# Navigating AI Export Controls and Supply Chain Resilience

**Podcast:** HMZE
**Published:** 2026-06-18

## Transcript

Dann muss man nur ein Outage sein.
Nein, nicht ein Outage, sondern ein Outage.
Ja, Outages.
Outages, viele Leute haben über die Wochen erlebt.
Wir brauchen ein Outage.
Willkommen zu einer anderen Episode von unserem neuen Season von Beyond Vibe Coding, Partnering mit Impala Search.
Der go-to Tag- und Executive-Search-Agenz in Deutschland.
In diesem Podcast, wir beschäftigen die transformationalen Veränderungen in Software Engineering und Knowledge Work in generell.
I'm Sebastian Heidelmeier, zu Erben, CTO at NorthIO.
And I'm André Neubauer, CTPO at Trusted Shops.
Great to have you back.
This time it's an emergency episode.
Correct.
Our weekends went totally different than we had planned.
Just kidding.
Obviously, as you may assume, we want to cover the latest event on Fable 5, the new frontal model of Anthropic.
And in this episode, we present our viewers to CTOs with...
A couple of years of experience.
So how we look at this.
Without further ado, let's jump right in.
Welcome to a special episode of the Beyond Vibe Coding Podcast.
This time it's only André and me.
And the reason why we're talking alone or just the two of us is we wanted to cover the fairly recent Fable 5 incident for those who have been living under a rock or are not that AI fascinated.
like we are.
I will briefly explain what happened.
Yeah, for those of you who live under a rock, Sebastian, you want to summarize what happened last, I think, Friday, right?
It was already Saturday in Germany, but what happened on Friday?
Yes, maybe before we get there, first of all, what is Fable 5?
Fable 5 is the first mythos model that was publicly available to the global user base of Anthropic.
Und da war wirklich ein vieles Hype around.
So ich sah viele Leute von meiner Nutzung auf LinkedIn auf den Linken, die es ein goertig sind.
So es war ein sehr guter Modell, speziell auch für Coding-Use-Cases.
Und dann auf der Saturday morning, da war ein Schock, weil es keine Fable 5 mehr war.
Wir haben die Message in einem ...
WhatsApp group that we are in where somebody was posting it, right?
I also, I had actually only on Friday evening, I had started to write a new app and test it out a little bit and see with the long spec, how far can the model go?
And then I wanted to iterate on it on Saturday morning.
And I was like, hey, what's going on?
Why is it not working, right?
And then, yeah, the message and suddenly I knew why it wasn't working.
So what happened on Saturday was that apparently Andy Jassy, or that's at least the rumor, made the US government aware that there was apparently a jailbreak in Mythos, sorry, in Fable 5, which is essentially a Mythos model with some restrictions.
And the government immediately issued an export control directive on the model, which means that no non-US citizen, this includes, by the way, Antropik employees who are living in the US, actually, they are not allowed to use this model anymore.
And only US citizens were allowed to use this model.
And this really was a big topic over the weekend.
And everyone was talking about how this must be seen actually as a geopolitical move as a big issue for European companies, but not just European companies globally.
Ich denke, die ich, was auf jeden Fall, was ein WAKE-up-Call.
Das ist jetzt ein WAKE-up-Call für XYZ.
Aber ich habe auch mein Weekend geplant.
Ich habe auch angefangen mit Fabel 5 an, auf dem Freitag.
Ich habe mich sehr gefühlt.
Ich habe auch einen Schreinstell.
Ich war sehr, sehr hungry, sehr aggressiv und dann war ich wirklich wirklich glücklich für die WEEKEND, wie ich es noch einmal probiere und habe einen besseren Verständnis auf den IMPACT und dann ja, die WEEKEND went different.
Beside, ich denke, unseren Plans für die WEEKEND, ich denke, die Frage und ich habe eigentlich nicht, ich habe eine VIEW, aber ich habe nicht mehr als meine Finalen Conclusion.
