Executive summary
- Access to frontier AI — the most advanced AI systems — is a prerequisite for Australia’s prosperity. If Australia’s AI capabilities are less sophisticated than its adversaries and competitors, it risks operating at a security disadvantage and conceding high-value industries and economic returns.
- Australia has not reckoned with its dependence on the United States for frontier AI access. Only the United States and China develop frontier AI; for Australia, that means structural dependence on the United States for the capability it needs. Australia treats ongoing access to the most capable models as a given and conflates the presence of data centres on its soil with sovereignty.
- Australia has no credible path to AI self-sufficiency. Building frontier models is out of reach without the necessary concentration of compute, talent and capital. And, scaling sovereign compute — data centres on Australian soil, owned and operated by domestic providers at the physical and cloud layer — to service all Australian inference needs would be inefficient and likely infeasible.
- Sovereignty, therefore, needs to be reconceptualised as managed dependence. Australia needs to move from accepting whatever access arrangements the market and the alliance deliver by default, to deliberate orientation toward securing two conditions for frontier AI access: unconditional capability parity with what the United States has access to domestically and reliable US provision of domestic inference capability for sensitive deployments.
- To achieve managed dependence, Australia should proactively secure favourable AI access terms and defensively deter their erosion. Proactively, Australia should negotiate a three-layered framework with the US Government, US labs with the most advanced models and US data centre providers. Defensively, the entanglement created by this framework raises the political cost of disrupting access.
- Targeted investment in key assets would provide Australia with cooperative leverage in negotiations. Critical minerals, compute infrastructure and assurance capabilities each occupy a key node in the AI supply chain that the United States values and where there is friction in substitution. None of these assets currently deliver the leverage Australia needs, but each has a specific pathway that targeted investment could unlock.
This report examines Australia’s access to frontier AI:the most capable models, and the compute needed to run them. It asks what Australia’s reliance on the United States means for its security and prosperity, and what strategy follows from takingthat dependence seriously.
Policy recommendations
- Build the institutional architecture for managed AI dependence through negotiating formal access commitments:
- Finalise negotiations of the US-Australia Technology Prosperity Deal as a strong political signal that Australia is a priority AI partner.
- Negotiate Memoranda of Understanding with leading US labs that commit to frontier AI access terms.
- Condition the United States’ data centre buildout in Australia on inference access commitments through the forthcoming Australian Standards for AI.
- Strengthen Australia’s negotiating position by converting assets into cooperative leverage:
- Secure a primary position in ex-China supply of processed gallium through enabling a second phase of Australia’s gallium program at Pinjarra.
- Capitalise on Australia’s differentiated position as a close US ally with abundant land and energy resources to host compute infrastructure for training US frontier models.
- Scope the mission of the Australian AI Safety Institute narrowly on national security evaluations situated in intelligence assessments of adversary capabilities. A broad mandate replicates functions the United States can source elsewhere; a narrow scope focuses limited resources on Australia’s comparative advantage.
Introduction
Nations that deploy new technologies grow faster and defend themselves better. Artificial Intelligence (AI) is on track to be among the most consequential technologies, amplifying existing capacity and accelerating innovation in the countries that deploy it well, and widening the wealth divide for those who fall behind.
Australia’s ability to capture AI’s potential relies on access to frontier AI — the most advanced AI systems — to match the capability deployed by competitors; a sub-frontier model that would be sufficient to perform a task in isolation falls short when others field stronger systems. In the national security domain, hostile actors will exploit the most capable systems available for use in cyberattacks, chemical, biological, radiological and nuclear (CBRN) weapon development and as a force multiplier in military operations. If Australia’s AI capabilities are less sophisticated than its adversaries’, it will be operating at a security disadvantage. Project Glasswing, Anthropic’s managed-access arrangement for its Mythos Preview model,1 demonstrates this: Australian organisations were not in the first wave of access to the most cyber-capable model, and no sub-frontier model would be sufficient to patch vulnerabilities should the capability proliferate. The economic stakes are the same: in high-value sectors where competitive outcomes depend on reasoning, pattern detection or complex scientific discovery, deploying sub-frontier tools concedes economic returns to those running more capable systems.
Yet, frontier AI is concentrated in general-purpose large language models developed in two countries. In 2024, the United States and China released 73 cutting-edge AI models between them, while the rest of the world combined produced only 13.2 And, every model at the true frontier of capability was developed in the United States, with Chinese capability trailing by months.3 The United States and China also host around 90% of global supercomputing capacity.4
Australia needs to orient its AI strategy toward securing ongoing access to frontier AI on terms that advance its national interest.
This concentration means that Australia is reliant on foreign-developed frontier AI models and on foreign-owned compute — the specialised processing hardware required to train and run them — for its national security and economic prosperity. For Australia, China is not a realistic source: geopolitical alignment and security concerns effectively foreclose that option for the national security and economic deployments that matter most.
Australia’s dependence on the United States is therefore not a policy choice but a structural reality. However, this dependence should not be naive, but deliberately managed: Australia needs to orient its AI strategy toward securing ongoing access to frontier AI on terms that advance its national interest.
