Cybersecurity & Tech Foreign Relations & International Law

The AI Sovereignty Paradox

Masahiro Kurosaki
Tuesday, July 28, 2026, 10:06 AM
How shifting strategic interests are reshaping cyber sovereignty in international law.
(紅色死神, https://tinyurl.com/9k3mbxcm, CC BY-NC-SA 2.0, https://creativecommons.org/licenses/by-nc-sa/2.0/deed.en)

The ongoing debate over cyber sovereignty reflects a recurring trade-off between two competing interests: the protection that sovereignty-as-a-rule affords against foreign cyber intrusions, and the operational latitude that rejecting or limiting that rule preserves for a state’s own extraterritorial cyber operations. That trade-off has shaped both what states argue and where they argue it. The rise of artificial intelligence (AI) sovereignty—a state’s capacity to develop, deploy, and control AI systems, including the data corpora, compute infrastructure, and model weights that constitute the AI supply chain, free from foreign dependence or manipulation—is making it newly acute for every state that has stopped short of treating any unauthorized access to its networks as a sovereignty violation. The resulting issue, however, is a paradox in which the legal positions that preserve a state’s freedom to operate in others’ networks now leave its own AI infrastructure unprotected. The United States, at once the world’s leading AI power and the most capable practitioner of cyber espionage by most assessments, illustrates it most sharply: It has carefully avoided taking a clear position on whether sovereignty functions as an independent primary rule in cyberspace—but now finds that same posture leaving its AI infrastructure without a clear legal basis for protection. The United Kingdom, which has gone further by explicitly declining to accept that sovereignty-as-a-rule has yet crystallized in international law, faces a structurally sharper version of the same problem.

In legal terms, what AI sovereignty most requires is protection against unauthorized state access to AI training infrastructure, a harm that existing threshold frameworks—which require demonstrable harmful effects or coercive interference—fail to capture. The stakes are already visible in state behavior: By January 2026, national initiatives aimed at building AI capabilities independent of foreign control had proliferated to nearly 130 across more than 50 countries, according to the CNAS Sovereign AI Index.

Sovereign AI policy and the international law of cyber sovereignty have so far been debated on largely separate tracks—but the two are connected: AI sovereignty is making the protection-latitude trade-off newly difficult to sustain—from two directions at once. The first pressure is strategic: As states designate AI training data and model weights as national security assets, they acquire a powerful interest in exactly the legal protection they have historically resisted. The second is technical: The primary threats to those assets—data exfiltration and data poisoning—sit uneasily within existing threshold frameworks, making an approach that treats any unauthorized access as a violation structurally preferable. Together, these pressures push the direction of customary international law toward such an approach—and confront states that have stopped short of that commitment with a shared question: How should they adjust their protection-latitude balance in light of an AI threat landscape that their current legal positions leave largely unprotected?

How Strategic Interests Have Shaped the Threshold Debate

Three clusters of positions have emerged, each reflecting a distinct balancing of protection and operational latitude.

The pure sovereignty camp—led by France and the African Union (AU)—holds that any unauthorized access to information and communications technology (ICT) infrastructure constitutes a violation regardless of effects, functioning as a “normative firewall” enabling states to invoke responsibility and countermeasures. The AU’s Common Position—representing 55 states whose experience has been overwhelmingly as targets—affirms that “any unauthorized access by a State into the ICT infrastructure located on the territory of a foreign State is unlawful,” making “the Tallinn Manual’s contrary position” difficult to sustain as current customary law. Customary international law is not decided by majority vote—it requires consistent state practice and opinio juris across states whose interests are specially affected—but the breadth of states now expressing the pure sovereignty position makes it increasingly difficult to characterize it as anything other than the emerging customary rule. Much of this camp has pressed its case in the UN’s universal forums—the Open-ended Working Group on Security of and in the Use of Information and Communications Technologies and now the Global Mechanism on ICTs in the Context of International Security—where broad participation gives its opinio juris the most weight. Austria’s 2024 position paper—announced after its foreign ministry faced a large-scale cyberattack—extends the framework to cover industrial cyber espionage: If unauthorized access to a chip manufacturer’s infrastructure constitutes a breach of sovereignty, why should access to AI training infrastructure be treated differently? For states with limited offensive cyber capabilities, the protection pure sovereignty affords outweighs the operational constraints it imposes—a calculation that AI sovereignty may be extending to a far larger set of states.

