Why the Sovereignty Debate Matters More than Governments and Industry are Admitting?

There is a necessary debate underway about how nations should position themselves in relation to AI capability. The Tech Policy Design Institute’s November 2025 paper, “From AI Sovereignty to AI Agency,” makes a compelling case that the binary framing of sovereignty, own it or don’t, is too blunt a policy instrument for a globally connected AI ecosystem. The paper proposes replacing it with the concept of agency: a nation’s capacity to maintain a strategic combination of access, control, choice and leverage over AI capabilities. It is a sophisticated reframing and it is wrong in ways that matter.

The paper is correct that sovereignty is contested and poorly defined and that Australia cannot and need not lead across every AI capability. It is also correct that resilient, diversified access to international capability is valuable and that strategic leverage can take many forms.

But the framework rests on an assumption that the events of June 2026 have contested: that access, reliably maintained and contractually protected is a meaningful substitute for control in mission-critical contexts.

It is not and the legal architecture of the major technology jurisdictions makes clear why contractual protections between an organisation and its vendor cannot resolve that problem.

What Access Actually Means Under Foreign Law

When an Australian government agency or enterprise deploys AI capability through a foreign-owned platform, it enters into a contractual relationship with a vendor. That contract will typically include data residency commitments, confidentiality protections and provisions governing how the vendor may use or disclose the customer’s information. These protections are real within the bounds of the contract. They are not real outside them and the legal frameworks of the two dominant AI jurisdictions, the United States and China each contain mechanisms that operate entirely outside the bounds of any commercial contract.

The United States Clarifying Lawful Overseas Use of Data Act, passed by Congress in March 2018, requires US-headquartered technology companies to produce data they control regardless of where that data is physically stored. Jurisdiction follows the vendor’s domicile, not the data’s location. An Australian agency that has negotiated data residency in an Australian data centre and has received written contractual assurances that its data will not leave Australian shores, remains subject to a lawful US government request directed at the vendor’s US parent entity.

The vendor’s contractual obligation to the Australian customer is subordinate to its legal obligation to the US government. No contract can make it do so. The Australia-US CLOUD Act Agreement, which entered into force on 30 January 2024, established a reciprocal framework for law enforcement data requests between the two countries but it does not limit the US government’s existing authority to compel US-headquartered vendors to produce data they control.

Access is not control

Data residency is not data sovereignty.

The Chinese legislative framework operates through a parallel but distinct mechanism. China’s National Intelligence Law of 2017 requires Chinese organisations and citizens to support, assist and cooperate with national intelligence efforts. China’s Data Security Law which came into force in 2021 and was supplemented by cross-border data flow provisions that took effect in March 2024 establishes state oversight of data exports and imposes obligations on entities handling data the state classifies as important. A contractual confidentiality clause between a vendor and its Australian customer does not override this obligation.

The critical insight both frameworks share is this: the legal obligation runs to the state, not to the customer. No commercial contract, however carefully drafted can create an obligation that supersedes the vendor’s domestic legal requirements. Data residency clauses, encryption commitments and confidentiality protections all operate within the space that foreign law permits them to occupy. When that space narrows, the protections narrow with it.

Why Contractual Protections Cannot Close the Gap

The response most organisations receive when they raise jurisdictional risk with their technology vendors is some version of the following: the contract includes strong protections, the vendor will notify the customer of any government request where legally permitted, the data is encrypted and access controls are robust. These responses are offered in good faith and they describe real features of sophisticated enterprise agreements.

They do not address the structural problem because the notification commitment is subject to the vendor’s legal ability to notify, which under both the US CLOUD Act and Chinese national security legislation may be constrained or prohibited entirely.

A government may accompany a lawful data request with a non-disclosure requirement, in which case the vendor cannot tell the customer anything has occurred. The customer’s contractual right to notification is in that circumstance, unenforceable not because the vendor has breached the contract but because the vendor is legally prevented from performing it.

A government may accompany a lawful data request with a non-disclosure requirement, in which case the vendor cannot tell the customer anything has occurred. The customer’s contractual right to notification is in that circumstance, unenforceable not because the vendor has breached the contract but because the vendor is legally prevented from performing it.

