In the age of artificial intelligence, being an ally does not necessarily mean being inside the gates. Pax Silica, the American-led technology coalition launched in December 2025, provided a striking demonstration in June. On 12 June, the US Department of Commerce directed Anthropic to bar all foreign nationals, including US residents and Anthropic employees, from its most advanced models. The restriction was lifted almost three weeks later without public explanation. No exemption was made for America’s allies. Even the United Kingdom, a founding member of a coalition explicitly grounded in geopolitical alignment with Washington, remained outside the perimeter. When access to frontier AI was at stake, nationality mattered more than alliance.
Pax Silica coordinates supply rather than distribution, spanning critical minerals, energy, semiconductor fabrication, logistics, compute and frontier foundation models, a scope described as more targeted than the G7 or G20. The coalition has expanded beyond the advanced economies with which it began, and now includes Argentina, Panama, Kazakhstan, India and the Philippines. A second summit on 25-26 June 2026 produced a Joint Statement on AI Opportunity carried by close to three dozen economies. Interestingly, the second summit fell inside the suspension of Anthropic models: as delegations signed a commitment to a pro-innovation regulatory approach, and heard opening remarks arguing that governments should treat artificial intelligence as an opportunity rather than a threat, their own nationals were barred from the most capable American models. The closest ally responded formally. On 6 July 2026, the House of Commons Science, Innovation and Technology Committee reported that the UK may not be able to count on its allies for frontier access, citing the episode directly for demonstrating terminability, or the power to revoke another actor’s supply of productive intelligence, which extends Farrell and Newman’s weaponised interdependence into the cognitive layer of the economy.
The episode exposes a distinction that is easy to obscure in discussions of technology alliances: control over the AI supply chain is not the same as access to the intelligence produced at its frontier. A state may be integrated into American-led arrangements for minerals, chips, energy and compute while remaining dependent at the model layer on access that is commercial, conditional and ultimately revocable. Pax Silica therefore aligns the physical infrastructure of AI without necessarily extending the same guarantees to its cognitive layer. For middle powers, the strategic question is not simply whether they belong to a trusted network, but which layers of their national AI stack that membership actually secures.
On the other hand, the Chinese-led World Artificial Intelligence Cooperation Organisation (WAICO), established in Shanghai on 16 July 2026 by twenty-nine states including Russia, Brazil, Pakistan and Malaysia, has since grown to 38 states, admits without conditions attached to political alignment and offers capacity-building as well as open-source collaboration. WAICO does not itself distribute models. Open-weight systems, from laboratories including DeepSeek, Kimi and Z.ai, are released independently of membership, run on hardware any state already owns, are significantly cheaper than frontier models, and, critically, cannot be withdrawn because no licence exists to withdraw, so access cannot be revoked. Perhaps unsurprisingly, open-weight model usage has risen materially over the past year, including among American firms.
Yet, open weights should not be confused with technological sovereignty. Their principal advantage is narrower but strategically important: once acquired, an external provider cannot easily terminate access to the model itself. States may still depend on foreign chips, cloud infrastructure, energy systems, software ecosystems and technical expertise to run or improve those models. The relevant distinction is, therefore, not between dependence and independence, but between different forms of dependence. Frontier proprietary systems may offer greater capability at the price of continuing external discretion over access; open-weight systems sacrifice some capability while reducing exposure to revocation at the model layer. For middle powers, the strategic task is to manage this trade-off rather than imagine that either ecosystem offers genuine autonomy.
Pax Silica membership guarantees nothing at the model layer besides priority placement in the queue to buy them, and hardware delivery is heavily conditional, transactional, and subject to immediate geopolitical leverage. Frontier model access purchased at commercial rates is recurring expenditure in foreign currency, and is not a capital asset: nothing accumulates and no domestic capability compounds. Frontier model access also remains revocable by a government that has demonstrated its willingness to revoke it. Sustaining such an arrangement against freely available open weights would require terms such as preferential pricing or guaranteed allocation. Pax Silica has offered none. That said, building an alternative isn’t available either. In March 2026, Anthropic tightened peak-hour session limits for paying customers on capacity grounds, and by May had agreed to spend 1.25 billion USD per month renting capacity from a competitor through 2029. If even leading American laboratories struggle to self-supply the compute their services require, the economics of sovereign frontier-model development are forbidding for most middle-income states.
