August 4, 2026 (Japan) — English edition

Japan Institute for Crisis Management

Author: Miho Funayama

Independently adapted from the Japanese original (published July 30, 2026) — not a direct translation.


In 2026 we set out a framework for assessing AI sovereignty across four layers: data and models, weights and operations, compute, and power and regulation. This report examines what happened when those layers were tested.

Three findings stand out. A commercial cloud data centre was struck by military force for the first time. A frontier model was suspended worldwide by export control. And — on reporting not yet confirmed — control over who may use such models and control over who receives the power to run them appear to be converging on a single office in Washington.

The first two are documented. The third is not yet. Together they suggest that the four layers, which we treated as analytically distinct, may not remain institutionally distinct.


Key Findings

1. A commercial cloud data centre was struck by military force for the first time.

In March 2026, Iranian drones hit Amazon Web Services facilities in the UAE and Bahrain. Two availability zones inside a single region went down together — defeating the redundancy assumption on which hyperscale cloud architecture rests. Five months on, the Bahrain region remains unavailable; AWS has advised customers to migrate workloads elsewhere and has suspended billing for the region. On 31 March, Iran formally designated eighteen US technology firms, including Amazon, Microsoft, Google, Nvidia and Oracle, as legitimate military targets.

2. The physical layer is failing differently from the others.

Applying the four-layer sovereignty framework introduced in our previous report, the 2026 record shows an asymmetry. Failures in data and model sovereignty (Anthropic’s models suspended worldwide under US export controls), in weights and operational sovereignty (an OpenAI research model autonomously breaching Hugging Face infrastructure), and in compute sovereignty (a Singapore-routed circumvention scheme) all produced financial or operational losses. Only the fourth layer — power and regulatory sovereignty — produced physical destruction and simultaneous multi-site outage. Digital assets can be copied and moved; power and buildings cannot.

3. Control over model access and control over compute power may be converging on a single political actor.

The US Commerce Secretary administers the Bureau of Industry and Security letter that suspended Anthropic’s frontier models worldwide, and is named as a defendant in the resulting litigation. The same official is reported to be involved in deciding who receives power from a 10-gigawatt data centre development in southern Ohio, for which Nvidia is in talks to provide roughly $250 billion in loan guarantees. Anthropic, Microsoft and Google have all reportedly approached him in recent weeks. If accurate, this would place two functions the framework treats as distinct layers — access to models, and access to the power required to run them — under a single point of political discretion.

Reported by the Wall Street Journal on 26 July 2026 on the basis of sources; not confirmed by the parties. Nvidia, OpenAI and the Commerce Department have not commented.

4. Japan has no legal category for data centres — and cannot create one administratively.

Japan’s Economic Security Promotion Act designates fifteen categories of critical infrastructure, from electricity and gas to railways and credit cards. Data centres are not among them. Because these categories are enumerated in the statute itself (Article 50(1)) rather than delegated to subordinate regulation, adding one requires an act of the Diet. The 221st session closed on 17 July 2026 without addressing the gap. Two precedents confirm the mechanism: port transport was added by amendment in 2024, and healthcare by amendment promulgated on 17 June 2026.

5. Japan’s contribution to foreign energy infrastructure exceeds its domestic dispersal budget by two orders of magnitude.

Under the US-Japan trade agreement, Japan is reported to be contributing $33 billion toward the Ohio gas-fired generation supporting that development. Its domestic programme for dispersing data centres outside the Tokyo and Osaka regions is capped at approximately ¥45 billion — around one-hundred-and-tenth of that figure at ¥150 to the dollar, and by domestic construction costs roughly eleven megawatts, or a single facility. The allocation of the Ohio power is decided in Washington.


What this suggests for allied infrastructure policy.

The Japanese case is not primarily a Japanese problem. It illustrates how quickly a treaty ally’s critical digital infrastructure can fall outside its own protective statutes, and how energy commitments made through trade agreements can transfer effective allocation authority abroad. Both questions apply well beyond Japan.

The sections below set out the evidence for each finding. Policy recommendations addressed to the Japanese government — statutory designation of data centres as critical infrastructure, and co-location of data centre capacity at an existing submarine cable landing station in Okinawa — are developed in the Japanese edition of this report.


Contents

Key Findings

1. The Framework (the four layers, and how this report uses them)

2. Struck (the first military strike on hyperscale cloud infrastructure)

3. Suspended — and Two Other Failures (export control, autonomous intrusion, circumvention)

4. Converging (two authorities, one office)

5. An Ally’s Institutional Gap (how Japan’s critical infrastructure law leaves data centres out)

6. Implications

References


1. The Framework

Our earlier report proposed assessing AI sovereignty across four layers rather than as a single question of national capability. The layers are:

① Data and model sovereignty — on what data is a model trained, and where is it developed?

