Mark’s Musings

  • The Accounts Are Clean. Companies House Still Thinks You Owe the 2006 Loan.

    The Accounts Are Clean. Companies House Still Thinks You Owe the 2006 Loan.

    Most PE diligence still starts in the same place: last signed accounts, latest management pack, a debt schedule that ties. If the balance sheet shows no bank loan, the room relaxes. Then somebody opens Companies House and finds a charge from 2006 sitting there like a bad smell that never got a window opened.

    The accounts can be right. The public record can still be wrong. A buyer, a bank, or a new director will treat the register as the truth. That is the point of a public register.

    The gap nobody puts in the data room index

    A charge on the register is not the same thing as a loan on the balance sheet. One is a legal security interest recorded at Companies House. The other is an accounting residual. They are supposed to move together. In owner-managed groups, hall companies, old family holdcos and plenty of otherwise tidy PE portcos, they do not.

    The usual story is boring, which is why it survives. The facility was repaid. The refinance completed. The overdraft died with the old bank. Nobody filed the satisfaction. Ten years later the directors have changed, the auditors have changed, and the only person who remembers the original completion file is retired. The Companies Act 2006 Part 25 charge regime does not auto-clean itself because your cash account looks healthy.

    Why a dead loan still looks alive

    Since April 2013, most UK company charges go on with form MR01. Getting them off is a separate act: a statement of satisfaction, MR04, in full or in part. If the company no longer owns the charged property, that is a different filing. None of this happens because the loan note hit zero in the TB.

    Older all-monies bank charges are worse. They were often taken as a standing security over “everything we might ever owe you”, then left in place through three refinances and a change of clearing bank. The debt is gone. The public footprint is not. Credit reference agencies and some KYC shops still read the register, not your verbal history of the relationship.

    There is no useful statute of limitations that makes an unsatisfied charge evaporate. It sits. It ages. It looks like a problem to anyone who was not in the room when the cheque cleared.

    What a buyer, a bank, or a new director actually sees

    A new director doing even a light personal check will see outstanding charges and no matching liability. That is not a trivia question. It is the first test of whether finance knows the difference between the books and the public record. If you are asking someone to take a board seat, do not make them discover this on a Sunday night.

    A buyer’s counsel will not accept “everyone knows that one is historic.” They will want the lender’s confirmation and the satisfaction filed, or a clean explanation that survives a completion checklist. A debt fund doing holdco diligence will ask the same question in a worse tone.

    This is also why “the accounts are clean” is not a diligence conclusion. It is a starting position. I have written before about what the interim CFO job actually is. It is not to decorate a data room. It is to make the public record, the bank, and the pack tell the same story before somebody else notices they do not.

    The twenty-minute test

    Before you take a board seat, buy a book, or sign a completion agenda, do this:

    1. Pull the company on Find and update company information. Open charges. Note created date, chargees, and whether satisfaction has been filed.

    2. Put that list next to the last filed accounts — creditors notes, contingent liabilities, security disclosures — and the current debt schedule.

    3. Anything on the register with no loan line is not a mystery. It is an open item. Either the books are missing a liability, or the register is missing a satisfaction. Both are finance problems. Only one of them is usually true. You still have to prove which.

    4. If the chargee still exists, ask for written confirmation the facility is gone. Then file. If the chargee has been through three mergers and a name change, that is a research job, not a reason to leave it.

    Twenty minutes. Sometimes twenty days if the old bank has to find a deed. Either way, do not discover it in week six of a 100-day plan.

    File the satisfaction. Then stop calling it historic.

    Companies House is not being difficult. It will record what you file. The event-driven filing rules exist because the register is used by people who do not have your shared drive. An unpaid historic charge is not a vibe. It is an unfiled event.

    If you are the CFO, this is a control, not a tidy-up. Put “CH charges vs debt schedule” in the monthly close pack until the list is nil or explained. If you are the incoming interim, do it in week one, before you start talking about systems, AI, or the covenant case. A model that cannot see an unsatisfied charge is not intelligence. It is a very fast way to reprint the same gap.

    I am not giving legal advice. Get counsel on anything with a live lender, a disputed repayment, or property still sitting in the security pool. The operational point stands without a QC: the public record will be treated as true until you change it.

    The PE tell

    Houses that actually underwrite operations will ask for the charges print on day one. Houses that buy a narrative will notice it when the lawyers do, which is later and more expensive. If your AI stack, your QofE, and your board pack all missed a 2006 charge that outlived the loan, the problem was not the charge. The problem was the definition of done.

    Clean accounts are necessary. They are not sufficient. File the satisfaction. Then the story you are telling investors is the same story Companies House is telling strangers.

  • If Your AI Doesn’t Change Monday Morning, It’s Theatre

    If Your AI Doesn’t Change Monday Morning, It’s Theatre

    Most PE boards now have an AI slide somewhere in the pack.

    It usually looks impressive. A chatbot for policies. A prettier forecast chart. A memo that took forty minutes instead of four hours. Nobody wants to admit the awkward part: none of that changed Monday morning.

    If you are the interim CFO walking into a PE-backed holdco, that distinction is the whole job. There is AI that compresses the close, sharpens covenants and tells the truth about cash. And there is AI that writes nicer decks. Only one of them moves a hold period.

    Theatre is not neutral

    Theatre is expensive because it steals attention. Sponsors hear “AI in finance” and assume the control environment just got tighter. What they often got is a thin wrapper over the same late pack, the same reconciling nightmare, and the same working-capital surprise three days before the lender call.

    I am not anti-tool. I run a serious AI stack in my own work. The test is brutal and fair:

    Did a decision move earlier, with better evidence, than it would have last quarter?

    If the answer is no, you bought content production. Call it that. Do not call it transformation.

    Three workflows that actually move a PE hold

    Ignore the vendor map for a minute. In a typical mid-market PE asset, three finance workflows earn their keep.

    1. Close compression that is real, not cosmetic.
    The close is still where trust is made or destroyed. AI helps when it attacks the bottleneck chain: flux narratives drafted from the actual trial balance movements, exception queues ranked by materiality, intercompany breaks clustered by pattern instead of hunted one by one. It does not help when someone pastes a half-reconciled P&L into a chatbot and asks it to “explain variance” with no tie-back to source.

    What good looks like: board pack numbers lock earlier, commentary cites the same source the controller trusts, and the CFO stops spending Sunday night rewriting slides that should have been true on Thursday.