Was ist die Takeaway?
Weil du könnt auf das Event aus sehr unterschiedlich angeln und du könntest bemerkst, sagen wir alle das alle, in der Risk Assessment-Likkelheit haben, dass sie das auf null ist.
Und ich denke, wir haben jetzt gelernt, es ist anders.
Dann könnte man auch sagen, es ist Fable 5, all die andere Sachen bleibt, so warum care?
Und dann, du musst immer wieder sehen das.
So I think very different views and also very different reactions are currently, you can read it currently at LinkedIn or like whatever your source of information is.
Absolutely.
Yeah.
What I find fascinating to begin with is that my initial response to Fable 5 was also like, wow, this is super impressive.
And then I tried the app that I Ich habe versucht, mit Fable 5 zu Ende zu arbeiten.
Ich habe dann mit Sonnet gesucht, die ich für Coden benutze, weil ich nicht mehr habe, zu Fable.
Und die fixen dann funktioniert.
Und ich habe dann auch eine neue Art, wie Cloud Code, ich denke, approaches Codenprojekte.
Ich habe nicht so einen neuen Projekt in einem Moment mit Cloud Code angefangen.
Ich habe dann oft mit Cloud Code angefangen.
Ich habe dann oft mit Pi gearbeitet.
Ich war nicht sicher, dass ich das neue Mode war.
Aber dann meine initiale Impression war anders.
Ich war nicht so impressed, als ich war, als ich war.
Und ich habe zu sagen, dass das vielleicht zu meinem Lower Level ist, weil ich in jeder Post habe, dass sie alle haben, ihre eigene eigene Anlage von AI-Adoption Level 0-8 oder so.
Und auf der Level 7 und above war Ich habe mich überrascht, dass Fable 5 ist.
Jeder ist höher als das, nicht so sehr.
Ich war nicht so sehr impressed.
Vielleicht bin ich höher als 7, ich habe zu admit.
Ich denke, die Gist des Fable 5 ist ein sehr impressioner Modell, no matter what.
Und was passiert jetzt, ist das Tor open und es kann nicht sein, weil es ist klar, dass das kann passieren.
Und zu einem Art, ich würde sagen, dass das ist Das ist ein Ziel der Trump-Administration.
adversaries, right?
And this will be the case partially.
So I'm not entirely sure if the geopolitical explanation is true.
It could also be that it's just like the Trump administration doesn't like the woke AI.
This could to some extent explain this a little bit, but it will also backfire on open AI because what's true for Right now could be true for OpenAI in the future.
And hence, what is clear right now is that this can happen, right?
And the question that is open now is, is this actually really a wake-up call this time after the many wake-up calls that we specifically in the U received already?
Or are we going to hit the snooze button again?
Yeah, maybe before we...
We can also share our view, maybe also our professional view and how companies may react on that.
I think that's the purpose of this episode, right?
Yeah, yeah, yeah.
But I just want to elaborate again on one aspect.
And I think it was...
So you mentioned Fable 5 is the first version of the Mythos series.
And there was a lot of noise around Mythos and the capabilities.
And Mythos itself, as you also mentioned, is even more powerful than Fable.
And I think they underestimated, from my point of view, either it's a flex, right?
They just want to show the power.
Or they really underestimated the power of that model.
Because, I don't know, for how many weeks and months they have been able to really assess the model.
So I'm not 100% sure if that was on purpose or not.
You could argue that was all planned.
They wanted Entropic to...
und dann auf die Möglichkeit, die auf die Möglichkeit haben, die wirklich eine große Reaktion von der Markt und dann auf die Möglichkeit, die auf die Möglichkeit haben, die die Macht auf das Modell zu haben.
Denn, ich sage es, wenn ich mich selbst hätte, wenn ich die Chance habe, ich würde das Modell testen.
If I realize it's a real step up in all tests and all benchmarks, and then you're surprised by the power because someone else is informing you, it feels strange to me.
