主权 AI:国家3-193的地缘政治战略与产业政策,Anjney Midha,a16z
主权 AI 不是一套已经定型的架构,而是对技术、法律和文化依赖控制权的要求。 对企业而言,这意味着知道工作负载位于何处、哪些政府可以强制调取数据;对国家而言,则意味着确保关键产业和日常生活中使用的模型不会植入对手的价值观。Anjney Midha 的宽泛定义是:“随着 AI 展开,尽可能掌控自己的命运。”
企业 AI 正在重新捆绑技术、实施与保险,而司法管辖区可能决定谁能赢下这套组合。 超大规模云厂商可以通过赔偿承诺吸收安全和合规风险;Midha 举的 CMA CGM 案例还涉及网络安全和版权风险。他认为,当美国《CLOUD Act》令美国供应商不可接受时,欧洲买家可能更偏好 Mistral。因此,采购问题不只是“谁的模型最好”,而是“他们买的是技术,还是保险?”
大多数国家今天都无法争夺前沿人才,但 Midha 不接受它们永远无法追上的说法。 他的 build-buy-partner 框架主张,短期通过合资获得即时接入,中期投资培养“前线部署的 AI 解决方案工程师”,并用10-20年时间建立本地预训练和后训练能力。当研究人员需要与 Meta 及其他前沿实验室竞价时,主权资产负债表可能必须出面,为这一生态播下种子。
每个国家都应将自身文化 token 化,然后把商品化的预训练与本地可防守的最后一公里分开。 Nathan Labenz 认为,政府应将经过筛选的语言和文化语料交给每一家领先开发商;Midha 赞同各国与他人合作完成预训练,最好基于 open weights,但保留本地产品化、持续后训练、分发和不可验证奖励的设计能力。他的检验标准很个人化:ChatGPT 用 Hindi 说话时,听起来“像一个来印度旅游的美国游客”,而不是本地人。
当前 open models 落后 closed frontier 的时间以月计而非以年计,这使通过后训练实现主权成为可能,但并非没有条件。 Midha 提到,从 o1 到 DeepSeek R1 只用了26天,认为中国跟进 reasoning 进展的窗口在60天以内,并将更广义的 open-versus-closed 滞后估计为约6个月或更短。他预计中国会继续将前沿模型开源,作为软实力工具;但 Labenz 强调,这依赖少数有国家或企业支持的参与者做出战略选择,而不是一个传统的开源社区。
AI factories 正在改写云计算经济学,并在定制芯片与 Nvidia 支持的“open scalers”之间制造战略竞争。 Midha 表示,GPU 在数据中心物料清单中的占比已从不到10%升至约60-70%;Amazon 缺少 GPT-4 替代品,推动其向 Anthropic 投资80亿美元,因为金额超过1亿美元的合同开始转向 Azure。Gemini–TPU 和 Anthropic–Trainium 的整合威胁 Nvidia,而 Nvidia 则通过 CoreWeave、Nebius、Mistral Compute 和地区性主权云回应。
中东能为美国提供资本、更快的建设速度、更低的每 FLOP 能源成本和地缘政治一致性,但基础设施承诺会累积影响数十年。 讨论称,相关交易要求美国进行一比一的基础设施投资;Midha 估计,在没有美国补贴的情况下,液冷 Blackwell 节点在 UAE 或 Saudi Arabia 的每 FLOP 能源成本可低约18-20%。他的战略警告是:“基础设施就是命运”:即使中国今天还无法提供等效系统,若头3-5年输给 Huawei,也可能决定未来30年。
1. 主权 AI 始于控制,而非某个标准定义
Midha 开场时的承认异常有用:“在各个地区,没有人拥有一个可用的主权定义。”让政策制定者界定主权,已经成了他让技术人员定义 AI agent 的对应问题——5个人通常会给出5个答案。
对技术人员而言,主权通常意味着模型和服务在本地或本地部署运行,不依赖由其他地方管辖的云基础设施。对国家领导人或大型企业 CEO 而言,范围更广:他们想要的是“随着 AI 展开,尽可能掌控自己的命运”。
一位欧洲 CIO 的版本是司法管辖权。目标是将 AI 工作负载放在不会自动受到外国“不必要的后门信息请求”影响的地方,尤其是在企业服务于多个监管体系下的客户时。
政府的版本则是文化。如果陪伴类产品和关键任务产业运行在由训练数据及后训练价值观塑造的模型上,领导人可能会把这些模型视为文化基础设施,要求其价值体系反映本国人口,而非敌对国家。
2. 企业买家采购的是能力,也是在购买一个承担责任的人
Midha 将企业还原为一个代表用户进行大额采购的组织。在云计算时代之前,CIO 会选择 Red Hat Linux 这类全公司基础设施,同时购买两样东西:技术,以及系统出问题时负责到底的支持。
自下而上的 SaaS 打破了这一模式。个人用信用卡采用 Dropbox、Slack 或 GitHub,合规和运营风险随后向上转移到 CIO 和首席合规官身上;接下来的10-15年,他们一直在追赶已经进入组织内部的产品。
超大规模云厂商通过提供安全保障和赔偿承诺,恢复了保险层。Midha 指出,如今 Azure 会为数项生成式 AI 服务提供赔偿,而两年前类似保护还不存在;买家获得运营层面的保障,直白地说,也获得了“你自己和团队的工作安全”。
关键任务客户可能仍希望由一家专业机构负责选择模型、管理部署并承担责任。他举的例子是 CMA CGM,这家全球第三大航运公司年收入700-800亿美元,不应为了自动化港口和货运运营,就被迫在 Mistral 7B、Mixtral、DeepSeek R1、reasoning models 和各种 reward designs 之间做选择。
3. 司法管辖权为本土 AI 供应商打开了对抗 Azure 的空间
Labenz 起初更倾向 Azure:企业已经把敏感数据托付给大型科技供应商,发送到 Azure 的查询可能比交给企业自建基础设施更能防范黑客。他提出的问题是,保守主义是否正在推迟企业获得更好技术的时间。
Midha 的分界线是对管辖该基础设施的司法体系是否信任。他的检验标准是:运行关键任务工作负载的客户,是否会接受他所说的美国法律可以依据《CLOUD Act》从美国云公司强制取得的访问权限;如果不能,那么即便本地基础设施成本更高,本地部署也具有合理性。
Labenz 的总结是——同时声明自己并不精通该法律的国际适用范围——买家仍然想要同一套技术、咨询和保险组合。欧洲客户可能只是更愿意从 Mistral 而非 Azure 购买这套组合。
Palantir 经常为美国关键任务工作负载承担这一角色,而 Mistral 正在成为欧洲对应的供应商。Midha 提醒,今天保险能力与前沿 open-model 性能未必来自同一家供应商。
4. AI 原生全栈正在拆解并重新捆绑云计算
Midha 将 Stargate 描述为一套整合式技术栈,覆盖芯片、数据中心、算力、模型和 ChatGPT。UAE 的安排把这一逻辑国际化:政府为居民提供接入资金,工作负载运行在以 OpenAI 为中心的国家级方案上,而不再只是传统的 Azure。
这颠覆了上一个云计算时代的组织逻辑。超大规模云厂商通过集中存储和 CPU 工作负载取胜,直到边际成本和抽象层优势让自建失去经济性;AI 公司现在则围绕模型和应用重新捆绑基础设施。
Mistral Compute 代表了 Midha 所说的新型“open scaler”:Nvidia 芯片部署在他所称的欧洲最大本地数据中心内,支持 Mistral 和其他 open models,同时让客户自由选择应用层。
因此,国家和企业再次面临 build-buy-partner 决策。它们可以购买完整的主权技术栈,与他人合作取得选定层级,或者自行掌握芯片、open weights、后训练、部署以及本土版 ChatGPT 界面。
5. 前沿之外的国家需要进入 token 流动
Labenz 将 Mistral 视为少见的国家冠军:虽然还没有站在前沿最尖端,但足够接近,能够保住欧洲的人才集中度。他怀疑,像 Brazil、Russia 或 Germany 这样人口众多的国家,无法在不浪费资本的情况下复制这种密度。
Midha 用战后金融体系回应。无法发行储备货币、也无法匹敌最大经济体的国家,仍然可以成为不可或缺的中介;Singapore 依靠稳定的法律、低腐败和营商便利,将自己嵌入全球美元流动。
他在 AI 领域对应的概念是“hypercenter partner nation”:一个不具备美国或中国规模、但主动进入 token、算力和 AI 服务流动的国家。战略选项仍然是“build、buy 或 partner”,但选择退出,就意味着接受主导中心分配的位置。
人才定价进一步强化了国家的角色。面对与 Mark Zuckerberg 竞价,本地私营公司“拿着小刀,没法参加那场火箭筒对决”,因此各国越来越多地动用主权资产负债表;由 UAE 支持的 G42 正在扮演类似 AWS 或 GCP 的基础设施角色,背后有国家资本支撑。
6. Gulf 希望用算力需求替代对油价的依赖
Midha 将 UAE 的战略与 Singapore 在中东原油精炼和增值转售中的角色相比。区别在于,Gulf states 已经拥有 petrodollars;它们的任务是把这些储备转化为 GPU 和持续的算力能力。
G42 的推销语实际上是“来这里运行你的工作负载”。未来30-50年,UAE 希望通过推理和数据中心收入,让本国 GDP 与油桶脱钩——Midha 说,地区决策者关注油价,就像美国人关注利率。
这套战略不只是拥有服务器。通过成为全球 AI 供应链中不可或缺的地点,该地区希望在传统资源优势减弱之前,获得需求、运营经验、合作伙伴关系和新的基础设施底座。
7. 人才主权是一张路线图,而不是一项5年采购计划
Midha 修正了 Labenz 的前提:大多数国家今天无法争夺前沿人才,但这并不能证明它们永久没有能力追赶。RL recipes 正在变得越来越公开——他提到 Mistral 的 Magistral 工作和 DeepSeek——但线上 RL 基础设施仍然包含大量靠实战积累的运营知识。
两人的时间判断仍未解决。Labenz 将可能出现的奇点放在约5年后;Midha 则区分 UAE 紧迫的5年规划与 Mexico 的20年时间尺度,并对“gentle singularity”而非瞬时的经济重写更有共鸣。
即便能力快速增长,Midha 认为各国仍需要能把模型接入真实工作流的人。他所说的“前线部署的 AI 解决方案工程师”理解业务领域、系统集成和 reward design,尤其能处理奖励无法客观验证的场景。
这一模式类似 India 在1992年与 Suzuki 的合作:外国能力通过 Maruti Suzuki 培训本地工人,随后本地控制权不断加深。Midha 认为 Saudi oil 也经历了类似转变,并主张美国的 AI 合作应带着盟友一起成长,避免它们转向 China。
8. 文化数据应在全球流动,实施则留在本地
Labenz 提出的捷径是一项国家数据计划:收集、整理并将文化和语言材料“放在银盘上”交给 OpenAI、Anthropic、Google 及其他前沿开发商。至少在未来2-5年,它们更强的通用训练系统应能胜过 Brazil 的国家级预训练尝试。
Midha 赞同眼下应把预训练外包。各国应将反映自身文化的语料 token 化,因为“如果你的文化没有被 token 化”,就只能依赖别人来代表它;随后与少数具备前沿预训练能力的团队之一合作。
他偏好以 open weights 为基础,因为这允许更深度地调整权重、进行 on-policy 更新和本地后训练。国家冠军真正可防守的工作,是分发、产品化、接入 healthcare、finance 或 defense,以及需要语境判断的 reward design。
他的 Hindi 体验提供了最鲜明的例子:ChatGPT 说话“像一个来印度旅游的美国游客”,带有外国的措辞和语言选择。本地供应商可以让助手听起来像本地人,即便基础模型来自海外;推理和持续后训练仍是需要不断锻炼的能力。
9. Open models 当前正在快速跟随 closed frontier
Labenz 提出类似 AI 2027 的风险:前沿开发商可能将训练规模扩大10倍、隐藏模型,从而制造一个本地后训练无法弥合的差距。届时,选择可能变成文化上不自然的前沿模型,或能力弱得多的本地化模型。
Midha 的反驳基于有时间边界的经验事实。他指出,从 o1 到 DeepSeek R1 只用了26天,称 China 能在60天内跟进 reasoning 进展,并表示观察到的 open-versus-closed frontier 一直大体同步,滞后在6个月以内。
即使在 o3 Pro 之后,他也没有看到最佳 closed system 与更新的 R1 之间存在不可逾越的阶跃式差距。他回忆说,在 DeepSeek 发布强大的 open models 已约8个月时,仍有专家告诉国会 US 领先 China 5-6年:“你们到底活在哪个星球?”
