Localised AI Models and Centralised Diffusion
On June 12, 2026, the US government directed Anthropic to suspend access to Fable 5 and Mythos 5 for all foreign nationals. The mechanism was an export control directive; the technical mechanism was an API geolocation check. This demonstrated something that had been theorized but not yet observed: centralised diffusion, where models are jurisdiction-bound by default.
Executive Summary
On June 12, 2026, the US government issued an export control directive requiring the immediate suspension of access to Anthropic's Fable 5 and Mythos 5 models for all foreign nationals, everywhere. The stated reason was a narrow jailbreak technique. The mechanism was simple: disable the API globally, revoking access from hundreds of millions of users based on a single jurisdiction's regulatory decision.
This event demonstrates centralised diffusion—the emerging architecture of AI access in which models are bound to jurisdictions, deployable only within defined borders, and subject to control by regulatory bodies.
Centralised diffusion is distinct from the "international diffusion" framework that has dominated policy discussion since 2023. International diffusion assumes models will be available globally, with variation in access terms, pricing, or capability. Centralised diffusion inverts this: models are default-local, with access to other jurisdictions as an exception requiring explicit permission.
This report examines several observations. First, localisation is now the baseline architecture—the Fable/Mythos suspension revealed that models can be instantly geographically restricted without technical constraint. Second, regulatory authority now precedes technical deployment. Anthropic built Fable with extensive safeguards, red-teamed them with government participation, and documented them transparently; none of this prevented suspension. Third, because models are deployed as metered API services rather than distributed weights, control happens at the endpoint layer—governments restrict API access. Fourth, centralised diffusion is economically self-reinforcing: a model available in the US serves US customers at low per-token cost due to scale, while the same model restricted to a single jurisdiction serves fewer customers at higher cost. Fifth, developing countries face constraints in building autonomous AI infrastructure when deployed models may be subject to suspension.
The central finding is that centralised diffusion emerges naturally from the current infrastructure and governance environment.
Definitions
Three concepts need separating, because policy discussion has blurred them:
Localised Model
An AI model deployed with explicit jurisdictional restrictions on access. Users outside the defined jurisdiction cannot use the model, either through technical restriction (IP geolocking, authentication rules) or legal prohibition (export control, regulatory directive). The model is operationally bound to a single nation-state's regulatory authority.International Diffusion
A model available globally, with optional variation in terms of service, pricing, capability, or data retention. A single provider controls the model, but access is geographically distributed. The model operates across jurisdictions under a single legal and contractual framework.Centralised Diffusion
The systematic shift toward localised models as the default architecture for AI deployment. Individual jurisdictions build or acquire models bound to their territory. Cross-border access requires explicit exemption.The "AI diffusion debate" of 2023-2026 largely assumed an international diffusion model. Some proposals aimed to expand access (democratise training compute, open weights); others to restrict it (export controls, capability tiers). Centralised diffusion asks why models should diffuse globally at all. The answer from multiple governments, simultaneously, is increasingly that they should not.
(From a centralisation perspective, this looks like democratisation—more actors have model access. From a governance perspective, it multiplies the regulatory points at which AI access can be restricted.)
The Fable/Mythos Suspension
The Fable/Mythos suspension did not emerge from a vacuum. It is the culmination of a regulatory escalation extending back several years:
First export controls on advanced chips
The US Department of Commerce restricts exports of Nvidia's most advanced GPUs to China, citing national security concerns. This marks the first explicit weaponisation of compute as a geopolitical asset. The framing shifts from open science to strategic control.
Biden-Harris AI Diffusion Rule
The Bureau of Industry and Security formalises export control logic into a comprehensive regulatory framework. Advanced AI exports are gated by national security assessments, country tiers, and licensing requirements covering both semiconductors and certain closed AI model weights.
Rule rescinded, controls remain
The Department of Commerce rescinds the Biden-era rule citing burden and diplomatic consequences, though export controls on advanced chips remain active. New guidance tightens restrictions on offshore chip use. A replacement framework is signaled.
Trump administration: allies-first model
Policy shifts toward preferential access for allied states and tighter restrictions on adversary states. Location verification proposals emerge to prevent restricted chips from reaching prohibited jurisdictions after point of sale. The mechanism shifts from security-filtered to commercially conditional, with geopolitical alignment as the primary filter.
India's Charter for Democratic Diffusion
At the India AI Impact Summit in New Delhi, the Charter for the Democratic Diffusion of AI is endorsed by 20 countries and 4 international organizations. It reframes diffusion as a development challenge focused on building local capacity and sovereignty, rejecting binding obligations in favor of voluntary coordination. The MAITRI platform is proposed as implementation infrastructure.
Fable/Mythos suspension
The US government directs Anthropic to suspend API access to Fable 5 and Mythos 5 for all foreign nationals. The mechanism is export control authority applied directly to API access—an escalation from hardware to service provision.
