The Geostrategic Case for Compute in Australia — Janet Egan [Compute Series]
This is the second episode in a multi-part series called 'Compute in Australia'. Series announcement here. More episodes to follow over the coming month.
[Recorded 24 August 2026.]
Janet Egan is Senior Fellow and Deputy Director of the Technology and National Security Program at the Center for a New American Security in Washington, DC. Her research focuses on the national security implications of artificial intelligence. She was previously the inaugural director of policy in Australia's Office of Supply Chain Resilience.
I caught up with Janet while she was home in Australia to stress-test the strategic case for building a large compute industry here. We discuss why training compute gives Australia more leverage than inference compute, whether hosting compute could also give us influence over AI safety, why copyright is a red line for the AI companies, and why Australia's window to act is "a month or months, rather than a year".
Video
Sponsors
- e61: a non-partisan economic research institute focused on Australian public policy. (As it happens, e61 was co-founded by Andrew Charlton before entering Parliament, though he's no longer involved.) To receive a copy of the new essay I co-authored with e61 on data centres and the compute economy, go to e61.in/joewalker.
- Vanta: helps businesses automate security and compliance needs. For a limited time, get one thousand dollars off Vanta at vanta.com/joe. Use the discount code "JOE".
Transcript
JOSEPH WALKER: Today I’m speaking with Janet Egan. Janet is a policy researcher at the Center for a New American Security, which is a think tank based in Washington, where she focuses on AI and national security.
And prior to that, she was the inaugural policy director in Australia’s Office of Supply Chain Resilience.
And I’m very lucky to be catching her while she’s on a trip back home to Australia.
Janet, welcome to the podcast.
JANET EGAN: Thank you for having me. I’m excited to be here.
Lessons from the AdBlue crisis
WALKER: So we’re going to talk about the geostrategic case for compute in Australia, but before we get into that: before we started recording, we were chatting about your experience in the Office of Supply Chain Resilience.
So for people’s context: there were a lot of COVID disruptions in 2021. Australia stood up this office in mid-2021. You were the inaugural policy director.
Only a few months after that office was stood up, we had what was called the AdBlue crisis. So AdBlue is this [diesel exhaust fluid] that’s used in trucks and heavy vehicles. I think about half of Australia’s road transport fleet relied on it. And a critical ingredient in AdBlue was urea, and China restricted exports of urea. I think we depended on China for 80 to 90% of our urea. We had only a few weeks of AdBlue stockpiled, so we’re facing this crisis where potentially we weren’t going to be able to, you know, deliver food to supermarkets, etc.
So I’d love to know, just firstly, how that story unfolded in the office, sort of from your perspective, and then what you learned from that experience.
EGAN: Yeah, absolutely. It’s probably one of the experiences I look back on with a lot of sleep deprivation but excitement to realise what government can do really quickly when it puts its mind to it.
So maybe a bit more background about OSCR, which we called it, the Office of Supply Chain Resilience. It was actually in formation and being stood up before COVID shocks. So the intent behind OSCR was to bring together the economic and national security considerations about supply chains into a single point of coordination across government. And this was emerging because we had the 5G security issues, where you had national security decisions really impact your economic decisions as well. And more and more the questions were coming up as to what are the supply chains where we’re really dependent on foreign countries and that are critical to the national interest. And then we talked a lot about sovereign capability, which I’m sure we’ll talk about today.
But the AdBlue crisis was one that took us completely off guard, and that’s because we spent a long time developing up these models that used Comtrade data – international trade data – to actually look at where are there real strong concentrations in supply chains, and where are we entirely dependent on just a few places in the world for something that’s critical. Urea was captured, sure, but the trade data did not differentiate between high-grade urea and low-grade urea.
Now let’s get nerdy about this. Low-grade urea is what you use for fertilisers, and so you’re putting [it] on your crops; it’s a regularly used fertiliser. High-grade urea is what was used to create diesel exhaust fluid, which is what was used for 80 to 90% of Australia’s trucking fleet, for example.
We first heard about this by industry calling us up and saying, “Hey, we’re a bit worried about these China export controls on urea. We’ve heard from some providers that they’re not able to get the stock.” And then we saw indications that other countries are starting to scramble to fly to different countries and take bulk urea and diesel exhaust fluid back to their jurisdictions. And it was then we realised, oh, actually this looks like it really could be a problem.
The interesting thing was that we’ve got no evidence that China did this deliberately as part of economic coercion or a trade dispute. One reason was that maybe it was just trying to limit a high-pollution activity in advance of the Winter Olympics, but it had massive flow-on effects.
