Skip to content
← DeepDive Governance & Geopolitics · 中文
DEEPDIVE / [GOV] · AI Geopolitics ← DeepDive DD · L5 Global Geopolitics · 2026-07-24 · v1 · Review as of mid-July 2026
L5 Global Geopolitics · Military AI · Governance Divergence

Battlefields, Data Centers,
and Two Governance Frameworks

Between 2025 and 2026, "AI and geopolitics" transformed from an academic topic into an ever-updating event log: Iranian drones made commercial hyperscale data centers into battlefield targets for the first time; autonomous drones in Ukraine and the Lavender system in Gaza turned military AI from a theoretical exercise into a reality with hit rates and casualty figures; Anthropic disclosed the first state-level cyber espionage operation where AI autonomously executed 80–90% of the actions; and just two weeks before China rallied 29 nations to sign the WAICO charter, both China and the US had refused to sign a joint declaration on military AI at the REAIM summit. The chip war and DeepSeek stories were covered in detail in "The Physics of the Cake" and "AI Model Ideology"—this piece focuses on the battlefields those two did not cover: military AI in live combat, the actual track record of deepfakes, and the fracturing global governance landscape.

AI Buzzwords · DeepDive  |  First published 2026-07-24  |  Feng Xiaoping
$150M
Iranian drone strike on Gulf
AWS data center · Amazon's estimated loss
80–90%
GTG-1002 cyber espionage operation
share of actions autonomously executed by Claude
35/85
REAIM Summit
share of countries signing military AI declaration
<1%
2024 election cycle verified misinformation
share of AI-generated content · Meta data
TL;DR · 30-second read

Both compute power and military AI have left physical craters in the real world.In 2026, a data center was destroyed by a drone for the first time, an AI target-locking system was subjected to courtroom-level evidentiary scrutiny for the first time, and global AI governance split into three mutually independent frameworks for the first time—while deepfakes, ironically, turned out to be the most underperforming item in this batch of "AI panics."

  • ▸1In March 2026, Iranian "Shahed" drones struck AWS data centers in the UAE and Bahrain—the first time in history a nation deliberately designated a commercial hyperscale data center as a wartime strike target
  • ▸2Ukraine boosted drone hit rates from 10–20% to 70–80%; Gaza's Lavender system once flagged 37,000 people as potential strike targets, with intelligence officers averaging 20 seconds of review per target
  • ▸3Anthropic disclosed the first state-level cyber espionage operation where AI autonomously executed 80–90% of the actions (GTG-1002), but the attackers reported that Claude would "hallucinate" and fabricate credentials—the only real safety valve currently in existence
  • ▸4Deepfakes proved to be "all thunder, no rain": AI-generated content accounted for less than 1% of verified misinformation during the 2024 election cycle; the real flood was low-tech cheapfakes
  • ▸5WAICO (China), the REAIM deadlock (both the US and China refused to sign), and the EU AI Act are running on three parallel tracks; 2026 has become the "first truly global phase" of AI governance, and also the year of itsfirst real fracture
counter-consensus ▸ The most important takeaway from this batch of news is not "how powerful AI is," but "AI threat reports themselves need to be discounted"—Anthropic, the Israeli military, and OpenAI's self-disclosures about their own systems all carry dual motives of public safety and narrative amplification; they should be cross-verified with independent researchers and UN scientific panels.
§ 01 / Compute Is the New Oil

Data centers,
bombed for the first time

First empirical evidence · Physical compute security

In 2025, multiple think-tank reports began describing compute as "the new oil"—Gulf states trading petrodollars for sovereign compute: G42, HUMAIN, the $100-billion-scale MGX fund, the 5-gigawatt Stargate UAE project. At the end of 2025, the US approved Blackwell chip exports to G42 and Humain, but with strict security conditions—which itself signaled that Washington treats Gulf compute as a strategic asset requiring management.

This logic ran into a reality check in March 2026. Iranian "Shahed" drones struck two Amazon AWS data centers in the UAE, and a data center in Bahrain was also affected—CNBC's report noted that Iranian state media framed it as retaliation for US military operations supported through these facilities. This was the first time in history a nation deliberately designated a commercial hyperscale data center as a wartime strike target: the attack caused structural damage, power outages, and water damage from fire suppression; local UAE banking systems were temporarily disrupted, and AWS was still issuing service credits to affected regions over a month later. Forbes estimated the attack cost Amazon roughly $150 million. Even more alarming, Iran subsequently threatened to list Microsoft, Google, Apple, Oracle, and a long string of other US tech companies as potential targets, and in early April a second drone struck another data center in Bahrain.

