Every ASEAN Enterprise Was a “Foreign National” for 18 Days
- By Winston Thomas
- August 18, 2026

At 5:21 p.m. Eastern on June 12, 2026, a letter reached Anthropic. Hours later, the company’s two most capable models went dark for every customer on earth.
The U.S. Commerce Department had invoked export-control authority after a reported jailbreak. Anthropic said it disagreed. It complied anyway. The directive barred access by “any foreign national, whether inside or outside the United States.” Anthropic could not verify nationality in real time across Amazon Bedrock, Google Cloud, Microsoft Foundry and its own API, so it switched everything off. Claude Fable 5 stayed down for 18 days, until Commerce lifted the controls on June 30.
Nothing broke, and there was no breach, bankruptcy, or flooded data center. Someone made a policy decision in a capital where your board has no vote, and a production dependency vanished the same evening. Now check your continuity plan for that scenario and in most cases it won’t be there.
Why this stops being academic
Chief executive officers told IBM that AI was already making 25% of operational decisions in early 2026. They expect 48% by 2030. Half your operating decisions, routed through dependencies you did not build and cannot see into.
The IBM Institute for Business Value surveyed 1,000 senior executives across 16 countries and 17 industries between February and April 2026, with Oxford Economics, publishing the results as “The Calculus of AI Sovereignty”. The headline numbers:
- 91% do not fully understand their AI dependencies across vendors, models and infrastructure. Only 9% rate their understanding excellent.
- 71% say switching their primary AI vendor or model would be difficult today.
- 81% say a seven-day outage at their primary AI vendor would be severe or critical, effectively halting operations.
- 6: The average number of AI-related operational disruptions executives absorbed over two years. Vendor service disruption topped the causes.
Eighteen days is longer than seven.
The easy objection is that you weren’t running Fable 5. But the model isn’t what changed in June; the precedent did.
AI sovereignty is control, not ownership
IBM defines AI sovereignty as an organization’s capacity to control its AI stack: infrastructure, data, models and operations. Strip down the language and it means answering one question: Can you move data, swap models and shift workloads when a dependency changes on you, whether that change is technical, commercial or regulatory?
Data sovereignty, where most of the focus had been and where many regulators are still formulating laws, answers a narrower question: Where does your data sit, and whose court order reaches it? It tells you nothing about who controls the model reading that data, who owns the orchestration layer routing the call, or whether you can walk when the price triples.
81% say a seven-day outage at their primary AI vendor would be severe or critical.
Fable 5 was down for 18.
Dependency itself has changed shape. Legacy dependency lived in infrastructure and applications and moved on a release schedule. AI dependency runs through the model layer, where behavior drifts without a new version release and terms of service change without warning. Ranked by frequency over 24 months, the shocks executives hit most often were price increases, then changes to terms of service, and then model deprecation.
The switching math no CDO wants to present
So what should a CDO do? Start with the timelines. They are what a board will remember.
Executives estimate an average of 145 days to move AI training and operational data to a different environment. 57% say replacing a core model would require significant decoupling or a full system rebuild. 56% say shifting core AI systems to another vendor would take at least six months. And 68% say meeting data residency requirements across geographies is already hard.
String those together, and a tactical vendor change becomes a fiscal-year program.
Then comes the finding that should stop any CDO cold. Multi-vendor estates that look like resilience mostly aren’t. When IBM ranked what actually drives vendor diversity, organizational fragmentation came first, then geographic and regulatory constraints. Deliberate risk management ranked last. The multi-vendor AI estate at most regional banks and telcos was never engineered; it accumulated from an acquisition, a country subsidiary, and a procurement workaround, and it delivers every cost of redundancy with none of the leverage.
Inventory the non-portable joints, the places where extraction is contractually or technically blocked. Next, standardize portability formats across proprietary and open-source environments so migration doesn’t start with a translation project. Then, build internal mirrors of critical training data, and test extraction from vendor environments before the day you need it.
Make sure fine-tuning and retraining can run internally or at a second provider, and validate the model-swap pipeline rather than assuming it. Lastly, take the CFO’s two metrics and put them in your own reporting: time-to-switch and cost-to-switch, per tier one system.
IBM’s own benchmark for success is specific. Migration should take weeks, not months, and alternatives should be validated rather than assumed.
Sovereignty is a budget line
Data placement is a CDO decision with a price tag attached. Organizations pay 2.8 times more in token processing when data sits far from where the model executes — roughly USD50 million a year in extra cost for a USD20 billion enterprise, buying no additional capability.
