For three days this June, a frontier AI model existed, worked, and then didn’t. You know what I’m talking about, right?
Anthropic released Claude Fable 5 on 9 June. Three days later, on 12 June, access was suspended — export-control powers, applied to a model that users had already started building on. It came back on 1 July. Nineteen days, start to finish, during which the availability of a frontier capability was decided entirely in elsewhere, and everyone else simply watched.
This is one example that perhaps has been mentioned before, and I am not here to rephrase or report on those 19 days. However, the example turns an abstract worry into an observed fact. The worry is that a country’s AI capability could, as the Alan Turing Institute’s CETAS brief puts it, “become unusable due to security issues, or suspended entirely due to factors outside the Government’s control.” Fable 5 was the dress rehearsal. Nobody’s contract mattered. The kill switch was somewhere else.
The binary I was ready to argue is the wrong one

The tempting frame — the one I nearly wrote — I was looking at when planning this post was the dycotomy betweemi “build and rent”. I will be concentrating in the UK ecosystem, but this can equally apply to other entities. Either we construct our own sovereign AI stack, or we resigns ourselves to being a tenant paying rent to landlords in Santa Clara and Redmond. It’s a clean, quotable dichotomy. And an Oxford evidence briefing I recently saw gave this view some real force, because the economic gap is not a rounding error.
Per the Stanford AI Index 2026, cumulative US private AI investment from 2013 to 2025 hit $757.3bn against the UK’s $34.1bn — a 22.2x difference. Before anyone reaches for “well, America is bigger”: the per-capita figures are roughly $836 versus $113, and as a share of GDP it’s 0.93% versus 0.20%. The gap is structural, not demographic. There’s a compute tax on top, though it isn’t quite the one the headline figures suggest. Azure’s eight-H100 VM (the ND96isr H100 v5) lists at $98.32/hour in East US — so a serious 1,000-GPU, 90-day training run costs on the order of $26.5m before storage and egress. Run the same job in UK South and the price gap is real but modest: Azure’s pay-as-you-go rate on this SKU varies only 5–15% across regions, and reserved pricing is region-independent. The sharper British penalty is availability, not sticker price. UK South capacity for this hardware is chronically constrained — teams routinely hit “SkuNotAvailable” errors most frequently in West Europe, Southeast Asia and UK South — which is a worse problem than a few percent on the bill, because you can’t optimise your way around GPUs that simply aren’t there. And the grid, which is upstream of all of it, is buckling: demand connection applications rose 460% in the six months to June 2025, with some data-centre projects reportedly facing waits of up to 15 years.
Stack those up and “just build it ourselves” starts to sound not merely appealing but, for some (many?) necessary.
The problem is that it not always possible, and CETAS says so plainly: a fully British training and inference stack “is infeasible for the UK.” Not undesirable, but infeasible. The brief’s own supply-chain sketch is the reason why. A single AI chip can carry Chinese raw materials, a Japanese wafer, a Dutch EUV lithography machine built from German optics and US light-source technology, Taiwanese fabrication, South Korean memory, US chip design, and British instruction-set IP. No country on Earth owns that chain end to end. Sovereignty-as-autarky isn’t just a hard goal.
So the “build or rent” argument collapses. Both poles may not be achievable, one because we it may not be affordable, the other has high dependencies as the Fable 5 fable showed.
CETAS’s contribution is to replace the binary with a spectrum, and to give it engineering teeth. The right aim, it argues, is controlled dependence: “using frontier systems where their advantages justify the exposure to risks such as loss of access, while ensuring that, if essential AI functions degrade, they do so gracefully rather than fail outright.”
That sentence carries a lot, let’s take a look. It concedes the thing my old framing resisted, that Britain will remain dependent on foreign frontier models, because that’s where the capability lives. But it reframes dependence as something you engineer around rather than escape. The goal isn’t independence. It’s graceful degradation: the design principle that when the risky component fails, the system limps rather than dies. Any engineer who’s built a resilient system recognises the pattern immediately, you don’t pretend the dependency won’t fail, you make sure its failure isn’t fatal.
