The AI Race Is Becoming a Race to Turn Capability Into Power

T

tt

Guest

GOAI Weekly Sensemaking — Week Ending 25 September 2026​

Executive Takeaways​

  • The dominant strategic signal this week is that the AI race is becoming a governance-and-conversion race. Frontier capability continues to improve and become cheaper to deploy, but strategic advantage increasingly depends on whether states can govern, industrialise, secure, and operationalise that capability faster than risks and dependencies accumulate.



  • AI formally entered the UN Security Council's international-security agenda. On 23 September, OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, Hugging Face CEO Clément Delangue, and Yoshua Bengio briefed the Council on AI and international security. The significance is institutional: frontier AI is no longer discussed only as technology policy or economic competition, but as a potential problem of international peace and security.



  • Frontier labs are themselves asking for international rules. OpenAI has called for U.S.-led global standards on capability measurement, risk management, preservation of human control, and conditions under which development should slow. Anthropic, meanwhile, released Claude Opus 5.5 with stronger safeguards while maintaining frontier-level performance at materially lower cost. Capability diffusion and governance pressure are advancing together.



  • Europe's conversion problem became unusually visible. ASML, Europe's most strategically important semiconductor firm, said it is currently selling no chipmaking systems in Europe because new fabs are not being built. The episode exposes the difference between possessing a world-class corporate chokepoint and converting it into a broader regional industrial capability.



  • Cybersecurity supplied the week's clearest evidence of operational conversion risk. Microsoft documented Storm-3168 activity using compromised Azure service principals to perform rapid resource discovery, credential collection, and destructive cloud operations. The attack illustrates how AI-era operational power can concentrate in workload identities, cloud permissions, and automation rather than in model weights themselves.



  • Agentic security is becoming a governance category of its own. Microsoft's September security updates focus on discovering local agents, extending Zero Trust to agent traffic, and governing what agents can reach. The relevant strategic shift is from securing users and applications to securing semi-autonomous machine actors operating across cloud and developer environments.



  • The core GOAI lesson is that capacity without conversion remains strategically incomplete. The United States and frontier firms are pushing toward global governance because capability is accelerating; Europe is discovering that strategic assets without domestic industrial demand do not automatically become regional power; and cyber defenders are learning that operational capability fails when identities, recovery systems, and control planes remain exposed.

Week-in-One-Paragraph​


The week ending 25 September 2026 showed that the next phase of AI competition will be determined less by possession of isolated technological assets than by the ability to govern and convert them into reliable strategic capability. At the United Nations Security Council, the heads of OpenAI and Anthropic urged governments to cooperate on frontier-AI safeguards, elevating AI from industrial and technology policy into the institutional machinery of international security. At the same time, Anthropic's Claude Opus 5.5 demonstrated that high-end capability is becoming cheaper and therefore easier to diffuse into organisations and markets. Europe produced the week's clearest negative case: ASML remains an extraordinary European chokepoint in the global semiconductor system, yet its executive said the company is selling no chipmaking equipment in Europe because the region is not building fabs at sufficient scale. Cyber developments completed the picture. Microsoft's reporting on Storm-3168 showed how compromised workload identities and automated cloud actions can turn access into destructive effect within minutes, while new security controls are explicitly being designed for autonomous agents. Taken together, these developments point to a common strategic problem: the gap between technological capacity and the institutional, industrial, security, and operational mechanisms needed to make that capacity usable without losing control of it.

Dominant Strategic Signal​


The AI race is becoming a governance-and-conversion race.

For several years, AI geopolitics was often narrated through possession: who had the best frontier models, the most advanced GPUs, the deepest semiconductor supply chain, the largest data centres, or the most abundant capital. Those variables still matter. But this week's developments reinforce a harder proposition: possession is strategically meaningful only when resources can be converted into reliable action under conditions of competition, risk, and dependence.



The UN Security Council meeting is important because it institutionalises this shift at the highest level of international security governance. AI firms did not merely ask governments to subsidise innovation or avoid regulation. They explicitly argued that increasingly autonomous systems require international coordination, capability measurement, shared standards, and mechanisms for preserving human control. This is a recognition that frontier capability has moved far enough downstream toward operational use that governance can no longer be treated as an external constraint applied after innovation. It is becoming part of the conversion architecture itself.