Labenz 的保留意见是制度性的:这些并不是由社区治理的 open-source projects。持续获得访问权取决于 Meta、中国企业和各国政府的战略选择,因此当前强大的快速跟随平衡并不保证永久存在。
10. DeepSeek 是中国软实力工具,Alibaba 则是其部署手臂
Midha 反对把 DeepSeek 视为传统的超大规模云厂商。他将其描述为一家对冲基金:在监管压力下即将关闭核心业务,于是转向前沿 AI 研究,并在与 Xi 会面后获得政治支持。
在他的基准情景中,中国政府会继续让一个前沿模型开放可用,因为全球采用会创造软实力。DeepSeek R1、Unitree humanoid 和 Ne Zha 2 构成了他所说的2025年前6个月中国文化与技术复兴的一部分。
稳态分工可能是:DeepSeek 吸引研究人才并“无情地 open source”,Alibaba 则将企业部署商业化。这样既能保留国家声望,也能通过分发创造 GDP,而不必迫使 DeepSeek 本身接受超大规模云厂商的经济模式。
Alibaba 的解决方案工程很关键,因为尽管 R1 在排行榜上表现强劲,但对企业而言“规模巨大且非常难用”。没有实施渠道,前沿模型不会自动扩散到经济体系中。
11. AI factories 将 Nvidia 与超大规模云厂商拖入新一轮技术栈战争
Labenz 的基准数据是:US 约占全球数据中心基础设施的45%,排名前25的国家合计占88%。Midha 预计,普通 CPU、存储和网络工作负载仍会集中化,但 AI 数据中心已经不再共享旧的物料清单。
他估计,GPU 目前约占数据中心的60-70%,而10年前还不到10%。因此 Jensen Huang 所说的“AI factory”不只是营销话术:物理设施和其承载的工作负载都已经改变。
模型接入如今可以转移大规模云工作负载。Midha 表示,Amazon 在2023年丢失金额超过1亿美元的合同、这些合同转向 Azure 后,向 Anthropic 投资了80亿美元,因为自身缺少 GPT-4 替代品;他当时是 Anthropic 的早期投资者之一,亲眼看到了一部分决策过程。
如果 Midha 的预测成真,即今年年底前3大模型中的2个——他指的是 Gemini 和 Anthropic——将在非 Nvidia 硬件上运行,那么 Gemini–TPU 和 Anthropic–Trainium 的整合就会威胁 Nvidia。Nvidia 的反击是 CoreWeave、Nebius、Mistral Compute 和地区性云组成的生态;Midha 认为未来18个月的“open scaler wars”仍然完全没有定论。
12. 本地算力是对地缘政治 404 的保险
对于本土基础设施很少的国家,Labenz 询问 AI 为什么应区别于进口云服务。Midha 的答案是战略自主:外部 API 在其管辖国家关闭服务之前都能运行,之后调用就会返回404错误。
正确范围应按工作负载划分,而不是追求完全自给自足。失去外国托管的娱乐内容或许可以接受;支撑 defense、healthcare 或其他关键任务产业的推理能力,则可能值得建设本地可控算力,就像各国会有选择地本地化 defense supply chains,却不会自行制造每一架飞机或每一辆坦克。
Labenz 的反驳值得保留:相互依赖可以抑制冲突。主权算力建设类似囚徒困境:每个国家都理性地降低依赖,但所有国家合计却在瓦解曾经提高战争成本的相互融合。
Midha 的答案是一项“AI 马歇尔计划”。美国必须承认中国挑战,同时继续成为稳定的伙伴;“运行在美国芯片上的 open models”可以让盟友在模型层获得主权,而不必转向 Huawei 的半导体技术栈。
13. 出口管制可能加速其试图遏制的 Huawei 生态
Labenz 质疑 China 是否真的能为海外 AI 建设提供供应,因为 DeepSeek 自己称 GPU 短缺正在限制发展,而国内需求可能会消化 Huawei 生产的一切。他认为,中国具备面向出口规模的基础设施能力还需要3-5年,不会立刻成为替代方案。
Midha 认为,制裁改变了发展轨迹,迫使 China 向 Huawei 投入主权资源。China 可能仍需3-5年才能具备前沿训练能力,但他认为,高效的2025 reasoning workloads 到年底就可能运行在 Huawei Ascend 芯片上,而推理能力可能在2-3年内实现脱钩。
他的明确保留是:“如果 DeepSeek R2 在未来某个时间发布,我不会感到意外的是”,它从第一天起就兼容 Ascend。分析上的错误,是冻结今天的能力差距,而不是追踪一棵如今已有国家资本和动机支持的5年技术树。
两位嘉宾都反对简单的遏制政策。Labenz 希望拥有独立的美国技术栈,但怀疑阻止 China 建立自己的版本是否有效;Midha 则主张广泛出口最好的美国技术,让采用本身携带美国影响力。
14. China 政策混合了真实的价值冲突与未解决的威胁模型
Labenz 认为,把 China 描绘成压倒性的威胁,同时又认为断供芯片后 China 永远无法追上,这两种叙事并不一致。Midha 的解释是路径依赖:AI 和半导体都是技术树,切断访问可能促使对手更早进入,并建设原本缺失的能力。
但 Midha 仍坚持建立独立的西方技术栈,因为对中国技术的依赖可能把中国式治理引入关键任务系统。工程能力并不能抹去他对该政府的描述——“最冷酷无情的威权政府之一”,而且经常伤害本国民众。
Labenz 记录的是一次真实的判断更新,而非假装确定。他仍对 China 的威胁保持开放态度,并提到一宗未经核实的 Detroit 机场事件:有人携带会损害农作物的真菌样本;他强调无法确定释放是否出于主观意图,但这件事让他此前偏鸽派的看法变得不再那么安稳。
两人都担心另一条主权轴线:基于人类偏好的 RL,可能以人类从未面对过的“速度和规模”,优化短视频或一对一助手的成瘾性。Midha 不希望外国政府控制面向 Americans 的这种优化。
15. 中东交易为美国买来资本、阵营一致与执行速度
Labenz 表示,相关 Gulf 基础设施协议要求在 US 进行一比一的配套建设。因此,Washington 获得外国直接投资、供美国公司使用的额外本土算力,以及该地区对美国而非中国技术栈的采用。
联盟逻辑受时间影响。Midha 表示,在 Biden administration 期间,芯片接入和本地 AI 生态的不确定性正推动 Gulf states 转向 China;由于“基础设施就是命运”,第一个供应商可以决定未来20-30年的标准和关系。
运营经济学同样重要。在对50%节省的说法打折后,Midha 估计,在没有政府补贴的情况下,采用油冷的 Blackwell 节点在 UAE 或 Saudi Arabia 的能源成本比 US 低约18-20%/flop。
Gulf 的治理方式压缩了建设周期。Midha 将 Europe 部分地区的情况与 UAE、Saudi Arabia 对比:前者的监管审批可能耗时2年,后两者则可以快速批准高速公路、数据中心和其他基础设施。
16. 物理安全可以管理,权重安全仍未解决
Labenz 询问 Gulf 设施由谁建设和控制、美国人员是否可能被召回、传闻中的远程关闭开关是否存在,以及可见的 gigawatt 级站点是否会隐性扩大美国防务保护伞。Midha 没有证实远程开关的说法,而是通过双重用途基础设施重新界定问题。
面向关键任务工作负载的前沿数据中心不必像巨型训练园区。由于训练和推理可以分开进行,这类部署可能规模很小,不会出现在普通申报文件中,也可以藏在类似百货商店的建筑内,而不需要把100,000块 Blackwell GPU 集中在一个地点。
一旦被发现,其物理防御将遵循所在国既有的反情报和空中防御体系。Midha 看不到专门针对 AI 的安全制度,也不认为这必然意味着新的美国安全承诺;问题在于 Saudi Arabia 或 UAE 能多有效地保护任何国家安全资产。
Labenz 提到,有中国公民因携带 TPU 设计图登机而被捕;Midha 回应说,他记得的是一名 Google 工程师,并认为美国前沿实验室内部不存在防止模型权重外泄的万灵药。“如果 China 想要这些权重,现在就能拿到。”
被刻意推迟的多米诺骨牌是 Taiwan。Midha 表示,Taiwan 未来2-3年的主权状态可能改写整个算力技术栈;他还担心出口管制会让重大行动更容易发生,Labenz 也曾提出类似论点。两人最后都警告,每个结论的“有效时间窗口正在越来越短”。
Today, we're exploring a fundamental question that governments around the world are wrestling with: If the United States and China are going to continue to dominate the fundamental AI inputs of talent, data, and compute, and thus own the AI capabilities frontier, what exactly should everyone else do?
My guest is Anjney Midha, general partner at Andreessen Horowitz, who brings deep software-industry investment expertise and a remarkable ability to channel diverse national perspectives on the opportunities and challenges of AI to the conversation. We begin by considering what sovereign AI means to the enterprise. I honestly hadn't planned on starting there, but it makes a lot of sense, considering the degree to which companies are both driving investment and adoption around the world and informing their respective governments' priorities.
Here, regulatory questions about which companies have to share what information with which governments, and under what circumstances, loom so large that U.S.-based hyperscalers are beginning to face new competition from national-champion AI data factory companies, like the ones recently announced in France, the UAE, and Saudi Arabia.