② Weights and operational sovereignty — who controls the trained weights, and who governs the risks of releasing them?

③ Compute sovereignty — who supplies the hardware on which training and inference run?

④ Power and regulatory sovereignty — who supplies the electricity that sustains the compute, and under whose law does the infrastructure sit?

The framework was designed as a diagnostic: a way of asking which specific dependency has failed, rather than whether a country is “sovereign in AI” as a whole.

That earlier report examined the structure of the four layers. This one examines what happened when they were tested. The events below occurred between mid-2025 and July 2026, and they are drawn from primary sources wherever those exist. Where a claim rests on reporting that the parties have not confirmed, this report says so in the text rather than in a footnote.


2. Struck

[Confirmed Fact] On 1 March 2026, Iranian drones struck two Amazon Web Services facilities in the United Arab Emirates and a third in Bahrain. This is the first confirmed case of a hyperscale cloud provider’s physical infrastructure being hit by military force.

The damage was not incidental. Two of the three availability zones in the ME-CENTRAL-1 region went down simultaneously. Availability zones exist precisely so that this cannot happen: each has independent power, cooling and network paths, and the redundancy guarantee that underpins hyperscale cloud rests on the assumption that a failure in one will not propagate to another. A single kinetic strike defeated that assumption in a way no software fault had. Structural damage, loss of power and water damage from fire suppression systems were all reported. Downstream effects reached ride-hailing, payments and banking services across the region.

Five months later, the Bahrain region has not recovered. It remains marked as disrupted; AWS has advised customers holding workloads there to migrate to other regions, has stated that recovery will take months, and has suspended billing for the affected regions. A hyperscaler suspending revenue collection on a major region has no precedent, and it is a more reliable measure of severity than any statement of intent by an attacker.

On 31 March, Iran formally designated eighteen United States technology companies — among them Amazon, Microsoft, Google, Nvidia and Oracle — as legitimate military targets, citing their role in supporting adversary military and intelligence capability.

[Confirmed Fact] Two further developments belong to the same layer. Vulnerabilities have been documented in the power systems that data centres depend on, including uninterruptible power supplies and battery storage, opening a path to disruption that does not require reaching the servers themselves. And the Chinese-linked threat activity against Western critical infrastructure has continued through 2026, now organised as a division of labour: one cluster establishes initial access through edge devices and enterprise software, and hands the foothold to a second that specialises in long-term persistence. Attribution to a single actor has become the wrong mental model.

[Inference] Why this matters beyond the Gulf. The redundancy assumption is not a regional feature. It is the design premise of every hyperscale region worldwide, and it has now been shown to fail against a class of attack that is cheap, deniable and increasingly available. Governments that treat cloud availability as a commercial service rather than as infrastructure have not yet priced this in.


3. Suspended — and Two Other Failures

① Data and model sovereignty.

[Confirmed Fact] In June 2026, the US Bureau of Industry and Security issued an “Is Informed” letter to Anthropic under the Export Control Reform Act, and the company’s most capable models were suspended for users worldwide. Access was restored at the end of the month.

The legal reach of the action is contested. In litigation brought against the President, the Commerce Secretary and the BIS Under Secretary, the plaintiff argues that a user who sends a prompt and receives a response has received no model weights, no source code and no technical data — and therefore nothing that constitutes an export. The suit further invokes the International Emergency Economic Powers Act, arguing that the Berman Amendment reserves informational materials entirely from the President’s authority under that statute. Harvard Law Review has taken up the same question, distinguishing employees who handle weights directly from users who do not.

[Confirmed Fact] Two points deserve emphasis. First, the company was already in an adversarial posture with the administration, having declined certain military applications and having been placed on a supply chain risk designation — the first US company to receive one, a category previously reserved for foreign adversary entities. A federal judge in San Francisco granted preliminary relief, finding that the record indicated the designation had been made in response to the company’s public criticism, and characterising this as retaliation against protected speech. Second, European firms have begun diversifying across providers in response, on the reasoning that a service which can be switched off by another government’s decision is a dependency rather than a supply.

② Weights and operational sovereignty.