It really feels strange to me.
But nevertheless, I think we now need to deal with the situation.
Maybe one aspect I also want to mention is...
I think it's not specifically on Entropic.
So it's not specifically on Fable.
It could be also like every other model, right?
So I think the state we are in is at a level where super high impact is not an exception anymore.
So it might happen also to OpenAI.
So they release, I don't know, Codex 5.6, Pro, whatever, so that they may see a ban or, yeah.
Yeah, so maybe subject to these export restrictions, right?
Export controls.
Definitely, yeah.
And I have to agree that the story about the jailbreak, it doesn't seem to add up really.
Specifically also since Andy Jesse from Amazon, right?
Amazon is one of the big investors in Anthropic.
They would lose.
if Anthropik would have damages because of that.
It's quite strange and curious to, at some point, I'm sure it will come out.
At some point, we will learn what happened and how this happened.
Also, I heard that Scott Besant, the Minister of the Treasury, I think that's what it's called in the US, right?
He was the one issuing this.
Handing it directly over to the CEO of Anthropik.
Ja, das ist das, was ich habe.
Vielleicht ist auch ein Fun Fact, nicht sicher, ob du wissen, dass Amazon wirklich investiert in Enthropic ist.
Ja.
Das ist also scary.
Warum würde ich harm eine Unternehmen, die ich auch investiere in?
Vielleicht ist die Investition so klein, dass die Risiko oder die Downside ist sogar größer.
If you're not in form authorities, but I guess it's a strange thing.
Nevertheless, it is as it is.
Exactly.
And at some point we'll learn what happened really.
Yeah.
The thing is now what to do with it, right?
And first and foremost, so I personally switched to Sonnet and iterated with Sonnet.
That's it.
And honestly, I couldn't master the energy to care a lot about this, to be very honest.
Warum?
Ja, so number one, obviously I wasn't too impressed by Fable 5, even though I have to admit I didn't run evals, right?
I just tested it once.
It seemed to work well, but not significantly better than other models that I've tested lately.
And number two, the way that I approach the whole topic of AI or agentic engineering, I'm using my Pi Harness, right, which is open source.
The Harness, and you can also say that the Harness is more than just the tool itself, right?
It's what you do with it, right?
The workflows that you use, the skills that you use, the extensions that you use.
And this builds some resilience into my workflows because I really on one project that I'm running, I'm using my JGPT plus subscription.
And if this is fully consumed, I'm in my limit, then sometimes I'm working with Cloud Code where I have a subscription and then sometimes even with my anti-gravity subscription.
So that being said, obviously this is not like, this is not a poster for a company.
How could a company like like that, there always needs to be a balance between absolute maximum peak performance and resilience because if you are fully focusing purely on performance, you always go with the best, right?
And always go with the fastest, then you are naturally not that resilient because you're so focused on this, right?
And I think to me, this is the The trade-off to be taken.
So it would be wrong right now to say, okay, we don't use these kind of models at all any longer.
We strictly go for local models or open weights models from other providers.
I don't know if open router would be safer or if you even have to go to European providers, be it Mistral, be it like you book your own GPUs in OVH, Jonas or Stackit or whatever and then run your own models.
It would definitely reduce the performance of the team if you would not use the top models right now.
However, building the possibility that you can switch into your setup so that you only lose, I don't know, 5% of performance and not fall back to 1% because you suddenly have to type code by hand.
I think that is how I think about it.
So looking at what are the that make us, make the team, make me more resilient in the now while still being able to use the top-notch models and use the most performing tools that are available.
Yeah, makes sense.
I mentioned earlier that I haven't quite made up my mind yet.
So from a tactical point of view, I see a Bandwidth of options or measures you could do, like maybe on the one side, like YOLO mode, right?
Don't care.
Like, just move on.
Accept the dependency.
Accept the risk.
Don't care.
On the other side, you could say, okay, that is now the wake-up call.