With the conversation grounded in that reality, we then turn to what countries should do and are doing. On the talent front, we agree that there's really no way for most countries to compete at the frontier today. But Anjney does argue that governments should play for longer timelines and try both to partner for access to the fruits of frontier labor now and to build the complementary, last-mile local delivery talent they'll need to be successful on a 10- to 20-year time scale.
On data, Anjney makes what I think is really an inarguable case that all governments should be tokenizing their cultures. We then debate whether they should expect better results by partnering with frontier developers or by trying to own fine-tuning and application development locally. Fortunately for them, as long as frontier open models continue to drop, those options are not mutually exclusive.
On compute, it seems that most countries will be asking themselves a complicated mix of questions, including: What level of independence do we really need and want, and what mix of partnership and local buildout is required to get there? Just how reliable are the United States and China as partners? Do we have to align with one or the other, or can we play both sides?
Obviously, that last question has become much more complicated recently, as the United States has shaken the foundations of its global alliances while in the midst of intensifying strategic competition with China. Still, aside from a few countries, like the UAE and Saudi Arabia, that have extremely deep balance sheets and can offer regulatory arbitrage in exchange for being cut into the global AI buildout on a strategic level, my sense coming out of this conversation is that, for most countries, some limited investment in critical infrastructure would be prudent. Beyond that, they're probably better off letting the market develop naturally and accepting quite a bit of dependence on the United States.
At the very least, I sincerely hope that the U.S. proves to be a good bet as an AI partner, first and foremost when it comes to responsible development of the frontier technology itself. To be honest, if it doesn't, I feel like the rest of the world might have even bigger problems to contend with.
Obviously, this is a super-dynamic space, and this was a great conversation. I really think that the empathy Anjney demonstrated for so many different positions that national leaders find themselves in, and the build-versus-partner framework that he brings to this analysis, are valuable contributions. I look forward to doing it again soon.
Anjney Midha, general partner at Andreessen Horowitz, welcome to The Cognitive Revolution.
It's great to be here. Thanks for having me.
I'm excited for the conversation. Today, we're going to be talking—and I'm sure we'll touch on other things—but the core theme is this notion of sovereign AI. I think it's actually the first time that I've covered it in 200 episodes of the podcast, so that's probably on me for being neglectful of what I see as an increasingly important concept and idea that, as geopolitics is literally exploding all around us, is certainly going to become more and more important.
My cards are on the table. I think AI is really important. I think governments should be taking it seriously. I think they should be thinking about how to invest in this technology wave, bring the best of it to their citizens, and also protect their citizens from the worst of it. And yet I find myself a little confused by this concept of sovereign AI, and I'm hoping you can help shed some light on the subject for me.
For starters, what is sovereign AI, and what is the big argument for it? I have a couple of different candidates, but I'd love to hear how you think about the big arguments for sovereign AI.
Yeah, no, it's a good question. I think we should start with first principles, right? One, I think we should acknowledge that nobody has a working, canonical definition of sovereign AI that seems to be consistent across different regions.
Yeah. We don't even have AI agents defined, so there's nobody there.
Yeah. So we are definitely in this weird regime where you have nation-state leaders and CEOs of the world's largest companies talking about how important sovereign AI is. Yesterday, Satya, I think, tweeted that they're launching their European sovereign cloud. If you look on the website for a definition of what they mean by sovereign AI, you can't find one, right?
I think this is one of my icebreakers now when I get together with policymakers or leaders who happen to find themselves in the position of not just being geopolitical leaders but now actually having to have an opinion on AI. I often ask them, “What's your definition of sovereign AI?” Which is the policymaker version of the “What's your definition of an AI agent?” test, right?
It's a great icebreaker because you ask 5 different people, and you're going to get 5 different answers. So let me try to paint a picture of what I think it means to people and then what I think it should mean.
What I think it means to people is that it's basically become synonymous with wanting control over your own destiny as AI plays out. If you're a nation-state leader, if you happen to be responsible for the future direction of a country or a large company, I think it's your way of communicating that you want control over your own destiny as much as possible as AI plays out.
If you're a technologist, an engineer, or a researcher, I think it tends to mean more a collection of services and models that run locally, on-premises, without having to rely on traditional cloud infrastructure that is then beholden to some set of geographical governance.
I'll continue laying out what I hear from different people. If I'm talking to a CIO of a company in Europe and asking them what sovereign AI is, what I often hear is, “To me, it's a way to have our AI workloads located in a way where I know they don't have to comply with backdoor information requests from foreign governments that I don't have to comply with if I don't want to.”
Some of those are American regulations, some are Chinese, and some are Singaporean. But if you're a company at any kind of scale and you have customers in various regions, it's a complete nightmare for you if your AI workloads are located in a place that makes you have to comply with the regulations of that place.
If you're a CIO, sovereign AI is your way of saying, “Look, I want to know where my workloads are, what regulations they comply with, and I want control over what regulations I have to comply with.”
If you're a nation-state leader, like a prime minister or an elected official, then I think it stops meaning something concretely technical and starts to mean something more cultural. If you say, “Look, a large percentage of my population is going to be talking to AI models as their daily companions, and a large percentage of my country's mission-critical industries are going to be running on AI workloads,” then not only are these models computing infrastructure and technical infrastructure, but they're also a form of cultural infrastructure. They're trained on training data, and they have a set of post-trained values in them.
I want those values to reflect our own and not some adversarial country. I think “sovereign” for them means the independence and the ability to control what value systems that cultural infrastructure reflects. So again, I think it means different things to different people.
But if you're asking for a sort of subset, I think it's a set of technologies and services that both convey the technical independence of traditional cloud infrastructure, but also the cultural independence of having to adhere to some other country's value systems that don't align with yours. Does that make sense?
Yeah, I think that's pretty interesting, and I hadn't even really considered it from the perspective of just the enterprise. But certainly, it does make sense to want to be mindful of what government backdoor requirements you might be walking into without even realizing it if you're not thoughtful and take care to minimize that kind of stuff.
I had been thinking about it more from the nation-state or cultural perspective coming into the conversation. Another way I was thinking about it is just in terms of inputs. If the inputs to AI are data, compute, and algorithms, you could say that the data is obviously the cultural stuff that can go into a model. The compute is the data centers, and those are very physical, real things that have a very specific place in the world.
And then, on the algorithms, I would equate that to talent if I'm thinking from an enterprise perspective. I was actually just talking to a friend yesterday who works for a mid-size boutique technology consulting firm that serves enterprises, and he was asking me, “How do I think about these data issues?” The people at our big enterprise customers are very conservative, with tons of lawyers, and we have a real hard time getting them to take any risk.
They're going to want to bring everything on-prem. They're going to want to have everything in-house. What do you think about that?
My response was that I would try to push through it. If I'm an enterprise—or if I were advising an enterprise—I think I would try to get the legal team comfortable with Microsoft's terms of service and feel like you probably already trust some big tech provider to have custody of important data. This maybe isn't necessarily so different from your queries going to the Azure cloud versus your own cloud.
In fact, they might even be more secure there in some ways, depending on what your threat model is. Relative to hacking, what's more likely to get hacked: your stuff or Azure? I don't know, but it's certainly not obvious which is more likely to leak.
So how do you think about that? With Microsoft taking something to the European market, for example, and saying, “Okay, we've got data centers here, and it's all local in some continental sense. You don't have to worry about American jurisdiction, Singapore, or what have you,” would you come down in the same place and say these enterprises are maybe a little overly focused on controlling their own thing relative to using the best provider and getting the benefits sooner, perhaps?
Yeah, so that's a good question. Here's a framework for how I tend to think about it: I like red-teaming the supply chain that delivers the product or service that you're depending on.
“Enterprise” is sort of a Silicon Valley word, because everyday people don't use that word. If you ask what an enterprise really is, it's basically either a business or an organization that makes large purchasing decisions on behalf of users. If you trace back to first principles the rise of this concept—the etymology of the word “enterprise”—it started to become a thing in the 2000s, when the idea of selling something and using something kind of diverged.
You were often selling a piece of software technology to somebody who actually wasn't the end user, because that person was the purchaser or decision-maker on behalf of the organization. That would be sort of classic top-down adoption, or diffusion, of a technology.
Then there was a violent disruption of that with bottom-up SaaS, or software as a service, where any individual within an enterprise—a company, an organization, even a government—could say, “Hey, there's this cool new tool called Dropbox or Slack, and I can just go swipe my credit card and start using it.” My colleagues could do that if they liked it, too.
Then, at some point, there's enough of us using it that it makes sense for us to adopt it across the entire organization. That was a huge shift in the way technology and software were diffused.
Traditionally, you had this top-down buyer model. When you say “enterprise,” I often think of governments as the largest enterprises. You often have the minister of IT for a country deciding what stack the country should run on.
I think what we're seeing right now is a back-to-the-future moment. In the pre-cloud era, and before packaged software, when you had a lot of on-prem infrastructure, you had CIOs and CTOs making decisions for the entire company. “We're going to use Linux. The entire company is going to use Linux, and we're going to go to Red Hat and buy a bunch of licenses to allow us to use the enterprise version of Linux.” Then we're going to buy the consulting and support that came with that contract to manage the deployment and complexity of deploying that system.
The second thing we're going to be buying is basically insurance: when the system inevitably fails, who's down the line? Who's providing the indemnity and the hook? Who's accountable to raise their hand and say, “We will fix this. This was our fault. We'll fix this problem”?
When you have any conversation about the enterprise, the framework I try to use is: What are they buying? Are they buying technology, or are they buying insurance?
In the top-down era, pre-software as a service and pre-cloud, you were often buying solutions. You were buying technology, and then you were buying insurance from the same person; they were bundled. That's why we had the rise of someone like Red Hat, which got completely unbundled in the SaaS era.
Because individuals were buying the technology, the risk—or the insurance—was moved to the CIO, the chief compliance officer, and so on. We've been in this scramble, this unstable equilibrium, for the last 10–15 years. Individual users within the enterprise were adopting the technology simply because it was the best product they wanted to use, like Dropbox, Slack, or GitHub.
Then you had CIOs constantly chasing them to try to buy insurance and say, “Well, wait a minute. This tool isn't SOC 2 compliant with the risk posture of the company,” or, in some cases, with the risk posture of the entire country. So who's on the hook?
That resulted in the rise of hyperscalers, or cloud companies like Azure, basically saying, “Hey, we'll sell you insurance. You should work with us, especially for infrastructure products, because we'll indemnify you. We'll provide the security and the indemnity, and when something bad happens, we'll raise our hand and say, ‘You, the CIO, are not on the hook. You can blame Azure.’”
So you're buying job security for yourself and your team, and that was an extraordinary offering. If you look at AI and generative AI terms of service today versus 2 years ago, Azure now indemnifies a bunch of the AI services. Two years ago, there was no indemnity offering.
So if your friend is asking you, “What should I use, Nathan? Should I trust Azure?” the first thing you need to ask is: Is he trying to buy technology, or is he trying to buy insurance?
