For two decades, digital security has largely been discussed in the language of breaches, ransomware, espionage and software flaws. Those threats remain. Yet by mid-2026, an older infrastructure question is reasserting itself beneath the AI boom: who controls the physical and contractual foundations of computation, and what happens when states, hospitals, utilities, banks and logistics systems become dependent on a narrow set of providers, regions and model intermediaries.
This is not the familiar argument about headline-grabbing cyber attacks. It is a more prosaic and, for that reason, more serious concern. AI systems are often presented as software services that can be integrated, swapped or scaled at will. In practice they rely on dense supply chains of advanced chips, specialist networking equipment, cloud availability zones, power-intensive data centres, software tooling, proprietary model weights, safety layers and access policies. What appears flexible at the application layer can be rigid underneath.
The result is a new category of national exposure. States are not merely adopting AI tools; they are binding administrative capacity, emergency response, intelligence analysis and parts of critical industry to a stack whose failure modes are poorly understood in public policy. The security challenge is therefore no longer confined to defending systems from intrusion. It extends to governing dependence itself.
From cyber risk to infrastructure dependence
Traditional cybersecurity assumes that the core asset already exists and must be protected from compromise. Compute governance starts earlier. It asks whether the asset can be accessed at all, on what terms, from which jurisdiction, with what degree of redundancy and under whose technical or legal control. In a cloud-native AI economy, those are security questions, not procurement details.
Consider the distinction. A ministry using AI to process benefits claims may have excellent access controls, encryption and monitoring. Yet if its workflows rely on a single external model provider, hosted in a small number of overseas regions, using hardware subject to export restrictions or supply shocks, its resilience may still be weak. Security in this context includes continuity, substitutability and operational sovereignty.
That is why the conversation is beginning to shift in serious capitals. The debate is less about whether AI is strategically important; that point is settled. The harder issue is how to prevent intelligence, administration and critical services from becoming functionally dependent on a stack that is globally integrated, commercially concentrated and geopolitically exposed.
In the AI era, resilience begins several layers below the application: in chips, cloud regions, power, networking, identity and the legal terms that govern access to all of them.
The new chokepoints are not where most institutions are looking
Public institutions tend to map risk according to familiar organisational boundaries: software vendors, data protection compliance, incident response and sector-specific regulation. AI introduces chokepoints that cut across those categories. Compute scarcity is one. Access to advanced semiconductors remains highly concentrated and shaped by industrial policy, export controls and fabrication bottlenecks. Cloud concentration is another. A small number of firms operate the hyperscale infrastructure needed for training and serving advanced models at economically viable scale.
There are also less visible dependencies. Foundation models may be open in research posture but closed in deployment practice, requiring external APIs, moderated gateways or proprietary optimisation layers. Safety and governance tooling can itself become a dependency if only a few vendors can provide robust evaluation, red-teaming or secure orchestration. Even identity and billing systems matter. A suspension, sanctions issue or contractual dispute can impair access as effectively as a cyber incident.
Many boards and ministries still treat these matters as supplier management. That understates the problem. When a service becomes embedded in policing, customs, health triage or electricity balancing, dependency on upstream compute ceases to be a commercial inconvenience. It becomes a question of state continuity.
Why resilience is now a matter of compute geography
The strategic question is no longer simply who has the best model, but who can withstand the failure, withdrawal or manipulation of the systems that make models usable at scale.
Geography has returned to digital policy with unusual force. The cloud era never abolished location; it merely obscured it. AI reverses the illusion. Training runs cluster where energy, cooling, capital, advanced chips and network connectivity can be assembled at scale. Inference for critical services also gravitates to regions with strong latency, compliance and infrastructure characteristics. This has made the physical map of computation strategically salient again.
For Europe, the issue intersects with long-running concerns about digital sovereignty, competition and data governance. For the United States, it sits alongside industrial policy and strategic competition over semiconductors. For middle powers, the dilemma is sharper: they need access to frontier capability but often lack local compute depth, domestic cloud alternatives or bargaining power over model providers.
Compute geography affects more than self-sufficiency. It shapes who receives capacity during shortages, whose legal orders apply during disputes, and which populations bear the consequences of outages or degraded service. A state may nominally possess advanced digital tools while lacking practical control over where and how they run.