The suspension reveals three technical facts:
API-based deployment is instantly geo-restrictable
Fable/Mythos are deployed as metered API services, making geographical restriction a configuration change. The US government did not need to seize servers, intercept model weights, or interrupt infrastructure. It issued a directive; Anthropic updated the API's geolocation check. Open-weight models, once public, cannot be recalled; API services remain under continuous control.Regulatory authority precedes technical rigor
Anthropic's safeguards for Fable were extensive: 1000+ hours of red-teaming with the US government and UK AISI, a defense-in-depth strategy combining narrow-jailbreak resistance and monitoring, 30-day data retention for jailbreak research, and clear documentation of limitations. None of this prevented suspension. The government concluded that the existence of a jailbreak method—regardless of severity or prevalence in other models—warranted removal.Export control law now applies to API access
Historically, export control applied to physical goods and technical data. The Trump administration extended it to model weights. The Biden residuum extended it to API access. The entire deployment pipeline—training through inference—is now subject to export control.What enabled this to happen with minimal procedural obstacle? The absence of a governing framework for model suspension. Anthropic had no formal recourse: no requirement for due process, technical review of the jailbreak's severity, proportionality assessment, transparency about the government's specific concern, or notice period for compliance. The company complied because non-compliance risked sanctions; the government issued the directive because no statute prohibited it.
(Export control of semiconductors affects supply chains; affected parties have months or years to adapt. Export control of a deployed API affects users instantly and globally.)
Before June 2026, the question was whether a government could restrict global access to a model. The suspension answers it: yes, instantly, under existing legal authority. The question now becomes whether governments should restrict global access. Major powers are converging on yes.
Evidence from major powers:
United States
Fable/Mythos suspension; continued export control of frontier models; geopolitical alignment tests for model access.China
Localised deployment within the Great Firewall; restrictions on cross-border data flows.European Union
Digital Sovereignty Action (June 2026) mandating local data processing for critical models.India
Draft framework requiring model localisation for financial and health sectors.Russia
Deployment of domestically-developed models with mandatory state review.These are parallel moves toward the same architecture.
The Architecture
Localised model deployment operates across three technical layers:
Layer 1: Model Acquisition
Train domestically (requires capital, data, expertise). License from a major provider (requires permission and compliance). Download open weights (requires compute and ongoing fine-tuning).Layer 2: Inference Deployment
Deploy on local infrastructure (data centers, edge networks). Set up authentication (geoblock foreign IPs, restrict user access). Monitor inference (detect jailbreaks, misuse, policy violations).Layer 3: User Access
API service (local users only). Web interface (IP-restricted). Integration with local applications. Compliance with local data residency requirements.Localised diffusion requires supporting regulatory infrastructure:
Export Control
Classifying models as controlled materials and requiring permission for cross-border transfer (in place in US, EU).Data Sovereignty
Requiring inference data to remain within national borders, processed by local entities (in place in India, EU, Russia).Content Regulation
Requiring local operators to ensure compliance with local laws—and therefore requiring local operators, not foreign APIs.Labor/Tax Sovereignty
Requiring AI services to source labor and infrastructure locally to ensure tax compliance and labor law enforcement.Security/Surveillance
Giving government access to model outputs, user data, or audit logs (in place in China, Russia, increasingly proposed in US/EU).Together, these create incentives for localisation: a company deploying globally must comply with all these simultaneously; a company deploying locally complies with one jurisdiction.
The supply chain implications are significant. Pre-localisation, Anthropic/OpenAI train models in California and deploy globally via API. Post-localisation, US companies train for US deployment and export-permitted allies; China trains for China and Belt & Road partners; the EU trains for EU citizens; smaller countries license or adopt open-source models. Each supply chain develops different architectures, safety practices, and governance. Interoperability becomes difficult; standards diverge. This efficiency loss is intentional—regional control takes priority over global efficiency.
Democratisation vs. Localisation
The diffusion policy debate of 2023-2026 framed access expansion as democratisation. Democratisation aimed to expand capacity for training and inference globally by reducing barriers to entry—lower chip costs, open-source weights, tutorials. Localisation contains models within jurisdictions by mandating local deployment, restricting cross-border access, and applying export control.
Goal
Democratisation: Expand capacity for training and inference globally.Localisation: Contain models within jurisdictions.
Mechanism
Democratisation: Reduce barriers to entry (lower chip costs, open-source weights).Localisation: Mandate local deployment, restrict cross-border access, export control.
Outcome
Democratisation: Models as tools anyone can use.Localisation: Models bound to jurisdictions, governments control deployment.
Both produce a landscape with more actors having model access, though the governance structure differs. The outcome is jurisdictional compartmentalisation.
Autonomous Capacity
The foundational premise of the diffusion debate was that if developing countries can train models, they can build autonomous AI capability. This premise depends on deployment remaining coupled with training. A country can train a frontier model while being prevented from deploying it across borders; training and inference are now decoupled.
