Federal AI policy in the United States has moved a long way in a short time, and 2026 has brought three changes that matter to almost any enterprise with international operations: tighter and more frequently adjusted export controls on advanced AI chips, new tariffs touching AI hardware components and the systems built from them, and a domestic regulatory posture that favours voluntary frameworks over binding rules. None of these developments is, on its own, unusual for a fast-moving technology sector. Taken together, and set against a more prescriptive European Union regime, they add a layer of strategic complexity that technology and procurement leaders cannot plan around informally. This briefing looks at what is actually changing, where the genuine trade-offs sit, and what a sensible response looks like for organisations operating across both markets.
Three federal policy levers moving at once
It helps to separate the three strands, because each has a different mechanism and a different enterprise impact. Export controls restrict which AI accelerators and related technology can be sold to certain countries and, in some cases, which cloud regions or customers can access the most advanced compute. Tariffs are a separate instrument, applied to categories of semiconductor and server hardware crossing US borders, and they affect cost rather than availability directly. Domestic AI regulation is the third strand, and here the current administration's approach has favoured voluntary commitments and sector guidance over binding federal rules, leaving much of the detailed regulatory activity to individual states and to existing sectoral regulators.
The combined effect is a policy environment that is easier to move through if your AI activity is purely domestic and lower-stakes, but considerably harder to plan around if your organisation sources hardware internationally, sells AI-enabled products across borders, or operates under both US and EU obligations simultaneously. It is this second group, which includes most sizeable multinational enterprises, that needs a deliberate response rather than a wait-and-see one.
A live example: the Fable 5 and Mythos 5 export episode
The clearest illustration of how fast this lever can move arrived in June 2026, when the US Department of Commerce issued an export control order restricting access, including for the developer's own foreign national staff, to Anthropic's newly released Claude Fable 5 and Mythos 5 models, citing national security concerns. Reporting at the time linked the order to a disclosed jailbreak technique said to bypass one of the models' safety safeguards, though Anthropic stated it had not been given a specific justification for the action. Anthropic paused access to both models for several weeks before the Department of Commerce lifted the export control requirement in early July, once the company agreed to deploy a targeted security classifier, work with government on standards for future model releases, and report malicious activity it identifies.
For enterprise buyers, the episode is a compact case study in the risk this briefing describes in the abstract. A frontier model that organisations had only just begun evaluating or integrating became unavailable to certain users with very little notice, for reasons that were not fully transparent even to its own developer, and then became available again on materially changed terms. Whether or not a given enterprise was a customer of these specific models, the underlying pattern, an export action targeting a model rather than a piece of hardware, triggered on security grounds, resolved through a negotiated compliance commitment, is now a real category of supply risk that model-level sourcing plans need to account for alongside the chip-level risks discussed below.
Export controls and tariffs are reshaping AI hardware supply chains
Export licensing requirements on advanced GPUs and related accelerator technology have continued to be adjusted through 2026, with eligibility rules, country groupings and licence conditions changing more frequently than the multi-year hardware refresh cycles that enterprise buyers are used to planning against. For any organisation that operates data centres or leases capacity in multiple regions, this means the compute available to a given subsidiary or cloud region can no longer be assumed stable for the life of a procurement contract. Capacity that is straightforward to source today may require a licence, a substitute chip generation, or a different regional footprint eighteen months from now.
Tariffs on semiconductor components and finished AI hardware add a second, more direct cost variable. Unlike export controls, tariffs do not typically block a purchase outright, but they do change the landed cost of GPUs, accelerators and the servers built around them, and that cost can shift with limited notice as tariff schedules are revised. For finance and procurement teams, this means AI infrastructure budgets built on last year's unit costs are at real risk of drifting, particularly for organisations that import hardware directly rather than buying compute as a cloud service. The practical implication is not that AI hardware becomes unaffordable, but that cost and availability assumptions need to be revisited on a shorter cycle than has historically been normal for enterprise IT procurement.