I do think we're in a back-to-the-future moment. With open source, what I'm seeing—certainly in regions like Europe—is that the largest enterprises, especially the ones who want sovereignty, that independence over the supply chain we've described before, are turning to companies like Mistral to say, “We want you to provide us the technology and the insurance.”
You come help. You figure out what the right implementation should be, because it's just way too complex. There are too many models coming out every week.
We have no idea how RLVR—reinforcement learning with verifiable rewards—works. We don't even know what a reward model is, but we want you to come automate.
Let's say I'm CMA CGM, the third-largest shipping company in the world, with $70 billion to $80 billion in revenue a year. I know I want to automate the entire port operations and cargo operations for my company, but I have no idea whether I should be using Mistral 7B, Mixtral, DeepSeek-R1, a reasoning model, or a non-reasoning model. My head is spinning because every week there's something new coming out.
At the same time, I need somebody to sell me the technology and manage the complexity of the technology. I want somebody to say, “Don't worry, I've got this. I'm managing your risk for you,” when it comes to anything going wrong—whether it's cybersecurity risk, copyright issues with the outputs, or whatever it might be.
I think we're getting back to the future, where the largest enterprises are turning to 1 or 2 companies to provide all of that. I often run into Palantir in the US as that sort of provider for mission-critical workloads, where they manage the technology deployment and provide indemnity. So I think it depends on whether your friend basically wants to buy Azure insurance, or whether they want the best technology. Often, right now, you're not getting both of those from the same place if what you're looking for is frontier open-source models. Does that make sense?
Yeah. I mean, that all sounds to me like it boils down to probably you should go with Azure. What would be the argument for actually trying to bring all this stuff onto your own enterprise, on-premises servers?
Well, if you don't trust Azure, right? Ultimately, Azure has to comply with government regulations that today are governed primarily by American law. If the workloads that your friend is running are in mission-critical industries outside the US and their customers would not be comfortable with back doors to the US government, then they should probably not go with Azure.
For example, the US CLOUD Act governs all workloads run by US cloud companies. So that is one way to break it down: Do your friend's customers care about the sovereignty of their workloads? Would they be fine with the US government having total access to those workloads? If the answer is no, then that's one reason they should be going with their own infrastructure.
Yeah. So I guess, to maybe try to summarize that again, it's like the trend seems to be pretty clearly toward a rebundling of technology and advisory services and this sort of insurance component. But yeah—
Because of some of these laws, like the US CLOUD Act—
Right. As a European company, for example, you might want to go with a European provider of that bundle as opposed to an American provider of that bundle. Obviously, there could be some nuance in terms of exactly how the US CLOUD Act applies internationally. I'm certainly not an expert in that, but I can understand why you might be more comfortable going with Mistral as opposed to Azure based on that.
Right.
While still basically seeking the same bundle.
Correct.
Yeah. Now, what's happening—and this is happening, I would say, in many regions across the world—is that you have an effort like Stargate here. It's a new kind of fully integrated cloud offering that starts with a single AI provider integrating the chips, the data center that runs the chips, the compute—the compute part of the stack—the entire model part of the stack, as well as the end applications, like ChatGPT.
That's certainly working in the US, and for the first time, I think we saw that get internationalized 2 weeks ago with the deal in that opening I did with the UAE, where they said, “We're going to offer ChatGPT to the entire country, and the government will pay for it,” because it's essentially free for all residents of the country. But the idea that now those workloads are running on the OpenAI offering for countries versus being run on Azure is the first clue that there's a rebundling of the cloud happening, where hyperscalers are getting unbundled and rebundled by AI companies.
In the previous era, in the rise of the hyperscalers and the rise of the cloud, the primary organizing function was the marginal cost of compute. By compute, I mean storage as well as CPU workloads. By centralizing almost all of these workloads in 1 place, the economies of scale were really, really hard to fight.
Let's put aside for a second the whole insurance argument that we talked about earlier. Just from an economic perspective, it didn't make sense for most companies to run their own workloads. The classic technology purchasing decision is no different: It's build, buy, or partner.
In the pre-cloud era, you had to build your own infrastructure and your own data centers. Then, when the clouds came and started presenting you with the value proposition of, “We can just offer you all of that, but cheaper, and abstract away the complexity for you so you don't have to manage your own infrastructure,” most enterprises, most countries, and companies chose to buy instead of build. A few came out on the other side because they were such large customers or had regulatory reasons that required them to go back to building.
I think that's what's happening now. A country like the UAE is basically saying, “We'll just buy the sovereign AI stack. We trust OpenAI, we love them, and we'll just buy it.” There are other countries and regions that are saying, “No, we're going to build.” It's not just countries. Some companies as well are saying, “We'll just build. We're going to own our own chips, we're going to want open-source models running on them, and we're going to handle the fine-tuning, the post-training, as well as the deployment.”
We'll take some open-source application—our own version of GPT—and we'll handle that. We will deploy that for our civilians or our customers. I think you want to analyze how, in those regions, they're not purchasing Azure. They're purchasing a full-stack, rebundled offering, or they're choosing to build that full stack themselves.
In the case of Mistral Compute, which is something they announced last week, Nvidia and Mistral are building a cloud. This is a new animal, where Nvidia chips—American chips—are being wrapped in a data center, which will be Europe's single largest local data center, with a cloud platform on top that runs both models as well as other open-source models, with the customer's choice of whatever application they want, including both open-source clients versus not.
And so it looks more and more like an open scaler that's rebundled cloud offerings along the dimensions of open-source workloads first, where open-source workloads are the first-class citizen, versus what has been the dominant paradigm for the last 15 years, which has been clouds bundling and providing cheaper and cheaper marginal cost of compute to customers for centralized workloads, but then primarily on proprietary technology.
So let's maybe shift to the value to countries and citizenries.
Yeah.
And maybe I'll go in order of talent, then sort of data, models, culture, and then infrastructure.
Yeah.
On the talent side.
Yeah.
It seems like Mistral—am I saying that right? You're the authority on this. They seem to be one of a very small number of national champions that has continued to pretty much keep up with the frontier. I mean, I wouldn't say they're quite at the frontier frontier, but they're not far behind. And certainly there is a critical mass of talent there. And that is something that is unique in Europe and close to unique around the world outside of the US and China.
Right?
So I guess that seems like a win just on its own merits, right? Like, if you're a country and you're like, “Well, who knows what might happen again? You know, geopolitics is exploding in all sorts of ways all over the place. We'd like to have a domestic talent pool that, if walls really come down, we can still do this stuff within our own borders with our own people and feel confident about that.” That seems like a pretty clear value proposition, right?
I do wonder how many countries you think could actually achieve that. It's notable that Germany doesn't seem to have a similar thing, and you can go down the list of most populous countries, and there are a lot of countries with a lot of people that don't have anything like this. Do you think they should be trying to create them, or could create them? Or would you worry, if you were advising Russia or Brazil, or big countries with lots of resources, that they would just be kind of wasting money on something that's never really going to amount to anything?
Yeah. Okay, so this is a good question. I'm going to go back to a story. I'll answer your question with a story. There was a moment post–World War II when a lot of folks were looking at the way the diffusion of a modern technology was changing the world: modern finance.
Post–World War I is when the Bretton Woods conference happened, right? A number of countries met up to talk about adopting the US dollar as a sort of global reserve currency. And then, post–World War II, is really when the adoption of that started accelerating. A lot of countries got together and said, “Wait a minute, this dollar thing is really working.” And that resulted in 2 clear power centers. There's America, which is the purveyor of the single global reserve currency, and then there's Europe, which is turning out to be one of America's largest trading partners.
Of course, this was when we were seeing the rise of the Middle East and Russia as well because of the petrodollar, and a bunch of other countries were going, “If we're not on the other side as a trade partner of the US, what do we do? We're just going to get left out in the modern finance era. How else do we amass reserves of our own reserve currency?”
Most countries navigated that build, buy, or partner tradeoff differently. But it resulted in the rise of a new kind of nation that I call essentially a hypercenter partner nation, right? This is a country that may not have the size of the big guys, may not have the talent of the big guys, but understands how to insert itself in the flow of value in the global economy. And that's what happened with countries like Singapore.
Singapore is a tiny island nation, right, with fewer than 3 million people. So it did not have a massive talent base, did not have vast oil reserves like the Middle East did to trade with the United States, and was not a net producer of currency like the US is. So how did they navigate that? Well, they said, “What we're going to do is make ourselves essential to the flow of global dollars going from the US and Europe into the East.”
What we're going to provide is a stable rule-of-law regime. Lee Kuan Yew and the founding fathers of Singapore did a lot of work to basically make Singapore have the lowest corruption index in the world, the lowest cost-of-doing-business index, and the highest ease-of-doing-business score in the world. And that resulted in them amassing this extraordinary wealth, just creating an extraordinary base of wealth for the country.
At this point, Singapore has one of the highest GDP per capita levels in the world and one of the top 10 sovereign wealth funds in the world. So my answer to your question is basically, you either have to build, buy, or partner. If you are either a hypercenter with the compute reserves and the talent, like America, China, and now increasingly Europe, or you have to find a way to partner and insert yourself in the flow of tokens in the global AI economy. And I think that's the race we're seeing play out right now.
The result is that you're essentially directionally correct. I don't think most of the world's economies have access to the kind of frontier pre-training or post-training talent that Mistral has. The vast majority of that talent is concentrated in the US. Europe is one of the few places that has it. And most countries outside of Europe, China, or the US either have to build, buy, or partner for that talent, right?
And boy is it getting expensive.
Zuckerberg is going to be hard to outbid, it seems.
It seems.
That's right. I mean, Meta—that's why, when you say “enterprise,” I think of nation-states and Fortune 500 companies as essentially in the same atomic unit, right? So if you're competing against Mark Zuckerberg for a researcher, you cannot bring a knife to that bazooka fight. And outside of the US, Europe, and China, there aren't that many private companies that can fight that battle, so it ends up being nation-states.
That's why there are so many countries going, “Wait a minute. If AI is a core piece of national infrastructure and we're bidding on talent against Meta, then we can't leave it to our private sector, which is tiny, to fight that fight for the country. We need to back it up with essentially sovereign dollars.” And that's what's happening, right?
If you look at the rise of G42 in the UAE, which is a kind of infrastructure company backed by the sovereign wealth fund, they are playing the kind of role in the economy that AWS or GCP plays here, but they're entirely state-backed, right? So governments have had to step in because the sheer capital required to play at the frontier is outside the purview of the buying power of most companies.
Yeah. So would you analogize, then, what the UAE and perhaps also Saudi Arabia are doing right now to the Singapore play from years past, of saying, “We're going to find a way to insert ourselves into the global flow of tokens”?
100%. Except they don't need their Singapore moment right now because they've got oil. So what they're going through is their petrodollar moment.
If you trace the history of Singapore, what's so interesting is they navigated the rise of the petrodollar through the concept of being an entrepôt, where they said, “Okay, we don't have our own oil, but we see this massive flow of one resource turning into another, which is petroleum turning into dollars on the other side of the world.”