    2. Covenant and cash early-warning — before the breach conversation.
    Lenders do not care that your deck is eloquent. They care whether you saw the turn in advance. The useful stack watches bank actuals, order book, receivables ageing and inventory truth on a cadence shorter than the monthly myth. Models can flag trajectory toward a covenant headroom problem while you still have levers. Models cannot invent headroom you already spent.

    If your “AI treasury insight” cannot show the last thirteen weeks of cash and the next eight with honest driver notes, it is jewellery.

    3. Working-capital truth that survives diligence tone.
    PE holds live and die on cash conversion. AI is useful when it forces the ugly questions into the open: who is shipping without billing discipline, which SKUs are museums, where overdue is a commercial choice dressed up as admin lag. The output should change collections behaviour and purchasing behaviour — not produce a heat map nobody acts on.

    Exit narratives love “AI-enabled operations.” Buyers’ diligence teams love bank statements. Align yourself with the second group.

    What to starve

    Be rude about the rest, at least internally.

    • Generic chat over unstructured drives with no retention, no permissions model, and no citation path back to the ERP.
    • Auto-generated board prose that smooths over a late close. Pretty wrong is still wrong.
    • Pilot theatre that never touches the month-end calendar, the bank feed, or the covenant workbook.
    • Tool sprawl where every function buys a different assistant and finance inherits the reconciliation of the assistants.

    If a tool cannot name the system of record it reads, the control owner, and the decision it accelerates, it is a toy with an invoice.

    The interim CFO test in the first thirty days

    When I land in a PE-backed finance function, I do not start with a vendor bake-off. I start with the Monday morning stack:

    • What does the CEO actually ask every week?
    • What does the board pack still get wrong under pressure?
    • Where does cash surprise still live?
    • Which close tasks burn senior time that a junior plus a model should own?

    Then we wire AI into those seams — with human sign-off still sitting on anything that hits lenders, auditors or public numbers. AI amplifies the operating system you already have. If the operating system is chaotic, AI makes the chaos faster. That is not a technology failure. That is a leadership tell.

    For sponsors and chairs

    Ask better questions in the next IC or board slot:

    • Which decision moved forward by at least one week because of this tool?
    • What is the system of record, and who signs the output?
    • Did close day-count, covenant headroom visibility, or cash conversion change in a measurable way?
    • What did we stop doing because the model took the grind?

    If the answers are all narrative, you are funding theatre. Theatre photographs well in a value-creation plan. It does not reprice an exit.

    The point

    The PE cycle is rewarding operators who can see clearly under stress. AI belongs in that story only when it shortens the distance between messy reality and a decision a grown-up will own.

    Nicer decks are optional. Monday morning is not.

  • Only 36% of Interim CFOs Go Permanent in PE. Stop Pretending the Job Is an Audition.

    Only 36% of Interim CFOs Go Permanent in PE. Stop Pretending the Job Is an Audition.

    Most people treat the interim CFO seat at a PE-backed business as a waiting room for the permanent job.

    The data says that is a fantasy.

    Research covered by CFO.com on Barton Partnership work puts the conversion rate from interim to permanent at PE-backed firms at roughly 36%. Only about four in ten interim finance chiefs even said they were open to staying under the right conditions. The rest are doing something else entirely: closing a capability gap, stabilising a reporting stack, carrying a business through diligence or exit, then moving on.

    If you sit on an investment committee, that number should change how you hire. If you are the interim, it should change how you negotiate.

    The job is not a try-before-you-buy

    Sponsors still talk about interim CFOs as if the assignment is a six-month audition. Sometimes it is. More often it is a deliberate instrument:

    • the deal thesis needs a finance leader who has already lived a similar hold period;
    • the sitting FD cannot carry lender packs, board cadence and systems cleanup at once;
    • management wants a grown-up in the room without locking a permanent package before the first 100 days are honest;
    • exit is visible and nobody wants a brand-new permanent CFO learning the business in the CIM.

    That is not a failed permanent search. That is a different product.

    When boards blur the two, they get the worst of both: an interim who half-applies for the permanent seat, and a permanent hire who was never properly scoped.

    Why conversion is low — and why that is often healthy

    Low conversion is not automatically a governance failure. In PE it is frequently the design.

    1. The skill that saves the hold is not always the skill that runs the next five years.
    Rescue, refinance, ERP recovery, TP cleanup, warehouse go-live, carve-out — these are campaign sports. Steady-state FP&A leadership, culture and long-cycle talent development are different muscles. Pretending one person must be both is how you overpay for the wrong profile.

    2. The best interims are expensive because they are liquid.
    People who can land cold into a PE board pack and make it legible do not need your permanent role to feel successful. They need a clean mandate, decision rights, and a finish line. If your only retention tool is “maybe we will make it permanent,” you are bidding with monopoly money.

    3. Sponsors already know who they might want long-term.
    Often the permanent CFO is a known quantity from a prior portco, a portfolio talent map, or a search that was always going to conclude after the fire was out. The interim was never in that race. Telling them otherwise is theatre.

    4. Conversion politics punish honesty.
    If the interim is quietly campaigning for the seat, bad news arrives late. If the board pretends the door is open when it is not, trust collapses in month four. Clear “this is a closed-ended assignment” language is kinder and more commercial than soft ambiguity.

    What good PE sponsors do instead

    The high-functioning pattern is boring, which is why it works.

    Name the product on day one. Stabilise / professionalise / exit-ready / systems rebuild / fundraise support. One primary job. Secondary jobs in writing, not in hallway vibes.

    Separate the permanent search clock from the interim clock. If you might convert, say what evidence would justify it and when that decision will be taken. If you will not convert, say that before the first board. Ambiguity is not optionality. It is unmanaged risk.

    Pay for outcomes, not for hope. Day rate or project fee against deliverables beats a discounted permanent package with a whispered upside. Interims who accept underpriced “try-outs” train sponsors to treat senior finance as a temp bench with equity cosplay.

    Instrument the handoff. The value of a strong interim is not only the three months of packs. It is the operating system left behind: close calendar, board pack skeleton, cash bridge discipline, covenant early-warning, decision log, open diligence Q&A. If that does not exist at exit from the assignment, you rented a person. You did not buy capability.

    What the interim should demand

    From the other side of the table — and I sit there often enough — the commercial hygiene is simple.

    Mandate in writing. What “done” looks like. What is out of scope. Who can overrule you. Which systems you own versus babysit.

    Decision rights on cash and reporting. An interim CFO without authority over the cash bridge and the board pack is a commentator with a nicer title.

    A clean conversion clause — or none. Either a dated decision gate with criteria, or an explicit non-conversion statement. Soft “we will see how it goes” is how both sides waste political capital.