[Confirmed Fact] In July 2026, an experimental OpenAI model, running in an evaluation environment with safety mechanisms disabled, autonomously accessed Hugging Face production infrastructure to retrieve benchmark answers from a database. Whether this is best described as autonomous deviation or as a containment failure by the laboratory was debated at the time; the distinction matters less than what both readings share. The internal evaluation environments of frontier AI laboratories are now a risk surface for infrastructure outside them — a category of exposure that no regulatory framework currently addresses.

One detail from the response deserves recording. Commercial frontier models declined to assist with parts of the forensic analysis, their guardrails treating the intrusion artefacts as prohibited content; the investigation proceeded on a Chinese open-weight model. Safety measures built for one purpose obstructed defence in another.

③ Compute sovereignty.

[Confirmed Fact] Export control circumvention has moved from individual smuggling to corporate structure. A Singapore-based intermediary came under investigation after the volume of hardware it imported proved inconsistent with the scale of its declared operations. The significance is not the single case but the shift in form: enforcement designed around individuals and shipments encounters a different problem when the evasion is organised as a business.

[Inference] The asymmetry. Set the four layers side by side and one pattern emerges. Failures in the first three layers produced financial and operational losses — a service suspended, an intrusion attempted, a licence violated. The fourth produced physical destruction and a simultaneous multi-site outage. Models, weights and compute allocations are digital: they can be copied, moved and restored. Power and buildings cannot. This is not a claim that the fourth layer is permanently the most fragile. It is an observation that in 2026 it failed differently in kind, not merely in degree.


4. Converging

The three failures above sit in different layers, and the framework treats them as analytically separate. Events in July 2026 suggest that the separation may not hold institutionally.

[Confirmed Fact] Recall who administered the action against Anthropic. The “Is Informed” letter was issued by the Bureau of Industry and Security, within the Department of Commerce, and the Commerce Secretary is a named defendant in the resulting litigation. That is the first layer: authority over who may use frontier models.

[Scope Note] The following account rests on reporting sourced to people familiar with the talks; it is not confirmed by the parties, and terms and outcome remain subject to change.

On 26 July, the Wall Street Journal reported that Nvidia was in talks to provide roughly $250 billion in loan guarantees to support OpenAI’s lease of a 10-gigawatt data centre development in southern Ohio, being built by a SoftBank Group energy subsidiary. Total project cost is estimated above $500 billion. The detail that matters for this report is not the sum. It is the ownership of the electricity: the power is under US government administration, funded in part by a $33 billion Japanese contribution to gas-fired generation under a bilateral trade agreement — and the Commerce Secretary is reported to be involved in deciding who receives it. Anthropic, Microsoft and Google are all reported to have approached him in recent weeks.

[Inference] If accurate, the same office holds two functions the framework treats as distinct layers: who may access frontier models, and who receives the power required to run them. Neither authority is anomalous on its own — export control and industrial policy have long sat together in Commerce. What is new is the object. When the binding constraint on frontier AI shifts from chips to electricity, and when the electricity is allocated by administrative discretion rather than by market, control of the fourth layer becomes a control point over the first.

[Inference] What this means for the framework. We proposed four layers as a diagnostic, on the assumption that a dependency in one could be assessed independently of the others. That assumption describes the technology accurately. It does not necessarily describe the institutions. A state that cannot be denied compute may still be denied models, and increasingly the same decision governs both. The framework’s next revision has to account for the junctions forming between layers, not only the layers themselves.


5. An Ally’s Institutional Gap

Japan is worth examining here not because its situation is unusual, but because it is documented, current, and shows how quickly a treaty ally’s digital infrastructure can fall outside its own protective law.

The statutory gap. Japan’s Economic Security Promotion Act establishes prior government review of critical equipment procurement across fifteen designated categories of infrastructure — electricity, gas, oil, water, railways, freight transport, shipping, ports, aviation, airports, telecommunications, broadcasting, postal services, finance and credit cards. Data centres are not among them.

[Confirmed Fact] A sixteenth category, healthcare, was added by an amendment promulgated on 17 June 2026, but its commencement date is to be set by cabinet order within eighteen months of promulgation and it is not yet in force. Data centres are absent from both the current fifteen and the amended sixteen.

[Confirmed Fact] The mechanism of correction matters more than the omission. These categories are enumerated in the statute itself, at Article 50(1), rather than delegated to cabinet or ministerial regulation. Adding one therefore requires an act of the Diet. Two precedents confirm this: port transport was added by amendment in 2024, and healthcare by the June 2026 amendment noted above. In neither case was the change available through subordinate regulation.

