Every few months, a new frontier release resets the terms of the artificial-intelligence debate. In June it was Anthropic’s Claude Fable 5 and Claude Mythos 5; within days, a US government export-control order forced Anthropic to cut access for foreign nationals. Access was restored two weeks later, but the episode demonstrated something middle powers have known in theory for a while: when you depend on someone else’s frontier capability, they control the off switch.
It’s a real concern and governments are scrambling to respond with new AI-sovereignty strategies, including plans to build national AI models. But there is a danger in jumping from understanding that dependence on foreign frontier capability creates strategic risk to concluding that AI sovereignty means a national frontier model. The concentrations of capital, compute and research talent required to compete at the technological frontier are simply beyond middle-power reach.
At the Tony Blair Institute for Global Change we argue for a broader conception of AI sovereignty, balancing access to frontier capability with managing strategic dependencies. There’s a requirement to look beyond ownership of the model to how countries position themselves across the AI stack.
Core to middle-power AI sovereignty is investing in the open-source stack. Not just models, but the broader ecosystem of tools, software, standards, data and technical capabilities that allow countries to adopt, adapt and deploy AI without having to build every layer themselves. But the open-source stack is broad. It is one thing to say governments should invest in open source and another to strategically pinpoint where they should target their resources.
Building on work with Mozilla and the findings of its new report, The State of Open Source AI, here we examine what these changes mean for middle-power AI strategy and where governments should focus their efforts. In light of recent advancements in the capability of open-source models, Mozilla observes that the strategic question for governments is shifting from “How do we own a model?” to “How do we ensure our country can securely deploy, adapt and switch between the world’s best models to capture the value created around them?”
The answer: invest in the AI harness.
The harness is an opportunity for middle powers to build strategic capability in a part of the AI stack where they can realistically compete. But it is more than that. The development of AI is nearing a critical inflection point: the choices made now about who builds, controls and sets the standards for the infrastructure around models will shape who is able to capture AI’s economic value and influence how the technology develops.
Put differently, middle powers do not need to build the world’s best AI “engine” to capture its benefits. Their opportunity lies in building the “roads” that allow increasingly abundant AI capability to be put to work.
What Is the AI Harness?
The software between people and models that determines what an AI system can see, remember and do is what’s defined as the AI harness. It includes the instructions that tell a model how to behave; connections to information such as company documents or government databases; access to tools that let it search the web, use software or interact with other systems; and memory that allows it to retain relevant information and keep track of a task. In short, it unlocks the model’s value.
The harness is becoming increasingly important with the rise of AI agents: systems designed to act on a user’s behalf, from making purchases and booking travel to coordinating calendars and carrying out business tasks. A model on its own cannot search a database, edit a file, make a payment, recover when something goes wrong or determine when a task has been completed; nor does it come with rules governing how it should interact with the world. For example, the harness defines whether an agent can make a payment of, say, £5 or £5,000 before seeking human approval. And if an agent can access government databases, the harness determines the records it can see, the information it can change and whether it can share that information with other systems.
How Open Source Is Changing the Calculus on AI Sovereignty
In the battle to produce competitive alternatives to US proprietary AI models, open source is holding its own. In July, Chinese startup Moonshot AI released Kimi K3. Its performance put an open-weight model (which makes its trained parameters – weight – publicly available, without necessarily being fully open source) within striking distance of the world’s leading proprietary systems across coding, reasoning and agentic tasks. In a test of agentic capability – how well the model can plan and execute multi-step tasks without intervention – Kimi K3 scored 88.3 per cent, against 88.8 per cent for OpenAI’s latest model, GPT-5.6 Sol.
This is indicative of a wider trend. Mozilla has found that the best open model now sits just one release cycle behind the closed frontier, while the cost of running a model with capabilities comparable to GPT-4 has fallen 50-fold in just three years. Open-weight models have gone from a negligible share of traffic on leading-model interface platforms in 2024 to constituting a majority of traffic by mid-2026.
Open models are no longer an interesting but inferior alternative to the frontier: they are capable, cheap and increasingly used in AI tools and products placed on the market. The strongest proprietary models still have an edge on some of the hardest tasks and that edge is important, particularly from a national-security perspective. But open models have crossed an important threshold for many economic applications, providing a viable alternative to countries either developing their own models or relying entirely on foreign providers.
