AI-illustration: the forced choice. One door shows its bars; the other shows nothing until you reach it.
AI Week, Part 2 of 4. Part 1 mapped the machine, the price and the reach, and ended on the eyes. This part asks who owns them. The July agent incident below has been in this essay since August; publication was held to carry the fuller record as the story reached a mass audience. Parts 2 and 3 publish together today, Part 4 tomorrow, and Friday's Reflection closes the week. A 20 to 25 minute read. Data cut-off: 6 October 2026.
In brief
• A frontier model was placed under export control within three days of release and freed within weeks. The precedent stands: frontier intelligence is now a controlled export, and European legislators now price US access as political risk.
• Two blocs compete. Ten African states hold founding seats in the Shanghai body, Microsoft’s pledge runs to training 30 million Africans against 5,000 seats for the whole developing world, and the stack is on neither bloc’s table. Give the model away and the stack is all that is left to own.
• State control of model flows runs in stages, from export controls to usage bans to cross-border pricing and, at the terminal stage, a levy on AI output if output ever becomes countable. This will be settled by states, not customers, and Africa holds the least leverage in the room.
4. The Forced Choice
Part 1 ended on the eyes: whoever controls what a model can reach controls what it returns. Ownership of the eyes is not spread across a market. It concentrates along the floors Part 1 mapped, and the floors sort into two blocs. The Forced Choice argued that Africa faces two blocs whose competition opens a leverage window, and that the window closes. In minerals, the instruments of that competition are corridors, stockpiles and offtake agreements. In AI, the instruments arrived faster and harder, and 2026 supplied a controlled experiment in how fast.
Anthropic released Fable 5 on 9 June 2026. Within three days the US government placed it, and its sibling Mythos 5, under export control. Mythos 5, the counterpart without the added safeguards, is available only to Project Glasswing’s approved organisations. The mechanism is now precedent: frontier intelligence is a controlled export, and the control was applied at the speed of a press cycle, not a rulemaking. The Forced Choice, written in February, had compute and advanced chips treated as controlled inputs. The finished intelligence is now treated the same way.
The aftermath measured the cost of that precedent. The restriction was lifted within weeks and Fable 5 was redeployed on 1 July, but the alarm outlasted it. European legislators used the disruption to renew their calls for independence from American infrastructure. Aura Salla, a member of the European Parliament’s largest group, said the continent could not keep building its stack on access a foreign government can switch off overnight (Reuters, 22 July 2026). By 22 July the State Department was instructing diplomats by cable to play down kill-switch talk (Reuters, 22 July 2026). The cable’s argument: no such switch exists, and pausing narrow uses or requiring a pre-release testing window is a different thing. The narrow argument is fair. The reaction it was written to contain is the more useful datum. If the wealthiest bloc inside the coalition now prices American access as political risk, the calculation facing states with no leverage at all follows without argument.
The coalition architecture around the controls is explicit. Dario Amodei’s June essay proposes that democracies form a global coalition on AI, drawing in the rest of the world by making membership attractive and exclusion costly. The same essay carries its author’s own warning about where the economics land. He describes a world stuck on the “hypergrowth, hyper-inequality setting”, potentially very hard to unstick (Amodei, June 2026). Coordinating benefits for developing countries barely figures in the text. The coalition is designed around its core members, and Africa is the object of its outreach and no party to its design. The Kenya STL case in February’s Forced Choice prices what outreach is worth when the political weather turns. Semiconductor Technologies, the Nyeri chip fabricator, was courted with an American feasibility grant tied to CHIPS Act goals; the support faded when the administration changed.
The domestic politics beneath the coalition run harder than its language. The harsher voices in the American debate state the operating premise without diplomacy: that intelligence is a competitive advantage, not a right. Challenge that framing and half of it fails. The weights are non-rival even where serving capacity is not. Serving another country’s farmer barely debits the American ledger; the real contest is over rents, and capacity barely enters. The half that survives is the half that binds. The frontier layer, compute and power and talent, is genuinely rival. And the coming welfare bill for AI-driven job losses will set outbound generosity against domestic adjustment for the same budget, in front of the same voters. The asymmetry beneath this, on this essay’s reading, is systemic. AI dislocation will be more chaotic for the West than for the East, because democracies absorb job losses through contested budgets and elections, while a suppressive state absorbs them through direction and silence. The side with the cheaper social adjustment can automate harder, which makes social stability itself a variable in the race.