And so what do we do as an office? The first thing was we had to find out what diesel exhaust fluid was and respond to questions of: does it really need to be there? Can we just switch it off? How would that work?
And then the full range of levers were deployed across government. And I was on phone calls to people who ran charter flights, and the biggest charter flights of the world, to work out how much would it cost and how much magnitude of diesel exhaust fluid could we bring in if we just hired the largest transport carriers in the world. I was talking to the military to work out where [were] our largest ships and could we redirect them to go pick up some of this critical supply. And then we were looking throughout the supply chain at, like, can you do rationing? Can you talk to different states and territories about how we’re spreading the limited supply we had? And trying to manage the hoarding aspect of it as well. So for a while we had enough, but everyone was spooked, so we then got shortages because of that.
It kind of turned into this all-government approach of every agency had a small stake in it. We had the Department of Industry looking at how do you build your own sovereign capability in this space. We had our posts overseas engaging with local counterparts in the northern hemisphere to work out: have you guys been affected? Do you have some we can bring online? We talked to Indonesia and got minister-to-minister level agreement to get some urea-grade supplies from them.
It was just one of those instances where it was very messy, but it gave me a firsthand account of how government can move quickly. And we did. Essentially what we managed to do was there was a fertiliser factory that was closing down in Australia. We were able to delay that closedown, redirect its approach to actually use a new reagent that we shipped in from Germany to combine it with lower-grade urea to make higher-grade urea, which was then used to make diesel exhaust fluid. And, through this sovereign initiative, we had this facility running for a period of time, and then we had to work out how to ensure they had enough COVID tests to keep their workforce operating, and how to get that supply through different floods that were happening in Queensland at the time.
So yeah, the long story short was it was not a well-organised process, and I think since then we’ve had a lot of lessons learned, and the new supply chain resilience initiatives have obviously professionalised a lot more than these scrappy days of just being on the phones and trying to find solutions. But it really impressed upon me that when you have the backing of ministers and the Prime Minister, when it is a national priority, you can just move so quickly. Within months we had solved this issue for Australia.
WALKER: It’s really interesting. I feel like government has two modes. There’s the glacial mode, which is the mode it normally operates in, and then the kind of crisis mode, where it can do things like what you just described. It’d be nice if there was a kind of third, “slow urgency” mode.
EGAN: I would love to see that. I think one of the closest things I’ve come to see in that space is when you have a small unit of people inside government who are highly agentic and empowered. There was a deregulation taskforce in 2019 whose whole mission was to go through the lens of a small business in Australia, or an individual in Australia trying to do business or work through systems, and identify where there was regulatory friction that didn’t need to be there, and trying to find pathways through.
So one example is when you have different occupational licence regimes across states and territories. The Deregulation Taskforce was like, “Wow, this seems insane. If you’re a builder in this jurisdiction, you’re not allowed to build in this jurisdiction until you’ve gone through all of these processes.”
And so I’ve seen some of that middle-range work, but you just have to have this confluence of agentic people who have backing and support to go through and cut through the people who don’t want things to happen, or at least bring them on that journey, and then to just advocate for change.
WALKER: Is talent the scarce thing?
EGAN: I think maybe there’s something… maybe there’s a cultural component too. I think there are so many talented people in government, but I think sometimes when you enter government you can be taught over time to follow process more than to think about outcomes. And then you’ve also got a layered structure that looks at mitigating risks to individuals, so your individual leadership aren’t wanting to step outside their territory to take on more risk and annoy more people. So you kind of need this confluence of people who are willing to ruffle a few feathers and people who really care about outcomes to push through some of that glacial process.
How seriously do Australian policymakers take AI?
WALKER: Okay, let’s talk about compute in Australia. So you’ve been in Australia for the last few weeks, speaking almost exclusively with Australians. When you go back to Washington, tell me how you’ll summarise your trip and what you’ve learned to friends. So, for example, is there anything that surprised you about how Australian policymakers are thinking about compute or AI in general? Any differences that you’ve noticed between how US policymakers and Australian policymakers are thinking about those topics? What’s stood out to you?
EGAN: Yeah, great question. I think the first thing that is so distinct between Washington, DC and Australia is how seriously people take AI. Again and again, I found myself having conversations where I’ve assumed that people think AI is going to be a big deal, and so I’ve started the conversation there, and find myself having to go back and retrace earlier discussions to say, “Oh, okay, here is where the pace of progress is heading. Here is the evidence that we’re continuing to see massive breakthroughs and we haven’t yet hit a wall, and here is the evidence that the recipes we have for continuing to improve capabilities are continuing to bear fruit, and so we’re on a trajectory.”

