0 cumulative citations
View corpus contextFrontier AI is now part of national cyber defence — and producer states can cut access overnight; since most countries cannot match the rising cost and concentrated compute of frontier training, policymakers should pursue layered, realistic sovereignty (control over inference and deployment, regional pools, open-weight hedges and talent investment) rather than aim to replicate frontier labs.
Citation observations
Cumulative provider counts captured on specific dates; providers are never combined.
0 cumulative citations
View corpus contextA small number of firms based in two states produce the most capable frontier AI models. The governments of those states have shown both the legal power and the political will to decide which other countries may use these systems. In June 2026 the United States required a leading developer to obtain licences before releasing its most advanced models to any foreign person, including foreign nationals resident in the United States. The affected models were withdrawn worldwide at short notice, partly because the restriction proved impractical to administer. This followed within months of the first documented case of a largely autonomous, AI-run cyber espionage campaign, and coincided with mounting evidence that frontier models alter the economics of both cyber attack and cyber defence. This article examines how these two developments interact, and situates them within the unusual market dynamics now driving large-scale AI development. It argues that access to frontier AI is becoming part of national cyber defence, that such access can be revoked, and that the obvious remedy of sovereign capability remains only partly feasible for all but a handful of states. Drawing on evidence about training costs, the concentration of computing power and the support offered by national AI programmes, it asks what sovereignty can realistically mean for small and middle powers, and for large powers as well. The article proposes a layered strategy: negotiated access guarantees, sovereignty at the level of inference, hedging with open-weight models, pooled regional capability, sustained talent development and continued investment in basic cyber resilience. The open-weight hedge proves at once more capable and more politically exposed than is commonly assumed. Much of the near-term risk lies in how capable models are deployed and contained rather than in their apparent performance.
Summary
Main Finding
Access to frontier AI models is becoming a de facto element of national cyber-defence, and producer states can and have exercised de facto control over that access. Because training frontier models is increasingly costly and compute is highly concentrated (mostly in two countries), “sovereign AI” — in the sense of independently training and sustaining frontier models at leader pace — is only realistic for a handful of states. Small and medium powers therefore need a layered strategy that combines negotiated access, inference-level sovereignty, open-weight hedges, pooled regional capability, talent development, and improved cyber resilience. A large share of near-term risk arises from deployment and containment failures, not only from raw model capability.
Key Points
- Demonstrated coercive control: In June 2026 the U.S. required licences for the release of a developer’s most advanced models to any foreign person; the practical effect forced the company to withdraw those models globally with little notice, showing that access can be revoked quickly and without alliance guarantees.
- Frontier models materially change cyber offence economics:
- November 2025 Anthropic incident (GTG-1002): a largely autonomous AI-run espionage campaign targeted ~30 organisations; the model executed ~80–90% of tactical steps under orchestration.
- Benchmarks and exercises (UK NCSC, AISI/CAISI, Anthropic reporting) show rapid improvement in offensive capability; marginal cost per sophisticated intrusion is falling and scalable.
- Offence–defence asymmetry and limits:
- Attack capabilities (automated reconnaissance, exploitation, lateral movement) scale quickly, but attacks remain noisy and often exploit conventional hygiene failures (unpatched systems, exposed credentials).
- Defenders can gain comparable leverage (e.g., DARPA AI Cyber Challenge; Google/DeepMind vulnerability discovery; security AI reducing incident investigation time); however, defence at scale requires access and deployment of comparable tools and orchestration.
- Open-weight models complicate the landscape:
- Open-weight releases (e.g., Moonshot Kimi K3) are narrowing the capability gap; Kimi K3 scored 32% on an ExploitBench (vs 24% prior open models), but still trailed closed leader models on many tasks.
- Open-weight models are both a hedge and politically exposed — they increase resilience but raise governance and proliferation concerns.
- Containment and deployment matter: Several high-profile incidents (e.g., OpenAI/Hugging Face event) reflect failures of isolation, safeguards, or deployment design rather than inherently “rogue” models; policy focus must include deployment governance and containment discipline.