And the only thing they had going for themselves was their location. And so Lee Kuan Yew did a bunch of strategic partnership deals, very reminiscent of how Sam and OpenAI have been doing a bunch of ecosystem deals. All of the crude from the Middle East—or the vast majority of the crude oil—was shipped on tankers to Singapore and then refined in Singapore. A value-added tax was added, and then it was shipped out to multiple other Western countries that would buy. And that's how Singapore navigated the petrodollar regime.
The UAE does not have to do the same thing because they've got the petrodollars. What they're trying to do is convert their petrodollars to petaflops, right? By buying vast amounts of GPUs—basically computer infrastructure, primarily from NVIDIA—and saying to the world, “Well, come run your workloads here.” That's the whole G42 pitch, right? Over the next 30 to 50 years, let's convert our petrodollars to compute and attract the world's largest customers to run their compute workloads here. And then the vast majority of our GDP should be decoupled from the price of an oil barrel.
The more time I spend in the Middle East, I realize that the way we follow interest rates here in the US is how they follow the price of a barrel, right? Entire investment projects are greenlit or not depending on the price of an oil barrel that week. And they would like to decouple their technological future from the price of oil, and compute and AI inference are that path for them.
Let me come back to that infrastructure in the Middle East question in a second.
But just to take one beat on the data side, and the linguistic, cultural, and sort of value side, because we've covered talent and I think we're basically on the same page that it's going to be very hard for almost anybody to amass enough talent density—
Right.
—to really compete for frontier AI.
That's right. It doesn't mean you don't want to develop your workflows generally, but that's sort of a frontier-versus-diffusion question. All these companies or countries should be promoting diffusion, but that's quite distinct from trying to amass the density to compete at the frontier.
Then you also hear this argument: We want the AIs to be good in our language, and we want them to reflect our cultural values and all that kind of stuff.
Right? There again, I feel like if I'm advising, let's say, 80%—maybe even 90%—of the countries in the world, and I said, "Okay, you've got your data, your culture, your language, you've got all this stuff. How can we make sure that you are best served by AI with respect to all that makes you unique and special?"
I think what I would say for almost all of them is—
Do a massive data collection and curation project, and then literally just take the data on a silver platter to all the hyperscalers and say, "Hey, please include this in your future training runs because we want your models to be fluent in our language, know about our idiosyncrasies, talk to us the way we want to be talked to, and reflect our values back to us."
Would you give the same advice? Here I'm thinking about Mexico, Argentina, Australia—you name it—all these middle-tier countries that we've kind of established probably can't compete at the talent frontier. There's this notion that if they don't do that somehow, they might miss out, and my suggestion is just: They want data, you have data. If you can bring it to them and allow them to use it, they'll happily incorporate it, and then you'll get what you were looking for in maybe the most efficient way.
Well, okay. To be clear, I don't believe that countries can't compete at the talent frontier. I just don't think they can compete today. At the end of the day, there are no secret recipes for RL. Everybody knows how to do it: Mistral published Magistral, its reasoning model, and DeepSeek put out the recipe.
There are some tips and tricks that you learn, especially when it comes to the infrastructure required to do RL, sort of online RL learning, that are hard to learn. But there's no fundamental reason why Singapore, the EU, or Mexico could not, in the long term, build out a talent pool that can do pre-training and post-training of their own models if they wanted to. If they started investing today in the right partnerships, the right educational institutions, and the right infrastructure, there's no reason they fundamentally can't get there, right? So the question is, what do you do in the short and medium term? What's the roadmap to get there?
Yeah, I'd put the singularity somewhere in the 5-year time frame. So 20 years sounds long to me, although obviously I don't know for sure that's going to happen.
Yeah, so that's it. I think that's one way to organize the timelines, right? There are certainly some countries that are more or less AGI-pilled than others. The UAE is more AGI-pilled than Mexico today. The UAE is saying, "Yes, it's hard to plan outside of 5 years, so let's do whatever it takes to build out our infrastructure and our talent pool here."
They're choosing to partner with OpenAI. They're trying to partner with everybody because their belief is that they have a 5-year period to establish their independence before the singularity arrives. The countries that are less AGI-pilled, that are less urgent about AI, are planning on a 20-year horizon.
But let's say for a second that the singularity arrives. I'm quite sympathetic to the idea of the gentle singularity: that it's not some violent rewrite 5 years from now where, suddenly and magically, the entire economy collapses and you're no longer relevant. I still think if you're Mexico, you want to plan for a 20-year horizon in which your young population can graduate to having useful jobs and purpose in life.
If a big percentage of that is doing useful post-training work on AI models or doing integration work between AI—whatever the frontier models are—and integrating those into the rest of the economy, that talent pool is really hard for them to get today, I would argue. But they have to invest in their capability to build out that talent pool over 10 years.
For example, I do think one of the most sought-after skill sets today is the equivalent of a forward-deployed AI solutions engineer, right? Someone who can bridge both of—
Is that what we call them here?
That's my own personal branding.
Right, but it's someone who can take a model and then integrate it into the right workflow.
Often that happens in some real-world task. Often that requires genuinely knowing how to do verifiable reward design. Maybe all of this will be automated 5 years from now, but as a country, I think it's possible to do what countries like India did in the 1990s with auto manufacturing.
In 1992, India started liberalizing and said, "We would like to go from being a socialist country to being a modern capitalist country. We don't have that capability, and we think auto manufacturing is one of the frontier economic sectors of the world. We need to develop that capability. We just don't know how. We can't leapfrog to doing that overnight. So let's partner."
They invited companies like Suzuki, which came in and set up joint ventures locally where they trained up the local population. They created a company called Maruti Suzuki that was responsible for producing the vast majority of cars in India for about a decade. Over time, they transitioned the running of that industry and that sector to local talent.
By the way, the US did the same thing with oil in Saudi Arabia in the 1950s and 1960s, with Saudi Aramco. That was originally Shell, right? The standard oil corporation of America went and did oil exploration in the Kingdom of Saudi Arabia and then, over time, transitioned that to a local talent base called Saudi Aramco.
I think that's the healthy way for the US to bring its allies along into the singularity: joint partnerships, kind of what NVIDIA is doing with Mistral in Europe. If we don't bring them along, they're going to turn to adversarial countries like China to do that. I just want to be clear that, in the short term, the talent race is intense. That doesn't mean that, in the long term, you can't partner with the right folks to set you up for a better future at the talent frontier.
And I don't think it's just a talent thing. I think that extends to all parts of AI frontier progress, whether that's data or compute. So, to your question more directly about data, if you're a country, you should certainly be figuring out ways to get your culture tokenized. If your culture is not tokenized, then fundamentally you're reliant on some other country to tokenize it for you.
I think tokenization is the most underdiscussed part of sovereign AI. Get that corpus that reflects your culture and values, tokenize it, and then figure out how to do pre-training on that corpus. I think there are several countries racing to do that today, certainly for languages that have a different root from the sort of base European languages. Does that answer your question?
Still, it does, although I still wonder where they're really going to get the best results. It still feels to me that just bringing all that data on a silver platter to the leading developers—you could maybe do both, but if you were Brazil, for example, and you said, "Okay, we've got all this massive data, and now we've curated it and tokenized it."
One of the great things about information—and perhaps one distinction between these earlier industries, auto and oil—is that this stuff is so intangible. To some degree, some of these things only have to happen once, whereas you have to actually stamp out every car. The cost of duplicating a trained model is obviously vanishingly low compared to the upfront cost that goes into it.
Right?
But if I'm Brazil and I'm saying, "Okay, I've done all that work now..."
I can do all these things. I can go to OpenAI and give them our data. I can go to Anthropic and give them the data. I can go to Google and give them the data, and I can try to develop a national champion. I would be pretty confidently willing to bet that the Brazilian national champion is going to be worse on a 2- to 5-year time scale, at least.
At using that data and actually even serving the local culture, as opposed to the hyperscalers, who I just think are going to be basically better at everything. And I don't know if you take the other side of that bet, but—
Oh, I think—
It was hard to win.
Well, I think it depends on what your definition of a local champion is, right? If the local champion is the provider of Brazilian-language models to the vast majority of its civilians or mission-critical industries like defense, healthcare, and finance, the value lies in the last mile, not the pre-training. At that point, yes, they should absolutely not try to develop their own pre-training capabilities in the short term, right? Because I think that just gets commoditized.
They're much better off finding a pre-training partner, ideally somebody who is an open-source pre-training partner, because then they have a ton more customizability over the post-training, right? Because if you have access to the weights, your ability to do weight adjustment and on-policy updates to the weights is dramatically higher if you have direct access than if you don't. But I completely agree with you: in the short term, you should find a pre-training partner instead of trying to replicate that.
But the last-mile distribution effects you have in your country—the last-mile advantage you have of knowing which companies are best positioned to consume that technology, how to productize it for them, how to do RL, and certainly how to deal with non-verifiable rewards, which is really where the stuff becomes fuzzy and you need local handholding—you’re tremendously more advantaged than OpenAI or Anthropic.
It's like, have you talked to ChatGPT in a language outside of English—in any local language?
Minimally. I speak enough Spanish to experiment with that a little bit, but—
My Spanish is terrible, so I don't. But I'm a native Hindi speaker, and when I talk to ChatGPT in Hindi, it speaks like an American tourist visiting India, with an American accent. Its diction is different, and its linguistic choices are different. It's like a tourist.
For any consumer use case in Brazil where your civilians don't want to talk to a tourist, they want to talk to a local, or for a mission-critical industry where, for the last-mile integration, you only trust a local partner, you're best off developing a local champion that's the AI partner for that, right? I completely agree with you: pre-training should be a partnership effort with whoever is the right technology partner that has it.
We've talked about how there are only 5 or 6 teams who can do that today. But over the long term, I think what happens is that knowledge diffuses out, and that company—which is today your local AI champion and largely a last-mile provider—will, over time, learn the knowledge required, just like with AI, with Aramco in refining or with Suzuki in manufacturing.
I don't think there's anything—you’re right that the marginal cost of producing a model is different from producing a car, but inference is an ongoing muscle, and continual post-training is a muscle that diffuses out. You should have local capability over the next decade in the future AI economy.
How much does that depend on the trajectory of overall capabilities, and specifically on closed- versus open-model capabilities? Obviously, nobody has the answer to what that's going to look like, but one could imagine that, if you take the AI 2027 scenario—
Yes.
A big part of that scenario is that the frontier developers start to close down. They're kind of running away from the rest of the competition. Nobody can match their 10×-ing training—
Right?
And they also start to keep some of their models secret in that scenario, which is a whole other can of worms. But I think it sort of depends on this: Would you rather use, like, o3 in Hindi, even though it's maybe not as native, or would you rather use, like, an o1 equivalent that has that local post-training?