This report makes that case by addressing four themes:
- Australia has not reckoned with its dependence on the United States for frontier AI
- Re-thinking ‘AI sovereignty’: Australia cannot build its way to self-sufficiency
- Managed dependence: Building the institutional architecture to secure frontier AI access
- The assets that give Australia real bargaining power
Australia has not reckoned with its dependence on the United States for frontier AI
The Australian Government has catalysed investment commitments that could scale to more than A$100 billion in data centre infrastructure;5 its National AI Plan is ambitious on AI adoption, focusing on scaling uptake across industry and the public sector;6 and in July 2026 Prime Minister Anthony Albanese announced a set of mandatory Australian Standards for AI and established an Office of AI within his department.7 However, Australia’s approach does not address vulnerabilities at the development layer; it treats ongoing access to frontier AI models as a given and conflates US-owned data centres in Australia with sovereignty.
Model access
Australia is dependent on the United States for frontier model access. For most deployments, Australia accesses closed-weight models remotely. That is, the US developer or cloud provider does not release the model weights (the trained parameters that constitute the model), and so retains the ability to restrict or condition access. There is a degree of protection against sudden access revocation in cases where Australia holds weights on-premises, either through downloading and running open-weight models (models where the weights are publicly released) or through physical transfer of closed-weight models into classified environments. However, neither option fully resolves the dependency. For open-weight models, not only do they trail the frontier, but Australia would be dependent on developers continuing to release capable open-weight models. And as geopolitical competition intensifies, developers may have limited incentive to give away their most powerful systems, meaning great powers may restrict releases to preserve advantage. On-premises closed-weight models also carry dependency as each new model version requires renewed access and transfer. Transferred weights are a depreciating asset; without guaranteed access to updates, Australia will fall progressively further behind as the frontier advances.
Australia’s dependency on the United States for model access is exposed at both the company and government level. At the company level, the major AI labs remain young, fast-moving companies whose product offerings, market strategies and safety policies are still in flux. As companies refine their commercial strategies, they could restrict model access through acceptable use policies, price increases once lock-in is established or simply decline to make their most capable models available in the Australian market. This risk is compounded by growing compute constraints, which may lead companies to deprioritise Australia in favour of larger markets when releasing their most advanced, inference-intensive models. Current good terms for model access should therefore not be taken as durable: Australia is currently operating in a buyer’s market, but commercial maturation and inference scarcity mean that dynamic is unlikely to last.
Current good terms for model access should therefore not be taken as durable: Australia is currently operating in a buyer’s market, but commercial maturation and inference scarcity mean that dynamic is unlikely to last.
Additionally, beyond commercial considerations, frontier AI companies have begun tiering access to their most capable models. Anthropic withheld its Mythos Preview model from general release, with initial access restricted through Project Glasswing to the US Government and a handful of mostly US firms, with Australian organisations admitted only in subsequent expansions.8 OpenAI similarly limited its GPT-5.5-Cyber model to vetted users through its Daybreak initiative.9 These examples demonstrate that unfettered access to the most capable models is ending, and that Australia, like other countries, is now liable to be excluded from the first wave of access.
At the government level, the United States can restrict Australia’s access to frontier models through both formal export controls and informal pressure on US developers. The June 2026 directive suspending access to Anthropic’s Fable 5 and Mythos 5 for all foreign nationals is the clearest demonstration: it confirms that the United States will use export controls to differentiate access by nationality.10 While the result was Anthropic suspending all access, including to Americans, this shows that the United States has the legal standing and the political will to tier access for all countries below what it accesses domestically. While this directive was a response to a specific national security concern, Australia should not rule out future scenarios where US export controls or predeployment review11 could be exercised for political or strategic ends, even where doing so would carry economic or diplomatic costs. Further, the US Government has demonstrated a willingness to use coercive tools against its own frontier AI companies,12 suggesting that informal pressure on developers’ licensing and market decisions cannot be ruled out. Australia’s exposure at the government level is therefore no longer hypothetical: the United States has both the mechanisms to restrict frontier access and the demonstrated willingness to use them.
Inference infrastructure
Even if Australia never trains a frontier model, it still needs the compute to run models to answer queries. This is inference: each time a user sends a prompt to a model, that request is processed on physical hardware. However, Australia’s inference infrastructure reflects the same pattern of dependency as model access. The majority of data centre investment in Australia is from US hyperscalers — the largest global cloud providers, like Microsoft, Google and Amazon Web Services (AWS) — building and operating their own facilities on Australian soil. The buildings are in Australia, but the chips and cloud services are controlled by US companies. Where the government points to security-accredited deployments, Australia remains dependent: government accreditation adds data security requirements and personnel clearances, but the underlying compute remains US-controlled. For example, the GovAI platform that serves government agencies runs on AWS and Microsoft Azure,13 and the A$2 billion Top Secret platform expected to be operational in 2027, will be operated by AWS.14 So while these domestic facilities meet Australia’s data isolation and security requirements, the underlying compute, chips and operational decisions are owned by US hyperscalers. Even where Australian companies are in the mix, the reality is less sovereign than the branding suggests: NEXTDC’s A$7 billion partnership with OpenAI pairs an Australian-owned facility with OpenAI models served through Microsoft Azure infrastructure, meaning the building layer is addressed but not the control layer.15 A small number of Australian compute providers exist — including, AUCloud, Vault Cloud — but they operate at a fraction of hyperscaler scale, none currently host frontier models and all remain dependent on imported US chips.

