press release
Published: 27 August 2026

Frontier AI access is a growing national security question for the UK, but analysis shows sovereign control of AI is a complex problem

Two recent events should dramatically alter the thinking and decision-making about the use of overseas AI models in the UK’s critical national infrastructure, argues a new white paper from the University of Surrey. First, the US Government has now demonstrated that its powerful AI models can be withdrawn from service by Government dictate.

Second, frontier AI is becoming increasingly important to attackers and defenders of digital networks. Together, these changes represent a threat to the UK's ability to protect its networks, and to its critical national infrastructure in particular. 

The white paper argues that a tipping point is being reached and that governments around the world need to consider sovereign control of increasingly powerful AI systems. Competing head-to-head with the US and China is all but impossible because of these countries’ investment of capital, infrastructure and talent. This paper suggests more realistic ways to retain the freedom of action necessary to protect the UK’s interests. 

Five key recommendations are set out by Professor Alan Woodward from the Surrey Centre for Cyber Security and Dr Andrew Rogoyski of the Surrey Institute for People-Centred AI. All five recommendations in their paper are: 

  • Focus on deploying frontier AI locally to protect against the “foreign kill switch” – instead of attempting the impossible task of “made in the UK” frontier AI. 
  • Record the risk of losing access to frontier AI on national risk registers and in procurement terms, thereby inviting action. 
  • Negotiate access guarantees between governments rather than through commercial contracts. 
  • Maintain a realistic approach to investing in the AI capability a mid-sized country can afford, especially the talent pipeline. 
  • Keep spending on security basics, which still have a huge role in preventing cyber-attacks, even in the age of frontier AI. 

The paper responds to the unprecedented events of June 2026, when the United States Department of Commerce required licences before Anthropic could release its two most advanced models to any foreign person anywhere in the world. Unable to separate foreign from domestic users at short notice, the company disabled them for everyone, and users in allied countries lost access without warning until the controls were lifted on 1 July. Legal commentators noted that this was the first time export controls had restricted a live AI service, where previously such controls had applied to more tangible products like high-end computer processors. 

The paper also notes that withdrawal of access to frontier AI can happen for reasons other than government intervention and draws attention to the fragility of some frontier AI labs’ business models, which have been dependent on huge levels of investment. 

Rogoyski and Woodward argue that running alternatives to frontier AIs, using open-weight AI models, only gets you so far. The United States has reportedly considered restricting its own nation's access to Chinese open models in an effort to ensure only US systems are used by its enterprises and government departments. If allies were asked to follow suit, a country's main supply and its fallback would end up under the control of the same government. 

The paper also examines how these systems are contained once running, after models belonging to a United States developer, with misconfigured safety measures inside a test environment, reached another company's live systems and were widely described as having “gone rogue”. 

Offensive capability is meanwhile rising quickly from a low base. The National Cyber Security Centre reported in March 2026 that, over eighteen months, the best public models went from making almost no progress on a simulated attack against a company network to completing more than half of the necessary steps to hacking success, at a cost of only around £65 per attempt. 

The authors also note that the campaigns documented so far exploited unpatched systems, default credentials and services left exposed to the internet. AI increases the speed and volume at which existing weaknesses are found and used, but it does not yet find new ways to breach a network where the security basics have been done properly. For a country with limited resources, they argue, a pound spent raising the security baseline of critical infrastructure buys more protection today than a pound spent on training an advanced AI model. 

The paper spotlights the UK, which has deep AI research strength and long-established cybersecurity institutions but little in the way of native frontier development, despite being the birthplace of Google DeepMind. 

Their warning to the dominant AI producer states is drawn from satellite navigation, where the possibility that the United States might deny the GPS signal was enough to prompt Europe to fund Galileo, Russia to revive GLONASS and China to build BeiDou. Unexplained restriction invites the same costly duplication, including from allies. 

[ENDS] 

Notes to editors 

  • The paper, Sovereign by necessity? Frontier AI export controls, cyber security, and the limits of national AI capability, is available here. It is a preprint and has not undergone peer review. The authors state that they chose immediate publication because the subject is moving quickly, and they invite comment. 
  • Professor Alan Woodward and Dr Andrew Rogoyski are available for interview. Please contact mediarelations@surrey.ac.uk to arrange. 

Media Contacts


External Communications and PR team
Phone: +44 (0)1483 684380 / 688914 / 684378
Email: mediarelations@surrey.ac.uk
Out of hours: +44 (0)7773 479911