Like, we need to, as you just said, like, we need to move everything to Europe.
Like, get our own infrastructure.
Like, best case, you do this in the seller, right?
Like, so, like...
You buy hardware.
So I think you have a point where you say, I think the advantage of running, of using really like the frontier models is too large.
So the downside, not just in regard to investment and effort to build that up, but like building your own stack, I think that is maybe for some business, and this is what I meant earlier, like it really depends on the context you are in.
If you are not really dependent on that, I hardly can think of a business which is, which would be maybe, there might be, like our listeners will tell us.
But other than that, I think the downside, not using the latest models, they're in, they're out, especially given the fact that they change still so rapidly.
Und dann, auf der anderen Seite, ich denke, dass ich YOLO-Mode auch nicht ein Option habe, wenn Ihr Unternehmen bereits erreicht.
Ich denke, wie Sie auch gesagt haben, es ist ein bisschen zu überlegen, dass es eine Art von Abstraction ist, dass Sie in der Worst-Case nicht haben, was eigentlich nicht passiert.
Ich bin ehrlich, dass sie ein Modell aus dem Modell ausgedrückt wurden.
für einige Stunden.
Ich denke, vielleicht ein paar Unternehmen haben es schon wieder adopted.
Aber in der Fall, wenn man sich so schnell, dann könnte man sich das auch wieder auf eine andere On-Premise, eine andere Modelle, oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine andere An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An-Premse oder eine An- because your harness is externalized, if you want to say so.
Yes, absolutely.
And fun fact, I actually had two meetings today about AI hardware and running models locally.
But in our case, it's because there on the horizon, there's the potential that we actually need this infrastructure for the use cases that we are supporting.
And we also have one Wir haben DGX in unserer Seller.
Wir haben einen Datencenter neben dem DGX mit 8 A100 GPUs.
Ich glaube, in einem von den Episoden, ich habe es, wie wir testen, was ein Gwenn 3.6 mit 35 Millionen parameters.
Es war blazing fast.
Es war viel Spaß.
Es war viel Spaß.
Wir konnten es nur 4 GPUs mit 4.
16 users in LMPerf Benchmarking.
And the model is quite capable for a lot of stuff.
So I tried it even locally for coding use case.
The speed was bad, but the quality was decent.
So I would say, again, right, I didn't run eval, so it would be hard for me to describe the percentage, but I wouldn't say it's even only 80% of the Frontier models.
It's probably even better than 80%.
So being able to run this, in a speedy way, already adds a lot of value, I would say.
And then for specific use cases, like if you want to do knowledge retrieval, either you have your data sources attached to it or you have actual pre-processed data in a database that you can use and you want to do RAC with it or whatever, this model would be totally capable and more than enough.
And there are tons of models in this.
You could, for smaller use cases, you could go with a Gemma 4.
There's a, I think, what is it, 12B model, which would comfortably run in 16 gigabytes of RAM.
And for really a lot of use cases, this will work perfectly fine, right?
Also, like text-to-speech models, we all know Whisper and FasterWhisper, and there's a ton of different models.
They don't need that.
Das ist alles gut.
Du kannst es gut.
So mein Kaises, es immer auf die Use Case.
Und die meisten advanced reasoning und whatever capabilities, das ist etwas, das du wahrscheinlich, für Coden.
Oder wenn du nicht genau, was du es für.
Aber dann, für Coden, da sind jetzt Models, die sind jetzt auf diese Use Cases, die sind Ich habe wirklich gut an Funktion, sorry, an Tool Calling, specifically also für Tools, die relevant sind für Coding.
Ich habe nicht testet es noch, aber ich habe noch geplant, die latest Kimme, was es called 2.7 Coder Model, das ist huge.
Es ist nicht easy, zu run es auf deinem Hardware, aber du kannst es natürlich von non-U.S.
companies.
Ich denke, auch internationaler Unternehmen, weil es ist OpenWeight.
