I recently had a chat with Hannah Betts about national data sovereignty and AI sovereignty. I’m sceptical about much of the discussion about this topic. Mostly because there is very little evidence that it is a real (rather than theoretical) problem, and because most of the responses confuse the physical location of the data with the jurisdiction that applies to that data. But recent events with Anthropic and Fable have forced me to rethink this.
Traditionally in the cyber security industry we have thought about national data sovereignty (the ability of a country to control its data) and jurisdictional risk (risk that comes from the legal jurisdictions that organisations and their suppliers operate under) in terms of confidentiality. The basic worry is that if my data is physically located in another country then that country’s law enforcement and security intelligence services have some form of privileged access to that information.
However, events over the last few years have made me think that this is not the whole story. I am beginning to think that jurisdictional risk has changed. And that now the thing to fear is that powerful states will disrupt our access to the information systems we depend upon. That jurisdictional risk has shifted its centre of gravity from a threat to confidentiality to a threat to availability.
Weaponised interdependence
There is a term for this in international relations: “weaponised interdependence“. The practice of powerful states using their control over the interdependent supply chains that are a part of modern globalisation to further their interests. They can abuse the chokepoints in these supply chains to threaten or punish countries. And people and organisations in those countries can end up as collateral damage.
Several events have led me to think that this weaponised interdependence could be a factor in cyber security and AI risk. The first one was the restrictions on US made software and cloud services to Russia and Russian organisations. In 2022 it was widely reported that Microsoft had stopped providing Windows security updates to Russia, and then in March 2024 it was widely reported that Russian users would lose access to Microsoft and Amazon cloud services. This was in part due to US sanctions on Russian organisations. Sanctions being a form of weaponised interdependence.
More recently the US government restricted access to Anthropic’s frontier model Fable 5. While this was rescinded a few days later, it raises the spectre of export controls denying us services that we depend upon.
It isn’t much of a stretch to imagine a US that wields export controls in the same way that it has weaponised tariffs. If the US government can use its power over the interdependence of global trade to coerce countries to toe the line on Greenland (half of Europe) or forest fires (Canada) then it’s not a stretch to imagine that government signing an executive order denying frontier models, AI models or even cloud services to countries that displease it. Even longstanding allies, like New Zealand.
Not just supply chain risk
You might think this is just a variation on standard supply chain risk. But what makes this different is that it is all about state power. Your standard supply chain security measures aren’t going to help here. Your due diligence, and your suppliers’ security measures don’t help if their government forbids them from delivering services in your country. Ordinary supply chain risk management tells you to diversify suppliers but that won’t help if they are all in the same jurisdiction – because it is the state who is the threat. Diversify jurisdiction and this problem recedes.
Managing the new jurisdictional risk
So, what can you do to manage this new and ‘improved’ jurisdictional risk? My first point is that controls to manage the confidentiality version of this risk don’t cut it. Bring your own key (BYOK) doesn’t help if you can’t access the data. The question has moved from “who could read this” to “who could switch this off, and what would we do the morning after.”
What will help are those measures designed to manage complete loss of service:
- A business continuity plan that addresses the blocking of access to the service.
- Diversifying the jurisdictions that you source services from.
- Creating solutions that are portable to other services.
- Defined exit strategies.
But in some cases – like frontier AI – where there are no practical alternatives, it may be all about accepting the strategic risk. Which is a board level conversation, not a technical one.
So, maybe I’m not as sceptical anymore. Maybe they were right about this – and maybe I was wrong. Though not for reasons we all thought. Welcome to the new era of jurisdictional risk – where you now need to factor in governments using their power to disrupt the availability of those services you depend upon. That faint noise you can hear is a thousand fingers tap-tap-tapping as we all update our risk registers.