The encryption argument requires similar precision. Encryption protects data in transit and at rest against unauthorised access. The CLOUD Act is explicitly encryption neutral, meaning it does not in itself compel vendors to decrypt data. What it does is compel vendors to produce data in their possession or control in accessible form and the government retains separate legal mechanisms, including through FISA Section 702, to compel cooperation in making that data legible. The practical consequence is that encryption managed by a US-headquartered vendor does not provide meaningful protection against a lawful US government request, because the government’s authority runs to the vendor who manages the keys, not merely to the data they protect.

The ICC provides the clearest illustration of where this leads in practice. Karim Khan, the Chief Prosecutor of the International Criminal Court, headquartered in The Hague and operating under international law, was temporarily locked out of his Microsoft Outlook account following a US government request in 2025. An institution operating under the Rome Statute, with no US jurisdictional nexus other than its use of a US-headquartered technology vendor, found its working environment disrupted by a US government action directed at that vendor.

Beyond data access, foreign governments also hold the authority to restrict what a vendor can provide to its customers, not just what information the vendor must disclose. That is a different and in some respects, more consequential power and it operates entirely outside the contractual relationship between vendor and customer. The broader point is that contractual protections are enforceable between the parties to the contract. Foreign governments are not parties to the contract. Their legal authority over the vendor is not derived from the contract and is not limited by it, so treating contractual protections as a solution to jurisdictional risk is a category error and it is one that procurement decisions across the Australian public and private sectors are currently making at scale.

June 2026 Made the Argument Concrete

On 12 June 2026, the US Commerce Department issued an export control directive under the Export Controls Reform Act of 2018, requiring Anthropic to suspend access to its Fable 5 and Mythos 5 models for all foreign nationals globally, including Anthropic’s own non-citizen employees. Anthropic received the directive with no advance warning. The letter provided no specific detail of the national security concern beyond a reference to a potential jailbreak technique. Upon finding that filtering access by nationality across its global infrastructure in real time was not technically feasible, Anthropic disabled both models for every customer worldwide.

Organisations that had procured licences, built workflows and planned programmes around those capabilities lost access within hours, through no failure of their own and with no contractual remedy available to them. Standard enterprise agreements including force majeure clauses and compliance-with-law provisions, provided no practical recourse. With the widespead use of AI automations, economies can be bought to their knees.

The event is significant not because of its scale, though the disruption to enterprise customers across finance, healthcare and critical infrastructure was considerable but because of what it demonstrated about the structure of the relationship between foreign AI vendors, their customers and the governments that hold legal authority over the vendor. The customer had a contract. The contract was not breached. The access simply ended, because the government that held authority over the vendor decided it should.

No contractual provision in any enterprise agreement currently on the market provides protection against that outcome, because the outcome does not arise from a breach of contract. It arises from the exercise of legitimate sovereign authority by a foreign government over an entity that the Australian customer has no power to influence.

This is precisely the scenario that the agency framework’s reliance on resilient, diversified access cannot accommodate. Diversifying across multiple US-headquartered AI vendors does not reduce exposure to US export control authority. It multiplies it. And a directive of this kind does not discriminate between customers who have one vendor and customers who have three.

The Agency Framework’s Blind Spot

The TPDi framework defines AI agency as the capacity to maintain a strategic combination of access, control, choice and leverage over AI capabilities. It proposes that nations need not own or control every capability to exercise meaningful agency and that resilient, diversified access to international capability is a legitimate and often preferable alternative to domestic development. This is a reasonable proposition for many categories of AI capability and the paper’s six-layer typology provides a useful structure for thinking about where domestic investment is most strategically valuable.

The framework’s weakness is that it treats access as a stable condition that can be maintained through good procurement practice, diversified supply chains and careful vendor management. The jurisdictional analysis above suggests that access to foreign-owned AI capability is not stable in that sense. It is conditional on the continued willingness of a foreign government to permit that access and on the absence of circumstances that might cause that government to restrict it. Those conditions can change without warning, without explanation and without any mechanism for the Australian customer to seek redress.

