← Marizanne Knoesen

Essay

Reality Infrastructure

On the intersection of AI and modern mercantilism: who owns the AI systems that decide, and the risk of renting them.

Introduction

What separates states over the next decade will not be GDP so much as position: whether a country owns the AI systems that decide its economic life, or rents them from someone who does, and whose version of reality it ends up running on.

I call that layer reality infrastructure. Traditional infrastructure moves goods; reality infrastructure moves decisions. It is the set of systems, now increasingly AI systems, through which economic and social life becomes legible and actionable, and which decide who gets capital, scrutiny or help. Control of it has become a strategic priority for great powers.

This is occurring alongside a broader shift from open, liberal globalism to modern mercantilism1: a more competitive, zero-sum world in which states intervene to secure wealth and self-sufficiency by avoiding trade deficits, protecting strategic industries, securing critical supply chains, and using trade, technology and market access as instruments. Because AI is both the prize and the mechanism of this new mercantilism, it is accelerating the shift while also becoming the principal arena of competition. States therefore play both defensively and offensively: they build and protect their own reality infrastructure, and they try to wreck their rivals'.

AI as reality infrastructure: the new prize for modern mercantilists

Reality infrastructure shapes which options are presented, which risks are surfaced and which actions get taken. When a firm is dropped from an AI's answer, a loan is refused in milliseconds, or an applicant is screened out before a recruiter sees the file, the system has decided something. At the frontier, some consequential decisions are already executed by AI without routine human review, while others are increasingly AI-assisted (Table 1).

Reality infrastructure does not replace institutions; it becomes the layer through which institutions see the world and act on it. Governments therefore do not treat AI as just another technology. The obvious appeal is growth: AI is the general-purpose engine of the next economy. But growth is something many states can share in. What a mercantilist fights to control is who owns the pie, how the slices are divided, and who is left depending on others' crumbs. This is why every serious state wants to own its reality infrastructure rather than rent it. The strategic logic plays out differently across countries: the U.S. ties it to military and technological primacy2, China to national rejuvenation3, and the Gulf states to diversification beyond oil4.

In a world of reality infrastructure, the rents move. Where they once accrued to cheap labour and raw materials, they now accrue to compute, data and the talent that builds these systems. Owning that layer is the new basis of national advantage. States here are playing for position. Buying the capability from whoever already makes it best is always cheaper, and no company answering to shareholders would do otherwise. But the cheaper option leaves the AI systems that decide your economy in someone else's hands, and a capability you rent is one the landlord can withdraw. Sovereignty now turns on whether you own the AI systems that decide your reality, or rent them from someone who does.

Each system in Table 1 decides an outcome that matters to mercantilist states, except now an AI makes the call.

SystemWhat it doesHow it applies to modern mercantilism
U.S. Customs Runs AI scoring to flag forced-labour supply chains5,6, and is moving to extend that scoring to tariff-dodging transshipment7. Decides which goods and firms reach the domestic market, shielding home industry and enforcing trade-law and forced-labour bans against rivals.
Silent Eight Silent Eight uses AI to investigate and adjudicate sanctions and restricted-party alerts in payment flows8 in real time, automatically clearing non-material matches and escalating higher-risk cases for review. Permission to transact across borders is decided by a model: sanctions and entity-list logic executes continuously at machine speed, rather than through sampled review or after-the-fact penalties.
Upstart AI underwriting9 that automates credit allocation, shifting effective control over who gets credit from the bank's loan officers to the model. The model sets which firms and households get capital and on what terms, concentrating control over national credit access. This determines capital flows, shaping which firms grow and which industries prosper.
Google AI Overviews AI Overviews and AI Mode10 synthesise a single answer that includes or omits a given business, increasingly replacing the click11 to the source. The synthesised answer effectively decides whether a firm is visible at all, the simplest manifestation of reality infrastructure; states now regulate and pressure this mechanism.

Table 1. Reality infrastructure: AI that decides. The firms aren't mercantilists; the mercantilist function has migrated into their decision layers. The first two are state functions and the mercantilist claim is strongest there. The second two are commercial decisions with economy-wide consequences; they matter because the same logic is already operating where the state has not yet reached, and therefore has every incentive to.

AI as the mechanism of mercantilist enforcement: the algorithmic operating system

Mercantilist rules used to be enforced by institutions: customs officers, bank compliance departments, export-control desks. Those institutions are finite. A state could only execute as much policy as its inspectors could physically check. AI removes that ceiling. Measuring turns into monitoring, and monitoring into enforcement that runs on its own, at volumes no bureaucracy could handle. Customs scoring and sanctions adjudication now both run inside the flow they police, assessing filings and payments as they arrive rather than sampling them afterwards.