In Washington, DC, no one is… well, very few people are questioning that. It would be odd if someone said, “Oh, I don’t think AI is a big deal. Oh, I think it’s just hype.” But the amount of times I’ve been asked in the Australian context, “Wait, isn’t it just a bubble? Like, surely AI is just all hype in the market, like the companies are talking themselves up.” That is a really big juxtaposition between the two different policy landscapes.
What surprised me in the positive way, though, has been how rapidly Australia has been moving to understand and grapple with these issues. You had Charlton on this podcast most recently, and it’s been amazing to witness the journey of initial conversations happening around AI in Australia to actually delving into the issue of compute at a ministerial level. We’ve seen the Department of Prime Minister and Cabinet set up a new AI taskforce. We’ve seen a growing number of policymakers express urgency at addressing these issues.
So I think we’re on the right trend, but I do think that there are a lot of very senior people in positions in government who still aren’t grappling with the realities of AI progress.
One theory I have for this is that it’s very easy to appear knowledgeable and be sceptical, but it’s actually very costly or hard to be knowledgeable and engaged in the issues – particularly if you’re a leading economist in your field or you are a thought leader in your industry and someone is asking you for takes on AI. It’s a cheap and easy take to have to say, “Look, I’m not sure this is a really big issue. I’m a skeptic.” It’s a much harder thing to do to sound really knowledgeable and informed and engage in those issues. So I think we’re moving in the right direction, but there’s still a way to go.
WALKER: So just in 30 seconds, because I’m going to ask you a bunch of questions that elaborate on this further, but give me your ideal world for compute in Australia by 2030. So, you know, how much compute, how is it deployed, what benefits is it delivering us?
EGAN: Yeah, big question. 30 seconds. I would say we have multi-gigawatt-scale compute training clusters in Australia, done in partnerships with the leading AI companies. The Australian government is not spending money on these. We’re redirecting the massive amount of AI capex into Australia’s clean energy transition and Australia’s compute capacity.
How much does frontier access matter?
WALKER: Okay, so let’s go through each of the arguments for compute in Australia from a geostrategic perspective. I don’t want to touch the economic stuff today. But I think if we divide the geostrategic arguments up into, say, three different limbs: the first is leverage for frontier access; the second is maintaining enough inference compute so that we can continue running our sort of critical services and military functions; and then the third is having some influence over the governance and alignment of AI systems.
So if that sounds like a good map to you, let’s start with compute as leverage for frontier access. And I think both in [that interview] and in conversations I’ve had since my interview with Andrew Charlton, what’s emerged as the crux in the Australian conversation at the moment is just: how much does access to the frontier actually matter? And if it doesn’t matter that much, then compute for frontier access is redundant, or not as needed as some people might think.
So I want to start by just asking a few questions about how much access to the frontier matters. So the first question is: I think the gap between the frontier and fast followers is currently about four months.
EGAN: I think it depends on whether you’re looking at the frontier models that have been publicly released, or the level of capability held within an AI company. And what we do know is that frontier US companies who have closed-weight models, they have not deployed or made publicly accessible through API their most advanced models. Their most advanced models are currently kept internal, and I think the estimate’s around two to three months more advanced than what is their publicly available model.
WALKER: I see. So say the gap between the non-public frontier and fast-followers was six months, and we were able to maintain that distance indefinitely. In that world, how much would frontier access matter for a middle power like Australia?
EGAN: I think it matters some… I think we could be in a position where that premise doesn’t hold.
But say that premise holds. I think it does matter in some ways, because six months is a long time if you have AI agents working at machine speed to do a whole range of tasks. And if we accept the premise that AI progress is continuing exponentially and that the capabilities of models are showing no sign of slowing, I think we’re going to be able to do increasingly astounding activities through AI. And so having a six-month lead in terms of what you might do for R&D, material science, your economy, but also your offensive cyber or your defensive cyber, I think is pretty drastic.
WALKER: Right, military R&D in particular. Okay, so now what are some reasons for thinking that that gap might actually widen?
EGAN: Yes. So at the moment we’ve got an AI industry that’s characterised by US companies driving forward the frontier and Chinese companies – said in very simple terms – Chinese companies are acting as fast-followers with open-weight models. There’s a number of reasons I think that this balance might shift over time.
The first is that there’s some extent of Chinese capability that is a result of distilling US models, and it’s very uncertain how much of Chinese capability is purely as a result of distillation versus what they’re doing themselves. But I think it’s reasonable to expect that US companies and the US government [are] going to get better at preventing distillation. So that’s one thing that could widen the gap further.
