← Back to writing

Starved by Design: The Sovereign AI Paradox

9 min read
Starved by Design: The Sovereign AI Paradox

Sovereign AI is being pitched to the national security community as a straightforward capability upgrade, yet the paradox holds regardless of vendor: the more classified the network, the worse the artificial intelligence running on it tends to be, because every technique that makes modern AI capable, live retrieval, fine-tuning, a connection to a frontier model, needs data to move, and a classified network's entire purpose is to stop data moving. That gap is a structural feature of how these systems are currently built, not simply a funding shortfall Australia can spend its way out of, though it narrows as local techniques improve. As Australia invests in sovereign and next-generation capability through programs like the Australian Signals Directorate's REDSPICE and the National AI Plan (Australian Signals Directorate, 2022; Department of Industry, Science and Resources, 2025), we owe ourselves an honest conversation about what a sealed enclave can and cannot do.


This article argues that the honest national posture is to master the control of AI, not to chase the fantasy of creating it.

The question I keep coming back to is this: why do we assume the high side gets the best technology, when everything about the high side is designed to stop technology working the way modern AI needs it to?

Introduction

Sovereign AI is the buzzword of the moment, and like most buzzwords it means five different things to five different people in the same meeting. For some it means training frontier models onshore. For others it means running someone else's model on Australian soil. For the national security community it usually means one thing above all, keeping the data, the model, and the inference inside a boundary we control.

That instinct is correct. The problem is that the same boundary that keeps our secrets safe also starves the AI we put behind it, and almost nobody selling sovereign AI into government wants to say that out loud.

The Starvation Chain

Modern AI is hungry. Retrieval-augmented generation needs a constantly refreshed corpus. Fine-tuning needs data to learn from. Frontier models need to be reached and updated. Every one of those needs assumes data can move.

On a classified network, data cannot move freely. That is the entire point of the network. So follow the chain, because each link forces the next:

  • Classification boundaries stop data flowing. Material sits at OFFICIAL, PROTECTED, SECRET or above under the Protective Security Policy Framework, and moving it up or down is a controlled, deliberate act, not a background process (Department of Home Affairs, n.d.).

  • Data that cannot move cannot feed the model. Your retrieval index goes stale. Your fine-tuning set is a fraction of what exists. The model reasons over yesterday's picture.

  • A stale model on an air-gapped network has no live route to a frontier provider. You run what you can host locally.

  • What you can host locally is smaller and older. A model you can stand up inside a sealed enclave is, today, behind the frontier, though the gap between the best open models and the frontier is narrowing, and it costs more to serve because you are buying and running the hardware rather than renting inference by the token.

Before following that chain to its end, the strongest version of the other side deserves stating, because the people who wrote these rules are not blind to what they cost. The Protective Security Policy Framework did not starve the high side by accident: classification boundaries exist to trade capability for containment, deliberately, because the alternative, a data-hungry model with a live path to a frontier provider, is also a live path for an adversary to walk the same corridor in reverse. That reading of intent is mine, not a quotation: no instrument I can point to says in terms "we accept a capability penalty here". What the framework does say is what it is for, and containment is plainly it. I would rather state the inference and let you weigh it than borrow authority the documents do not offer. On that view, a stale, smaller model is not a flaw in the enclave, it is the enclave working exactly as designed, and asking it to feed as freely as a corporate network is asking it to stop being classified. That case deserves real weight, and I concede the core of it: nobody should design an enclave that trades its security guarantee for a smarter assistant, and if that is the honest choice on offer, take the security every time. What the trade-off case does not answer is the part of this article that is actually new. Agencies are not, in practice, being told they face this trade honestly. They are being sold sovereign AI as though the enclave will feel like the tools on the corporate network, when the very boundary that makes the enclave worth having is the boundary guaranteeing it will not. The trade itself is sound. What is missing is candour: naming it before the business case is signed, not after the enclave disappoints the people using it.