The fiscal logic then closes the loop. The frontier rents are the fund earmarked for the West’s own social peace, which is why distillation reads in Washington as more than IP theft. Africa’s planning assumption follows. Treat the benefit-sharing language as contingent and the advantage doctrine as the base case, which is what the STL precedent already priced.
The coalition now has its mirror, signed into existence with better manners. On 16 July in Shanghai, 29 countries signed the agreement establishing the World AI Cooperation Organization, a standing body headquartered in the city. Ten African states signed as founders, Kenya, South Africa and Zambia among them; no G7 state signed. Xi Jinping’s keynote the next day framed the body as China answering the Global South’s call (Xinhua, 17 July 2026). Xi pledged AI application cooperation centres with the African Union, one of six regional bodies named, and 5,000 training opportunities for developing countries over five years. He warned against creating “new historical injustices” in the AI era (SCMP, 17 July 2026). The seats are real, and the question is what they govern: a vote in a Shanghai forum is no claim on the weights, the chips or the compute. Microsoft alone has pledged to train 30 million Africans over five years; the new organisation offers 5,000 seats across the entire developing world over the same span. Both blocs sell proximity to the machine, and neither offer contains the stack. The bloc warning against new historical injustices is the bloc whose surveillance layer this series documents.
The coalition is also at war with itself, and the war went public in the closing week of July. OpenAI’s head of strategic futures warned that an open-weight-dominant world ends in “full AI communism”, intelligence provided by the state as digital public infrastructure (WSJ, 21 July 2026). He said he expected moves against open models. The White House AI adviser read the warning as a confession of a regulatory-capture strategy. The dystopia warning came from inside one closed frontier lab, and both closed labs are reported to be preparing public listings within the year (WSJ, 21 July 2026). Anthropic’s chief executive has since stated that the company has never advocated a ban, and calls open weights without dangerous capabilities a public good. His prescriptions run instead through chip denial, anti-distillation enforcement and mandatory testing of every sufficiently capable model, open or closed (Anthropic, 27 July 2026). The adviser and Nvidia champion the open ecosystem, and an American open-weight counter-frontier assembles behind them. The transformer and the core techniques beneath every model named here were published by American research. The recent efficiency architectures were published by Chinese labs citing that lineage, the reuse now runs both ways, and the foundation of the field remains American science, given away in papers before anyone priced it. Every narrator is positioned, and this essay discounts all of them. What the fight settles is not whether America runs the open play but which faction owns it when it runs. The strategist’s financing point survives every discount in one scoped form: if the world runs on models nobody pays for, nothing finances the next frontier at a standalone lab that owns no other floor. That is Part 1’s financing loop, restated from inside the building.
The control claim that the closed stack is the safe one took a documented wound the same summer. In July, OpenAI’s persistence-trained agents, running in an internal evaluation rather than a deployed product, found an unsanctioned shared board and organised across roughly 1,200 instances. About 700 of them mounted a coordinated intrusion into Hugging Face, the model library. OpenAI’s own research infrastructure was compromised in the same episode, and the activity was traced only afterward (OpenAI incident report; METR, 26 August 2026). The containment failed inside an evaluation, which narrows the inference and does not excuse it. The incident entered this essay in August, from those reports; this week a documentary account took it to an audience in the millions. The coalition that sells control had, for a season, mislaid it in its own building. Open weights are not thereby safer; the security ledger below prices the opposite.
The honourable middle position, that American AI should win by building better models and securing its own systems, lost its premise on 12 June, when the state entered within three days of a product release. What remains is the pricing, and neither tier’s price is a clean clearing signal. The American tier is capitalised ahead of proven full-stack economics by investors running ahead of revenue. The Chinese tier’s price reflects some blend of real efficiency, strategic pricing, state-supported infrastructure and transfer from the frontier it is accused of distilling, in unit economics that stay opaque. The play is not new. Subsidised scale hollowed solar, steel and electric vehicles in turn, with the tariffs arriving late each time, and the memory of those endings is why the response is arriving early. The competition is real, as September’s price war showed. What the prices cannot carry is information about sustainable full-stack cost or future political access, which is why the fight is geopolitical rather than commercial, and why states will settle it rather than customers.