This exposes Australia to risks through US jurisdictional reach, capacity constraints and provider concentration. US-operated data centres, even outside the United States, give the US Government “jurisdictional hooks,” which could be used to direct US cloud providers to constrain or condition access to compute already deployed in Australia.16 Contractual protections and Australia’s own jurisdiction over the provider’s Australian operations offer real means to push back on US government direction, but where there are overlapping jurisdictions there is no guarantee Australia would prevail. Further, as AI is embedded into economies globally and demand for inference compute grows exponentially, Australia is dependent not just on existing infrastructure but also on providers’ ongoing willingness to invest in and upgrade local capacity. As for model access, when global demand for compute inputs outstrips supply, US companies may face pressure to allocate chips to US customers at the cost of foreign demand, or choose to serve their largest and most profitable markets first. These risks are compounded by lack of provider diversification: concentration of dependency on a few US hyperscalers leaves no alternatives if these risks materialise. The most acute example of this is that Australia has already committed its Top Secret cloud infrastructure to a single US provider, AWS,17 with no alternative platform in place at that classification, which means that if the terms of the relationship with AWS deteriorate, there is no readily available fallback.
Re-thinking ‘AI sovereignty’: Australia cannot build its way to self-sufficiency
The instinctive response to this dependence is to pursue autonomy; if Australia is structurally reliant on the United States, building Australia’s own AI capabilities must be the answer, either through full development of AI models and infrastructure or scaling sovereign compute. But Australia cannot build its way out of dependency on the United States.
The most detailed Australian articulation of the sovereignty-by-building case proposes A$4.5–5 billion over five years for government-owned ‘AI factories’ to develop domestic AI capabilities.18 But for Australia, developing frontier AI models is unrealistic. Frontier development depends on compute, talent and capital, with one estimate placing the cost at around US$500 billion,19 and Australia does not have the necessary concentration of these inputs to mount a viable attempt. It lacks capital at the scale available in the United States; compute is increasingly constrained and US-controlled; and while talent is the most policy-correctable of the three inputs, Australia’s strength lies in research rather than the commercialisation layer.20 These shortfalls are compounded by a moving target: as the United States continues to advance, the frontier is moving further out of reach. France and Canada illustrate the problem. Both have invested heavily in national champions Mistral and Cohere, yet both are falling further behind the frontier and pivoting toward enterprise provision. Even at A$5 billion, Australia would buy sub-frontier capability at best, which answers no strategic need: where frontier access is restricted, a lagging model is too far behind to substitute, and where access is open, importing is cheaper than building.
An alternate response is to bypass the current trajectory by investing in an alternate technical paradigm, on the expectation that a different architecture could deliver Australia capability parity while bypassing the capital-intensive race for compute.21 In other words, rather than competing on the current terms, Australia would bet on a fundamentally different way of building AI that does not require the vast quantities of compute the frontier labs depend on. However, this approach misreads the economics of AI, as even a genuinely novel paradigm would likely benefit from the compounding returns of compute, talent and infrastructure. More fundamentally, this approach also misjudges the required urgency: many leading experts consider near-term transformative AI to be likely.22 By the time any alternate paradigm matured, the economic and national security advantages afforded by frontier access may have already accrued to those with access, and Australia would have forgone the very gains that could have resourced an alternate effort.
On compute, if foreign-controlled data centres on Australian soil retain dependency on the United States, the logical response is to invest in sovereign compute — data centres on Australian soil, owned and operated by domestic providers at both the physical infrastructure and cloud layer. But scaling sovereign compute to service all Australian inference needs would be inefficient and likely infeasible; it is a moving target with very high and largely untracked costs that almost no middle power is likely to achieve.23 Australia’s capital position compounds the difficulty: it has minimal private capital, and its Future Fund and superannuation funds are commercially constrained, directed toward high-return investments in ways that make prioritising sovereignty politically challenging.24
Further, even where sovereign compute is built, Australia remains dependent on US-designed chips. Scaling sovereign compute would not eliminate Australia’s reliance on the United States but swap dependency on a US cloud provider for dependency on a US chip supplier, retaining the underlying exposure while forgoing the cost efficiencies of the US full-stack export deal.
Given the challenges in scaling sovereign compute and the inevitable dependency on US-designed chips, it is sensible to accept that the majority of Australia’s inference will be provided by US-controlled hyperscalers. For the vast majority of inference needs, where latency and data sovereignty considerations are relatively unimportant, Australia should pursue whatever is most economically robust, whether domestic or US-owned. For sensitive commercial or government deployments, domestic inference with appropriate security infrastructure is necessary. But the smaller scale does not change the sovereignty argument; Australia remains dependent on US-designed chips whether building at scale or for sensitive deployments alone.
