AI generated by the author. On 12 June 2026, at 5:21 PM US Eastern Time, a single letter from the United States Department of Commerce switched off two of the most capable AI models on Earth for every non-American on the planet. Not a country. Not a sanctioned entity. Not a company on a blacklist. Nationality itself. Anthropic had ninety minutes to comply. It could not verify citizenship for hundreds of millions of users in ninety minutes, so it did the only thing it could do - it turned Claude Fable 5 and Claude Mythos 5 off for everybody. Including its own non-citizen employees. (The Conversation, Lawfare, IAPP) Eighteen days later, on 30 June, the restriction was lifted. But the lesson was already delivered, permanently, to every CIO, every CTO, every defence ministry, and every founder on the planet. The technology never stopped working. Your permission to use it did. If you are still running your company's crown jewels through somebody else's API endpoint in July 2026, you are not running a technology strategy. You are running a hostage situation - and you are the hostage. The Mission-Critical Nature of Local AI AI generated by the author. Let us start with the thing nobody in your leadership meeting wants to say out loud.Every single prompt you send to OpenAI, Anthropic, or Google leaves your building. Every one. Your merger memo. Your unreleased source code. Your patient records. Your legal discovery. Your salary bands. Your unfiled patent. Your customer list. Even your incident post-mortem that names the exact vulnerability you have not patched yet. All of it travels across a wire, lands on infrastructure you do not own, in a jurisdiction whose laws you did not vote for, governed by a terms-of-service document that can be revised on a Tuesday. Yes - the transport is encrypted. Yes - the vendors are serious about security. Yes - most of them have excellent engineers. I am not disputing any of that. I have worked with these systems for years and I respect the people who build them. But encryption in transit is not sovereignty. Encryption at rest is not sovereignty. A SOC 2 report is not sovereignty. Sovereignty is a very simple, very old question: who can compel access to this data, and can I stop them? If the honest answer is "somebody else, and no" - then you do not have sovereignty, not even a shadow of it. And if you are a Ministry of Defence, an intelligence directorate, a nuclear regulator, a central bank, a defence contractor, or a frontier research lab, sovereignty is mission critical. A must-have. Do you want your weapons telemetry on a rented server? Do you want your counter-terrorism analysis in someone else's inference log? Do you want your national payment rails reasoned about by a model you cannot audit, hosted in a country that can revoke your access in ninety minutes? No? Then you need your own model. On your own metal. Under your own law. Every country needs one. Every defence department needs one. Every serious enterprise needs one. If you have been asleep on this - wake up now! No Cloud Server Is Safe - And 97% of Breaches Are Never Publicised AI-generated by the author Now, this is the part where somebody always tells me I am being alarmist.I am not. Not at all! The 2026 breach record is a list of reported breaches. Unreported breaches are much higher! The Salesloft-Drift campaign in August 2025 compromised OAuth tokens and reached 700+ organisations - including Cloudflare, Palo Alto Networks, and Zscaler. No exploit. Just stolen tokens and patience. (Cyber Defense Magazine) Gainsight, November 2025 - reportedly another 200+ Salesforce instances. Same playbook. Same crew. Same result. Through 2026, ShinyHunters ran a sustained extortion campaign against SaaS and CRM platforms, exfiltrating at scale from Salesforce and Microsoft 365 environments, almost entirely through vishing against Okta, Microsoft Entra, and Google SSO accounts. (Strobes, PKWARE) Charter Communications confirmed a breach in May 2026 traced to one social-engineering phone call that compromised a single employee's Entra account. Monitoring later tied the exposed dataset to 4.9 million accounts. (Bright Defense) Cloud-conscious intrusions rose 37% year over year in 2025, and organisations reporting significant cloud breaches jumped 154%. One in four global cyberattacks now targets cloud environments directly. (StationX cloud security statistics, 2026) And here is the one that should end the debate in any government building. In July 2025, a SharePoint zero-day chain was exploited across 400+ organisations, and the victim list included the U.S. National Nuclear Security Administration - the agency responsible for designing and maintaining the American nuclear stockpile. Microsoft attributed the activity to Chinese state-linked actors Linen Typhoon, Violet Typhoon, and Storm-2603. (Reuters/Bloomberg, Dark Reading, Microsoft Security) I want to be scrupulously honest with you here, because