- Sovereign AI is not a data centre question but a control question: if a foreign directive, a vendor decision or a price change can take your AI away, you are not sovereign, regardless of where the servers sit.
- On 12 June 2026 the US Commerce Department directed Anthropic to suspend access to Claude Fable 5 and Claude Mythos 5 for any foreign national worldwide. Unable to verify nationality in real time, the company suspended access for everyone. Access returned on 1 July, a nineteen-day interruption.
- Hosting in Australia does not settle it. The US CLOUD Act lets US authorities compel US-headquartered firms to produce data held anywhere. The jurisdiction of the entity controlling the model matters more than the building.
- Open-weight models changed the maths. Kimi K3 benchmarks near the frontier; a compressed build runs in roughly 610GB, two desktop machines, and smaller open models run on a single 128GB laptop. Treat it as a capability floor, not parity.
- Sovereign capability is the capacity to exercise independent judgement and act on it. If the judgement layer is offshore, so is the sovereignty, wherever the servers sit.
On the evening of Friday 12 June, Australian organisations running Claude Fable 5 in their workflows did not lose a supplier. They lost a capability. No notice, no appeal, and no Australian in the room when the decision was made.
The detail most coverage skipped is the one that matters. The US Commerce Department did not order a general shutdown. Secretary Howard Lutnick wrote to Anthropic directing it to suspend access for any foreign national, anywhere in the world, including foreign nationals working inside the United States. Australians were not collateral damage in somebody else's outage. Australians were the category.
The company had no reliable way to verify nationality in real time, so it pulled access for everyone. Nineteen days later the controls were lifted, and global access returned on 1 July.
Be fair about what that episode actually shows. The vendor publicly disagreed with the order and said so. The restriction lasted under three weeks. The system, such as it is, corrected itself. If you are building a risk case, this was a near miss rather than a catastrophe.
Near misses are the only warning you get.
The two answers Australia keeps giving, and why both are wrong
The first answer is that Australia should build its own frontier models. The second is that Australia cannot possibly compete, so we should rely on capability built elsewhere and get on with adopting it.
Look at the numbers behind the first answer. Science & Technology Australia, drawing on the Stanford AI Index, puts AI investment from 2013 to 2024 at roughly $470 billion for the United States, $119 billion for China, $28 billion for the United Kingdom, and $4 billion for Australia. We are not going to close that gap with a media release. Anyone promising a domestic answer to GPT or Claude is selling something.
But the second answer collapses under a single question: rely on it for what?
Because the assumption buried inside "we can just use overseas models" is that access is a commodity relationship. Diesel and fertiliser are commodities. They can be stockpiled, substituted, sourced from a second country at a price. Frontier model access is not like that. It is contingent, revocable, concentrated among a handful of firms, and subject to the trade policy of a government that has never asked an Australian what they think. There is no switch-supplier option, because the switch is not yours to throw.
This is AI vendor lock-in, and it operates at a level most Australian procurement teams have never had to price. It is not only about where the data sits. The United States CLOUD Act allows US authorities to compel US-headquartered technology companies to produce data held anywhere in the world, Australia included. Local hosting does not resolve that. The jurisdiction of the entity controlling the model matters more than the postcode of the building it runs in.
Both answers are wrong because both are arguing about hardware. The sovereign AI question is not where the servers sit. It is who holds the judgement.
The on-premise moment arrived, and almost nobody noticed
Something has changed in the last twelve months that the policy conversation has not caught up with.
Moonshot released Kimi K3 on 16 July, a 2.8 trillion parameter open-weight model, with the weights published by 27 July. It sits fourth on the Artificial Analysis Intelligence Index, behind Claude Fable 5 and two variants of GPT-5.6 Sol, and it took first place on the Frontend Code Arena. On GDPval, which measures real-world tasks across 44 occupations, it placed third behind the two leading commercial systems. An open-weight model is now inside the same conversation as the frontier, and anyone can download it.