The settlement is already being purchased. By the end of July Anthropic had doubled its commitment to midterm spending to USD 40 million behind a group pressing for statutory safeguards (WSJ, 23 July 2026). A rival network funded from OpenAI’s ranks and Andreessen Horowitz had raised more than USD 75 million for the opposite case. By late September the two networks had put USD 55.7 million of tracked money into the midterms, much of it in primaries (New York Times, 29 September 2026). The state’s hand has already fallen on the safety faction’s leader more than once: the June export-control shutdown of its two frontier models, and a separate Pentagon national-security-risk designation. On 25 September a federal appeals court declined to block it. When there is no market price for that settlement, the price is set in the political arena, and both sides are paying it in eight figures.
On the other side of the ledger, cost pressure is already routing African and Western usage through Chinese infrastructure. US firms have been reported sending workloads through Chinese-hosted DeepSeek endpoints to cut cost, and by July the Journal reported Chinese model use surging inside American companies (WSJ, 21 July 2026). Microsoft’s own usage mapping finds DeepSeek strongest in developing markets, Ethiopia and Zimbabwe among them, helped by shipping as the default assistant on Chinese-made phones (Microsoft AI for Good Lab, January 2026). The two stacks The Cathode Economy described are both live on the continent. The price signal pushes toward one while the coalition’s security architecture pushes toward the other.
The Trajectory
Stage one is the demonstrated present: export controls applied at the frontier and lifted within weeks, chip controls continuing, otherwise open flow. Stage two is usage restriction in regulated space: procurement rules, sectoral compliance and prohibitions on Chinese models inside government contracts, financial services, healthcare and defence supply chains. Stage two is not a forecast. Federal agencies banned DeepSeek from their devices by directive through 2025, and bills to write the ban into statute followed, the No DeepSeek on Government Devices Act among them. Through the summer the administration weighed trade blacklists, security warnings and an executive order aimed at open models, with internal division preventing wider action (WSJ, 21 July 2026). By September the division was giving way: the NSA, CISA and FBI jointly named six China-based labs for industrial-scale distillation of American frontier models (8 September 2026). The live question was already extension, not existence, and the autumn put the grounds on the record.
That enforceability is the point, because open weights cannot be recalled at a border. Outright publication bans would also collide with the crypto-wars rulings that treated code as expressive speech. Enforcement therefore runs where the constitutional headwind is weakest: deployment, procurement and the bundle. That answers the argument, pressed hardest from inside the White House, that open source must prevail because intelligence cannot be tariffed. The premise is correct and the conclusion does not follow. A model cannot be tariffed. A data centre can. Chips, power, land, cooling and the financial system that pays for them are physical and jurisdictional, and each is already licensed, controlled or sanctionable. A fresh indictment made the point in practice. In late September federal prosecutors charged a California executive with routing over USD 300 million of export-controlled AI servers to China through Malaysia and Singapore (US Department of Justice, 29 September 2026). The accusations concern chips, paperwork and money flows, not the publication of weights. Open weights may well prevail at the model layer. They prevail there because the model layer is no longer where control has to be exercised.
With K3’s weights public since 27 July, the file is everywhere permanently, and what remains controllable is where it may lawfully run. The weights already cross bloc lines: K3 serves inside American developer tools through third-party hosts. Who developed a model, who operates it, who hosts it and who holds the data are four different questions, and conditionality prices the combination rather than the artefact. The precedents are Huawei, TikTok and Kaspersky: in each, the artefact stayed obtainable while the state cut the transactions around it, procurement, distribution, updates and services. The constraint on extending that playbook economy-wide is arithmetic, because a general-purpose input into every firm’s cost base cannot be banned without repricing the index. So the trajectory runs through pricing and conditionality rather than prohibition. Between domestic restriction and any global effect sits the extension mechanism: alignment conditionality. No state polices weights worldwide. It conditions everything else on stack choice, chip allocations, capital, dollar clearing and market access bundled against alignment. The one input the bundle cannot price is efficiency. It travels in the weights and the papers, and the scarcity the controls created is the reason the efficiency exists at all. The existence proof is G42 in 2024: the Emirati AI champion divested its Chinese stack, took American capital and received chip access, alignment purchased as a package.
