2025 Conference on International Cyber Security | 4-5 November 2025
Register now

Chenghao Sun

Who Controls Cyber Power? Frontier AI Firms and the Privatization of Strategic Gatekeeping

As frontier AI becomes increasingly embedded in cybersecurity, intelligence analysis, military command systems, and critical infrastructure protection, the control of cyber power is no longer exercised solely by states. This paper argues that frontier AI firms are emerging as strategic gatekeepers: they control access to models, compute, cloud infrastructure, safety evaluations, cyber benchmarks, and deployment rules that increasingly shape the distribution and use of cyber capabilities. Recent studies suggest that frontier AI may initially benefit attackers more than defenders in cybersecurity, while also creating new opportunities for automated defense and resilience. This dual-use ambiguity gives private firms unusual authority to decide when capabilities are released, restricted, monitored, or aligned with state security priorities.The paper develops the concept of “privatized strategic gatekeeping” to explain how AI companies mediate between market incentives, national security demands, and international cyber stability. It examines three mechanisms: capability gatekeeping, through model access and cyber-safety testing; infrastructural gatekeeping, through cloud, compute, and platform dependencies; and geopolitical gatekeeping, through firms’ selective alignment with governments, defense agencies, and allied technology blocs. Rather than replacing states, these firms reshape how states exercise cyber power by creating new dependencies and chokepoints.By linking frontier AI governance with debates on digital sovereignty, cyber diplomacy, and strategic stability, the paper contributes to the conference theme of a “digital state of nature.” It shows that the central question is not only how states regulate AI firms, but how these firms increasingly regulate the strategic possibilities available to states.