RSS Amplifier

Anticipating the Unintended · Jul 5, 2026

#351 How to Get to 'Sovereign AI'?

0
Sign in to vote or save

Pranay Kotasthane · Anticipating the Unintended

Insights on current policy issues in India
—RSJ

A few weeks ago, users outside the United States who tried to access Anthropic’s Claude Fable 5 and Mythos 5 models were greeted with an unusual message: the models were unavailable. The restrictions did not last long and were subsequently lifted. Most users will probably not remember the episode. Governments and companies, however, should.

The immediate issue was a national security concern in Washington. The larger issue was that a frontier AI model, available globally one day, became unavailable globally the next because the US government had decided that access should be restricted. Whether that decision was justified or not is almost beside the point. What matters is that the episode demonstrated that such a thing is possible.

The world has spent the last few years discussing artificial intelligence largely in terms of capability and competition. Which company has the best model? Which country is ahead? Who will capture the economic value? The Anthropic episode suggests that there is another question that deserves attention: what happens if critical parts of an economy begin to depend on systems whose availability ultimately rests on policy decisions taken in another country?

For much of the past three decades, most countries would not have worried too much about this question. They accepted dependence on American technology because they believed they understood the bargain they were entering into. America built and maintained much of the infrastructure of the modern world. The internet was American, so was the GPS. The dominant software platforms were American. Cloud computing was overwhelmingly American. The world’s financial plumbing sat on American foundations. Countries understood that these arrangements created asymmetries, but they accepted those asymmetries because the provider was viewed as reliable and the rules of the game appeared stable.

This arrangement was never entirely altruistic. American companies and investors profited enormously from their position at the centre of the global economy. Yet for most countries, the bargain worked. That confidence has weakened.

The change did not begin with Donald Trump, although his presidency accelerated it. Export controls have expanded, sanctions have become more frequent, tariffs are now instruments of coercion and alliances are being used to settle scores. The message received by many countries was that American policy had become less predictable and that access to American technology could no longer be regarded as unconditional.

This matters because technology, especially AI, has ceased to be merely technology. It has become infrastructure and a matter of sovereignty. Infrastructure creates dependencies, and dependencies create leverage.

Artificial intelligence sharpens this problem because it is not another software application. It is becoming a layer that will eventually sit across almost every activity in the economy. Governments will use it to process information and administer services. Financial institutions will use it to allocate capital and manage risk. Manufacturers will use it to design products and optimise production. Scientific research will increasingly depend upon it. A large amount of routine cognitive work will eventually be mediated through AI systems. Once a technology acquires this character, access to it ceases to be merely a commercial issue.

We have already seen how, in the last few years, countries dependent on foreign energy and semiconductors can be pressured. Countries relying on foreign intelligence infrastructure can be held to ransom in ways that are difficult to even specify today. The issue is not whether the United States intends to use such leverage. Intentions change with administrations and with circumstances. The issue is that the capability exists.

This explains why the debate around AI sovereignty has become more serious in recent months. Sovereignty in this context does not mean self-sufficiency or digital nationalism. It means preserving a degree of choice and control over systems that are becoming systemically important. A country that cannot function if access to a foreign AI model is interrupted is not sovereign in any meaningful sense in that domain. It has outsourced part of its cognitive infrastructure to another country and to corporations that ultimately remain subject to that country’s laws and political priorities.

France recently decided to replace Palantir within parts of its intelligence apparatus, with French officials arguing that the country could not depend on companies capable of “turning off the tap”. Germany has moved in a similar direction and Spain has discouraged state-controlled firms from entering into new contracts with Palantir. Even in Britain, where reliance on American technology has traditionally attracted little political resistance, there is increasing scrutiny of Palantir’s role in public institutions.

The irony is that Palantir itself has now become one of the loudest voices arguing for AI sovereignty. Its recent narrative emphasises the importance of retaining data, controlling model weights and preserving institutional ownership of knowledge. The argument is not entirely disinterested. The company also sells products designed to operate in sovereign environments and has recently aligned itself with open-weight models and sovereign deployments. Companies often detect shifts in incentives before policymakers do because their commercial interests force them to.