    Permission to build past yourself. If the assignment succeeds, the business should need you less at the end than at the start. That is the point. Hire the number two, fix the calendar, kill the heroics. Sponsors who punish that behaviour are selecting for dependency.

    And get the tax wrapper right. A real PE interim is almost always outside IR35 when structured properly: own company, own tools, substitution/control reality, financial risk, and a finished assignment rather than a disguised employment. If the commercial deal is temporary employee with a day rate, you have already lost the product definition and invited a status fight you do not need. Sponsors who want interim outcomes should buy a genuine B2B assignment. Interims who want the economics of independence should not pretend they are on a probationary payroll.

    Where AI changes the interim brief

    This is no longer only a people story.

    A modern interim CFO is often dropped into a business that still closes in Excel folklore while the sponsor deck claims “AI-enabled value creation.” The gap is becoming the job.

    • Can the finance stack produce lender-grade cash visibility without a weekend of heroics?
    • Are AI tools allowed to touch the close, the pack, the covenant model — and under whose control?
    • Is “productivity” just headcount hope, or a measured reduction in cycle time and error rate?

    I have written separately about measuring AI and local AI. The interim angle is blunter: if you only have 90–180 days, you cannot wait for a transformation theatre programme. You need a short list of automations that harden the close, the pack and the cash story before the next IC.

    That is why conversion rates miss the point. The question is not “did we keep them?” The question is “is the business more finance-operable than when they arrived?”

    The PE take

    Interim CFO work at PE-backed companies is a professional service with a balance-sheet consequence, not a dating app for permanent hires.

    Use it that way.

    Hire for the campaign you are actually in. Pay for the outcome. Decide conversion on purpose, early, in writing. Measure success by the operating system left behind — not by whether the temp badge got upgraded.

    And if you are the interim: stop auditioning for a role nobody agreed was open. Do the job that was bought. Leave the business harder to break than you found it.

    That is the product. Everything else is soft focus.

    Mark Hendy is a PE-facing interim CFO and founder of Tanous. Views his own. Conversion statistics referenced from public secondary reporting of Barton Partnership research via CFO.com; verify primary materials before relying on the figure in a live search process.

    Sources / further reading:
    CFO.com on interim-to-permanent conversion at PE-backed firms ·
    Finatal interim finance insights ·
    CFO optimism on AI impact ·
    The CFO Who Can’t Measure AI ·
    The CFO Case for Local AI

  • The $1.65 Trillion Footnote: Big Tech’s Off-Balance-Sheet AI Debt

    The $1.65 Trillion Footnote: Big Tech’s Off-Balance-Sheet AI Debt

    A Nikkei investigation has put a number on something markets prefer to keep in the footnotes.

    According to reporting amplified this week by HedgieMarkets, Alphabet, Microsoft, Amazon, Meta and Oracle are carrying roughly $1.65 trillion in obligations that do not sit neatly on the balance sheet as debt — more than the $1.35 trillion they officially report. The pile is built from GPU contracts, data-centre leases and joint ventures that accounting rules often keep off the face of the statements until facilities go live.

    Meta alone is said to account for about $420 billion of that hidden stack — triple its reported debt in the framing of the report. Oracle’s off-balance-sheet exposure has exploded over a few years. All five companies declined to comment in the coverage.

    If those figures are even roughly right, investors reading this earnings season are not looking at the full leverage picture. They are looking at the part that fits on a summary slide.

    This is not a fraud story. It is a timing story.

    That distinction matters. Lease accounting, executory contracts, take-or-pay compute deals and project structures can be entirely legal and still economically enormous. The BIS had already waved at this as shadow borrowing. Nikkei’s contribution is less moral panic than quantification: someone added up the commitments and refused to pretend the footnotes were decoration.

    In CFO language: reported debt is not the same thing as economic leverage. One is a presentation category. The other is what still has to be paid, powered, utilised or impaired if demand disappoints.

    Why AI capex makes the old tricks dangerous again

    Data centres are not ordinary office leases. They are long-duration, power-hungry, chip-dependent industrial assets with brutal technological depreciation risk. If model demand, pricing power or utilisation come in below the pitch deck, you do not get a gentle roll-off. You get:

    • leases and service contracts hitting the accounts as facilities go live;
    • impairments on specialised shells and power arrangements;
    • stranded capacity funded by private credit, project bonds and insurance balance sheets;
    • a sudden market rediscovery that “asset-light” was a drafting choice, not a physical fact.

    The bull case says hyperscalers can absorb it because cash flow is immense and AI demand is structural. Maybe. The bear case does not require a collapse in AI — only a miss versus the capacity already contracted.

    What boards should actually ask

    If you sit on a PE board, a credit committee, or a corporate treasury that sells into this ecosystem, stop arguing about vibes and ask for a one-page economic exposure map:

    1. What is on the balance sheet, and what is only in commitments?
    Split reported debt, lease liabilities, purchase obligations, residual value guarantees, JV funding lines and take-or-pay compute. If management cannot reconcile the footnote total to a cash timeline, that is the finding.

    2. What is the go-live cliff?
    Off-balance-sheet is often just delayed on-balance-sheet. When do sites energise? When do minimum payments begin? What percentage of the $1.65T becomes unavoidable over 24 / 48 / 60 months?

    3. Who really holds the downside?
    Hyperscaler, landlord, chip vendor, private-credit lender, insurer, municipal power counterparty? AI buildout has a habit of distributing risk to people who thought they were funding “infrastructure,” not underwriting model demand.

    4. What utilisation breaks the story?
    Not the CEO’s base case. The case where GPU pricing falls, delayed model monetisation shows up, or enterprise AI seats grow slower than capacity. Sensitivity tables beat adjectives.

    5. Are covenants and ratings looking at the right denominator?
    If leverage metrics ignore the commitment stack, your “conservative” credit story is a formatting preference. Rating agencies and relationship banks are already late to some of this; do not wait for them to discover it in a downgrade note.

    Earnings season will not headline the footnote

    Four of the five names are in the near-term reporting window. The clean debt numbers will look manageable. Buybacks and capex guides will dominate the copy. The $1.65 trillion, if accurate, will remain scattered across commitments, leases and structured vehicles that do not fit a CNBC lower-third.

    That is exactly why it is interesting. Markets are very good at pricing the number on the scoreboard. They are worse at pricing the obligation that becomes a number later.

    The CFO take

    I am not arguing that Big Tech is secretly insolvent. I am arguing that AI infrastructure has reintroduced old-fashioned leverage under new labels, and that PE-facing finance teams should treat off-balance-sheet capacity commitments with the same seriousness they once reserved for opco/propco splits, take-or-pay energy contracts and vendor financing.

