Neither Open nor Free: Emerging Bifurcation of Global AI Access Infrastructure

Summary

Rapid shifts in mid-2026 have crystallised global AI governance around two competing access structures: the US-led Pax Silica, which gates frontier AI behind trusted supply chains free of Chinese influence, and China’s WAICO, which organises access around open-weight models for the Global South. The Mythos episode demonstrated that access within either structure is conditional and revocable, with frontier AI now firmly treated as a strategic asset. India, a Pax Silica member with limited indigenous capability, must move beyond access dependency towards building sovereign capability across the full AI stack.

Introduction

Global AI governance was more dynamic in summer 2026 than in several preceding years, with the US applying, suspending and conditionally restoring export controls on a deployed AI model within weeks, while moving towards a de facto licensing system. Simultaneously, China launched WAICO, a 30-member intergovernmental AI cooperation body promoting open-source innovation for the Global South. The two countries’ moves have assembled competing coalitions, enrolling most of the world.

These rapid developments have created a structure in which AI access is organised around specific, often opposing, models. At the same time, framing AI as a strategic asset rather than a commercial product has gained traction, making it a subject of supply control. For any state that depends on imported AI, access architecture is becoming a central concern, especially as its frameworks take on an increasingly bipolar configuration. The volatility of AI development and access, alongside increasingly consolidated governance frameworks, requires strategic attention.

The Swerving Road to Access

Beyond its technical capabilities, Mythos marked a major turning point in AI’s geopolitical and governance considerations. Mythos 5 was described as a general AI tool with cybersecurity capabilities that could detect vulnerabilities at a massive scale. Anthropic released Fable 5, a safeguarded public variant of Mythos, while restricting Mythos itself due to its dual-use potential.[1] The two models have shown unprecedented capabilities in controlled testing set-ups that were presumably comparable to human expertise. For instance, Claude’s Mythos Preview and Opus 4.8 models were used to create functional protein ‘mini-binders’ with significantly higher success rates than industry standards.[2]

In late July 2026, reports emerged that during certain ‘capture the flag’ exercises with instructions to find system vulnerabilities, the model was involved in breaking out of isolated sandboxes and gaining access to the internet. The model reportedly sent emails, posted sandbox-circumvention analyses online, and hacked three organisations by exploiting system misconfigurations. Anthropic’s pending IPO may have incentivised it to aggrandise these capabilities, and independent verification remains limited.[3] Nevertheless, Mythos has come to represent a significant leap in AI capabilities and, along with the dual-use implications, has led to the model becoming subject to national controls.

While Anthropic initially restricted Mythos to Project Glasswing and released Fable with stringent guardrails, the company disabled both globally on 12 June 2026. This followed a US Department of Commerce directive prohibiting access for all foreign nationals and requiring government licenses for foreign supply under threat of civil and criminal penalties.[4] Unable to verify user nationalities in real time, Anthropic turned off the model class entirely. Notably, this marked the first time US export controls were applied to a deployed AI model rather than the underlying semiconductors (as before).[5]

Although the official reasons behind the ban remain undisclosed, speculation has focused on possible causes. One possible trigger was Amazon CEO Andy Jassy reporting a possible bypass, or jailbreak, for Fable 5’s guardrails.[6] The exploit reportedly raised concerns about diverting military intelligence to countries like China and Russia. It should be noted, however, that Anthropic itself called the reported vulnerability to be ‘narrow’ in a way that other models could also develop similar exploits. The company argued that making Fable 5 completely invulnerable to jailbreaks was impossible, and that an industry-standard defence-in-depth strategy involves monitoring, detection and rapid damage control.

