
The question of sovereignty over AI in the defence space is a longitudinal rather than momentary one. After a deal is concluded, the question remains if Australia will continue receiving what the technology morphs into. Australia should be acquiring a position within a trajectory of forward-moving capabilities.
Unlike the discrete information once shared between allies or marked as AUSTEO, AI models blur the distinction between the information an ally contributes and the capacity it ultimately receives.
While most commercial uses of LLMs like Claude do not retrain the foundational models, Anthropic’s agreement (Opens in new window) with the US Department of Defence explicitly included a capacity to develop prototypes of new models fine-tuned on American defence data.
Suppose that years of AUSTEO intelligence data are used to improve an Australia-specific defence model.
The original files would remain easy to classify and their access remains controlled. But the resulting model may become better than previous systems at identifying an adversary’s submarine or interpreting satellite imagery.
The subsequent question stemming from that model is what now counts as AUSTEO?
The underlying data, certainly. But what about the capability produced from the models trained on those data? An AUSTEO marking can follow a secret but it cannot, by itself, determine who controls what a machine became capable of as a result of learning about that secret.
This is the fundamental distinction that AI provides from previous generations of technology. It can convert classified information into performance, and information security rules governing its partnership with other countries have little to say about who controls the resulting performance.
There may not be one discrete technological object that can become sovereign in the way that Marles or any other official expects.
An Australian defence application might combine an American foundational model, Australian classified data, a fine-tune of that model hosted in Australia, local servers, Anthropic providing updates, and subsequent generations of the underlying model, which itself is subject primarily to US law.
The combination of those components makes old definitions of sovereignty complicated. The capability that Australia seeks emerges from the continuing relationship among each of them. The question of sovereignty in the age of frontier AI requires control over the process of the formation of capabilities because the security boundary has moved from the document to the pipeline.
Ultimately, Marles’ insistence on making Australia the second home of frontier AI capability is a real one. But it is insufficient as a measure of technological sovereignty over important capabilities.
Local staff can build expertise. Domestic investment can create leverage over major companies. But Australia has to define a position in the continuing process through which AI capability evolves.
That requires three things. Australia needs arrangements that provide continued operational access and transitions between generations of models. There must be clarity about who has rights to models developed using Australian protected information. And Australia must define what capability it has to evaluate and manage any changes to the underlying models or safeguards that its fine-tuned models use.
The achievement of 20th century alliance building was in constructing institutions that allowed for sharing extraordinarily sensitive national security information to circulate among close allies while preserving national control.
The next problem lies in how allies jointly develop and exchange capabilities produced from shared technology without losing meaningful national control over them.
The test of that sovereignty cannot merely be where the data centre is located. The crucial question is whether Australia can retain control as secrets are turned into changing capabilities.
Leave a comment