Look, it took 26 days to go from o1 to DeepSeek R1. What China has demonstrated is that they're able to fast-follow the frontier of reasoning within 60 days, right? We're sitting here in June, and it's been more than 6 months since o1 came out. Of course, o3 Pro has come out, but the distance between o3 Pro and the new version of R1 is not some hard-to-close step function. It's very—it's very—
The current data seems to be that the frontiers of closed-source and open-source models are basically moving in lockstep, at roughly 6 months or less, right? I think there were a lot of experts up in front of Congress a year ago very confidently claiming that the U.S. was 5 to 6 years ahead of China, which, to me, felt like I was being gaslit. I was like, what planet are you on?
DeepSeek had been putting out incredibly strong open-source models for about 8 months before R1 came out. So, for anyone who was paying attention, it was clear that the gap between closed-source and open-source models was not some multiyear race, right?
Still, that's an interesting dynamic, too. Again, I don't think anybody has a great crystal ball for this sort of thing, but one does wonder: These aren't open-source projects in the traditional software sense of being community-driven, where anybody can—
No, they're nation-state-backed at this point.
Yeah. They're still hyperscalers who are just making a strategic decision, for the moment, to do that open-sourcing. So I do still wonder how long China will continue to do that, and, for that matter, how long Meta will continue to do that.
Yeah, so DeepSeek is not a hyperscaler.
So DeepSeek is not a hyperscaler, right?
They are, at this point, a hedge fund that was arguably under a ton of regulatory pressure to shut down its core business because the CCP believes that financial instability for the markets, as introduced by market makers like hedge funds, is net negative. They then turned to doing frontier AI research really well and got a meeting with Xi to continue doubling down on their frontier research efforts.
So I don't think analyzing the incentives of DeepSeek as a hyperscaler is an accurate lens. I think analyzing their game-theoretic optimal strategy from the position of a geopolitical player, with the blessing of the CCP to stay at the frontier, is more realistic.
I think they essentially, within the current regime, will continue doing whatever it takes to have a Chinese model open-sourced at the frontier and adopted by every country on Earth as a form of soft power.
The three-way release of DeepSeek R1, the Unitree humanoid, and the animated movie Ne Zha 2, which was a blockbuster hit, was one of the most extraordinary events. There was a complete soft-power revival in China in the first 6 months of 2025 relative to the last 2 years, which had been marked by malaise in the Chinese economy.
The primary narrative was that China had lost technological supremacy, was losing cultural supremacy, and was losing financial supremacy because the financial markets had been on a downturn ever since the real-estate bubble there.
Whether or not you consider DeepSeek to have gotten lucky, what we're certainly living in now is a regime where the CCP views frontier open-source models as a core national capability and will continue open-sourcing them as long as it sees that as a way to ensure soft power globally. It doesn't have anything to do with hyperscaler revenues.
Yeah. No, that's definitely a good point. I feel like I have a hard time predicting what exactly they're going to decide to do, but that's a good baseline.
Yes. Yes, that's right. What's actually unique about China is the way the structure of the market works: As long as Alibaba keeps monetizing DeepSeek as the enterprise distribution arm of DeepSeek—which is kind of the stable equilibrium they're in right now—DeepSeek is the AGI research frontier lab that's sucking up all the best frontier research talent and continuing to publish and open-source ruthlessly to further, I would say, the country's reputation on the global stage, while Alibaba keeps monetizing it in the enterprise.
I think the CCP will maintain that as a healthy, steady-state equilibrium, because it benefits both the Party. It also benefits GDP in terms of there now being an enterprise infrastructure-software deployment arm within China that knows how to do all the solutions-engineering work we were talking about earlier to actually diffuse DeepSeek into the economy.
Actually, if you remember R1, it's a pretty unwieldy model. It's a very hard model to actually use. It climbed all the leaderboards, and from a raw capability standpoint it's great, but it's a model that's really massive and very hard for most businesses to know what to do with. Alibaba is doing a lot of that work for them now.
That's the steady-state equilibrium I see for now. So let's turn to the infrastructure.
This is obviously what gets the most attention because there are the most dollar values, and then you've got these exquisite assets getting plopped down all over the globe.
Right.
I started because I'm no Dylan Patel here, but I do have access to deep research. So, just to get a baseline, one of my working theories over time has been that AI basically converges to look like the cloud because, in the limit, it sort of is cloud-like: anywhere there's compute, you could run AI. Why would it diverge that much from that?
What deep research told me when I asked it to characterize the distribution of data centers today was, first of all, that the US has about 45% of the global data center infrastructure. The top 25 countries account for 88% of data centers, and that obviously leaves the bulk of the countries with only about 10%, with many countries having no significant data center footprint at all.
One other aspect that I asked deep research to look at was how different parts of the compute stack might be distributed differently. It basically said that compute is more centralized—the most centralized. Storage is less centralized; you've got CDNs and all that kind of stuff. Network is, of course, the least centralized because you've got to actually get to all the end users.
So, I guess the big question is, in the fullness of time—meaning maybe the 5 years between now and the singularity—do you think that the AI infrastructure footprint looks meaningfully different from that? If so, how would it end up being different, and maybe why?
Yeah, I do think that it would look very different in some ways, but almost identical in some others, and I'll explain which is which.
As we discussed earlier, I don't think there's going to be a fundamental change in the traditional, non-AI parts of the data center economy. Compute, storage, networking, good old-fashioned EC2 instances, and good old-fashioned CPU workloads—those are the workhorses of the economy today. Most businesses should benefit from centralization, where the vast majority of your workloads are running on Amazon EC2 or whatever. So, for traditional, non-AI workloads, I don't see that changing anytime soon. I think public clouds have been fantastic for most software and technology adoption, and that's going to continue to be the case.
AI workloads are a whole different story for 2 reasons. One is that, if you X-ray a data center, a data center is not a data center anymore in that it no longer has the same bill of materials that it did 5 years ago. Something like 60% to 70% of a data center now is GPUs. This is a huge change, whereas 10 years ago, less than 10% were GPUs.
This is why Jensen, I think, is on a whole tear to try to get everybody to realize—he calls them AI factories for a reason. He wants to call them AI factories because he thinks this is not just marketing. He's like, "Guys, under the hood, the data centers look fundamentally different now. We should not be calling them data centers anymore. The bill of materials has changed completely. The workloads they're running have changed completely."
For that part of the new data center economy, it's the most aggressive rewriting of the cloud infrastructure business that we've ever seen. If you don't have the frontier model that developers want to use, they literally are switching clouds. This is why, arguably, Amazon had to invest $8 billion into Anthropic when they were losing $100-plus-million contracts to Azure in 2023, because they didn't have a frontier model on Amazon infrastructure. They literally just didn't have a GPT-4 alternative.
I was an early investor in Anthropic, so I got a chance to see some of the calculus behind the scenes, and it was very painful. Public cloud workloads were being moved on the basis of who had the best AI model. That's why we're currently in a race where Google is trying to integrate as deeply as it can across the entire stack, between Gemini and TPUs. Amazon is in a race to try to integrate AI across Anthropic and Trainium, their custom silicon. Arguably, Microsoft is trying to work on custom silicon as well. They've had an 8-year effort there.
I think they're behind, but Satya would like to control his own destiny. They don't really have their own frontier lab today that is equivalent to Anthropic, but they're trying to build that capability in-house.
That begs the question of what happens to Nvidia, right? Because if the largest proprietary models are fully integrated on custom silicon with the clouds and they're going full stack, then Nvidia's core business is at threat, right? Because by the end of this year, two out of the top three models, Gemini and Anthropic, are running on non-Nvidia hardware, that's a core existential threat. And to Jensen's credit, I think he saw the writing on the wall and started investing in a whole ecosystem of new AI-first clouds like CoreWeave, like Nebius, and most recently like Mistral, right?
I think what we'll have is basically 3 or 4 different types of clouds. You'll have the closed scalers, like Google Cloud and Amazon Cloud, and then you'll have the open scalers, like Mistral Compute, which is a closed, tightly integrated offering between an AI frontier lab like Mistral and Nvidia. You will have regional clouds like Nebius, and CoreWeave is another one. I think there are a couple of these in the Middle East, like G42. There's one called Humain that the Kingdom of Saudi Arabia just launched.
The rest of the world is going to have to decide whether they want to be on an open stack or a closed stack. Your guess is as good as mine where things go 18 months from now. But I don't think Jensen will just give up the entire AI factory economy to the custom-silicon winners of the cloud.
What's beautiful about him is that, because he's such a deep technologist, he's 4 steps ahead. He knew his biggest customers were also trying to kill him starting a decade ago. This is why he's been such an aggressive partner to AI frontier startups, because he sees that, as long as a developer like Mistral—a frontier research team like Mistral—keeps reaching for Nvidia chips, Nvidia will see a healthy ecosystem continue growing globally.
I think the natural arc of centralization, as you said, is very strong, but it's not unchallenged. The primary players—the live players, I would say—are now the AI startups that are changing the destiny of these workloads. If you had told me a year ago that Mistral was going to be running compute with tens to hundreds of thousands of Blackwell chips serving workloads in Europe, I would have laughed. But that's literally what they announced last week.
So, these new open-cloud wars are going to be one of the primary stories that get written in the next 18 months. I don't think it's a foregone conclusion at all that the traditional clouds end up winning. They can have the CPU workloads.
Right. I guess I'm wondering what the case is for trying to get data centers on your actual soil now. If you're a country that maybe hasn't had data centers on your sovereign territory historically, I don't really know country by country, but certainly we could find countries in Africa where they just don't have them.
Maybe Mexico, for example, probably doesn't have nearly as much data center presence as it uses, and is probably just effectively importing that across the network from the United States. Again, I'm guessing about that, but it seems like a pretty good guess.
Should those countries just say, "Okay, well, it's worked for us thus far for traditional compute. We may as well just let the market run its course again this time, and we can import inference. Who cares if we're calling across a border for inference? We're not really in a great position to play that game anyway, so fine"?
Or should they be saying, "This is different. We have to have GPUs running on our own sovereign territory"? It seems like that impulse is out there, but I'm not quite sure why, or what exactly they hope to gain from it or protect themselves from by doing that.
Yeah. This is the idea of cultural infrastructure, right? If you don't have the infrastructure locally—the compute hosting and running inference for your models—then you're beholden to somebody else to run that infrastructure for you.
From a supply chain and strategic autonomy perspective, if that compute isn't in your country, you're dependent on those API calls that you're shipping and hitting coming back with full uptime and not returning a 404 error if some government that governs the infrastructure your workloads are hitting turns it off.
I don't think it's net new from a supply-chain perspective. If you see AI workloads, particularly inference, as core national infrastructure, the same way you view parts of your defense infrastructure, then you just have to decide which parts of this supply chain we need strategic autonomy over. We're going to set those up locally. And which parts do we not? We use those from partners.
The vast majority of the world's governments don't build their own jets, right? They don't build their own tanks. They buy them. But then there are some parts of their supply chain where they go, “Wait a minute. Actually, we do want strategic autonomy over this subcomponent of the aviation industry,” and then they build that out locally.