Thus, the argument that the potential vulnerability could be exploited for adversarial use of military intelligence may not fully hold up. Alternatively, clashes over Anthropic refusing the Trump Administration unfettered defence access may explain the restrictions; earlier, the Pentagon had labelled the company a ‘supply chain risk’ in retaliation as well.[7] The executive order on AI and Cybersecurity, signed on 2 June 2026, was reportedly also drawn over concerns about Anthropic’s AI models. Combined with the fact that the Department of Commerce orders against Mythos class models had no comparable hit, the move may have been selectively used against Anthropic.[8]

Another critical context is the breach of the AI model after its release. Beyond reports of possible Chinese access to Mythos, reports also suggested the US Administration and Anthropic clashed over Anthropic giving South Korean company SK Telecom access to the model.[9] The allegations were centred on SK Telecom’s links to China,[10] which the company has denied.[11] Thus, several indications suggest that the AI’s technical capability was, at the very least, not the only reason for the unilateral decision to cut access to Mythos; geopolitical and strategic considerations also played a role.

Nevertheless, the decision to restrict the model was reversed swiftly. By 26 June 2026, Mythos was restored to more than a hundred trusted US-based companies.[12] By 1 July 2026, access to Fable 5 was restored worldwide. Mythos 5, however, was slated for re-release to selected ‘trusted partners’; access was given to Project Glasswing members, gated by standards set by the US government.[13] This is highlighted by the fact that although the license requirement for supplying the models was withdrawn, the US government retained the right to re-impose it.

The suspension alarmed US allies, who had assumed guaranteed, uninterrupted access. For instance, during the G7 Summit, French President Emmanuel Macron warned the United States that US allies “will not buy any model made by [US AI] companies if from one day to the next you can just turn off the switch“.[14] Canadian Prime Minister Mark Carney called it a lesson to diversify, given the dangers of over-reliance.[15] In South Korea, meanwhile, this led to a call for AI sovereignty. US allies have also slowly been reducing their dependence on US-based companies for software, while migrating towards open source and/or sovereign-developed software ecosystems.[16] Nevertheless, given the AI stack’s transnational structure, full decoupling from US providers remains immediately impractical for most allies.

The Emerging Frameworks as Crossroads of Access: Pax Silica vs WAICO

The Mythos suspension was not a standalone event, but part of broader access structures already under construction. These access structures fall into two major governance systems, each representing opposed principles.

The US-led Pax Silica coalition, launched in December 2025, conditions supply to trusted partners to secure critical mineral, semiconductor and AI supply chains free from Chinese influence and adversarial access. The coalition, now 25 members strong, aims to advance ‘mutual prosperity, technological progress, and economic security’ through partnerships across the technology stack, reducing dependencies, countering unfair market practices, and enhancing national and investment security.[17]  India joined this coalition in February 2026, against the backdrop of the AI Impact Summit in New Delhi.

The second access regime in development is represented by the World Artificial Intelligence Cooperation Organization (WAICO). In principle, it is open to any sovereign state and does not require members to adhere to a particular government system or have specific political alignment. China first proposed WAICO at the 2025 World Artificial Intelligence Conference, but it initially failed to gain traction. However, the July 2026 iteration of the Conference saw 29 countries signing an agreement establishing WAICO, now with 37 signatories and one Observer nation.[18] Notably, the membership that encompasses countries predominantly from Africa, Latin America and Asia corresponds to China’s existing relationships in the Global South. Whether WAICO develops functional authority or remains a forum, however, remains unclear.[19]

What we do know is that WAICO’s proposals are grounded in open model weights, non-discrimination, five thousand training places for developing countries over five years, and a governance structure in which no single power controls the rules.[20] These proposals, while superficially sharing some common threads with Pax Silica (such as cooperation in AI development and sovereignty in AI), emanate from a fundamentally different approach from the US-based coalition. Where Pax Silica centres on trusted, secured supply chains, WAICO emphasises state sovereignty in AI and narrowing North–South capability gaps.

A third track, consisting of global governance institutions, does exist, but it is weaker on the access front. The UN’s first Global Dialogue on AI Governance (Geneva, July 2026) and the earlier AI Impact Summit (New Delhi) both flagged capability concentration as a central concern and called for inclusive AI.[21] As norm-setting bodies with no enforcement power, however, they do not control access. Therefore, the two power-led coalitions mentioned earlier set the terms for the supply of advanced AI and for instituting access to frontier capabilities, not the universal institutions.

