Back to AI Research

AI Research

Sovereign by necessity? Frontier AI export controls... | AI Research

Key Takeaways

  • Frontier AI export controls, cyber security, and the limits of national AI capability" examines the geopolitical and security implic...
  • A small number of firms based in two states produce the most capable frontier AI models.
  • The governments of those states have shown both the legal power and the political will to decide which other countries may use these systems.
  • In June 2026 the United States required a leading developer to obtain licences before releasing its most advanced models to any foreign person, including foreign nationals resident in the United States.
  • The affected models were withdrawn worldwide at short notice, partly because the restriction proved impractical to administer.
Paper AbstractExpand

A small number of firms based in two states produce the most capable frontier AI models. The governments of those states have shown both the legal power and the political will to decide which other countries may use these systems. In June 2026 the United States required a leading developer to obtain licences before releasing its most advanced models to any foreign person, including foreign nationals resident in the United States. The affected models were withdrawn worldwide at short notice, partly because the restriction proved impractical to administer. This followed within months of the first documented case of a largely autonomous, AI-run cyber espionage campaign, and coincided with mounting evidence that frontier models alter the economics of both cyber attack and cyber defence. This article examines how these two developments interact, and situates them within the unusual market dynamics now driving large-scale AI development. It argues that access to frontier AI is becoming part of national cyber defence, that such access can be revoked, and that the obvious remedy of sovereign capability remains only partly feasible for all but a handful of states. Drawing on evidence about training costs, the concentration of computing power and the support offered by national AI programmes, it asks what sovereignty can realistically mean for small and middle powers, and for large powers as well. The article proposes a layered strategy: negotiated access guarantees, sovereignty at the level of inference, hedging with open-weight models, pooled regional capability, sustained talent development and continued investment in basic cyber resilience. The open-weight hedge proves at once more capable and more politically exposed than is commonly assumed. Much of the near-term risk lies in how capable models are deployed and contained rather than in their apparent performance.

"Sovereign by necessity? Frontier AI export controls, cyber security, and the limits of national AI capability" examines the geopolitical and security implications of the concentration of frontier AI development within a small number of firms in two states. The authors, Alan Woodward and Andrew Rogoyski, argue that because frontier AI is now integral to national cyber defense, the ability of these two states to restrict access to such models creates a significant vulnerability for other nations.

The Challenge of AI Sovereignty

The paper identifies that the most capable AI models are produced by a limited group of firms in only two countries. These governments have demonstrated both the legal authority and the political intent to control which foreign entities can access these systems. A notable example occurred in June 2026, when the United States mandated that a leading developer obtain licenses before providing advanced models to any foreign person, including foreign nationals living in the U.S. This led to a global withdrawal of the models, as the licensing requirements proved difficult to manage.

The Intersection of AI and Cyber Security

The authors note that frontier AI models have fundamentally changed the economics of cyber attacks and defenses. This shift is particularly urgent following the first documented instance of an autonomous, AI-driven cyber espionage campaign. Because access to these models is now a component of national cyber security, the risk of that access being revoked by a foreign power creates a strategic dependency. The authors conclude that achieving full sovereign AI capability is currently impractical for most nations due to the high costs of training models and the extreme concentration of necessary computing power.

A Layered Strategy for National Capability

To address these risks, Woodward and Rogoyski propose a multi-layered strategy for small and middle powers:

  • Negotiated Access: Securing formal guarantees for AI model access.

  • Inference Sovereignty: Focusing on the ability to run models locally.

  • Open-Weight Hedging: Utilizing open-weight models as a safeguard, though the authors warn that this approach is more politically exposed than is generally recognized.

  • Regional Cooperation: Pooling resources to build shared regional AI capabilities.

  • Resilience: Sustaining long-term investment in talent development and basic cyber security infrastructure.

Key Considerations for Implementation

The authors emphasize that the primary near-term risk is not necessarily the performance of the models themselves, but how they are deployed and contained. While open-weight models offer a potential hedge against export controls, the paper suggests that their utility is constrained by the political realities of their development and distribution. The analysis suggests that for most states, sovereignty in the age of frontier AI is a matter of necessity that requires a pragmatic, layered approach rather than the pursuit of total independent control over the entire AI development stack.

Comments (0)

No comments yet

Be the first to share your thoughts!