Another thing that might widen the gap is this idea of recursive self-improvement, which is where you get AI making better AI, and that kind of creates this flywheel of AI progress that then gives you this intelligence explosion that’s then hard to rapidly follow – particularly if you use those intelligence dividends to push back or counter distillation or counter Chinese progress in that space, which, given the state of US-China relations, could be a real possibility.
And I think another reason that this issue might change is open-weight models are democratising access to AI capabilities, but we’re seeing now that there’s sort of discussions within China to stop making the most advanced models open weight. And so maybe there’s a ticking time clock on how long we can access open-weight models freely. And that’s because essentially every user of an open-weight model has the ability to download a local instance. Once you have access to the model weights, it’s very trivial to strip away any safeguards that have been put in place. You can just tweak the model weights, and fine-tune it and train away safety behaviours.
WALKER: Yeah, the safety filters can be changed through the inference code, but the safeguards are in the weights.
EGAN: You can tweak the weights. You can further train it, you can untrain it, you can… It’s a very trivial process to actually strip away the safeguards that might have been put in place.
And so Chinese companies – there’s rumours, and I haven’t seen this affirmed anywhere – but there has been discussions that Chinese companies are already not releasing their most capable versions in open weight, because they don’t really want to pass capable cyber weapons into the hands of everyone in a way that will get them in trouble with the Chinese government.
Now, as AI becomes more capable across more domains – and talking to the AI companies, it sounds like bio is ready for significant uplift, and they’re getting more evidence that that might be the next dual-use cab off the rank – there’s another fundamental question: are you going to keep democratising access to everyone around the world, who can then strip away all the safeguards and use it for nefarious purposes?
So there’s this ticking time bomb of a decision for China to think about how is it going to approach open-weight models. They’re not very profitable, open-weight models, because you’re not really regaining a lot of the training costs, because you’re making it available for free. And so I think any strategy that rests entirely on the proposition that we can just continue accessing open-weight models that’s six months behind the frontier hasn’t grappled with those complexities.
WALKER: Right. Okay, I have a few follow-up questions here. So one is: my sense is that cyber will end up defence-dominant and bio will probably end up offence-dominant. Is that your sense as well?
EGAN: I think that’s generally the accepted trend. For cyber, we’re expecting to see this massive dip into offence-dominant for maybe one to two years, depending on how quickly we can use AI agents running across the entire insecure code of the internet and every operating system to secure it. And that is really costly to do. I know OpenAI Foundation is actually looking at hiring people to work out a plan to do some of this stuff. But yeah, that’s very much a work in progress. So near term, cyber is offence-dominant. Later, hopefully defence-dominant, once it’s AI writing secure code.
And then you might still have some cyber capabilities that are exquisite in a form that makes them offence-dominant. So if you think about your resources in terms of compute: how much compute you’re deploying to guard your surfaces of code that you’re pretty sure is secure but know it may not be entirely secure. An AI attacker only needs a lot of compute to go after one particular section, and could probably outperform. If you have a lot of compute for one exquisite cyber weapon, you could probably still get real breakthroughs.
It’s very hard to control bio risk, because one single instance can have such dramatic effects. We saw with COVID-19 the impacts of a pandemic, and that wasn’t even an engineered pandemic designed to be as harmful as possible. I do worry about the bio space. I think the best thinking at the moment is how do you focus on the parts of the supply chain you can kind of restrict. So, for example, synthetic DNA screening: if you’re ordering gene sequences from a lab and it’s being printed for you, what requirements are there to check that it’s not part of a known virus that could be problematic, or part of an unknown virus that shows indications it could be problematic? So there’s some of the open questions as to how we manage that.
WALKER: So my next follow-up question is: what’s your rough sort of model of the CCP here and how they’re thinking about these security risks? And what are some things that could surprise us with respect to how they respond? So, I mean, if it is indeed true that AI is so strategically important, maybe they decide it’s just worth taking those risks?
EGAN: They could. I’m by no means the expert on the CCP. I have been engaged in some Track II dialogues with Chinese AI companies, and so have some sort of insight into how the frameworks work over there. The CCP is deeply involved in the development of AI models in China, to the extent that it seems to me that Chinese AI companies expect the Chinese government to weigh in on what risk is appropriate and not appropriate, and so aren’t necessarily like the US companies, who are doing their own analysis of what are their risk thresholds and safeguards.
