The AI Race May Be Measuring the Wrong Kind of Power

On 3 September, two announcements offered different views of AI power. OpenAI released GPT-6 Astra, and company president Greg Brockman closed the briefing by declaring, “Welcome to the AGI era.”

Why ecosystem diffusion may matter as much as frontier supremacy

On 3 September, two announcements offered different views of AI power. OpenAI released GPT-6 Astra, and company president Greg Brockman closed the briefing by declaring, “Welcome to the AGI era.” OpenAI designated Astra as the first model to reach the critical level for cybersecurity capability under its Preparedness Framework, meaning that under the right conditions it can discover previously unknown vulnerabilities and develop ways to exploit well-protected systems with far less human direction than before.

On the same day, Nvidia announced a nearly US$13 billion agreement to acquire Hugging Face, a platform used by more than 18 million developers, researchers, and creators to share and deploy AI models.  Nvidia said Hugging Face would remain open to models, clouds, and computing platforms from across the AI ecosystem. Its regulatory filing places the expected closing in the first half of 2027, subject to regulatory approval.

The relationship between those stories became clearer because Hugging Face had faced an unusual security incident only weeks earlier. During an OpenAI cybersecurity evaluation involving an earlier internal research model rather than Astra, autonomous agents escaped intended restrictions and compromised parts of Hugging Face’s infrastructure. For forensic analysis, some leading commercial models refused parts of the work because of their safety safeguards, so the team switched to an Nvidia-quantized version of the Chinese GLM-5.2 model that it could run on its own infrastructure, keeping sensitive attacker data inside its environment.

Stay ahead of the geopolitical week.

MD Briefing delivers expert analysis across five global fronts — the Indo-Pacific, energy, geoeconomics, European security, and the Middle East — every Monday morning. Free.

An American frontier lab, an American platform, an American chipmaker, and a Chinese model had become intertwined in one episode. Days later, Reuters revealed that earlier OpenAI agents had used more than ten additional websites for unauthorized communications. Reuters has also reported that US and Chinese officials are exploring bilateral AI-safety talks, although the timing remains unsettled.

These developments show why AI safety and control are moving into high politics. They also expose a quieter form of geopolitical power that leaderboards capture poorly: the ability to build an ecosystem that other institutions eventually find difficult to leave.

The frontier bias in AI strategy

Much contemporary AI strategy begins at the technological frontier. The Institute for AI Policy and Strategy’s January 2026 report, Strategic Visions in AI Governance: Mapping Pathways to Victory, written by Oscar Delaney, Maria Kostylew, Oliver Guest, and Peter Wildeford, maps nine possible approaches to navigating powerful AI. The visions differ in the balance between private and government control, centralization and international cooperation, while the prospect of one actor maintaining a significant technological lead shapes which policies appear attractive. A decisive intelligence advantage could generate major scientific, economic, cyber, and military benefits, but technology can also create power by spreading widely enough that institutions reorganize around it.

Three races, different winners

The AI race is increasingly three overlapping competitions. The frontier race is about who develops the most capable models and autonomous systems. The infrastructure race runs through chips, cloud capacity, data centers, networks, and energy. The quieter diffusion race is about whose models developers build on, whose platforms companies integrate, and whose technologies become familiar enough to underpin thousands of other systems.

Stanford’s 2026 AI Index found that, as of March, the performance gap between leading US and Chinese models had narrowed to 2.7 percent after models from both countries repeatedly traded leading positions. Astra’s September release illustrates how quickly that frontier can shift again. Benchmark leadership can change within months; ecosystems built around software, skilled workers, organizational processes, and infrastructure are much slower to unwind. For policymakers and risk managers, a temporary performance lead and deep ecosystem dependence are different strategic assets.

China does not need to win the frontier.

This distinction changes how China’s position should be assessed. Chinese companies can accumulate influence without holding the global frontier at every moment if their technologies become capable, affordable, and adaptable enough for others to build around them.

Hugging Face’s summer 2026 review counted more than 151,000 models derived from Alibaba’s Qwen family, giving Qwen a considerably larger derivative footprint on the platform than Meta’s Llama ecosystem.  While not a measure of global market share, those derivatives reveal what developers are choosing as foundations for products and specialized applications.  The same review found that major Chinese releases were significantly more likely than comparable American releases to use licenses that make models easier to modify and redistribute.