credibility matters more to me than drama: no classified information is known to have been compromised, and the NNSA said impact was minimal. I am not going to tell you launch codes leaked. They did not - as far as any public record shows. But read the sentence again anyway. Attackers reached inside the perimeter of the agency that builds nuclear weapons - through commodity enterprise software. Not through a spy. Through a patch cycle. Now let me address your instinct that the breaches you read about are the whole picture. They are not. They are not even close. Peer-reviewed research modelling under-reporting against cyber-insurance claims data - which is the closest thing we have to a complete dataset - estimates that only approximately 3% of all cyber incidents ever appear in public breach databases. (Risks, MDPI, 2022) The U.S. Department of Justice has put the figure at roughly one in seven cybercrimes being reported at all. (Anapaya summary) And EY's disclosure analysis found that out of 74,098 Form 8-K filings in 2020, exactly 40 reported a material cybersecurity incident - in a year Verizon counted 3,950 confirmed breaches. (EY analysis) So when I said in my outline that most breaches are never publicised, I was being conservative. The truth is worse than 80/20. The truth is closer to 97/3. Every headline breach you have ever read about is the visible 3%. What do you think is in the other 97%? The Jurisdiction Question - And Yes, That Includes the CCP AI generated by the author I want to handle this section carefully, because it is where most writing on this topic collapses into noise.The issue is not that Chinese engineers are bad engineers. DeepSeek, Qwen, MiniMax, Kimi, and GLM are genuinely excellent pieces of work. I have said so publicly and I will keep saying so. The issue is law. China's National Intelligence Law of 2017, Article 7, states that all organisations, companies, and citizens shall support, assist, and cooperate with national intelligence work. There is no carve-out. There is no requirement to notify the data owner. There is no court order to contest. (Analysis, Information Security Media Group) DeepSeek's own privacy policy states that user data is stored and processed in the People's Republic of China. That is not a rumour. That is the published terms. And governments moved accordingly. DeepSeek has been banned or restricted on government devices in Italy (nationwide), Australia, Taiwan, South Korea, Canada, India, the Czech Republic, and at least seventeen U.S. states, with a bipartisan federal "No DeepSeek on Government Devices Act" introduced in Congress. (Newsweek, National Law Review, NBC News) And Wiz Research found an exposed ClickHouse database belonging to DeepSeek containing over a million records - chat histories, API keys, backend logs - with no authentication at all. But Thomas, you might say - you are just doing the standard ideology of pointing at China. No. I am not. Check this out! The U.S. CLOUD Act reaches data held by U.S.-domiciled providers regardless of where that data physically sits. In June 2025, Microsoft's own Director of Public and Legal Affairs in France testified under oath before the French Senate that Microsoft could not guarantee that French public-sector data stored in Microsoft's French data centres would never be transmitted to U.S. authorities without the French government's consent. (Cloud Security Alliance Lab Space, DanubeData) Read that again. Data in France. In a French region. Marketed as sovereign. And the vendor's own lawyer says under oath that sovereignty cannot be guaranteed. That was the moment European policy changed forever. The European Commission's Tech Sovereignty Package and the Cloud and AI Development Act (CADA), introduced 3 June 2026, now define a four-level sovereignty framework for sensitive public-sector workloads precisely because contract language cannot override jurisdiction. (Computerworld, BISI) So here is my actual position, and it is symmetrical: Beijing can compel Chinese providers. Washington can compel American providers. Brussels can compel European providers. That is not a moral judgment. That is how sovereign states work. It has always been how they work. The mistake is not choosing the wrong flag. The mistake is believing that renting intelligence from any flag is the same as owning it. The Kill Switch Was Not a Theory. It Was Thrown. Everything I have written above was, until June 2026, a risk argument.Then it became a case study. The Commerce Department's Bureau of Industry and Security, under Secretary Howard Lutnick, issued a directive under the Export Control Reform Act of 2018 - a law drafted with uranium centrifuges in mind - and applied it, for the first time in history, to access to a software service. (Mondaq / Mayer Brown, HSF Kramer) The trigger was a reported jailbreak that could strip the cyber guardrails off Fable 5 and Mythos 5 - enabling zero-day