Managed dependence: Building the institutional architecture to secure frontier AI access
If there are no credible paths to self-sufficiency, dependence on the United States is not a policy choice but a structural reality. While this dependence may be uncomfortable, it is not optional. But dependence need not be naive. Sovereignty, properly understood, is not about chasing self-sufficiency but about ensuring that dependence does not become a vulnerability that can be exploited. The strategic task is to move from passive dependence, in which Australia accepts whatever access arrangements the market and the alliance deliver by default, to managed dependence, in which securing favourable terms of frontier AI access becomes an explicit objective of Australia’s AI strategy.25
Sovereignty, properly understood, is not about chasing self-sufficiency but about ensuring that dependence does not become a vulnerability that can be exploited.
Australia’s AI strategy should therefore be organised around the core objective of securing good access terms for frontier AI. In this context, access comprises two conditions:
- Access to the most capable frontier AI models, without restriction and at capability parity with what the United States has access to domestically.
- Reliable US provision of the domestic inference capability required for sensitive deployments, including the specialised infrastructure needed for government applications.
A three-layered access negotiation
Managed dependence cannot stop at defining what Australia needs; it must be operationalised, requiring Australia to deploy its assets strategically to secure favourable arrangements before any disruption materialises and to create entanglement that raises the cost of withdrawing access.
Proactively, the objective is to move Australia from ad hoc commercial relationships into longer-term frameworks that embed commitments on access. Leverage operates at two stages. First, to get Australia to the negotiating table; without strategic assets that the United States values, there is no basis for negotiation. The October 2025 Trump-Albanese White House meeting illustrates this. The commitment to develop a bilateral Technology Prosperity Deal (TPD) — a framework for cooperation on critical and emerging technology like the United States has with the United Kingdom, Japan and the Republic of Korea — was bundled alongside a critical minerals framework and reaffirmation of defence cooperation under AUKUS.26 This suggests that Australia’s entry into technology negotiations was predicated on its broader value in supply chains and defence. The second stage is to deploy leverage to secure favourable terms once Australia is at the negotiating table. Australia’s leverage at this stage determines whether the arrangements deliver genuine access commitments or amount to market access for US firms dressed up as strategic cooperation.
At this second stage, Australia should negotiate with the United States across three layers:27
1. Government-to-government agreements: Providing political commitment
Australia and the United States have already committed to develop a TPD. The United States has signed similar deals with the United Kingdom, Japan and the Republic of Korea, using a boilerplate template. However, the differences between TPDs offer lessons: the US-UK TPD was made contingent on progress on unrelated trade issues, allowing the United States to suspend the TPD punitively. Australia should insist that its TPD is standalone and not conditional on unrelated negotiations. Australia should also press for the TPD to do more than default to generic language on technology cooperation, but name frontier AI access as a bilateral priority and recognise Australia as a trusted destination exempt from export controls on frontier AI models. There is precedent for this: under AUKUS, the United States certified Australia’s export control system as comparable to its own, making Australia eligible for licence-free defence trade.28 The same basis of trust could place Australia inside the US export control perimeter for frontier AI models, recognising Australia as a trusted security partner whose access poses no risk of capabilities reaching adversaries.
2. Government-to-lab: Model access for government and conditions for the market
These agreements need to serve two functions. First, secure government-specific provision: model access at full capability parity with US domestic deployments, including timely access to new releases, availability on classified infrastructure and no unreasonable use restrictions. Second, set framework conditions for the broader Australian market, so that Australian customers are not treated as lower-priority than US ones on capability access, timely releases or pricing. This establishes the baseline on which commercial relationships between Australian businesses and frontier labs can operate. Australia recently signed its first Memorandum of Understanding (MoU) with an AI lab — Anthropic — which covers safety collaboration, economic data sharing and forecasting infrastructure needs.29 The United Kingdom has similar MoUs with three frontier labs — Anthropic, Google DeepMind and OpenAI — which are stronger in that each commits the lab to deploying AI capability within government.30 But even the UK agreements only partially address secure-government AI provision and do not address conditions for the broader market. Australia should build on the foundation of the Anthropic MoU to negotiate stronger agreements with all three frontier labs across both functions.
3. Domestic inference provision: Trading favourable investment conditions for terms
Domestic inference provision should be an exchange where Australia offers favourable investment conditions, and hyperscalers commit to terms on capacity, continuity and pricing. Australia controls the factors that make it an attractive destination for hyperscaler investment: access to land and energy, and the enabling environment through stable planning approvals and regulations. Australia’s recently released Expectations of data centres and AI infrastructure developers demonstrate the government is already using the approvals process to condition hyperscaler investment, but the Expectations do not yet extend to commitments on capacity, continuity or pricing for sensitive deployments.31 Australia recently signed an MoU with Microsoft, the first hyperscaler to formally align with the Expectations alongside commitments on continued investment in AI and cloud capability.32 Australia should build on this foundation to condition investment against access risks for domestic inference.
The proactive framework does double duty: it secures terms, but it also creates entanglement that makes disrupting those terms costly. Withdrawing technology access from a partner whose strategic value you have publicly affirmed carries a political cost that a private company cancelling a procurement contract does not. Government-to-government agreements, firm-level commitments and hyperscaler infrastructure on Australian soil all create friction against erosion — together they represent a visible, public integration that is politically costly to dismantle.