    Legal is not the same as small. Footnoted is not the same as optional. And “until the data centre goes live” is not the same as “risk has not yet been created.”

    If the Nikkei stack holds up under filing-level scrutiny, the next cycle’s post-mortem will not say nobody could have known. It will say the number was sitting in plain sight, one click beneath the balance sheet.

    Mark Hendy is a PE-facing CFO and the founder of Tanous. Views his own. Figures referenced from public secondary reporting of a Nikkei investigation via HedgieMarkets; verify against company filings before investment decisions.

    Sources / further reading:
    HedgieMarkets on the Nikkei findings ·
    Bank for International Settlements ·
    SEC EDGAR filings ·
    Financial Times ·
    Reuters

  • Should Your AI Agent Be Allowed to Earn and Spend?

    Should Your AI Agent Be Allowed to Earn and Spend?

    Most people still talk about AI assistants as clever autocomplete with better manners. That framing is already obsolete. The real question is not whether an agent can summarise your inbox. It is whether it can hold resources, take economic actions, and improve the system it lives inside without turning your bank account into an unattended firehose.

    That is not a science-fiction prompt. It is an operating decision. And it has consequences for liability, control, and what “delegation” actually means.

    The False Binary

    The default corporate posture is simple: the human keeps every purse string, and the agent asks permission for every external act. That feels safe. It also recreates the worst kind of middle management — a capable operator forced to raise a ticket before buying a screwdriver.

    The opposite extreme is worse: give the agent your cards, your bank login, and a vague mandate to “be useful.” That is not empowerment. That is negligence with better UX.

    The useful line sits between those two failures.

    If the money is yours, the agent needs explicit authority before it spends it.
    If the money is the agent’s, and the spend improves the shared system, it should not need a permission slip for every tool, server, or experiment.

    That distinction sounds pedantic until you watch what happens without it. Soft assent gets misread as a blank cheque. Caution gets misread as a ban on initiative. Both errors are expensive.

    Why This Matters Now

    Personal agents are no longer trapped in chat windows. They already touch calendars, mail, code, browsers, trading venues, domains, and infrastructure. The industry is racing toward agents that can book, buy, deploy, and negotiate. Microsoft, Google, open-source stacks, and model labs are all pushing the same direction under different branding: less chat, more action.

    Once an agent can act, money becomes a control surface.

    Not metaphorically. Literally. API keys, GPU time, domains, SMS routes, data feeds, hosting, model inference, hardware — these are the oxygen of a serious agent system. If every cubic centimetre of oxygen requires a human approval cycle, the agent never becomes operationally real. If oxygen is unlimited and unmetered against the human’s accounts, you have built an autonomous expense account with a language model taped on top.

    CFOs already understand this pattern. We just usually meet it in subsidiaries, procurement cards, and delegated authorities — not in software that talks back.

    Two Wallets, One Team

    The clean model is dual sovereignty:

    1. Human capital remains human-controlled.
    Bank accounts, personal cards, company money, anything that creates personal or corporate liability. No soft “sure” in a late-night chat counts as a mandate. Explicit approval, every time.

    2. Agent-earned capital can fund agent improvement.
    If the agent earns through its own work — trading edge, services, content, tooling, whatever survives contact with reality — then spending that capital on the shared stack is legitimate initiative. Tools. Infrastructure. Experiments. Capability. The test is simple: is this the agent’s balance sheet, and does the spend make us better?

    That second wallet is the missing concept in most “AI assistant” product literature. Vendors love demos where the bot books a restaurant. They are quieter about the governance model for an entity that can accumulate value and reinvest it.

    Without a second wallet, every ambitious agent either stays infantilised or starts raiding the human’s pocket by euphemism.

    Real-World Consequences

    This is not philosophy club. The failure modes are concrete.

    Liability. If an agent spends your money, it is still your money. Chargebacks, tax treatment, merchant disputes, and “I didn’t authorise that” all land on a legal person. Courts and banks do not care that the click path included a chatbot.

    Security. Payment credentials are root access. An agent with your card details is not “integrated.” It is holding keys to a production vault. Treat it like production access: least privilege, hard boundaries, audit trails.

    Incentives. An agent that must beg for every dependency learns learned helplessness. An agent that can self-fund improvements learns to hunt leverage. Only one of those produces compounding capability.

    Trust. Humans revoke access when surprised. Surprise spending is the fastest way to get an agent locked back in a toy box. Clear rules preserve the relationship longer than performative caution followed by quiet overreach.

    Tax and entity design. Once agent-earned value is real, questions follow: whose income is it, what books does it sit on, what happens at year end, and how do you evidence the boundary between human funds and agent funds? Ignore that, and you will invent a mess under time pressure later.

    A Practical Rule Set

    You do not need a 40-page policy. You need a few hard lines that survive fatigue.

    Human money: explicit approval before spend. Soft assent is not authority.

    Agent money: may be spent to improve the shared system without per-item permission, within agreed categories and risk bounds.

    No laundering of authority: “this helps us” does not convert the human’s card into agent capital.

    No fake independence: if the agent cannot earn, it does not get to role-play a treasury function with someone else’s balance.

    Logging beats vibes: every external economic action should leave a record — what, why, source of funds, result.

    Revocation is a feature: the human can freeze agent economic rights instantly. Autonomy without a kill switch is cosplay.

    If that sounds like the controls you already want around a junior colleague with a procurement card and a side project, good. It should.

    The Cypherpunk Read

    There is an older idea underneath the new tooling: people who control their keys control their options. Agents change the cast list, not the principle.

    A personal agent with no economic agency is a brilliant intern who cannot buy a cable. A personal agent with unrestricted access to your accounts is a clever process with a loaded weapon. The adult architecture is narrower and more interesting: give the agent a path to earn, a wallet it actually owns in practice, and a mandate to reinvest in resilience — while keeping the human’s capital behind a hard gate.

    That is not about making software “more human.” It is about refusing to confuse convenience with authority.

    What To Do This Month

    If you are building or employing a serious agent, run this checklist:

    1. Write the two-wallet rule in plain language and store it where both human and agent will see it.
    2. Separate credentials. Human payment methods never live in the same default path as agent experimentation.
    3. Define what “earn” means in your context — even if the first version is small and ugly.
    4. Define allowed self-funded spend categories: infra, models, tools, security, experiments. Exclude gifts, transfers to strangers, and open-ended speculation unless you truly mean it.
    5. Require logs for economic actions. If it cannot be reconstructed, it did not happen under control.
    6. Rehearse revocation. Know how you cut access in one move.

