The record — 2026

Declassified

They can read it. They can revoke it. They can raise the rent.

Frontier cloud AI now comes with surveillance deals, government-ordered model recalls, and mandatory prompt retention that overrides your ZDR contracts. Agentic Frontier puts modern AI on your infrastructure — on-prem, colo, or private cloud you control.

File AF-2026 · Zero data retention by physics, not by contract

These are not hypotheticals. They are 2026 events, reported by major outlets and confirmed in company statements. If your AI stack depends on a frontier API, your access, your data, and your cost model sit on someone else’s terms.

Exhibit
A
Mar 2026

The Pentagon picks a winner

After the U.S. Department of Defense blacklisted Anthropic for refusing to drop two red lines — no mass surveillance of Americans, no lethal autonomous weapons — OpenAI announced a deal with the Pentagon. Critics argued the early “any lawful use” framing left the door open to AI-enabled domestic surveillance.

The Atlantic reported that OpenAI was “opening the door to government spying.” The Verge detailed how the Pentagon pressed for bulk analysis of Americans’ data. Sensor Tower data cited by the BBC showed ChatGPT uninstalls surging roughly 200% after the announcement. OpenAI later amended the agreement; civil liberties voices remained unconvinced that the loopholes were closed.

The lesson for enterprise buyers: when the frontier vendor’s other customer is the state, your terms of service are not the only terms that matter.

Exhibit
B
Jun 12–Jul 1 2026

The 19-day recall

On June 12, 2026 — three days after launch — the U.S. Department of Commerce issued an export-control directive ordering Anthropic to suspend access to Claude Fable 5 and Mythos 5 for any foreign national, anywhere, including Anthropic’s own foreign-national employees.

Anthropic’s published statement: without a way to verify nationality in real time, they “must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.” Both models went dark worldwide. Access stayed offline for 19 days. Controls lifted June 30; Fable 5 restored July 1. The Cloud Security Alliance called it the first time the U.S. government directly compelled an AI company to revoke access to specific deployed model versions based on user nationality.

If a model can be yanked from every customer overnight by a letter from Commerce, it is not infrastructure. It is a privilege.

Exhibit
C
Jun 2026

Fable 5 reads your prompts

Anthropic designated Fable 5 and Mythos 5 as “Covered Models.” Zero data retention is not available. Prompts and outputs are retained for 30 days for trust-and-safety review — on every platform, including AWS Bedrock, Google Cloud, and Microsoft Foundry. Anthropic’s own statement linked the retention requirement to jailbreak research: “a policy change that carries real costs for us with customers.”

Reporting from InfoQ, Mashable, Securosis, and others: existing enterprise ZDR agreements do not apply to Fable 5 traffic; Bedrock’s “data stays in AWS” boundary breaks when provider_data_share is required; flagged content can be kept up to two years. Microsoft shipped Fable 5 to GitHub Copilot customers while, according to byteiota, blocking the same model for its own employees.

ZDR by contract is only as strong as the next model release. ZDR by physics — weights and inference on hardware you control — does not renegotiate itself.

01 — Access

They can revoke it

A government letter, a ToS change, or a safety classifier can take your production model offline. Your SLA does not override a Commerce directive.

02 — Data

They can read it

Mandatory retention with human review turns prompts into a third-party corpus. Regulated workloads — HIPAA, privilege, finance — cannot absorb that.

03 — Contract

Terms rewrite themselves

Last year’s ZDR agreement may not cover this year’s “Covered Model.” The lock you negotiated applies until the next launch day.

04 — Cost

They can raise the rent

Metered tokens scale with usage. Successful AI adoption becomes a surprise line item. On-prem hardware amortizes; API bills compound.

Own the weights. Own the wire.

Modern open-weight models are good enough for most internal work — document Q&A, coding agents, ops copilots, classification, extraction. You do not need to rent a frontier API to ship useful AI inside the company.

Principle 01

ZDR by physics

Prompts never cross a provider boundary. Retention is not a clause you hope holds — it is a network path that does not exist.

Principle 02

Weights can’t be recalled

Once the model files are on your GPU or colo, no export-control letter to a SaaS vendor takes them offline for your team.

Principle 03

Flat, predictable cost

Capex and power replace per-token surprise. Scale usage without negotiating another enterprise rate card.

Models
Open-weight class: Llama, Qwen, DeepSeek, Mistral, and peers — sized to your evals, not a vendor’s roadmap.
Serving
vLLM, llama.cpp, or equivalent on GPUs you own, lease, or colocate. OpenAI-compatible endpoints for drop-in tooling.
RAG
Retrieval over your internal documents, tickets, and runbooks — citations in, answers out, nothing leaves the perimeter.
Agents
Workflows wired to your internal APIs and approval gates. Suggest-only or supervised execution — your policy, your audit log.

How we work

Software consulting for companies that want AI in their internal stack without renting a frontier model — or the politics that come with it.

SVC-01

Sovereignty audit

Map where prompts go today, which vendors retain what, and which contracts silently expired when a new model class shipped. Deliver a risk memo and exit options.

SVC-02

Private model deployment

GPU sizing, serving stack, eval harness, and hard-cutover plan. From lab box to production endpoint your team can operate.

SVC-03

Internal RAG & agents

Document search with citations, ops copilots, and agentic workflows against your systems — designed for auditability and least privilege.

SVC-04

Cost-model comparison

Side-by-side: frontier API burn vs. owned hardware over 12–36 months. Numbers your CFO can argue with, not vibes.

SVC-05

Team enablement

Runbooks, on-call ownership, and handoff so the stack does not leave with the consultant. Your operators keep the keys.

Next step

Book a sovereignty call

Tell us what you run today and what you refuse to put in a frontier API. We’ll sketch an on-prem path that fits your stack and your risk posture.

Email hello@
hello@agentic-frontier.com