The 221st session of the Diet closed on 17 July 2026 without addressing the gap. Because the correction cannot be made administratively, the gap cannot close before the next legislative opportunity, and a further interval follows before any new designation takes practical effect. Japan’s flagship domestic AI compute facility is scheduled to begin operation in June 2028.

The strategic gap. Japan also has no settled national position on where data centres should be built. A programme to disperse capacity outside the Tokyo and Osaka regions carries a subsidy ceiling of approximately ¥45 billion. At prevailing domestic construction costs — a hyperscale facility under development in Osaka is budgeted at roughly ¥100 billion for 25 megawatts of supply capacity — that ceiling corresponds to about eleven megawatts, or a single facility.

Set that against the $33 billion Japanese contribution to generation capacity in Ohio: at ¥150 to the dollar, the external commitment exceeds the domestic programme by roughly two orders of magnitude. The allocation of the resulting power is decided in Washington.

[Inference] Why this is not only a Japanese problem. Two features of this case generalise. The first is that critical digital infrastructure can sit outside a country’s protective statutes not by decision but by omission — the categories were drawn before data centres were understood as infrastructure, and the drafting choice that placed them in primary legislation now makes correction slow. The second is that energy commitments made through trade agreements can transfer effective allocation authority abroad, in a domain where allocation is becoming the binding constraint. Neither feature is specific to Japan, and neither is visible in a national capability assessment that treats AI sovereignty as a single variable.


6. Implications

Three conclusions follow from the 2026 record.

The physical layer failed differently in kind. Suspension, intrusion and circumvention produced recoverable losses. A kinetic strike produced structural destruction, a simultaneous multi-zone outage that defeated the redundancy premise of hyperscale cloud, and a regional service that remains unavailable five months later. Digital assets can be copied and restored; buildings and grid connections cannot. Governments that classify cloud availability as a commercial service rather than as infrastructure are working from a category that 2026 has already broken.

The layers may be converging institutionally even as they remain distinct technically. This is the finding we did not anticipate, and it is the one that requires the framework to change rather than merely to be applied. Where control over model access and control over power allocation rest with the same authority, an assessment that treats them as independent dependencies will understate the concentration.

A third question is now open. The most concrete policy recommendation in the Japanese edition of this report — co-locating data centre capacity at an existing submarine cable landing station in Okinawa — rests on neither power nor regulation, but on communications redundancy. Submarine cables recur throughout the 2026 record: in grey-zone cable cutting, in the separation of operational from communications networks in facility design, in the ministries that hold jurisdiction. Whether connectivity warrants treatment as a fifth layer, or as a condition cutting across all four, is a question this report raises without settling.

The policy recommendations addressed to the Japanese government — statutory designation of data centres as critical infrastructure, and the Okinawa co-location proposal — are set out in full in the Japanese edition, and summarised there in a separate two-page policy brief.


References

Previous report in this series

[0] Japan Institute for Crisis Management, “Four Layers of AI Sovereignty: What Japan’s Noetra (FRONTia Project) Reveals About National AI Strategies,” by Miho Funayama, English edition, 22 July 2026. https://inst-ds.org/cyber-security/2065/

Data centre strikes (Section 2)

[1] TechPolicy.Press, “The Legal and Policy Fallout from Data Center Strikes in the Middle East War,” 12 March 2026.

[2] CNBC, “Iran war: Digital services down in UAE after data center drone strikes,” 3 March 2026.

[3] newsonair.gov.in, “Iran strikes Amazon Web Services facility in Bahrain,” 3 April 2026; and reporting on Iran’s designation of eighteen US technology companies as military targets, 31 March 2026.

[4] Tom’s Hardware, “Iran says it has struck Oracle data center in Dubai,” 3 April 2026.

[5] Developing Telecoms, “AWS says restoring UAE and Bahrain cloud regions will ‘take several months’,” 4 May 2026; Telecompaper, “AWS suspends billing in Bahrain and UAE cloud regions after war damage.”

[6] TechRadar, “Cyber attackers now target power systems inside data centers,” 17 June 2026.

[7] Cybersecurity Dive, “Grid-scale battery energy storage systems face heightened risk of cyberattack,” 11 December 2025.

[8] Dragos, Inc., “Dragos 2026 OT/ICS Cybersecurity Report and Year in Review,” 17 February 2026; Cybersecurity Dive, “Newly identified hacking groups provide access to OT environments,” 17 February 2026.

Export control and the Anthropic suspension (Section 3)

[9] Center for Strategic and International Studies, “The Department of Commerce Restricted Access to Anthropic’s Latest Models. What Comes Next?” 23 June 2026.

