Executive Summary
The focus on Artificial Intelligence (AI) models obscures vulnerabilities in data infrastructure, cloud services, rare earths, chips, and energy systems that support AI development. AI governance discussions focus heavily on models and algorithms. However, the growing dependence on cloud infrastructure, open-soure models, critical minerals, semiconductor manufacturing, and energy systems is creating new security vulnerabilities. Governments should view AI as a strategic infrastructure ecosystem rather than a solely software capability.
This draws on recent reports from July 2026 about China’s export restrictions on advanced AI models, training data, and chip designs, which signals that AI infrastructure is increasingly being treated as a strategic national asset. As well as discussions from the World Summit on the Information Society (WSIS) Forum 2026, that took place in Geneva in July, that demonstrated effective digital transformation relies on robust underlying infrastructure. The discussions particularly emphasized the African scenario of limited access to computing infrastructure and capacity.
Key Points
- AI relies on highly concentrated infrastructure and resource networks.
- Open-source AI ecosystems introduce new supply-chain attack vectors.
- AI supply-chain vulnerabilities span physical, digital, and geopolitical domains.
- Existing AI governance frameworks do not fully address infrastructure dependence.
- Economic security and AI policy are becoming increasingly interconnected.
Analysis
Most of today`s AI governance frameworks focus on scrutinizing models, their outputs, biases, alignment, and if the system is aligned with fundamental rights, while overlooking the infrastructure that produces them. Recent studies and reports, such as MITRE ATLAS and TrendAI, show that “the rapid adoption of open-source AI models exposes organizations to significant supply chain threats that often evade traditional security tools”. The studies present the digital security breaches in supply chain from using open-source AI models: training data, provenance, and contributors are often undisclosed, making backdoors introduced during training or fine-tuning difficult to detect through conventional tools like SBOMs or static code review. This makes it so that the automated tools of the supply chain are now one of the primary focuses for AI threats.
Nonetheless, in the light of WSIS: “a new reality is emerging. Increasingly, governments are recognising that the ability to govern AI depends not only on regulating algorithms but also on securing the infrastructure that makes them possible. Data centres, advanced semiconductors, cloud computing, electricity grids, submarine cables, digital public infrastructure, and skilled workforces have become as strategically important as the AI models themselves”. With this new reality in mind, the recent events of China’s export restrictions seems to be aligned with the expanding geopolitical tension around the essential minerals, rare earths and infrastructure necessary for the development of AI.
The significance of these new events is that they challenge the prevailing assumption that AI governance can be achieved primarily through model regulation. While oversight of algorithms remains important, the security, resilience, and accessibility of the infrastructure underpinning AI may ultimately determine which states and societies can effectively develop and benefit from these technologies. Failure to address infrastructure dependencies risks creating new forms of technological dependence, exacerbating global inequalities in AI access, and exposing critical systems to disruptions originating far outside the model layer. In practice, AI governance is increasingly becoming a question of infrastructure governance, economic security, and strategic resilience.
The African case illustrates this dispute: researchers and African governments disclose the limited access of the continent to the world’s share of AI compute and data centres capacity. African experts emphasized that the small share access of AI capability has forced many institutions and States to rely on infrastructure located abroad, increasing security risks and depending on global inequalities.
Policy Implications
- Governments should extend supply-chain security frameworks (e.g., the EU Cyber Resilience Act, NIST SSDF) to explicitly cover AI models as artifacts, not just code.
- Infrastructure, equally compute, chips, energy, submarine cables, should be treated as critical infrastructure subject to resilience and investment screening, not purely commercial policy.
- For under-resourced regions, international cooperation on compute access and data-centre investment is essential to prevent AI dependency from replicating prior resource-extraction dynamics.
References
VERMA, Ashish; PATEL, Deep. Exploiting Trust in Open-Source AI: The Hidden Supply Chain Risk No One Is Watching. Available at: https://www.trendaisecurity.com/en-us/resources-insights/deep-research/exploiting-trust-in-open-source-ai-the-hidden-supply-chain-risk-no-one-is-watching
BROOKS, Chuck. The Growing Cybersecurity Risks To The Supply Chain In The AI Era. Available at: https://www.forbes.com/sites/chuckbrooks/2026/05/22/the-growing-cybersecurity-risks-to-the-supply-chain-in-the-ai-era/
TANNA, Shivani. China considers tighter export controls on AI models and chips, FT reports. Available at: https://www.reuters.com/world/asia-pacific/china-considers-tighter-export-controls-ai-models-chips-ft-reports-2026-07-21/
MITRE ATLAS. AI Model Tampering via Supply Chain Attack. Availabe at: https://atlas.mitre.org/studies/AML.CS0028
MILIĆEVIĆ, Nenad. AI governance is becoming infrastructure governance. Available at: https://dig.watch/updates/ai-governance-infrastructure-governance