Public sector AI is creating concentrated operational risk
Governments tend to digitise unevenly. A few visible services modernise rapidly while procurement, identity systems and legacy databases lag. AI can accelerate this imbalance by adding a sophisticated decision layer atop brittle administrative foundations. The temptation is understandable: automation promises speed, cost control and analytical support. But when deployment outruns institutional redesign, AI can concentrate risk rather than reduce it.
The danger is not always model error in the abstract. It is the coupling of multiple public functions to shared external dependencies. If the same cloud region, model service or orchestration layer supports welfare processing, immigration triage, emergency communications and tax operations, a single technical or legal disruption can cascade across apparently separate domains. Few governments are organised to see that interdependence clearly.
Resilience therefore requires a shift in public-sector architecture. Agencies need to know not only which AI tools they use, but which compute, network and model pathways those tools rely on. They need realistic fallback modes, local degradation procedures and procurement terms that preserve data portability, audit access and migration options. This is a more exacting discipline than the first wave of AI experimentation encouraged.
Critical infrastructure is becoming an AI customer before it becomes an AI master
Electricity networks, ports, telecoms operators, water utilities and transport systems are increasingly purchasing AI-enabled capabilities for forecasting, maintenance, anomaly detection and customer operations. This is rational: such systems generate large volumes of operational data and often face chronic labour and efficiency pressures. But in many sectors the buyer understands the operational problem better than the model stack it is acquiring.
That asymmetry matters. Critical infrastructure operators may become dependent on managed AI services long before they develop in-house capacity to test, substitute or safely isolate them. In effect, they become customers of strategic infrastructure they do not fully govern. The risk is amplified where maintenance vendors, industrial software providers and cloud services are tightly integrated, making disentanglement expensive and slow.
Here the lesson from earlier cyber practice is useful but incomplete. Segmentation, redundancy and disaster recovery remain essential. Yet AI adds a layer of behavioural dependence. Operators may gradually lose human familiarity with edge cases as recommendations become embedded in routine operations. When a model service degrades, is withdrawn or behaves unexpectedly, the organisation can discover that it has outsourced not just processing power, but operational judgement.
The strategic question is no longer simply who has the best model, but who can withstand the failure, withdrawal or manipulation of the systems that make models usable at scale.
Regulation is advancing, but mostly above the waterline
The past few years have produced a significant body of AI governance: the EU AI Act, the NIST AI Risk Management Framework, the OECD AI Principles, UNESCO’s recommendation and secure development guidance from national cyber agencies. These instruments are valuable. They improve accountability, clarify obligations and establish a common language for risk.
In the AI era, resilience begins several layers below the application: in chips, cloud regions, power, networking, identity and the legal terms that govern access to all of them.
But most of this architecture sits above the deepest resilience issues. It addresses model risk, safety, transparency, human oversight and system development practices more directly than dependence on underlying compute and service concentration. That is not a criticism of the frameworks so much as a reminder of their scope. Regulatory maturity in AI does not automatically deliver strategic robustness in AI infrastructure.
The same is true of industrial policy. Measures such as the US CHIPS Act respond to a genuine vulnerability in semiconductor supply chains, but they do not by themselves solve the governance challenge facing institutions that consume AI as a service. Fabrication capacity, cloud power, export controls, software ecosystems and public procurement all interact. Security policy can no longer treat them as separate files.
What a compute resilience agenda would actually involve
Much discussion of sovereign capability drifts quickly towards the most maximalist interpretation: a nation must own everything from chips to models. For most countries that is unrealistic. The more practical agenda is resilience through layered control, diversified access and institutional clarity about failure modes.
A serious compute resilience agenda would include several elements.
- Dependency mapping: critical institutions should identify their upstream model, cloud, semiconductor and networking dependencies, including subcontracted services and geographic exposure.
- Portability by design: procurement and technical architecture should favour standards, data exportability and interfaces that allow migration between providers where feasible.
- Fallback operations: agencies and operators need tested degraded modes, not merely theoretical business continuity plans, for moments when AI services become unavailable or legally inaccessible.
- Regional redundancy: critical workloads should not rely on a single region or legal jurisdiction if continuity is essential.