The assets that give Australia real bargaining power
Whether managed dependence can deliver favourable access terms depends on the strength of Australia’s assets. A signed agreement is only as durable as the interest sustaining it; what makes access commitments hold is Australia occupying a position in the AI supply chain that the United States would damage by withdrawing from. Therefore, an assessment of assets serves two purposes: evaluating the strength of Australia’s current negotiating hand and identifying where investment would generate the most leverage.
Assets generate leverage in negotiation by occupying a key node in the AI supply chain where they are:
- Critical to the stack: Australia supplies an asset that the United States values and that creates a binding bottleneck if removed; other parts of the chain cannot function without it.
- Resistant to substitution: Australia’s position is durable; the United States cannot innovate the dependency away by redesigning the stack to eliminate the need for the asset.
- Scarce: Australia is the sole or primary source of the asset. Current scarcity requires the United States to have few viable alternative sources, and future scarcity requires structural advantage such that the United States cannot readily diversify or onshore.
For non-allies, or those pursuing strategic hedging, by keeping options open between the United States and China, leverage would also demand a fourth condition — credible restriction — where the middle power could threaten to withhold the asset. However, for a close ally like Australia, credible restriction is not just unnecessary but incoherent. Australia’s assets derive their strategic value from being embedded in the US relationship, and a threat to withhold them would undermine the very conditions that make them valuable.
Instead, Australia applies cooperative leverage, where bargaining power flows from indispensability rather than threat. Real bargaining force, absent credible restriction, is achieved through trust. For a less aligned partner, the United States must hedge against future unreliability and account for active diversification efforts. Whereas, for Australia, that strategic discounting neither applies to what Australia offers the United States nor to what the United States is prepared to commit to Australia on frontier AI access in turn. The cost of accepting Australia’s offerings is already resolved given existing close alignment; and as Australia increases its position at key nodes of the US-led AI supply chain, the more it is in the United States’ interests to extend capability to a partner actively building the allied stack.
The same strategic indispensability underpins the US-Australia defence relationship. Over decades, Australia has embedded itself at the centre of US strategy in the Indo-Pacific, and the United States has responded with sustained investment in Australia’s defence capability. AUKUS is the most consequential example. Australia has access to US frontier defence technology not because it threatened to withhold its defence assets — hosting of US forces, intelligence sharing and military interoperability — but because the relationship rests on trust and mutual strategic indispensability.
Australia needs to extend this to its strategy for frontier AI access through investing in assets that generate strategic indispensability in the AI supply chain. Three assets are most promising: critical minerals, which sit at the base of the AI hardware stack; compute infrastructure, where Australia could host capacity the United States needs; and assurance, where Australia could differentiate itself by specialising in national security evaluations. Each is assessed below against the three conditions for cooperative leverage.
Critical minerals
Critical minerals form the base of the AI hardware stack: rare earth elements for magnets and coolants in data centre equipment; gallium and germanium for semiconductor fabrication; and lithium for batteries and energy storage. There are no near-term engineering workarounds supporting substitution at scale. The United States cannot meet the demand domestically. It is fully import-dependent for 12 critical minerals and reliant on imports for more than half of its consumption of an additional 28.33
However, the critical input is processed materials, not raw ore. Transforming ore into usable manufacturing inputs requires complex chemical processes and specialised equipment. The resulting high-purity chemicals — integrated supply, where mining and refining are both ex-China — is what the United States is seeking from its allies.
Scarcity of processed critical minerals is real, compounded by Chinese dominance. China controls approximately 90% of rare earths processing,34 98% of gallium production35 and 60% of lithium refinement.36 Against this picture of Chinese dominance and given the trajectory of US-China technology competition, scarcity must be assessed against ex-China (without China) supply, not global supply.
Australia’s leverage therefore lies in how its ex-China critical minerals supply can protect the US-led technology stack against two distinct threat vectors. The first is Chinese price flooding. China uses its dominant processing position to suppress global prices below the cost of operation for ex-China facilities, undermining the processing capacity that the US-allied stack depends on.37 The second is Chinese export controls. China has demonstrated that it will weaponise critical mineral supply chains, banning exports of gallium in December 2024, and expanding export controls on critical minerals in October 2025.38
Australia is positioned to respond to both scenarios. Against price flooding, the price floor mechanism in Australia’s Critical Minerals Strategic Reserve is designed to provide guaranteed offtake to keep specific Australian processing facilities commercially viable under sustained Chinese pressure. Against export controls, in addition to providing a significant ongoing share of ex-China supply, Australia’s Strategic Reserve will allow it to purchase uncontracted volumes of critical minerals and direct them to allied customers.
How much weight Australia carries in both scenarios — and therefore its leverage — depends on Australia having a primary proportion of ex-China processed supply:
Nd/Pr is currently the only critical mineral where Australia’s projected position is scarce enough within ex-China supply to negotiate from a position of cooperative leverage. Gallium could reach that threshold if Australia’s program is expanded to include a second refinement facility at Pinjarra.
Application to the three-layered access negotiation: Australia’s critical minerals position operates at the government-to-government layer of the negotiating framework, in Australia’s TPD negotiation with the United States. Australia’s critical mineral reserve is the asset that got Australia to the negotiating table and gives it standing to demand favourable AI access terms once there. Defensively, the US Government’s public investment in Australian critical minerals supply chains affirms Australia as a strategic partner whose value the United States has publicly committed to, raising the political cost of simultaneously eroding its AI access terms.