The effect is that the rules of economic life migrate out of institutions and into how the systems are built. This raises the stakes of a second contest: not just who has the most compute and chips, but whose values and rules get built into the systems that are exported. To export an AI system is to export a way of governance.

Defensive actions: building and protecting your own reality infrastructure

Securing the physical and data foundations

A country that depends on foreign compute is exposed. Hence the scramble for sovereign compute: Canada's12 $1bn programme, the UK's fab purchase13, the UAE's Falcon14. But most of this “sovereign” AI still runs on foreign, mostly U.S. technology. Around 70% of the 130-plus national infrastructure and model projects tracked by the Sovereign AI Index15 lean on at least one foreign partner, and four out of five of those involve a U.S. firm (Figure 1). The foreign provider can still restrict or switch off the capability: the spending buys the appearance of independence, not the substance. And compute is of no use if your data sits elsewhere, so states are fencing in data too, through localisation rules, sovereign clouds and limits on transfers16.

Pie chart showing the foreign-partner breakdown of national sovereign AI projects: U.S. partner 56%, no disclosed foreign partner 31%, other foreign partner 8%, both U.S. and Chinese partners 3.2%, Chinese partner 2.4%.
Figure 1. Countries seeking sovereign AI rely heavily on American technology. Covers national infrastructure and model projects only. Source: CNAS Sovereign AI Index.

But none of it runs without power. Compute's binding constraint is electricity17. A frontier training cluster draws power on the scale of a small city onto grids never built for it, so a state cannot build sovereign compute without securing huge, reliable power and the grid to carry it. That pulls mercantilist governments straight into energy markets, treating electricity as a national-security input. The grid now sets the pace for how fast any of this gets built.

Because no serious state will rent a rival's stack, the world is building parallel fabs, clusters and grids that a purely efficient market would never construct. The result is a vast capex boom18, private money at the frontier and state money in the sovereign programmes, driving up the price of power, memory and materials.

Governance of reality infrastructure

Governance decides how much freedom AI companies have, who else gets to use AI, and on what terms. It works on three levels. The first is physical, through the hardware: U.S. export controls can reach Chinese firms and their subsidiaries outside China19 (Figure 2), and they bite for one reason: the U.S. and its allies retain a near-monopoly over the critical semiconductor manufacturing tools. ASML20 makes essentially every EUV machine needed for leading-edge chips, while TSMC21 produces more than 90% of the world's most advanced logic chips. The leverage extends beyond restricting exports: in 2025, for the first time, the U.S. tied export licences to a revenue share22, taking 15% of Nvidia and AMD's China sales. The second level is the models themselves: in 2026, when a U.S. order barred foreign nationals23 from Anthropic's most capable models, the company switched them off for everyone24, restoring them under three weeks later once the Department of Commerce lifted the controls. Control reaches all the way to the trained system, and works as a dial that someone else's government is holding. The third level is rules as barriers. The EU AI Act25 makes Europe expensive to enter through risk-tiered compliance, documentation and oversight duties backed by fines of up to 7%26 of global turnover, while China's CAC requires generative models to align with “Core Socialist Values,”27 policing what models may present and be. Both make market access conditional on adopting a bloc's rules.

Timeline from 2010 to 2025 comparing United States and China export-control actions, colour-coded by instrument: prohibitions, export restrictions, the Foreign Direct Product Rule, entity lists, informal statecraft, licence requirements, legislation, extraterritorial measures, tariffs and end-use export restrictions.
Figure 2. China and the U.S. use of export controls: legislation and restrictions on matters and goods of strategic importance, 2010–2025. Source: IISS, simplified and recreated from the original.

Who is governed is itself shifting. Mercantilism once worked through state-chartered monopolies such as the East India Companies. Today the state leans on private giants instead: Nvidia, Microsoft and TSMC, firms that hold more compute and model capability than most countries but answer to shareholders rather than governments. Expect states to keep bringing private AI capacity under greater public control, and increasingly into public ownership, closing the gap between the infrastructure they depend on and the infrastructure they command. The shift is already visible: in 2026 Senator Bernie Sanders proposed a one-time 50% stock tax28 on major U.S. AI firms, with the shares deposited into a sovereign wealth fund, while the Trump administration has separately explored taking equity stakes29, alongside golden shares, licensing conditions and revenue-sharing. Ownership matters because it fuses interests: a government that owns Nvidia stock has every reason to support its chip sales abroad, much as states once backed their chartered trading companies.

Offensive actions: degrading someone else's reality infrastructure

States do not only build their own reality infrastructure; they also degrade their rivals'. There are three attack layers, used independently or in combination, ordered below from the most direct.

