingency architecture that Sovereignty Agility demands.

Compare Australia, which activated its first binding AI governance obligation on 15 June 2026, the day before the Fable 5 shutdown. Under the Digital Transformation Agency Policy for the Responsible Use of AI in Government version 2.0, all ninety-four non-corporate Commonwealth entities are now required to maintain an internal register of every in-scope AI use case with a named accountable owner. All ninety-four met the deadline. A further twenty complied voluntarily. The December 2026 additions (AI impact assessments before deployment, incident reporting obligations, oversight processes) extend the framework further. Australia's public sector now has explicit, named, accountable ownership of every AI use case it is running.

This is not a commentary on which government made a better policy choice. It is an observation about which governance architecture has greater resilience to the access-layer risk the June 2026 events revealed. A government that knew which AI systems it was running, who owned accountability for each, and had assessed the risk profile of each would be structurally better positioned to respond to an access disruption than one that did not. Australia knew. New Zealand, in the public sector context, had the GCDO Responsible AI Guidance; in the private sector, it had voluntary principles. When the disruption came, both Five Eyes members lost access at the same moment. One had an inventory. One did not.

The exposure has a dual character. For New Zealand enterprise leaders in the private sector, the absence of a regulatory requirement to maintain AI use-case visibility means most organisations also lack it. There is no regulatory floor requiring that contingency be planned. For the public sector, the NCSC and GCSB situation, if the trade-publication reporting is accurate, illustrates a different dimension of the same gap. A cyber defence agency that participates in a frontier AI programme at Washington's invitation is operating under a dependency without a bilateral guarantee. When the directive landed, it carried no Five Eyes exception. Access to Mythos-class capabilities under such an arrangement would be governed entirely by a commercial relationship with the United States government, not by any New Zealand instrument. That is not a criticism of any individual programme or decision. It is a structural observation about how the access layer works. It is not a treaty right. It is a commercial arrangement that a foreign government can terminate.

Political leaders in the United Kingdom, Canada, France, and the Netherlands publicly characterised the Fable 5 event as a wake-up call, describing frontier AI model access as the kind of infrastructure that requires sovereign control. For small open economies without domestic frontier AI capacity, that framing matters directly. Frontier AI access has joined the category of technologies, alongside semiconductors, undersea cables, and satellite bandwidth, where supply reliability is a national-security consideration, not merely a commercial one. The light-touch regulatory bet assumes access stability. Access stability is now subject to a control mechanism that a partner nation's government can activate in hours, without warning, and without bilateral exception.

Sovereignty Agility, as this series has developed it since Part 9, is the ability to adapt AI architectures quickly to regulatory changes or vendor shifts. The June 2026 event tested it at speed. Organisations that had built production workflows on a single frontier model API discovered they had no Sovereignty Agility. When the directive arrived at 5:21 PM Eastern time, their workflows stopped. Sovereignty Agility is not optional governance hygiene. It is operational continuity planning, and the June 2026 events have given it an empirical test case.


What the pattern asks of enterprise leaders

The governance implications of asymmetric regulation are practical, not theoretical.

Consumer-protection controls retreating to voluntary principles means that if your AI system makes a biased decision about a job applicant, you may have no mandatory legal framework requiring you to demonstrate you assessed that risk. That does not mean the risk has gone away. It means the compliance incentive to manage it has weakened. Organisations that were planning compliance programmes around Colorado-model obligations should understand the extent to which those obligations have been replaced by disclosure-only frameworks. Governance investment driven by strategic risk management, not by regulatory minimum-floor compliance, becomes more important when the floor drops.

Access controls tightening as enforceable state action means that your operational continuity now depends partly on decisions made by foreign governments, operating through legal instruments with no advance warning, no defined evidentiary standard, and no administrative appeal mechanism. This series discussed the Authorship Inversion last week: more than eighty per cent of Anthropic's production code is now authored by AI. When the models that author that code were taken offline in hours, the implications extended beyond user productivity to the development pipeline itself. The same logic applies to any organisation that has integrated frontier AI into production workflows. Continuity planning for AI access disruption is not an exotic risk scenario. It is mainstream enterprise risk management.

VentureBeat's enterprise guidance, issued immediately after the Fable 5 shutdown, was direct. Any organisation building agentic workflows or production applications tied solely to a single closed-API provider risks immediate operational failure if that provider faces an export-control directive, a cyber incident, or an injunction. AI supplier diversification is not a nice-to-have. It is the operational equivalent of not running your entire business continuity plan through a single internet service provider.

Three practical steps follow from the June 2026 events.

First, map your AI dependency surface. Know which workflows depend on which frontier APIs. If you cannot name the model, the provider, and the scope of the dependency, you cannot assess the continuity risk. The Australian register requirement, a named accountable owner for every AI use case, exists precisely because the visibility is the precondition for the risk management. Most New Zealand enterprises do not have this visibility. Building it does not require a regulatory mandate. It requires a deliberate decision to treat AI dependencies as infrastructure dependencies, with the same inventory rigour you would apply to cloud services or key vendors. Build the equivalent, whether or not your regulatory environment requires it.

Second, design for portability. Architectural choices that make it straightforward to switch providers or fall back to a previous model generation are now an enterprise continuity design requirement, not an engineering preference. The organisations that shifted to Claude Opus 4.7 or GPT-5.5 within hours of the Fable 5 suspension were the ones that had not architecturally coupled themselves to a specific model endpoint. Portability by design requires slightly more upfront architecture work. It requires significantly less emergency recovery work when access is disrupted without warning.

