The week ending 25 September 2026 showed that the next phase of AI competition will be determined less by possession of isolated technological assets than by the ability to govern and convert them into reliable strategic capability. At the United Nations Security Council, the heads of OpenAI and Anthropic urged governments to cooperate on frontier-AI safeguards, elevating AI from industrial and technology policy into the institutional machinery of international security. At the same time, Anthropic's Claude Opus 5.5 demonstrated that high-end capability is becoming cheaper and therefore easier to diffuse into organisations and markets. Europe produced the week's clearest negative case: ASML remains an extraordinary European chokepoint in the global semiconductor system, yet its executive said the company is selling no chipmaking equipment in Europe because the region is not building fabs at sufficient scale. Cyber developments completed the picture. Microsoft's reporting on Storm-3168 showed how compromised workload identities and automated cloud actions can turn access into destructive effect within minutes, while new security controls are explicitly being designed for autonomous agents. Taken together, these developments point to a common strategic problem: the gap between technological capacity and the institutional, industrial, security, and operational mechanisms needed to make that capacity usable without losing control of it.
The AI race is becoming a governance-and-conversion race.
For several years, AI geopolitics was often narrated through possession: who had the best frontier models, the most advanced GPUs, the deepest semiconductor supply chain, the largest data centres, or the most abundant capital. Those variables still matter. But this week's developments reinforce a harder proposition: possession is strategically meaningful only when resources can be converted into reliable action under conditions of competition, risk, and dependence.
The UN Security Council meeting is important because it institutionalises this shift at the highest level of international security governance. AI firms did not merely ask governments to subsidise innovation or avoid regulation. They explicitly argued that increasingly autonomous systems require international coordination, capability measurement, shared standards, and mechanisms for preserving human control. This is a recognition that frontier capability has moved far enough downstream toward operational use that governance can no longer be treated as an external constraint applied after innovation. It is becoming part of the conversion architecture itself.
Anthropic's Opus 5.5 sharpens the same point from the technology side. The model is presented as delivering performance comparable with the company's top tier at substantially lower operating cost, while incorporating stronger safeguards and external pre-release evaluation. Lower cost expands the number of organisations able to use frontier-level capability. That improves diffusion and economic value, but it also expands the number of environments in which model behaviour, access, identity, data governance, and cyber controls must work reliably. Cheaper intelligence increases the conversion opportunity and the governance burden simultaneously.
Europe's ASML problem is the inverse. Europe possesses one of the most strategically important corporate assets in the entire semiconductor value chain. Yet the company says its current European system sales are effectively zero because the region is not building enough advanced semiconductor manufacturing capacity. The implication is not that ASML lacks strategic value. It is that the presence of a national or regional champion cannot substitute for the surrounding ecosystem required to convert a chokepoint into broader capability: fabs, customers, capital expenditure, energy, skilled labour, demand, supply-chain coordination, and sustained industrial policy.
Cybersecurity reveals where failed conversion can become immediate strategic loss. Microsoft's Storm-3168 investigation documented compromised Azure service principals conducting reconnaissance, bulk destructive actions, key retrieval, and attacks on recovery mechanisms. The attacker did not need to seize a frontier model. It targeted the privileged interfaces through which organisations already automate cloud capability. This is a reminder that operational power resides in identities, permissions, control planes, and recovery architecture as much as in algorithms.
The common denominator is therefore conversion governance. States and organisations must govern who can access advanced capability, how it is integrated into infrastructure, how dependencies are managed, how failures are contained, and whether alternatives exist when critical suppliers or systems become unavailable. The strategic unit is no longer the model, the chip, or the firm in isolation. It is the conversion system connecting them.
In GOAI terms, the centre of gravity this week sits across all three layers. Invention continues to advance and diffuse. Industrialisation determines whether capability can be produced and scaled domestically. Operationalisation determines whether it becomes usable in institutions and critical systems. Governance operates across all three, shaping access, coordination, security, legitimacy, substitution, and control.
The invention layer was visible in the release of Claude Opus 5.5 and in the broader frontier-lab discussion about increasingly autonomous and self-improving systems. Anthropic says Opus 5.5 performs at the level of its higher-end Fable 5.1 on most work while operating at lower cost, and that it underwent external evaluation by Frontier Design and METR before release.
The strategic implication is not simply another benchmark improvement. When frontier-level performance becomes cheaper, the effective supply of advanced intelligence expands. That can accelerate scientific work, software development, cyber defence, and organisational adoption. It can also compress the time between invention and operational diffusion, leaving less room for institutions to adapt.
Industrialisation produced the week's most revealing geopolitical contrast. ASML remains Europe's premier semiconductor chokepoint, but a senior executive said the company is currently selling no chipmaking machines in Europe because the region is not building new fabs at sufficient scale. Reports coincided with renewed debate over a Chips Act 2.0.