Now the part that gets overclaimed, so let me be precise. You cannot run Kimi K3 on a laptop. Unsloth, who produce the compressed builds most people actually run, put full precision at 1.56 terabytes. Their most aggressive compression brings the file down to 594GB and needs roughly 610GB of combined memory to run. Their own guidance is that this fits an NVIDIA DGX Station, or a Mac Studio paired with a second 128GB machine.
Read that number again, because what is remarkable about it is how small it is. Six hundred and ten gigabytes is two desktop computers. It is a capital purchase in the tens of thousands of dollars, sitting in a room in Adelaide or Toowoomba, drawing power from your own wall. It is not a data centre. It is not a hyperscaler contract. It is not an export licence.
Be equally precise about the cost of that compression. At one bit per weight the model agrees with its full-precision self about 79 per cent of the time. Push to two bits, at 861GB, and that rises to around 90 per cent. This is a degraded copy of a frontier-class system, not the thing itself. Anyone selling you desktop parity with Claude or GPT is not being accurate, and you should be suspicious of them.
But here is the part nobody seems to have registered. Once those weights are on your disk, they are yours. A directive issued in Washington can stop new access. It cannot reach into a building in Geelong and delete a file. That is what sovereignty looks like at the level an organisation can actually act on, and it costs less than a delivery van.
And if 610GB is more than your organisation needs, the tier below runs on one machine. A MacBook Pro with 128GB of unified memory handles OpenAI's 120 billion parameter open model at close to full precision, or Qwen 3.5's 235 billion parameter mixture-of-experts model at conversational speed. Work that sat behind a hyperscaler API eighteen months ago now runs on a laptop.
Consider what that inverts.
Traditional enterprise software took the best part of two decades to travel from on-premise to cloud. The pull was cost, elasticity, and someone else's maintenance burden. AI is making the same journey in reverse, in about two years, and the pull is different: data that cannot leave the country, latency that cannot tolerate a round trip, cost that cannot scale linearly with usage, and now, demonstrably, access that cannot be guaranteed.
That is the sovereignty conversation nobody in Canberra is having, because it does not require a ribbon-cutting.
Once those weights are on your disk, they are yours. A directive issued in Washington can stop new access. It cannot reach into a building in Geelong and delete a file.
The upgrade we actually need is in the people making the decisions
Here is the harder argument, and the one I expect to be least popular.
The reason Australia keeps arriving late to structural technology decisions is not a shortage of compute. It is the composition and the incentives of the people making the call.
The Grattan Institute's work on this is the most credible Australian source we have. In its 2019 submission to the Senate inquiry into ministerial standards, Grattan found that since 1990, more than a quarter of former federal ministers and assistant ministers moved into roles with special interests after leaving politics, from a sample of 191 people. Its broader finding was blunter still: the restrictions meant to govern that movement are unenforceable, because the Prime Minister alone determines what counts as a breach and no meaningful sanction exists.
This is not an accusation of corruption, and I am not making one. It is a structural observation, and structure beats intent every time. When the same small population circulates between the department, the regulator, the consultancy and the firm being regulated, the questions that get asked in the room are the questions that population has been trained to ask. Sovereignty questions are slow, expensive, and unglamorous. They do not fit an electoral cycle or a partner track. They lose, not because anyone decided against them, but because nobody was in the room whose job it was to raise them.
That data is from 2019, and it covers ministers generally rather than technology policy specifically. Treat it as directional. The direction is not encouraging.
I have said for years that we are trying to install new software on broken hardware. That is normally an observation about organisations. It applies to countries too. You can buy the most advanced intelligence layer on earth and route it through a decision-making structure that was not built to receive it, and the output will be exactly as good as the structure allows. Which is to say, not very.
The Prime Minister's July speech does mark a real shift, and it builds on the National AI Plan released in December 2025. A national regulatory framework for large AI data centres, with legislation flagged for early next year, and an explicit warning that Australia must not become a warehouse for products made overseas. The appetite has arrived. It has arrived pointed at buildings.