discovery and working exploit generation. The response was total. Foreign nationals, inside or outside the United States. No negotiation. No appeal. No advance notice. And when access was restored on 30 June, it came with hardened guardrails that reportedly caused a measurable collapse in benchmark scores - lower capability, delivered to the same paying customers, by regulatory necessity. Now think about what a foreign enterprise learned that month. You can be a paying customer in good standing. You can have production systems, agents, and pipelines built on the API. You can have signed contracts, SLAs, and enterprise support. And you can lose all of it in ninety minutes because of a policy conversation you were not invited to, in a capital city you do not live in. The Lawfare analysis put it perfectly: a deployed commercial AI model is not enriched uranium that can be physically contained without consequence. It is a service on which hundreds of millions of people have built dependencies - and when Washington demonstrates that access can vanish overnight, it teaches every government and every foreign business on Earth that depending on American AI is itself a risk. That is the sentence that will define the next decade of AI procurement. And this is not a one-off. In 2025, Commerce restricted chip-design software sales to China, then rescinded the restriction six weeks later as trade negotiations shifted. On. Off. On. A lever, not a policy. (Cirran) A 2 June 2026 Executive Order then created a pre-release review framework for advanced AI systems, and OpenAI's GPT-5.6 series launched into limited preview for trusted partners whose participation had been shared with the government. Government review is now a release dependency.. What If Both Washington and Beijing Turn Off the Tap? AI-generated by the author Now let us game out the scenario that keeps me up at night, and that almost nobody outside defence circles is modelling honestly.Today, the global AI supply looks roughly like this: a small number of U.S. frontier labs at the capability ceiling, and a flood of Chinese open-weight models underneath them eating the volume. The numbers are extraordinary. On OpenRouter, the largest neutral model router, Chinese open-weight models went from under 2% of token traffic in late 2024 to roughly 61% by May 2026. Four of the five most-used models are Chinese. Meta's Llama, which led the open-weight world two years ago, has fallen off the rankings entirely. (Data Gravity, Lawfare) So picture a bad month. Not a war. Just a bad month. A Sample Scenario: A serious AI-enabled cyber incident is attributed to a foreign actor. Washington extends the June 2026 precedent from one company to the whole frontier tier - licences required for foreign access, no exceptions. Simultaneously, Beijing decides that open-weighting frontier-class Chinese models is a strategic gift it can no longer afford, and the Qwen, DeepSeek, GLM, Kimi, and MiniMax releases simply stop. What breaks? Everything downstream of an API key. Your customer support automation. Your document processing. Your coding agents - and remember, programming rose from about 11% of OpenRouter usage in early 2025 to more than 50% by mid-2026. Your fraud screening. Your clinical summarisation. Your translation layer. Your national language services. Every AI service your company relies on! Every country that treated AI as a utility bill instead of infrastructure discovers, in a single quarter, that it has outsourced cognition itself. Now ask the question your board should already have asked: If both taps closed tomorrow, what would still run inside your building? If the answer is "nothing" - you do not have an AI strategy. And there is a second-order effect that is even more important, and it is the deep irony of the whole story. Export controls did not slow China down. They forced China to build a cheap, open, self-sufficient stack - and then give it away for free. Denial produced the exact competitor it was designed to prevent. Every Country and Every Enterprise Needs Its Own Local LLM AI generated by the author The good news - and there is enormous good news - is that the world already figured this out and started spending. Sovereign AI in 2024 was an aspiration. In 2026, it is a budget line in most of the G20. United Kingdom: £1.1bn committed, including £750m for a national AI supercomputer and £400m for advanced AI chips. (Computing) European Union: €20 billion mobilised for the AI Gigafactory programme, plus the CADA sovereignty framework. Canada: CAD 925.6 million over five years for sovereign public AI infrastructure, plus the AI Sovereign Compute Infrastructure Program launched April 2026. India: the most pluralistic sovereign AI architecture on Earth - BharatGen at IIT Bombay, AI4Bharat at IIT Madras, Sarvam AI in the private sector, all under the IndiaAI Mission. (PDP Spectra) France (Mistral), UAE (G42/Falcon), Saudi Arabia (HUMAIN), Singapore (SEA-LION), Japan (LLM-jp) - all national programmes, all live. The sovereign AI infrastructure market was USD 24.8 billion in 2026, projected to reach USD 301.6 billion by 2040. (Roots Analysis) And yet - here is the gap that should terrify every board - only 29% of organisations are treating sovereign AI as a concrete near-term priority, even though 95% say it matters to their operations. (The AI Forest) Ninety-five percent know. Twenty-nine percent are doing anything about it. That gap is where the next decade's catastrophes live. And I have to say the honest thing here, because I am not selling anything: on-premise is not automatically safe. The NNSA breach happened on an on-premise SharePoint server. Self-hosting a model badly, on an unpatched box, with over-permissioned service accounts, is not sovereignty - it is a different address for the same disaster. Sovereignty means control plus competence. But you cannot have security without control. Control is the floor. Everything else is built on it. Why American Firms Must Go Open Weight - Aggressively, and Now AI generated by the author Meanwhile the American answer at the top of the open-weight stack was, until three weeks ago, embarrassingly thin, except for Nvidia’s Nemotron lineup off an entire family of LLMs.Then July 2026 happened. On 15 July, Thinking Machines Lab - Mira Murati's outfit, founded barely two years ago - released Inkling, its first model trained from scratch with the full weights published. Apache 2.0. A Mixture-of-Experts transformer with 975B total parameters and 41B active, pretrained on 45 trillion tokens of text, images, audio, and video, reasoning natively across all four. Context window of 256K on their Tinker platform and a full 1M on the Hugging Face weights. (Thinking Machines Lab, TechCrunch, Simon Willison) It debuted at 41 on the Artificial Analysis Intelligence Index - the leading open-weights release from any U.S. lab. Look at what it displaced: Inkling - 41 NVIDIA Nemotron 3 Ultra - 38 (the previous American leader) Google Gemma 4 31B - 29 OpenAI gpt-oss-120b - 24 (Artificial Analysis) And it is not just a leaderboard number. Inkling beats both Kimi K2.6 and DeepSeek V4 Flash on agentic work - 1238 Elo on GDPval-AA v2 against 1190 and 1189 - while burning 25K output tokens per Intelligence Index task where GLM-5.2 burns 43K, Kimi K2.6 burns 38K, and DeepSeek V4 Pro burns 37K. Cheaper thinking, not just better thinking. Native image and audio input is a real differentiator in open weights. And a preview of Inkling-Small at 12B active parameters is already shared, for the people who do not have a rack to spare. There is one more thing in that release that nobody should skip past: Thinking Machines explicitly trained Inkling to answer directly on topics that may be subject to censorship. Think about what that sentence means for a ministry in a small country choosing its national model lineage this year. The rest of the American stack finally has company too. OpenAI's gpt-oss-20b and gpt-oss-120b remain Apache 2.0 with 128K context, running happily on Ollama, vLLM, and llama.cpp - gpt-oss-20b fits in 16 GB of memory and gpt-oss-120b in 80 GB. (OpenAI Help Center) NVIDIA ships Nemotron with weights, training data, and recipes. Google ships Gemma 4. That is a real ecosystem. But to be honest about the scoreboard: GLM 5.2 sits at 51 on the Intelligence Index. Inkling sits at 41. DeepSeek V4 Pro scored 80.6% on SWE-bench Verified, the top open-weights result on Earth. Chinese open-weight models still carry roughly 61% of routed tokens on OpenRouter. Inkling narrowed the gap by three points against the previous American best - and even Thinking Machines said plainly it is not the strongest model available, open or closed. They positioned it as the best base for customisation, which is a far smarter bet than a leaderboard win. So this is not a victory lap. This is the first serious American open-weight release that a sovereign buyer can actually build a twenty-year dependency on. There need to be twenty more like it. And the pressure is already political. On 22 July 2026, the Little Tech Association - nearly 200 companies including Proton and Y Combinator - wrote to Trump, Lutnick, and Kratsios warning that banning Chinese open-weight models such as Kimi would kill startups without slowing proliferation by a single day. (ExplainX) They are right, and the reason they are right is the whole thesis of this article: you cannot ban a downloaded file. You can only out-ship it. Because every hospital in Kenya, every ministry in Vietnam, every startup in Brazil, and every bank in India that stands up its first local model this year is choosing a lineage. They are choosing tokenisers, prompt conventions, fine-tuning ecosystems, safety tooling, and a two-decade dependency chain. Whoever's weights they download today owns the stack they build tomorrow. The first company and country to