Some governments, by the way, did realize that they depended too much on foreign governments for critical defense processes and supply chains. This was the case with Europe, right? For the vast majority of the last 70 years, Europe has basically consistently outsourced core national infrastructure to other parts of the world. They have now corrected that—or are starting to correct that—with an $800 billion defense bill, saying, “We're going to have to fight for Ukraine because, as Vice President JD Vance said at the Munich Security Conference, the Americans aren't going to subsidize this for us anymore.”
And so we need to do our part in funding and spending for our defense if we want to continue being part of NATO. I think if you view compute through the lens of core national infrastructure and cultural infrastructure, it comes down to this: yes, I could ship my workloads off to somebody else, but what happens when they turn it off? Is that okay?
For some workloads, I think the answer is, “Yeah, sure.” If 30% of my country's citizens are using a cloud in some other country for entertainment, and they turn it off, that may not be strategic autonomy. But for mission-critical industries like defense and healthcare, we probably need strategic autonomy, and so I want those compute workloads to be running locally. Does that make sense?
Yeah, it's a tough logic right now. I'm a proud globalist, I think, and I feel like, as we head into this AI transition—which I hope is gentle, but I'm not so sure—I kind of wish we were maintaining or even deepening the level of integration across countries and increasing the barriers to conflict.
This seems like a classic prisoner's dilemma, where from every individual perspective there's an argument for, “We don't want to be the ones dependent.”
Yeah.
But there is a common good in mutual dependence. I think it's now been violated once or twice, but traditionally no 2 countries with McDonald's had ever gone to war. There seems like there's something there that was worth preserving, and yet we're kind of liquidating that.
I agree with you, but look, it starts from—let me put it this way—if that's a future we want to live in, then we need to acknowledge, 1, that the Chinese adversarial threat is very real, and then we, as America, need to bring along our allies and be stable, reliable technological partners. But if we're not going to be sending those signals, then what more can we expect than the rest of the countries trying to develop their own plan?
That's why I'm a huge proponent of a Marshall Plan for AI, by the way. I do think it's a huge win for America that Mistral in Europe is going with American chips and not Huawei chips, because the European continent has been courted by the Chinese semiconductor industry like never before in the last 18 months, and yet they're choosing to proceed with American semiconductor partners. This is a huge win for globalization. This is a huge win for America.
I think that's the template that we should want globally, right? Open models running on American chips is a great template for global integration like the kind you just described. I just think we have to acknowledge that the model layer, as it currently stands, has a ton of vulnerabilities if it ends up being centralized and closed source and does not confer the benefits of sovereignty, independence, self-determination, and cultural independence that most countries—at least most wealthy countries—want.
I think the sooner we acknowledge that they want sovereignty over the model layer but are totally happy partnering with us on the semiconductor part of the stack, the sooner we can rush to at least 2 stable blocks in the world. It doesn't seem like anytime soon China is interested in pausing its rush for frontier progress.
Yeah, I wanted to get into these recent deals, especially the ones in the Middle East, but the one with Mistral in Europe is also really relevant. I guess my question on that is: do the Chinese really have chips to sell? Well, I mean, I know that they have 5G infrastructure to sell, and that's been a whole battleground as well. Who will use Chinese and who will not? There's been pressure applied in all sorts of different directions, right?
Right. But my broad sense in the AI era is that, for example, DeepSeek has said publicly, despite—and in contradiction of—sort of the official Chinese narrative, that they are limited by their inability to acquire more GPUs.
Yeah. And so I guess I am wondering: is it really realistic to think that all these countries that the U.S. is currently partnering with could actually go to China and buy? My sense is just that the supply is not there, and their domestic market would eat up all that they can create, and lots more.
I think the evidence is that chip sanctions so far on China have had 1 clear impact: they have resulted in an enormous doubling-down of local investment in Huawei's ecosystem. I think there's an alternate future where, if we didn't put any sanctions on them, we could continue making their 20-year arc of the semiconductor industry dependent on the U.S. I think that ship has sailed now.
Partly, that was started by the Biden administration, which made it clear that China could not count on a stable supply of frontier chips—let's say, 3-nanometer or below—from American manufacturers, from American vendors. But until that happened, Huawei was not even in the game for frontier chips. They are now in the game. They have sovereign backing from their country, a ton of momentum, and motivation to develop and close that capability gap.
They're not there today, but there's a national-level race there to catch up, certainly starting with inference. They may not get there with frontier training capabilities for, let's say, 3 to 5 years, but as long as the current arc of compute efficiency keeps on track, I don't think there's any reason why you can't be running frontier reasoning model workloads circa 2025 on Huawei Ascend chips by the end of this year.
In fact, I wouldn't be surprised if DeepSeek R2, whenever it comes out, makes clear that it's Ascend-compatible on day 1. They are in a full-on tear to try to decouple themselves from American chips. And I think that's the position we've created—the U.S. has created—for them.
Time will tell if it was the right one, but I think if you look at the data, it's very clear that Huawei is in a much stronger position today than it was 3 years ago in terms of narrowing the gap between its chip capabilities and those of the U.S. And that's the arc.
I think doing a static point-in-time analysis of their capabilities is dangerous. What we need to be asking is—we need to be doing a 5-year analysis—and where they're heading is that they will be able to close the gap. Because workloads are becoming more and more efficient, I don't think it's that crazy for them to be able to decouple at least the inference part of their ecosystem from the U.S. within 2 to 3 years.
Yeah, I've seen them put up a hospital in—what was it, 6 days or something? So never underestimate the speed.
Never underestimate the Chinese.
China might be able to do something.
Yeah. There's a funny incoherence, I think, sometimes in our policies, where we simultaneously make China out to be this big, terrible bad guy that's going to—I'm not even sure what exactly the threat model is supposed to be. I often ask people, what exactly am I supposed to be afraid of China for? Are my grandkids going to be speaking Chinese? What is it exactly that you expect? You can offer an answer to that if you have one.
I usually don't get great answers, but we have this sort of, “Oh my God, China, they're so scary.” And then, on the other hand, we're like, “But if we cut them off from this, they'll never catch up,” you know? And I'm like, I don't know which side of that to believe. It doesn't seem like a coherent idea.
Or, at minimum, it seems like there's sort of a needle-threading that we're trying to do with this policy, where we can stay ahead just long enough to get to the singularity and they won't catch up. But a lot of things have to come together just right for this policy to ultimately pay off in a new American hegemony, via our values being dominant in some sort of superintelligence or whatever.
Yeah, look, I know earlier I said that there’s nothing secret about RL. The recipe is known, and nations can catch up if they want. The corollary to that is they have to invest at the right time, and I’m very sympathetic to the argument—or to the line of reasoning—that AI is a tech tree and you have to get involved early enough in the tech tree to develop your own capability years from now if you want. You can’t just bury your head in the sand for 5 years and then, at some date in the future, show up and try to catch up on RL or AI progress.
Chips are very similar, right? And I think we have accelerated their adoption into the tech tree. The threat now is that if America and our allies stop progressing along the tech tree and instead there’s a future where you’re entirely reliant on China’s tech tree, then let’s make no mistake: our mission-critical workloads and so on are going to be dependent on whatever governance they choose to impose on the infrastructure running these workloads.
Look, as much as, from a technological perspective, I think it’s okay to admire their engineering prowess, from a cultural perspective, we have to acknowledge that this is one of the most ruthless authoritarian governments, whose biggest victims are often its own population, right? They’re willing to do things that I don’t think we’d ever want our families to have to be subjected to. Unless we are all okay with the trade-off in civil liberties and oftentimes persecution that comes with the Chinese form of governance, I think we have to ensure that we have our own frontier stack that’s independent of China.
Yeah, I’m totally sold on that. By the way, we should build our own stuff; we should have our own fabs. And by “we,” I mean the United States. I think that makes total sense and is almost inarguable. Where the rubber hits for me is more on the question of, are we going to—should we try to deny them similar access? And if so, why, and how do we make that not self-defeating? Those are much harder questions. I certainly wouldn’t want to see the AI territory at any level of the stack go to China, but I
I’m much less convinced that we should be trying to deny them their own version of it, if only because it just ratchets up tensions and makes everything else harder. And I’m not sure that we’re necessarily accomplishing all that much.
But.
No, yeah. So, I agree. I believe in the opposite, which is: let’s ship the best technology and export it to everybody so everybody adopts it, including the Chinese.
Yeah, I’ve made that argument, too. If you really want American values to dominate AI, why not just give them free inference? Now, they’ll probably not even accept it. That’s a whole other question.
Yes.
That’s what they did with the internet, right? They created their own internet and prevented our companies from operating there. We never reciprocated that, and arguably that’s why we are stuck in a situation where ByteDance and TikTok are more successful, arguably, in America than Instagram is. Different conversation, I think.
I am certainly concerned about the arc of post-training on short-form video. That is going to eat the brains of the next generation in a way that I don’t think we are prepared for, even though I’ve ordinarily been sympathetic to the argument that humans are resilient. Arguments were made for previous technical waves that video games were terrible for our kids and TV was terrible for kids, and yet we turned out to be fine. I do think RL on human preference today can be weaponized at a speed and scale that humanity has not really been prepared for before.
I think that’s totally right. If you take what Facebook has done—and this might be, roughly speaking, OpenAI’s plans—I mean, they literally just hired a person to run applications who was a big player in developing the News Feed into what it now is. But if you apply that same level of optimization to one-to-one AI interactions, I think you do end up in a
Or at least there’s a pretty good chance you end up in a dark place.
I would not overindex on the executive hires, but I understand your greater point, which is that AI RL on human preference is a very, very, very powerful way to drive addiction to AI products. Agreed. I would not want the Chinese government doing that to our population.
And I agree. It’s certainly premature to judge any individual. You could also make the argument that who better to avoid the mistakes the second time around than the person who was deepest in the details of it the first time around? So I could see that going either way.
I want to also, just to put myself on record, say I remain very open-minded to the idea that China really is a terrible bad guy. I live in Detroit. Not too long ago, there was a story that came out of, literally, the Detroit airport where somebody came in from China with some fungus sample that is like a
Yes.
And
I have been poking around trying to get a little more information on that. It’s hard to get good information on such a story. One could wish that we had people in key positions who were making these announcements, like at the FBI and the DOJ and whatnot, who were maybe a little more universally trusted than the people we actually have. But what I have heard has basically been, “Yeah, dude, that kind of checks out, and you probably should be afraid.”
I’m updating on that, and I’m like, man, if they’re willing to try to release bioagents that would destroy crops—this wasn’t necessarily about to be released—but anything messing around in the domain of bioagents that destroy crops…
That’s insane. Not only is it just straight-up evil and dangerous, but I have to imagine it puts their own population at risk, right? These things are not the kind of things you can just release in a controlled form or fashion and expect to only harm the other side of the world. Spores can float a long way on the winds. I just think that’s totally insane.
So, for people who have framed me in the past as overly dovish on China, just know that I’m at least trying to continue to pay attention to this and update my worldview as new evidence comes in, which from time to time it does.
