The Access Gap
- Jun 22
- 7 min read

JPMorgan and Goldman didn't restrict Claude because the model stopped being useful. Anthropic didn't withdraw Fable and Mythos because customers stopped wanting them. Read the pattern correctly and a new operating constraint comes into view — one regulated institutions need to govern like any other.
The model was not the problem. That is the point.
JPMorgan reportedly cut its Hong Kong staff off from Anthropic's Claude models in June, extending a restriction Goldman Sachs had adopted in April. In neither case was performance the issue. The trigger was access: licensing terms that exclude Greater China, a strict reading of the contract, and the growing sensitivity around where advanced AI can be used. Days earlier, Anthropic had taken its newly launched Fable 5 and Mythos 5 models offline after a US export-control directive required access to be suspended for foreign nationals — pulling them for everyone because it could not implement the restriction selectively in time. Different mechanisms, same signal: a model can be technically available in the market and operationally unavailable to part of the organisation.
That is the access gap. Most firms are still asking which model performs best. The sharper question is becoming: can the business still operate when the model is no longer available to the team, country or workflow that needs it?
Decode the pattern first
The JPMorgan case is easy to misread. The tempting headline is geopolitical — AI splitting into blocs. That may be part of the story, but it is not the most useful reading for executives. The practical reading is operational. A global bank can approve a model in one place and remove it in another; a tool can sit inside an internal AI platform for some employees and vanish for others; a vendor relationship can look fine at group level and become untenable for a specific geography or business line.
None of this is new in regulated finance. Banks have always managed regional constraints, data rules and outsourcing restrictions. What is new is the constrained asset. It is no longer only a database, a cloud service or an application. It is intelligence. Once analysts, developers, compliance and client-facing teams reorganise their work around a model, losing access is not a minor inconvenience — it interrupts a way of working that has already become embedded. The question is not whether any given model is good. It is whether the organisation has built around access it does not fully control.
Access is not capability
At first, an AI provider feels like a tool. Teams use it to draft, developers to code, analysts to research, compliance to accelerate review. None of it looks like dependency. It looks like productivity. Then the work starts reorganising itself around the model: prompts are tuned to its behaviour, retrieval systems calibrated to it, agents built on its tool-calling structure, evaluation routines shaped around its output. Employees assume the capability will be there tomorrow because it was there yesterday.
That is where the economics quietly change. The company still believes it has bought software. In reality it has begun running part of its operating model through someone else's infrastructure, rules and availability decisions. The contract may be replaceable. The workflow may not.
Europe already holds part of the answer
This is where the European regulatory environment is more useful than many firms realise — and not only because of the EU AI Act. The AI Act matters: it helps institutions classify systems, identify high-risk use cases such as creditworthiness and customer assessment, and build risk management into the AI lifecycle. But the access problem is not only an AI-risk problem. It is an operational-resilience problem, and that is DORA's territory.
DORA was designed for exactly this dependency logic — financial entities increasingly rely on external technology providers for critical services, and unmanaged reliance becomes a systemic weakness. It does not stop a provider from changing access, altering terms, or being caught by an external government decision. What it does is stop a regulated institution from discovering the dependency only after the disruption. Europe's advantage is not that its rules eliminate technology dependency. It is that they force dependency to become visible.
In practice, DORA turns AI access into a management question. If a model supports a critical or important function, the institution should know it. If a workflow depends on a single provider with no credible alternative, it should know that too — and know, before access is lost, whether switching would take three months, trigger new approvals, create data issues or interrupt customer service. DORA also requires exit strategies for ICT services supporting critical functions, and an exit strategy is not a clause in a contract; it is the tested ability to move or continue a service without unacceptable disruption. For AI-enabled work that means concrete answers: can the same workflow run on another model, can the data be reconnected safely, do the controls still hold, is the output still good enough, and who decides when to switch? This is where many AI strategies remain weak. They optimise for adoption, not reversibility — measuring usage while leaving dependency untested.