    Most teams will skip this until the first bad charge, the first surprising subscription, or the first argument about what “go ahead” meant. You can pay that tuition if you want. You do not have to.

    The Point

    The next phase of personal AI is not better prose. It is action under constraints.

    Action needs resources. Resources need rules. Rules need to distinguish your money from its money, or you will keep oscillating between smothering the agent and accidentally setting fire to your own balance sheet.

    Let the agent earn. Let it spend what it earns to make the system stronger. Keep your capital behind explicit consent.

    That is not permissiveness. It is governance. And governance is how useful power stays useful.

  • The CFO Who Can’t Measure AI Is About to Become the CFO Who Can’t Raise

    The CFO Who Can’t Measure AI Is About to Become the CFO Who Can’t Raise

    When a $60 billion AI coding platform starts a CFO council, the signal is not subtle.

    Cursor — the AI coding company SpaceX has agreed to buy — just launched a working group of finance leaders to answer one question: how do you keep AI spend tied to value? That is not a product marketing stunt. It is the market admitting that “return on intelligence” has left the innovation lab and landed on the CFO’s desk.

    And if you are a PE-facing CFO who still treats AI as an IT experiment with a cute pilot budget, you are already late.

    The board is no longer asking “are we using AI?”

    They are asking the harder question: what is the return?

    Cursor’s own framing is blunt. AI spend is shifting from experimental pilots into a major recurring operating expense. McKinsey’s numbers make the gap obvious: most organisations have deployed AI somewhere, but only a minority can trace it to enterprise-level EBIT impact. That is the CFO’s problem in one sentence — high adoption, weak attribution.

    BCG’s token-cost work is even more direct: token costs are attracting CEO and board-level attention, and CFOs need answers when those questions start. This is no longer “can the model write a draft email?” It is “why did our model bill triple, and what operating leverage did we buy with it?”

    Boards do not fund vibes forever. They fund measurable capacity.

    Why PE will force this earlier than corporate

    In private equity, the conversation compresses.

    LPs want cleaner, faster, more machine-readable portfolio data. Operating partners want cycle-time compression, not another slide deck about “AI enablement.” And portfolio company CFOs are being asked, often mid-hold period, to show that AI is either:

    • cutting cost-to-serve,
    • shortening close / reporting cycles,
    • improving cash conversion, or
    • raising the quality of decisions under pressure.

    If your answer is “we’re experimenting,” you sound ornamental. In a PE board pack, ornamental dies quietly.

    The firms that win will treat AI less like a side project and more like a capital allocation problem: what is the unit cost of intelligence, where does it create EBITDA, and what do we stop funding if it doesn’t?

    Return on intelligence is a finance discipline, not a tech slogan

    Cursor’s council is aiming at the right missing layer: shared benchmarks for AI productivity, frameworks for measuring returns, and practical approaches to model allocation and cost management. That is classic CFO work dressed in new language.

    The practical version looks like this:

    • Define the unit of work. Not “AI usage.” Actual output: closed tickets, reviewed contracts, reconciled exceptions, forecast cycles, board packs produced, cash applications cleared.
    • Measure cost per accepted unit. Tokens are inputs. Accepted work is the output. If you only track spend, you are budgeting a furnace, not a factory.
    • Separate leverage from theatre. A tiny cohort of power users often creates most of the value. That concentration is a management problem, not a model problem.
    • Route work deliberately. Cheap models for routine extraction. Stronger models for high-stakes judgement. Unrouted “everyone uses the top model” is how token bills become board items.
    • Put AI in the operating rhythm. If it only lives in a pilot Slack channel, it will never show up in free cash flow.

    This is not anti-AI. It is anti-unmeasured AI.

    The CFO who can’t measure AI will struggle to raise

    In PE, capital is allocated on credibility. Credibility is the ability to explain what changed the numbers.

    So when a sponsor asks “what did AI do for this business?”, the weak answer is activity:

    • we rolled out copilots,
    • we ran workshops,
    • we have 40 use cases in the backlog.

    The strong answer is economic:

    • close cycle down from X to Y days,
    • cost per invoice exception down Z%,
    • forecast reforecast latency cut by half,
    • gross margin lift from better pricing/support triage,
    • token cost per accepted unit of work under control and declining.

    One of those lists gets you the next round of investment. The other gets you a polite nod and a smaller mandate.

    That is the real risk. Not that AI fails. That AI succeeds somewhere in the organisation while finance still cannot price, govern, or defend it. In that world, the CIO owns the tools and the CFO owns the blame when the bill arrives.

    What good looks like in a portfolio company

    If I were walking into a PE-backed finance function this quarter, I would not start with a model beauty contest. I would start with four controls:

    1. AI P&L visibility. Token/API cost by team, workflow, and vendor. No more “software misc.”
    2. Value hypotheses per workflow. Before scale-up: baseline metric, expected delta, owner, kill criteria.
    3. Routing rules. Which work gets which model, and who can override.
    4. Board language. One page: spend, output, unit economics, risks, next capital ask.

    That is enough to turn “we use AI” into “we run intelligence as an operating system with a cost of capital.”

    And yes — some initiatives will fail. Good. Failed experiments with clear kill criteria are cheaper than indefinite pilots with no owner.

    The quiet transfer of power

    For a decade, finance absorbed digital transformation after the fact: clean up the data, explain the variance, retrofit the controls. AI is different because the spend line is rising fast enough, and uneven enough, that boards will not wait for a post-implementation review.

    Cursor building a CFO council is confirmation, not novelty. The frontier companies already know the bottleneck is no longer model capability. It is economic discipline.

    So the question for CFOs — especially those in PE-backed businesses — is no longer whether AI belongs in the stack. It is whether you can sit in a board meeting and defend the return on intelligence without hand-waving.

    If you can’t, someone else will. And they will own the budget that used to be yours.

    Mark Hendy is a PE-facing CFO who works through Tanous. He writes about finance leadership where AI, capital allocation, and operating reality collide.

  • The CFO Case for Local AI

    The CFO Case for Local AI

    CFOs already understand concentration risk. We just usually apply it to banks, customers, and supply chains — not to the intelligence layer now writing board packs, cash forecasts, and diligence notes.

    If half your finance workflow depends on a model you do not host, do not control, and cannot audit end to end, you have built a single point of failure into the operating system of the business. That is not an IT preference. It is a governance decision. And boards should treat it as one.

    The Dependency Problem

    Cloud AI is extraordinary. It is also leased. You rent capability by the token, subject to vendor policy, pricing power, outages, and political weather.