And so then it turns into: what’s your model of actors within the CCP who are more or less bullish or bearish on AI, and are looking at rates of progress and risk? And I think there has been some discussion about how… so in China there is some discussion about risks emerging from AI, and for the CCP it’s also around information risks. So what are AI models telling their citizens? Are they aligning with good socialist Chinese values or not?
It’s probably quite a long answer to say I don’t have a very clear steer on where they’ll land on this. I do think that the Chinese government is going to regulate, and already is regulating, AI in China, and so it will probably be like a tweak and adjustment as they see more risks come to light.
WALKER: So another question is: for mitigating the biosecurity risks posed by open-weight models, one obvious solution is to just not publish the model weights, but there are other policy alternatives for mitigating those risks. For example, you could exclude sensitive data from the training corpus. Do you have a sense for how feasible those other alternatives are, and whether they’re sufficiently robust?
EGAN: Yeah, I think with bio it’s a difficult one, because once you’ve published weights, you can then train it further on additional data sources. And so if you have access to a lot of data on biological science in this field, you can then create that capability inside a very intelligent general-purpose model. So it’s much harder to sort of mitigate against that fully.
But I think it is a really big question as societies we need to grapple with, because there’s real risks to keeping everything in closed-weight models as well – like risk of power concentration into just a few companies in just a couple of countries. That also seems really risky. And so, I don’t think there’s one clear right answer here. I do think that bio is so offence-dominant that we need to start taking it seriously now, not wait till a risk starts to hit the horizon.
WALKER: Right. Now, are open-source models really Australia’s only way of pursuing a fast-follower approach?
EGAN: Hmm. Well, I think it depends what you mean by fast-follower approach here. I think the ideas of building our own frontier AI model from scratch I’ve tended to be very sceptical about, because of just the sheer costs involved in developing an AI model.
WALKER: Not contemplating that. Say, again, like a six-month gap.
EGAN: I mean, Australia could try and build out large compute clusters and distil American AI models, just like China is doing.
WALKER: And then just not publish the weights.
EGAN: But I think… One of the cruxes here is how much you think the frontier is where the most valuable activity will happen, from an economic and national security perspective. And one way I think about this is if you’ve got two employees: one of them is your intern, who’s pretty smart, fast learner, but every part of their work you need to check, because they have some ability to make stuff up and often make mistakes, and it’s not quite there. And then you also have an employee that is exceptional, your second in charge, and they’re giving you analysis and results that you rarely ever need to check, and their error rate is very low.
It seems to me that most of the most valuable economic activity comes from the one that’s most advanced – the expert in this field – not the one that is much less advanced. And so I think I tend to err on the side of thinking that the real gains and automation will come from the most capable models.
WALKER: Say in two years you’ve completely changed your position about the importance of access to the frontier. What do you think a likely reason for that would be?
EGAN: Yeah, there’s a few here. One is that data centres are just not made securely, and so companies are spending a ton of money to develop the frontier, and then the weights are easily stolen and exfiltrated. So enough actors take what they want to allow that to diffuse.
A second would be if we do start to see AI hitting a wall in terms of the known recipes for progress at the moment – which we haven’t got indications of yet – but if that happened, then a fast-follower approach might be sufficient if it’s capping the level of capability.
And then I think the third one is if the US manages to combat Chinese distillation really comprehensively and Chinese AI progress continues apace, then that would also make me reconsider, like, okay, maybe it is possible to do a fast-follower model in the longer term.
WALKER: And would that depend on some algorithmic breakthroughs or greater sample efficiency?
EGAN: We are getting algorithmic breakthroughs all the time in terms of just increasing efficiency in how we use compute for training and inference. I guess we’ve got two concurrent trends in the use of compute. Like, pushing forward the frontier needs ever more compute. So I think [for compute] the overall stock is increasing over triple a year, and you need five times the amount of compute to train the most capable model. But then this concurrent trend is that over time any given level of capability is much cheaper and more accessible because of that algorithmic progress.
So I think we’re going to just continue to see great software progress, great algorithmic progress. The thing there, though, is it diffuses fast. It’s just knowledge. And so that’s much harder to gatekeep than something like compute.
Compute-for-access
WALKER: All right, let’s talk about compute-for-access. So I have many questions I’d like to ask you here. The first is: could you just summarise how you see the differences between your preferred model of compute-for-access and my acquaintance, your friend, Anton Leicht’s preferred model of compute-for-access?
EGAN: Yeah, so Anton and I have talked a bit about this. And I am very bullish on the idea of training compute, because AI training – one day maybe we’ll be able to decentralise it fully or have greater decentralisation, but currently companies much prefer to have centralised training compute. And by that, I mean they don’t want to split their training runs of AI models over more than two jurisdictions, or two massive data centre clusters, or a handful at max. Which means that with training compute, you therefore just have maybe one or two countries that are going to host your training.
