Sovereign by necessity? Frontier AI export controls, cyber security, and the limits of national AI capability
Alan Woodward, Andrew Rogoyski
University of Surrey
cs.AI, cs.CR
Submitted: 2026-08-13
Updated: 2026-08-14
Comments: 42 Pages
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 75/100
The gist: The most capable artificial intelligence (AI) frontier models are produced by a small number of firms based in two nation states.
Terminology
Summary
The most capable artificial intelligence (AI) frontier models are produced by a small number of firms based in two nation states. The governments of those states have shown that they have both the legal power and the political will to decide which other countries may use these systems. In June 2026 the United States directed a leading AI developer to apply for licences to release its most advanced models to any foreign person, including foreign nationals based in the US. Partly due to the impracticality of this restriction, the models in question were withdrawn worldwide at short notice. This happened only months after the first documented case of a largely autonomous, AI-run cyber espionage campaign, and amid growing evidence that frontier models change the economics of both cyber-attack and cyber defence. This article examines how these two developments interact. It also considers some of the unusual market dynamics that currently drive the development of large AI systems. It argues that access to frontier AI is becoming part of national cyber defence, that this access can now be revoked, and that the obvious remedy, building sovereign AI capability, is only partly feasible for all but a handful of states. Drawing on recent evidence on the costs of training an AI model, the concentration of computing power and the support from national AI programmes, the article asks what sovereignty can realistically mean for small and middle powers, even large powers. It proposes a layered strategy: negotiated access guarantees, sovereignty at the level of inference, hedging with open-weight/source models, pooled regional capability, sustained development of talent, and continued investment in basic cyber resilience. It also finds that the open-weight hedge is at once more capable and more politically exposed than is commonly assumed, and that a substantial share of near-term risk lies in how capable models are deployed and contained rather than in their apparent performance.
Improvements for AI systems
Improvements to AI Systems:
-
Revocation-Aware Deployment Architecture: Design AI systems with built-in mechanisms to detect and gracefully handle sudden loss of model access (e.g., via licensing revocation). This includes local caching of critical inference logic, automatic fallback to open-weight models, and pre-trained
survival modes
that maintain essential cyber-defence functions without frontier-model dependencies. -
Sovereign Inference Layers: Develop AI systems that separate training (centralized, high-cost) from inference (deployable locally). Improved systems can run fully on domestic hardware with encrypted model weights, enabling nations to retain operational control even if training providers are cut off.
-
Open-Weight Hedging with Political Risk Scoring: Create AI systems that continuously evaluate the political exposure of their underlying open-weight models (e.g., tracking export-control changes, licensing terms, and upstream dependencies). The system can autonomously switch to alternative open-weight models or adjust deployment strategies based on real-time geopolitical risk assessments.
-
Autonomous Cyber-Defence with Degraded-Mode Operation: Train AI systems to operate effectively under constrained compute or model-quality conditions. This includes reinforcement learning for cyber-defence that explicitly optimizes for scenarios where the AI must rely on smaller, local models or rule-based fallbacks during a revocation event.
-
Regional Pooled Intelligence: Build AI systems that can federate across multiple sovereign nodes (e.g., a coalition of small states) to share inference loads and training updates without centralizing control. Improved systems use privacy-preserving techniques (e.g., federated learning, secure aggregation) to maintain collective cyber-defence capability while respecting national boundaries.
-
Deployment-Containment Focus: Shift AI system design from maximizing raw performance to optimizing for safe, contained deployment. This includes built-in
guardrails
that limit autonomous actions during cyber operations, human-in-the-loop verification for high-impact actions, and audit trails that track model decisions to prevent escalation or unintended consequences.
What the Improved AI System Can Do:
-
Maintain critical cyber-defence operations even if the primary frontier model is withdrawn globally, by seamlessly switching to local, open-weight, or pooled regional models without service interruption.
-
Predict and pre-empt access revocations by monitoring geopolitical signals (e.g., policy changes, export-control announcements) and automatically reconfiguring its own deployment to minimize disruption.
-
Operate with sovereign integrity—a nation can run the AI entirely on its own infrastructure, with no external dependency for inference, while still benefiting from advanced capabilities.
-
Collaborate across borders in a secure, federated manner, allowing smaller states to pool compute and talent without sacrificing national control or data privacy.
-
Limit autonomous cyber-attack capabilities by design, focusing instead on defensive containment, rapid threat detection, and resilient response under degraded conditions.
-
Provide transparent risk assessments for every model version, including its political exposure, so operators can make informed decisions about when to rely on frontier vs. open-weight systems.
Abstract
A small number of firms based in two states produce the most capable frontier AI models. The governments of those states have shown both the legal power and the political will to decide which other countries may use these systems. In June 2026 the United States required a leading developer to obtain licences before releasing its most advanced models to any foreign person, including foreign nationals resident in the United States. The affected models were withdrawn worldwide at short notice, partly because the restriction proved impractical to administer. This followed within months of the first documented case of a largely autonomous, AI-run cyber espionage campaign, and coincided with mounting evidence that frontier models alter the economics of both cyber attack and cyber defence. This article examines how these two developments interact, and situates them within the unusual market dynamics now driving large-scale AI development. It argues that access to frontier AI is becoming part of national cyber defence, that such access can be revoked, and that the obvious remedy of sovereign capability remains only partly feasible for all but a handful of states. Drawing on evidence about training costs, the concentration of computing power and the support offered by national AI programmes, it asks what sovereignty can realistically mean for small and middle powers, and for large powers as well. The article proposes a layered strategy: negotiated access guarantees, sovereignty at the level of inference, hedging with open-weight models, pooled regional capability, sustained talent development and continued investment in basic cyber resilience. The open-weight hedge proves at once more capable and more politically exposed than is commonly assumed. Much of the near-term risk lies in how capable models are deployed and contained rather than in their apparent performance.
Sources
- The rising costs of training frontier AI models
- Uplifted Attackers, Human Defenders: The Cyber Offense-Defense Balance for Trailing-Edge Organizations
- Mitigating Cyber Risk in the Age of Open-Weight LLMs: Policy Gaps and Technical Realities
- Algorithmic progress in language models
- International AI Safety Report 2025: First Key Update: Capabilities and Risk Implications
Related papers
- MAVEN-T: Reinforced Heterogeneous Distillation for Real-Time Multi-Agent Trajectory Prediction
- Model Discovery Agent: LLM-assisted Bayesian experiment design for data-efficient discovery of mechanistic world models
- The Clinician's Veto: Navigating Trust, Liability, and Uncertainty in Autonomous AI Prescribing
- MindHelper: Closed-Loop Embodied Mental-State Reasoning for Precision Intervention
- Incumbent Advantage: Brand Bias and Cognitive Manipulation Dynamics in LLM Recommendation Systems
- VSAL: A Vision Solver with Adaptive Layouts for Graph Property Detection