The effects-based camp—represented by the Tallinn Manual 2.0 and most Western and like-minded states—accepts sovereignty as a rule but requires physical damage, loss of functionality, or interference with inherently governmental functions. Japan’s 2021 Group of Governmental Experts submission exemplifies this middle position in the protection-latitude trade-off: more protection than the U.K. accepts, more latitude than pure sovereignty allows—latitude that Japan now relies on for the “remote access and neutralization measures” authorized under its active cyberdefense framework. Elaborated through the Tallinn Manual process—expert-led, hosted by the NATO-accredited Cyber Defence Centre of Excellence—it nonetheless leaves everything below those three criteria unprotected.

The operational latitude camp comprises two distinct positions. The U.K.—in a 2018 attorney general speech, its 2021 Group of Governmental Experts submission, and a 2022 attorney general speech—has declined to accept that sovereignty-as-a-rule has yet crystallized in international law, relying instead on an expansive non-intervention principle. The stance has direct “implications for intelligence and offensive cyber operations”: Sovereignty-as-a-rule would expose the Government Communications Headquarters’s (GCHQ’s) nondestructive intrusions into foreign ICT infrastructure to the very standard the U.K. declines to endorse. GCHQ’s then-director acknowledged that “stealth and ambiguity are key attributes of cyber operations.” The U.S. position is structurally different and more explicitly hegemonic: While U.S. capabilities dominate, sovereignty-as-a-rule would constrain National Security Agency (NSA) and Cyber Command operations. Should Chinese cyber capabilities reach parity, the calculus reverses—a state more exposed as a target gains more from the rule’s protection than it loses by accepting its constraints. AI sovereignty represents precisely such a shift in the making. The United States’s 2021 national position affords that a cyber operation may violate international law “in certain circumstances,” without committing to sovereignty as an independent rule. Since then, the U.S. has invested heavily in allied frameworks while opposing a dedicated international law thematic group within the new Global Mechanism. Both positions leave these states exposed on precisely the category of low-level, nondestructive intrusions they would most need protection against as AI sovereignty states.

China and Russia complicate this picture. Both are among those most often accused of violating the very sovereignty they invoke—China a self-styled champion of “cyber sovereignty” since 2015, when Xi Jinping insisted no state should “engage in, connive at or support cyber activities that undermine other countries’ national security,” while widely assessed as one of the most prolific intruders into foreign networks. What’s more, Russia’s Information Security Doctrine, which commits to “protecting the information sovereignty of the Russian Federation,” follows the same pattern. Yet that gap between word and deed does not disturb the analysis here, for two reasons. First, violations do not erase rules: As the International Court of Justice explained in the Nicaragua judgment, what would weaken a customary rule is not the breach itself but a claim that the conduct is lawful as of right. It follows that a state that breaches the rule while denying the conduct leaves the rule’s authority intact—as China has over the U.S. Office of Personnel Management (OPM) breach and as Russia did over the SolarWinds intrusion, which U.K. and U.S. authorities attributed to Russia’s Foreign Intelligence Service. Second, the pressure on Washington is not diminished by Beijing’s and Moscow’s inconsistency: It stems from a shift in America’s own policy record, traced next.

The Strategic Pressure: AI Sovereignty Disrupts the Existing Alignment

The U.K.’s AI Opportunities Action Plan describes AI compute infrastructure as “critical strategic assets”; the U.S. “Winning the Race” AI Action Plan identifies safeguarding American AI against theft and misuse by malicious actors as a cross-cutting priority. The Biden administration’s AI Diffusion Rule—which created the first export control over advanced model weights (ECCN 4E091), subjecting them to a presumption of denial for most destinations, though rescinded in May 2025—records an official U.S. determination that controlling the spread of model weights is necessary to protect national security.

The same states that have kept the threshold for sovereignty violations high—to protect GCHQ and NSA operations that intrude into foreign ICT infrastructure without physical damage—are now designating their own AI assets as requiring protection against exactly those operations. The State Department’s Pax Silica initiative—launched in December 2025 and now with 24 signatories to its declaration, including the U.K., Japan, and Australia—commits its signatories to protecting sensitive technologies and critical infrastructure from “undue access, influence, or control.” The June 2026 executive order on AI and cybersecurity directs federal agencies to prioritize the cyber defense of AI systems as critical national infrastructure. The Five Eyes agencies’ joint statement of June 2026 warns that frontier AI models are “fundamentally transforming both offensive and defensive cyber capabilities” on a timeline of “months, not years”—yet says nothing about the international law basis for responding when adversary states target that infrastructure. Each of these instruments asserts sovereign entitlement over AI assets while leaving the legal remedy for their compromise unresolved.