Compute infrastructure
Through the lens of sovereignty as self-sufficiency, scaling domestically controlled sovereign compute is futile. However, hosting US-owned data centres on Australian soil may offer a source of strategic leverage in negotiations to secure frontier AI access.
Compute infrastructure is critical to the AI supply chain with large-scale data centres required for frontier model training and inference. Compute cannot be substituted out of the stack — algorithmic improvements have made models more efficient, but efficiency gains have not reduced total compute demand. Instead, the compute required for frontier training doubles approximately every six months,45 and inference-time scaling means each query now consumes more compute.
Energy availability is becoming the critical bottleneck to meeting this growing demand with global data centre electricity consumption projected to more than double by 2030.46 In the United States, this constraint is already felt acutely. For example, grid connection wait times in Virginia are already at four to seven years.47 Given energy constraints, the United States will need to look abroad to scale compute at the rate needed to maintain leadership at the frontier.
At current ambition — to be an inference hub for the Asia-Pacific — Australia’s compute position is not scarce. US hyperscaler investment in the Asia-Pacific is not concentrated in one primary regional hub, but diffused across India (disclosed commitments totalling approximately US$36.2 billion),48 Japan (US$18.1 billion)49 and Australia (US$16.5 billion).50 Singapore, Malaysia, Indonesia and Thailand are also hosting substantial infrastructure.51 Within this picture, Australia is a significant but non-dominant player.
However, Australia’s differentiated position as a close US ally with abundant land and energy resources creates a more ambitious opportunity: hosting compute on which US frontier models are trained.52
Australia’s differentiated position as a close US ally with abundant land and energy resources creates a more ambitious opportunity: hosting compute on which US frontier models are trained.
Hosting compute for AI training runs — the extended computation through which a new model is built — requires the United States to extend a deeper level of trust than for inference. Novel capabilities with dual-use potential can emerge during training runs, requiring the United States to have confidence that the host country’s security settings protect against adversary targeting, and that it will not exercise its jurisdiction over the infrastructure against US interests. On security settings, both Australia and the United States designate data centres as critical infrastructure, but while US security expectations are largely voluntary, Australia imposes statutory obligations on operators, including mandatory incident reporting and government intervention in serious incidents.53 Critical 5 — the Five Eyes forum for sharing practices on critical infrastructure protection — means standards have developed against a common baseline.54 Therefore, a US company hosting compute in Australia does so under security obligations that are, if anything, more stringent than those domestically. Furthermore, Australia’s track record shows it will not exploit a privileged position against US interests. Pine Gap demonstrates the United States has already trusted Australia to host its most sensitive infrastructure. Five Eyes architecture means security threats to hosted data centres can be shared and assessed at classified levels. And, under AUKUS, the United States formally certified that Australia’s export control system is comparable to its own. No other country outside the Five Eyes has the same basis of trust with the United States as Australia.
However, trust alone is not sufficient: hosting training-scale compute also requires abundant land and energy. Time to power — how quickly a new data centre is connected to reliable electricity — is the primary criterion US companies are applying when selecting where to build.55 Australia’s land availability and renewable energy resources position it well. Australia has some of the highest solar radiation per square metre globally, making large-scale solar and battery storage viable at the volumes data centre clusters require. Australia also has available land to site infrastructure away from constrained urban grids.56 Of the other Five Eyes partners, the United Kingdom faces high electricity costs and land constraints, and New Zealand has limited energy generation capacity, leaving both unable to support training-scale data centre development. Canada is Australia’s closest comparator with available land and substantial renewable capacity, primarily hydro.
Cooperative leverage will therefore flow to whichever country establishes itself as a training hub first. The investment required is so large and replacement so costly that early commitments lock in the AI ecosystem for decades. Australia must move before those commitments are made elsewhere.
Application to the three-layered access negotiation: Hosting frontier training compute would give Australia leverage across all three layers of the proactive negotiation with the United States. At the government-to-government layer, political recognition of Australia as a trusted host of overseas training capacity in the TPD would underwrite investment decisions. At the second government-to-lab layer, hosting frontier training compute is the asset that would give Australia real leverage in MoU negotiations, allowing Australia to demand stronger access commitments that other countries have been unable to secure. At the third layer, where Australia is seeking to trade favourable investment conditions for access terms, providing compute infrastructure for frontier training is a more valuable offer to hyperscalers. This means the planning approvals and grid access conditions Australia controls are correspondingly more valuable, and conditioning those on commitments on capacity, continuity and pricing would convert a gatekeeping role into guaranteed access terms.
Defensively, training infrastructure creates entanglement: a US company that has made the commitment to having expensive and scarce compute hardware installed on Australian soil cannot easily withdraw it.