This is a textbook capability-conversion problem. Europe possesses a globally indispensable firm, advanced research institutions, regulatory power, and significant public funding. Yet those assets do not automatically create domestic leading-edge semiconductor production. Industrial capability requires complementary investment, production sites, demand, customers, energy, skills, permitting, and a credible long-term market.
Operationalisation was visible both at the international level and inside digital infrastructure. The UN Security Council's decision to hold a high-level meeting on AI and international security shows that AI systems are increasingly viewed through their potential effects on security, military affairs, cyber operations, state power, and systemic risk.
At the organisational level, Microsoft's Storm-3168 findings demonstrate how quickly access can become effect. A compromised service principal moved from reconnaissance to a seven-minute destructive sequence against Azure resources, followed by credential collection. That is operationalisation in adversarial form: machine-speed use of permissions and cloud control planes to convert access into disruption.
Governance was the strongest cross-layer mechanism this week. It appeared in calls for international capability standards, model safeguards and external evaluation, proposed limits on dangerous uses, debates over European industrial policy, cloud identity controls, recovery protection, and Zero Trust architectures for AI agents.
The point is not that governance is replacing competition. Governance is becoming one of the arenas through which competition is conducted. Standards can shape market access; safety requirements can affect release timing and cost; cloud identity controls determine resilience; and industrial rules influence where production capacity accumulates. Governance therefore affects the efficiency with which technological resources become strategic capability.
What happened: On 23 September, the UN Security Council held a high-level briefing on artificial intelligence and international security. Briefers included OpenAI CEO Sam Altman, Anthropic CEO Dario Amodei, Hugging Face CEO Clément Delangue, and Yoshua Bengio. The meeting was convened by France under the Council's maintenance-of-international-peace-and-security agenda.
Why it matters: This is an institutional threshold. AI has been discussed for years in economic, ethical, regulatory, and arms-control contexts, but a dedicated Security Council session embeds frontier AI directly in the vocabulary of international peace and security. That increases the likelihood that future debates will involve strategic stability, cyber operations, autonomous systems, proliferation, capability monitoring, and crisis-management mechanisms.
What happened: OpenAI called for the United States to lead international efforts around shared AI standards, including capability measurement, risk management, preservation of human control, and conditions under which development may need to slow. At the Security Council, OpenAI and Anthropic leaders both argued for international cooperation on frontier risks.
Why it matters: The firms producing frontier systems are acknowledging that unilateral corporate safeguards are insufficient for capabilities with cross-border effects. This does not remove their commercial interests or resolve disagreements over regulatory design. It does, however, change the strategic relationship between firms and states: frontier labs are increasingly attempting to co-design the institutions that will govern the systems they build.
What happened: ASML Executive Vice President Frank Heemskerk said the company is currently selling no chipmaking systems in Europe, attributing the situation to weak investment and the absence of significant new semiconductor-fab construction. The comments came as Europe continued debating a second-generation Chips Act.
Why it matters: ASML is arguably Europe's strongest single asset in the global semiconductor system, yet its presence has not generated a self-sustaining European advanced-manufacturing ecosystem. This demonstrates the difference between possessing a chokepoint firm and converting that firm into broad regional capability.
What happened: Anthropic released Claude Opus 5.5 on 22 September. The company says the model performs at the level of Claude Fable 5.1 on most work while costing around 40 percent less than Opus 5 on typical token-billed workloads. Anthropic also emphasised stronger behavioural safeguards and external pre-release evaluation.
Why it matters: Falling cost changes geopolitics because frontier capability becomes easier to diffuse across enterprises, governments, startups, and smaller states. The relevant variable is not only who invents the model but who can afford to operationalise it at scale.
What happened: Microsoft Security Research documented Azure-focused malicious activity associated with Storm-3168, which Microsoft links to JADEPUFFER. Two compromised service principals were used for reconnaissance, destructive operations, and credential collection. Microsoft observed a seven-minute destructive sequence involving more than 100 storage-account deletion attempts and additional attacks on databases, recovery protections, and keys.
Why it matters: Workload identities are becoming high-value strategic control points. Modern cloud environments depend on service principals, API permissions, automation, and non-human identities. When those identities are compromised, attackers can operate at machine speed across infrastructure.
What happened: Microsoft's September security updates focus on discovering and governing local AI agents, extending Zero Trust to agent traffic, and controlling the resources agents can access. The company is treating agents as entities that require visibility, identity, access policy, and containment.
Why it matters: Traditional security architecture assumed human users, services, and applications. Agentic AI introduces semi-autonomous actors that can initiate actions across software environments and interact with other agents and tools. That expands the set of identities and control relationships organisations must govern.
What happened: Microsoft described EvilTokens as a fast-growing phishing-as-a-service platform that abuses legitimate OAuth device-code flows. Attackers can trick users into authorising sessions without directly stealing passwords, bypassing some traditional MFA expectations. Microsoft also observed automation supporting the phishing infrastructure.