The implications extend well beyond Palantir and even beyond artificial intelligence.

A significant portion of the valuation of several American technology companies rests on the assumption that the rest of the world will continue to build on American platforms and accept the resulting dependencies. SpaceX is perhaps the most obvious example. The investment case around Starlink assumes that governments around the world will permit a privately controlled American company to become an essential part of their communications infrastructure.

That assumption no longer looks as safe as it once did.

If governments have become uncomfortable relying on a foreign company merely to analyse their data, they may become equally uncomfortable relying on a foreign company for communications, navigation or artificial intelligence. They may still conclude that they have little choice. But they will also seek alternatives and diversify dependencies wherever possible.

The economics of artificial intelligence are changing at the same time.

For the last few years, investors have operated with two assumptions. The first is that proprietary frontier models will capture extraordinary economic rents because they possess unique capabilities that everyone will have to use. The second is that the rest of the world will continue to build its digital future on American technological foundations. Both assumptions are under scrutiny or will be soon.

Increasingly capable open-weight models are now available at a fraction of the cost of the leading proprietary systems (almost 1/20th of token cost) and, for many applications, they are becoming good enough. The performance gap remains, but it is no longer large enough to make questions of cost, control and sovereignty irrelevant. A government or company looking at this landscape is likely to ask a straightforward question. If an open model offers most of the capability at a much lower cost and allows greater control over data, deployment and weights, why should critical systems be built on proprietary platforms that may one day become subject to export restrictions or political conditions?

The answer cannot simply be that the proprietary model performs better.

The United States also faces a strategic dilemma. It sees artificial intelligence as a foundational technology and wants to preserve its lead. But every restriction on access creates incentives for others to reduce their dependence and accelerate the development of alternatives. This has happened before. Restrictions on advanced semiconductors encouraged China to invest heavily in its own ecosystem and accelerated the emergence of alternatives to technologies that once appeared unassailable. Similar dynamics may now begin to play out in artificial intelligence.

The challenge for India is more acute.

India is behind the frontier in foundational AI models. It cannot simply wish away that reality. If it wants to deploy artificial intelligence rapidly across government and industry, it will have to rely on foreign systems for the foreseeable future. The best proprietary models are American. The best open-weight models increasingly come from China. Neither option is comfortable.

Dependence on American proprietary models creates strategic exposure to a country that has shown a willingness to use technological dominance as an instrument of policy and whose politics have become less predictable than they once were. Dependence on Chinese models raises a different set of questions around trust, transparency and security. Whether open-weight Chinese models are genuinely open in every relevant sense is something many governments will continue to examine carefully.

India’s problem is therefore that none of the available choices is optimal. The policy challenge is not to eliminate dependence altogether, which may be impossible, but to ensure that no single dependency becomes so deep that it begins to constrain future choices. The objective cannot be complete technological self-sufficiency. Very few countries have the capital, talent and scale to replicate the entire AI stack. But neither can the objective be to maximise short-term access to frontier capabilities while ignoring the long-term consequences of dependence.

Strategic autonomy in the age of artificial intelligence means preserving optionality. It means developing domestic capabilities where possible, building indigenous compute, encouraging open ecosystems where practical, diversifying suppliers and ensuring that critical public infrastructure does not become irrevocably tied to a single foreign provider. It also means not to fall into a trap that India is getting into increasingly, that of “one nation - one X”. This mindset has become infectious in policy circles. But a single platform in this context now looks like a worse idea than before. For example, NPCI, the nodal agency that runs the UPI rail as a monopoly, can be susceptible to cyber attacks, dependence on foreign cloud providers and AI platforms that can be grounded in future by actors sitting outside India on purely geopolitical grounds. The more we opt for such centralisation, the greater our risks.

Until recently, AI sovereignty was largely a talking point for European policymakers and technology strategists. The events of the last few months have made it a practical question for governments and companies everywhere. Countries have worried about dependence on foreign oil, foreign capital and foreign supply chains. They may soon have to think about dependence on foreign intelligence infrastructure in much the same way.