Anthropic's Opus 5.5 sharpens the same point from the technology side. The model is presented as delivering performance comparable with the company's top tier at substantially lower operating cost, while incorporating stronger safeguards and external pre-release evaluation. Lower cost expands the number of organisations able to use frontier-level capability. That improves diffusion and economic value, but it also expands the number of environments in which model behaviour, access, identity, data governance, and cyber controls must work reliably. Cheaper intelligence increases the conversion opportunity and the governance burden simultaneously.



Europe's ASML problem is the inverse. Europe possesses one of the most strategically important corporate assets in the entire semiconductor value chain. Yet the company says its current European system sales are effectively zero because the region is not building enough advanced semiconductor manufacturing capacity. The implication is not that ASML lacks strategic value. It is that the presence of a national or regional champion cannot substitute for the surrounding ecosystem required to convert a chokepoint into broader capability: fabs, customers, capital expenditure, energy, skilled labour, demand, supply-chain coordination, and sustained industrial policy.



Cybersecurity reveals where failed conversion can become immediate strategic loss. Microsoft's Storm-3168 investigation documented compromised Azure service principals conducting reconnaissance, bulk destructive actions, key retrieval, and attacks on recovery mechanisms. The attacker did not need to seize a frontier model. It targeted the privileged interfaces through which organisations already automate cloud capability. This is a reminder that operational power resides in identities, permissions, control planes, and recovery architecture as much as in algorithms.



The common denominator is therefore conversion governance. States and organisations must govern who can access advanced capability, how it is integrated into infrastructure, how dependencies are managed, how failures are contained, and whether alternatives exist when critical suppliers or systems become unavailable. The strategic unit is no longer the model, the chip, or the firm in isolation. It is the conversion system connecting them.



In GOAI terms, the centre of gravity this week sits across all three layers. Invention continues to advance and diffuse. Industrialisation determines whether capability can be produced and scaled domestically. Operationalisation determines whether it becomes usable in institutions and critical systems. Governance operates across all three, shaping access, coordination, security, legitimacy, substitution, and control.

Layer Map​

Layer I — Invention​


The invention layer was visible in the release of Claude Opus 5.5 and in the broader frontier-lab discussion about increasingly autonomous and self-improving systems. Anthropic says Opus 5.5 performs at the level of its higher-end Fable 5.1 on most work while operating at lower cost, and that it underwent external evaluation by Frontier Design and METR before release.



The strategic implication is not simply another benchmark improvement. When frontier-level performance becomes cheaper, the effective supply of advanced intelligence expands. That can accelerate scientific work, software development, cyber defence, and organisational adoption. It can also compress the time between invention and operational diffusion, leaving less room for institutions to adapt.

Layer II — Industrialisation​


Industrialisation produced the week's most revealing geopolitical contrast. ASML remains Europe's premier semiconductor chokepoint, but a senior executive said the company is currently selling no chipmaking machines in Europe because the region is not building new fabs at sufficient scale. Reports coincided with renewed debate over a Chips Act 2.0.



This is a textbook capability-conversion problem. Europe possesses a globally indispensable firm, advanced research institutions, regulatory power, and significant public funding. Yet those assets do not automatically create domestic leading-edge semiconductor production. Industrial capability requires complementary investment, production sites, demand, customers, energy, skills, permitting, and a credible long-term market.

Layer III — Operationalisation​


Operationalisation was visible both at the international level and inside digital infrastructure. The UN Security Council's decision to hold a high-level meeting on AI and international security shows that AI systems are increasingly viewed through their potential effects on security, military affairs, cyber operations, state power, and systemic risk.



At the organisational level, Microsoft's Storm-3168 findings demonstrate how quickly access can become effect. A compromised service principal moved from reconnaissance to a seven-minute destructive sequence against Azure resources, followed by credential collection. That is operationalisation in adversarial form: machine-speed use of permissions and cloud control planes to convert access into disruption.

