All topicsSTATE OF AI REPORT.

Washington is asserting control over frontier AI

Superintelligence has made it from a meme in AI circles into a White House executive order. As governments prepare for more capable systems, they are asserting control over who can access them and how they can be used, despite not owning equity or board control over these companies.

Questions in this section

Can the US restrict access to frontier AI models abroad?When was access to Fable 5 and Mythos 5 restored?Does a domestic data center confer AI sovereignty?Are sovereign AI pledges the same as delivered capacity?Do public compute allocations show how much compute was used?Why do the sovereign AI budget totals differ?How is AI being used in military operations?Can data centers become military targets?
Superintelligence moves from technology-industry ambition into a White House executive order.
Superintelligence moves from technology-industry ambition into a White House executive order.

In June, a US export directive barred foreign nationals from Fable 5 and Mythos 5, including those inside the US. Anthropic suspended both models for all users to comply, then announced restored access on Jul 1, 2026. For the rest of the world, this made the dependency concrete: Washington could withdraw access to critical technology with immediate effect.

Anthropic's Pentagon dispute brings this question into the use of AI itself. The company refused to remove restrictions on mass domestic surveillance and fully autonomous weapons, while the department sought access for any lawful use. Developers and governments are contesting who sets the boundaries.

A domestic data center does not confer control over its models

Selected sovereign AI programs in the report pledge about $138B toward compute access, infrastructure, and domestic development. Some are still in procurement, while others have begun delivering capacity. NVIDIA separately reported more than $30B in sovereign AI revenue in fiscal 2026. The CNAS Sovereign AI Index shows countries returning to the same foreign vendor (NVIDIA) to build domestic capacity.

Selected sovereign AI program pledges total about $138 billion, with delivery at very different stages.
Selected sovereign AI program pledges total about $138 billion, with delivery at very different stages.

As I argued in Europe cannot rent its way to AI sovereignty, a domestic data center does not confer control over the models inside it. A credible alternative requires sustained spending on researchers, compute, energy, and successive model generations. Europe's practical goal should be enough domestic capability to keep essential work running through a cutoff and negotiate with a bargaining chip in hand, which could be powered land and data center capacity. That is, if its energy prices and planning permission challenges can come down to be competitive…

Sovereign AI programs pursue different kinds of control

CNAS tracks 184 government-backed AI projects in 67 countries outside the US and China, with disclosed budgets of about $84B. The report’s separate selection of sovereign program pledges totals about $138B. These compilations cover different projects and country sets, so the totals cannot be treated as rival estimates of the same spending.

Korea illustrates how a strategy can extend beyond a data center. Its plan connects domestic models, engineering skills, compute, procurement, and consumer access. Government contracts and adoption vouchers can create demand for local providers while model development trains the people needed to operate and improve the systems. The eventual test is whether these components produce usable domestic capability.

Further reading: slide 169, slide 170, slide 172.

Compute access programs need measures of actual use

The EU, UK, and India report different stages of delivery. Europe plans up to seven gigafactories targeting around mid-2028. The UK’s initial SOV/AI cohort received over three million GPU-hours of allocations, against 67 million requested. India reported 9.318 million approved GPU-hours across 237 projects in its August update.

None of the three programs reported measured usage in the report’s comparison. A planned site, an application for compute, and an approved allocation each answer a different question. To assess whether public spending is helping developers, the next evidence should show hours delivered, who used them, and what that access enabled.

Further reading: slide 173.

Compute programs report planned capacity and allocations, with usage still unreported.
Compute programs report planned capacity and allocations, with usage still unreported. Report slide 173.

Electricity costs shape what countries can sustain

A country can secure chips and still struggle to operate them competitively. At a site drawing a continuous gigawatt, an additional one cent per kilowatt-hour costs $87.6M a year. The report’s retail electricity comparisons show large differences across countries, although they cover different periods and tax treatments and are not matched data-center contracts.

China’s industrial policy also links power prices to domestic chips. The FT reported enhanced discounts in some provinces for facilities using Chinese accelerators. That can change the economic trade-off when local chips consume more energy. Access to electricity, the conditions attached to it, and the ability to build a local customer base all affect how much independence a compute investment can buy.

Further reading: slide 177, slide 178.

Regulation is advancing through several different institutions

The report describes US states continuing to legislate while Washington seeks national rules. New York’s RAISE Act focuses on frontier-lab safety protocols and incident reporting. Colorado’s approach addresses consequential uses such as hiring and lending. A company can face obligations relating to both the model it builds and the decisions made with it.

California’s new assessor and auditor laws add another layer: standards for recognizing independent assessors and, later, registration and disclosure requirements for covered compliance auditors. They do not require every developer to commission an audit. In Europe, the report distinguishes delayed high-risk-system deadlines from model enforcement and transparency provisions that went ahead. These developments make the details of scope, evidence, and enforcement as consequential as the announcement of an AI law.

Further reading: slide 183, slide 184, slide 185.