Inference compute, however, I think is much more fungible and likely to be commoditised, because you can build it in small pockets, large pockets, and you can build it around the world, and it doesn’t have the same gains of being centralised.
Now, Anton is very bullish on this idea of everyone should build out inference compute, and then you can trade access to that compute, or have companies get access to that compute in return for saying, “Hey, we will make sure that your citizens have access to the models that we’re running.”
And apologies to Anton if his views changed recently, because he did mention to me recently that he’s becoming more excited about training compute as well. For Anton’s view, he says inference is what you want. You want access to the models. It doesn’t really matter who trains it, you just want to have access.
I think, though, that if you are the country that is hosting a large proportion of the world’s training compute, you get more kinds of access.
So when I think about access, I think about the deal space of: Australia has, you know, renewable energy, geopolitical stability, good connections with the US through Five Eyes, and space… But the key barrier there is copyright. Obviously, as we all know, AI companies won’t pay for a copyright licence in Australia, because it will undermine their cases for fair use applicability in the US.
So this deal space is that you can create the conditions to welcome training to Australia, and then, because of the first-mover advantage, because companies want to have a guaranteed place to build out their compute, you can ask for a lot in return.
And so when I think of compute-for-access, I think of:
- You get companies to agree to ensure that Australians get access to frontier models.
- You ask companies to provide a certain proportion of their compute – it can just be a very small proportion compared to the overall compute – but [it] goes towards public good research in Australia and is accessible by Australian researchers and engineers.
- And then you also have access to information. You have close collaboration between the Australian AI Safety Institute and the frontier labs operating in that jurisdiction.
And I think those three kinds of access are all very important.
WALKER: Got it, got it.
EGAN: And sorry, to be clear, the public compute dedication would also be for non-company employees. I’m really excited about this. So someone from an AI lab will say, “This is ridiculous. People outside the labs don’t use compute to its best advantage. It seems wasteful to give this scarce resource over to public infrastructure. We can just do more with it and do public good with it.”
My pushback against that is trying to build out an ecosystem of researchers that know how to use AI compute well and can put it towards public good challenges.
In the US, you have this new initiative – it’s been in pilot for a while now – called the National AI Research Resource, which is government-funded compute for AI researchers to use on public good research. I worry that for Australia and for other countries around the world, other governments, the cost of compute is just continuing to skyrocket, because we’re facing a compute shortage, and we don’t want researchers to be priced out of access. So for me, this is like another part of the deal: that if you’re the first mover and say we will offer you a safe harbour for training, you can extract a lot of this sort of value from the companies themselves.
WALKER: Right, right. On the difference between your and Anton’s preferred models, there’s perhaps another reason for thinking that focusing on training compute is better than merely inference, and that is that with the training compute you get a lot of the benefits of inference compute anyway, because the chips can be used for inference. It’s more efficient for the labs, because they can utilise those same chips.
EGAN: I think we are seeing a growing divergence between training chips and inference chips. I think Australia will attract some inference regardless of its approach, but what I see as a real benefit with training is just the scale it unlocks in the near term.
None of this detail is publicly attested to by the companies, but researchers have done a pretty good job at trying to guesstimate how much of the overall compute budget is used for AI training-related activities, including R&D, and how much is used for inference. Weirdly, there’s more demand for inference than is being really… I mean, companies could direct a lot more of their compute to inference, but they’re still choosing to direct… about a third to half of their overall compute spend goes towards training and R&D.
And so if you’re thinking about – if you put your hat on as the AI company, they’re saying, “We’re hitting data centre moratoriums in the US. We would like to bring another democratic power to the table in terms of thinking about AI and how we structure national security and the economy going forward. Which country shall we choose? And once we’ve chosen it, we shall build out like five to eight to ten gigawatts of training compute in short order.”
Now, this is massive amounts of compute. One gigawatt is roughly one nuclear reactor’s worth of energy, and it takes time to build. But because you get dividends from centralising your compute, training means that once you’ve locked into an ecosystem, it’s more advantageous to keep building out that one ecosystem than decentralising your training across multiple different countries.
So I think training is great, because it means that you just grab a big part of the value chain of an AI company, and then that creates the incentives. When you do that, in return for changing rules and regulations, you can extract concessions back, one of them being access to frontier models.
Yes, at the end of the day, a US company is still at the behest of the US government, but you do create an internal champion within the US to say, “Hey, no, this partner is really important. We really need access to these compute resources. We can’t just leave them as an afterthought. Can we invite them into the tent?”