It makes little economic sense for most middle powers to spend billions building a general-purpose national model from scratch when increasingly competitive open-source capability is readily available. The strategic question for governments, therefore, becomes less about building models and more about having the assets and capabilities needed to translate increasingly available intelligence into economic value.
Imagine the world’s richest companies were spending hundreds of billions of dollars racing to produce ever more powerful car engines, while challengers were producing dramatically cheaper engines that might not match the best on every measure, but could handle most journeys and were available for anyone to use. If a middle power had $1 billion to invest in improving road transport, there would be no sense in trying to build the world’s 20th-best engine. The better strategy would be to make its economy exceptionally good at putting the challengers’ cheaper and still very good engines to work. That would mean building the vehicles the engines propel, the roads the vehicles run on, the charging points that fuel them and the services that maintain them. It would also mean creating the ecosystem of businesses and services that turn cheap, abundant engines into economic value.
In other words, don’t race to build the engine – start building the roads.
For AI sovereignty, this does not mean models cease to matter, nor that middle powers should become indifferent to where they come from. Dependence on a small number of foreign model providers still creates strategic risk – as the recent Mythos and Fable episode demonstrated – so governments should continue working to secure access to frontier capability where it matters (particularly for national security and cyber). However, managing dependence differs from trying to eliminate it by reproducing the frontier domestically.
The harness is a critical part of that infrastructure: it is what allows increasingly capable models to be adapted, deployed and put to work across an economy.
Middle Powers Have a Huge Opportunity
When the battle for AI sovereignty was framed as a battle over model ownership, few countries had a realistic chance to compete. With the rapid improvement of open-source models, the nature of the contest has changed – and the playing field is much more even.
As a result, middle powers are in a position to capture economic value. Some will control the scarce resources needed to deploy AI at scale, such as energy and compute. Others might have advantages in proprietary industrial data, strengths in trusted government digital infrastructure or expertise in particular sectors and markets. However, all countries have an opportunity in the harness layer.
Harness software is the infrastructure that allows models to be deployed across business and public services and adapted to local needs; it is also dramatically cheaper and more accessible to develop than frontier models.
However, Mozilla’s developer evidence reveals an important gap, ripe to be filled. While 79 per cent of developers use open models, for mid-sized organisations only 55 per cent of teams using them reach production, compared with 66 per cent of teams using closed models (57 and 73 per cent respectively for large enterprises). The problem is not that open models lack capability; instead, developers report difficulties around deployment, hosting, scaling, security, privacy, compliance, maintenance and standardisation. Proprietary models often come packaged with mature infrastructure that makes them relatively straightforward to deploy. By comparison, open models offer greater freedom and control but the surrounding infrastructure is less developed, often making them more difficult to use.
This is where the economic opportunity arises. Governments can support the harness-layer market by investing in foundational open-source tools for shared harness infrastructure that would benefit the wider ecosystem. They can also help make existing open tools secure and reliable enough for government and enterprise use.
But even more important than supporting open-source harness development is ensuring that the foundations of the harness ecosystem remain open and interoperable. Middle powers can encourage vigorous competition in the products and services built at the harness layer, but must work together to establish common rules and standards to support them.
Consider the earlier transport analogy. Governments and companies can compete over whose roads are smoother, whose cars are more aerodynamic and whose charging points are more efficient. But businesses and economies enjoy greater benefits when cars can travel across different road networks and use different charging infrastructure. Compatibility expands the market in which products and services can operate, allows transport businesses to reach customers across borders and lowers costs for producers, who can build on common infrastructure. For drivers it means a better experience and greater choice between competing products and services.
It is the same for AI. Countries can compete on the quality of the AI infrastructure and services they build, while preserving a common foundation that prevents any single model or harness from becoming the only viable way to participate. That means working together on open standards and protocols that allow different models and harnesses to work together, with common approaches to how agents connect to data and tools, transfer memory, and establish identity and permissions.
Get this right and middle powers can create larger, more competitive markets for their domestic firms while enabling wider innovation. They can also ensure that their economies can take advantage of the best AI models available, wherever they come from.