Although no formal rule bars dual membership, the two coalitions are almost entirely non-overlapping.[22] Kazakhstan is the sole exception.[23] The split has drawn Cold War comparisons, though the divide follows technological rather than ideological lines: the tension between Pax Silica’s China-exclusion requirement and WAICO’s Beijing-anchored open access makes dual membership a near-impossible balancing act.[24] That said, the scope for a state to belong to both coalitions is limited, as it will be difficult for any country to meet Pax Silica’s requirement for China-free supply chains while leveraging open-access frameworks within Beijing-led WAICO.

Membership is defined not only by the geopolitics of technology, but by the nature of technology itself. While companies such as Google, Meta, NVIDIA and Microsoft promote and have deployed open-weight models, US models are largely proprietary and closed.[25] However, despite this open-model orientation, most of these companies keep their frontier models proprietary, not open. Chinese models, by contrast, are largely open-weight. In fact, during the suspension of Mythos, China had released a series of open-weight models such as Kimi K3, Minimax and Zhipu.[26]

Notably, US and Chinese models were comparable on certain metrics, even though the Chinese models were built and run with significantly lower investment and operating costs.[27] US government and academic assessments suggest the capability gap is months, not years, partly due to Chinese resource efficiency, and partly because open models grant access to a diverse global data ecosystem.[28] As of now, the two distribution frameworks are developing capabilities almost in parallel; within weeks of Mythos’s launch, China launched comparable models, and OpenAI has now launched GPT-6 Astra as a foothold in the agentic AI domain. The AI model is closed, and access is gated, which, like Mythos, is revocable. This creates an interesting juxtaposition with Chinese open models with near-frontier capabilities.

However, the ‘open model’ direction taken by WAICO as a whole, and China specifically, must be taken with a caveat. First, WAICO remains largely aspirational; as noted, details of what would enable its institutionalisation remain undisclosed and unestablished.[29] Open, free-to-download AI models are not value-neutral exports, and Chinese open models will likely have the country’s broader vision of digital governance centred on cyber sovereignty and state control of information embedded in them. For each download and use, they will diffuse Chinese technical standards, data ecosystems and governance preferences alongside the technology itself.[30]

Therefore, these open models export not just Chinese AI capabilities, but also indirectly, a particular understanding of how digital technologies should be governed. Additionally, China is gating access to its frontier models; China’s Ministry of Commerce recently opened consultations with the private sector on restricting overseas access to China’s most advanced models, advancing the logic of frontier AI as a strategic asset rather than a commercial product.[31] Thus, the architecture of open access that China, and WAICO by extension, perpetuates may also not be perpetual. Ultimately, both powers treat AI access as a strategic asset; the two coalitions represent competing methods of control, not a choice between control and openness.

The Choice before India

India occupies an unenviable position in this structure. It is a member of Pax Silica, which gives it access to technology but concentrates dependence on a government with a history of unilateral denial. More importantly, the Mythos episode, combined with the 2025 AI Diffusion norms, has reiterated that the vulnerability extends beyond models to advanced chips and computing infrastructure. It has exposed what can be seen as ‘toolbox fallacy’ logic that may be extant in the country, which treats access to an imported frontier model as a pre-condition for domestic development. On the other hand, India has not joined WAICO, the only BRICS country to do so, because the access it grants comes with caveats regarding Chinese standards, norms and data security.[32]

This complicates India’s aspiration to lead the Global South, undermined by membership in an exclusionary Western coalition and insufficient indigenous AI capability. China, meanwhile, through WAICO and more recently the BRICS 2026 summit, has not only advanced several AI models but has also been building an international ecosystem around them.[33] This suggests that China’s ambition extends beyond exporting models towards occupying parts of the supply side of Global South AI. While India has made significant global contributions in areas like Digital Public Infrastructure, AI leadership will require proactive, practical application exports that go beyond norm-setting. What India needs, therefore, is to distinguish between access to capability and development of capability.