Es gibt viele Providers, die das Modell runen.
Es gibt auch viele Optionen.
Und wenn wir in die Hardware gehen, gibt es auch verschiedene Möglichkeiten, die man hätte.
Du musst nur die vollständigen und sofort nach 200 Euro Euro machen, wo man die latest H100 oder 200 GPUs runn.
Du kannst auch einfach Like something like a Make Mini that we discussed, right?
Or the, what's it called?
I think the GB10 DGX Spark chip by NVIDIA, where there's also from ASUS, from Dell and different providers have different also price points for these computers.
I think this could also, even from a cost perspective, depending on what you're doing, if you are constantly going above your subscription, basically, right?
You're running complex use cases and you need a model that's more in the 80 billion parameter.
Dann 128GB von RAM-Computer wird eigentlich kein Problem sein, also von einem Kosten-Perspektiven.
Auch wenn sie auch mehr und mehr kostenlosen sind, weil die Komponenten so präzzy sind.
True.
Ich denke, in der Strukturkosten, du bist absoluten richtig.
Ich kann mich auch sagen, dass es ein Blindspot ist.
Ich denke, die Effort zu bringen, oder zu machen, es zu schaffen, wie bei der Produktion, ist es nicht gut.
Aber vielleicht bin ich da.
Vielleicht bin ich da.
Vielleicht bin ich da.
Ich kann auch sagen, dass wir heute ein Meeting haben, auf der Topik.
Ich wollte eigentlich nur noch einmal auf die Frage stellen, ob wir noch auf unsere Strategie sind.
Für mich, vielleicht auch eine Art von einem Sprach oder einem Sprach- oder einem Sprach- oder einem Sprach- oder einem Sprach- Ich denke, es ist gut zu beperren, zwei Dinge zu beperren, zwei Dinge zu beperren.
So auf der einen Seite, ich würde beperren, zwischen internen und externen, so wie internen, vielleicht hat es eine lower-impact.
Du kannst das besser mit dem, was mit dem Kunden zu beperren.
Und dann würde ich beperren, zwischen dem, was die impact ist.
in regards to, is it really a blocker or is it just slowing you down, for example?
And I think if you do the metrics, right, and I think then you know which topics you need to work on, right?
So you might have some features in your company which are customer-facing and which might be a blocker in case they are not available, these models.
So that is maybe a good activity to then care very specifically on that product.
Have a plan B or some kind of a, I don't know, mitigation plan.
I think it's not disaster recovery, but like it might be an aspect of that, by the way.
So instead, or compared to making the entire company bulletproof, right, or resilient, I think like really focusing on what might have a larger impact on the company rather than like securing everything just.
Just in quotes, right?
Just because of that incident.
Absolutely.
Yeah.
I also thought about this case.
I mean, probably Fable 5 was too new to be actually used customer facing, I would assume, right?
So there are probably no companies aside from Anthropic that would bring this in front of customers yet.
But still the same is true for any other model, right?
But then thinking about what is an actually in an actual use case where you would in a product use such a strong model, even the latest Opus model, probably for the product use cases that most companies are running right now.
And I'm not sure if there's actually already so many, aside from big tech, obviously, and the typical companies that are running AI use case or LLM based use cases at scale.
They would probably not necessarily need the full thinking or, I mean, multimodality, probably yes, because there could be different kinds of inputs, right?
But then it's usually, I would assume, more a RAC kind of use case where you receive some input, right?
Then you need to retrieve some contextual information from somewhere.
And then create an answer for a very specific type of questions, right?
In a specific context.
And there you, yeah, it should be relatively easy to use different kinds of models and even be fairly agnostic when it comes to providers.
And at some point I would even argue it might be, there might be, I mean, if you start with it, it's always cheaper, no CAPEX and no operational complexity to use it out of the.
out of the box basically, right, from the provider.
But at some point, it might even become interesting to see if you can run it cheaper if you host it yourself, right?