be everywhere - wins. A reasonable question - if you give the weights away, how does anybody make money? Ten ways. Off the top of my head. Managed and dedicated inference. Sell the weights for zero and the uptime for plenty. Nobody's ops team wants to run a 120B MoE at 99.99%. Mistral, Together, Fireworks, and Baseten all live here. Enterprise licensing and indemnification. Free for everyone under 700M MAU; a real contract, real IP indemnity, and real legal cover above it. Meta's community licence proves the model works. Hardware pull-through. NVIDIA gives away Nemotron weights, training data, and recipes - because every download eventually needs Blackwell silicon underneath it. Open weights are the world's best GPU marketing. Sovereign national deployments. Governments will pay eight and nine figures for weights they can own, air-gap, fine-tune on classified corpora, and audit line by line. This is the single largest untapped revenue pool in AI. Fine-tuning and post-training platforms. The weights are free. Turning them into your model - QLoRA runs, domain adaptation, evaluation harnesses, RLHF pipelines - is a product. Compliance, safety, and audit tooling. EU AI Act Article 50 obligations, model cards, provenance, red-team reporting, watermarking. Regulated buyers will pay for the paperwork more reliably than for the model. The open-core split. Weights open, agentic scaffolding closed - memory systems, tool routers, orchestration, observability. The intelligence is the commodity; the harness is the moat. Distillation-as-a-service. Sell the pipeline that compresses your frontier model into a 4B SLM that runs on a factory-floor edge device at 40 tokens/second. Certified device and appliance channels. A sealed inference appliance, pre-loaded, pre-hardened, FIPS-validated, sold to hospitals, courts, and defence primes who will never touch a cloud endpoint. Ecosystem gravity and talent capture. Every researcher who builds on your weights is running a free experiment for you, publishing free documentation for you, and interviewing for you. Llama did not make Meta money directly. It made Meta the default - and defaults compound. Free weights. Paid everything else. That is the oldest winning strategy in software history, and the West is currently losing a race it invented. Apple Had the Right Idea - And Was Simply Too Early Ai generated by the author I want to give credit where it is overdue.Apple bet on on-device intelligence when the entire industry was sprinting toward the biggest possible model in the biggest possible data centre. They got mocked for it. The models were small. The capability lagged. The reviews were brutal. They were not wrong. They were early. Because the direction of travel is now unmistakable. The rule of thumb for local deployment in 2026 is roughly half the parameter count in gigabytes at 4-bit quantisation - a 14B model wants about 8 GB, a 70B wants about 40 GB. Consumer hardware crossed 24 GB years ago. Unified-memory machines cross 128 GB today. (Layer3Labs) Meanwhile GLM 5.2 sits at the top of the open-weight Intelligence Index at 51, roughly five points below Claude Fable 5, and DeepSeek V4 Pro scored 80.6% on SWE-bench Verified - the top open-weights score, matching GPT-5.5-class agentic performance. (OpenRouter) The gap between "the best model on Earth" and "the best model you can own outright" is now measured in single-digit index points and about eighteen months. That gap is closing. It will keep closing. So here is my forecast, and I will put my name on it. By 2028, every user, every enterprise, and every country that wants one will have their own model - running on hardware they control. Not a chatbot. A colleague. Local. Private. Fine-tuned on your life, your language, your institution, your law. Your data never leaves your device. Your intelligence never needs permission. This is my prediction - and I stand by it. But What About the Terrible Things People Will Build? Ai generated by the author Now; for the other side of the coin - and I refuse to write this article without it.Open weights mean guardrails can be removed. Not bypassed. Removed. Fine-tuned away in an afternoon on rented GPUs. And people are already doing terrible things with what exists today. Deepfake attacks rose 2,100% globally, per Sumsub's Identity Fraud Report 2025–2026. The Arup deepfake video call in Hong Kong cost one company USD 25 million across 15 transactions - impersonating multiple colleagues in real time. The FBI's first standalone AI-fraud category logged USD 893.3 million in adjusted losses from 22,364 U.S. complaints in 2025. Deloitte projects U.S. generative-AI-enabled fraud losses reaching USD 40 billion by 2027, up from USD 12.3 billion in 2023. Humans detect high-quality deepfakes at roughly coin-flip accuracy, and detection tools lose 45–50% of their lab accuracy in the real world. "Nudify" bots on Telegram reached about 4 million monthly users, and