Why it matters: AI-era systems still depend on conventional identity infrastructure. Advanced models and agents do not eliminate older attack paths; they can increase the value of successfully compromising them because a stolen identity may expose cloud data, SaaS platforms, developer tools, and AI services simultaneously.
What happened: Microsoft published new tracking of Storm-2570, a ransomware affiliate observed across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Microsoft argues that focusing only on the final payload obscures recurring post-compromise tradecraft that defenders can detect earlier.
Why it matters: This matters for AI geopolitics because automation and AI assistance increasingly operate inside longer attack chains. Strategic defence depends on identifying recurring behaviours, privileged access, persistence, and lateral movement before attackers reach the final destructive or extortion phase.
Pattern: AI-era cyber power is concentrating in identities, automation, and cloud control planes.
Cybersecurity was not the dominant strategic signal of the week, but it supplied the clearest operational evidence for the wider governance-and-conversion argument. Three developments matter together: Microsoft documented automated destructive cloud activity through compromised service principals; its September security architecture explicitly extends Zero Trust to AI agents; and its EvilTokens research showed how legitimate authentication mechanisms can be turned into scalable access infrastructure.
The week's most strategically important vector was compromised cloud workload identity, specifically service-principal credentials with excessive or consequential permissions.
Microsoft found that credentials associated with one affected service principal had previously appeared in plaintext in a public GitHub issue. The company could not confirm that this exposure was the route used by Storm-3168, so it should not be presented as confirmed initial access. What is confirmed is that compromised service principals were subsequently used for destructive and credential-collection operations across Azure resources.
The strategic significance lies in the position of the identity. A service principal is designed to let software act without a human repeatedly authenticating. That makes it a conversion mechanism for legitimate automation—and, once compromised, for adversarial automation as well.
The week's strongest confirmed incidents centred on cloud environments rather than newly disclosed attacks against physical critical infrastructure. The relevance to critical infrastructure is nevertheless direct. Electricity, water, transport, healthcare, government, and defence organisations increasingly depend on the same cloud identities, SaaS platforms, developer pipelines, and agentic systems documented in this week's research.
The analytical inference is therefore that critical-infrastructure exposure is migrating upward into digital control planes. Physical resilience will increasingly depend on whether cloud identity, recovery systems, remote management, and AI-enabled operational tools remain available under attack.
Ransomware remained active through Storm-2570 and through the ransomware-aligned behaviour associated with Storm-3168. However, the strategically important point is that attackers are targeting the recovery and control architecture before the extortion stage. Storm-3168 attempted to delete storage, databases, and recovery-related protections while collecting keys that could provide access to data.
This creates pressure on organisations to separate recovery authority from production authority. If the same compromised machine identity can alter production resources and disable recovery, resilience exists administratively but not operationally.
Microsoft's Storm-3168 reporting associates the activity with JADEPUFFER, a threat actor previously documented in agentic ransomware research. The material used for this Weekly does not establish a state sponsor. The correct classification is therefore financially or operationally malicious activity with geopolitical relevance because it demonstrates a transferable model for AI-orchestrated cloud attacks, not a confirmed state operation.
This distinction matters. Strategic significance does not require state attribution. Techniques that compress cloud reconnaissance, credential collection, destruction, and recovery impairment can diffuse between criminal and state-linked ecosystems, increasing the defensive burden on both governments and private operators.
Treat machine identities as first-class strategic infrastructure. Inventory service principals, workload identities, API keys, agent identities, and automation accounts; eliminate long-lived public secrets; rotate exposed credentials immediately; enforce least privilege; isolate recovery authority; monitor machine-speed bursts of administrative activity; and require explicit policy for what AI agents can reach.
The governing principle is simple: every identity that can convert software instructions into infrastructure action should be treated as a privileged control surface.
| Control surface | Direction this week | Strategic significance | GOAI interpretation |
|---|---|---|---|
| International frontier-AI governance | Rising sharply | Very high | AI becomes an explicit international-security coordination problem |
| European semiconductor industrial depth | Weak / exposed | Very high | Strategic firms do not automatically create regional capability |
| Frontier-model cost and diffusion | Falling cost / widening access | Very high | Cheaper capability accelerates both operationalisation and governance burden |
| Cloud workload identities | Rising sharply | Very high | Machine identities become high-value conversion and attack surfaces |
| AI-agent identity and traffic | Emerging rapidly | High | Zero Trust must expand from human users to autonomous actors |
| Recovery infrastructure | Under pressure | High | Resilience fails if production compromise can disable recovery |
| OAuth / SaaS identity | Persistently exposed | High | Conventional identity remains the bridge into AI-enabled enterprises |
| International standards leadership | Contested | High | Rule-setting becomes a source of strategic influence |
The Weekly Sensemaking applies the Geopolitics of AI capability-conversion framework: Invention, Industrialisation, and Operationalisation, with governance operating across all three layers. The framework distinguishes possession of AI-related resources from the institutional, industrial, infrastructural, and operational processes required to convert those resources into usable strategic capability.