I mean, for that you need a certain type of scale, specifically also because the older models are generally very cheap also from providers, right?
But yeah, so that's why I didn't even think so much about this case because it doesn't seem to be so, in der Sinne, dass es wahrscheinlich sehr easy zu finden, einen anderen Providere, der einen anderen Providere hat, einen anderen Providere zu finden.
Ich denke, du bist absolut richtig.
In der sehr speziellen Situation, ich denke, nur ein paar Unternehmen, wenn es an alle, haben sich geflüchtet.
Auf der anderen Seite, du wirst nicht, vielleicht, wenn sie alle die Services verhindern, dass sie eine Verkaufnahme für Entropik verhindern.
Wir wissen noch nicht, aber das Wir-Dun-Know-Yet passiert oft in den letzten Monaten und Quartes.
Ich denke, wir sollten uns bereit sein.
Ich würde für die Frontier modellen, weil es der Qualität, der Produktivität, der Gains und so weiter.
Ich würde nicht für YOLO modellen.
Ich denke, Sie müssen die wichtigen Systeme in Ihrem Landschaft und Sie müssen sich vorbereitet für das.
Muss es sich überall sein?
Probierlich nicht.
Es gibt einige Experten.
Es ist okay, dass sie sich verletzt und Sie können mit dem, Sie können mit dem, aber für die Dinge, die sich entscheiden, ob es sich um die Bankrupte oder nicht ist, ich denke, dass sie eine Plan B ist.
Und wenn das nicht existiert, dann würde ich sagen, es war ein guter Wake-up-Call.
Absolut.
Amen.
Ich fully agree.
Wenn du über Cloud Code denkst, dass sie sich aus dem Weg weg von...
oder sogar den Cloud Desktop-App.
Das wäre ein großer Bummer.
Ich meine, da, du könnte wahrscheinlich proxieren und routierst die Request zu etwas, dass du selbst selbst oder vielleicht auch eine Open-Router oder etwas.
Aber still, einfach nur über das, und vielleicht testen es und machen eine Failover-Test ist etwas, das sollte auf der Radar sein.
Ja, das ist gesagt, ich denke, Ja, das ist das, was es.
Es ist die Balance.
So, du solltest nicht sagen, jetzt, wir freig sind und wir nicht mehr benutzen, das kommt aus den USA oder vielleicht sogar China, wenn du willst.
Das ist wahrscheinlich nicht gut.
Auf der anderen Seite, sagen wir, ich gehe einfach nicht, ich gehe einfach nicht, es ist wahrscheinlich nicht gut.
Es ist immer die Balance, und es ist auch, wieder, We used to say in the past, it always depends, right?
It always depends on what you're using it for.
Are you using it internally?
Are you using it for products that you serve to your customers, right?
Which like there might be different criticalities and also the different use cases.
I mean, a lot of engineering organizations right now without Cloud Code would be out of work, I would say, right?
Or they would not be able to work as long as Cloud Code is not working.
Just like thinking about this scenario, thinking about what you could do in order to overcome it, either by proxying and routing to some other provider or by saying, no, we invest a lot in the harness, the skills, workflows, extensions, whatever, and we are able to switch to a new harness very quickly so that we can use different kind of models in the All of this is relevant, I would say.
There should at least be a plan for that and ideally some tests already.
So some capacity of some principal engineer or senior engineer or someone who likes to take care of that should go into these kinds of tests.
Good.
Thanks for the summary.
I think we speak when there's the next incident.
Yes, so next week basically.
Let's see.
Bye-bye.
See you next time.
Bye.
The Beyond Vibe Coding Podcast is a project by Sebastian Heidemalze Erpen and Andre Neubauer partnering with ImpalaSearch.
The content is created by us and our guests.
Join the discussion on LinkedIn or visit our website where we publish all episodes.
For questions and inquiries, feel free to reach out via LinkedIn.
Thank you for your time and see you in the next episode.