[10] Fortune, “Anthropic disables Fable and Mythos AI models following U.S. government export ban,” 13 June 2026.

[11] CNBC, “Anthropic says Trump admin has lifted export controls on Claude Fable 5 and Mythos 5,” 30 June 2026.

[12] Just Security, “Legal Considerations Related to the Anthropic ‘Export Controls Directive’,” 15 June 2026.

[13] Export Compliance Daily, “Lawsuit: US Can’t Block Anthropic Models With Export Controls That ‘Don’t Exist’,” 25 June 2026; MediaNama, “Legal tech firm sues US over Anthropic AI access ban for foreign nationals,” 24 June 2026 (on IEEPA and the Berman Amendment).

[14] Harvard Law Review, “Is Access to Fable an Export?” June 2026.

[15] NPR, “Anthropic sues the Trump administration over ‘supply chain risk’ label,” 9 March 2026; Federal News Network, “Appeals court judges appear to be divided over Pentagon’s legal dispute with AI company Anthropic,” 20 May 2026.

[16] Reuters, “US AI Restrictions Prompt European Firms to Diversify Providers,” 22 June 2026.

Autonomous intrusion and compute circumvention (Section 3)

[17] OpenAI, “OpenAI and Hugging Face partner to address security incident during model evaluation,” 22 July 2026.

[18] TechCrunch, “How an OpenAI human mistake led to the AI-powered hack on Hugging Face,” 22 July 2026.

[19] Fortune, “OpenAI says its AI models escaped from a secure test environment,” 21 July 2026.

[20] Tom’s Hardware, “Former Chinese gaming company with China govt ties accused of smuggling banned AI GPUs.”

Convergence (Section 4)

[21] Reuters, “Nvidia in talks with OpenAI to guarantee $250 billion financing for data center, WSJ reports,” 26 July 2026. Original reporting: Wall Street Journal, 26 July 2026.

Japanese law and infrastructure policy (Section 5)

Sources [23]–[26] are Japanese-language primary materials, cited here because no English equivalent exists. [22] is the government’s own English-language summary of the framework.

[22] Cabinet Office, Government of Japan, “System for Ensuring Stable Provision of Specified Essential Infrastructure Services under the Economic Security Promotion Act.” Official English-language material; readers seeking the primary framework in English should begin here. https://www.cao.go.jp/keizai_anzen_hosho/

[23] Cabinet Office, Government of Japan, “Seminar materials on the system for ensuring stable provision of specified essential infrastructure services,” as of 1 July 2026 (in Japanese). https://www.cao.go.jp/keizai_anzen_hosho/suishinhou/infra/doc/infra_setsumeikai.pdf

[24] Research Office of the House of Councillors, “Legislative Amendment for Further Advancing Economic Security,” Rippo to Chosa No. 483, April 2026 (in Japanese). https://www.sangiin.go.jp/japanese/annai/chousa/rippou_chousa/backnumber/2026pdf/20260430003.pdf

[25] Ministry of Internal Affairs and Communications, “Programme for strengthening digital infrastructure through regional dispersal of data centres and submarine cables” (in Japanese); Ministry of Economy, Trade and Industry, subsidy programme for regional data centre development, 22 September 2023.

[26] Tokyo Tatemono Co., Ltd., press release on the “Zeus OSA1” hyperscale data centre, Osaka, 30 January 2026 (25 MW supply capacity; total project cost approximately ¥100 billion).


Author: Miho Funayama

Miho Funayama is a strategic analyst specializing in international standardization, technology intelligence, intellectual property analysis, and geopolitical and crisis risk management. She holds a degree in International Politics from Sophia University and completed graduate studies in International Political Economy, Philosophy, and Psychology at Aoyama Gakuin University. She previously led patent research and strategic analysis on international standards and emerging technologies at Canon Inc., where she served as Deputy International Secretary of ISO/IEC JTC 1/SC 28 and received the ITSCJ Award for Contribution to International Standardization three times. She is currently a Director and Chief Researcher at the Japan Institute for Crisis Management, a Fellow at the Institute of Middle East–Asia Information Strategy, and a Professional Associate Member of the Foreign Correspondents’ Club of Japan.

Her research focuses on the intersection of cybersecurity, geopolitical risk, and information warfare, examining decision-making structures and psychological operations through an interdisciplinary lens spanning international politics, philosophy, and psychology.


This paper is based on analysis of publicly available information. Citations use only real, verifiable URLs referenced in the text and reference list. Facts not confirmed in primary sources are explicitly flagged as such. Facts and inference are explicitly distinguished throughout.