Buildings are the easy part. A data centre is a capital decision with a ribbon at the end of it. Capability is a decision about people, and it compounds slowly, and no one gets photographed next to it.
This time, do it differently
Every technology wave of the last thirty years has been optimised for the narrowest possible set of beneficiaries, and every one has been followed by a decade of legislating the consequences back into the system. Search, social, the platform economy, the gig economy. In each case the technology was designed to concentrate value, we acted surprised when it concentrated value, and then we spent years trying to redistribute it after the architecture had already set.
We are at the architecture stage again. Right now.
The real choice in front of Australia is not sovereign versus dependent. It is extractive versus distributed. Whether the intelligence layer this country runs on is built to maximise return for the loudest voice, the largest balance sheet and the most heavily capitalised shareholder, or whether it is designed from the start to return value to everyone with a stake in the outcome: the farmer, the employee, the regional supplier, the taxpayer funding the grid it runs on.
That is a design decision. It is being made now, mostly by default, mostly by people who will not be in those roles when the consequences land.
Which brings me to the stance I hold across everything I do. Human in the Loop. The automation carries the load; the human carries the judgement being applied around the technology.
Sovereign capability is not a stockpile and it is not a building. It is the capacity to exercise independent judgement about your own future, and to act on that judgement without asking permission. If the judgement layer is offshore, so is the sovereignty, no matter where the servers sit. And if the humans holding that judgement have not been upgraded to the level the decision demands, then it does not matter how much compute we build. We will simply make offshore-shaped decisions faster, in a data centre with an Australian flag on it.
What to do on Monday
Three things, in order of how quickly they can be done.
- Establish your floor. Every organisation of consequence should be able to answer one question: what can we still do on the day the API stops answering? Not as a replacement for frontier models, which remain better at most things. As a floor. Run something you own, on hardware you control, doing the work you cannot afford to lose. The entry price for that is now a room and a purchase order, not a partnership with a hyperscaler. The June suspension lasted nineteen days. Cost nineteen days out for your business, then decide whether the floor is worth building.
- Upgrade the decision layer before the tool layer. Most AI programmes fail because the technology arrives into a decision-making structure that was not ready to receive it. The constraint is almost never the model. It is the quality of the judgement being applied around it, and the willingness of the people in the room to be wrong in public.
- Write the stakeholder question into procurement, not the annual report. If distributed value is the position, it belongs in the contract, the vendor assessment and the board paper. Anywhere else and it is decoration.
The June episode gave Australia a nineteen-day preview of a question we have been avoiding. The controls were lifted. The models came back. Almost everyone has already forgotten.
That is the part that should concern us.
What can you still do on the day the API stops answering?
If you cannot answer that first question, that is where to start. It is the opening question of the AI Health Check, and I will run through it with you.
Book your AI Health CheckQuestions people are asking
What is sovereign AI?
Does hosting AI in Australia make it sovereign?
What happened when Anthropic's models were export-controlled in June 2026?
Can Australian businesses run frontier-class AI models on their own hardware?
How should Australian businesses reduce AI vendor lock-in?
- Anthropic, Redeploying Claude Fable 5, 30 June 2026
- Forbes, coverage of the Commerce Department export-control directive, 16 June 2026
- CNBC, on the lifting of export controls, 30 June 2026
- Moonshot AI, Kimi K3 technical blog and API documentation, July 2026
- Unsloth, Kimi K3: How to Run Locally, quantisation analysis and hardware requirements, July 2026
- Artificial Analysis Intelligence Index and GDPval-AA v2 benchmark results, July 2026
- Grattan Institute, Submission to the Senate revolving door inquiry, August 2019
- Grattan Institute, Who's in the Room? Access and Influence in Australian Politics, 2018
- Science & Technology Australia, response to the National AI Plan, December 2025, citing the Stanford AI Index
- Australian Strategic Policy Institute, The Strategist, on the Prime Minister's AI address, July 2026

About the author
British technology futurist, AI keynote speaker and advisor. Thirty years across enterprise technology and AI strategy, helping leaders navigate the future of work. The futurist who died.