
In June, a US export directive barred foreign nationals from Fable 5 and Mythos 5, including those inside the US. Anthropic suspended both models for all users to comply, then announced restored access on Jul 1, 2026. For the rest of the world, this made the dependency concrete: Washington could withdraw access to critical technology with immediate effect.
Anthropic's Pentagon dispute brings this question into the use of AI itself. The company refused to remove restrictions on mass domestic surveillance and fully autonomous weapons, while the department sought access for any lawful use. Developers and governments are contesting who sets the boundaries.
A domestic data center does not confer control over its models
Selected sovereign AI programs in the report pledge about $138B toward compute access, infrastructure, and domestic development. Some are still in procurement, while others have begun delivering capacity. NVIDIA separately reported more than $30B in sovereign AI revenue in fiscal 2026. The CNAS Sovereign AI Index shows countries returning to the same foreign vendor (NVIDIA) to build domestic capacity.

As I argued in Europe cannot rent its way to AI sovereignty, a domestic data center does not confer control over the models inside it. A credible alternative requires sustained spending on researchers, compute, energy, and successive model generations. Europe's practical goal should be enough domestic capability to keep essential work running through a cutoff and negotiate with a bargaining chip in hand, which could be powered land and data center capacity. That is, if its energy prices and planning permission challenges can come down to be competitive…
Sovereign AI programs pursue different kinds of control
CNAS tracks 184 government-backed AI projects in 67 countries outside the US and China, with disclosed budgets of about $84B. The report’s separate selection of sovereign program pledges totals about $138B. These compilations cover different projects and country sets, so the totals cannot be treated as rival estimates of the same spending.
Korea illustrates how a strategy can extend beyond a data center. Its plan connects domestic models, engineering skills, compute, procurement, and consumer access. Government contracts and adoption vouchers can create demand for local providers while model development trains the people needed to operate and improve the systems. The eventual test is whether these components produce usable domestic capability.
Further reading: slide 169, slide 170, slide 172.
Compute access programs need measures of actual use
The EU, UK, and India report different stages of delivery. Europe plans up to seven gigafactories targeting around mid-2028. The UK’s initial SOV/AI cohort received over three million GPU-hours of allocations, against 67 million requested. India reported 9.318 million approved GPU-hours across 237 projects in its August update.
None of the three programs reported measured usage in the report’s comparison. A planned site, an application for compute, and an approved allocation each answer a different question. To assess whether public spending is helping developers, the next evidence should show hours delivered, who used them, and what that access enabled.
Further reading: slide 173.

Electricity costs shape what countries can sustain
A country can secure chips and still struggle to operate them competitively. At a site drawing a continuous gigawatt, an additional one cent per kilowatt-hour costs $87.6M a year. The report’s retail electricity comparisons show large differences across countries, although they cover different periods and tax treatments and are not matched data-center contracts.
China’s industrial policy also links power prices to domestic chips. The FT reported enhanced discounts in some provinces for facilities using Chinese accelerators. That can change the economic trade-off when local chips consume more energy. Access to electricity, the conditions attached to it, and the ability to build a local customer base all affect how much independence a compute investment can buy.
Further reading: slide 177, slide 178.
Regulation is advancing through several different institutions
The report describes US states continuing to legislate while Washington seeks national rules. New York’s RAISE Act focuses on frontier-lab safety protocols and incident reporting. Colorado’s approach addresses consequential uses such as hiring and lending. A company can face obligations relating to both the model it builds and the decisions made with it.
California’s new assessor and auditor laws add another layer: standards for recognizing independent assessors and, later, registration and disclosure requirements for covered compliance auditors. They do not require every developer to commission an audit. In Europe, the report distinguishes delayed high-risk-system deadlines from model enforcement and transparency provisions that went ahead. These developments make the details of scope, evidence, and enforcement as consequential as the announcement of an AI law.
Further reading: slide 183, slide 184, slide 185.
Military deployment is testing who controls AI use
The report documents frontier AI entering live US military operations. Axios reported Claude’s use during the raid that captured Nicolás Maduro, although its precise role was not confirmed. The Pentagon described Grok-enabled Maven workflows helping US forces deploy more than 2,000 munitions at 2,000 targets within 96 hours. A separate campaign-level figure of 13,000 targets over 38 days overlaps with that account and should not be added to it.
Human oversight still depends on the information reaching the decision-maker. CNN reported that false AI-generated intelligence linked a Chinese ship’s cargo to nuclear weapons. Troops prepared to board before officials caught the error. That account illustrates how an incorrect model output can influence operational planning even when people retain authority.
Anthropic’s dispute with the US government concerned the supplier’s ability to prohibit domestic mass surveillance and fully autonomous lethal weapons. The report describes procurement exclusions and litigation following those objections. The broader question is who can impose and enforce limits after a government has adopted a privately supplied model.
Further reading: slide 166, slide 167.
Cloud facilities have become physical targets in war
AI infrastructure is exposed to military conflict as well as restrictions on chips and model access. The report records Iranian drone strikes on two AWS facilities in the UAE on March 1 and damage to AWS infrastructure from a nearby strike in Bahrain. Iran subsequently identified technology facilities and organizations as targets and threatened Stargate UAE.
The evidence differs across incidents. A further attack in Bahrain was claimed in July, with damage observed in satellite imagery but no confirmation from AWS. The confirmed March damage is enough to show that placing cloud infrastructure in a country creates exposure to its physical security environment. Sovereign-compute plans and business continuity arrangements need to account for that exposure alongside access to power and chips.
Further reading: slide 168.