Memory Palace

AI Grand Strategy for Middle Powers

Sovereign AI, how?

Middle powers cannot decide what happens at the frontier, but they host the grid, the minerals, and the waste. That is where their strategy has to start.

Cornelis de Man, two astronomers at a table with a celestial globe

The question

A prompt I was given recently: if in ten years we have developed and deployed AI which was not capable of causing catastrophic harm, what was pivotal in making that a reality?

Most answers in the room went to governance, independent evaluators, interpretability, control. I agree with the list. What holds my attention is the word pivotal, which assumes we will be able to look back and name the thing that worked. Safety is mostly counterfactual, and counterfactuals are difficult to claim credit for. A treaty, a delayed release, and a capability that never arrived all produce the same visible record: nothing happened.

I should say that I have published this page and withdrawn it twice. Each time the argument looked thinner to me a week later than it had on the night I posted it, and I do not promise that it will stay up now. I mention this because it is the same problem in miniature. It is difficult to hold a position on a moving object without either fixing it too early or refusing to commit at all, and I have not found the setting between those two that I can live with.

For a middle power the question lands differently again, because almost nothing on that list is ours to decide. We do not train frontier models. We do not set release thresholds or hold the weights. The interesting question is not what we would do at the frontier, but what remains available to a state that will only ever be downstream of it.

What forecasts can and cannot carry

I read AI 2027 and AI 2041 close together. One is a scenario with timelines, written to be argued with. The other is fiction with commentary, ten stories, more interested in how the technology arrives in a life than in when.

My difficulty is not that either is wrong. Being fair to the range of possibilities costs accuracy, and breadth buys the author survival while taking decision value from the reader. AI 2027 narrows and accepts being visibly wrong. AI 2041 spreads and purchases plausibility with the spread. Both show their working, which is also what makes the hedging visible: you can see which assumption is carrying the conclusion.

So I read them as noticing rather than planning. A ministry cannot procure against a scenario. It can decide in advance which observations would change its mind.

The leverage I think is worth considering

I would like to build a policy playbook for middle powers navigating the AI transition, something a mid-level official could open and use. This page is an attempt to find out what would go in it.

The leverage is not at the model layer. Pretending otherwise produces documents that read like wishes. There are two places I would put more of my confidence.

  1. The supply chain. Where the compute is sited and whose grid it draws from. Which minerals move through which port, under whose labour law. Who may test a system before it reaches the public, and on what terms. Which standards a market of thirty or fifty million people can make expensive to ignore. Unglamorous, and held now, by states that will never train a frontier model.

  2. Energy security. A data centre is a claim on electricity and water, made in one jurisdiction, for a service sold in another. The clean-energy supply chain has its own geography: lithium, cobalt, nickel, polysilicon, each with a place where the tailings stay. Returns go to the countries that lead. Extraction, e-waste, and strain on fragile grids go to those with less room to refuse. Slow, distributed, and conceded quietly while everyone watches the model.

My current intuition on a “safe” outcome

Three conditions, each by 31 December 2036, each at the number I would bet at today.

Facility-level disclosure, 30%. A major market requires large data centres to report electricity draw, water withdrawal, and siting under audit, public, with a penalty. Company-level aggregates do not count. Aggregation is where the siting question disappears.

Sourcing and take-back at the border, 20%. Import or operation of AI hardware conditioned on verified mineral provenance and a funded end-of-life obligation. Lower, because it constrains a trade relationship rather than a filing.

A hosting coalition, 15%. Three or more middle powers apply common conditions to new compute siting, with at least one project refused or renegotiated under them. Announcements do not resolve it. The refusal is the test.

Sixty-five points, deliberately. All three together is not one per cent, since disclosure makes the rest cheap; call it five to eight.

The fourth I will not number. Whether compute demand keeps compounding or flattens through efficiency and a capability plateau decides the other three, and I cannot write a criterion for it that I would not bend once I saw the result.

What I do not want to be true in ten years

If we reach 2036 without a catastrophe, and with a decade of strained grids, contaminated sites, and shipped e-waste behind us, someone will still be able to say the safety project succeeded. On its own terms they will be right. I would like to have argued in advance against the version of success that gets there by moving the cost onto people who were never asked.

This page is still taking shape, and I expect the middle-power part of it to change the most.