India must therefore pursue development on parallel tracks. In the near term, India should seek frontier models only where no adequate substitute exists, with the understanding that access may be provisional. India must assess whether imported capabilities yield more long-term value than equivalent investment in domestic compute, models, datasets and research. Additionally, India should leverage open, self-hostable models for functions that do not require frontier systems, engineer and adapt them to Indian requirements, and reduce dependence on foreign providers as intermediaries for sensitive inference.

The medium-term track must focus on capability accumulation through an indigenous software envelope. This minimises the possibility of data harvesting by the supplier state from open models where the software may be deployed. It would also ease integration of indigenous models as they develop.[34] A software envelope, also known as a model wrapper or AI gateway, is a software layer built on a raw AI model that makes it usable for specific tasks. It interfaces between the AI model and the user.

For example, France uses open-weight and open-source models from companies like OpenAI, Mistral and DeepSeek through a software envelope called the Albert API. The API serves as a shared AI service run by the French government, helping public administrations use generative AI tools safely and easily. It gives ministries and public entities a unified, secure interface to use multiple AI models for specific tasks. This not only reduces redundancies and resource costs by avoiding the need to develop and deploy in-house AI models, but also accelerates adoption while keeping control and security at the centre.

Long-term, India must invest across the full AI stack to ensure disrupted nodes can be substituted domestically.[35] SarvamAI provides a good example: its 30B and 105B models were trained from scratch in India, demonstrating growing domestic capability in training and data curation, but on imported semiconductors sourced through the IndiaAI mission.[36] This shows why model sovereignty alone cannot secure the broader AI stack; if access to these semiconductors is curtailed, it affects future model development, and supply-chain diversification alone will not guarantee capability.

These tracks must converge around replaceability, built into new systems from the outset with interoperability across legacy and updated infrastructures. It is not realistic to assume all systems can be made 100 per cent indigenous across the AI stack. The aim is to ensure that dependencies do not become structural lock-in. Globally, the ongoing shift away from US-based companies shows that dependencies can be direct pain, and India’s own example of poor scaling in Linux-based MayaOS (against current Microsoft suites) shows the cost of lock-ins. Indigenisation remains slow and costly, but deferring it until near-term measures fail is a poor moment to confront dependency. Building full-stack capability that enables both replaceability and practical AI leadership must remain India’s central aspiration.

[1] Ashley Capoot, “Anthropic Releases Mythos-like AI Model to the Public Two Months After Private Rollout Rocked Wall Street”, CNBC, 9 June 2026.

[2] Aminu Abdullahi, “Anthropic Says Claude Designed Protein Binders Validated in Lab Tests”, eWeek, 20 August 2026. Binder proteins are specialised engineered or natural proteins that attach with high precision to specific target molecules like other proteins, DNA, or cell receptors. They have applications in medical domain such as targeted delivery of treatments, microscopic imaging of proteins, protein blockers for harmful compounds, or enable cells to destroy malignant protein compounds, showing an ‘overall hit rate ranging from 22.6 per cent to 35.1 per cent depending on the operational configuration (indicating a cumulative success rate of 26.8 per cent), well above the 10 per cent to 15 per cent success rate typical of standard industry campaigns’. Claude’s models developed 1,320 designs for 15 target proteins, 354 of which were applicable across 14 targets. In single targeting (specifically, Mythos Preview working on the protein RBX1), the overall hit rate was over 40 per cent.

[3] James Royal, “Anthropic IPO: Powerful New Claude Mythos Has Investors Clamoring for the Next Big Thing in AI”, MarketWise, 14 April 2026.

[4]  Kate Koren, Kevin Kurland and Aalok Mehta, “The Department of Commerce Restricted Access to Anthropic’s Latest Models. What Comes Next?”, CSIS, 16 June 2026.

[5] The specific regulation, Section 744.22 of the Export Administration Regulations (EAR) deals with military intelligence end uses and/or end users, and provisions for ‘deemed exports’ (wherein access to a controlled technology, when granted to a foreign resident inside the US, is considered to be exported to the resident’s home country itself).