So the causal end point is this. The higher the classification, the more the AI is starved, the smaller and staler the model, and the higher the cost per unit of capability. The high side gets worse AI precisely because it is the high side, a shape of the constraint rather than a criticism of anyone's engineering.

The starvation chain. Each link forces the next.

Creation Versus Control

This is where the sovereign AI conversation splits, and where I think we lose the plot.

There are two very different ambitions hiding under one word. The first is AI creation, building and training frontier-scale models ourselves. The second is AI control, being able to run, govern, secure, and assure models onshore, whoever built them.

Creation is largely a fantasy for a nation our size, and we should be honest about why. Frontier training demands compute at a scale that a handful of hyperscalers and states can muster, and for now the gap is widening. Announcing a sovereign model is easy. Standing up the compute, data, talent, and ongoing training to keep it competitive is a different order of problem, and the numbers do not favour us. Programs like REDSPICE meaningfully lift our sovereign capability (Australian Signals Directorate, 2022), but capability to run and defend is not the same as capacity to create at the frontier.

Control, on the other hand, is achievable and is the thing that actually matters for national security. Can we host a capable model inside a boundary we own, assure it, evaluate it, log it, and keep foreign legal reach away from it? That is a solvable engineering and policy problem, and it is where the money should go.

This distinction is not academic. When a foreign-hosted model is involved, data residency in an Australian region does not give you sovereignty, because the provider can still sit under extraterritorial legal reach through instruments such as the United States CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018). Residency is about geography. Control is about jurisdiction. Confusing the two is how you buy a sovereign badge and inherit a foreign subpoena.

Only Variety Can Absorb Variety

There is a law from cybernetics that explains why even control has a ceiling, and it is worth sitting with. In 1956 W. Ross Ashby stated the Law of Requisite Variety: to regulate a system, a controller needs at least as much variety, as many distinct possible responses, as the system it is trying to control (Ashby, 1956). Put plainly, only variety can absorb variety. A thermostat can control a room because a room's behaviour is simple. Nothing that simple can control a frontier model, because a frontier model's range of possible behaviours is astronomically larger than any oversight mechanism, a review board, a test suite, or a single human in the loop, can bring to bear.

This is the honest limit on the word control. You can host a model onshore, log it, evaluate it, and keep foreign legal reach away from it, and you should. But you cannot out-vary it. Complete behavioural control of a frontier model is not a backlog item, it is a structural impossibility, because the controller will always hold less variety than the thing it controls.

So the move is not to match the model's variety. It is to shrink the variety you have to control in the first place. Narrow the task. Bound the operating envelope. Wrap the probabilistic core in deterministic guardrails. Keep a human on the consequential calls, where their judgement, not their raw variety, is what counts. This is why creation is the wrong race, it is a variety contest a mid-sized nation cannot win, and why control is achievable only when you design the system to need less of it. Sovereignty as control is not the power to match a frontier model. It is the discipline to give it less room.

As capability rises, the model's variety soars while your oversight crawls. Bound the gap you cannot cover.

The So What?

So if the high side is starved by design, and creation is a fantasy, what does an architect actually do? A few things, and none involve pretending the enclave gets the same assistant as the corporate network.

  • Bring the model to the data, not the data to the model. On the high side the data will not come to you. Design for local inference against local corpora, and accept the capability trade.

  • Treat cross-domain solutions as first-class architecture. The controlled movement of data between classifications determines whether your model is fed or starved. It deserves the same design attention, and scrutiny, as the model itself.

  • Budget for the sovereign penalty upfront. On-premises inference on your own hardware costs more than metered cloud inference. If your business case assumes frontier-API economics on an air-gapped network, it is wrong before it starts.

  • Stay model-agnostic. Do not back a single horse. The frontier moves and geopolitical trust shifts. A thin model layer that lets you swap models without rewriting applications is the architectural expression of sovereignty as control. It is also where you shrink the variety you have to govern: one governed seam with its own logging, provenance, and guardrails, instead of a different captive model in every tool.