Okay, these deals in the Middle East. I believe you were even there for some part of this conversation, right? And
Yes, I was not physically there for the announcement of a number of the Trump administration’s new deals there. I have been involved in a number of conversations. A number of the founders and companies I work with have been approached by both American and Middle Eastern data center providers, compute providers, and government folks who are all actively trying to create a joint ecosystem across the 2 regions, across the Middle East and the US. So I’ve just been peripherally involved in some of these conversations, but I was not there for President Trump’s trip.
Gotcha. I guess it seems pretty intuitive. We talked an hour-plus ago now, I think, at this point, about the strategy that the Middle Eastern countries are running to try to do something analogous to Singapore from the past generation in the financial system. They want to insert themselves into the global flow of tokens. That makes total sense. It’s obvious to me why these countries would want to do it.
Yeah. I also understand why the AI industry would want to do it, insofar as they are deep-pocketed customers, ready to buy, and all that good stuff. What’s a little less obvious to me is what the United States is getting out of it.
One question is: what is the bottleneck that these countries are relieving for us? Is it that they can muster energy faster? Is it that they can greenlight projects faster? Is it that they don’t need these things to be profitable, and so they’re willing to pay more than maybe American customers, counterfactually, would be willing to pay? What’s in it for the US? Why don’t we just do it all here?
So, one: they’re required to do half of it here. There’s a 1-to-1 match for all infrastructure they build out there; they have to build out a 1-to-1 match here. So that’s one. We’re getting a ton of foreign direct investment, a ton of infrastructure. That’s just a baseline requirement for all deal-making there on infrastructure deals.
The second is we get them to build on the American stack, not the Chinese stack. I mean, Huawei has been courting every one of these Middle Eastern hyperscalers or sovereigns aggressively for the last 2 years. I think—and I’m very glad—that we get a continued ally in the Middle East, or continued alliances. This is what we were talking about earlier. This is an extended version of our Marshall Plan.
So what do we get? We get more folks in our camp than in China’s. So I think we get a bunch of capital, more infrastructure funding in the US, which results in more chips and compute capacity for our companies here and our founders here, and we get more allies in the Middle East than allies with China.
So, I think we get a bunch of investment, a bunch of compute, and a bunch of geopolitical wins. So, yeah, I think it was a sort of win-win in that situation. And I think the hardest thing—or the thing we've got to watch out for, right?—is a defection from that alliance, right?
If I was one of the regions in the Middle East, by basically doubling down on America as my ally, I'm running the risk of alienating China, right? How do I protect against America in a future where America is, for whatever reason, not a reliable partner of mine? For the time being, they seem to think we're reliable partners, which is great, so I'm happy. But that wasn't clear, by the way, under the Biden administration.
I think the Middle East was in a place where they were being denied a local AI ecosystem. They were being denied certainty of chips, and that was driving them into the arms of China. I think things were getting pretty tense, where they were starting to have to build out and do sort of joint infrastructure. You know, the thing about infrastructure is, infrastructure is destiny. So, you have to plan on 20- to 30-year horizons, right?
And so, if you lose an ally in the first chapter, you're essentially predetermining the outcome 20 years in advance. There were moments in the Biden administration where we were basically driving the Middle East into the arms of China and therefore giving up the 20- to 30-year arc of the destiny of the infrastructure in that region to Huawei versus our guys. I think that's correct.
That's why I still come back to that question of just how ready China is to actually meet that demand. And I do agree with you that we should not underestimate it, and we should not just take one static point in time. It does still feel like it's at least a few years away, though, before China would actually be exporting AI infrastructure.
For these Middle Eastern countries, it seems like the deal with China is not now, but 3 to 5 years from now, if Huawei can scale to the point where there's surplus beyond what Alibaba and DeepSeek and all their own domestic major companies want to buy, which I assume is a lot. So, yeah. Yeah, totally.
3 to 5 years, but that determines the next 30 years. If you lose the first 3 to 5, you've lost the 30. That's the nature of infrastructure deal-making, right? You lose the first mile, you've predetermined the outcome 30 years hence. So, yeah, I kind of agree with you, but that is why the 3-to-5-year window is so critical. It doesn't really matter when, in a sense.
Yes, racking and stacking a frontier data center with Ascend chips might take 3 to 5 years, but the point is that it's an Ascend—it's a Huawei data center. And then what happens to the buildout? What happens with the next 500 megawatts of capacity and the next 500 megawatts of capacity?
You have now essentially set the Middle East on a path down the tech tree where success is predetermined over the 30-year arc in China's favor versus ours.
So, aside from this competition-with-China angle, what would you say is the next most compelling reason to do these deals? Is it because they can turn on energy super fast and we can't, or...?
Yes. So, I do think that, on a per-FLOP basis, there's roughly an 18% lower cost of energy, from what I can tell. Some of the marketing would be like, “Oh, you can get 50% energy gains,” but on liquid-cooled footprints, there's about an 18% lower cost of energy. Once I handicap it for a bunch of other factors, I think you get an 18% to maybe 20% lower cost of energy per FLOP by locating a Blackwell node in the Middle East—in the UAE or the Kingdom—than you do by locating it in the US without government subsidies here.
So, yes, there's a lower energy footprint there, partly because a bunch of these data centers are liquid-cooled with oil. So, yes, there's a pure sort of energy reason to do it.
Look, I also think one of the realities we have to contend with—until recently, with the new administration here—is that the Kingdom of Saudi Arabia and the UAE are countries with their own form of governance. They don't have democratic elections, but they do have the ability to move quickly when it comes to infrastructure and highways, right? They can get through regulatory red tape really fast.
And now that those regions are very aggressively pro-America and pro-modernization, they're changing dramatically the modern fabric of society, right? If you go to KSA, you'll often see a complete change in cultural values relative to 5 years ago. The speed at which you can get frontier data centers up because of the lack of red tape relative to other regions across the world is kind of crazy.
Whereas there are still parts of Europe where putting up a frontier data center can take 2 years of getting through red tape and approvals, in the UAE that's just not the case. So, even though there's a technical reason why the compute in these places is more energy efficient, there's also a speed-of-execution thing here.
Yeah. What do you think, as this develops, what is it going to look like in terms of personnel, control and governance, and literally military protection? So, what I mean there is: okay, we know it's going to be in the UAE or Saudi Arabia, but who's going to build it? Are we going to have Americans over there doing the building? And does that create a vulnerability where, for these countries, the US could at some point say, “Everybody has to come home”?
Are there other governance things? I've heard—and this is an unverified rumor—that in some part of some of these deals there's an agreement on an off switch that's supposedly remotely controlled. I don't know if that's true or not, but that obviously would be an interesting sovereignty question.
And then, literally, missiles are flying right now, right? We've had recent episodes of US aircraft carriers reportedly having to turn fast to avoid missiles, to the point where they're dumping planes over the side of the aircraft carrier. Yeah, and data centers aren't so maneuverable.
So, I don't know, does this also imply a major expansion of the American defense umbrella to protect these assets? Because if we have gigawatt data centers in the desert in the Middle East somewhere, everyone's going to know where they are, and they're not going to be that hard to hit with a missile. They're much harder to hit in the US than they would be over there, right?
So, what deterrence do we have, and what sort of promises do you think we might be implicitly making? So, anyway, there's personnel, governance of the sort of off-switch variety, and the risk of missiles.
Yeah, yeah. So, this is a good question. The framework you want to apply to this is dual-use technology, right? Because AI is a dual-use technology. It's often governed by civilian law, a certain body of work that is separate from laws that govern defense capabilities and so on, which govern non-dual-use technology.
If you're talking about a frontier data center that is classified for mission-critical workloads, actually, the construction of these data centers is classified information. It's confidential. It is quite hard to trace, for a number of reasons.
Like other sorts of critical national infrastructure, the set of protocols that go with the setup of those data centers is different from traditional data center construction protocols. You can't just treat them like a traditional Google data center. It doesn't show up in regulatory filings, and the construction protocols do not look like traditional data center construction protocols.
For better or for worse, right now, because model training happens in a different place than inference, the data centers running mission-critical inference workloads can be quite small. You don't need 100,000 Blackwells in one place to run military workloads or national-security workloads.
From a pure physical, brick-and-mortar perspective, they're not that easy to trace. Their footprint is different. They can often just be inside what looks like a department store on the outside. Then there's the whole part of counterintelligence and so on.
Let's say there's counterintelligence from an adversarial nation that figures out where these workloads are running, and they will be targeted. Then the analysis you want to do is basically: what is the threat vector, and what is the frontier of warfare in that situation?
If it's an aerial threat vector, then you're essentially running the UAV playbook. These data centers—at least the ones that are civilian data centers in the Kingdom and so on—are governed by their laws, their military posture, and their aerial playbooks. So, I don't think the analysis is AI-specific, is my point. That just applies to any kind of asset.
The risk of that particular asset being attacked is no greater or lower than the risk of any national-security asset there. It depends on basically how good the government there is at defending its best assets. So, I don't think it requires a net-new expansion if you're talking about the physical footprint of these data centers.
There's a whole other analysis we could talk about, which is the weights. And this is why open source is so effective, because if your entire national-security apparatus is predicated on the idea that weights don't get stolen, then I don't know how to protect you.
Yeah, exactly. I think that remains, including in the United States, a completely unsolved problem. There have been Chinese citizens who have been caught boarding planes from the US with TPU schematics.
I think there was a Google engineer. I don't think there's a panacea right now within the U.S. frontier labs to prevent model weight exfiltration. That is real. If our adversaries—if China—wants the weights, they're getting the weights right now.
Yeah, I think everybody—yeah, I think that's the case at this point. I don't think we should expect other countries to be able to do something even we can't do yet.
Yeah.
All good. This has been—you've been very generous with your time, and I really appreciate it. Do you have any closing thoughts? Anything we didn't touch on that you want to share? We've covered a lot of ground, that's for sure.
No, we should do a part 2. I don't think we got to talk about Taiwan at all, which is a whole other can of worms. But I think that's a critical part of the story. Depending on how Taiwanese sovereignty plays out over the next 2 or 3 years, the arc of how the rest of the compute infrastructure and the rest of sovereign infrastructure plays out will be quite different. So that's for next time.
Yeah, talk about a big domino, to say the least. Yeah.
Yeah. Yeah, that's one of those reasons that I'm still not sold on the export controls, because I feel like, if nothing else, it's clearly making it that much easier for some big move to be made on Taiwan, as opposed to the scenario where China was getting the chips.
But I've said that on this feed many times. So, cool. Any other closing thoughts? I mean, we can definitely check in. I feel like the cycle times are getting shorter and shorter, so I don't know if it's 6 months away or 3 months away when we'll have to come back and evaluate all of AI and geopolitics, but something tells me it won't be all that long. Any other closing thoughts?
No, that's exactly it. Everything we discussed today should be treated as subject to shorter and shorter time spans of relevancy. So, see you Monday.
Sounds good. Anjney Midha, general partner at a16z. Thank you for being part of The Cognitive Revolution.
Thanks for having me.