Few members are at liberty to act on such an assessment. Kazakhstan showed what the bargain looks like for a state with leverage upstream and none downstream. It holds substantial leverage upstream in critical mineral reserves Washington requires, and no frontier capability downstream, with no prospect of financing any. Astana signed the Pax Silica Declaration at the June summit, while the models were still disabled, and a month later signed the WAICO agreement at ministerial level, a judgment defensible when read against the founding documents, since one instrument governs supply chains and the other standards and training. In mid-August 2026, however, Reuters reported on an internal US State Department draft warning the thirty-five signatories of the AI Opportunity statement that participation in Beijing’s framework is incompatible with trusted-partner status, i.e. states must pick a side. Astana is therefore being asked to forgo the only productive intelligence it can afford, in return for admission to a coalition supplying capability it cannot buy. What, on such terms, does exclusivity secure for a state in that position?
Kazakhstan illustrates the wider dilemma facing middle powers in the emerging AI order. Bargaining power is not distributed uniformly across the technology stack. A state may possess considerable leverage in minerals, energy, manufacturing or geography while remaining almost entirely dependent at the model and compute layers. Alliance membership does not erase these asymmetries; it merely places them within a political framework. The rational strategy for middle powers is therefore neither technological autarky nor unconditional alignment, but portfolio diversification across the stack: securing reliable access where dependence is unavoidable, retaining substitutable suppliers where possible, and building domestic capacity in those layers where the costs of external termination would be greatest.
Furthermore, Washington is reportedly considering restricting or banning Chinese open-weight models. Such a prohibition would not, by itself, partition the stack, since released weights cannot be recalled and no American agency can theoretically police servers in Astana or Manila if a US company does not own them. The test of a genuine alliance is whether these member states then legislate domestically, instruct their cloud providers, enforce at the border, and whether export controls extend to weights themselves. Should Pax Silica members legislate to that effect, would such a coalition, whose members have to police their own firms and researchers on behalf of the US, remain a genuine supply-chain arrangement at all in the long run?
The rationale for prohibiting open weights is uncontrolled diffusion of frontier cyber capability, which was also the rationale for denying allied cyber defenders access in June 2026. Neither prohibition nor denial of open weights for Pax Silica members carries a compensating guarantee that they will receive frontier models instead. Washington is more likely to offer its partners something similar to an undertaking not to repeat June 2026, access to cheaper but less capable models or investment in data centres built on members’ own territory. None of these would replace what a ban removes: a state’s ability to access productive intelligence without paying frontier prices. This may sting even more given that open-weight model releases have closed much of the capability gap over the past year.
A ban on open-weight models would therefore alter what such a state may lawfully run rather than what it can afford, and the burden of enforcement would fall on its own regulators and customs authorities. Encryption export controls in the 1990s had the same structure. Strong cryptography spread regardless, leading to a commercial cryptography industry beyond American jurisdiction. Realist premises again predict low compliance with bans on open-weight models, since most states, members or not, discount commitments in proportion to the likelihood of being abandoned.
The emerging divide in AI geopolitics is therefore unlikely to be captured adequately by asking whether a state belongs to an American or Chinese technology coalition. The more consequential measure is how much of its national AI stack rests on foundations that another actor can withdraw, restrict or price beyond reach. For middle powers, technological sovereignty will rarely mean independence across the stack. A more realistic objective is managed interdependence: reducing the number of critical layers at which a foreign government or company retains an effective veto over national capability. In the age of AI, alliances may determine the ecosystem. Access determines the power.