Governance across the layers​


Governance was the strongest cross-layer mechanism this week. It appeared in calls for international capability standards, model safeguards and external evaluation, proposed limits on dangerous uses, debates over European industrial policy, cloud identity controls, recovery protection, and Zero Trust architectures for AI agents.



The point is not that governance is replacing competition. Governance is becoming one of the arenas through which competition is conducted. Standards can shape market access; safety requirements can affect release timing and cost; cloud identity controls determine resilience; and industrial rules influence where production capacity accumulates. Governance therefore affects the efficiency with which technological resources become strategic capability.

Ranked Developments​

1. AI enters the UN Security Council as an international-security issue​


What happened: On 23 September, the UN Security Council held a high-level briefing on artificial intelligence and international security. Briefers included OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, Hugging Face CEO Clément Delangue, and Yoshua Bengio. The meeting was convened by France under the Council's maintenance-of-international-peace-and-security agenda.



Why it matters: This is an institutional threshold. AI has been discussed for years in economic, ethical, regulatory, and arms-control contexts, but a dedicated Security Council session embeds frontier AI directly in the vocabulary of international peace and security. That increases the likelihood that future debates will involve strategic stability, cyber operations, autonomous systems, proliferation, capability monitoring, and crisis-management mechanisms.



  • GOAI mapping: Governance across Invention and Operationalisation.
  • Assessment: The important change is not that the UN suddenly controls frontier AI. It does not. The change is that frontier capability is now sufficiently consequential for the world's central security institution to treat it as a collective-action problem. That creates a new arena in which states and firms will compete to define standards, thresholds, and legitimate uses.

2. Frontier firms move from resisting regulation to proposing international control architecture​


What happened: OpenAI called for the United States to lead international efforts around shared AI standards, including capability measurement, risk management, preservation of human control, and conditions under which development may need to slow. At the Security Council, OpenAI and Anthropic leaders both argued for international cooperation on frontier risks.



Why it matters: The firms producing frontier systems are acknowledging that unilateral corporate safeguards are insufficient for capabilities with cross-border effects. This does not remove their commercial interests or resolve disagreements over regulatory design. It does, however, change the strategic relationship between firms and states: frontier labs are increasingly attempting to co-design the institutions that will govern the systems they build.



  • GOAI mapping: Governance across all three layers.
  • Assessment: The central question is who sets the standards. A U.S.-led framework could become a vehicle for alliance coordination and market-setting, but rivals may interpret it as institutionalisation of U.S. technological advantage. Global AI governance is therefore likely to combine genuine common-risk management with strategic competition over rule-making authority.

3. ASML exposes Europe's industrial conversion gap​


What happened: ASML Executive Vice President Frank Heemskerk said the company is currently selling no chipmaking systems in Europe, attributing the situation to weak investment and the absence of significant new semiconductor-fab construction. The comments came as Europe continued debating a second-generation Chips Act.



Why it matters: ASML is arguably Europe's strongest single asset in the global semiconductor system, yet its presence has not generated a self-sustaining European advanced-manufacturing ecosystem. This demonstrates the difference between possessing a chokepoint firm and converting that firm into broad regional capability.



  • GOAI mapping: Industrialisation and governance.
  • Assessment: The policy lesson is not simply to subsidise more fabs. Europe needs a conversion architecture connecting strategic technology, viable customers, industrial demand, energy, capital, permitting, workforce, and long-term purchasing commitments. Without that ecosystem, strategic autonomy remains asset-rich but operationally thin.

4. Anthropic's Opus 5.5 makes frontier-level capability cheaper while tightening safeguards​


What happened: Anthropic released Claude Opus 5.5 on 22 September. The company says the model performs at the level of Claude Fable 5.1 on most work while costing around 40 percent less than Opus 5 on typical token-billed workloads. Anthropic also emphasised stronger behavioural safeguards and external pre-release evaluation.



Why it matters: Falling cost changes geopolitics because frontier capability becomes easier to diffuse across enterprises, governments, startups, and smaller states. The relevant variable is not only who invents the model but who can afford to operationalise it at scale.



  • GOAI mapping: Invention -> Operationalisation, with governance across both.
  • Assessment: Capability diffusion is likely to outpace institutional adaptation. As models become simultaneously more capable and cheaper, organisations face pressure to adopt before governance, cyber controls, process redesign, and accountability mechanisms are fully mature. Cost reduction can therefore accelerate both capability conversion and conversion risk.