The Anthropic episode will probably be forgotten by most users. Policymakers should not forget it quite so quickly. It highlighted something that had remained largely theoretical until now. Access to advanced AI is not merely a commercial relationship between a provider and a customer. It also creates a strategic relationship between countries. As artificial intelligence becomes embedded in governments, businesses and public infrastructure, that relationship will receive far more scrutiny than it has so far. India will have to act soon on building domestic capabilities and diversifying its choices to avoid being caught in a cleft.

— Pranay Kotasthane

I want to add another nuance to RSJ’s excellent analysis. He is right that the framing of AI as infrastructure is no longer theoretical. But I think the current debate makes a mistake by treating all foreign AI models as creating the same kind of dependency. The sovereignty risk posed by proprietary API-based models and open-weight models is fundamentally different. Let me explain.

When a government ministry or a bank builds a workflow on Claude or GPT, every query travels to a server in the US, processed by a company subject to US jurisdiction. The “tap” that RSJ describes—the one that can be turned off—matters because the dependency is continuous. If an export control or sanctions decision were to remove access tomorrow, the workflow would break.

Now consider the alternative. An Indian financial services firm downloads the weights of an open model—say DeepSeek or GLM—and runs inference on GPUs rented from data centre firms in India. What exactly is the sovereignty risk here? The model weights are a static file of parameters sitting on Indian hardware. The data never leaves Indian territory. The Chinese lab that created the model has no ongoing connection to the deployment, no API to revoke, and no kill switch to flip. In a narrow sense, this setup has better data sovereignty properties than using a foreign proprietary API.

This is the counterintuitive finding. From a data-flow perspective, running a Chinese open model on Indian infrastructure can be safer than sending queries to an American proprietary endpoint.

Part of the reason these Chinese models behave the way they do is how they were built. In June 2026, Anthropic accused Alibaba’s Qwen lab of operating roughly 25,000 fraudulent accounts and generating nearly 29 million conversations with Claude to extract its capabilities—something Anthropic called the largest known distillation attack to date. Earlier in the year, Anthropic had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax. OpenAI made parallel accusations about DeepSeek.

This matters for the sovereignty debate because the Chinese open-weight models are not entirely indigenous Chinese creations built from the ground up on Chinese data and Chinese design philosophies. They are, to a significant degree, compressed versions of American frontier models. The knowledge within them is substantially of Western origin.

A recent experiment by my colleague Bharath Reddy offers supporting evidence. He tested GLM 5.2 on politically sensitive questions—Tiananmen, Taiwan, Chinese leadership—through two pathways: the native Chinese chat interface and via OpenRouter, a third-party inference provider. The native interface censored and deflected, whereas the same model on OpenRouter produced detailed, balanced, well-cited responses indistinguishable from those of a Western model.

If these models had been fully retrained on Chinese-curated data, one would expect at least some divergence in how sensitive political topics are handled. That the uncensored responses closely mirror Western models is consistent with the distillation evidence. The censorship isn’t in the weights; it’s a compliance layer for domestic Chinese regulation bolted on at the deployment stage.

Large Indian firms and regulators are wary of using these open-weight models because they suspect Chinese “backdoors”, even though there is no special backdoor in an open-weight model, which is just a set of billions of weights and biases (parameters). It cannot exfiltrate data. It has no network connection of its own. If inference runs on Indian GPUs in an Indian data centre, the data pipeline is entirely domestic. The Chinese lab is no more “in the loop” than the authors of a textbook are when someone reads their book in another country.

This highlights the perception and compliance risk China’s digital exports face, even when the technical risk is minimal. But it is worth being precise about what we’re worried about. The fear of “Chinese AI” in Indian boardrooms is often a category error: the risk of Chinese hardware (with potential physical backdoors) or Chinese equity (with potential political influence) is being mapped onto Chinese model weights, where the threat model is structurally different.

I don’t want to be glib about this. The security research community has identified concerns around sleeper agents and trojans in neural networks—models that behave normally on standard benchmarks but produce subtly compromised outputs under specific trigger conditions. But this risk is not specific to open-weight models.