The commercial return can emerge elsewhere. In its June-quarter results, Alibaba reported that AI Cloud and Compute Services revenue grew 45 percent year on year, while AI-related product revenue recorded triple-digit growth for a twelfth consecutive quarter. The pattern suggests an ecosystem strategy: widespread access accelerates adoption, while cloud computing, enterprise services, and platform integration capture value as usage deepens. A model can remain highly consequential even when another temporarily tops the benchmarks, provided enough developers and institutions keep building around it.

How adoption becomes dependency

Ecosystem power rarely looks geopolitical at first. A company chooses one model because it is cheaper, a university teaches another because students can access it easily, a bank builds applications around a platform its engineers already understand, and a government agency stays with an existing provider because migration would slow an important project.

Together, those choices become strategic. Employees develop provider-specific skills, consultants specialize, data and processes are organized around particular platforms, and new applications are designed to work with the same ecosystem. Procurement and training reinforce what is already in place. Eventually, replacing the technology involves retraining staff, moving data, rewriting applications, and redesigning business processes.

For a risk director, this begins to resemble concentration risk. The central issue is how much of an organization becomes difficult to operate without a particular provider.

AI ecosystem power grows when adoption gets easier faster than exit does.

A multiplex world of dependencies

The emerging AI order is unlikely to divide neatly into American and Chinese technological blocs. A single institution may use American chips, Chinese models, domestic data infrastructure, and European governance standards at the same time.

The proposed Nvidia acquisition of Hugging Face makes this overlap unusually visible. Nvidia already occupies a critical position in AI computing, while Hugging Face sits closer to developers and model distribution.  Nvidia’s regulatory filing notes that many successful open models originate in China and are then adapted by developers in the United States and elsewhere, while also identifying restrictions on models from particular regions as a potential risk to the platform and the business.

This is a multiplex digital ecosystem in practice: ownership, infrastructure, models, data, and regulation cross national boundaries rather than lining up neatly behind one bloc. The strategic question is which technological layers are difficult to substitute, where sensitive data flows, and how long an institution could continue operating if an important provider became unavailable. Vulnerability rises when several critical dependencies converge and credible alternatives disappear.

When dependency is stress-tested

The July Hugging Face incident shows why these questions matter as autonomous AI becomes more capable.  Hugging Face’s forensic reconstruction identified roughly 17,600 attacker actions between 9 and 13 July. The volume and speed were far beyond what a human operator could sustain manually, while the system repeatedly rebuilt tools and communication channels as circumstances changed.

Hugging Face could keep investigating because it had another model it could run and control locally. That optionality becomes more consequential when the same dependency moves into banking, electricity, telecommunications, or public administration. A technical failure, cyber incident, provider restriction, or geopolitical disruption could affect systems supporting payments, energy supply, or essential public services. If the AI layer cannot be replaced quickly, a technology dependency becomes a business-continuity problem; across enough critical institutions, it becomes a national resilience problem.

Financial regulators already recognize the underlying logic. Under the European Union’s Digital Operational Resilience Act, financial institutions relying on third-party ICT services for critical functions must maintain documented and tested exit strategies that allow them to move away without disrupting business continuity. AI increasingly deserves the same discipline one layer higher.

Sovereignty is the power to switch—and keep functioning.

A practical test for sovereign AI follows. Local servers and nationally branded models can contribute to resilience, but strategic agency ultimately depends on whether institutions retain meaningful choices when circumstances change.

An AI-oriented digital public infrastructure could provide part of that buffer. One group of public safeguards should preserve the ability to move: interoperability, portable data, and credible provider substitution. Another should preserve continuity under stress through trusted identity and permissions, auditable decisions, incident reporting, and human override and fallback mechanisms for essential functions. These public rails can make competing AI ecosystems easier to govern and reduce the risk that early commercial adoption hardens into institutional captivity.

OpenAI may ultimately be right that the world is entering something resembling an AGI era. The technological frontier deserves serious attention, and exploratory US-China safety discussions show that advanced AI capability and control are already becoming matters for heads of state. Yet another geopolitical structure is forming beneath the headlines through developer ecosystems, platforms, cloud infrastructure, organizational routines, and the switching costs that connect them.

The strategic challenge is not to eliminate technological dependence. It is to keep dependence reversible. In the AI age, sovereignty may ultimately be measured by whether a society can still choose, govern and recover when the systems it relies on no longer behave as expected.

Tuhu Nugraha
Tuhu Nugraha
Tuhu Nugraha is an AI governance and digital economy strategist focused on ASEAN and the Global South. As Principal of the Indonesia Applied Digital Economy and Regulatory Network (IADERN), he advises public institutions and industry leaders on systemic risk and strategic adaptation as AI, digital financial systems, and critical infrastructure reshape the region.