The Anatomy of the AI Cold War
Sovereign AI
Back to Writing
Jul 6, 202611 minutes

The Anatomy of the AI Cold War

Happy summer break. When you return, AI will have changed forever.

Imagine opening Claude to draft a resignation letter you haven't told anyone about yet. Before you can type a word, it asks you to verify with MitID. Somewhere, that request just got logged, tied to your legal identity, sitting on an American server. Welcome to the AI Cold War and the Political Era of AI, where Europe will have to make a choice.

Many analysts have predicted this moment would come. In his Situational Awareness paper from 2024, Leopold Aschenbrenner warned that as AI approached human-level capabilities, it would inevitably be absorbed by the national security state, culminating in a classified, Manhattan Project-style takeover. Concurrently, Daniel Kokotajlo’s AI 2027 correctly predicted that a "Regulatory Squeeze" and institutional friction would act as a massive dampener, delaying public deployment precisely because linear political structures cannot cope with exponential code.

There are several reasons why political interest that has been brewing in the AI pot for some time is now finally surfacing. Some even speculate that political control may be too late. Of course, the Mythos export ban is attracting most of the attention on this although this is merely a symptom of something much larger at play. A series of key events over the last three weeks indicate that we may be on route to an actual Cold AI War.

Explore the Cold War field guide

Explore the interactive AI Cold War field guide

How did we get here?

The first half of 2026 is proof that AI got expensive before it got efficient. So, companies started looking for alternatives. Those alternatives are open models, and increasingly Chinese ones. They already carry the majority of open-model traffic on platforms like OpenRouter, priced 10 to 30 times below American rates. Press has dubbed this pressure the Tokenpocalypse, the moment enterprises discovered that running AI at scale doesn't get cheaper the way everyone promised. It gets unpredictable, because agentic tasks now trigger ten or twenty calls to the model instead of one. Uber capped what employees could spend. Microsoft pulled internal licenses. Every dollar that migrates away from American labs is a dollar China's open models can pick up instead, and by summer, the shift was showing up in the numbers. In just a year the marketshare of tokenspend for American models went from 70% to 30% on Openrouter. China now dominates with 47% of the market. This was not accidental. The US practically abandoned the open arena, when Meta discontinued its investment. This means China has won the easy battle of the open-weight AI infrastructure of the world. Now the US is practically reaping what it sowed.

A second reason for the current shift we are seeing is that the gap in AI capability is closing faster than anyone expected and it’s closing from the wrong direction for Washington. While Mythos sat locked away, several actors showed how far strong harnessing can carry a weaker model, better prompts, better orchestration, better tool use, elevating even Chinese open models close to Mythos-tier on specific tasks. Security researchers at Semgrep showed this directly: GLM 5.2, an open Chinese model, beat Claude on a hacking benchmark with nothing but a plain prompt. Another lab, Intelligent Internet lifted the performance of GPT 5.5 and managed to make it beat Fable on software engineering tasks just by building a tailored harness. This indicates something important. The race is no longer just about powerful models. How you utilise them matters increasingly.

The bottom-line for any legislator is that the genie is already out of the bottle and unless you dial back current AI progress, the technology is now out there for anyone to pick up and harness. The moment for regulation may already have passed.

Layer distilling on top, the technique labs use internally to shrink a strong model into a cheap one, and the picture sharpens further. Distillation is a common post-training technique in AI labs. Think of it like a teacher-student method where Mythos is tutoring smaller models like Opus or Sonnet by distilling its knoweledge into their weights. But the technique is not limited to closed labs and can be used by anyone. Anthropic told the US Senate that operators tied to Alibaba's Qwen lab ran roughly 25,000 fake accounts through Claude, generating 28.8 million exchanges. The business model is simple: Chinese shell companies offers Claude-level intelligence at a fraction of the price to users, then use their data to distil Chinese open models further.

Add all this up, and we see why experts are now speaking openly about America's shrinking lead in the race against China. That fear, of losing the race outright, could very well be a key reason for what happened next.

Washington's actions wasn't just fear of one dangerous model. It was fear of losing control of the race itself, and Mythos gave it the perfect pretext to grab that control. AI saw a major leap in capability this spring, reportedly finding flaws in almost all of NSA's own classified systems in hours during an authorized test, elevating the technology from useful and efficient to a security risk overnight. Washington now controls the access and pace of American AI through a 30-day government review before any frontier release. Slow the releases down, tighten who gets to see what first, and you also slow down exactly the kind of harvesting China has been doing. Whether that's the stated goal or a convenient side effect depends on who you ask. Either way, the intent is to regain control of the technology.

Meanwhile, an entirely separate wall fell. Europe's last hope for safe harbouring data in the US evaporated on June 29, when the Supreme Court ruled the president can fire the heads of independent regulators, like the FTC, at will. European companies had told themselves American cloud services were legally safe because an independent FTC stood behind the data agreement. That independence is gone. Nothing about this ruling has anything to do with the AI race. It just happened to land in the same month, and it means the ground under any American AI deal just moved too.