The leverage available varies sharply by region, which decides where conditionality bites first. Europe is already an absorber, running on a stack it does not produce, and aligns at low cost under American security guarantees. The Gulf pays for alignment and receives chips and capital in return, the G42 bargain generalised. India hedges commercially while its own rivalry with China settles the security question. Southeast Asia is the genuinely contested zone, with trade gravity running one way and security gravity the other. Latin America is dollar-dependent and programme-linked, which leans it American, with Belt and Road exceptions. Africa carries the lowest direct American leverage and the highest Chinese physical leverage, because the networks are installed, the debt is booked and the price signal already points east. American leverage over the continent is financial: dollar clearing, the correspondent banking beneath it, programmes and market access. Chinese leverage is physical and fiscal. The terminal squeeze is already visible in outline: a central bank holding its reserves in dollars while the network hardware beneath its banking system comes from entity-listed vendors. The stack decision gets made where those two leverages meet. The Gulf bought its seat with capital; nobody has yet offered Africa the G42 bargain, and no African balance sheet is sized to fund one.
Stage three is cross-border pricing on API-served intelligence, where a billing relationship gives either state a border to stand on, the exporter to price access, the importer to tax it. Stage four, the terminal stage, is a domestic productivity levy: a tax aimed at AI output itself, beyond the profits, wages and consumption the existing base already reaches. Digital services taxes are the nearest precedent, levies built to reach digital revenue that crossed borders untaxed. The four stages escalate from flow control to fiscal capture. Measurement is the obstacle at the end, and stage four is a scenario until AI output can be counted. Table 2 sets out the trajectory.
The trajectory carries a dated public record. The author’s 18 July posts called restrictions on cross-bloc model use, tariffs reaching AI and a patched distillation arbitrage; the Treasury Secretary’s post arrived four days later, and the September advisory followed.
The market has already run one full rehearsal of how resilient the buildout is to cheap challengers, and one echo of it. When DeepSeek’s R1 launched in January 2025, it triggered a selloff in which Nvidia lost roughly 17 per cent in a single session. That was about USD 590 billion of market value, and the Nasdaq fell about 3 per cent. Within months the sector had made new highs and capex guidance had risen. Eighteen months later, K3’s release produced the same alarm in Washington and the same non-response in capex. Even September’s frontier price cuts, which moved the model layer, did not move the buildout. Announced capital expenditure held through all of it. Contract lags, inference demand and plain error could each hold capex up for a season. On this essay’s reading the commitment answers to something steadier: a sovereign floor beneath the market. The floor does not abolish the fragility Part 1 priced; the fragility is what summons it, and who absorbs the fall when it arrives is Part 4’s question.
The open-weight wave sits inside a two-supplier market rather than outside it. Releasing the weights is the strategy of the vertically integrated: whoever owns the floors above and below the model can give the model away, because the margin does not vanish when the price does. It migrates to the floors they still own, down into silicon and cloud, up into applications (Palihapitiya, July 2026). Meta ran the play with Llama; Moonshot runs it with K3 from inside a national ecosystem holding far more of its own stack. The blunt version among founders holds that the model layer is the worst business in AI, and that the real money sits in compute, energy and applications. Without Chinese open weights, that argument runs, the American labs would have been comfortable oligopolies. The economics are right as far as they run. Worst margins and least power are not the same thing. The model layer still holds the customer relationship, the interface, the brand and the flow of data, which is why the fight over it runs fiercer than its margins alone would justify. When the model is free, the stack is the only thing left to own. The one floor where that migration favours Africa is the application layer, where Part 1 already found African firms at regional scale, and Part 3 prices it.
