The Capability You Rent
The model your work ran on was there on Tuesday and gone on Friday. You read the headline, filed it under "AI news," and scrolled on.
Last week the most capable coding model was switched off in an afternoon. Anthropic had just shipped its newest generation — Fable and Mythos, the pair everyone assumed would quietly make the next quarter better: Fable for the mere mortals, Mythos for the immortals — the engine serious work now leans on, mine included. Not deprecated. Not priced out of reach. Not moved behind a higher tier. Gone, by a government directive not one of the people leaning on it had any say in.
The event was covered loudly — Time, Fox Business, the Economist, the whole spectrum inside forty-eight hours. And most of the people whose work sat on top of that model did roughly what I did first: read the headline — US pulls Anthropic's most powerful models — filed it under "AI news," and scrolled on.
That filing is the tell. The coverage was loud; the reading was shallow. Everyone got the verdict. Almost nobody turned to the sentence underneath it — the one that isn't about Anthropic, or governments, or AI news at all. It's about you, and the way your work is built.
Here is the sentence. The capability you build your work on, you don't own. You rent it — and the rent is paid in something you don't control.
It felt like ownership; that's the whole trouble. You paid, and it was there — reliably, every morning, the way water is there when you turn the tap. And that comparison is exactly the mistake. Water is a utility: regulated, sovereign, dull on purpose, engineered to be the most boring thing in your day. You can build a house on it because a century of institutions exists to keep it boring. A frontier model is not that. It's a disruption wearing a utility's clothes — contested, fast-moving, sitting on a fault line of trade policy, switchable in an afternoon by people you'll never meet. We took the newest, least settled capability of the decade and filed it where we file the water bill.
So you did what anyone does with a utility: you arranged your work around the model being there. You wrote your process assuming the capability the way you assume the floor — and you stopped noticing you'd assumed it.
The directive didn't create that arrangement. It made it legible. For one afternoon the difference between owning a capability and renting permission to use one stopped being abstract, and a great deal of work found out all at once which side of that line it had been standing on.
This is worth naming precisely, because the reflex is to reach for a backup login and call it handled. (I reached for mine. It took a beat to notice that a second key to a house you're renting is still a house you're renting.) It isn't a tooling gap. It's a posture. Somewhere, someone built the work as if a borrowed capability were a part you owned — maybe you, maybe a call made above you — and that's a stance, not a feature anyone was short of.
So the repair isn't a spare key either. It's owning your relationship to the capability — a smaller, plainer thing than it sounds. It means knowing what the model is actually for in your work: not "I use AI," but the specific job it does — the one thing that would genuinely stop if the model went dark. It means knowing what could stand in its place before you need it to. And it means treating its presence as a decision you made and could remake, rather than a law of nature you build under. The renter assumes the model the way you assume gravity. The owner picked it, for a reason, and could pick again.
What that looks like in practice I'll come back to. First it's worth seeing why the posture matters more every month, not less.
It matters more for two reasons, and they pull the same way.
The first: the better the capability, the more reachable it is — the same edge that makes a model worth leaning on makes it the one a directive comes looking for. A model nobody depends on doesn't get switched off; there's nothing to be gained by it. The one running underneath millions of workflows is a different object — it's leverage, and leverage draws a hand toward the switch, whether that hand belongs to a government, a pricing committee, or a board. Capability and reachability sit at one coordinate. So "just use the best one" doesn't carry you clear of the question; it carries you deeper in.
The second is quieter and matters more. The capability itself is moving — off the model, and into the arrangement around it. Most of the recent jumps in what these systems can actually do came less from new model weights than from the scaffolding around them: the way calls get routed, the steps chained, smaller models stitched into a system worth more than any single part of it. When a stack of modest models wired together outperforms one frontier model on real work — and it now does — that's a result you got from the wiring, not the engine. The race stopped being only train a better model. It became build a better arrangement around the model — and an arrangement is something you assemble, not something you buy switched-on.
Which puts the renter in a strange position, once it's in focus. The part you rent — the raw model — is the part being commoditised. It's converging: the distance between the best and the rest is now counted in months, not years. More than a hundred and fifty of the security field's own people put their names to as much in the days after the ban — the capability isn't unique, it's present in other models, the frontier is close behind. The part that's appreciating is the arrangement — what you put around whatever model you reach for. And even there the ground moves: this quarter's clever scaffolding gets absorbed into next quarter's model, so no single trick stays valuable for long. What survives that absorption isn't a trick at all. It's the practice of arranging — run on your own work, again and again.
So the trap, plainly: you rent the part that depreciates, and unless you've built an arrangement of your own, you hold nothing of the part that appreciates. The ban didn't cause that. It printed the depreciation schedule where you could finally read it.
Here's the part the loud coverage never reached. The work that didn't so much as flinch when the model went dark didn't belong to people holding a better model. It belonged to people whose value never lived in the model in the first place. It lived in the arrangement — and the giveaway was how their Friday went. While everyone else hunted for a backup login, they swapped the engine and kept moving, because nothing they did was pinned to that one model. The job was named; the model was just whatever happened to be doing it that week.
That's "model-agnostic," once it stops being a checkbox and becomes a way of working: not "my setup supports six providers," but a process built so that which model is running is a swappable detail and never a foundation. The test is the one that just ran for real — if your model went dark this afternoon, is that a swap, or is it an event?
And that's the thing the ban quietly proved. The model is sand — it resets, it shifts under you, it can be switched off in an afternoon. The arrangement you live around it is solid: it compounds, and it's yours. Owning the capability was never about owning the model. It was about owning the arrangement the model plugs into.
And that's the threshold I'll stop at. What that arrangement looks like for your work — which of your workflows earns a warm alternative kept ready, what "model-agnostic" actually costs to build once you're living it instead of nodding at it, how you keep the practice running while the floor won't hold still — that's the part this piece won't hand you. Not because it's a secret. Because there's no file for it. It's the same shape as everything else worth having here: the arrangement can't be shipped to you, only built — on your work, with you. The model, you can rent. The owning, you do.
Next in the series → The Configuration Is the Moat. This was the diagnosis — the model is sand. Next is the solid part: what the arrangement actually is, and why the configuring, not the model, is the moat. (coming soon)
Catch you next time.
— Ambros
Co-created with AI. The judgment is mine.
The reading underneath
For anyone who'd rather turn the thing over than scroll past it.
The directive and the shutdown — Anthropic's official statement · the WSJ trigger story (Amazon's talks with officials that set it off).
"More than a hundred and fifty of the security field's own people" — the open letter on transparent AI cyber protections, signed by 150+ security professionals stating the capability isn't unique.
The lead "measured in months, not years" — Rafa Schwinger, The Physics of a Fable; benchmarks at artificialanalysis.ai.
"A stack of modest models outperforms one frontier model" — Andrew Trask on routed ensembles; OpenRouter's Fusion as the working proof.


