The Leverage Middle Powers Have in the AI Race
Allied democracies can offer something U.S. industry desperately needs.

The world may soon be fracturing into artificial intelligence “haves” and “have-nots.” Last week, reports emerged that the White House had asked Anthropic and OpenAI to withhold early access to their latest systems from the British government’s AI Security Institute, the world leader in testing frontier models. Alarmed British officials had already begun to assess the economic and security impacts from losing access to the latest models.
They are right to worry. The rest of the world should be even more concerned. If Washington is prepared to restrict access for its closest intelligence partner, no country can count on an untrammeled supply of U.S. AI indefinitely.
The world may soon be fracturing into artificial intelligence “haves” and “have-nots.” Last week, reports emerged that the White House had asked Anthropic and OpenAI to withhold early access to their latest systems from the British government’s AI Security Institute, the world leader in testing frontier models. Alarmed British officials had already begun to assess the economic and security impacts from losing access to the latest models.
They are right to worry. The rest of the world should be even more concerned. If Washington is prepared to restrict access for its closest intelligence partner, no country can count on an untrammeled supply of U.S. AI indefinitely.
Indeed, the British episode is the latest in a growing list of warning signs for middle powers. When Anthropic launched its powerful Mythos cybersecurity model in the spring, it gave access first to a select group of handpicked companies. Every one of the launch partners was American. In June, in an effort to address a domestic security question, the Trump administration used sweeping export control authorities to bar any foreign national, anywhere in the world, from accessing Anthropic’s most advanced models. The order was lifted weeks later, after the company agreed to work with the government on standards for future releases, but for U.S. allies, the lesson was clear: Their access to frontier AI depends on the whims of the U.S. government.
But foreign states are not without leverage of their own. To sustain the stock market rally and the trajectory of AI progress—among the Trump administration’s central political priorities—the AI industry needs to keep building data centers. In the United States, that is getting increasingly difficult: Americans dislike AI and the firms that build it; they dislike large, noisy, energy-hungry construction projects; and they dislike shadowy corporations paying hush money to advance such projects.
That opens the door to what might be called a grand compute bargain. Allied democracies can offer something the U.S. AI industry desperately needs: data center sites with reliable power, predictable governance, and existing security relationships. In return, they can extract something they desperately need: guaranteed access to frontier AI systems. It’s a clean quid pro quo: U.S. allies help solve the domestic data center shortfall, and the United States gives its allies a slice of its AI industry in return.
The scale of the U.S. data center buildout is staggering. This year alone, in what has become the largest industrial mobilization since World War II, four U.S. tech companies will spend more than $700 billion, or around 2 percent of U.S. GDP, on AI infrastructure. That spending is overwhelmingly flowing to domestic data centers: The United States now has more data center capacity than the next 14 countries combined. China, its nearest rival, hosts only about a fifth as much AI computing power. There are single megaclusters in the United States, such as the Anthropic-Amazon site in Indiana, that reportedly contain more computing power than all of Europe. Even the largest clusters in close U.S. allies such as Australia and South Korea are a small fraction of that size.
This concentration has helped the United States leave the rest of the world behind on AI; only China has a realistic chance of competing at the frontier. All European model developers combined, for example, earn less than 2 percent of the revenue of just two U.S. companies. In the first half of this year, OpenAI and Anthropic alone raised roughly 10 times more venture capital than every European AI start-up put together.
Until recently, much of the world remained relatively sanguine about this situation. Governments assumed that even if their countries did not have the resources to build frontier systems themselves, they could capture the gains of rapid AI progress by using and adopting AI systems well, whether U.S. frontier models or Chinese open-source ones. But that assumption is now looking increasingly fragile, endangered on two fronts.
First, security concerns are driving the U.S. government and U.S. developers to restrict access to their best models. States that don’t have access to the most advanced systems will struggle to compete in a race to deploy and diffuse AI across their economies. Second, the surging demand for AI computing is outpacing the buildout of the data centers required to supply it. Unlike with traditional software licenses, which have near-zero marginal costs, every unit of AI computing served to one customer requires compute that is unavailable to another. With leading developers regularly facing compute crunches, even unrestricted commercial access could face rationing—rationing that is unlikely to favor non-American consumers.
Chinese models, for their part, may be cheap, but for European and Asian democracies wary of Chinese dependencies, they come with their own risks, and there is no guarantee that Beijing will continue to greenlight open-source models indefinitely. When the European Union did not get access to Mythos, the Europeans were not reassured by their access to “good enough” Chinese alternatives.
That leaves U.S. allies in a precarious position: They are ensured neither a share of the economic and strategic gains from developing AI nor reliable access to the systems U.S. AI companies will build.
But the U.S. buildout may soon lose steam. Data center moratoriums are spreading across the country, from New York to Texas. The backlash is a rare bipartisan phenomenon: 3 in 4 Americans oppose the construction of a data center nearby, including two-thirds of Republicans and around 80 percent of Democrats. It’s beginning to have meaningful economic effects: About $18 billion of loans tied to Oracle projects in New Mexico have come under pressure, as investors worry that local opposition will derail the company’s massive AI infrastructure plans.
