Sovereignty stops being a think-tank topic and becomes a head-of-state agenda item
Last week the lesson was blunt: the ground you build on can be pulled out overnight by a decision made in another capital. This week the story moved out of Anthropic’s blog and into the G7, a Seoul press conference, and a US export doctrine that appears to cover any frontier model served from American soil. The freeze on Fable 5 and Mythos 5 is still in force, but the first signals of a thaw arrived alongside a much larger realisation: the “kill switch” issue isn’t a one-off. It’s a structural feature of how the AI economy is currently set up and the implications of what this means for implementation in workflows. Here’s what I learnt on AI in Trading this week:
1. From Kill Switch to G7 Membership
The episode that reframed everything last week escalated fast. The G7 summit at Évian-les-Bains failed to reverse the US export controls that knocked Fable 5 and Mythos 5 offline globally, and the restriction remained in effect. And the standoff behind it spilled into the open: Bloomberg published the letter from Commerce Secretary Howard Lutnick warning Anthropic it would need a government licence to grant any foreign national access to the models – anywhere in the world, on pain of criminal and civil penalties. Internal messages obtained by the New York Times reportedly show Anthropic staff arguing the lab is being unfairly targeted and “bullied” – employees arriving at the same conclusion as many that this looks more like a relationship issue rather than one of safety.
At a closed-door meeting on June 17, Anthropic’s Dario Amodei and Google DeepMind’s Demis Hassabis called for a US-led coalition to shape international AI rules and standards – with Canadian PM Mark Carney signalling the US could lead it. Amodei argued cooperation should cover structured access to frontier models and chip trade that excludes China, plus joint work on cyber, bioterrorism and intelligence risk. OpenAI’s Sam Altman pushed instead for a neutral international testing forum. The room also included Mistral’s Arthur Mensch, Cohere’s Aidan Gomez, Salesforce’s Marc Benioff and Meta’s Alex Wang. No binding commitments emerged. Separately, Macron announced that Western democracies would stand up a coordinated AI cooperation platform within a month, with a follow-up in September.
The same companies who spent the last month fighting their own governments over access used the G7 to pitch Washington as the leader of global AI governance. The proposed fix for “one government can switch you off” is apparently a club of governments who get to decide who’s trusted – that’s a different model of access now based on whether or not you are invited to join the club.
Why this matters for trading: For a European desk, the question shifts from which provider do I depend on to “is my jurisdiction inside the membership club and on what terms” – and how you manage that as a global organisation spanning several jurisdictions at once. That’s not something a procurement team can hedge. Model access has become a policy variable, and it belongs on the same watchlist as any other macro or regulatory exposure – monitored continually at an operations and board level, with open-source kept in reserve as the fallback.
2. The Doctrine Underneath It – and Why Every API Is Now in Scope
The “deemed export” doctrine, codified at 15 CFR 734.13, treats releasing controlled technology to a foreign person inside the US as an export to that person’s most recent country of citizenship or permanent residency. By one account, the Fable 5 directive is the first time it has been applied to a commercially deployed AI inference API – a running cloud service – rather than to physical goods, source code or technical data. As Bloomberg’s legal analysis put it, Lutnick has expanded the boundaries of export law to target just the use of a model.
This means any organisation whose operations depend on a US frontier model accessed via API is now subject to the same export-control framework that governs advanced weapons components – with no contractual protection, no advance-notice requirement and no guaranteed restoration timeline. Legal advisers are already telling firms to map which users, business units and jurisdictions had access, determine whether any foreign nationals inside or outside the US could reach the models directly or indirectly, and confirm whether any providers still route traffic to them through managed services.
Why this matters for trading: The risk here isn’t where your data sits – it’s now who your people are. A multinational desk in London or Frankfurt staffed by non-US nationals is precisely the configuration the doctrine reaches, and no data-residency clause touches it. That makes model access now an operational-resilience question: requiring mapping which desks and dependencies fall in scope, and treat “this could be switched on the basis of who’s at the desk” as a live scenario to plan for – whatever the contract says.
3. Seoul: the First Cracks in the Freeze
Anthropic’s Managing Director of International, Chris Ciauri, said at a Seoul press conference that the company was “very confident” the models would become available again in the coming days. Separately, Bloomberg reported that some firms who were chosen early to test Mythos ahead of wider release still had access to a preview of the system, despite the order that shut down other versions.
Korea has been at the centre of the controversy after the Washington Post reported that a Korean telecommunications company with Mythos access triggered the directive over suspected ties to China. Reports tie the order to a jailbreak discovery plus concerns that SK Telecom had accessed Mythos 5 through Project Glasswing. Anthropic, for its part, maintains the technical case is thin: it reviewed a demonstration of the cited technique and found only a small number of previously known, minor vulnerabilities, which other publicly available models can also discover.