It is easy to see how the gravitational pull toward open models only becomes stronger for regions like Europe. Imagine being able to host and control models, forecast costs and control data with full autonomy. But of course there a no roses without thorns and when it comes to large AI models, full control is very much an illusion because the models are very hard to monitor. Weight-poisoning is the open-model version of a supply chain attack: because a model's parameters are published and downloadable, someone can bury a hidden trigger inside them before release, invisible to standard safety checks. All it takes is one line of malicious code to introduce a backdoor and the illusion of control evaporates. Cheap and open isn't the same as safe.

So, this is where we are: political control of AI has arrived in Washington, and it isn't leaving. It arrived exactly as companies grew tired of paying for AI that didn't deliver on its promised efficiency, pushing them toward cheap, open, mostly Chinese alternatives, right as Washington watched its lead shrink and reached for control to slow the bleeding. Trust in China sours over distillation even as companies keep buying, and open models remain unregulated for the one risk that matters most: nobody is checking what's hidden inside the weights.

What comes next?

There is no question that June was a milestone in several regards. As we look ahead on the last six months of the year, it seems very likely that we have entered an era of AI that will look remarkably different from the one we left.

August is the cutoff

The US regulation is being worked on this very moment, and it will determine how the AI game is played going forward. An executive order signed June 2 gives federal agencies until August 1 to stand up a classified process that sets the threshold for which AI models count as a “covered frontier model,” exactly the kind of designation Mythos would meet. The NSA Director makes that call, in consultation with other agencies. We don’t know what criteria will be used, as they are classified. The labs that participate will presumably learn how their own models score. The public won’t.

Participation is listed as voluntary, meaning developers can choose to give the government 30 days of pre-release access. But the turmoil around Fable and Mythos already showed what voluntary looks like in practice: a worldwide shutdown, then reopening only through a trusted-partner arrangement that pulled the government into the release, weeks before this framework even existed to make such an arrangement routine.

The balance the administration is aiming for is commercial freedom at home, tight control at the border. This isn’t a temporary Trump policy. Once the NSA has built the machinery to secretly test and review AI models, it stays built. A future government, of either party, doesn’t have to invent it again. It just has to decide whether to use the switch that’s already sitting there.

The real concern

Regulation slows releases. It doesn't slow capability. The next Mythos is probably already running inside a lab somewhere, and it's reasonable to assume labs and governments can see further ahead than the rest of us. What looks like an effort to contain today's model may really be a pre-emptive move against what comes after it.

The actual turning point, the one many AI researchers treat as the real point of no return, is the moment a model becomes good enough to build its own successor. This isn't abstract. OpenAI's own safety framework already has a formal category for exactly this: a "Critical" risk tier defined as a model capable of fully automated AI self-improvement. Anthropic says over 80% of the code merged into its own production systems is now written by Claude.

Distillation feeds this directly: a recent US policy analysis argues that because distillation lets Chinese labs generate training data by leveraging American infrastructure, it frees up their own scarce compute for exactly this kind of self-improvement research, and once one Chinese developer extracts those gains, every other Chinese lab can distill from them too.

Imagine the version of this that matters:

China distilling enough of a future American frontier model to ask it how to rebuild itself from scratch. Some researchers still reject the whole idea of an intelligence explosion. The most-cited forecast, from Anthropic co-founder Jack Clark, puts it at a 30% chance by 2027 and 60% by 2028, not exactly consensus, but not fringe either. Once a model can meaningfully improve its own successor, the zero-days and export bans that dominate this essay start to look like peanuts. The fight stops being about who has the better model, and starts being about who controls the thing building the next one.

A Battlefield with two Fronts

It is clear by that stakes are increasing and the Cold AI War has two battlefronts, fought simultaneously: keeping Chinese models out, and keeping American intelligence in.

Keeping Chinese models out. The first battlefront is commercial. If open models keep growing in enterprise adoption, American frontier labs face mounting commercial pressure. Open models currently act as the trojan horse China is using to undermine the market share and valuation of the American labs, and unless someone fixes the current, broken tokenomics, this is likely to continue. But the entire AI economy already runs on subsidized capital, not profit, so expect this fight to be waged politically as much as commercially. The battle against cheap Chinese tech isn't new, and the US already has a set of cold weapons it could put to work:

  1. Blacklisting. Cuts off Chinese lab access to US chips and cloud.
  2. The Huawei playbook. Makes companies who use Chinese tech toxic to their US clients.
  3. Bureaucratic friction. Buries companies using Chinese models in audits they can't pass.
  4. The TikTok Treatment. Full ban on service which flips the switch and kills US API access

Four escalating options, and even the harshest one can't delete a file someone already downloaded.