To make “how much control” tractable, the brief decomposes sovereignty into four mechanisms, and this is the part I’d attach to every procurement decision in Whitehall:
| Control mechanism | What it buys you | Where it breaks |
|---|---|---|
| Contractual | No-training clauses, retention limits, zero-data-retention, uptime guarantees | “Contractual commitments remain subordinate to applicable law” — a legal order overrides any of it, as Fable 5 proved |
| Technical | Data protection via encryption and confidential computing / trusted execution environments | Protects confidentiality, not availability; TEEs aren’t bulletproof and leak at the edges (external tool calls, side channels) |
| Model possession | Self-hosting open weights removes the imposed-cutoff risk | The open-weight frontier lags the closed frontier by ~4 months; self-hosting runs ~$1.5m capex plus ~$750k/year, and UK electricity is ~3.5× US prices |
| Operational | Jurisdictional and administrative control of infrastructure — location, admin, ownership, legal jurisdiction, accreditation | “Residency alone is not the same as control”: a UK-region workload on a US-owned cloud is still exposed to foreign legal compulsion |
Read across that table and the Fable 5 lesson snaps into focus. Contractual control, the thing most organisations lean on, is precisely the one that failed, because a nation state order sits above the contract. The controls that would actually have preserved continuity are the expensive, unglamorous ones further down: locally retained open-weight fallbacks, accredited UK infrastructure, tested portability between providers.

The move I find useful is the one that rescues this from “own everything, trust no one”; CETAS refuses to apply maximum control everywhere. Different tasks warrant different depths.
Open-source intelligence work outside a classified environment, the brief suggests, might run happily on a closed-weight frontier model with decent contractual terms. You want the best capability, the data isn’t especially sensitive, and if access drops for nineteen days you cope. At the other extreme, countering state threats might justify a closed-weight model with an open-weight fallback on accredited UK infrastructure, i.e., capability and continuity, at considerable cost. Counter-terrorism sits somewhere in the middle. The point isn’t the specific allocations, which the brief explicitly floats as discussion-starters rather than doctrine. It’s the principle: match the control depth to what you actually lose if the capability degrades.
There’s a subtlety worth looking at here as it complicates the reflexive “just use open weights” answer. The current open-weight frontier isn’t American or European, it is actuallt Chinese, with models like Z.ai’s GLM-5.2 and Moonshot’s Kimi K3 rivalling the closed frontier on some benchmarks and pricing lower. That’s a live option for model-possession control. It’s also one that comes with documented baggage: research on DeepSeek’s R1 found it more susceptible to jailbreaks, exhibiting embedded political bias at the weights level, and — this is the one that should make any security team wince — injecting measurably more security bugs when prompts contained politically sensitive triggers. So the escape route from American dependence may run through a different dependence that carries its own risks. There’s no clean exit. There’s only the deliberate choice of which exposures you can live with.
I started thinking about this post to look at the question of whether Britain will build intelligence or rent it forever. The better question, which CETAS made me consider is: for each thing we need AI to do, how much control do we actually require, and are we engineering for the day access disappears?
That’s less rousing than a call for a British champion to rival the hyperscalers. It won’t fit on a conference banner. But it’s the version that survives contact with the supply chain, the electricity bill, and, most of all, those three days in June when a frontier model blinked out and no contract clause could bring it back.
Sovereignty in this case, it turns out, isn’t a wall you build. It’s a set of dials you tune, task by task, knowing the worst can happen and making sure that when it does, the lights dim instead of going out. The Turing’s institute, fittingly, has given us the schematic. The open question is whether the people writing the procurement contracts will read it before the next suspension, rather than after.
Drawn from two July 2026 sources: an Oxford evidence briefing on UK AI sovereignty (Stanford AI Index 2026; UK Compute Roadmap; AI Growth Zones; UK grid connection reforms consultation), and George Balston, “AI Sovereignty and National Security: Identifying the UK’s Dimensions of Control,” CETaS Policy Briefs, Alan Turing Institute. The Fable 5 timeline follows Anthropic’s own statements (suspension 12 June, redeployment 30 June/1 July). Economic figures are nominal source-year values; government time-to-power and cost figures are stated projections, not observed outcomes.