Why this matters for trading: That some preview partners kept access throughout the freeze is the tell- tale sign: restoration isn’t a return to open access but a tiered, vetted-partner model – differential, conditional, revocable. Who gets back in first, and on what terms, is the clearest early signal of how this new membership club could actually operate in practice.
4. Sovereignty Goes Mainstream – and the “Application Layer” Comfort Blanket Comes Off
The outage landed on top of an EU policy push already in motion. On June 3rd the Commission published its Tech Sovereignty Package, spanning chips, infrastructure, cloud and AI, with the Cloud and AI Development Act at its core, aiming to triple EU data-centre capacity over five to seven years. But the sharper commentary this week pushed back on Europe’s favourite reassurance – that it can win at the application layer and rent the frontier from others. One widely shared analysis argued that building applications on market-leading foreign models does not solve sovereignty, and that interventions meant to secure autonomy can instead entrench dependence.
A new report, flagged in last week’s newsletter, highlights a structural vulnerability: the AI Act is premised on US providers not wanting to lose the European market – but if compute becomes scarce, there’s little incentive for them to keep serving Europe. And the Palantir episode showed the anxiety isn’t theoretical: France’s intelligence services moved to drop Palantir in favour of a domestic provider, citing strategic autonomy, while UK parliamentary debate flagged that European data in European data centres can still be reached under US law, contracts notwithstanding.
Why this matters for trading: chasing full autonomy across the entire stack would run into the trillions – but instead firms are looking to prioritise the layers where dependency is most strategically dangerous with compute and energy first, then identify which model dependencies are genuinely load-bearing for execution and risk, and which are conveniences. Sovereignty isn’t owning everything – it’s knowing which switch you can’t afford to have flipped.
5. Trading Desks Carry On Adopting – and the Monitoring Gap Surfaces
Meanwhile AI in trading – particularly fixed income keeps advancing. At the ICMA conference in London at the end of May, Aberdeen’s Louise Drummond described building agents to take on heavy-lift tasks with access to the firm’s data, processes and policies, having run no-touch trading since 2023 on passive and low-value flow, then using AI to analyse the results and decide where to automate next – telling the room the firm is “probably at the start of our AI journey.” BNP Paribas AM’s Yannig Loyer was optimistic on AI in fixed income trading, foreseeing parts of the bond market eventually fully agent-traded – from systematic investment decisions to smart order routing, RFQ and liquidity provision – while noting the first practical use case was parsing of runs. DekaBank’s Thorben Lüthge described a bias-removing tool that now gives every primary-book trader a hedging recommendation based on market parameters, structure and the supply-demand situation – producing less variance, with one comment that AI is “much more neutral” than the desk’s people. The scale is striking: industry analysis suggests 70–80% of standard execution flow – prechecks, order management, fill monitoring – could eventually run autonomously, shifting traders toward execution strategy, exceptions and stressed situations.
While the panellists were firm that everything runs with a trader, compliance or risk in the loop to verify results and that client outcomes are as expected – there is now a new issue to solve for. In a new GovAI technical report the authors raised the question of how well are AI agents behaving? Frederik Hytting Jørgensen and Aidan Homewood examined the “offline monitoring” frontier labs use to police their own internal agents – recording every action an agent takes, then having a separate “monitor” model review the transcripts after the fact for suspicious behaviour like disabling logging or tampering with research. Their conclusion is that from current public disclosure, you can’t tell how well it works end-to-end. A monitor flagging an attack doesn’t mean a human ever sees it – the transcript can be filtered out, badly summarised, or missed in review. They suggest labs publish the monitoring rate, pipeline recall, human recall and detection lag – the numbers that tell you the actual probability of catching something.
Why this matters for trading: This is the same tension as last week’s “stochastic engine, deterministic pipeline” problem, now showing up in production. The firms pairing autonomy with human-in-the-loop verification and neutrality claims are moving in the right direction, but neutrality is itself a model property that can drift after an update, and “a human is in the loop” only reduces risk if the concerning signal actually reaches that human. The report’s distinction – between whether the alarm works and whether anyone acted on it – is precisely the question a desk running agentic RFQ or hedging now needs to answer about its own controls. Worth noting too: if labs themselves can’t yet evidence end-to-end detection on their internal agents, the desks deploying those models downstream are inheriting a monitoring gap they didn’t create and can’t see into.
The real takeaway for trading desks is the dependency you’re managing isn’t just on a model, it’s on agents reliable enough to deploy, accountable to a named human, and whose reach you can actually see and control. You can’t hedge that with a procurement clause in an agreement – that can only be built for.
Thanks for reading,
Rebecca