Military deployment is testing who controls AI use

The report documents frontier AI entering live US military operations. Axios reported Claude’s use during the raid that captured Nicolás Maduro, although its precise role was not confirmed. The Pentagon described Grok-enabled Maven workflows helping US forces deploy more than 2,000 munitions at 2,000 targets within 96 hours. A separate campaign-level figure of 13,000 targets over 38 days overlaps with that account and should not be added to it.

Human oversight still depends on the information reaching the decision-maker. CNN reported that false AI-generated intelligence linked a Chinese ship’s cargo to nuclear weapons. Troops prepared to board before officials caught the error. That account illustrates how an incorrect model output can influence operational planning even when people retain authority.

Anthropic’s dispute with the US government concerned the supplier’s ability to prohibit domestic mass surveillance and fully autonomous lethal weapons. The report describes procurement exclusions and litigation following those objections. The broader question is who can impose and enforce limits after a government has adopted a privately supplied model.

Further reading: slide 166, slide 167.

Cloud facilities have become physical targets in war

AI infrastructure is exposed to military conflict as well as restrictions on chips and model access. The report records Iranian drone strikes on two AWS facilities in the UAE on March 1 and damage to AWS infrastructure from a nearby strike in Bahrain. Iran subsequently identified technology facilities and organizations as targets and threatened Stargate UAE.

The evidence differs across incidents. A further attack in Bahrain was claimed in July, with damage observed in satellite imagery but no confirmation from AWS. The confirmed March damage is enough to show that placing cloud infrastructure in a country creates exposure to its physical security environment. Sovereign-compute plans and business continuity arrangements need to account for that exposure alongside access to power and chips.

Further reading: slide 168.

Evidence you can use

The model-access restrictions and restoration

2026-06-12 to 2026-07-01

The model-access restrictions and restoration
DateEvent
2026-06-12SourceExport controls applied. Anthropic suspended both models for all users.
2026-06-30SourceAnthropic said the export controls had been lifted.
2026-07-01SourceAnthropic updated its notice to say access was restored.

Timeline based on Anthropic’s account. Restored access does not imply identical availability across every product, cloud, or customer. The company described separate arrangements for Mythos and its Glasswing partners.

Sources: Anthropic: redeploying Fable 5.

Frequently asked questions

Answers drawn from the report and the sources below.

Why do the sovereign AI budget totals differ?

CNAS’s roughly $84B covers disclosed budgets for its tracked projects outside the US and China. The report’s roughly $138B is a separate selection of program pledges. The project and country coverage differ, and neither total represents verified spending.

Source: State of AI Report 2026, slide 169: Outside the US and China, 67 countries have sovereign AI projects · State of AI Report 2026, slide 170: Selected sovereign AI program pledges total about $138B.

Sources and dates

2026 report snapshot. Preview revised 2026-10-07. Individual data periods and source checks are listed below. This is not a claim that every source was updated on that date.

  1. Anthropic: statement on the export directiveJune 2026. Primary source checked 2026-10-07.
  2. Anthropic: redeploying Fable 5Updated 2026-07-01. Primary source checked 2026-10-07.
  3. Nathan Benaich: Europe cannot rent its way to AI sovereignty2026. Author analysis.
  4. State of AI Report 2026, slide 166: Anthropic vs. US Government: who defines the limits of AI usage in defense2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  5. State of AI Report 2026, slide 167: Frontier AI goes live in US military operations2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  6. State of AI Report 2026, slide 168: Iran turned US commercial cloud infrastructure into an explicit military target set2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  7. State of AI Report 2026, slide 169: Outside the US and China, 67 countries have sovereign AI projects2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  8. State of AI Report 2026, slide 170: Selected sovereign AI program pledges total about $138B2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  9. State of AI Report 2026, slide 172: Korea is going big on funding domestic AI and building a market for it2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  10. State of AI Report 2026, slide 173: Governments are funding compute access for domestic AI developers2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  11. State of AI Report 2026, slide 177: Europe’s data center ambition is hampered by significantly more expensive energy costs2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  12. State of AI Report 2026, slide 178: China uses cheap power to favor domestic AI chips2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  13. State of AI Report 2026, slide 183: US states keep regulating AI despite Trump’s push for national rules2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  14. State of AI Report 2026, slide 184: California builds independent oversight of AI safety claims2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  15. State of AI Report 2026, slide 185: Brussels delays high-risk EU AI Act rules by up to 16 months2026 report snapshot. Read against the report PDF on 2026-10-07. Study-specific limits retained.
  16. State of AI Report 20262026 report snapshot. Report PDF. See individual slide references for the expanded analysis.
  17. CNAS: Sovereign AI Index2026 report snapshot. Retained from the launch essay.
  18. executive order - www.whitehouse.govOriginal source link retained from the launch essay.
  19. restrictions - www.anthropic.comOriginal source link retained from the launch essay.
  20. $30B - s201.q4cdn.comOriginal source link retained from the launch essay.

Cite this page

Benaich, Nathan. “Washington is asserting control over frontier AI.” State of AI Report 2026. Published 2026-10-08.