MAIM Among Friends: Alliance Implications of Frontier Model Withholding

When access to frontier AI models that promise to provide a decisive strategic advantage is withheld, adversaries may be tempted to MAIM: negotiate, steal, or destroy. But the calculus changes when MAIM intersects with alliance dynamics: Australia and the US’s Western allies face an incentive and opportunity structure that may promote, and enable, the less instead of the more destructive options.

Early last month, Anthropic declined to give Britain’s AI Security Institute pre-release access to Claude Mythos 5.1. Although previous versions of the model had been made available to the British agency for testing, the latest iteration of Mythos was initially restricted to vetted American organisations. While there is no evidence that Washington ordered Anthropic to exclude the British, nor that this represents some wider rupture in the special relationship, the episode raises interesting—and already oft-discussed—questions as to what happens when the boundaries of the Western AI ecosystem no longer match the boundaries of the Western alliance system.

I approach this question from the hitherto under-researched perspective of MAIM dynamics in existing alliances. At its simplest, MAIM describes a deterrent dynamic in which a state seeking an overwhelming AI advantage risks provoking rivals to steal, sabotage or otherwise neutralise that advantage. Proposed by Dan Hendrycks, Eric Schmidt and Alexandr Wang, the strategic logic of ‘Mutual Assured AI Malfunction’ argues that when a rival appears to be close to developing AI systems that will confer it a decisive strategic advantage—whether through asymmetric research, cyber, or intelligence capabilities—there are a few options available. ‘Race harder’, by accelerating frontier AI research to close the gap; negotiate some sort of agreement to access the model; conduct espionage to acquire the frontier model and level the playing field in that manner; or seek to degrade the rival’s capability either through covert or overt actions against AI infrastructure such as data centres and research facilities. The overall MAIM framework then describes the deterrent relationship produced when states know that an attempt to establish an overwhelming AI advantage could invite efforts to disable it.

The framework is written principally with adversaries such as the United States and China in mind. But I argue its logic changes slightly when technological dependence runs through alliances instead of rivals or adversaries. NATO and the Five Eyes bring together states with unusually deep military, intelligence and political commitments. They do not, however, guarantee equal access to commercially developed American AI. When an alliance contains both a more dominant AI power such as the United States—still home to more top-tier AI models and much of the frontier AI ecosystem, including AI investment and infrastructure— and countries increasingly dependent frontier models, advanced compute, cloud infrastructure and associated AI capabilities that they neither own nor control, what happens?

Among allies, however, MAIM dynamics would likely operate differently than they would  between adversaries. The prospect of losing the benefits of the alliance relationship surely means overt sabotage becomes a much more costly option to contemplate. Negotiated access, however, might become easier with the backing of pre-existing goodwill, assurances based on pre-existing cooperation in other fields, or quid pro quo arrangement in other aspects of the alliance, such as basing rights or levels of military expenditure. Independent development might also become more defensible and serve as a springboard for cooperation. Espionage might also become more attractive and easier.

Post-Second World War nuclear proliferation serves as an intriguing guide. The United States attempted to place a fence around the technology it had developed through the Manhattan Project, the 1946 McMahon Act ended wartime nuclear information-sharing even with Britain. But London did not accept permanent technological dependence and resumed independent development, testing an atomic bomb in 1952. Once Britain had demonstrated substantial capabilities of its own, extensive Anglo-American nuclear cooperation returned through the 1958 Mutual Defence Agreement. De Gaulle, however, repeatedly questioned whether the United States would risk its own cities in defence of Europe. France therefore remained within NATO politically while insisting upon an independent nuclear force and, in 1966, leaving the alliance’s integrated military command. The Soviets, as is by now well known, benefited substantially from espionage within the Manhattan Project to supply them with information on American nuclear work, leading to their own first test in 1949.

Information controls create incentives and these three historical cases point to three possible responses to technological dependence which can be read for parallels to today: the British bargain for access after demonstrating independent capability, the French persistence in developing an independent capability, or the Soviet Union’s acquiring of what is denied through espionage.

Espionage, in particular, becomes an interesting prospect within a pre-existing alliance. Close allies already exchange personnel, research, intelligence and defence technology. Their scientists work in the same companies and universities; their officials sit in the same meetings; their intelligence agencies maintain close working relationships. Precisely the links that make an alliance valuable and effective can make clandestine acquisition easier than it would be for an adversary: and espionage, if it does occur, may be viewed as less escalatory than equivalent espionage by an adversary.

The incentive could also grow as an alliance becomes less trusted. A government that believes access to American frontier models will remain available has little reason to run the political risks of stealing it. A government which fears that access might disappear in a crisis faces a different calculation. If developing a sovereign frontier model is prohibitively expensive, acquiring model weights, training techniques, or other proprietary technical knowledge clandestinely begins to look more attractive. Tighter American controls could then follow, confirming the ally’s original fear and producing a spiral in which restriction encourages hedging, hedging encourages suspicion, and suspicion produces further restriction.

AI also differs from nuclear weapons in one important respect. Most NATO states can rely upon American extended nuclear deterrence without possessing the design of an American warhead. NATO still describes US strategic nuclear forces as the ‘supreme guarantee’ of allied security. But an AI capability is not simply a weapon held in reserve. Access to better models could confer continuous advantages in intelligence, cyber operations, military planning, scientific research and economic productivity. An American promise to employ its AI capabilities in defence of an ally may therefore be a poor substitute for giving that ally access to them.

For Australia, this problem is hardly theoretical. AUKUS and Five Eyes place Canberra unusually deep inside the American security system. Yet Australia has not to date hosted frontier-AI training, and the government acknowledges that insufficient domestic compute could constrain the growth of its own AI industry. At the same time, Australia’s expanding AI infrastructure includes major investments from American firms such as Amazon and Microsoft, including Amazon’s planned A$20 billion investment in Australian data-centre infrastructure and Microsoft’s A$5 billion investment in hyperscale cloud and AI capacity. Australian Government National AI Plan Canberra has also entered formal AI collaboration arrangements with Microsoft and Anthropic. This creates a familiar alliance asymmetry: Australia may share the strategic consequences of frontier-AI development without controlling the models or infrastructure on which those capabilities depend. Australian policymakers therefore have an interest in ensuring that access to strategically important AI becomes part of the alliance bargain before dependence is entrenched.

MAIM need not turn allies into enemies. It does suggest that alliance membership cannot make the politics of technological dependence disappear. If America increasingly restricts access to frontier AI on national-security grounds while expecting allies to share the risks created by its development and deployment, those allies will look for ways to reduce their dependence. Some will bargain. Some will build. And, eventually, some may be tempted to steal.

An AI alliance will be most stable when its technological boundaries and its geopolitical commitments broadly coincide. Otherwise, what’s a little MAIM among friends?


Alexander Yen is a DPhil candidate in International Relations at the University of Oxford and Founding Convenor of the Oxford China Research Group. His research focuses on Chinese foreign policy, state rhetoric, international order, and strategic competition. He has written on China, AI, and geopolitics for policy-facing audiences.

This article is published under a Creative Commons Licence and may be republished with attribution.

Photo: Max Gruber, Wikimedia Commons (CC BY 4.0)

Get in-depth analysis sent straight to your inbox

Subscribe to the weekly Australian Outlook mailout