5. Storm-3168 demonstrates agentic and automated cloud destruction through compromised workload identities​


What happened: Microsoft Security Research documented Azure-focused malicious activity associated with Storm-3168, which Microsoft links to JADEPUFFER. Two compromised service principals were used for reconnaissance, destructive operations, and credential collection. Microsoft observed a seven-minute destructive sequence involving more than 100 storage-account deletion attempts and additional attacks on databases, recovery protections, and keys.



Why it matters: Workload identities are becoming high-value strategic control points. Modern cloud environments depend on service principals, API permissions, automation, and non-human identities. When those identities are compromised, attackers can operate at machine speed across infrastructure.



  • GOAI mapping: Operationalisation and governance.
  • Assessment: The incident supports a broader GOAI proposition: cybersecurity is a capability-conversion constraint. An organisation can possess advanced AI and cloud resources while remaining strategically fragile if the identity and permission architecture connecting them is weak.

6. Agent security becomes an explicit Zero Trust problem​


What happened: Microsoft's September security updates focus on discovering and governing local AI agents, extending Zero Trust to agent traffic, and controlling the resources agents can access. The company is treating agents as entities that require visibility, identity, access policy, and containment.



Why it matters: Traditional security architecture assumed human users, services, and applications. Agentic AI introduces semi-autonomous actors that can initiate actions across software environments and interact with other agents and tools. That expands the set of identities and control relationships organisations must govern.



  • GOAI mapping: Operationalisation; governance across deployment environments.
  • Assessment: Agent governance will become a strategic infrastructure issue. Organisations that cannot attribute actions, restrict agent privileges, revoke access, or observe machine-to-machine traffic will struggle to convert agentic capability safely into operational advantage.

7. Device-code phishing shows that identity remains the practical bridge into high-value cloud systems​


What happened: Microsoft described EvilTokens as a fast-growing phishing-as-a-service platform that abuses legitimate OAuth device-code flows. Attackers can trick users into authorising sessions without directly stealing passwords, bypassing some traditional MFA expectations. Microsoft also observed automation supporting the phishing infrastructure.



Why it matters: AI-era systems still depend on conventional identity infrastructure. Advanced models and agents do not eliminate older attack paths; they can increase the value of successfully compromising them because a stolen identity may expose cloud data, SaaS platforms, developer tools, and AI services simultaneously.



  • GOAI mapping: Operationalisation and governance.
  • Assessment: Identity is becoming the common control plane across human users, cloud workloads, SaaS applications, and agents. Strategic resilience therefore depends less on adding isolated AI-security products than on designing a coherent identity architecture across all actors.

8. Ransomware remains relevant, but behaviour matters more than payload branding​


What happened: Microsoft published new tracking of Storm-2570, a ransomware affiliate observed across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Microsoft argues that focusing only on the final payload obscures recurring post-compromise tradecraft that defenders can detect earlier.



Why it matters: This matters for AI geopolitics because automation and AI assistance increasingly operate inside longer attack chains. Strategic defence depends on identifying recurring behaviours, privileged access, persistence, and lateral movement before attackers reach the final destructive or extortion phase.



  • GOAI mapping: Operationalisation and governance.
  • Assessment: The broader lesson is methodological: defenders need to govern the process through which attackers convert access into impact, not merely the final malware artefact. That mirrors the GOAI distinction between resources and capability conversion.

Cyber-AI Strategic Risk Pattern of the Week​


Pattern: AI-era cyber power is concentrating in identities, automation, and cloud control planes.

Cybersecurity was not the dominant strategic signal of the week, but it supplied the clearest operational evidence for the wider governance-and-conversion argument. Three developments matter together: Microsoft documented automated destructive cloud activity through compromised service principals; its September security architecture explicitly extends Zero Trust to AI agents; and its EvilTokens research showed how legitimate authentication mechanisms can be turned into scalable access infrastructure.



