Back to Insights
Governance

When AI tools become part of the supply chain

On 12 June 2026, Anthropic restricted access to two models following a US export control directive. For European critical infrastructure, the lesson is not about data access. It is about uncontrolled dependency on the tools an organisation is starting to rely on.

Martin Lichstam
Martin Lichstam
Co-Founder & Chief Architect
June 13, 2026·6 min read
When AI tools become part of the supply chain

When European organisations talk about digital sovereignty, the discussion often lands on data: where information is stored, who can access it, and which laws apply. These are important questions, but they do not capture the full operational risk of a stack that sits outside the EU.

On 12 June 2026, Anthropic announced that it was restricting access to two models, Fable 5 and Mythos 5, following a US export control directive. According to Anthropic, the directive applied not only to users outside the United States, but to anyone who is not a US citizen, including people located in the US and Anthropic employees without US citizenship.

The decision shows that a tool used in day to day operations can become restricted or unavailable because of a US security assessment.

For Swedish organisations in critical infrastructure, that is an important reminder. The risk is not only about data access. It is about continuity and control over the tools the organisation is starting to rely on.

When AI becomes an operational dependency

For many organisations, AI began as support for text, summaries and analysis, something individual employees used alongside their ordinary systems. Increasingly, AI is now used in agents, automated workflows and internal decision support.

That can mean reading supplier documentation, reviewing contracts, compiling incident reports, analysing risk, or supporting development and security work. When AI is used this way, the model is no longer just a tool. It becomes part of the supply chain.

At that point it is not enough to ask whether there is a contract, a data processing agreement, or security documentation. The organisation also needs to understand what the service actually requires in order to function.

There may be a contract with a European supplier while a central function depends on a US AI model. There may be clear terms for personal data but no plan for what happens if the model can no longer be used for certain customers or in certain regions. There may be security documentation but no consolidated picture of the technical, legal and operational dependencies.

It is worth being precise about one point that is easy to miss. European hosting is not the same as European jurisdiction. A supplier headquartered in the United States can be reached by US legal process even when the data physically sits in a datacentre inside the EU. An EU region checkbox does not, on its own, remove that exposure.

The risk often arises in the gap between how a service is contracted and how it actually works.

The practical problem is not American AI. It is uncontrolled dependency.

The Anthropic example does not mean European organisations should stop using American AI. That would be neither realistic nor particularly helpful.

It shows something more concrete: AI has to be used in a way the organisation can manage if the conditions change.

If a workflow is built directly against a specific AI supplier, a restriction can quickly become an operational problem. That is especially true if the solution is tightly coupled to a particular model contract, a particular API structure, or a particular supplier's technical way of working.

In that case it is not enough to swap the model in theory. In practice it can require rebuilding, new security assessments, new contracts, new testing and new internal decisions.

For organisations in energy, water, transport, municipal services and other critical infrastructure, this is not an abstract technical question. It is a question of resilience.

Bounded keeps AI usable even when conditions change

Bounded uses AI where it creates value, including advanced models from leading suppliers, but the product is not built as a hard dependency on a single model or a single AI supplier.

If a model, supplier or infrastructure component becomes unsuitable, restricted or unavailable, we should be able to switch. Our customers should not carry the risk of a critical function standing or falling on a single supplier's jurisdiction, export controls, or security policy conditions.

We are not an alternative to all American AI. We are the layer that lets European organisations use AI without becoming blind to the dependency.

MostServicesvs.Bounded

Scroll to see how your data flows

Foreign-Controlled Cloud

Customer

Data lives here

Vendor Platform

Foreign-headquartered

LLM

Model

Same cloud

No sovereignty boundary. Foreign law governs everything by default.

EU Sovereignty Boundary
Customers
Energy / Utilities
Infrastructure
Critical Entities

Bounded

Governance Layer

Standby
Model B
Active
Model A
Standby
Model C

External, swappable, foreign jurisdiction.

For Swedish infrastructure operators, that is decisive. They need to be able to use the best technology, wherever it comes from, but in a way that can be governed, monitored, and changed when needed.

It also means AI has to be treated as part of the supplier picture. If AI agents are used for supplier review, security work, development, incident handling or document analysis, the organisation needs to understand which function the model supports, what information is processed, which suppliers and subcontractors are involved, what contractual terms govern the use, and what happens if access is restricted.

That is exactly the overview Bounded helps create: a consolidated picture of suppliers, contracts, subcontractors, technical dependencies and changes over time.

For organisations covered by NIS2 and the Swedish cybersecurity law, this is not only a technical question. It is part of maintaining control over the digital supply chain.

If you are mapping where AI already sits in your own supply chain, we are happy to help you get that picture. It is a good place to start, whatever you decide to do next.
Martin Lichstam

Martin Lichstam

Co-Founder & Chief Architect

Engineered high-performance products at Apple and Twilio. Now building the sovereign defense layer for European critical infrastructure, focusing on operational precision.