South Korea recorded roughly 297 deepfake sex crimes in the first seven months of 2024 alone. (StationX, Keepnet, Bright Defense, Digital Applied)Deepfakes are the entry level of this problem.The June 2026 export control was not triggered by a fraud scam. It was triggered by a model that could find zero-days in critical infrastructure that human researchers had missed for decades. So I will say plainly what I actually believe, and it will annoy people on both sides: You should not open-weight the absolute frontier. Not yet. Not this year. Not while a single fine-tuning run can strip cyber guardrails off a model that outperforms national security researchers. But the tier below the frontier - the tier that runs a hospital, a court, a school system, a ministry, a mid-size manufacturer? Open it. All of it. Aggressively. Immediately. If the guardrails are baked into the base weights - If safety tooling ships alongside every release - If provenance and watermarking become table stakes - If national deployments carry audit obligations - If the release tier is matched honestly to the capability tier - Then we get sovereignty without arming the arsonists. That is a hard engineering problem. It is not an impossible one. Gpt-oss-safeguard, the ROOST Model Community, and the EU AI Act's Article 50 obligations are the first honest attempts. We will need many more. But difficulty is not a reason to stop. Difficulty has never been a reason to stop. What To Actually Do On Monday Morning AI-generated by the author Enough theory.Here is the work. Run the tap-off drill. Assume every external AI API is dark for 30 days starting tomorrow. Which systems fail? Write the list. Show it to your board. That list is your sovereignty roadmap. Inventory your AI OAuth grants. "Allow All" is the new misconfigured S3 bucket. Most organisations have no idea which AI tools hold elevated access to their cloud. Find out this week. Classify workloads by jurisdiction exposure, not by sensitivity alone. Ask the Stackscale question: if a judge asked today which jurisdiction governs your critical data, could you answer with a document? Stand up one real local model. One. Start with gpt-oss-20b or a Qwen3-class model on Ollama or vLLM. Prove the pipeline end to end - ingestion, RAG, evaluation, logging - before you argue about which model wins. Route by sensitivity, not by habit. Frontier API for public marketing copy. Local model for anything you would not email to a stranger. This is a routing table, not a religion. Budget for the second source. Fallback providers, staging windows, and customer-eligibility checks are now production architecture, not procurement paperwork. Fine-tune on your own corpus. A 14B model that knows your business beats a 400B model that does not. QLoRA on modest hardware gets you there faster than you think. Write the guardrail policy before you need it, and audit it like you audit financial controls. Start small. Start ugly. Start Monday. But start. Conclusion: Own Your AI (Enterprise/Country/Eventually - User) AI generated by the author I have spent years writing about this industry and I have never been more convinced of a single sentence than this one:Renting your intelligence to an external company that you have no control of is a ticking time bomb. Check the list below: Data. Weights. Compute. Law Control. Own all five, and you are sovereign. Own four, and you are exposed. Own none, and you are simply hoping that no letter arrives at 5:21 PM on a Friday. One such letter arrived. Ask Anthropic. Ask every foreign customer who woke up on 13 June 2026 to find the most capable tool they had ever used was gone, not because it broke, but because they were born in the wrong country. I was one of them. That is not a criticism of Anthropic, who had no choice and said so publicly. It is a description of the world we actually live in. And I remain, as always, an optimist - not in spite of this, but because of it. Because the answer already exists! The weights are downloadable. The hardware is affordable. The tooling is mature. The tutorials are free. A nurse in Coimbatore, a magistrate in Nairobi, a founder in São Paulo, and a defence analyst in New Delhi can all run capable intelligence on machines they own, in languages they speak, under laws they voted for. The most decentralised transfer of capability in human history, and it is happening right now, in public, and almost nobody is paying attention. The countries and companies that move in the next eighteen months will spend the following twenty years being copied. The ones that wait will spend those twenty years asking permission. Own your AI. It has never mattered more. All the very best - and God bless you all! References and Further Reading The June 2026 export control action The Conversation — Legally or not, the US government is controlling global access to the world's most powerful AI — https://theconversation.com/legally-or-not-the-us-government-is-controlling-global-access-to-the-worlds-most-powerful-ai-286118 Lawfare — Will the New Export Controls Shake the Foundations of the U.S. AI Industry? — https://www.lawfaremedia.org/article/will-the-new-export-controls-shake-the-foundations-of-the-u.s.