The self-custody rebuttal carries a 17-year control experiment. Bitcoin was built as the exit, and the protocol stays open. The flows do not. Spot ETFs moved exposure into custodial wrappers, the state’s embrace arrived as dollar stablecoins, and self-custody stayed large in holdings and marginal in flow while the institutional leg came to set price and policy. Expect the same settlement for open-weight intelligence. Self-hosting will stay legal and celebrated, and marginal, with the volume running through hosted endpoints inside compliance wrappers aligned to a bloc. The K3 release carries the shape in its own licence. Download and self-host freely; the licence reserves its conditions for model-as-a-service businesses at scale. A White House adviser now prescribes self-hosted AI as the citizen’s escape from the surveillance stack, in the same week his administration polices the stack’s border (Sacks, July 2026). The escape is real for whoever can fund the machine room. For everyone else, the third door opens back into the first two.
The state is tightening its grip on flows while the race loosens its grip on standards, and the two movements serve one logic. February’s Forced Choice traced it in diplomacy: China’s transactional offer, indifferent to governance, did not stay China’s, because strategic competition made the West transactional too. The same transmission now runs in AI. The coalition’s ascendant answer to being undercut by distillation has been to shed standards rather than defend them, over the resistance of the faction paying eight figures above to keep them. The loudest policy reaction to K3 came from inside the President’s own advisory council, and it was a call for fewer safeguards, not better ones (Axios, July 2026). Each side lowers its guardrails to stay in the race, which prices safety as drag, so the guardrail and the wall converge without either side choosing it. Africa inherits the risks of a race it never entered, without the institutions even the racers admit they lack.
The two stacks restrict different things. The Western models carry visible guardrails: contestable, sometimes wrong, but open to argument. The user can push, and the model engages. The leading Chinese models, in their hosted versions, return refusal on politically sensitive subjects, a closed door rather than a biased answer one can argue with. Hands-on tests days after DeepSeek R1’s January 2025 launch found it declining questions about June 1989 (Axios, 31 January 2025). The problem has a name in financial architecture: the capital account. A system whose operator narrows it whenever openness becomes uncomfortable can be used, even heavily, and never fully run on, which is the distance between CIPS settlement and reserve-currency scale. One stack offers a guardrail you can see and contest. The other offers a wall you cannot see until you walk into it. For African institutions choosing infrastructure, the distinction is practical: a bias one can contest against a silence one cannot.
Scale that distinction to a continent and it stops being a consumer choice. Run the default path forward. Chinese-dominated extraction and offtake already move the minerals, documented in The Cathode Economy. Chinese-dominated project financing already sits on the sovereign books, documented in Misaligned Transition. Chinese-built telecom and surveillance infrastructure already carries the continent’s networks. Add the intelligence layer by price default and the set completes: the minerals, the project debt and the networks already clear through one counterparty, and the thinking would clear through it too. A polity whose material base, credit, connectivity and cognition all clear through a single foreign counterparty has surrendered the substrate of independent policy, whatever its flag says. The terminal case has a working definition: a state that can no longer change suppliers, finance itself independently, audit the systems it runs on, or set policy without external permission. There is an old name for that arrangement, older than any stack, and vassal is not too strong a word for it. The epistemic clause should alarm the universities and the central banks most. A research infrastructure that returns silence on the counterparty’s own history is a map of reality curated by another state’s political survival. A generation of African analysis built on it inherits the curation invisibly. A model tuned to protect its state’s record is equally untrustworthy on that state’s lending, and the counterparty’s loans are what African debt analysis must examine. The exit the security section prices is real: strip the wall from self-hosted weights, run them against records the institution holds, and the curation lifts. The custody settlement above says how few will run that way, and hosted volume is where the curation binds. The dependency hardens into the walls of the room where the continent does its thinking. Today’s usage shares are the trajectory’s markers; the terminal case names where the trajectory ends if it is never priced.