Assurance
Evaluation of frontier AI models is not a peripheral governance function; it is a critical component of the AI supply chain and cannot be substituted without unacceptable risk. The US Government has a direct interest in ensuring its frontier models do not carry serious national security risks before they proliferate, recognising the need for classified evaluations of advanced AI models’ capacity to generate or exacerbate cyber risks and chemical and biological threats.57
Government-level capacity for frontier AI evaluation has expanded significantly since the UK AI Security Institute (UK AISI) was established in 2023 and no longer represents a scarce capability. The International Network for Advanced AI Measurement, Evaluation and Science (the Network; formally named the Network of AISIs) now comprises 10 governments,58 and commercial capacity is also growing; in 2024, UK assurance firms generated approximately £1 billion in revenue, a market projected to exceed £6.5 billion by 2035.59
The Australian AI Safety Institute (Australian AISI) enters a landscape already populated by established institutions with more resources: the UK AISI is operating with £66 million annually (A$132 million),60 and Canada C$10 million (A$11 million),61 compared to Australia’s A$7.5 million per year over the forward estimates.62
However, within a more classified tier of assurance, Australia’s position is scarce. US demand for evaluation — and therefore leverage potential — is concentrated in the national security sphere: the US AI Action Plan directs evaluation of frontier models for cyber and CBRN risks to its Center for AI Standards and Innovation (CAISI), working with US national security agencies and frontier developers.63 Five Eyes provides the trust infrastructure and interoperability with US systems that any allied role in this national security evaluation would require; no amount of investment in technical capacity replicates it.
Five Eyes provides the trust infrastructure and interoperability with US systems that any allied role in this national security evaluation would require; no amount of investment in technical capacity replicates it.
Within the pool of Five Eyes partners, Australia brings distinctive assets, particularly in cyber. The Australian Signals Directorate’s REDSPICE program — launched in 2022 to significantly increase Australia’s cyber capabilities by A$9.9 billion over ten years — has built offensive and defensive cyber capability at scale with explicit AI integration.64 The skills developed are structurally analogous to those required for cyber evaluations of frontier models. Critically, REDSPICE does not operate exclusively at top-secret classification, with deliberate restructuring of physical infrastructure and employment pathways to enable meaningful work at lower classifications. This makes it a more accessible collaboration partner for AISI evaluation functions than a traditional signals intelligence team.65
National security evaluation of US frontier models does not occur in a vacuum; it sits within a broader ecosystem of AISI technical analysis and intelligence assessments. There is an unrealised opportunity for Five Eyes partners to capitalise on their existing architecture for AI security cooperation. Australia could instigate and lead a Five Eyes AI security workstream, convening Five Eyes Network members to jointly evaluate the cyber risks of major open source models; building shared threat understanding among national security communities; and integrating Network technical assessments with intelligence analysis. Australia is well-placed to differentiate itself as the convenor: its Indo-Pacific positioning, deep China expertise and unique economic exposure and integration into Southeast Asia give Australia a vantage point no other Five Eyes partner holds. However, the window is time-limited as the United States could internalise the function or another Five Eyes partner could move first.
Application to the three-layered access negotiation: A differentiated assurance position prioritising national security evaluation, would operate across two layers of the proactive negotiating framework. The leverage is strongest at the government-to-government layer, where positioning itself as the Five Eyes convener on AI security would strengthen Australia’s overall negotiating hand; it adds to Australia’s credibility and value as a partner on AI. At the government-to-firm layer, Australia can leverage access commitments by providing frontier labs with national security evaluation capability they cannot conduct themselves. At both layers, Australia should push for national security evaluation to be named explicitly in the relevant texts: in the TPD as a bilateral priority, and in MoUs with labs as a joint commitment.
Policy recommendations
- Build the institutional architecture for managed dependence on the United States for frontier AI access through negotiating formal access commitments with the US Government, frontier AI labs and hyperscalers.
- Finalise negotiations of the US-Australia Technology Prosperity Deal (TPD) as a strong political signal that Australia is a priority AI partner: Australia should ensure the deal is standalone and not conditional on unrelated negotiations, and that it recognises Australia as exempt from US export controls on frontier AI models, placing it inside the US export control perimeter on the same comparability basis established under AUKUS. Australia should also ensure the text names its differentiated position across the allied AI supply chain — in critical minerals, compute infrastructure and assurance — framing this as a partnership of mutual strategic value rather than one-way technology dependency.
- Negotiate Memoranda of Understanding (MoUs) with US frontier labs that commit to frontier AI access terms: Australia should secure government-specific provision — capability parity, timely releases, on-premises classified infrastructure hosting — and set the baseline for Australian commercial customers on model parity access and through establishing a price ceiling. MoUs should include a joint commitment to national security evaluation of frontier models, reflecting what Australia brings to the partnership.
- Condition hyperscaler infrastructure buildout in Australia on inference access commitments: As the Expectations of data centres and AI infrastructure developers are absorbed into the mandatory Australian Standards for AI, extend the conditions on planning approvals and grid access to include commitments on capacity, continuity and pricing for sensitive government and commercial deployments.
- Strengthen Australia’s negotiating position by converting underleveraged assets in critical minerals, compute infrastructure and assurance into cooperative leverage.