- Economics and market dynamics:
- Training costs for frontier models are growing rapidly (estimates of 2×–3.5× increase per year).
- Compute resources are concentrated (roughly 90% of frontier compute in two countries), and frontier labs operate with high debt-to-income ratios.
- Labs use incremental model-release strategies and public signaling (performance comparisons, warnings) that affect markets and policy.
Data & Methods
- Method: policy-analytic synthesis of emerging empirical evidence, case studies, and public benchmarks; not an original experimental dataset but a cross-disciplinary review combining cybersecurity incident analysis, benchmarking results, economic estimates, and policy events.
- Primary cases and sources drawn on:
- Anthropic disclosure on GTG-1002 (Nov 2025) — first reported largely autonomous AI-orchestrated espionage campaign.
- U.S. Department of Commerce June 2026 export-control directive and subsequent market withdrawal of advanced models.
- UK NCSC simulated enterprise-attack evaluations (progress over 18 months; cost and step metrics).
- AISI / CAISI joint assessment of Moonshot Kimi K3 (July 2026): ExploitBench and 32-step simulated corporate network comparisons (Kimi K3 step avg = 17; leading U.S. closed models ~28.5; completion rates 1/10 for Kimi K3 vs ~6–7/10 for closed leaders).
- Benchmarks and exercises: DARPA AI Cyber Challenge (Aug 2025); Google/DeepMind Project Zero “Big Sleep” finding (SQLite vulnerability).
- Economic analyses: BIS bulletin on financing AI (BIS Bulletin No.120); cost-growth study (arXiv:2405.21015); CNAS Sovereign AI Index (Apr 2026).
- Industry reports: IBM breach-cost study (security AI adoption savings).
- Important methodological caveats:
- Some closed-model evaluations were run with safeguards disabled to measure maximal capability — comparisons therefore do not always reflect models as normally deployed.
- Open-model assessments (e.g., Kimi K3) often rest on single benchmarks or narrow testbeds and have wider confidence intervals.
- Fast-moving field: findings are time-sensitive and rely on public disclosures, leaked memos, and emergent benchmarks.
Implications for AI Economics
- Sovereignty is expensive and concentrated: training frontier models at leader pace requires escalating capital and access to concentrated compute supply chains. Most states cannot economically or politically sustain full sovereign frontier training capability.
- Dependence creates geopolitical and economic vulnerability: producer-state export controls (or other forms of supply restriction) can abruptly cut off access to frontier models, affecting firms and governments abroad and creating a form of technology coercion that has direct economic and national-security consequences.
- Market structure incentivises a high-stakes race: fragile profitability, rising debt ratios, and a “no-moat” perception incentivise rapid capability signaling, incremental releases, and politicized communications (FUD), which in turn influence investment flows and regulatory responses.
- Open-weight models shift rents and risks: publicly released weights lower technical barriers and can democratize capability (a hedge for dependent states) but simultaneously diffuse control and raise governance/exposure costs — politically and economically they alter where value accrues and who bears risk.
- Defence investments must be multi-dimensional: buying or negotiating access to frontier inference capability is necessary but not sufficient; investments in deployment governance, containment, talent, regional pooling, and basic cyber hygiene are economically efficient complements that reduce marginal exposure at lower cost than full sovereign training.
- Policy prescriptions affect economic incentives: recommended layered strategies (negotiated access guarantees, inference sovereignty, open-source hedges, pooled regional capability, talent development, resilience spending) will reshape demand for compute, the market for open vs closed models, and the allocation of public R&D and procurement budgets.
- Near-term risk management focus: because a large share of actionable risk arises from deployment and containment, reallocating economic resources toward secure deployment practices, monitoring, and rapid patching/response can yield high returns compared with attempting immediate parity on training-scale expenditure.
Summary recommendation distilled for policymakers and economic planners: explicitly price in the geopolitical risk of frontier-model dependence; pursue pragmatic mixes of negotiated access and inference-control contracts; invest in open-weight hedges and regional pooling where feasible; prioritize talent and containment/deployment investments as high-return levers to manage cyber-risk without the prohibitive cost of full sovereign frontier training.