  1. Non-human identities are becoming strategic assets and liabilities. Storm-3168 used compromised service principals rather than an interactive human account to perform reconnaissance, destructive actions, and credential collection. As organisations deploy more automation and agents, the number of privileged machine identities will continue to expand.
  2. Automation compresses the access-to-impact timeline. Microsoft observed a destructive sequence lasting roughly seven minutes. The strategic concern is not only AI-generated malware; it is the ability to coordinate large numbers of valid cloud operations at machine speed once sufficient privilege has been obtained.
  3. Agent governance is moving into mainstream security architecture. Microsoft now explicitly frames agent discovery, access governance, traffic inspection, and containment as Zero Trust requirements. This indicates that agentic AI is becoming an operational security category rather than an experimental edge case.
  4. Identity attacks remain highly reusable across the AI stack. EvilTokens exploits OAuth device-code flows to obtain authorised sessions without conventional credential theft. A compromised identity can provide access not only to email or files but to cloud consoles, developer systems, model APIs, and enterprise AI services.
  5. Ransomware and extortion remain downstream outcomes, not the whole strategic problem. Storm-2570 illustrates the value of tracking recurring intrusion behaviour before payload deployment. Storm-3168 showed activity consistent with ransomware-aligned objectives, including attempts to impair recovery, but Microsoft did not observe a ransom note or confirm successful exfiltration in the investigated incident.

Most strategically important exploited vulnerability/attack vector​


The week's most strategically important vector was compromised cloud workload identity, specifically service-principal credentials with excessive or consequential permissions.



Microsoft found that credentials associated with one affected service principal had previously appeared in plaintext in a public GitHub issue. The company could not confirm that this exposure was the route used by Storm-3168, so it should not be presented as confirmed initial access. What is confirmed is that compromised service principals were subsequently used for destructive and credential-collection operations across Azure resources.



The strategic significance lies in the position of the identity. A service principal is designed to let software act without a human repeatedly authenticating. That makes it a conversion mechanism for legitimate automation—and, once compromised, for adversarial automation as well.

Critical infrastructure exposure​


The week's strongest confirmed incidents centred on cloud environments rather than newly disclosed attacks against physical critical infrastructure. The relevance to critical infrastructure is nevertheless direct. Electricity, water, transport, healthcare, government, and defence organisations increasingly depend on the same cloud identities, SaaS platforms, developer pipelines, and agentic systems documented in this week's research.



The analytical inference is therefore that critical-infrastructure exposure is migrating upward into digital control planes. Physical resilience will increasingly depend on whether cloud identity, recovery systems, remote management, and AI-enabled operational tools remain available under attack.

Ransomware, extortion, and supply-chain pressure​


Ransomware remained active through Storm-2570 and through the ransomware-aligned behaviour associated with Storm-3168. However, the strategically important point is that attackers are targeting the recovery and control architecture before the extortion stage. Storm-3168 attempted to delete storage, databases, and recovery-related protections while collecting keys that could provide access to data.

This creates pressure on organisations to separate recovery authority from production authority. If the same compromised machine identity can alter production resources and disable recovery, resilience exists administratively but not operationally.

State-linked and geopolitically meaningful cyber activity​


Microsoft's Storm-3168 reporting associates the activity with JADEPUFFER, a threat actor previously documented in agentic ransomware research. The material used for this Weekly does not establish a state sponsor. The correct classification is therefore financially or operationally malicious activity with geopolitical relevance because it demonstrates a transferable model for AI-orchestrated cloud attacks, not a confirmed state operation.



This distinction matters. Strategic significance does not require state attribution. Techniques that compress cloud reconnaissance, credential collection, destruction, and recovery impairment can diffuse between criminal and state-linked ecosystems, increasing the defensive burden on both governments and private operators.

Practical strategic lesson for organisations​


Treat machine identities as first-class strategic infrastructure. Inventory service principals, workload identities, API keys, agent identities, and automation accounts; eliminate long-lived public secrets; rotate exposed credentials immediately; enforce least privilege; isolate recovery authority; monitor machine-speed bursts of administrative activity; and require explicit policy for what AI agents can reach.

The governing principle is simple: every identity that can convert software instructions into infrastructure action should be treated as a privileged control surface.