But the window for middle powers to shape this harness layer may be narrow. Leading AI companies are already building harnesses around their models and as these systems spread, the protocols and rules embedded within them can quickly become the defaults that others build around. The risk is not standardisation itself, but allowing harness standards to become entrenched without open governance and genuine interoperability. This would leave a small number of providers with disproportionate influence over how models are deployed and used.
Middle Powers Should Act With Urgency
The shift towards the harness gives middle powers a genuine opportunity to capture more of AI’s economic value, and influence how the technology is deployed. But that opportunity will not secure itself. Governments need to invest in the harness ecosystem while using their market and convening power to ensure it develops around open, interoperable foundations. Here are four steps that middle powers should take.
1. Invest in Critical Open-Harness Infrastructure
If widely used harnesses are optimised around the models and services of the companies that built them, domestic firms face a structural disadvantage when trying to compete. They may still be able to build harness products and services, but it will increasingly be on terms set by incumbent platforms and within markets organised around them.
Governments should therefore treat foundational harness software as strategic infrastructure. That means investing in the shared tools that allow different models to be turned into reliable products and services: connections to data and software, agent orchestration, memory systems, evaluation and monitoring, secure execution, and identity and permissions.
Open models are already widely used by developers, but they are less likely to make it into production (as deployed AI systems and tools) because their surrounding software tooling and infrastructure remains less mature than that of proprietary models. Governments can help by funding the development and maintenance of important open components, security testing them and helping make them reliable enough for businesses and public institutions to use at scale.
This is not an argument for governments to build a single national harness; nor does every harness product need to be open source. The aim is to ensure a strong foundation of shared open infrastructure on which domestic firms can build competing products and services.
2. Make Interoperability and Portability Requirements of Public AI
In theory, the availability of multiple open-weight models provides alternatives: if one model becomes unavailable or too expensive, or is overtaken by a better one, governments can switch. But that only works in practice if different models can plug into the same harness without the surrounding system having to be rebuilt. Open models create the possibility of exit; an interoperable harness makes exit practical. Without one, governments could still find themselves effectively locked into a provider despite having alternative models available.
Governments should therefore use procurement to make sure the harness market develops around interoperability rather than provider lock-in. For significant public-sector AI systems, procurement frameworks should ask a simple question: could the underlying model be changed without rebuilding the service? That means (where technically appropriate) common interfaces between models, tools and data; portability of workflows and memory; access to evaluation records; and credible arrangements for moving to another provider. Governments should also favour standards that can be implemented by multiple vendors rather than interfaces controlled by a single platform.
This is not an “open source at all costs” procurement policy. Proprietary systems might offer the best performance or value for particular uses. The objective is to make sure that choosing a proprietary model today does not unnecessarily determine which model or provider governments must use tomorrow.
3. Keep Memory and Institutional Context Under National Control
A critical component of interoperability is memory. Governments may be able to replace one model with another, but switching is of limited value if it means losing the institutional context accumulated around the previous model.
Memory is a function of the harness that allows an AI agent to retain relevant information beyond a single interaction. Over time, an agent operating inside a government department can accumulate knowledge of previous cases, decisions and interactions, remember the state of ongoing work and build up context about how an organisation operates. This institutional context makes the system more useful over time, drawing on what it already knows rather than requiring processes, decisions and ongoing work to be repeatedly explained. But that also creates a powerful source of lock-in: if memory sits inside a model provider’s proprietary system, changing the underlying model could mean losing or having to reconstruct years of accumulated context, creating an incentive to remain with an existing provider even when better or cheaper models become available.
Governments should therefore design AI systems in a way that keeps memory under their control, separate from any single model provider. They should retain control of where sensitive memory is stored, who can access it and how it can be transferred between authorised systems. Common formats and interfaces should allow the same institutional memory to be used with different models as technology changes. This extends TBI’s previous argument that strategic data should be treated as a national asset into the agentic era.
4. Shape Emerging Rules for AI Agents Before Proprietary Standards Harden
The harness encodes many of the rules that will govern AI agents: how they access data and tools, retain memory, establish identity and permissions, interact with other systems and are evaluated. These rules will increasingly shape what AI can do, what decisions remain in human control and how the technology interacts with institutions and society. As agents increasingly move from answering questions to taking real-world actions, the rules and controls built into the harness will become increasingly consequential.