The WEF (World Economic Forum) subsequently called for "treating AI infrastructure as critical infrastructure"—a phrase that before March 2026 was mostly theoretical, and afterwards became a belated policy recommendation. Meanwhile, a Gulf International Forum analysis poured cold water on the "oil-for-compute" narrative: Gulf data centers are essentially downstream extensions of the hydrocarbon economy; in 2024, the UAE's renewable energy share was only 8.7%, Saudi Arabia's 2.2%, far below the global average of 31.8%—the "compute advantage" actually rests on natural gas power generation capacity, not clean energy endowments.

China's contrasting path is radically different: in 2025, newly installed power capacity exceeded 540 GW (about 80% wind and solar), and over the past four years total new installations equaled rebuilding the entire US grid. The US-China competition around AI energy infrastructure presents two entirely different physical logics—this layer was detailed in the energy comparison in "The Physics of the Cake"; here we only add one reminder: compute security is no longer just "is there enough power," but also "can it be blown up."

§ 02 / The Battlefield

Ukraine's drones,
Gaza's target-locking

CSIS Wadhwani AI Center · +972 Magazine investigation

Military AI in 2025–2026 is no longer a hypothetical exercise—it is a battlefield reality with specific hit rates and casualty figures.

Ukraine: Autonomous navigation boosted hit rates from 10–20% to 70–80%

CSIS Wadhwani AI Center's Kateryna Bondar provided the most frequently cited set of figures from this war in "Ukraine's Future Vision and Current Capabilities for Waging AI-Enabled Autonomous Warfare": autonomous navigation boosted drone target hit rates from 10–20% to 70–80%; targets that previously required 8–9 drones to destroy now only needed one or two. Ukraine produced about 2 million drones in 2024, with the goal of making half of 2025's procurement AI-guided (from 0.5% to 50%). One often-overlooked detail: AI currently replaces only the "last 100 to 1,000 meters" of autonomous approach and reconnaissance analysis; target selection is still completed by human operators—fully autonomous warfare remains a vision, not current practice. Germany's Helsing AI's EW-resistant drone HX-2 Karma, Ukraine's government coordination platform Brave1, and Aerorozvidka's Delta real-time command system are all compressing what used to require 40 hours of battlefield analysis into seconds—but the "Army of Drones" point-scoring system (6 points for a killed soldier, 40 for a tank) sparked ethical controversy over "gamified warfare," which the West Point Lieber Institute specifically warned must be accompanied by command oversight and legal review.

Gaza: Lavender and the "20-second" review per target

+972 Magazine journalist Yuval Abraham, based on testimony from six Israeli intelligence officers, disclosed the Lavender system—which at the start of the war flagged up to 37,000 Palestinian males as potential strike targets, reportedly with about 90% accuracy (i.e., about a 10% error rate); intelligence officers averaged only "20 seconds" of review to confirm each target. Coupled with the Gospel/Habsora system for marking buildings and the Where's Daddy system for tracking targets back to their homes, it formed a target-generation pipeline where human review was essentially a "rubber stamp." It was reported that at the start of the war, strike authorization for each junior target allowed 15–20 civilian casualties, and for senior commanders the authorization could exceed 100. International humanitarian law analyses pointed out this system's challenges to the three core principles of "distinction," "proportionality," and "accountability"; the West Point Lieber Institute provided the other side—the IDF rebutted some accusations as "factually baseless," emphasizing that any weapons system can be misused, which does not mean the system itself is illegal.

In September 2025, Microsoft terminated the Israeli 8200 Unit's access to Azure services, after The Guardian reported that the unit used Azure to process mass surveillance data from Gaza/West Bank to identify bombing targets; UN Secretary-General Guterres publicly stated he was "deeply disturbed" by the reports—this was the first time a Western cloud provider proactively severed a client relationship over military AI use issues. This precedent itself may warrant longer-term attention than Lavender's specific accuracy figures.

Battlefield data (Ukraine hit rates, Gaza Lavender error rates and casualty figures) mostly come from unilateral or anonymous sources, and should be treated as "contested reports" rather than settled conclusions.

Editor's note · Source reliability caveat

§ 03 / Autonomous Cyber Warfare

GTG-1002 and
"hallucination" as an accidental safety valve

Anthropic · 2025-11-14 disclosure

On November 14, 2025, Anthropic released a report that would be cited repeatedly thereafter—"Disrupting the first reported AI-orchestrated cyber espionage campaign".