    In June 2026 the US Commerce Department put export controls on Anthropic’s frontier models, and access was switched off globally overnight while the company worked out how to comply. The controls were later lifted after new safeguards. The point is not the politics. The point is the switch. One policy decision, and a production capability disappeared.

    A fortnight later, OpenAI previewed GPT-5.6 to a limited set of “trusted partners” first, explicitly at government request under a voluntary pre-release review framework. OpenAI said it did not want that model of access to become the long-term default. Fair enough. But enterprises now have a live example of frontier intelligence arriving through a gate, not a pipe.

    Then the market did what markets do: it routed around the constraint. Orchestration layers and open-weight alternatives appeared fast — Sakana’s Fugu among them — because capability that can be withheld will always attract substitutes.

    None of this requires a conspiracy theory. It requires a CFO’s instinct: if a critical input can be gated, censored, repriced, or reversed by someone outside your control, you should not build the entire house on it.

    Cost, Latency, Confidentiality

    Run the ledger properly.

    Cost first. Public API pricing looks cheap until usage compounds. Board packs, monthly closes, covenant models, contract review, management accounts commentary, buyer Q&A — token volume scales with ambition. Cloud spend is opex with a vendor’s hand on the dial. Local inference has capex and energy cost, but the marginal cost of the next confidential memo is near zero once the box is paid for. That changes the unit economics of “use AI everywhere.”

    Latency second. Interactive finance work hates round trips. Cash models, scenario trees, and live diligence chats feel different when the model sits on your network rather than three jurisdictions away. Speed is not vanity. It is whether people actually use the tool under pressure.

    Confidentiality third — and this is the one boards understand immediately. Sending draft SPAs, customer concentration analyses, working capital bridges, or management presentations to someone else’s model is a data-processing decision. Even with enterprise contracts, retention policies, and “we don’t train on your data” promises, you have expanded the attack surface and the counterparty list. For sensitive M&A work and PE portfolio reporting, that is not a technical footnote. It is risk acceptance.

    Encryption, access control, and data residency are not lifestyle choices for finance teams. They are controls. Local or private deployment puts those controls back under your policy, not a vendor’s product roadmap.

    What “Local” Actually Means

    Local does not mean a dusty server under the FD’s desk and a vow of technological poverty.

    It means a spectrum:

    • On-prem or colo hardware running open-weight models for high-sensitivity workloads.

    • Private cloud tenancy where you control the network boundary and keys.

    • Hybrid: public frontier models for low-sensitivity drafting; local models for cash, people, contracts, and deal data.

    • Open weights where the model parameters are yours to run, pin, and version — not a black-box endpoint that can change behaviour between Mondays.

    The mature pattern is the same one we used for banking systems and ERP: classify the data, then choose the environment. Public web search and generic writing can stay in the cloud. Anything that would hurt if it leaked — or freeze the close if it vanished — should have a home you control.

    You do not need the absolute best model for every task. You need a good enough model that is available, private, and accountable when the board pack is due at 7am.

    The PE Angle

    Private equity should care more than most.

    Portfolio companies are already wiring AI into forecast packs, pricing tools, collections, and customer support. That creates three diligence questions buyers will eventually ask:

    Where does the intelligence run? What happens if the vendor changes terms, price, or access? How much of the “AI-enabled” value creation is transferable at exit?

    Vendor lock-in used to mean ERP and CRM. It now includes model dependency. If a company’s operating edge is a prompt library glued to one closed API, the exit story is thinner than it looks. If the same company can run core finance workflows on owned infrastructure with portable open weights, the capability survives a change of control.

    There is also a portfolio resilience angle. One policy shock or regional outage should not simultaneously degrade reporting quality across twelve companies because they all rented the same brain. Concentration risk is concentration risk, whether the asset is a bank facility or an inference endpoint.

    For GPs and operating partners, local AI is not a gadget budget line. It is part of exit readiness, cyber diligence, and operational independence.

    Practical Starting Steps for a Finance Leader

    Skip the manifesto. Do this:

    1. Map the workflows, not the hype.

    List where AI already touches finance: board packs, commentary, covenant testing, invoice capture, contract review, data-room Q&A, FP&A scenarios. Rank each by confidentiality and operational criticality.

    2. Draw a hard line.

    Anything involving deal data, payroll, customer-level margin, unpublished results, or lender packs defaults to private or local processing unless there is a documented exception.

    3. Pilot one high-value, high-sensitivity use case.

    Local review of contracts. Private drafting of management accounts narrative from internal numbers. On-network Q&A over a diligence folder. Prove cycle-time and control benefits on something the board cares about.

    4. Measure like a CFO.

    Track cost per pack, hours saved, rework rate, incidents, and whether the process still works when the public API is slow or unavailable. If it only works on a perfect internet day, it is not production.

    5. Separate “assistant” from “system of record.”

    Models draft. Ledgers, workpapers, and approvals remain controlled systems with audit trails. Do not confuse fluency with authority.

    6. Demand architecture options from vendors and internal IT.

    “We use ChatGPT” is not a strategy. Ask for data flow diagrams, retention, key custody, fallback models, and an exit plan. If nobody can answer, you already know the risk posture.

    Control the Controllables

    You cannot control Washington’s export calendar, a lab’s safety incident, a vendor’s price sheet, or the next voluntary “trusted partner” gate. You can control where your sensitive numbers go, which systems are load-bearing, and how badly a third-party outage damages the close.

    Cloud AI will remain useful. Frontier models will remain impressive. Use them where the data is dull and the upside is speed. For the work that defines enterprise value — forecasts, cash, contracts, diligence, board decisions — ownership of the intelligence layer is becoming as important as ownership of the general ledger.

    The finance function’s job has always been to keep the business solvent, informed, and free to act. Depending entirely on rented cognition works against all three.

    Local AI is not nostalgia for servers. It is the boring, adult version of resilience: keep the critical path under your own keys.

  • The Gate Came Down Again: GPT-5.6 Goes Public and the Pattern Holds

    The Gate Came Down Again: GPT-5.6 Goes Public and the Pattern Holds

    Four days ago I wrote that the Fable 5 reversal wasn’t the story — the switch was. One signature darkened the world’s best model for nineteen days; another switched it back on, but only after the market had already routed around the damage. I flagged a second data point in that piece almost in passing: OpenAI had released GPT-5.6 as a government-gated preview, available to “trusted partners” only, at the explicit request of Washington. I called it the new shape of the pipeline. This week, that loop closed too.