For middle powers, this has significant national-security implications. The harness determines how AI can interact with sensitive national systems: for example, whether an agent can only read a classified record or also transmit it outside a secure environment. If governments become dependent on harnesses designed and governed elsewhere, they risk importing permission structures, security assumptions and technical constraints that were not designed around their own national-security requirements.
But because these rules are not yet settled, there is an opportunity to shape them. By investing now, middle powers can help define emerging standards around their own security requirements, priorities and values – becoming rule-makers instead of rule-takers as standards are established.
Mozilla’s report identifies permissions – the rules governing what an agent can access and do – as a major unresolved gap in the emerging harness ecosystem. To help fill this gap, governments can fund the development and testing of open-permission systems; ensure their technical agencies and experts participate actively in international standards-setting processes; work with like-minded countries on common approaches; and use public-sector deployments to test how those standards work in practice. Governments also need to be able to verify that permissions are actually being followed. That means supporting common methods for testing agent behaviour, keeping reliable records of consequential actions and auditing whether agents are remaining within the authority they have been given.
This is an area where middle powers can exercise influence far beyond their share of global frontier-model compute. Acting together, they can help establish rules that become widely adopted across markets rather than simply accepting whichever approaches achieve commercial scale first.
Open-weight AI models from leading Chinese labs (including Alibaba, DeepSeek, Moonshot and Z.ai) are now among the world’s most capable; they are ahead of open-source options stemming from the US or elsewhere and come closest to matching proprietary US frontier models. That raises a concern for middle powers: does relying more heavily on open models simply mean swapping dependence on US frontier-model providers for dependence on Chinese technology?
A thriving open-source ecosystem can help countries avoid replacing one dependency with another – and interoperability is key. If models from different developers can plug into the same harness, governments and businesses can move between Chinese, American and other models as their relative capability, cost and risk change, without rebuilding the surrounding system.
Perhaps more importantly, participating in the open ecosystem gives countries influence over how that ecosystem develops. Withdrawing from it risks having the opposite effect. The Trump administration, for example, has considered restrictions on China’s cutting-edge open-weight models as their capabilities and adoption have increased, in an effort to limit US reliance on Chinese AI and address associated national-security risks. But such restrictions could prove strategically counterproductive: they might protect US proprietary frontier-model providers from competition domestically, but in doing so leave Chinese models to become the default open foundations for developers, businesses, and governments globally if competitive alternatives do not emerge.
Some major US technology companies are backing the case that American leadership means competing in the open ecosystem rather than withdrawing from it. The emerging response is therefore not simply to shut Chinese models out, but to compete with them in an open ecosystem.
Similarly, the strategic response for middle powers is not to choose between an American or Chinese AI ecosystem, but to preserve a plural one. That means investing in interoperable harness infrastructure that allows models from different sources to be substituted as circumstances change. It also means participating in the development of that infrastructure so that middle powers can help shape the standards, protocols and permissions governing how models connect to data, tools and other systems.
The objective is not to avoid models developed abroad, but to build an ecosystem in which dependence on any one foreign model or provider remains manageable.
It’s the Internet All Over Again
There’s a precedent for this situation: the open internet that is taken for granted was not inevitable. At critical moments in its development, organisations such as Mozilla fought to ensure that no single company controlled the gateway to the web, while open protocols and common standards allowed different browsers, websites and services to work together. Imagine the alternative: an internet whereby one or two companies control the rules through which everyone connects, where websites have to be designed around their technology, and where moving to a competitor means rebuilding most of what you had already created. The internet would be less competitive, less innovative and far less open to new entrants. Instead, common foundations allowed innovation to flourish, turning the internet into shared infrastructure for the global economy.
AI is approaching a similar inflection point. Open-source models are making powerful intelligence cheaper, more abundant and available to more people. But abundance alone does not determine who benefits: the use of hundreds of capable models being mediated by a handful of companies controlling the harnesses around them would be of little benefit to anyone. Much more preferable would be an ecosystem built on common, interoperable infrastructure, where models and agents can work together, businesses can compete across borders and countries retain meaningful choice over which intelligence they use and how it operates within their economies.
The standards and protocols of the harness are still taking shape, giving middle powers an opportunity to help build the common foundations of the AI economy rather than inherit them.
Don’t build the engine. Build the roads – and make sure everyone can drive on them.