Domestic legislation is not itself opinio juris. But as states justify data localization requirements—Russia’s data localization amendments (Federal Law No. 242-FZ), China’s Data Security Law (2021), the EU’s General Data Protection Regulation transfer restrictions (Chapter V)—in terms of sovereign entitlement over territorial data, those justifications and the pure sovereignty position mutually reinforce each other. Even China’s concept of “cyber sovereignty,” framed as domestic control, rests on the same claim of territorial entitlement. It is the convergence of justifications, not the legislation itself, that may come to be read as opinio juris in the forums where the pure sovereignty position has gained the most traction.

The Technical Pressure: Why Threshold-Based Protection Fails for AI Infrastructure

AI training infrastructure is a force multiplier: The quality of the models it produces shapes the effectiveness of every AI-enabled capability built upon them. What distinguishes it from the operational systems the threshold framework was built around is the nature of its vulnerability—compromising the infrastructure at the training stage may compromise the AI itself, often invisibly and in ways that are difficult to reverse.

Exfiltration produces no immediate harmful effects of the kind those frameworks require.

Once model weights leave a developer’s control, they cannot be recalled: Stolen weights enable malicious actors to strip away the safeguards built into the most capable models, while the targeted system itself continues to function normally—the system suffers no physical damage, or no loss of functionality. Under effects-based sovereignty, such an operation falls outside the protective scope. Under the U.K.’s nonintervention approach, it is harder still to reach: Exfiltration deprives a state of a strategic asset without compelling any change in governmental decision-making. Under pure sovereignty, unauthorized access itself is the violation. The traditional objection—that espionage per se does not violate international law—is precisely the position the AU’s and Austria’s statements are eroding. And for those who would locate the threshold somewhere between the two poles—Chircop, for instance, argues that a sovereignty violation requires harm that is more than de minimis—a state’s own decision to subject model weights to national-security export controls is at least evidence that their loss is not trivially minor.

To be sure, below-threshold intrusions are not new—which is precisely the point. Volt Typhoon’s pre-positioning inside U.S. critical infrastructure, for example, has already shown that intrusions causing no present damage can carry serious strategic weight. AI sovereignty sharpens that lesson. In 2015, the background-investigation records of more than 21 million people were exfiltrated from the OPM—an intrusion U.S. officials suspected China of directing. At the time, the former CIA and NSA director could call it “honorable espionage work.” Yet that shrug is harder to justify today: The U.S. government has already gone on record designating model weights a national security asset, subject to controls it determined were “necessary to protect U.S. national security and foreign policy interests.” Further, the OPM hack left vulnerable information about capability; model weights are that capability itself—a state that loses the asset loses the capability, not merely the knowledge of it. In short, AI does not create the below-threshold gap this piece has described. Rather, it sharpens that gap by putting a different kind of asset inside it—the capability itself, and one the state has already put on the record as vital to its security. That combination is what makes the stakes unprecedented.

Data poisoning exposes the analytical failure.

Data poisoning—corrupting the data used to train an AI model so that the model learns hidden, malicious behavior—poses a different kind of threat: Whereas exfiltration steals the asset, poisoning corrupts it from within. Poisoning web-scale training datasets is demonstrably practical—researchers showed that for as little as $60, an attacker could have poisoned portions of the datasets behind major AI models—and backdoored models can behave normally until a specific trigger appears, with the deceptive behavior persisting through, and even being hidden by, standard safety training. The EU AI Act requires high-risk AI systems to withstand such attacks. Applying the Tallinn categories to this scenario is not straightforward. There is no physical damage. Whether latent corruption counts as a loss of functionality is contestable—a defender of the effects-based view could argue that a backdoored model is functionally impaired from the moment of poisoning—but the impairment cannot be demonstrated until it manifests, potentially months or years later. The inherently governmental functions argument fares no better: It requires tracing a temporally diffuse causal path that is diffuse in time, running from the moment of poisoning to eventual harm. The protection that effects-based sovereignty offers is therefore largely ex post, attaching only once harm has revealed itself, and offering little at the point of intrusion. Data poisoning also falls beyond the U.K.’s nonintervention principle: Covert manipulation of training data does not deprive a state of its freedom of choice over policy. Others have argued in a related context that AI-era threats call for “a new legal paradigm” for sovereignty. Pure sovereignty supplies one: By locating the violation in the unauthorized access itself, it protects at the moment of intrusion rather than waiting for effects that may never become provable.