Now, I will give this more than a passing nod, because it is the strongest threat to the whole argument, not a footnote. Synthetic data generation, retrieval tricks, and distillation from frontier models are genuinely narrowing the gap between what you can host locally and what the frontier can do, and that gap-closing work is where the funding should go if you take this article's argument seriously. Put a number on how far it has got, though, and the picture is less comforting than the enthusiasm suggests. On the Epoch Capabilities Index, open-weight models have trailed the frontier closed models by an average of four months since January 2026, an eight-point gap, which is slightly wider than the three-month average that held from January 2023 to October 2025 (Epoch AI, 2026). The techniques are real and the lag is not closing. Even so, distillation and synthetic generation shrink the size of the penalty; they do not remove the classification boundary that still decides what data any of those techniques get to train on inside the enclave. That is a separate and worthwhile conversation for my architecture friends, and it changes the size of the constraint, not its direction.

Interactive: the thin model layer across enclaves, one governed seam for logging, evaluation and model swaps.

Conclusion

We are at risk of selling the national security community a fantasy, that sovereign AI on the high side will feel like the tools they use at home. It will not, and the sooner we are honest about that, the better the architecture we will build.

What gets us out of this is honest design rather than louder promises: treat the starvation chain as a fixed constraint, spend the effort on control rather than the vanity of creation, and tell the customer the truth about what a sealed enclave can and cannot do.

So here is the question I would leave every leader with. Are you buying sovereign AI because you have understood the trade, or because the word sounds like safety? Because those are very different purchases, and only one survives contact with the network.

Thanks for reading.

The views expressed in this article are my own and do not represent those of my employer, or any of my clients.

See related articles: Beyond the Hype: Unveiling the Multi-Cloud Mirage in Public Sector Cloud Strategy.


References

17 min read2 likes

The Undeclared Dependency: Every Technical Supply Chain Has a Strait of Hormuz

AI cannot secure a supply chain that has never been written down: detection coverage has a ceiling set by what you have actually declared, and no model can flag an edge it was never shown. Australia's fuel stocks, your cloud builds, and the defence industrial base are all exposed through the same weakness, dependencies nobody wrote down, and the unglamorous act of declaring the graph and then verifying it continuously is the actual security control. The clever model you point at the problem comes a distant second.

Critical InfrastructureSupply ChainAINational SecurityArchitecture
11 min read1 like

Exempt by Design: The AI Governance Gap in the National Intelligence Community

It is fair to assume the agencies wielding AI on the most consequential decisions carry the tightest rules governing it; in Australia, for the national intelligence community, that assumption is exactly backwards. The mandatory framework for government AI, the Digital Transformation Agency's policy now at v2.0 with a mandatory use-case register, exempts the Defence portfolio and the national intelligence community (Digital Transformation Agency, 2025). The National AI Plan shelved the proposed mandatory high-risk guardrails and stood up an AI Safety Institute instead (Department of Industry, Science and Resources, 2025). What is left for the community is point-in-time authorisation under the Protective Security Policy Framework and an oversight office that has appointed a single Chief AI Officer (Inspector-General of Intelligence and Security, 2025).

AIGovernanceNational SecuritySovereign AIOversight
22 min read

Obsolete the Day You Sign It: Australia Needs a Continuous ATO, and It Already Has the Missing Piece

Australia has already written down continued authorisation. The Protective Security Policy Framework carries a section headed "Continued Authorisation" which states that authorisation to operate "is generally ongoing once the system is operational", with the system owner monitoring so that the risks of operating the system stay inside the entity's tolerances (Department of Home Affairs, 2026, s 13.3.1.1). The familiar complaint, that we still run annual certificates while the Americans moved on, does not survive the text.

AIContinuous AuthorisationSecurityGovernanceSovereign AI