Run it the other way, and the case makes itself. Organizations with the strongest practical control across data, models and infrastructure protect 55% more operating profit from AI-driven disruption. 72% of executives say they would absorb a 20% cost increase to keep multiple vendors live.
Data sitting far from where the model executes costs 2.8× more in token processing — about USD50 million a year for a USD20 billion enterprise. It buys no additional capability.
None of that argues for owning everything. IBM’s framing is selective sovereignty: a set of dials, not a switch:
- Tier one covers fraud engines, credit decisioning, and proprietary algorithms. Validated alternatives, tested egress paths, rehearsed outage drills.
- Tier two is customer service AI, HR analytics, supply chain optimization: managed dependency, modular architecture, contractual exit rights.
- Tier three is transcription and translation. Buy it and stop gold-plating it.
Sri Lanka Telecom sits outside ASEAN, but its fix is the most transferable one in IBM’s research. Constant hyperscaler model updates kept forcing the team to rework solutions, so they built an AI gateway that abstracts model dependencies, letting them swap models and providers with minimal disruption to applications. Not a moonshot. An abstraction layer, and a refusal to hard-code a vendor into the business.
ASEAN’s patchwork is the operating environment
Singapore's digital development minister, Josephine Teo, made an adjacent point in Jakarta in June 2026, cautioning that treating sovereignty as ownership of the entire stack, chips to applications, is “neither realistic nor helpful for most countries.”
Enterprises here already straddle sovereign clouds, national data centers, hyperscaler regions and edge sites scattered across archipelagos. Layer on Vietnam’s AI Law (No. 134/2025/QH15, effective March 1, 2026, and binding on foreign entities), Indonesia’s PDP Law, Singapore’s PDPA and sectoral rules from MAS to Bank Indonesia. The correction has started: 24% of enterprises have repatriated workloads from public cloud, and another 38% intend to.
Watch the telcos. They sit inside national borders, answer to domestic regulators and increasingly own the data centers. IBM’s report casts them as infrastructure partners for sovereignty rather than connectivity vendors.
What answers the June 12 problem
So what actually failed on June 12? Three things, in sequence. Inference ran on infrastructure the customer did not control. The model could not be substituted inside a working day. And the customer held none of the keys, logs, or the decision.
IBM’s answer is IBM Sovereign Core, announced in January 2026 and generally available since Think 2026 on May 5, 2026. Put it against those three failures rather than on the sovereignty label.
Take where inference runs. Sovereign Core deploys models, inference services, and agents inside a customer-defined boundary, on customer-provided infrastructure, and model execution can be pinned locally with no external provider access. A directive aimed at a hosted API does not reach a model already running in your own data center. That is the structural difference between renting intelligence and operating it.
Substitution comes next. The platform accepts IBM’s models, open-weight models or your own, and its partner catalog includes Mistral alongside AMD, Cloudera, Dell, Elastic, Intel, MongoDB and Palo Alto Networks. An open-weight European model running in-boundary is a materially different dependency from a U.S. frontier API, and it is the closest thing on the market to an answer for the 57% who say a model swap means a rebuild.
Then the switches. The control plane is customer-operated, and identity, encryption keys, secrets, logs, and audit evidence stay in-boundary. Compliance controls are enforced at runtime rather than assessed afterward, with more than 160 preloaded regulatory frameworks and evidence generated and retained on your side of the line. For a CDO reconciling MAS, Bank Indonesia, and Vietnam’s AI law across one estate, that turns audit from an assembly exercise into a query.
Built on Red Hat OpenShift and Red Hat AI, IBM Sovereign Core deploys on premises, in-region, or through a regional service provider. It is how the telco argument becomes procurable rather than theoretical. IBM has also published a statement of direction committing to open-source the core components of the foundation, and that’s the whole ballgame. Deliver it, and the lock-in objection dissolves.
Apply the skepticism you would give anyone offering to map your dependencies for you. Then use the one test that works on every vendor in the room, IBM included: Ask what exit looks like, in days; then ask them to put the number in the contract.
CDOs spent a decade making data portable. The next decade is about making decisions portable. Start where June 12 began, with a written list of everything that stops working when someone else's government sends a letter.
Image credit: iStockphoto/Fotolite
Stay ahead with CDO Nexus
Join an exclusive community of CDOs and data leaders
- Access curated trends and thought leadership from IBM and industry experts.
- Participate in private roundtables and webinars to solve regional CDO challenges.
- Connect with a network of like-minded leaders navigating the same data landscape.
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.