A widening compliance gap between Washington and Brussels
Alongside a lighter domestic regulatory posture, the United States has left most AI governance activity to voluntary frameworks, existing sectoral rules and state-level initiatives, rather than a single binding federal AI statute. The European Union has taken the opposite path, with the AI Act's obligations continuing to move into active enforcement, a topic we cover in detail in a separate briefing on this site. The result is a genuine divergence in compliance burden between the two markets, not simply a difference in emphasis.
For a company operating only in the US, the lighter federal posture can mean faster internal AI deployment and lower day-to-day compliance overhead. For a company operating in both markets, the same underlying AI system may need to satisfy materially different documentation, risk-assessment and transparency obligations depending on where it is deployed, with no equivalent US requirement to anchor a single global control set against. That asymmetry, more than either regime in isolation, is what enterprise compliance and legal teams need to plan for.
What this means for enterprise AI sourcing and vendor strategy
The practical consequence for sourcing teams is that AI hardware and cloud compute can no longer be treated as a commodity purchase governed purely by price and performance. Supplier concentration risk now sits alongside those factors: an organisation dependent on a single chip vendor, a single manufacturing region, or a single cloud provider's regional capacity is more exposed to a licensing change or tariff adjustment than one with a diversified base. Building genuine optionality, whether through multiple hardware vendors, a mix of owned and cloud-sourced compute, or contractual flexibility to shift regions, is now a resilience measure rather than a nice-to-have.
Contract terms deserve equal attention. Multi-year hardware and capacity agreements signed without provisions for tariff pass-through, export-control-driven substitution, or regional reallocation expose the buyer to cost and availability risk that the supplier is often better placed to absorb or hedge. Enterprises should expect, and negotiate for, contract language that addresses what happens if a policy change affects the specific hardware or region a deal depends on, rather than discovering the gap after the fact.
Building an operating model that flexes across jurisdictions
Given that US and EU requirements are unlikely to converge in the near term, the more durable response is an internal compliance and sourcing operating model designed to flex, rather than a single global standard set to the stricter regime by default. Mapping AI systems, and the jurisdictions in which each is deployed, to the specific obligations that actually apply in each location avoids both the cost of over-engineering every deployment to EU-grade documentation and the risk of under-engineering a system that later needs to operate under it. This is the same requirement-mapping discipline that works well for data residency programmes, applied here to a policy landscape that is diverging rather than converging.
Procurement, legal, security and engineering all need a seat at this table, because the decisions involved, which hardware to buy, which contract terms to insist on, which compliance documentation to maintain by default, span all four functions. Organisations that leave this exclusively to one team tend to end up with either unworkable engineering constraints or compliance gaps that surface only when a regulator or auditor asks.
What enterprise leaders should do now
- Map current and planned AI hardware and compute sourcing against active export-control and tariff exposure by region.
- Diversify hardware vendors and cloud regions where feasible, rather than relying on a single supplier or jurisdiction for critical AI capacity.
- Maintain the ability to route critical workloads to more than one model provider, so a single vendor-specific export action cannot stall production access, as happened with Fable 5 and Mythos 5 in June 2026.
- Build tariff pass-through and export-control substitution clauses into new and renewed AI hardware and capacity contracts.
- Maintain a single compliance baseline mapped to the strictest jurisdiction you operate in, rather than a US-only or EU-only default.
- Revisit AI infrastructure cost forecasts at least twice a year while tariff and export-control schedules remain fluid.
- Give procurement, legal, security and engineering joint ownership of AI sourcing and compliance decisions.
- Brief your board on supply chain and regulatory divergence as a standing risk item, not a one-off update.
None of this requires treating US policy shifts as a crisis. What it requires is treating them as a fact pattern, one that changes the cost, availability and compliance calculus for AI hardware and services more often than enterprise planning cycles are used to, and building the sourcing and governance flexibility to absorb that change without disruption. Need help mapping your AI sourcing and compliance exposure across US and EU obligations? Email sales@halfteck.com.