Your AI Contract Has a Clause Nobody Signed
Three times in five weeks, working AI models became unavailable to paying customers, and the three events had nothing in common except the outcome. On June 12, the most capable model on the market went dark worldwide after a government export-control directive arrived at the vendor late on a Thursday afternoon; access came back roughly three weeks later. Through July, multiple federal departments blocked their employees from using Chinese AI models while reports circulated of broader measures under consideration. Then on July 19, Moonshot paused new subscriptions to Kimi K3, the most talked-about model launch of the summer, because demand outran its GPU supply within 48 hours. A directive, a policy posture, a hardware shortage. Different causes, different countries, different politics, identical result: access ended on a timeline the customer didn't choose. Every AI dependency now carries what we call the availability clause, and leaders who plan as if it doesn't exist will read about their own architecture in the news.
What actually happened to model availability this summer?
Access got interrupted from three unrelated directions, and none of them appeared in anyone's contract.
Take the events one at a time, because the pattern only shows up in the aggregate. The June directive required the vendor to block foreign nationals from its two newest models, a condition it couldn't verify in real time, so it disabled both models for every customer on the planet, mid-subscription, with no advance notice. Teams building on those models found out the way the public did. Restoration took a negotiation between the company and the government that no customer had a seat in. The federal department blocks ran the other direction: agencies spanning defense, energy, commerce, and Congress restricted internal use of Chinese models, and reporting through July described further options under discussion, from hosting requirements to supply-chain rules, none finalized. And the Moonshot pause had no government in it at all. A 2.8 trillion parameter model met more demand than its lab had chips to serve, so the lab protected existing subscribers and closed the door to new ones while it adds capacity. To be clear about what this article is doing: we take no position on whether any of these decisions was right. Whichever way the policy debates resolve, the view from your side of the API is the same. The model you planned around answered yesterday and doesn't today.
What is the availability clause?
The availability clause is the unwritten term attached to every AI dependency: access can be paused, gated, throttled, or revoked by actors and events outside your commercial relationship.
The clause was never negotiated. It binds anyway. It exists because model access now sits downstream of at least four parties who are not you and not your vendor's account team. Governments on both ends of the supply chain can restrict a model, and this summer proved that applies to American frontier models as readily as Chinese open ones. The vendor's own risk posture can pull a model or gate a capability in response to a jailbreak, an incident, or a regulator's raised eyebrow. Physical compute supply caps how much of a popular model exists to sell, as Moonshot's GPU wall just demonstrated. And the cloud intermediaries most enterprises actually buy through add a fourth layer that can drop or delay a model for reasons of their own. Traditional vendor risk lives inside a contract: you have an SLA, a renewal date, a negotiation. The availability clause sits above all of that. There's no counterparty to call, because the counterparty is a policy meeting, a hardware market, or a compliance officer you'll never meet.
Haven't we covered model-loss risk before?
We gamed out one scenario. This summer showed the risk is ambient, arriving from several directions at once, including directions with no politics attached.
Earlier this year we walked through what a restriction on Chinese models would mean for companies that standardized on them for cost, and that analysis stands. What's changed is the shape of the problem. That piece asked what happens if one specific policy lands. The last five weeks delivered availability shocks from an American lab's government standoff, from agency-level compliance postures that shift behavior long before any rule is final, and from a vendor simply running out of hardware. Uncertainty does real work here even when nothing is enacted: when departments blocklist a model category, counsel at regulated companies start asking whether it belongs in production, whatever the eventual rules say. This is also where single-model risk gets its teeth. Concentration on one vendor was always an exposure, but the availability clause is the mechanism that converts the exposure into an outage. A company running everything through one model is betting on more than that vendor's roadmap. It's betting that four external parties it can't see will all keep saying yes.
What should you do about a clause you can't strike?
You can hold this risk one of two ways, and only one of them is a decision.
The first path is to absorb availability shocks as news. Most companies are on it by default. Nothing breaks until something does, and then the dependency map gets drawn live, during an outage, by whoever's still in the office. The cost of this path runs past downtime, into discovering that nobody knows which workflows die when a specific model goes dark, because nobody ever wrote it down. The second path treats availability as an architectural input. Inventory which production workflows depend on which models, including the models buried inside SaaS tools you don't think of as AI vendors. Qualify a fallback for each workload that matters and push real traffic through it before you need it, because a failover you've never exercised is a hope. Put an abstraction layer between workflows and any single provider so switching is configuration, and set an honest recovery-time target for a model outage the way you already do for a data-center one. Swap-ready architecture was worth building when the risk was a vendor repricing you. Now the same investment covers a directive, a blocklist, and a GPU shortage at once, and that's the argument for making it this quarter: one build, every direction of the clause covered. The clause stays in force either way. The two paths just decide whether you meet it prepared.
If you don't know which of your workflows would go down with which model, we can help you.
Check out our AI Blueprint approach or reach us at contact@theyor.com