- Independent assurance: evaluation, logging and incident review should not depend entirely on the same provider whose system is being assessed.
- Public-interest procurement: contracts should address audit rights, model update notice, continuity obligations and secure exit conditions.
None of this eliminates dependence. It does, however, turn hidden fragility into governable risk. That is a substantial improvement over the current pattern, in which institutions adopt AI tools faster than they can describe the infrastructure assumptions those tools embed.
The politics of continuity will become harder
As AI systems move from experimentation to administrative normality, service disruption will acquire a different political charge. Citizens may not care whether a decision-support system runs on one model family or another, but they will care if benefits are delayed, hospital scheduling fails, border processing slows or utility outages lengthen because upstream compute has become constrained. The politics of digital dependence are often dormant until continuity breaks.
What looks like software innovation from the surface often behaves like infrastructure concentration underneath.
This will place governments in an awkward position. They may want the efficiency gains and innovation tempo associated with globally integrated AI markets, while also needing domestic assurance that essential systems remain available during disputes, crises or supply shocks. Those objectives can be reconciled, but only with more explicit trade-offs than most political systems have yet articulated.
There is also a competition dimension. If a few states and firms accumulate outsized control over the infrastructure of advanced computation, access itself becomes a source of leverage. Smaller countries may find that their AI ambitions are limited less by talent or demand than by bargaining power over compute, cloud and model access. That would create a stratified digital order in which capability is mediated by infrastructure patronage.
Why boards should think like civil defence planners
Corporate leaders often approach AI through productivity, product improvement and cost management. In sectors tied to critical services or broad social dependence, that is too narrow. Boards should ask the kind of questions once associated with civil defence and operational continuity. Which functions must survive prolonged cloud disruption? Which model-linked workflows can revert to deterministic software or human review? Where do single points of contractual failure exist? How quickly can the organisation switch providers, regions or operating modes?
These are not anti-innovation questions. They are the conditions under which innovation becomes dependable. The more AI is woven into claims processing, fraud controls, industrial maintenance, customer authentication or market operations, the less acceptable it becomes to discover basic resilience gaps only during an incident. Security teams cannot carry this burden alone. It spans procurement, legal, operations, engineering and board governance.
The organisations best positioned for the next phase will be those that treat AI not as an isolated application domain but as a layer of strategic dependency. They will know which capabilities are mission-critical, which can fail gracefully and which must remain under tighter institutional control. That distinction is likely to matter more than raw experimentation volume.
The coming divide: AI-rich versus AI-resilient
Much commentary still sorts countries and firms into leaders and laggards according to model capability, research output or investment levels. By the end of the decade, a more useful distinction may be between the AI-rich and the AI-resilient. The former can access powerful systems in favourable conditions. The latter can continue to govern, operate and adapt when those conditions deteriorate.
This is an important conceptual shift. It suggests that resilience is not a secondary feature of digital strategy but one of its primary measures. A country with modest domestic model development but strong continuity planning, diversified procurement, robust public cloud governance and clear audit rights may be more secure than one with flashier AI deployments built atop brittle dependencies.
What looks like software innovation from the surface often behaves like infrastructure concentration underneath. That fact should reorder policy priorities. Security in the AI age will certainly involve defending systems against attack. But it will increasingly depend on whether societies understand, and can govern, the stack on which intelligent systems actually run.
A narrower but more realistic ambition for sovereignty
The language of sovereignty can invite overreach. Few states can or should aspire to full autarky across semiconductors, cloud and advanced models. The wiser ambition is narrower: ensure that essential public functions and critical sectors are not trapped by unexamined dependencies, and that failure at one layer does not produce national paralysis.
That requires more institutional patience than the current AI cycle rewards. It means investing in procurement competence, infrastructure literacy inside government, cross-sector stress testing and regional cooperation on standards and capacity. It may also require admitting that some digital conveniences are strategically expensive if they concentrate too much control in too few hands.
By mid-2026, the security story of AI is no longer only about malicious prompts, synthetic fraud or model misbehaviour. It is also about pipes, fabs, contracts, data centres and the uneven geography of computation. Nations that recognise this early will not become immune to disruption. But they will be better placed to absorb it, negotiate around it and preserve public trust when the AI stack proves less frictionless than its sales pitch once suggested.