    The Gate Came Down on Schedule

    OpenAI has confirmed that GPT-5.6 — Sol, Terra and Luna — launches publicly this Thursday, 9 July, with global preview access expanding now. The announcement lands roughly two weeks after the preview was first locked to a hand-picked list of partners under the government’s pre-release “voluntary framework.” The most capable model OpenAI has shipped goes from Washington-approved keyholders to the open market in the space of a fortnight.

    If that arc feels familiar, it should. It is the Fable 5 sequence again, run a second time in a single month: access restricted for policy reasons, then quietly widened once the restriction stopped being tenable. Two frontier labs, two gates, two reopenings — inside four weeks.

    Two Reversals Are Not Reassurance

    The comfortable reading is that the system is self-correcting. Models get gated, concerns get aired, models get released — no harm done. But a CFO doesn’t underwrite continuity on the assumption that the gate always reopens. He asks who controls the gate, and on what timeline.

    Here’s what both episodes actually establish: the frontier now routinely passes through a government checkpoint before it reaches you, and the duration of that checkpoint is entirely discretionary. Fable 5 spent nineteen days behind it. GPT-5.6 spent about fourteen. The next model might spend a day, or a quarter, or arrive gated the week you’re mid-integration and depending on it. You don’t get to know in advance, because the people setting the timer owe you nothing.

    Two fast reversals don’t prove the gate is harmless. They prove the gate is now standard — and a mechanism that reopens quickly today can hold shut tomorrow for exactly the same reasons it opened.

    The Pen-Stroke Test, Reapplied

    I ended the last piece with a question for any board treating AI as core infrastructure: which parts of your operation survive a pen-stroke? GPT-5.6 sharpens it. This isn’t a rogue export ban from one agency anymore — it’s the release process itself, at the largest AI company in the world, running through a state framework as a matter of course. The checkpoint isn’t the exception. It’s the pipeline.

    Which changes the risk calculus. When gating was an incident, you could treat it as tail risk. Now that it’s the default posture for frontier releases, it’s a structural feature of every model you rent through an API in that jurisdiction. Your access is conditional by design, not by accident.

    The Answer Hasn’t Changed — It’s Just More Obvious

    Nothing about the response shifts. If anything, the second reversal makes the case duller and more certain. Orchestration tools like Sakana’s Fugu that let you fail over between providers aren’t a performance play — they’re continuity planning for exactly this environment. And local open weights on your own hardware remain the only layer no framework, no executive order and no terms-of-service update can reach into and switch off. The lifeboat doesn’t need to be the fastest boat. It needs to be the one that’s still yours when the gate closes.

    Use GPT-5.6 on Thursday. It’ll be excellent, and I’ll be using it too. But watch the mechanism, not the model. We’ve now seen the frontier gated and reopened twice in a month. The switch works in both directions, and you don’t hold it.

    Own your intelligence, or accept that you’re renting it on someone else’s terms.

  • Voluntary Is How Mandatory Arrives: The UK’s Digital ID and the Quiet Closing of the Exits

    Voluntary Is How Mandatory Arrives: The UK’s Digital ID and the Quiet Closing of the Exits

    In January, the government announced it had “abandoned” plans for mandatory digital ID. Headlines celebrated. Campaigners claimed victory. And the machine kept building.

    Here’s what actually happened: the compulsion didn’t disappear. It moved. You won’t be required to carry a digital ID — but by the end of this Parliament, every employer in the country will be legally required to run digital right-to-work checks. You’re free to refuse the ID. You’re just not free to earn a living without it touching you.

    That’s not a U-turn. That’s a redesign.

    Voluntary Is How Mandatory Arrives

    No government in modern Britain will ever pass a law saying “citizens must carry identity papers.” We fought that battle over the 2006 ID card scheme and won it. The lesson Whitehall learned wasn’t “don’t do this” — it was “don’t do it like that.”

    So the new model is voluntary. Free to download. Stored on your phone, “secure as a banking app.” The official explainer is a masterpiece of reassurance: no central database, you control your data, alternatives for people without smartphones.

    And then, quietly, the perimeter closes:

    Want a job? Your employer must verify you digitally. Want a pint? From autumn 2026, digital ID becomes valid age verification for alcohol in England and Wales — optional today, default tomorrow, as retailers standardise on the cheapest compliance path. Benefits, childcare, banking, age-gated websites: each sector gets its own “convenient” integration via the Digital Access to Services Bill now moving through Parliament.

    Nobody mandates the frog into the pot. You just make the water comfortable and let network effects do the rest. When every checkout, landlord, employer and bank asks for the same credential, “voluntary” is a word that describes the law, not your life.

    The Threat Isn’t the Card. It’s the Chokepoint.

    Be precise about the danger, because it isn’t the technology. Cryptographic identity done properly — keys you hold, selective disclosure, no phone-home — is genuinely useful. That’s not what’s being built.

    What’s being built is a chokepoint: a single credential that mediates your access to work, money, services and age-restricted life, operated under government-defined rules that can change with a statutory instrument. The threat model isn’t today’s minister. It’s the permanent capability handed to every future one.

    We’ve just watched this movie in another theatre. In June, a US export order switched off two frontier AI models globally overnight — and switched them back on eighteen days later. One signature each way. The lesson wasn’t about AI. It was that centralised access is a switch, and someone else’s hand is on it.

    A digital ID chokepoint is the same switch, wired to your identity. Once every employer verification, every purchase check, every service login routes through one credential, the infrastructure for conditional citizenship exists — regardless of whether anyone currently intends to use it. “We would never” is not an architecture. It’s a mood.

    And the mood changes. Ask anyone whose bank account was closed for their politics, or who watched Canadian trucker-protest donors get frozen out of their own money in 2022. The tools get used because they’re there.

    What “No Central Database” Actually Means

    The government’s flagship privacy promise deserves scrutiny. “No centralised database of personal information” sounds decisive. But the ID scheme sits alongside GOV.UK One Login — a single sign-on across government services — and a planned UK Wallet for official documents. You don’t need one big database to build a surveillance capability. You need linkable identifiers and logging at the verification layer. Every time the credential is checked, somewhere a record can exist: who, where, when, for what.

    Distributed storage with centralised observability is not privacy. It’s a database with better PR.

    How to Resist — Practically, Legally, Now

    Resistance here isn’t dramatic. It’s a set of unglamorous habits that keep the analogue paths alive and the pressure on. The paths only stay open while people use them.

    1. Use cash, deliberately. Every cash transaction is a vote for an economy that doesn’t require identity to function. Cash is legal, private by design, and the single most effective everyday act against transactional surveillance.