Target layerMechanismExampleWhat it degradesHow it weakens the rival
Breach the systems Machine-speed intrusion aimed at the systems themselves: AI scouts, writes exploits, harvests credentials and exfiltrates data. Anthropic in 2025: a Chinese state group ran30 Claude Code for 80–90% of an intrusion against ~30 targets across tech, finance and government. The systems a modern economy and state run on. Steal what you can't build, e.g. IP and data. Degrade the functioning of the rival's decision systems. You gain capability and deny theirs.
Poison what feeds them No breach required: flood the information field AI systems ingest with AI-generated content, fake personas and spoofed sites. The US DOJ's 2024 seizure31 of 32 domains tied to Russia's “Doppelganger” operation. The information the systems work off, causing people and machines alike to act on a corrupted picture of reality. The rival's systems act confidently on false inputs while the manipulation lasts: wrong decisions at machine speed and scale.
Break the trust that turns outputs into decisions Make authentic outputs harder to trust. Whether through one-off fabrications or the cumulative effect of breaches and poisoning, even genuine outputs become unsafe to act on without verification. In 2024 an employee of the engineering firm Arup authorised32 fifteen transactions totalling roughly US$25m after a video call in which every other participant was a deepfake. The loss was not the point; the point is that a video call stopped being self-authenticating, and every firm now has to pay to establish and authenticate what used to be free and trusted. The trust that turns outputs into real-world economic and operational decisions. Once doubt sets in, everything gets a verification tax: tighter thresholds, more human review, slower transactions, higher risk premia. Decisions get costlier and slower economy-wide.

Table 2. Degrading a rival's reality infrastructure: three layers of attack. The examples are early instances: attacks on today's systems, information and trust. As decisions migrate into AI (Table 1), the same three layers carry more of the economy, and the payoff of each attack compounds.

None of the three requires matching a rival at the frontier. Degrade the system, the information it runs on, or the trust that allows its outputs to be acted upon, and you raise a rival's cost of capital without building anything of your own. The mechanism runs back through the decision machines in Table 1. Breach the systems and the decision machines are degraded at the source. Poison the information they ingest, and the automated underwriter or the border-screening engine works off a corrupted picture, so its outputs can no longer be trusted without verification.

The rational response is to widen the margin of safety: higher risk premia, tighter approval thresholds, slower decisions, more human review of what was meant to be automatic. Do this across lending, trade and payments and borrowing costs more, transactions clear slower, and productivity stalls. The damage is macroeconomic. That is the ultimate edge of the offensive move, and the asymmetry is stark: degrading a rival's reality infrastructure costs a fraction of building your own. So the states that cannot build at the frontier reach for degradation instead. China is the exception, a frontier builder that also degrades; for Russia, Iran and North Korea, degradation is the primary lever33. Polluting the shared information space corrodes the attacker's own environment too, but that cost falls hardest on countries most plugged in and most answerable to their publics, which is exactly what the main wielders are not. Open, integrated economies are the main victims: cyberattacks, disinformation and digital disruption become a cheap-to-inflict cost aimed at them.

Who wins and who loses

The physical foundations of AI remain concentrated in a small number of firms and countries. The larger question is whether reality infrastructure itself stays concentrated, or whether open models, cheaper training and wider access to compute erode that concentration over time.

The answer changes who collects the rent, not whether rent is collected. If concentration persists, the U.S. and its national champions own the full stack and set the terms of access, with TSMC and ASML indispensable beneath them and the enablers, e.g. grids and cyber, riding the build-out. The ~70% renting foreign infrastructure lose at every layer at once.

If open models reach durable parity, the model layer commoditises, and that is a loss for exactly the firms whose valuations rest on it. But the rents do not disappear; they migrate downwards to the layer that cannot be copied. Chips, fabs and power become more valuable, not less, because they become the only scarce thing left. So parity is worse for today's model champions and better for the renters, though only at one layer: their dependence narrows rather than ends, and what remains of it is the part that takes a decade and a national budget to replace. Under either branch, open and integrated economies remain the cheapest degradation targets.

What separates states in the next decade won't be GDP so much as position: whether a state owns its systems or just rents them, and whose version of reality it ends up running on.