Consider: India trains a world-class language model competitive with GPT-5. Technically, this is autonomous capability. India cannot deploy it globally—export control restricts cross-border access. Indian users can use it; users elsewhere cannot. India has trained a model but cannot monetise it, scale its capabilities through user feedback, or establish market dominance. It operates at regional scale.
True autonomy requires both training capacity (ability to build models) and deployment capacity (ability to serve models globally at scale). Localisation decouples these: training is distributed (many countries can train), deployment is centralised (only major powers can serve globally). The inference economy recreates the asymmetry it was supposed to resolve.
The Geopolitical Logic
Why are major powers moving toward localisation? The answer is geopolitical.
United States
Protects OpenAI/Anthropic revenue by restricting competitor access to US users. Preserves US capability to deploy in allied nations through export control exceptions. Gives US government leverage over global deployment.China
Creates a walled ecosystem where Chinese companies serve Chinese users. Prevents US models from reaching Chinese users. Gives government visibility and control over all model deployment.European Union
Supports EU tech sovereignty goals. Creates opportunities for European AI companies. Provides leverage through data residency and content regulation.Developing Countries
A way to assert independence from major powers. Prevents models from encoding foreign values. Allows governments to control AI deployment in accordance with local laws.(From a purely rational standpoint, localisation is geopolitically optimal—it gives each jurisdiction control and prevents dependencies on foreign infrastructure. This assumes jurisdictions view AI deployment as zero-sum. Geopolitical logic prevails over economic logic when security and autonomy are perceived as threatened.)
The Institutional Vacuum
Localisation is possible because there is no international framework preventing it. There is no UN Convention on AI Access, no treaty establishing model deployment as a right, no dispute resolution mechanism for export control. When the US suspended Fable/Mythos, Anthropic had no recourse—it could not appeal to an international body, challenge the government's reasoning, or request procedural safeguards.
The UN's AI governance initiatives have produced no binding instruments; the Global Compact on Digital Rights remains voluntary; the proposed AI Neutrality frameworks have no enforcement mechanism; MAITRI and other regional diffusion initiatives focus on building infrastructure, governing access only indirectly. In the absence of binding international law, unilateral action by major powers fills the space.
What Autonomous Deployment Would Require
To resist localisation and maintain genuine autonomous capacity, developing countries would need frameworks preventing unilateral suspension. This is technically and institutionally difficult.
Technical
Redundant inference infrastructure across multiple jurisdictions so no single government can disable service. Model weights deployed openly so they cannot be recalled. Community governance so no single entity can be pressured to suspend.Institutional
Agreements with other countries to not enforce unilateral export control. Regional frameworks establishing model deployment as a public good. Binding dispute resolution mechanisms for access disputes.Economic
Sustained investment in regional inference infrastructure. Coordination to achieve competitive per-token cost. Revenue models that do not depend on a single jurisdiction.This is achievable—it requires will and capital, though developing countries must coordinate in ways they have not yet demonstrated willingness to do.
The Path Forward
Localised diffusion is now the baseline assumption for major powers. The question is whether developing countries will accept it or resist it.
Acceptance means building local models and accepting local deployment, dependent on local infrastructure and subject to local government control. This is lower-cost and easier to implement, though lower-autonomy and creates rental dependencies.
Resistance requires five things:
Regional Inference Infrastructure
African countries deploy shared infrastructure. Asian countries coordinate on ASEAN-wide deployment. Regional scale avoids the inadequacy of national efforts and the impossibility of global deployment.Open-Weights as Default
Open-source models cannot be recalled by unilateral government action. Developing countries should prioritize deployment of open models and invest in their improvement to eliminate dependency on closed APIs.Regional Governance Frameworks
No recognition of unilateral export control between member states. Commitment to maintain deployment of each other's models. Shared dispute resolution for access conflicts.Regional Compute Investment
African Union, ASEAN, Arab League, MERCOSUR should establish regional inference infrastructure as public goods, since individual countries cannot sustain their own data centers.Negotiating Power
A billion users in Africa and South Asia represent trillions of inference tokens—leverage that can be used to negotiate terms of access and governance.Centralised diffusion—localised models bound to jurisdictions—is now the baseline for major powers. The Fable/Mythos suspension was a demonstration. The question developing countries face is whether they will be active participants in shaping it or passive consumers of it. Passive participation means adopting local models as dictated by major powers or renting inference from regional providers, accepting that models are jurisdiction-bound. Active participation means building regional infrastructure, coordinating on governance, and establishing frameworks that prevent unilateral suspension.
The infrastructure and governance for active participation are in progress. Building them is the work of the next 2-3 years. Every month that major powers consolidate localised deployment increases the cost of establishing alternatives. For developing countries, the question is how to build autonomous AI infrastructure that cannot be unilaterally suspended by foreign governments—a question requiring different investments, coordination, and governance frameworks.