Third, reassess your governance for the regulatory direction, not the regulatory floor. Consumer-protection obligations are retreating to disclosure minimums in some jurisdictions. The organisations rewarded for governance investment are those that treat it as a precondition for sustainable deployment, not as a compliance minimum to clear. When the floor drops, the organisations with governance architecture above the floor are differentiated. The ones that built to the floor precisely are now ungoverned in the space above it.

The Governance Gap this series has tracked since Part 5 was primarily internal: organisations deploying AI without the oversight frameworks their risk profile required. The June 2026 events added two external dimensions. Enterprise leaders who build their governance architecture only for the internal dimension are now managing two of the three gaps and hoping the third does not open while they are looking the other way.


The implication on the sovereignty side is worth naming directly. The instrument that pulled Fable 5 and Mythos 5 offline was an export-control mechanism: a Bureau of Industry and Security letter issued under the Export Controls Reform Act of 2018, the same statutory family that governs which semiconductors and which trained model files may cross which borders. Frontier AI access has now joined semiconductors, undersea cables, and satellite bandwidth in the category of technologies where supply reliability is a matter of state authority, not commercial contract alone. For a small open economy with no domestic frontier model capacity, that shift is structural. Access that depends on a single allied government's administrative discretion, with no treaty floor and no bilateral exception, is not sovereign capacity. It behaves like infrastructure right up until the day a directive withdraws it.

When someone in Washington can shut down your AI workflows in hours, and you have no plan for that, you have a governance gap. What does yours look like?

I would like to hear from enterprise architects, CIOs, and risk leaders who have run this analysis since 12 June. What does your AI dependency map look like right now, and where is the single point of failure you have not yet planned around?


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. They do not represent the views of my employer, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance. I follow the Public Service Commissioner's Code of Conduct for the Public Sector and social media guidance.


Andreas Hamberger is a New Zealand leader in Architecture and Security and Associate Member of the Institute of Directors. The Hamberger Report: Generative AI 2026 provides enterprise leaders with evidence-based analysis of the AI landscape.


I use AI tools, including Sudowrite, Claude, Perplexity AI, DeepSeek AI, ChatGPT, Grok, Copilot, Openart and Gemini, as deliberate production tools, not ghostwriters. This is consistent with my position: AI amplifies human judgement; it does not replace it. The frameworks, arguments, and editorial decisions in this series are original work. AI accelerated the process. The thinking is mine.


[1] Holland and Knight. "Colorado Governor Signs SB 26-189, Repealing and Replacing the Colorado AI Act." 15 May 2026. https://www.hklaw.com/en/insights/publications/2026/05/colorado-governor-signs-sb-189

[2] Davis Wright Tremaine. "Colorado AI Act Repeal: The New Transparency-Only Law." May 2026. https://www.dwt.com/blogs/privacy--security-law-blog/2026/05/colorado-ai-act-repeal-new-transparency-law

[3] Buchalter. "Colorado Rewrites Its AI Law: What Employers Must Know About SB 26-189." May 2026. https://www.buchalter.com/insights/colorado-rewrites-its-ai-law-what-employers-must-know-about-sb-26-189/

[4] Gibson Dunn. "EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes." May 2026. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

[5] EU AI Act Service Desk / artificialintelligenceact.eu. "Article 50 Transparency Obligations: Application Timeline." 2026. https://artificialintelligenceact.eu/

[6] Anthropic. "An Update on Fable 5 and Mythos 5 Access." 13 June 2026. https://www.anthropic.com/news/fable-mythos-access

[7] FifthRow. "US Export-Control Order and the Global Suspension of Fable 5 and Mythos 5: Operationalising Compliance as a Live Mandate." June 2026. https://www.fifthrow.com/blog/us-export-control-order-and-global-suspension-of-fable-5-mythos-5-operationalizing-compliance-as-a-live-mandate

[8] Rozenshtein, Alan. "Standardless Administrative Action: The BIS 'Is Informed' Letter to Anthropic." Lawfare. 15 June 2026. https://www.lawfaremedia.org/

[9] Digital Transformation Agency (Australia). "New Central Register for AI Transparency Statements from Commonwealth Entities." 15 June 2026. https://www.dta.gov.au/articles/new-central-register-ai-transparency-statements-commonwealth-entities

[10] Digital Transformation Agency (Australia). "AI Policy Update: Strengthening Responsible Use Across Government." 2026. https://www.dta.gov.au/articles/ai-policy-update-strengthening-responsible-use-across-government

[11] Ministry of Business, Innovation and Employment. "Investing with Confidence: New Zealand's Strategy for Artificial Intelligence." July 2025. https://www.mbie.govt.nz/

[12] Gartner. "Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure." 26 May 2026. https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure

[13] Federal Register / Sidley Austin. "ECCN 4E091 and the Closed-Weight Model Export Control Framework: Establishment and Revocation." 2025. https://www.federalregister.gov/

[14] VentureBeat. "After the Fable 5 Shutdown: Why Single-Provider AI Dependency Is Now an Operational Risk." June 2026. https://venturebeat.com/

[15] Favaro, M. and Clark, J. "When AI Builds Itself." Anthropic Institute. 4 June 2026. https://www.anthropic.com/institute/recursive-self-improvement

[16] B2B News New Zealand and SecurityBrief New Zealand. "NZ Cyber Agencies Named in Restricted Frontier AI Access Programme." June 2026 (New Zealand trade-publication reporting; not independently confirmed by primary agency statement). https://securitybrief.co.nz/

Previous
Previous

From Pilot to Production: The Year the Control Plane Ate the Model

Next
Next

The Authorship Inversion