References

  1. Bridgewater Associates (2026a) Global outlook: our CIOs on modern mercantilism, AI, and managing money today. YouTube. Available at: youtube.com (Accessed: 7 September 2026).
  2. White House (2025) America's AI action plan. Available at: whitehouse.gov (Accessed: 7 September 2026).
  3. State Council of the People's Republic of China (2017) New generation artificial intelligence development plan. Translated by DigiChina. Available at: digichina.stanford.edu (Accessed: 7 September 2026).
  4. Center for Strategic and International Studies (2025) The United Arab Emirates' AI ambitions, 24 January. Available at: csis.org (Accessed: 7 September 2026).
  5. United States Customs and Border Protection (2026) Uyghur Forced Labor Prevention Act, 17 June. Available at: cbp.gov (Accessed: 7 September 2026).
  6. Gold, A. (2023) 'AI startup Altana wins DHS contract', Axios, 20 July. Available at: axios.com (Accessed: 7 September 2026).
  7. United States Customs and Border Protection (2026) Heightened import disclosures for supply chain visibility. Advance notice of proposed rulemaking, Docket No. USCBP-2026-1058, Federal Register, 2 September. Available at: federalregister.gov (Accessed: 7 September 2026).
  8. Silent Eight (2026) Payment screening suite. Available at: silenteight.com (Accessed: 7 September 2026).
  9. Upstart (2026) Upstart. Available at: upstart.com (Accessed: 7 September 2026).
  10. Google (no date) AI Overviews and AI Mode. Available at: search.google (Accessed: 7 September 2026).
  11. Fishkin, R. (2026) 'In 2026, less than one third of Google searches still send a click', SparkToro, 8 June. Available at: sparktoro.com (Accessed: 7 September 2026).
  12. Innovation, Science and Economic Development Canada (2026) Canadian sovereign AI compute strategy, 4 June. Available at: ised-isde.canada.ca (Accessed: 7 September 2026).
  13. Ministry of Defence (2024) UK defence supply chain bolstered to support armed forces, 27 September. Available at: gov.uk (Accessed: 7 September 2026).
  14. Technology Innovation Institute (no date) Falcon LLM. Available at: falconllm.tii.ae (Accessed: 7 September 2026).
  15. Center for a New American Security (2026) Sovereign AI Index. Available at: interactives.cnas.org (Accessed: 7 September 2026).
  16. Cory, N. and Dascoli, L. (2021) How barriers to cross-border data flows are spreading globally, what they cost, and how to address them. Information Technology and Innovation Foundation, 19 July. Available at: itif.org (Accessed: 7 September 2026).
  17. International Energy Agency (2025) Energy and AI. Available at: iea.org (Accessed: 7 September 2026).
  18. Bridgewater Associates (2026b) The macro implications of the AI capex boom. Available at: bridgewater.com (Accessed: 7 September 2026).
  19. Congressional Research Service (2025) Export controls and the semiconductor supply chain. Report R48642, 19 September. Available at: congress.gov (Accessed: 7 September 2026).
  20. Nicol-Schwarz, K. (2026) 'AI boom: Nvidia, ASML and the Dutch chip equipment maker behind lithography', CNBC, 29 January. Available at: cnbc.com (Accessed: 7 September 2026).
  21. Klingler-Vidra, R. (2026) 'How Taiwan came to dominate the global chip industry', The Conversation, 1 April. Available at: theconversation.com (Accessed: 7 September 2026).
  22. Shapero, J. (2025) 'Nvidia, AMD strike China chip revenue-sharing deal with the White House', The Hill, 8 December. Available at: thehill.com (Accessed: 7 September 2026).
  23. Center for Strategic and International Studies (2026) Department of Commerce restricted access to Anthropic's latest models: what comes next. Available at: csis.org (Accessed: 7 September 2026).
  24. Anthropic (2026) Fable and Mythos access. Available at: anthropic.com (Accessed: 7 September 2026).
  25. European Union (2024) Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union, L 2024/1689. Available at: artificialintelligenceact.eu (Accessed: 7 September 2026).
  26. European Union (2024) Article 99: Penalties, in Regulation (EU) 2024/1689 (Artificial Intelligence Act). Available at: artificialintelligenceact.eu (Accessed: 7 September 2026).
  27. Butts, D. (2024) 'Chinese regulators begin testing generative AI models on socialist values', CNBC, 18 July. Available at: cnbc.com (Accessed: 7 September 2026).
  28. Beggin, R. and Ovide, S. (2026) 'Bernie Sanders proposes wealth fund to give Americans a stake in AI', Washington Post, 18 June. Available at: washingtonpost.com (Accessed: 7 September 2026).
  29. Rozen, C. (2026) 'Three ways Trump could get a stake in AI firms', Reuters, 22 June. Available at: reuters.com (Accessed: 7 September 2026).
  30. Anthropic (2025) Disrupting AI espionage. Available at: anthropic.com (Accessed: 7 September 2026).
  31. United States Department of Justice (2024) Justice Department disrupts covert Russian government-sponsored foreign malign influence operation. Available at: justice.gov (Accessed: 7 September 2026).
  32. Magramo, K. (2024) 'Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee', CNN, 16 May. Available at: cnn.com (Accessed: 7 September 2026).
  33. OpenAI (2024) Disrupting malicious uses of AI by state-affiliated threat actors. Available at: openai.com (Accessed: 7 September 2026).

Figure sources

  1. Figure 1. Center for a New American Security (2026) Sovereign AI Index. Available at: interactives.cnas.org (Accessed: 7 September 2026).
  2. Figure 2. International Institute for Strategic Studies (2025) China's use of export controls, February. Available at: iiss.org (Accessed: 7 September 2026).