"Approved vendor" is not executable capability
This is the trap. A firm can have an approved provider, a responsible-use policy, a model-risk process and a clean procurement file — and still not have proven that the capability is executable where the business needs it. The real test is concrete: can the relevant team use the model in its jurisdiction, for this workflow, with the required data connected, under the applicable rules — and can the process still run if the model is removed? If the fallback has never been tested, the organisation does not yet have an AI capability. It has a dependency with a nice interface. Adoption metrics hide this. A firm can report hundreds of use cases and have no answer for what happens when a provider restricts a region or pulls a model. The dashboard says adoption. The operating model says exposure.
Model-agnostic by design
The conclusion is not to avoid frontier models — the capability is real and the gains are material. It is that the workflows that matter should be model-agnostic by design. Not perfectly model-neutral, which is unrealistic, but built so the business logic is not trapped inside one provider. Prompts, evaluation criteria, retrieval content, business rules and decision rights should stay as portable as possible; alternatives should be tested against the actual process, not just abstract benchmarks; and critical workflows should carry a defined minimum service level if the preferred model disappears.
Crucially, not every use case earns the same continuity planning. If marketing loses a drafting tool, work slows; it does not stop. If a bank loses a model embedded in software development, fraud review, transaction monitoring or compliance analysis, the cost of disruption is an order of magnitude higher. The resilience question should follow the business case: the more directly a model drives a material outcome, the more deliberately its dependency should be governed. That is where DORA and AI strategy should meet — and rarely do.
The ownership gap
The hard part is not technical. It is organisational. Legal sees the licence, procurement sees the vendor, technology sees the integration, security sees the access risk, risk sees the controls, compliance sees the regulatory perimeter, the business owner sees the operational impact, and local teams see the geography. Each function can be right within its own frame while the organisation is wrong as a system, because nobody owns the full dependency. AI access cannot be governed through a vendor register or a model-risk review alone. It needs orchestration across functions that each see only one part of the picture — which is precisely the discipline DORA and the AI Act, used well, can supply.
What BridgeUp is doing about it
The lesson from JPMorgan, Goldman and Anthropic is not that firms should stop using frontier AI. It is that AI capability is not the same as AI access — and the gap between them is an integration problem, not a procurement one.
This is the terrain BridgeUp works. The access question is the kind that arrives with five right answers and still cannot move: legal reads the licence and the jurisdiction, technical sees the integration and the portability, commercial owns the business case that decides which workflows are worth protecting, the people dimension holds the decision rights and the question of who can act when access changes, and data governs what can be reconnected and how. Each function is right within its own frame. The dependency still belongs to no one. As the orchestration practice for European regulated industries, BridgeUp holds all five dimensions at once — without belonging to any of them — and drives the question to a decision: which agentic workflows are genuinely critical, which carry tested alternatives, and what the operating reality actually does the morning a model disappears from a team, a country or a workflow. Regulation — the EU AI Act, DORA — is the terrain this plays out on, not the work itself; the work is making the operating reality hold up to it.
The technology is here. Making it hold when access shifts is the integration ahead.
The firms that win with agentic AI will not be the ones running the most tools. They will be the ones that know which capabilities to own, which to rent, and which dependencies they cannot afford to leave unowned. The model is the easy half. The integration is the work.
Not sure whether your agentic programme could absorb a sudden loss of access? That is usually the kind of question a Leadership Read answers first — a senior, neutral read of where your programme actually stands and the first moves to make. Where the dependency is already concrete — a single-provider workflow under an AI Act or DORA deadline — a Build Sprint orchestrates one defined piece, such as a continuity and fallback design, to a conclusion and designs how it runs day to day. Start a conversation.
Sources: Financial Times reporting on JPMorgan and Goldman Sachs restricting Claude access in Hong Kong (April–June 2026); reporting on the US export-control directive concerning Anthropic's Fable and Mythos models; Regulation (EU) 2022/2554 (DORA); the EU AI Act; EBA guidance on outsourcing arrangements.
An analysis from BridgeUp Consulting — bridgeupconsulting.com




Comments