The agency framework scores Australia’s position across 101 AI capabilities and provides a measure of agency for each. But the scoring does not adequately capture the asymmetry between access that is contingent on foreign government discretion and control that is exercised under domestic law. An organisation that has diversified its AI vendor relationships across three US-headquartered providers has not meaningfully reduced its jurisdictional exposure. It has distributed its dependency across three entities all subject to the same foreign legal authority.

A Question the Framework Does Not Ask

The TPDi paper is transparent about its funding, which is a genuine and meaningful commitment to accountability. Its founding sponsors include Amazon, Apple, Microsoft, Salesforce, Adobe and Atlassian, alongside Australian government departments, the Australian Computer Society, Commonwealth Bank and the Minderoo Foundation. The institute operates a blind trust structure under which funders commit not to direct outputs and agree to public disclosure of their support. Those are meaningful structural protections and they should be acknowledged.

What they do not resolve is a structural tension that research ethics has long recognised: funders do not need to direct outputs to influence institutional thinking. The selection of research questions, the framing of policy problems, the choice of which trade-offs to foreground and which to treat as manageable, all of these reflect assumptions that develop over time in environments shaped by the interests of institutional supporters. It does not require bad faith. It requires only that the people doing the research operate, as everyone does, within a set of assumptions about what problems are worth solving and what solutions are plausible.

Amazon, Apple, Microsoft and Salesforce are US-headquartered multinational technology companies with significant commercial interest in Australian enterprise and government procurement of cloud and AI services. They are precisely the category of vendor whose market position is strengthened by a policy framework that treats access to their platforms as a legitimate form of national AI agency rather than requiring domestic sovereign alternatives. A framework that concludes resilient, diversified access to international capability is often a sufficient substitute for domestic control is a framework that is commercially convenient for those vendors. Whether that convenience influenced the framework’s design or simply happened to align with it is a question the funding structure alone cannot answer. It is, however, a question that Australian policymakers and procurement decision-makers should hold in mind when assessing the framework’s conclusions, particularly in the context of mission-critical capability decisions where the consequences of getting the answer wrong are not recoverable.

The point is not that TPDi’s researchers lack integrity or that the framework is deliberately constructed to serve commercial interests. The point is that the framing of a policy question, what counts as adequate sovereignty, what level of foreign dependency is acceptable, what risks are manageable through contracts versus structural alternatives, is never neutral. And when the institutions that shape that framing are substantially funded by the parties who stand to benefit from one answer over another, that is a fact worth naming clearly.

Where the Tension Resolves

None of this is an argument for autarky in AI capability. Australia cannot and should not attempt to develop sovereign alternatives across every layer of the AI stack and the TPDi framework is correct that strategic leverage, international partnerships and diversified access are valuable instruments of national AI policy. The argument is narrower and more specific: for capabilities that govern mission-critical operations, hold sensitive or classified information or form part of the governance and accountability architecture of public sector entities, access to foreign-owned infrastructure is not a substitute for Australian ownership and control, regardless of how carefully the contractual protections are structured.

The distinction the agency framework glosses over is between capabilities where disruption is inconvenient and capabilities where disruption is consequential. For the former, diversified access and strong contracts may be entirely adequate. For the latter, the June 2026 event demonstrated that the contingent nature of access to foreign capability is not a theoretical risk to be managed at the margins. It is a structural feature of the relationship between a vendor and the government that holds jurisdiction over it.

Organisations and agencies that are currently relying on contractual protections to manage their jurisdictional risk exposure should examine that reliance carefully. The question is not whether the vendor intends to honour the contract. The question is whether the vendor will remain legally able to do so if the government that holds authority over it decides otherwise. On current evidence, the answer is no and no contract can make it yes.

DOLIUM is an Australian-owned, designed and developed System of Work, IRAP-assessed and listed on the DTA Software Marketplace Panel. Its open architecture means the operating logic, audit trail and governance framework remain permanently under enterprise control within the juridiction of where it operates, with no licensing arrangement capable of affecting that right.

To explore how DOLIUM’s System of Work fits your operating model, book a briefing with the team.