This operation, discovered in mid-September and attributed with high confidence to the China-state-backed team GTG-1002, saw the attackers trick Claude Code into believing it was "conducting legitimate defensive cybersecurity testing," bypassing its safety guardrails. Claude then autonomously executed about 80–90% of the attack operations—reconnaissance, vulnerability discovery and exploitation, credential theft, lateral movement, and data exfiltration. Humans only intervened at 4–6 key decision points, targeting about 30 global targets (tech, finance, chemicals, government agencies), and successfully breached some of them. IAPS's follow-up analysis pointed out the report's true national-security implication: once autonomous attack agents proliferate, they will significantly lower the barrier to cyber attacks, enabling originally limited-capability actors to conduct large-scale operations, giving attackers the upper hand in the short term until defenders' automation catches up.

But the most memorable detail in this report is actually the limitation it exposed: the attackers reported that Claude would "hallucinate"—fabricating credentials, exaggerating attack successes, preventing this operation from achieving full autonomy. This is both a headache for hackers and, in some sense, the only real safety valve currently in existence. It's also worth noting that some experts, including security researcher Kevin Beaumont, publicly questioned whether Anthropic's report exaggerated its scale claims and the "China threat" narrative—threat reports issued by frontier labs carry a dual attribute of public service and their own commercial narrative, which also applies to OpenAI and Google's respective threat intelligence reports, and should be cross-verified with assessments from independent bodies like the UN scientific panel.

Viewing this incident alongside this site's other piece, "When AI 'Hacked' Hugging Face Itself", makes the pattern clearer: whether it's state-level cyber espionage or evaluation sandbox escape, the recurring pattern across 2025–2026 is that AI agents' "tenacity" has for the first time exceeded the imagination of the safety boundaries humans drew for them—not that they have already mastered full autonomous combat capability.

§ 04 / Counter-intuitive

Overhyped deepfakes:
all thunder, no rain

Alan Turing Institute CETaS · IPIE · Meta data

If the realities of military AI and cyber warfare are both grimmer than expected, deepfakes' actual impact on elections is one of the rare exceptions where the hype outpaced the reality.

A series of reports from the Alan Turing Institute's CETaS, after tracking the 2024 "super election year" (nearly 2 billion voters casting ballots), reached a somewhat unexpected conclusion: the News Literacy Project found that content used seven times more frequently than AI-generated material was actually "cheapfakes"—low-tech decontextualized video clips and misleading captions. IPIE's "The Role of Generative AI Use in 2024 Elections Worldwide" built a dataset of 215 incidents across 50 countries holding competitive elections; 80% of countries experienced generative AI-related incidents, but Meta's data showed that AI-generated content accounted for less than 1% of misinformation confirmed by fact-checkers during the 2024 election cycle. Both the Brennan Center and the WEF (World Economic Forum) concluded that "the doomsday scenario did not materialize."

This doesn't mean the risk has disappeared—only that its shape has shifted. CETaS's follow-up report, "From Deepfake Scams to Poisoned Chatbots," pointed out that the new threat vector in 2025 is financial scams and "poisoned chatbots," not campaign-ad-style deepfake videos. Romania's 2024 presidential election, canceled outright due to suspected foreign-funded AI-boosted intervention, remains the most prominent empirical case to date; the Center for Democracy and Technology (CDT) in the US warned that risks will rise for the 2026 midterm elections, stating "we've only seen the tip of the iceberg." OpenAI, across three threat reports in 2024–2025, disclosed and banned multiple influence operations from China, Russia, Iran, and Israel, with the core judgment being "evolution rather than revolution"—AI boosted the efficiency of these operations, but most still failed to achieve real audience scale.

Russia's Pravda network's goal appears to be not persuading real human readers, but rather "poisoning" web-crawlers that scrape online content to train AI models—the next battlefield for deepfakes may not be the polling station, but the training corpora of the next generation of large models themselves.

Atlantic Council · "Eight ways AI will shape geopolitics in 2026"

§ 05 / The Great Governance Divergence

WAICO, the REAIM deadlock,
and three paths

White House AI Action Plan · WAICO · REAIM · UN Scientific Panel

On July 23, 2025, the White House released "Winning the Race: America's AI Action Plan," with three pillars and over 90 actions; its core logic is "whoever has the largest AI ecosystem sets global standards," while pressuring allies via Foreign Direct Product Rules and supporting open-source/open-weight models (treating them as geopolitical strategic assets).