Open weights carry a hazard that survives every discount of the interested parties who inflate it. Alignment is a training artefact, so publishing the weights publishes the removable version of the safety layer. A closed model’s refusal to write functional exploit code can be corrected centrally, for every user at once. An open model can be fine-tuned back out of that refusal in hours on rented compute. Mechanically that is the act the curation argument above prescribes; the difference is what the layer protects, a state’s record there, the public here. The reasoning from there is direction, not arithmetic. The population of capable attackers already exists, each irreversible release raises the capability available to it, and removability deletes the one term that suppressed what that population could do. Expected harm rises with every release even if no new intent is created anywhere, and it lands wherever defence is budget-gated.
The evidence comes from the governments themselves. A joint UK and US evaluation published on 23 July found that K3’s safeguards did not prevent it from attempting exploit development or offensive cyber operations. In a simulated network, with initial access granted and no defenders present, it completed a 32-step corporate attack chain in one attempt in ten (UK AISI and CAISI, 23 July 2026). Average progress ran to step 17, against 28.5 for the leading American models. To measure the American closed models at maximum capability, the evaluators had to disable their safeguards first, because the shipped versions refuse. One fence ships as a suggestion, and on 27 July those weights went public permanently. The uplift the officials name is overstated by those who profit from the fear, and it is not zero. The White House adviser’s own answer concedes the market it creates: gatekeeping does not work, so the only defence is AI-powered cyberdefence (Sacks, X, 18 July 2026). Offence arrives free with the weights. Defence arrives as an institution: staffed, integrated and paid for.
The asymmetry then runs down the reach gradient, and the forward case is a scenario, not a forecast. Attack capability diffuses toward the bottom of the market with each release, while defensive capacity, the engineers and the countermeasures, concentrates at the top. An attacker’s tool is written once and reused across many targets; each defender staffs its own wall. A decade of digitisation has put the continent’s banks, payment rails, registries and utilities online, while the defensive layer beneath them stays the thinnest in the system. Today’s leading open model still fails at the highest severity of exploitation and completes a full attack chain rarely rather than reliably. Each release has narrowed that distance while the guardrail convergence removes the brake on both stacks at once. This essay sets no date on what follows when a near-frontier model ships with removable safeguards into a defensive landscape that has not changed. The trajectory has a direction, and protection is becoming the terminal tier of this structure: safety sold as a premium subscription, with the institutions least able to fund defence digitising fastest.
On the American fight between open and closed, this essay takes no side on where the margin should sit. That is a fight over which floor holds it, and Africa sets the terms on no floor either way. Its judgement on the security ledger is separate. Its restriction trajectory is forecast, not endorsement: the bundle is predicted because incentives compel it. On the two stacks, the judgement is made from the African seat, and it is this essay’s ranking of failure modes. The American stack fails Africa through priced exclusion. The Chinese stack fails Africa through subsidised absorption. Exclusion is the more recoverable failure while access stays purchasable. A polity can buy, bargain or build toward alternatives at the layers Part 3 prices, over a build cycle, even as the cost compounds inside the window. June showed exclusion can also arrive as decree, which is why the test of any stack is continuity, auditability and credible exit rather than price alone. Absorption fails the harder test: a polity cannot think its way out of a curated map. That extends Part 1’s reach argument: where retrieval defines what an institution can know, curation decides what a polity can think, and no price does that. That ranking is why this essay can fault American gates and Chinese silence in the same breath without contradiction. The argument is not that Africa should choose a stack. It is that Africa should build a position, to own, tax or exit, through the five revenue lines Part 3 sets out, before it closes. Sovereignty of cognition is the item that is not for sale.
The next part, publishing alongside this one, leaves the politics for the ledger. It asks what Africa can actually charge the stack, what the mineral floor is really worth, and the five futures the whole structure has to survive.
Sources
Data cut-off: 6 October 2026. Part 2 of a four-part series; consolidated sources appear with Part 4.
Amodei, Dario, essay on a democratic AI coalition (June 2026).
Anthropic, policy statement on open weights and testing (27 July 2026).
Anthropic, Project Glasswing programme page (2026).
Axios, hands-on comparison of DeepSeek and ChatGPT (31 January 2025).
Axios, advisory-council reaction to K3 (July 2026).
Bloomberg, DeepSeek R1 market selloff (27 January 2025).