- Secure a primary position in ex-China supply of processed gallium through enabling a second phase of Australia’s gallium program at Pinjarra: Through the confirmed Wagerup facility, Australia is projected to supply 32% of ex-China processed gallium, significant but below the threshold for leverage. Expansion to a second phase at Pinjarra — Alcoa’s other alumina refinery — would increase Australia’s share to 55%, giving Australia a primary position. The immediate action is to prioritise the Huntly mine approval, which would secure multi-decade feedstock supply to Pinjarra, the necessary precondition for gallium extraction at this site. Both the Western Australian and federal Environment Ministers have decision-making authority and can act on national security grounds; the Australian Government should make clear at the highest levels that this approval is a strategic priority. In parallel, Australia should engage the same trilateral grouping that backed Wagerup — Alcoa on the commercial side and the US and Japanese governments — to present the strategic case for a second phase at Pinjarra. Australia should publicly commit to conditional co-investment under the Critical Minerals Facility, providing political support ahead of feasibility completion and final investment decision. While there is a nascent pathway to gallium production through zinc byproduct, this remains at R&D stage and is not positioned to contribute to ex-China supply on AI-relevant timescales,66 making Pinjarra the most expedient pathway to increased leverage.
- Capitalise on Australia’s differentiated position as a close US ally with abundant land and energy resources to host compute infrastructure for training US frontier models: Hosting training-scale compute would position Australia as a critical node in the AI supply chain, conferring leverage that inference hosting alone cannot. The investment required is so large and replacement so costly that early commitments lock in the AI ecosystem for decades. Australia must move before those commitments are made elsewhere. The first step is securing US political support through the TPD, naming Australia as a trusted host for overseas training capacity. With bilateral backing in place, Australia should treat training-scale facilities as a distinct class within the Australian Standards for AI and establish a dedicated framework that provides a fast and predictable pathway for investment. This should include security conditions aligned with Australian critical infrastructure obligations and foreign investment screening scoped narrowly to qualifying training facilities, making it both politically defensible and targeted. The framework should be developed in coordination with US counterparts so that Australian facilities can be treated as pre-certified trusted hosts rather than requiring case-by-case assessment. An important second step is negotiating bespoke copyright arrangements to enable AI training on Australian content. Designing the right copyright scheme is outside the scope of this report; however, it would allow AI training to be conducted in Australia with greater legal certainty.
- Scope the mission of the Australian AI Safety Institute (AISI) narrowly on national security evaluations situated in intelligence assessments of adversary capabilities: Rather than pursuing a broad mandate spanning whole-of-government coordination and regulatory support — functions that replicate what established institutions and the newly announced Office of AI already cover — the Australian AISI should define its value-add to the international assurance ecosystem narrowly: prioritising national security evaluation capability and seizing the convening role among Five Eyes evaluation institutes for joint evaluation of adversary AI models.
Annex A: Critical minerals supply projections
The tables below set out projected supply of processed critical minerals from outside China — 2030 for lithium and rare earths, 2028–29 for gallium. Output is given in tonnes per annum (tpa). These are projections, not current production. Table 2 draws on IEA projections of national lithium refining output from existing and announced projects. Tables 2 to 4 are built from named facilities: each figure combines a plant’s nameplate capacity — the maximum annual output it is designed to produce — with its commissioning timeline, the date its operator has announced it will begin production. Both rest on the same assumption: that announced projects are built as planned, come online on schedule and run at full design capacity. Projects that are delayed, scaled back or abandoned would lower these totals; facilities not yet announced could raise them.
While Australia is projected to be the fourth-largest single Lithium supplier at ~14%, ex-China supply is dominated by Chile and Argentina with a combined total of ~62%.
Chinese supply is projected to be ~91% of global supply in 2030.68 Of the thin ex-China supply, Australia is the largest single source of Dy/Tb at ~40% of quantified supply, and more once Lynas Malaysia’s undisclosed output is counted.
i. Percentages are calculated on quantified suppliers only (~1,890 tpa combined) and exclude Lynas, whose Dy/Tb output is not publicly disclosed. Arafura’s Nolans project will produce a further ~28 tpa Dy and ~8 tpa Tb contained within a mixed SEG/HRE oxide product, excluded here as it is not separated oxide.
Chinese supply is projected to be 60-70% of global supply in 2030.76 Australian-owned or Australian-sourced production accounts for ~68% of projected ex-China Nd/Pr supply.
ii. Derived estimate; no stated nameplate capacity exists in MP Material’s public disclosures.
iii. Solvay’s La Rochelle facility is additionally producing Nd/Pr at an undisclosed volume, with potential to scale to 2,000-5,000 tpa conditional on further investment not yet confirmed.
China currently produces approximately 98% of global primary gallium,83 and an estimated 50% of high-purity refined gallium.84 China’s dominance at both tiers is projected to persist through the late 2020s. Of the ~50% of refined gallium produced outside China, most relies on Chinese primary feedstock and remains vulnerable to Chinese export controls. The table below shows projected 2028-2029 supply from facilities with genuinely integrated ex-Chinese mining and refining operations. Of this, Australia supplies ~32% of projected ex-China gallium, rising to ~55% if Alcoa’s conditional Pinjarra expansion proceeds.
iv. Wagerup is targeting 60 tpa in its first phase before ramping to 100 tpa; the figure shown is full design capacity.
v. 2030 projection.
vi. Commercial-scale potential to 40 tpa; no confirmed timeline.