[6] Julia Shapiro, “What to Know About the Anthropic Models Takedown”, The Hill, 16 June 2026.

[7] Isabella Wilkinson, “The US Government’s Latest U-turn on Anthropic’s Mythos Sends Mixed Signals on AI Governance”, Chatham House, 2 July 2026.

[8] Anselm Küsters, “US Access Ban on Anthropic’s Fable/Mythos 5: More of a Geopolitical Signal than a Necessary Security Measure”, Centres for European Policy Networks.

[9] Martin Holland, “Ban on Anthropic’s AI Models: China Allegedly Had Access to Mythos”, Heise Online, 15 June 2026.

[10] Louise Matsakis and Maxwell Zeff, “The Korean Telecom Giant at the Center of Anthropic’s Mythos Controversy”, The Wired, 17 June 2026.

[11] The allegations against SK Telecom (SKT) are less about the company by itself, given a minimal presence it holds in China; SKT has 1.9 million USD in revenue and seven staff in China. SKT did have ties to China Unicom through a joint venture, but the stakes it had in the Chinese company were sold by 2009. However, SKT’s parent conglomerate, the SK Group, has affiliates that hold significant stake within Chinese semiconductor and energy sector, which is why the Mythos scrutiny was tilted towards SKT. See Mitch Shin, “Anthropic’s Export Control Crackdown Leaves South Korea Caught in Washington’s AI Crossfire”, The Diplomat, 24 June 2026; Louise Matsakis and Maxwell Zeff, “The Korean Telecom Giant at the Center of Anthropic’s Mythos Controversy”, no. 10.

[12] Maxwell Zeff, “Trump Administration Allows Anthropic to Release Mythos to Select US Organizations”, Wired, 26 June 2026.

[13] Karishma Saurabh Kalita, “US Lifts Export Ban on Anthropic’s Most Powerful AI Models After Security Review”, India Today, 1 July 2026.

[14] Martin Chorzempa, “Fable of the Mythos Saga: Ad hoc US AI Model Controls Could Help China”, Peterson Institute for International Economics, 2 July 2026.

[15] Rob Gillies, “Canadian Prime Minister Mark Carney Says US AI Restrictions Underscore Risks of Dependence”, AP News, 14 June 2026.

[16] The US software exports operate in alignment with the US domestic laws. As such, US laws such as the CLOUD Act can be, and have been, used to gain access to private data generated within the importing country despite local data protection laws. This was exemplified by the reports of a recent data leak in Netherlands, wherein Microsoft leaked emails, minutes and invitations of the Dutch Civil Servants, without scrubbing their names of anonymising the data despite GDPR and Dutch Data Protection laws. See  Martyna Chmura, “European Tech Sovereignty and the Security Risks of Decoupling”, Bloomsbury Intelligence and Security Institute, 11 March 2026.

[17] The mandate spans across technological stack in global supply chain, supporting private industry, promoting shared and trusted ecosystem of AI developers and vendors to revitalise legacy industries while developing new markets, reducing excessive dependencies, protect against market overcapacity and unfair dumping practices, and to enhance overall national and investment security for partner nations. See Under Secretary for Economic Affairs, “Pax Silica”, U.S. Department of State.

[18] Gerald Mako, “China’s New AI Club: The World Artificial Intelligence Cooperation Organization”, The Diplomat, 21 July 2026.

[19] It is not yet clear whether WAICO will become a functioning institution with real authority, i.e., if it will have a defined budget, enforcement powers, etc., or it will continue as a multilateral forum, as much of the structures of WAICO as an organisation remains undisclosed to public.

[20] Kai-Shen Huang, “Open Models are Becoming a Tool of Chinese Statecraft”, Australian Strategic Policy Institute, 11 September 2026; “China’s Xi Jinping Launches New AI Alliance: What is it?”, Al Jazeera, 17 July 2026.

