A vendor can sign every clause a bank asks for, data residency, uptime, breach notification, and still not be able to promise tomorrow.
Not because the vendor is dishonest. Because continuity was never entirely theirs to promise.
In June 2026, the US Commerce Department ordered Anthropic to suspend foreign-national access to its two most capable models, Fable 5 and Mythos 5, for every user outside the US, including the company's own foreign-national staff. Not a breach. Not a contract dispute. A government directive, triggered after researchers found a guardrail bypass exposing offensive cybersecurity capability, including the ability to generate working exploit code. Anthropic couldn't reliably tell a foreign national from a US person across a user base in the hundreds of millions, so both models went dark for every customer, American or not. Access returned on June 30, once the company had tightened the guardrails the government wanted fixed. Nothing in Anthropic's control, and nothing in any customer's contract, decided when.
"Frontier access has become conditional infrastructure," Sanchit Vir Gogia, chief analyst at Greyhound Research, said once the models came back. "The models went dark globally because nationality could not be verified in real time, so a control aimed at foreign nationals became an outage for everyone."
Months earlier, a different kind of interruption showed the same shape from the infrastructure side. In March 2026, strikes during the Iran conflict hit AWS facilities in the UAE and Bahrain, knocking out availability zones across two regions and starting a fire at one UAE site. Contact centers and digital banking at Abu Dhabi Commercial Bank and Emirates NBD went down for hours; full regional capacity took months to rebuild. No service-level agreement had anticipated it, and it wasn't AWS who answered for it. The Central Bank of the UAE issued a rare waiver letting banks temporarily host customer data outside the country, reversing its own residency rule, so lenders could fail over to infrastructure abroad while AWS rebuilt. Iran struck the same Bahrain facility again in July, a reminder that the waiver wasn't a plan drawn up once and filed away. It had to keep holding.
"We sincerely apologise to our customers for the inconvenience experienced over the past 48 hours," ADCB group chief executive Alaa Eraiqat said once services were restored. The bank, he added, was "taking this opportunity to further strengthen our operational resilience and service infrastructure... even in unlikely extreme situations like this." ADCB had done nothing wrong. It still had to apologize for it.
→ The same Gulf strikes, traced through everything that quietly ran on top of the damaged infrastructure, ride-hailing, payments, two major banks: Cloud Beneath the Cloud.
Neither of these is a story about a vendor breaking a promise. Both are stories about a promise that was never the vendor's to make.
The board conversation this changes
A vendor's continuity is bounded by its own government's restraint, and by whatever regional infrastructure happens to be standing that week. Neither of those is on the vendor's org chart, and neither shows up in a request for proposal. Gartner named the response one of its top strategic technology trends for 2026: geopatriation, the deliberate move of workloads off global hyperscale cloud and onto jurisdictionally distinct infrastructure. Worldwide sovereign cloud spending is on track for eighty billion dollars in 2026, up 35.6 percent on 2025. Governments are the largest buyers. Financial services is the sector right behind them, pushed there less by geopolitics in the abstract than by rules like the EU's Digital Operational Resilience Act, which requires banks to hold a tested exit strategy for losing their primary cloud provider entirely. It has to be a plan a regulator can ask to see, not a slide in a resilience deck. Sound architecture doesn't protect a board from a directive issued in a capital it's never had reason to think about before.
→ The architecture argument underneath this, in full: The On-Prem Awakening.
That piece argued sovereignty is a choice about which system decides, records and contains a customer's data, not a paperwork exercise. It's still true, and it still isn't enough on its own. Correct architecture tells you who's accountable in steady state. It doesn't tell you what happens the week a decision gets made in a capital that has nothing to do with your bank, by a government with no visibility into your customers at all.
What holds up
No clause survives a government directive or a damaged data center, so a better contract isn't the fix. What holds up is how fast an enterprise can move once one of these lands, measured in hours, not the quarter a normal vendor migration takes.
On the infrastructure layer, that's the argument for deployment under the operator's own control, on-premise, private cloud, hybrid, rather than trusting a single cloud vendor's terms of service to hold under a pressure the vendor never chose either. On the delivery layer, it's the same argument at a smaller scale: the channel a message actually travels through, push, SMS, email, WhatsApp, is usually hard-coded into a campaign tool by whoever set it up years ago, invisible until the day it's the only thing standing between a bank and its customers. Appice's Traffic Manager exists for that day: providers monitored continuously, a failing one substituted automatically, in under an hour, with zero code changes. It doesn't solve the infrastructure question on its own, that's a separate architectural choice, but it solves the one most banks haven't priced in at all, which channel vendor they're quietly hostage to.
→ A single-region MarTech outage that made the same point a year earlier: The Open Architecture Illusion.
What this changes in a vendor review
Three questions worth adding to the next vendor review. If this vendor's home government ordered it to stop serving you tomorrow, how long before you could route around it, hours or quarters? If the region your data sits in lost power, connectivity or physical capacity for a season, is failover a plan on a slide or a switch someone can flip? And who, today, actually owns the decision to move, a named person, not a migration project nobody's had to write yet. A bank that can answer all three has priced in a risk most vendor contracts still pretend isn't there. DORA already requires an answer in writing from banks operating in the EU; other regulators are watching before drafting their own.
Uptime is a contract. Continuity is a government's to give or take, or an outage's, and it was never the vendor's promise to keep. The only defense left is being able to move before anyone asks permission.
The full argument for reversible architecture, the Traffic Manager pattern included, is in The Perimeter.