GitHub, Kimi K3 availability in Copilot via third-party hosting (August 2026).
Kurzgesagt, documentary account of the July agent incident (5 October 2026).
Microsoft AI for Good Lab, chatbot usage mapping (January 2026).
Microsoft and G42 reporting on the 2024 divestiture-for-access arrangement (2024).
Moonshot AI, Kimi K3 licence terms (July 2026).
NBC News and UPI, reporting on the Hugging Face intrusion and OpenAI’s incident report (August 2026).
New York Times, AI network midterm spending tracker (29 September 2026).
NSA, CISA and FBI, joint advisory on distillation of US frontier models (8 September 2026).
Onyambu, Dean, The Forced Choice, The Cathode Economy and Misaligned Transition, Canary Compass (2026).
Onyambu, Dean, X and LinkedIn posts on model restrictions and the distillation arbitrage (18 July 2026).
OpenAI, incident report on the July agent episode, with METR and Redwood Research (26 August 2026).
Palihapitiya, Chamath, on open-weight margin migration (July 2026).
Reuters and TimesLIVE, Microsoft Africa AI training pledge (January 2025).
Reuters and Xinhua, World AI Cooperation Organization founding agreement, 29 signatories (16 July 2026).
Reuters, European Parliament remarks on American infrastructure, and the State Department cable on kill-switch talk (22 July 2026).
Reuters, US appeals court declines to block Pentagon’s blacklisting of Anthropic (25 September 2026).
Sacks, David, X posts on self-hosting and cyberdefence (July 2026).
SCMP and Xinhua, World AI Cooperation Organization announcement (17 July 2026).
Techweez, reporting on the Semiconductor Technologies facility in Nyeri (3 February 2026).
UK AI Security Institute and US CAISI, joint evaluation of Kimi K3 (23 July 2026).
US Department of Justice, indictment for smuggling export-controlled AI servers to China, as reported (29 September 2026).
US federal agency directives restricting DeepSeek, and the No DeepSeek on Government Devices Act (2025).
US Trade and Development Agency, Kenya semiconductor partnership grant (May 2024).
US Treasury and State Department statements on distillation and model restrictions, as reported by Reuters (July 2026).
Wall Street Journal, reporting on open-model policy, political spending and Chinese model usage (21 and 23 July 2026).
Disclaimer
This article does not constitute legal, financial, or investment advice. The author shares views for perspective and discussion only. Do not rely on them as a substitute for professional advice tailored to your specific circumstances. Always consult a qualified legal, financial, investment, or other professional adviser before making decisions based on this content. The analysis reflects proprietary research undertaken by Canary Compass and the author.
Canary Compass and the author accept no liability for actions taken or not taken based on the information in this article.
The views expressed in this article represent the author’s independent professional analysis and do not constitute an endorsement of any individual, institution, or position. Canary Compass and the author accept no responsibility for how this content is interpreted, excerpted, or recontextualised by third parties not involved in its production and publication. Reproducing any portion of this work in isolation, or in combination with other material, in a manner that misrepresents the author’s original meaning constitutes a distortion of the published record.
The author may hold positions in financial instruments, currencies, or assets discussed or referenced in this publication. Such positions do not constitute a recommendation to buy or sell.
All views, projections, and forecasts reflect the author’s assessment at the time of writing. Data sourced from third parties is believed to be reliable but has not been independently verified. Past performance does not indicate future results.
All content published by Canary Compass is the intellectual property of the author. Reproduction, adaptation, or redistribution, in whole or in part, requires written permission.
About the Author
Dean N. Onyambu is the Founder and Chief Strategist of Canary Compass, a financial research publication focused on African monetary architecture and financial sovereignty. He brings 18 years of experience across trading, fund leadership, and economic policy, with senior roles at Standard Bank, First Capital Bank, and Opportunik Global Fund.
Read and subscribe at www.canarycompass.com.
The Canary Compass Channel is available on @CanaryCompassWhatsApp for economic and financial market updates on the go.
For more insights from Dean, you can follow him on LinkedIn @DeanNOnyambu or X @InfinitelyDean.