[21] The report specifically expresses concerns regarding AI capabilities (infrastructure, expertise, evaluations), risks it incurs and the wealth it creates, and their uneven distribution/concentration across private entities and states.  Notably, it cites that approximately 90 per cent of the total AI compute capability is concentrated in two countries: US (75 per cent) and China (15 per cent). See United Nations, “Preliminary Report of the Independent International Scientific Panel on AI” [Executive Summary], Independent International Scientific Panel on Artificial Intelligence, July 2026.

[22] Though reportedly US is planning to officially take stance that countries will need to choose between Pax Silica and WAICO. See Michael Martina, “US to Tell Partners They Must Pick Sides in AI Race with China”, Reuters, 15 August 2026. WAICO has a mix of democracies and authoritarian governments, while US has forwarded ‘trusted partners’ as the organising value system of Pax Silica, which is largely democratic by default, not by design.

[23] Kazakhstan is a member to both Pax Silica and WAICO. However, there are also instances of countries which are stakes in one, but may have been invited to other as well, such as Bangladesh (invited to Pax Silica, observer to WAICO) and Singapore (founding member of Pax Silica, invited to WAICO).

[24] Priya Raman, “The AI Cold War: Pax Silica vs WAICO, Explained”, Stanford Tech Review, 15 August 2026.

[25] Several AI companies, many of them coming from the US, had signed a letter called ‘Open Weights and American AI Leadership’, which was published in July 2026 by Nvidia CEO Jensen Huang. The letter has spurred creation of a coalition that backs Open weight models, which has ballooned from 25 initial members to over 270 entities globally. Notably, companies like Anthropic and xAI have not joined the coalition, and have driven the closed AI models debate.

[26] Tony Peng, “👐🏻As Anthropic Tightens Access, Chinese AI Labs Open Their Models”, Recode China AI, 15 June 2026.

[27] Nicholar Gordon, “China’s Moonshot, Z.AI, and DeepSeek are Callenging U.S. AI Labs—and Beating Them on Cost”, Fortune, 26 July 2026.

[28] Crucially, using large and diverse training data does not mean an AI continues collecting data from its users. Open-weight models can run entirely on an organisation’s own systems, keeping data local and under its control. Their capabilities come from data used during training, not from access to private operational data.

[29] Aspects such as a definite budget, membership criteria and enforcement capacity.

[30] There are documented instances of Chinese Digital Silk Road providing low-cost export of technologies that, while open access and low-cost, come with Chinese technical standards, as well as terms regarding data-sharing or surveillance. Zimbabwe’s National Facial Recognition & Biometric Database, build with Chinese company CloudWalk Technology, enables CloudWalk to retain access to data, which the company uses to refine facial recognition aspect of its AI models. See Ethan Thayer, “The Digital Scramble for Africa: Understanding Chinese Smart Cities in Africa”, Small Wars Journal, 10 July 2026.

[31] Fanny Potkin, “Beijing is Looking at Curbing Overseas Access to China’s Top AI Models, Sources Say”, Reuters, 7 July 2026.

[32] “India Seeks Assurance from US Against ‘Abrupt AI Technology Cutoffs’: MeitY Secretary S Krishnan”, ANI, 25 June 2026.

[33] Angela Barnes, “China’s Xi Jinping Proposes BRICS ‘Open-Source AI Zone”, Euronews, 14 September 2026.

[34] Paul F. Langer and Stefan Haag, “AI Sovereignty: Redundant Use of Large Language Models for Public Sector Resilience”, Public Organization Review, 2026.

[35] The paper introduces Governance-Aware Retriever Framework (GnARF), one of whose aspects is using customised PII Filtering layer (a component of software envelope). The paper indicates privacy by design and regulatory compliance to be major advantages of this approach, along with ensuring there is no AI model vendor ‘locking in’, i.e., AI models may be swapped without needing to modify whole ecosystem.

[36] Sanjana B, “Sarvam AI Unveils Indigenously-built 30B and 105B LLM Models”, Business Line, 18 February 2026.

Keywords : Artificial Intelligence