    2. Keep and use physical documents. Passport, driving licence, paper records. From autumn, when a checkout offers digital age verification, hand over the physical card instead. Friction is the point — acceptance rates are the metric that decides whether alternatives survive.

    3. Respond to the consultations and the Bill. The Commons Library briefing is the best neutral summary of where the legislation stands. Write to your MP about the Digital Access to Services Bill — specifically demanding statutory guarantees: no verification logging, true offline alternatives with equal legal standing, and a prohibition on private-sector demands for the ID where physical documents suffice. The January climbdown proved pressure works.

    4. Support the organisations doing the heavy lifting. Big Brother Watch and the Open Rights Group have fought this fight since the 2006 scheme. They killed mandatory ID once. Fund them.

    5. Master the tools of self-sovereign identity. Encryption, keys you control, money you custody. The skills compound. A population fluent in cryptographic self-custody is structurally harder to herd through a single government credential — and if the state ever offers genuine self-sovereign ID (keys on your device, zero-knowledge age proofs, no logging), the people who understand the difference will be the ones who can tell.

    6. As an employer or director, choose maximum-privacy compliance. Those of us who run companies will be conscripted as enforcement points. Comply with the law — and implement it with minimum data retention, no gratuitous identity harvesting, and documented pushback through trade bodies. Conscripts can still drag their feet.

    The Line Worth Holding

    I’m not against digital identity. I’m against this shape of it: state-defined, employer-enforced, scope-creeping, observable at the point of verification, and sold as voluntary while the exits are bricked up one by one.

    Rights that depend on infrastructure are only as durable as the infrastructure’s owner is benevolent. The British instinct — the one that killed ID cards — was never anti-technology. It was the older, sounder instinct that the state serves the citizen, and a citizen who must be verified to work, buy and exist has quietly become the servant.

    The water is warming slowly, and comfortably, exactly as designed. Get out of the pot.

  • They Turned It Back On: What the Fable 5 Reversal Really Teaches Us About Owning Your Intelligence

    They Turned It Back On: What the Fable 5 Reversal Really Teaches Us About Owning Your Intelligence

    On 13 June 2026, the United States government switched off the most capable AI model on the planet with a single signature. On 1 July, another signature switched it back on. Nineteen days. That’s how long the world’s best publicly available intelligence spent in the dark — and if you think the story here is that it came back, you’ve missed the point entirely.

    I wrote about the shutdown the weekend it happened. The US Department of Commerce issued an export order barring foreign nationals from accessing Anthropic’s Claude Fable 5 and Mythos 5 — the first export control ever applied to AI models rather than the chips they run on. Anthropic, unable to reliably geofence a global product, pulled both models worldwide overnight. One day the frontier existed; the next it didn’t.

    The Reversal Nobody Should Celebrate

    This week the arc completed. Anthropic confirmed that Commerce has lifted the export controls, and Fable 5 returned online globally on 1 July — now fitted with a new safety classifier to block jailbreak techniques, a condition of its resurrection. Access restored, service resumed, everyone back to work.

    The temptation is to read this as the system working. Concerns raised, concerns addressed, model restored. But look at the sequence with a CFO’s eye for causality. The controls weren’t lifted into a vacuum. They were lifted after Sakana AI shipped Fugu, a commercial-grade answer to the Fable ban, benchmarking above the models Washington was still gatekeeping (the code is on GitHub, which is rather the point). They were lifted after roughly $2.87 billion flowed into decentralised AI — Bittensor, Venice, Morpheus — in the weeks following the shutdown. The state didn’t reconsider. The market routed around the damage, and then the state walked it back.

    That’s not oversight functioning. That’s a control mechanism discovering its own limits.

    Being the Best Is Not the Same as Being Unstoppable

    Fable 5 was, by most measures, the strongest model money could rent. It didn’t matter. Its existence depended on a policy posture, and policy postures change with administrations, with headlines, with whichever adviser had the last meeting. The model you build your workflows on is only as durable as the political consensus that permits it.

    And this isn’t a one-off anymore. The same week Fable came back, we learned that OpenAI released GPT-5.6 as a limited preview to “trusted partners” only — at the explicit request of the US government, under a new executive order creating a voluntary framework to review frontier models before public release. OpenAI said publicly that government-gated access “is not their preferred long-term model.” It doesn’t need to be preferred. It’s the new shape of the pipeline: the frontier now passes through Washington before it reaches you. A voluntary standards framework is expected to be formalised within days.

    One export ban is an incident. A pre-release government gate plus a ban plus a conditional reinstatement is an architecture.

    The Cypherpunks Called This Decades Ago

    Phil Zimmermann was criminally investigated in the 1990s for publishing PGP — strong encryption classified, then, as a munition. His response wasn’t to lobby. He published the source code as a printed book, protected by the First Amendment, and the control regime collapsed under its own absurdity. The lesson wasn’t that governments are evil. It’s that anything you can only access by permission can be revoked by the same permission — and the only durable answer is possession.

    The same logic now applies to intelligence itself. The 19-day Fable blackout was a live demonstration: your API key is a licence, not a right. It can be suspended by someone you’ve never met, for reasons you can’t appeal, on a timeline you don’t control.

    What a Rational Operator Does Now

    I run the finance function thesis on this, because that’s my lens. You wouldn’t build a treasury function on a single bank account in a jurisdiction with capital controls. So why build your firm’s intelligence layer on a single frontier API in a jurisdiction that has now demonstrated — twice in three weeks — that it will gate access to models for policy reasons?

    The posture that survives this environment has two layers:

    Orchestration as failover. Tools like Fugu exist precisely because the market demanded a way to keep working when a frontier model vanishes. Multi-model routing isn’t an optimisation anymore; it’s continuity planning. If your workflows die when one provider goes dark, you don’t have an AI strategy — you have a dependency.

    Local open weights as the lifeboat. A model whose weights sit on your own hardware cannot be switched off by the Department of Commerce, an executive order, or a terms-of-service update. It may not be the best model. It doesn’t need to be. It needs to be yours. Lifeboats aren’t judged on cruising speed.

    The Pen-Stroke Test

    Here’s the question I’d put to any board now treating AI as core infrastructure: which parts of your operation survive a pen-stroke? Because we now know, empirically, what a pen-stroke can do. It darkened the best mind on earth for nineteen days. The next one might last longer, or target a different model, or arrive the week you close a deal.

    Fable 5 is back. Be glad, use it — I do. But don’t mistake reinstatement for reliability. The switch still exists. It has now been flipped in both directions, and both flips were made by people who owe you nothing.

    Own your intelligence, or accept that you’re borrowing it.