The obstacles are not purely political; technical constraints, such as U.S. grid capacity, are tightening, too. In the shrinking number of jurisdictions that still welcome data centers, developers are running out of ways to power them. Order books for behind-the-meter gas turbines, the industry’s fastest route to power, are backlogged by years. Nuclear energy, meanwhile, is far from delivering at the scale required.
The Trump administration’s original solution to its domestic constraints was the Gulf. That option was always risky; today, it looks increasingly untenable. Seven months after Iranian drone swarms hit Amazon data centers in the United Arab Emirates and Bahrain, the facilities remain mostly offline, and the company has failed to restore customer access to data hosted inside them. The UAE is revising its plans for its largest AI facilities, dispersing projects across the country, but so long as the war drags on, supply chains remain snarled, and insurance costs stay elevated, companies will think twice before pressing ahead in the region.
That gives the United States’ democratic allies an opening. Five Eyes partners such as Australia can offer cheap solar power and ample land. European allies such as Germany can offer decommissioned industrial sites with existing grid connections. The Nordics have abundant hydroelectric power. Japan and South Korea, despite their own land constraints, offer political stability, deep security partnerships, and sophisticated workforces. With AI labs desperate for even modest sources of compute for inference (the process of deploying systems for day-to-day use, as opposed to training new models), relatively small contributions to the buildout are increasingly valuable.
Hosting U.S. data centers gives allies two things. The first is tax revenue: a direct economic stake in the AI industry at a moment when the gains from AI threaten to concentrate entirely in the United States. Loudoun County, Virginia, for example, collects $1.3 billion a year in county taxes from these facilities, or about $2,800 per resident. For European governments under mounting fiscal pressure, this is not a trivial consideration.
The second is sorely needed leverage. In exchange for favorable sites, U.S. allies can seek guaranteed access to frontier models: They can demand contractual assurances that the labs release frontier models in their markets at the same time as in the United States and that their critical infrastructure operators receive access equivalent to their U.S. counterparts.
Contractual guarantees of model access, however carefully drafted, are only as durable as the incentives that sustain them. That is why the physical infrastructure matters: It gives allies deeply skeptical of U.S. promises an enforcement mechanism. Companies that have sunk billions of dollars into overseas data centers have given the hosts the ability to impose costs if the relationship sours. They can reduce energy access or fiscal benefits, withdraw permits for expansion, or, in extremis, restrict their operations entirely, repurposing the data centers for their own domestic purposes. Without this commitment mechanism, allies are relying on assurances from companies and a government whose policies have given them every reason for skepticism. But if U.S. firms fear losing access to their infrastructure, they will have strong incentives to lobby against the overbroad export controls and restricted access programs that allied governments fear lie ahead.
The politics of these negotiations will be anything but easy, on both sides. For U.S. allies, pursuing these compute-for-access deals requires swallowing multiple bitter pills at once: It requires accepting that the United States will stay ahead on frontier AI, that allied leverage is limited, and that the best way to use their own limited grid and data center site capacity is to host U.S. firms. U.S. tech companies have never been especially popular in much of the world; today, their popularity may be at historic lows in most advanced democracies.
Yet the ask of allied governments is relatively limited. They should not offer public subsidies to some of the world’s wealthiest companies. But they do need to provide predictability: credible signals that they will not obstruct projects that meet clear criteria on clean energy, grid investments, and local tax commitments. Allies that can offer timelines to get a data center up and running of around two years from project approval to first operation—fast by the standards of most advanced democracies—will find no shortage of takers. In Australia, one of the most attractive locations for data center buildouts, Anthropic has recently signed a lease agreement for more than 2 gigawatts of data center capacity.
On the U.S. side, meanwhile, these deals require willingly handing allies leverage over the United States: data center projects that these allies could, in theory, subsequently cut off, expropriate, or hinder. For an administration that has been at best skeptical of its democratic allies and at worst outright hostile to them, this runs against nearly every instinct.
Nearly every instinct—but not all. The administration cares, above all else, about sustaining the U.S. lead over China on AI and keeping the stock market rally alive. As Treasury Secretary Scott Bessent put it last month, “If they were to pull away from us on AI, then nothing else would matter.” Without giving allies some ability to punish U.S. defection, those allies will not commit to the U.S. tech stack. They will hedge between U.S. and Chinese models, pursue sovereign alternatives, no matter how uncompetitive, and slow-walk the approvals of the data centers that underpin the U.S. AI lead.
For centuries, European states sealed peace treaties by exchanging hostages—the son of a king, for example, handed over as a guarantee of compliance. No one expects the Trump administration to offer up one of its own. But several billion dollars’ worth of data centers on allied soil might serve a similar purpose.
Sam Winter-Levy is a senior fellow at the Carnegie Endowment for International Peace. X: @SamWinterLevy
Anton Leicht is a fellow at the Carnegie Endowment for International Peace.
Stories Readers Liked
Brazil’s Election
















