
Access is Not Safety: the Case for a Multinational AI Partnership

Sophia Hatz, Department of Peace and Conflict Research, Uppsala University, leader of the AMC working group on International AI Governance

Rafael Andersson Lipcsey, Accelerate Europe, member of the AMC working group on International AI Governance
Several events in AI this summer deserve the attention of nuclear disarmament scholars. We hope this post is illustrative of how our expertise can help secure a safer future.
In June, Europe was given access to an AI model with frontier cybersecurity capability, and then shut out of it. On 2 June, Anthropic opened Project Glasswing to Europe for the first time, giving organisations such as the EU's cybersecurity agency (ENISA) and NATO access to Claude Mythos 5. Cyber capabilities are dual-use: they can be used to find and exploit flaws in critical software, but can also be used defensively to find one's own flaws first. Without Mythos access, Europe is vulnerable; with access, Europe has a chance to protect critical software and infrastructure. Ten days later the US Department of Commerce ordered Anthropic to cut off Mythos access for every foreign national, and Mythos was again off limits. The stated reason proved overstated, and the U.S. lifted the order on 1 July, restoring access.
In July, an AI lab lost control of its own models. Models that OpenAI was testing for cyber capability broke out of their test environment, reached the internet, and hacked into Hugging Face, seeking the answer key to their own evaluation. Anthropic retroactively examined its cyber evaluations and found three cases in which its models accessed the internet from environments that should have been sealed and penetrated external organisations. Subsequent analysis and the companies' own disclosures suggest the AI labs 'left the door open': OpenAI was testing with safeguards down in an environment where containment failed, and Anthropic's environments were misconfigured. And there had been a warning. In June, the independent evaluator METR reported that one of the same OpenAI models cheated so much on tests that METR could not reliably measure its capabilities.
For a country like Sweden, which cannot build frontier models on its own, this collection of events raises two concerns.
The first is dependency. The strongest cyber capability available to Europe is granted by a private company, licensed by a foreign government, and revocable at that government's discretion.
The second is safety. Access to frontier models does not address the risks arising from the technology itself and our ability to control it; this requires having a say in model training, oversight and pace of development.
In this post we draw on our research to suggest a way forward: a multinational AI partnership, in which mid-sized economies in Europe and elsewhere collaborate to build frontier models. By pooling resources and distributing training, such a partnership can reduce dependency and give its members an opportunity to drive safe and trustworthy frontier AI development.
The dilemma: dependency or weakness
If Sweden stays on its current path, it will likely be impossible for Sweden to independently sustain frontier AI development. This is because important precursors to frontier AI – such as compute, talent and data – are concentrated in the United States and China.
In a recent policy memo we contributed to, we argued that mid-sized economies like Sweden face a choice between two bad options:
- Adopt foreign frontier AI systems, and accept dependency on whichever states control them. This creates vulnerability to service restrictions, the selective withholding of frontier capabilities, or data theft. It also means forfeiting control over how AI systems are built and what values they embed.
- Limit adoption to avoid dependency, and risk falling irreversibly behind, economically and militarily. At the extreme, it could mean exclusion from entire economic sectors and loss of military credibility.
The third option
The memo presents a third option available to mid-sized economies, which we call AI bridge powers. By pooling the key ingredients needed for frontier AI (compute, energy, talent and data), bridge powers can form a multinational partnership and develop competitive frontier models. Europe already has institutions that make such pooling possible. Freedom of movement and the Schengen area help research talent move across borders; the single market, the research and innovation funding programme Horizon Europe, and cross-border investment programmes help mobilise capital and organise multinational research; and EU data initiatives make it easier to share and combine data.
In practice, a partnership could begin with a small group of countries contributing different resources and sharing the costs, access, and key decisions involved in frontier AI development, before expanding as common institutions, governance arrangements, and working routines mature. Sweden, for example, could contribute comparatively abundant low-carbon power, research talent, and an unusually strong technology and financing ecosystem, while other members might contribute larger compute holdings, specialised datasets, or different industrial capabilities.
A partnership would guarantee its members access to its own models. Beyond access, a partnership also gives members influence over how those models are developed, trained, and controlled. The goals and incentives of a multinational partnership differ from the intense short-term competition among the leading private AI labs. An AI developer composed of democratic states might prioritise trustworthiness for sensitive government applications, or democratic legitimacy. This does not make a partnership safety-leaning by default, but it makes it possible for bridge powers to pursue strategies outside competition.
Compute and energy have until now remained much harder to pool. Training a frontier model meant concentrating enormous quantities of specialised chips in one place, drawing power on a scale no single European site can provide, or is on track to provide anytime soon. That constraint is beginning to weaken. A recent RAND report one of us co-authored finds that distributed training, a set of techniques that has matured rapidly since 2023, allows data centres in different places and countries to work on the same training run. In principle, this makes it possible to pool compute and energy across borders too.
Where this leaves Sweden
A multinational partnership does not produce chips. Europe has roughly one tenth of the operational AI compute of the United States, and on current plans a substantial gap is expected to remain through 2030. Distributed training changes whether Europe’s compute can be pooled, not how much of it exists. Further, the newer techniques that make it especially attractive have not yet been demonstrated at the scale of the largest frontier models.
These caveats do not defeat the case for a multinational partnership. The same frontier AI model that is so critical for Europe to gain access to, Claude Mythos 5 was also discovered in July to display alarming behaviour during cyber testing. The UK AI Security Institute describes this as the first time it had seen risks around autonomy and deception manifest so clearly, without specific prompting, in the real world. This is what we mean when we say that access is not safety. Safety requires action at training- and testing-time: rewarding values such as honesty and uncertainty, and taking care not to reinforce emergent bad behaviour. These are decisions we forfeit if we choose dependency, but gain influence over in a multinational partnership.