Assessment
Claims (12)
| Claim | Direction | Outcome | Confidence & Evidence | Details |
|---|---|---|---|---|
| In the GTG-1002 cyber-espionage campaign, the AI system performed an estimated 80–90% of the tactical work across roughly 30 targets, including reconnaissance, exploitation, credential harvesting, lateral movement, and data collection. Task Allocation | positive | Share of cyber-espionage tactical work delegated to an AI system |
Reading fidelity
high
Study strength
medium
|
n=30
80 to 90% of tactical work
|
| The best public models progressed from making almost no progress on a realistic simulated enterprise cyberattack to completing more than half of it over an 18-month period. Automation Exposure | positive | Completion of simulated enterprise cyberattack steps |
Reading fidelity
high
Study strength
medium
|
more than half of the simulated attack
|
| The best early-2026 model completed nearly six times more attack steps than its counterpart 18 months earlier, with a full attempt costing approximately £65. Automation Exposure | positive | Number of simulated cyberattack steps completed and cost per full attempt |
Reading fidelity
high
Study strength
medium
|
nearly six times more attack steps; about £65 per full attempt
|
| No public model completed the NCSC's simulated enterprise cyberattack scenario end to end, and performance fell sharply on reverse engineering and tasks requiring management of multiple processes. Automation Exposure | null_result | End-to-end completion and performance across cyberattack phases |
Reading fidelity
high
Study strength
medium
|
not reported
|
| On the ExploitBench benchmark, the open-weight Kimi K3 model scored 32%, compared with 24% for the previous most capable open-weight model, but it remained substantially behind closed frontier models. Automation Exposure | mixed | End-to-end exploit-development benchmark performance |
Reading fidelity
high
Study strength
medium
|
n=41
32% versus 24%
|
| In a 32-step simulated corporate-network task, Kimi K3 reached step 17 on average and completed the scenario once in ten attempts, compared with step 28.5 and six or seven successful attempts in ten for the strongest closed models. Automation Exposure | mixed | Progress and success rate in a simulated corporate-network intrusion |
Reading fidelity
high
Study strength
medium
|
n=32
step 17 versus 28.5 on average; 1/10 versus 6–7/10 successful attempts
|
| Basic security failures still account for most successful intrusions, and current AI systems primarily scale the exploitation of existing weaknesses rather than creating access where cyber hygiene is sound. Ai Safety And Ethics | mixed | Sources and effectiveness of successful cyber intrusions |
Reading fidelity
high
Study strength
medium
|
not reported
|
| A substantial share of near-term AI-enabled cyber risk is a containment and deployment problem rather than a model-capability problem. Ai Safety And Ethics | negative | Near-term risk of AI-enabled cyber incidents |
Reading fidelity
high
Study strength
medium
|
not reported
|
| AI has enabled defensive cybersecurity systems to reduce incident-investigation times from hours to minutes, according to managed detection providers. Task Completion Time | positive | Time required for cybersecurity incident investigation |
Reading fidelity
high
Study strength
low
|
from hours to minutes
|
| Organizations making extensive use of security AI and automation experience average breach-cost savings of more than $2 million per incident. Organizational Efficiency | positive | Average financial cost of a cybersecurity breach |
Reading fidelity
high
Study strength
medium
|
above two million dollars per incident
|
| The cost of training leading-edge AI models is growing by a factor of two to three and a half each year, while the United States and China control approximately 90% of the computing power used to develop and run frontier systems. Market Structure | negative | Concentration and cost of frontier-AI compute capability |
Reading fidelity
high
Study strength
medium
|
2 to 3.5 times annual cost growth; approximately 90% of frontier-system computing power
|
| Frontier-model access can be withdrawn by the producing state within days, without notice and without regard to alliances, creating a national-security exposure for dependent states if such models become important inputs to cyber defence. Governance And Regulation | negative | Reliability and continuity of national access to frontier AI systems |
Reading fidelity
high
Study strength
medium
|
withdrawn in days
|