And so it’s less about strong-arming any foreign government into any position. It’s more about creating the environment that means you’re a trusted partner to the US, and a trusted part of the value chain to a company that will advocate for your inclusion in discussions around how frontier AI is accessed and used.
WALKER: So of these various strategic benefits that we’ve mentioned, do you know if any of them depend on whether the compute is built and owned by American hyperscalers versus Australian companies?
EGAN: I don’t have strong views on that. I think at the end of the day, I don’t think that’s a big differentiator.
I think it will still lead to construction jobs in Australia, which is what’s mainly important.
WALKER: Okay, so just focusing again specifically on leverage for frontier AI: this word “leverage” gets thrown around a lot, and it can feel a bit hand-wavy at times. I’d just like you to add some detail, and it can just be, you know, hypothetical detail – I’m not going to hold you to this – but what could a compute-for-access deal look like here? For example, what are the enforcement mechanisms, etc.?
EGAN: Yeah, I think I haven’t thought about this in massive detail, but I think there’s something here around: you could have written in that there’s a significant financial penalty if that company fails to provide frontier access to Australians or the Australian government. You could require that access to that compute, access to the energy for that compute, relies on upholding that part of the agreement. And essentially you’re just creating the incentives for that company to advocate very heavily for Australian engagement on frontier AI issues – including when the US government might say, “Hold up, Fable 2.0, we’re restricting access to non-US citizens”.
I think the important part here also hinges on Australia’s geopolitical alignment with the US. So to model US government decision-making, you might say no one is thinking, “Hey, we really want to chop Australia out of the tent,” but no one in the US government is thinking, “Hey, we really want to bring Australia into the tent.” Australia is just not really top of mind for anyone in Washington, DC when they’re thinking about AI policy.
But once you become the valued partner of, “Hey, we’re helping you overcome domestic energy bottlenecks, we’re going to be a counterpart” – just like Pine Gap helps with signals intelligence, Australia helping with compute for AI training – I think that means you are part of those discussions in a much more natural way.
The way I say it is: it’s very hard to uninvite a friend from a party if they’ve already arrived, but it’s very easy to forget to issue them an invite.
WALKER: True, this is true. And sorry, just before we go on, to make sure I’m spending enough time on the right things: of all these possible strategic benefits we’ve laid out, do you view the frontier access as the most valuable?
EGAN: I think it is up there as the most valuable.
But one other thing I’d point out there is: we’ve had a lot of warnings that we are looking at workforce disruptions – and when I say warnings, projections. We haven’t necessarily seen it play out in the data. Although you might also look at horses in the Industrial Revolution. I don’t know if you’ve seen that meme going around: at the start of the Industrial Revolution, it was a great time to be a horse. So many horses, just going up and up. And then, just when the motor engine became cheap enough to diffuse broadly, overnight horse numbers just dropped off. So I think just because we haven’t seen signs in the economy yet of massive disruption doesn’t mean we should rest easy.

So if we are looking at a world where a lot of the valuable economic work can suddenly be automated, and a lot of those gains might be routing back to just a handful of companies in two countries, that brings concern to me about how the Australian government would provide for its citizens through a period of disruption in workforce displacement.
If you have a big part of the value chain, and if these companies are making bank, it does kind of give you some ability to redistribute some of those benefits to your citizens – particularly with training compute, because once you’ve invested in five gigawatts’ worth of energy, that’s much stickier to relocate away from. While inference compute can be built anywhere in the world and you can decentralise it, so it’s much more fungible, and [there’s] less leverage from that.
WALKER: Yeah, I’m personally sceptical of the likelihood of those Jobpocalypse kind of scenarios, but obviously it’s a tail risk that’s worth considering. Brian Albrecht, he had a great article on this, ‘You Are Not a Horse’. Have you seen it?
EGAN: Yeah, because we then just find other forms of labour and… yeah. But, hey, look at the China shock. If you look at the macro numbers, I mean, everyone’s a winner, but if you look at the micro impacts – as Australia, as the US, we haven’t really done a good playbook of how to manage economic disruption for groups of people. And I think having [the] ability to maybe rent-seek a bit, through having some of the value chain to support that change, I think is important.
But I take your point that anyone who is too certain about what’s going to happen with AI is overconfident, and we’ve just got so much uncertainty to grapple with. We don’t know how this will play out. I love this idea of radical optionality, which I think Charlie Bullock at LawAI put forward, of just: how can you increase the option space available to you for a wide variety of different futures we might be facing?