Allied AI programs illustrate the gap most concretely.

The most significant example is AUKUS Pillar II: In April 2023, the U.K. hosted the first AUKUS AI trial, connecting U.S., U.K., and Australian drones in real time and retraining AI models in flight. If adversaries exfiltrated training data from or introduced poisoned inputs into that shared infrastructure, the U.K. would have no clear international law basis for characterizing the intrusion as a sovereignty violation. Without that predicate, it would have no countermeasures basis (Articles on State Responsibility [ASR], Articles 22 and 49) for its response either—leaving only retorsion (lawful but often inadequate measures such as sanctions or diplomatic expulsions) or the narrow and contested plea of necessity (ASR, Article 25), which requires a grave and imminent peril that latent compromise is ill-suited to establish. The forums in which allied AI cooperation is taking place are not the forums in which the threshold debate is being resolved—and the legal framework governing that cooperation remains largely unexamined.

Where the Law Is Heading: Implications for All Three Camps

Customary international law appears to be moving toward pure sovereignty—as Patrick C. R. Terry’s analysis and Russell Buchan and Nicholas Tsagourias’s assessment of the AU position suggest. AI sovereignty may accelerate this convergence: It brings major cyber-capable states into the category of states with a strategic interest in pure sovereignty; it generates assets for which pure sovereignty may be the only framework that fits the technical reality; and it generates justifications for sovereign entitlement over AI assets that may come to be read as expressions of opinio juris. The Global Mechanism on ICTs, which began work in 2026, and the Global Digital Compact (2024) provide institutional channels through which these tensions may increasingly be addressed.

Each camp now faces a version of the same question: Where should the protection-latitude balance be redrawn? For the pure sovereignty camp, AI sovereignty validates the position it already holds. For the effects-based camp, it exposes the unprotected zone the Tallinn threshold leaves—particularly for data operations—and may require extending protection downward. For the operational latitude camp, it creates a structural trap: The legal positions designed to preserve space for intelligence operations are the same positions that deny legal remedies when AI infrastructure is the target. For U.S. policymakers specifically, if adversaries exfiltrate training data or model weights underpinning U.S. defense AI systems—including under AUKUS Pillar II or Pax Silica—the U.S. faces the same gap: no clear basis for calling the intrusion unlawful and therefore none for the countermeasures that would follow from it. To be sure, sanctions and indictments remain available: Washington has deployed both against state-linked hackers for a decade, from the 2014 indictment of People’s Liberation Army officers through Volt Typhoon. But they impose costs after the fact rather than protect the asset. Nor do they substitute for a legal finding: As creatures of each state’s domestic law, allies can act in parallel, each under its own authority, but no single one of those actions amounts to a joint determination that the intrusion violated international law—the shared legal predicate any collective response beyond retorsion would require. That absence of a remedy is a legal problem, not a policy prescription: To be clear, this piece does not argue that Washington must now embrace pure sovereignty. It argues that Washington’s legal position and its policy record sit in tension, and that the choice between them can no longer be deferred. That policy record speaks for itself: The export controls, the June 2026 AI executive order, and the Pax Silica declaration all constitute implicit claims that exfiltrating or poisoning AI training infrastructure is wrongful; the legal position needed to make that claim explicit is the one the U.S. has most carefully avoided stating. Resolving that gap—through updated national positions, alliance-level norm statements, or engagement with the Global Mechanism—is where the AI sovereignty paradox will be settled, and where the next chapter of the cyber sovereignty debate will unfold.


Masahiro Kurosaki is Professor of International Law at the Tohoku University School of Law, Japan. He also serves as the Chair of the Study Group on International Law organized by the Operational Policy Division of the Bureau of Defense Policy, Ministry of Defense of Japan. He has, on occasion, represented the Government of Japan in diplomatic negotiations on international human rights and humanitarian law as a legal adviser, provided expert testimony before a committee of the National Diet of Japan, and participated in various councils and expert groups convened by the government. After joining the International Relations Faculty of the National Defense Academy (NDA) of Japan in 2008, he held positions as Lecturer (2008–2011), Associate Professor (2011–2022), and Professor (2022–2026). He has published numerous articles and book chapters on the law of international security, the law of armed conflict, international criminal law, and Japanese security laws.
}

Subscribe to Lawfare