-ai-industry IAPP — US government order forces commercial suspension of two frontier AI models — https://iapp.org/news/a/thought-for-the-week-us-government-order-forces-commercial-suspension-of-two-fronteir-ai-models Mondaq / Mayer Brown — Commerce Department Extends Export Controls To Advanced AI Models — https://www.mondaq.com/unitedstates/government/1811352/commerce-department-extends-export-controls-to-advanced-ai-models-authorizes-release-to-specific-trusted-partners HSF Kramer — License to model: Emerging US rules impact global access to frontier AI — https://www.hsfkramer.com/insights/2026-07/license-to-model-emerging-us-rules-impact-global-access-to-frontier-ai Volkov Law — When the Government Pulls the Plug — https://blog.volkovlaw.com/2026/06/when-the-government-pulls-the-plug-anthropic-export-controls-and-the-future-of-ai-governance/ U.S. House of Representatives — Letter to Commerce Department on frontier model export controls, 18 June 2026 (PDF) — https://liccardo.house.gov/sites/evo-subsites/liccardo.house.gov/files/evo-media-document/6.18.26-letter-to-commerce-department-on-frontier-model-export-controls.pdf Cirran — The US just switched off a frontier AI model for foreigners — https://cirran.eu/blog/us-export-controls-frontier-ai Anthropic — official statement on restored access — https://www.anthropic.com/news/fable-mythos-access Breaches and the reporting gap Reuters / Bloomberg — US nuclear weapons agency breached in Microsoft SharePoint hack — https://www.reuters.com/world/us/us-nuclear-weapons-agency-breached-microsoft-sharepoint-hack-bloom Microsoft Security Blog — Disrupting active exploitation of on-premises SharePoint vulnerabilities — https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/ Dark Reading — US Nuclear Agency Hacked in Microsoft SharePoint Frenzy — https://www.darkreading.com/cyberattacks-data-breaches/us-nuclear-agency-hacked-microsoft-sharepoint CSO Online — Foreign hackers breached a US nuclear weapons plant via SharePoint flaws — https://www.csoonline.com/article/4074962/foreign-hackers-breached-a-us-nuclear-weapons-plant-via-sharepoint-flaws.html Risks (MDPI, peer-reviewed) — Modeling Under-Reporting in Cyber Incidents — https://doi.org/10.3390/risks10110200 EY Center for Board Matters analysis — Most Breaches Go Unreported — https://www.auditupdate.com/post/ey-s-annual-cybersecurity-disclosure-analysis-most-breaches-go-unreported Anapaya — The Unseen Problem of Unreported Cybercrime (DOJ one-in-seven figure) — https://www.anapaya.net/blog/the-unseen-problem-of-unreported-cybercrime Cyber Defense Magazine — Why 2026 Will Be The Year Of SaaS Breaches — https://www.cyberdefensemagazine.com/why-2026-will-be-the-year-of-saas-breaches/ Strobes — Top Data Breaches of April 2026 — https://strobes.co/blog/top-data-breaches-april-2026/ PKWARE — 2026 Data Breaches — https://www.pkware.com/blog/2026-data-breaches Bright Defense — List of Recent Data Breaches in 2026 — https://www.brightdefense.com/resources/recent-data-breaches/ StationX — Cloud Security Statistics 2026 — https://app.stationx.net/articles/cloud-security-statistics Jurisdiction, the CLOUD Act, and EU sovereignty Cloud Security Alliance Lab Space — EU Tech Sovereignty: Cloud Concentration Risk — https://labs.cloudsecurityalliance.org/research/eu-tech-sovereignty-cloud-ai-enterprise-risk-v1-0-csa-styled/ Computerworld — EU takes first steps to reduce reliance on US hyperscalers — https://www.computerworld.com/article/4181816/eu-takes-first-steps-to-reduce-reliance-on-us-hyperscalers.html BISI — EU Cloud and AI Development Act: Sovereignty, AI and US Tech Dependence — https://bisi.org.uk/reports/eu-cloud-and-ai-development-act-sovereignty-ai-and-us-tech-dependence Stackscale — Cloud sovereignty: which laws govern your company's data? — https://www.stackscale.com/blog/cloud-sovereignty-which-laws-govern-your-companys-data/ Kiteworks — How the EU Data Act and GDPR Conflict with US CLOUD Act Demands — https://www.kiteworks.com/gdpr-compliance/eu-data-act-gdpr-cloud-conflict/ DanubeData — The US CLOUD Act Explained (2026) — https://danubedata.ro/blog/us-cloud-act-european-alternatives-2026 China, the National Intelligence Law, and DeepSeek restrictions Information Security Media Group — Asian Governments Rush to Ban DeepSeek Over Privacy Concerns — https://www.bankinfosecurity.com/asian-governments-rush-to-ban-deepseek-over-privacy-concerns-a-27476 National Law Review — Three States Ban DeepSeek Use on State Devices and Networks — https://natlawreview.com/article/three-states-ban-deepseek-use-state-devices-and-networks NBC News — US lawmakers move to ban DeepSeek from government devices — https://www.nbcnews.com/business/business-news/us-lawmakers-move-ban-deepseek-government-devices-chinese-surveillance-rcna190965 Newsweek — US Ally Bans China's DeepSeek On Government Devices — https://www.newsweek.com/australia-bans-deepseek-national-security-ai-china-2025973 Alabama Attorney General — 21 AGs urge Congress to pass No DeepSeek on Government Devices Act — https://www.alabamaag.gov/attorney-general-marshall-urges-congress-to-ban-china-based-ai-platform-deepseek-on-government-devices/ Grand Linux — DeepSeek and China AI Risks (National Intelligence Law Article 7 analysis) — https://www.grandlinux.com/en/blogs/deepseek-risk-china-ai.html Open weights and the model landscape Data Gravity — China's Open-Weight Takeover — https://www.datagravity.dev/p/chinas-open-weight-takeover OpenRouter — The Open Weight Models that Matter: June 2026 — https://openrouter.ai/blog/insights/the-open-weight-models-that-matter-june-2026/ OpenAI Help Center — OpenAI open-weight models (gpt-oss) — https://help.openai.com/en/articles/11870455-openai-open-weight-models-gpt-oss Hugging Face — The Best Open Source and Open-Weight LLM Models to Run Locally in 2026 — https://huggingface.co/blog/daya-shankar/open-source-llm-models-to-run-locally Kingy.ai — State of Open-Weight AI Models — https://kingy.ai/blog/state-of-open-weight-ai-models/ Layer3Labs — Best Open-Weights AI Models for Business (2026) — https://www.layer3labs.io/open-weights/best-open-weights-ai-models Thinking Machines Lab — Inkling: Our Open-Weights Model (official announcement, 15 July 2026) — https://thinkingmachines.ai/news/introducing-inkling/ Artificial Analysis — Thinking Machines has released Inkling, the new leading U.S. open weights model — https://artificialanalysis.ai/articles/thinking-machines-has-released-inkling-the-new-leading-u-s-open-weights-model TechCrunch — Thinking Machines amps up its bet against one-size-fits-all AI with its first open model, Inkling — https://techcrunch.com/2026/07/15/thinking-machines-amps-up-its-bet-against-one-size-fits-all-ai-with-its-first-open-model-inkling/ Simon Willison — Inkling: Our open-weights model — https://simonwillison.net/2026/Jul/16/inkling/ AIwire / HPCwire — Thinking Machines Launches Open-Weight 'Inkling' Foundation Model for Fine-Tuning — https://www.hpcwire.com/aiwire/2026/07/16/thinking-machines-launches-open-weight-inkling-foundation-model-for-fine-tuning/ Axios — Mira Murati's Thinking Machines debuts its first AI model — https://www.axios.com/2026/07/15/mira-murati-thinking-machines-open-weight-model-inkling ExplainX — Inkling Open Weights — Thinking Machines Lab (2026) (includes the Little Tech Association letter, 22 July 2026) — https://explainx.ai/blog/inkling-thinking-machines-open-weights-july-2026 Sovereign AI programmes and market Computing — Government commits £1.1bn for sovereign AI infrastructure — https://www.computing.co.uk/news/2026/government/government-commits-more-than-one-billion-sovereign-ai PDP Spectra — Sovereign AI in 2026: Mistral, G42, HUMAIN, BharatGen, and the National-AI Map — https://pdpspectra.com/blog/sovereign-ai-initiatives-2026/ Roots Analysis — Sovereign AI Infrastructure Market — https://www.rootsanalysis.com/sovereign-ai-infrastructure-market The AI Forest — The Rise of Sovereign AI Data Centers — https://theaiforest.com/sovereign-ai-data-centers-whats-driving-the-2026-boom/ Forrester — 2026 European Predictions — https://www.forrester.com/press-newsroom/forrester-european-2026-predictions Deepfakes and misuse StationX — Deepfake Statistics 2026 — https://app.stationx.net/articles/deepfake-statistics Keepnet — Deepfake Statistics 2026: Verified Benchmarks & Risks — https://keepnetlabs.com/blog/deepfake-statistics-and-trends Bright Defense — 150+ Deepfake Statistics — https://www.brightdefense.com/resources/deepfake-statistics/ Digital Applied — Deepfake Statistics 2026: Fraud and Detection Data — https://www.digitalapplied.com/blog/deepfake-statistics-2026-fraud-detection-data Adaptive Security — Deepfake Statistics 2026 — https://www.adaptivesecurity.com/blog/deepfake-statistics-2026-the-data-security-leaders-need-to-know AI generated by the author Work With Me Consulting & 1:1 Sessions topmate.io/thomascherickal Digital Products thomascherickal.gumroad.com Exclusive Content & Early Access patreon.com/thomascherickal I work on technical writing, AI consulting, course collaborations, AI upskilling for individuals, AI mentoring at all levels, and CXO weekly AI training. Free to connect on LinkedIn.Newsletter: thomascherickal.kit.com Thomas Cherickal, 2026 · The Digital Futurist · thomascherickal.com · thomascherickal.github.io · Chennai, India The first draft of this article was generated by Claude Opus 5. All images were generated by NightCafe Studio.
Relying On Cloud AI Is Dangerous But Sovereign Local AI Is An Unstoppable Force
Full Article
Original Source
Read the full article at Hackernoon →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.