Containing the American intelligence. The second battlefront is political, fought on the terrain of industrial espionage. There's no doubt malign distillation sits at the center of the political framework being written right now. Labs are already taking their own precautions: tighter access controls, hiding the reasoning trail, shaping answers so a stolen conversation teaches a rival less than it used to. These are a clear sign the war is already shaping product design, and just as clear a sign of where the technology hits a wall without actively degrading the product for everyone else. A model's entire purpose is to answer the question put to it, which means "helpful" and "being harvested" look identical from the outside. Every fix on one front becomes a cost the other side simply routes around. Neither side wins this outright. Both sides just keep fighting it, because the thing being protected and the thing being stolen are the same interface, doing exactly the job it was built to do.

Where the technology stop, the power of the administration takes over, and that's why access to AI is about to be governed in a way it never has before.

KYC becomes the new standard

As security is becoming a central concern in AI many expect a familiar tool from the financial sector to enter the industry: KYC, or Know Your Customer, widely used to validate identity and prevent fraud.

OpenAI already requires a government-issued ID and a live selfie check before you get API access to its most advanced models, adopted partly because DeepSeek-linked accounts were caught harvesting its outputs. Expect this to become standard procedure across frontier models in the coming months.

If you actually want to plug the distillation gap, checking ID on the companies building models isn't enough. You'd have to start requiring verified identity on ordinary conversations, the kind you and I have with Claude every day, not just on the big enterprise accounts training something large.

Europe is arriving at the same destination from a completely different direction. The EU's digital ID wallet becomes mandatory for large platforms within the next year, with Denmark's beloved MitID feeding directly into it. A German pilot has already tested it authenticating AI agents. Whether you like it or not you'll soon need a verified identity to have a serious conversation with an AI.

Privacy is the first casualty for Europe

Europe's legal right to send data to US cloud services rests on the FTC being independent. This assumption is cited 259 times in the agreement that makes it legal. And that this assumption is now false.

Until this June, there was at least a theoretical limit on who could reach into that data: an independent regulator had to sign off, a court could be appealed to, somebody existed that didn't answer directly to whoever happened to be in the White House. That limit is gone.

Combine it with the CLOUD Act, which already lets US authorities compel an American company to hand over data no matter where it's physically stored, and you get a system where a European user's full conversation history, now tied to a verified identity thanks to KYC, can be requested by the US government with no independent body left to say no.

The Trump administration has spent the past year expanding Palantir across federal agencies, IRS, DHS, and others, building exactly the kind of system that fuses scattered data into a single, detailed profile of a person. The IRS alone has paid Palantir over $130 million to mine its databases. That's the infrastructure already running on Americans' own tax and government records.

Every serious conversation with an American AI model now sits inside a system with logging built in, identity attached, and one office in Washington that can reach it, with no independent check left standing. And there is not much Europe can do about it.

How will this impact our use of AI? Companies handling sensitive work, healthcare, law, finance, government, will have to treat US AI tools as restricted or banned outright. More people might quietly self-censor what they type. One thing is certain: we can’t keep banging the “sovereign European cloud"-drum just by location only. As long as it sits with an American company, storing the data in Frankfurt doesn't change who can be legally compelled to hand it over.

Europe has to pick a side

This brings us to the question Brussels has spent two years ducking: if Washington makes continued access to American AI conditional on Europe formally siding against Chinese models, what does Europe say?

Say yes, and European hospitals, banks, and ministries run on infrastructure that answers to the judgment of one office, whoever holds it, with no court left to appeal to. Say no, and the fallback is open models that are increasingly Chinese, carry a security risk nobody can fully audit, and offer no legal recourse of their own.

There's no safe third option waiting in the wings although Europe's own open alternative, Mistral, is genuinely trying. Billions committed to data centers outside Paris and in Sweden, revenue up twentyfold in a year, an open-weight model line that hasn't closed the way Meta's did. That's not nothing. But it's fragile and it's a one-horse race. America runs OpenAI, Anthropic, Google, X.ai and Meta against each other. China runs DeepSeek, Alibaba, Zhipu, Moonshot, and MiniMax against each other. Europe has exactly one serious bet, and if it stumbles, there's no second horse waiting. Mistral's CEO Arthur Mensch admits that the company doesn't have the best models yet, only that it's closing in on them, and that even startup founders in Mistral's own backyard in Paris still reach for Claude first.

Maybe Europe doesn't need a model that beats Claude or Qwen. What it needs is enough of its own tech that if either one gets switched off tomorrow, businesses keep working while they figure out the next move. In the great Maslow pyramid of AI needs, Sovereignty sits at the self-actualization tier, the flattering story we Europeans love telling about ourselves. But self-actualization is empty talk if the shelves below it are bare. Before anyone's earned the right to talk sovereignty, there's unglamorous stock to fill: working compute, working hosting, a fallback that actually runs when someone else flips the switch. That looks less like sovereignty and more like a backup generator. But a generator gives you something to negotiate with. And as the temperature cools in a new era of AI Cold War, that's one honest, achievable goal Europe can hope for.

L

Lars Harder

Writing on sovereign AI, digital identity, and what it means to remain human in an era of algorithmic culture.

// more reading