On 12 June 2026, the US Commerce Department issued an export control directive that forced Anthropic to pull its two most capable models offline for every customer in every jurisdiction. The government acted within hours of the decision. The trigger was a security concern serious enough to warrant immediate action.
The instinct to read this as good news for organisations running legacy enterprise software is understandable. The models that demonstrated the capability are gone. The threat they demonstrated is not.
What the ban actually changed
Fable 5 and Mythos Preview are offline. GPT-5.5, Claude Opus, Claude Sonnet, Kimi 2.7, and dozens of capable open-source models are not. The US government did not ban AI-assisted vulnerability research. It took one lab offline for a news cycle.
One hundred cybersecurity professionals, including researchers from Nvidia, Google, Adobe, and Sophos, signed an open letter making exactly this point. Their argument was direct: Fable and Mythos were not uniquely capable. They were the ones in the news. The underlying capability, the ability to scan enterprise codebases autonomously and find working exploits overnight, is now present across multiple model families. Removing two of them does not change the threat landscape. It changes the attribution.
The permanent exposure problem
For organisations running OpenText on supported, compliant versions, the risk calculus has not shifted materially. Vendors patch. Customers update. The window between discovery and exploitation is narrower than it used to be, but the mechanism still works.
For organisations running unsupported versions, none of that applies. A vulnerability found in an end-of-life version stays there permanently, because no patch is ever coming. The brief absence of the most prominent tools in this space is not a security improvement. It is a pause in the news cycle, not a pause in the underlying risk.
The brief absence of the most prominent AI security tools is not a security improvement. It is a pause in the news cycle.
What OpenText already knows
Vendors have their own tooling. OpenText, like most enterprise software vendors, runs adoption and telemetry analysis on customer deployments. They know which versions are in use, which installations are out of compliance, and where the exposure sits. The temporary unavailability of publicly accessible AI models does not affect what the vendor already knows about your deployment.
What it may affect is the false sense of breathing room some organisations will take from the news. That breathing room is not real.
The only useful response
Knowing your licence and support position is not a theoretical exercise. It is the only way to understand whether you are running software that can be patched and whether your compliance position entitles you to those patches when they exist.
If your deployment is on an unsupported version, the question is not which AI model found the vulnerability. The question is whether the vulnerability exists in your version and whether anyone can fix it. A temporary export ban does not change either answer.
The window that matters is not the one that closed on 12 June. It is the one between now and the point at which your exposure becomes someone else's opportunity.