China’s current willingness to let open-weight models flow freely is itself a signal. The Chinese government has a demonstrated pattern of restricting exports when materials become strategically important: gallium, germanium, antimony, and rare earth processing technologies were all freely exported until they weren’t. That open-weight AI models are still being exported without restriction tells us something about how strategically significant Beijing considers the current generation of models.

But models are becoming the primary intermediary through which people interact with information. Today, people use DeepSeek to write code or summarise documents. Tomorrow, they may use it as a primary source of cognition. When that happens, China faces an uncomfortable problem. Its own open models, built with Chinese talent and compute, will become the vehicle through which the world encounters balanced, often unflattering (from Beijing’s perspective) accounts of Tiananmen, Taiwan, Xinjiang, and the Great Leap Forward. Bharath’s experiment shows this is already what happens when deployment-layer censorship is absent.

The Chinese government invests enormous resources in domestic information control. But open-weight exports effectively punch a hole in that project by producing versions of Chinese AI that, once deployed abroad, deliver precisely the narratives that Beijing works to suppress. As long as models are mere tools, this is tolerable. The moment they become information intermediaries at scale, it becomes a strategic problem. A government that censors the domestic internet is unlikely to remain comfortable exporting AI models that undo that censorship for everyone else.

This leads me to a prediction. The most significant marker of exponential AI may not be US export controls on chips but the Chinese government’s stance on open-weight model exports. If these models become truly transformative—capable of meaningfully shaping how hundreds of millions of people understand the world—expect China to restrict their export. And unlike physical goods, model weights cannot be “unexported” once downloaded. Which means any restriction would apply only to future, more capable generations.

The implication for India is that the window of free access to capable open-weight models may not remain open indefinitely. This strengthens rather than weakens the case for building domestic inference infrastructure now. Indian firms should be investing in the capacity to download, fine-tune, and deploy open models while they are freely available, rather than assuming that availability will persist.

Since the risk profile of open models differs qualitatively from that of proprietary APIs, the policy response should also differ.

First, Indian firms should actively encourage the growth of domestic AI inference infrastructure. The ability to run any model on Indian hardware, without data leaving Indian territory, is a capability worth having. This is where RSJ’s concern about centralisation and “one nation, one X” is most relevant. India needs multiple inference providers, not a single national AI cloud.

Second, regulators should focus on the deployment layer—where data flows, who controls the compute, and what audit trails exist—rather than on the national origin of model weights. A blanket suspicion of cheap Chinese-origin open models is commercially costly. It denies Indian firms access to capable, low-cost models while doing nothing to address the sovereignty risk, which lies in proprietary API dependencies that create continuous exposure to foreign jurisdiction.

Third, there is a timing dimension to this. If China eventually restricts open model exports, India will want to have already built the institutional and infrastructural capacity to absorb whatever is available before the window closes. Fine-tuning capability, evaluation and red-teaming expertise, and domestic compute are all things that take months to build. Starting now is imperative.

Fourth, there is a residual vulnerability that open weights cannot solve. Every GPU that powers inference in India today—whether it is an A100, an H200, or an RTX 6000 — is designed by American firms that might be subject to American export controls. Open weights solve the model-access problem and the data-flow problem. They do not solve the compute supply chain problem. And the only short- to medium-term option available to India here is to be on reasonably good terms with the US by participating in initiatives like Pax Silica. I think that’s not difficult to manage. It doesn’t mean agreeing with the US on all issues, but to keep engaging them as India has done over the last year, despite major provocations.

The sovereignty debate should not treat AI as a monolith. The risks are layered, and the responses must be too. We need to recognise that not all foreign models create the same kind of dependency, and that the cheapest, most accessible models might, in the right deployment configuration, also be the most sovereign.

Reading and listening recommendations on public policy matters
  1. [Paper] The EU CHIPDIPLO initiative has a good industry survey of geopolitical risks in the semiconductor domain over the next five years.

  2. [Essay] A terrific Aeon piece on the illegible benefits of AI.

  3. [Tracker] With the CG Semi's first assembly line beginning commercial production, 3 OSAT plants in India have now been marked operational on our semiconductor manufacturing tracker. Bonus: We added chip design centres too.

Read the original on publicpolicy.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.