Subscribe to The Informer for monthly expert analysis, and to Events for advance notice of visiting world leaders and distinguished guests.
You may unsubscribe from Lowy Institute newsletters at any time. For information on our privacy practices and how to unsubscribe, see our Privacy Policy.
The most-pressing world events explained by Lowy Institute experts and global contributors, in your inbox, every Thursday.
You may unsubscribe from The Interpreter at any time. For information on our privacy practices and how to unsubscribe, see our Privacy Policy.
Artificial intelligence, explained.

Australia has spent decades grappling with this contradiction between technological integration with allies and retaining national control over its systems and capabilities (Getty Images Plus)
AUSTEO could mark a secret as protected, but it says nothing about who controls the capability that secret becomes.
At the beginning of what would become a consequential month for Anthropic, the AI giant behind leading tool Claude, Deputy Prime Minister Richard Marles travelled to San Francisco and said that he wanted the company to find a “second home (Opens in new window)” in Australia.
As the AI industry continues its boom, Australia is now pitching itself as the next step beyond the United States. Marles presented (Opens in new window) Australia’s political and geological stability, its infrastructure, and its Five Eyes membership as reasons for a future investment.
But such a shift raises a question of what would make AI capacity that moves from the United States become Australian enough to count as sovereign?
Australia has spent decades grappling with this contradiction between technological integration with allies and retaining national control over its systems and capabilities.
Material shared through Five Eyes and other sources can be restricted to Australian personnel (with the designation AUSTEO, Australian Eyes Only). This and other indicators can mark how information should or should not be released to partners.
Sovereign AI needs the modern equivalent of those designations. But AI makes the object being protected much harder to define.
There may not be one discrete technological object that can become sovereign in the way that Marles or any other official expects.
In recent years, programs like the F-35 have modernised that thinking about sovereignty away from just possession of a physical platform and towards continued access to software.
The Australian Department of Defence says that exploiting the F-35’s capabilities requires ongoing reprogramming and updates to support systems. To that end, Australia and the UK established a US-based lab to produce mission data for the aircraft.
Frontier AI systems make sovereign control more difficult because, unlike the decades-long development process of the F-35, the capacity of AI models is being continuously superseded.
Anthropic does not sell one stable Claude model indefinitely. It operates a pipeline of models that are activated then retired in short succession. When a model is retired, sometimes months later, customers must migrate to the next system.
Australia could negotiate perfect sovereign access to a frontier model today and discover that the capacity they have built for has shifted to a successor within six months.

The F-35 have modernised thinking about sovereignty away from just possession of a physical platform towards continued access to software (Mikaela Fernlund/Defence Imagery)
The question of sovereignty over AI in the defence space is a longitudinal rather than momentary one. After a deal is concluded, the question remains if Australia will continue receiving what the technology morphs into. Australia should be acquiring a position within a trajectory of forward-moving capabilities.
Unlike the discrete information once shared between allies or marked as AUSTEO, AI models blur the distinction between the information an ally contributes and the capacity it ultimately receives.
While most commercial uses of LLMs like Claude do not retrain the foundational models, Anthropic’s agreement (Opens in new window) with the US Department of Defence explicitly included a capacity to develop prototypes of new models fine-tuned on American defence data.
Suppose that years of AUSTEO intelligence data are used to improve an Australia-specific defence model.
The original files would remain easy to classify and their access remains controlled. But the resulting model may become better than previous systems at identifying an adversary’s submarine or interpreting satellite imagery.
The subsequent question stemming from that model is what now counts as AUSTEO?
The underlying data, certainly. But what about the capability produced from the models trained on those data? An AUSTEO marking can follow a secret but it cannot, by itself, determine who controls what a machine became capable of as a result of learning about that secret.
This is the fundamental distinction that AI provides from previous generations of technology. It can convert classified information into performance, and information security rules governing its partnership with other countries have little to say about who controls the resulting performance.
There may not be one discrete technological object that can become sovereign in the way that Marles or any other official expects.
An Australian defence application might combine an American foundational model, Australian classified data, a fine-tune of that model hosted in Australia, local servers, Anthropic providing updates, and subsequent generations of the underlying model, which itself is subject primarily to US law.
The combination of those components makes old definitions of sovereignty complicated. The capability that Australia seeks emerges from the continuing relationship among each of them. The question of sovereignty in the age of frontier AI requires control over the process of the formation of capabilities because the security boundary has moved from the document to the pipeline.
Ultimately, Marles’ insistence on making Australia the second home of frontier AI capability is a real one. But it is insufficient as a measure of technological sovereignty over important capabilities.
Local staff can build expertise. Domestic investment can create leverage over major companies. But Australia has to define a position in the continuing process through which AI capability evolves.
That requires three things. Australia needs arrangements that provide continued operational access and transitions between generations of models. There must be clarity about who has rights to models developed using Australian protected information. And Australia must define what capability it has to evaluate and manage any changes to the underlying models or safeguards that its fine-tuned models use.
The achievement of 20th century alliance building was in constructing institutions that allowed for sharing extraordinarily sensitive national security information to circulate among close allies while preserving national control.
The next problem lies in how allies jointly develop and exchange capabilities produced from shared technology without losing meaningful national control over them.
The test of that sovereignty cannot merely be where the data centre is located. The crucial question is whether Australia can retain control as secrets are turned into changing capabilities.
About the author
Cory Alpert
Cory Alpert is a PhD researcher at the University of Melbourne, where he studies the impact of AI on democracy. Previously, he served in the Biden White House for three years and as the senior adviser to Mayor Steve Benjamin.