A Lawfare analysis says the push for AI sovereignty is intensifying a long-running dispute over whether unauthorized cyber intrusions into another state’s networks violate sovereignty under international law. The article contrasts a pure sovereignty position associated with France and the African Union, an effects-based approach reflected in the Tallinn Manual and many Western states, and an operational-latitude posture linked to the U.K. and, in a different form, the U.S. It argues that governments have historically preserved room for intelligence collection and offensive cyber operations by resisting a broad sovereignty rule, even as AI systems become more central to national security.
The piece warns that this legal posture leaves AI assets such as training data, compute infrastructure, and model weights exposed to low-level but strategically significant intrusions including data theft and data poisoning. Drawing on examples such as the OPM breach, Volt Typhoon activity, and security cooperation under AUKUS Pillar II, it says current thresholds focused on physical damage, loss of functionality, or coercive interference do not clearly cover covert compromise of AI systems. Background references to France’s formal cyber-law position and a U.K. government speech on international law underscore the divide among states as customary international law appears to be moving toward stronger sovereignty protections in cyberspace.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
A Lawfare article published on 2026-07-28 argued that the rise of AI sovereignty is intensifying the debate over whether unauthorized cyber intrusions violate state sovereignty, and that U.S. and U.K. legal positions may leave AI infrastructure insufficiently protected against low-level intrusions.
In a 2022 government speech, the United Kingdom argued that there is no specific prohibition in international law on cyber activity that falls short of intervention or use of force, reflecting its operational-latitude position in the sovereignty debate.
France's 2019 national position stated that any unauthorized penetration of French systems or production of effects on French territory by cyber means can constitute a violation of sovereignty, articulating a broad legal view in international cyber law.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
lawfaremedia.org
Open sourcecyberlaw.ccdcoe.org
Open sourcegov.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.