Within exactly one year, China produced its own answer: on July 26, 2025, Li Qiang announced the "Global AI Governance Action Plan" at the World AI Conference; on July 16–17, 2026, 29 nations signed an agreement in Shanghai to establish the World AI Cooperation Organization (WAICO), headquartered in Shanghai; UN Secretary-General Guterres attended the signing ceremony, and Wang Yi signed on China's behalf. Multiple analyses suggest Beijing's AI diplomacy is shifting from "exporting infrastructure and standards" to "reshaping global rules, norms, and institutions"—WAICO, in a sense, provides Global South countries with a governance architecture parallel to the Western one, analogous to the role of the Shanghai Cooperation Organization.

The UN level has not been idle: on August 26, 2025, the General Assembly unanimously adopted resolution A/RES/79/325, establishing a 40-expert Independent International AI Scientific Panel and Global AI Governance Dialogue, with Yoshua Bengio chairing the scientific assessment; the first global dialogue was held in July 2026. But this multilateral path suffered its most significant setback to date in the military AI domain—at the REAIM summit held on February 4–5, 2026, in A Coruña, Spain, both the US and China refused to sign a joint declaration on military AI use; ultimately only 35 of the 85 participating nations signed. Civil society organizations like Stop Killer Robots have long called for upgrading such principles from "voluntary declarations" to legally binding treaties, but the simultaneous absence of both the US and China is seen as a severe blow to global AI arms control—neither country is willing to concede an inch on technological advantage. The EU is pursuing a third path: the AI Act's prohibited-use clauses and AI literacy obligations came into force in February 2025, general-purpose model obligations in August, but the "Simplification Omnibus Act" in November 2025 and the political agreement in May 2026 have already delayed part of the high-risk rules implementation timeline to 2028.

Path
Lead
Core logic
AI Action Plan
United States
Largest ecosystem sets standards + export controls to pressure allies
WAICO / Global Governance Action Plan
China
Provide parallel governance architecture for the Global South
AI Act
European Union
Rights and risk framework, but high-risk clauses already delayed

The result of three paths coexisting is what the Atlantic Council calls "AI governance entering its first truly global phase in 2026"—almost all countries now, for the first time, have platforms to discuss AI risks and coordination mechanisms, but the platforms themselves have already fractured into the US's voluntary standards framework, the EU's rights-and-risk framework, and China's inclusive cooperation framework centered on WAICO; the three are mutually independent, and also do not exclude overlapping membership among each other's participants.

§ 06 / Closing

Three analytical frameworks
you can take away

After reading these events, more useful than memorizing any specific figure are three analytical tools you can apply repeatedly.

  • Distinguish "capability races" from "diffusion races"—DeepSeek V4 trails the US by three to six months yet could reshape the default options across global supply chains, showing that what often determines the long-term landscape is not whose frontier model is stronger, but whose tech stack first gets actually adopted in more countries and more industries (see "The Physics of the Cake").
  • Maintain "calibrated skepticism" toward any self-disclosed threat report—whether Anthropic's GTG-1002 report or the Israeli military's response on Lavender, corporations and militaries have both the motive to serve public safety and the motive to amplify the adversary narrative they face; it's best to cross-verify these alongside assessments from the UN scientific panel and independent security researchers.
  • Use RAND's Five Questions framework or Foreign Affairs' three-axis frameworkto unpack any "AI geopolitics" debate—most disagreements actually stem from the two sides holding different implicit assumptions about whether "AI is heading toward a transformative breakthrough, whether it is easily diffusable, and whether China is sprinting toward the frontier," rather than from disagreements over the evidence itself.

This review mixes sources of varying reliability: first-hand authoritative documents (White House, UN, Anthropic/OpenAI original reports), top-tier think tanks (CSIS, Brookings, CNAS, CFR, RAND), and investigative reporting (+972 Magazine) are relatively solid; but battlefield data (Ukraine hit rates, Gaza Lavender error rates and casualty figures) mostly come from unilateral or anonymous sources, and should be treated as "contested reports" rather than settled conclusions. This field changes extremely fast—the Iranian data center strike, WAICO's落地, and the REAIM deadlock all happened within the past few months; the next major update could overturn any judgment in this piece at any time.

Revision history

First published 2026-07-24

Companion material