SDA Bocconi Insight Logo
Knowledge

AI geopolitics: When access to models becomes a business risk

geopolitica

“Whoever becomes the leader in this field will rule the world.” Vladimir Putin said this in 2017, speaking about Artificial Intelligence to an audience of Russian students. For years it sounded like a striking line, with the usual rhetoric about the technology race. Then Mythos arrived.

In the first part of this series, we described the story of Anthropic's model capable of finding (and potentially exploiting) thousands of vulnerabilities in the digital infrastructure on which much of today's world rests, and the block imposed by the U.S. government in June 2026 on its “twin” model, Fable 5.

That block opened a question that goes far beyond corporate cybersecurity: when a model can find and strike the flaws in the systems that keep banks, hospitals and power grids running, “who controls it and who can use it” is no longer a commercial issue, but a lever of power between states.

The “stack” of power

Artificial Intelligence is not a single thing: it is a stack of overlapping layers — commonly referred to as the AI stack. At the bottom are the chips, the silicon that makes it possible to train models. Above that is compute capacity: the data centers (and therefore the cloud) where those chips are run. Higher up are the models themselves. And at the top is access: who can use them, under what conditions, and within which boundaries.

For more than a decade, the battlefield was silicon. The United States built an elaborate export-control regime to prevent China from buying the most advanced chips. Beijing, for its part, responded by moving a growing share of compute on domestic hardware, although its champions (Huawei, SMIC) are still quite far from the frontier.

The real novelty is that export control has moved up the stack. It is no longer only the machines that are controlled, but the models themselves: with Mythos/Fable, in June 2026, access to a cyber-capable model (that is, capable of conducting offensive cyber operations) was, for the first time, restricted on the basis of nationality. It is the moment when AI stopped being just a product and became a dual-use technology (civilian and military at the same time): something that a state can claim the right to govern because it touches national security.

Anyone who follows AI closely will not find all this particularly surprising. In June 2024, Leopold Aschenbrenner , a former OpenAI researcher, dismissed after raising internal alarms about security, published Situational awareness: the decade ahead , a 165-page essay that circulated widely in Silicon Valley. For some, the most important text of the decade; for others, an extreme and decidedly fatalistic work. The central thesis of Situational Awareness is that achieving AGI (Artificial General Intelligence, a form of AI capable of matching human cognitive flexibility and learning any intellectual task) by 2027 is “strikingly plausible”. From this follows a political consequence: the race to A(G)I becomes a matter of national security.

Two chapters of the essay, read again today, seem like the screenplay of the Mythos case. The first is Lock down the labs , on the need to lock down the most advanced AI labs because frontier models should by now be considered state secrets to be protected from espionage. The second is The free world must prevail , based on the idea that the free world, understood as the West and more specifically as the U.S. and its sphere of influence, must come first in the race to AGI — if necessary, even through direct government intervention. When the U.S. Department of Commerce excluded foreign citizens from access to Fable, it was putting into practice a logic that had been debated in San Francisco for two years.

It is worth adding a side note. In the meantime, Aschenbrenner has launched a thematic investment fund that has exceeded USD 20 billion in assets under management, starting from around USD 225 million in September 2024 and posting a return of more than 1,000% since launch. Today, the fund's largest position is Anthropic itself, accounting for around one fifth of the portfolio. In other words, the people trying harder than most to predict the outcomes of this race are also the ones betting the most on it.

But Aschenbrenner was not alone. In January 2025, the arrival on the market of DeepSeek — the first major Chinese generative AI model — fueled accusations that China was trying to exploit, to its own advantage, capabilities developed by OpenAI and other leading U.S. labs. In that context, Anthropic CEO Dario Amodei published On DeepSeek and export controls , arguing that well-enforced controls are the only thing capable of determining whether the AI world will be “unipolar” (with the United States and its allies firmly in the lead) or “bipolar” (with China on equal footing). In March 2025, Dan Hendrycks (of the Center for AI Safety), former Google CEO Eric Schmidt and Scale AI's Alexandr Wang published Superintelligence strategy , proposing a concept destined to spark debate: Mutual Assured AI Malfunction (MAIM). According to the concept, we will soon enter an era of AI deterrence modeled on nuclear equilibrium, in which any attempt by one state to achieve dominance in AI would be neutralized by rivals' sabotage. And sabotage, the authors note, passes above all through cyberattacks. Put differently: the ability to breach others' systems is not only a corporate problem; it is also the tool with which states will keep one another in check.

Europe's dependence

While around forty U.S. organizations and the UK AI Safety Institute already had access to Mythos through Project Glasswing, discussed in the previous article, the European Union remained excluded. ENISA, the European Union Agency for Cybersecurity, had to negotiate for weeks to obtain access to Project Glasswing as the first EU institution. In the meantime, the European Central Bank urgently convened Eurozone banks after learning that Mythos had identified vulnerabilities in financial software used widely across the area. It is hardly surprising that soon afterward a giant such as BNP Paribas officially announced a three-year extension of its partnership with Mistral, probably the most advanced European company in AI as of today.

There is also an aspect here that overturns centuries of power logic. Project Glasswing is, in effect, a national-security coalition managed by a private company. The Pentagon, according to several reports, is using Mythos to secure U.S. government systems; allied governments are negotiating to access it; and, not least, the U.S. civilian cybersecurity agency (CISA) appeared to be on the margins of the discussion, while large private companies were inside. The center of gravity is shifting, with private entities increasingly able to influence the innovation policies of entire nations. Governments face the difficult task of having to formalize a relationship with frontier AI labs without yet having form rules on how to deploy a dual-use technology such as this one.

And what about those that are not States?

All of this may seem like a matter reserved for states and large laboratories. But it is not: the geopolitics of AI enters directly into the balance sheets and risk registers of any company. For those in the boardroom, it translates into three very concrete implications.

The first is the most brutal: a capability on which the organization depends, perhaps critically, can disappear overnight by decision of a foreign government. The June block lasted nineteen days, but it was enough to show that “what if it goes dark tomorrow?” is a Board-level question, not an IT-department question. Translated into action: operational continuity must be rethought to include a geopolitical breaking point.

The second concerns the organization's position relative to the “poverty line” discussed in the first part. In the next few years, it is reasonable to assume that some companies will have access to frontier AI models; others will have to make do with a lower-quality stack. In this scenario, redundancy becomes balance-sheet prudence: multiple providers, open-source alternatives and, above all, contracts that include continuity clauses, data residency and exit routes. Deciding where to run models is no longer a procurement and IT detail, but a strategic choice that senior leadership must oversee directly. This is also due to the current gap between frontier proprietary models and open-source alternatives. Although open models are becoming increasingly capable and credible, they still tend to lag behind in performance, a limitation that can result in greater exposure to risk.

The third implication is less obvious, but no less relevant: regulatory compliance is fragmenting along geopolitical blocs. Those operating across multiple jurisdictions will have to reconcile sometimes incompatible rules on how AI can be used, including in security contexts. Ignoring this means risking the discovery that one is out of compliance in a key market.

For a single organization, in short, geopolitics now helps define the playing field: which models it will be able to access, at what cost and under whose rules. This makes the operational question we will address in the final part even more crucial: how to rebuild the security model when AI and automation become structural components of both attack and defense.

The opinions and reflections presented in these articles draw on a series of discussions held over recent months within the Corporate Information Security Roundtable , an initiative involving European and American Chief Information Security Officers, as well as on the research activities of DEVO Lab , SDA Bocconi’s laboratory dedicated to studying innovation and the adoption of new technologies in companies.