Strategic Exposure Matrix​

Control surfaceDirection this weekStrategic significanceGOAI interpretation
International frontier-AI governanceRising sharplyVery highAI becomes an explicit international-security coordination problem
European semiconductor industrial depthWeak / exposedVery highStrategic firms do not automatically create regional capability
Frontier-model cost and diffusionFalling cost / widening accessVery highCheaper capability accelerates both operationalisation and governance burden
Cloud workload identitiesRising sharplyVery highMachine identities become high-value conversion and attack surfaces
AI-agent identity and trafficEmerging rapidlyHighZero Trust must expand from human users to autonomous actors
Recovery infrastructureUnder pressureHighResilience fails if production compromise can disable recovery
OAuth / SaaS identityPersistently exposedHighConventional identity remains the bridge into AI-enabled enterprises
International standards leadershipContestedHighRule-setting becomes a source of strategic influence

What to watch next week​

  • Whether the UN Security Council briefing produces a follow-on process, formal reporting mechanism, expert group, or state-backed proposal on frontier-model monitoring and international AI security.
  • Whether the United States translates OpenAI's call for U.S.-led global AI standards into an allied initiative, standards coalition, bilateral U.S.-China channel, or domestic regulatory framework.
  • Whether China, the EU, or other major actors respond to the frontier labs' governance proposals with competing standards, objections to U.S.-led rule-setting, or alternative multilateral arrangements.
  • Whether Anthropic's Opus 5.5 cost reductions trigger further price competition that materially lowers the threshold for enterprise and government adoption of frontier-level models.
  • Whether ASML's warning becomes a concrete input into Chips Act 2.0 through demand-side incentives, long-term purchasing commitments, fab financing, or measures designed to create European customers rather than only subsidise supply.
  • Whether additional cloud incidents confirm that compromised service principals and agentic automation are becoming a repeatable attack pattern rather than an isolated case.
  • Whether Microsoft, major cloud providers, or identity vendors introduce mandatory or default controls specifically for AI-agent identities and agent-to-agent traffic.
  • Whether ransomware groups adopt more agentic cloud-native tradecraft in which infrastructure destruction, credential harvesting, and recovery impairment are automated before conventional extortion begins.

Analytical framework​


The Weekly Sensemaking applies the Geopolitics of AI capability-conversion framework: Invention, Industrialisation, and Operationalisation, with governance operating across all three layers. The framework distinguishes possession of AI-related resources from the institutional, industrial, infrastructural, and operational processes required to convert those resources into usable strategic capability.

Sources​

  1. United Nations — “Artificial intelligence and international security — Security Council, 10228th meeting,” 23 September 2026.
  2. United Nations — “OpenAI and Anthropic brief Security Council amid ‘real and imminent’ threat posed by runaway AI,” 23 September 2026.
  3. UK Foreign, Commonwealth & Development Office — “Foreign Secretary Address to the UNSC on Artificial Intelligence,” 23 September 2026.
  4. Reuters — “AI leaders warn UN of security risks as systems grow more powerful,” 23 September 2026.
  5. Financial Times — “OpenAI joins call for US-led global AI standards,” September 2026.
  6. OpenAI — “The AI policy window is open. We need to act,” 9 September 2026.
  7. Anthropic — “Introducing Claude Opus 5.5,” 22 September 2026.
  8. Anthropic — “Model system cards — Claude Opus 5.5,” September 2026.
  9. Bloomberg — “ASML Executive Says Europe’s Biggest Firm Has No Sales in Europe,” 22 September 2026.
  10. NL Times — “ASML currently sells no chipmaking machines in Europe, executive says,” 22 September 2026.
  11. Microsoft Security Research — “Storm-3168: Agentic-driven cloud attacks using compromised service principals,” 25 September 2026.
  12. Microsoft Threat Intelligence — “Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments,” 24 September 2026.
  13. Microsoft — “What’s new in Microsoft Security: September 2026,” 24 September 2026.
  14. Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research — “Unmasking EvilTokens: Getting to the root of device code phishing,” 22 September 2026.
  15. OpenAI Forum — “Daybreak: Strengthening Cyber Resilience with AI,” 23 September 2026.
 

Thread statistics

Created
tt,
Replies
0
Views
2
Back
Top