What does sufficient leverage look like?
WALKER: Okay, let’s dwell on compute for frontier access for a bit longer. So say Washington restricts major American AI labs’ ability to provide frontier access to non-American markets, and we have all this compute in Australia. We cut off the labs’ access to that compute because they’ve violated the terms of whatever compute-for-access deals that we’ve signed with them.
The optimistic view, is that the labs then go to Washington and advocate for our interests. But I can equally imagine a much more pessimistic scenario where the labs go to Washington and Washington says, “Don’t worry, we’ll just horizontally escalate against Australia and sort it out for you.” So why is that not more likely?
EGAN: I think this is a genuine thing to be concerned about. So when people talk about hard-nosed leverage, I’ve seen arguments that ASML – the Netherlands lithography machine maker – has so much leverage, and the Netherlands can pull it to extract concessions from the US.
WALKER: And it does have leverage, but within that specific narrow domain.
EGAN: Yeah, and if ASML pulled that lever, you can bet your bottom dollar there’s a trade war happening, and it’ll escalate. And I think the US would probably be the winner in that trade war.
And so I think the model for how you can use the compute soft leverage approach is trying to grease the wheels of better pathways, increase the friction of worse pathways, but you’re not trying to get to a hard bargaining agreement. You’re trying to make the case of: we are a critical part of the supply chain, and come in as a peer and a friend, rather than trying to pull hard leverage on the US.
WALKER: Got it. Okay, so I want to ask a question about that comment you just made about us being a critical part of the supply chain. So let’s talk about what that actually means. So one rough mental model I have is that in terms of using compute for our sovereignty and being able to continue to run critical national and defence functions, the relevant metric is just the absolute amount of compute we have, to be past some threshold where we can keep running those functions.
Distinct from that, thinking about compute as leverage for these larger benefits, like frontier access or influence over governance and alignment, is more about the percentage of global compute that you host. So it’s an absolute versus relative distinction. Does that make sense to you?
EGAN: Somewhat. I think it depends on whether you see a future where you want to integrate frontier models into your national security apparatus, in which case engagement with the companies is a big part of that, rather than just hosting your own cluster.
WALKER: I see. It’s not enough to merely have compute; you need compute plus the frontier models.
EGAN: Yes. And again, if you’re only looking at inference compute, I think it matters in terms of what proportion of global compute you hold. And if you can get a big share of global compute, that puts you in a very good position for a wide range of futures. But I think that it’s also about the amount of… Training compute is its own subcategory as well.
WALKER: All right, so we can talk about both inference and training compute. So what do you think is the – and again, just gut instinct, I’m not going to hold you to this – but what’s the minimum percentage of global inference compute, and then training compute, that we would need in order to have “leverage”?
EGAN: I think there’s a couple of ways to model this. I’ve heard some people say that Australia could have realistically aimed for 20 to 30% of global compute. I haven’t… that’s someone else’s BOTEC [back-of-the-envelope calculation], not mine.
I think, though, that if you take maybe the leading AI company currently – so say Anthropic – and if you hosted half of their training compute, I think that would be very good from a geostrategic perspective. If you could host half of Anthropic’s training compute and half of OpenAI’s training compute, again, super valuable.
So there’s probably a few different models to break down, and different things will get you different kinds of access and oversight and leverage. More equals more, generally, particularly as we enter compute scarcity. It seems valuable to have these resources. I think in the near term, though, the most valuable thing Australia can do is demonstrate – and this goes back to that OSCR story about AdBlue – is demonstrate that we can build data centres quickly and we can do it well, with certainty.
WALKER: Yeah, okay. Because I feel like this is a really important premise in the compute-for-leverage argument. It’s like: okay, we want leverage; what does that actually look like; and what’s the minimum percent of global compute we need?
Because if we take that 20 to 30% of global compute number: say by 2030 there’s at least 100 gigawatts of AI compute in the world, and at least 50 gigawatts of that is in the US. So if Australia has 20 to 30 gigawatts, that is half of the non-US share. That feels like a lot, given that I think we only have about 1.5 gigawatts of total data centre capacity right now, which obviously includes more than just AI compute.
So for the compute-for-frontier-access benefits to really cash out, it just seems like you need an amount of compute that, from our view here today in August 2026, seems almost unachievable.
And I’m trying to play a kind of Socratic devil’s advocate role here.
EGAN: No, I think this is fair, but I think I’d fall back on… I think it’d be great to have more compute… So I think OpenAI had internal estimates that it’s going to have like six gigawatts by 2027 of overall compute.
WALKER: Of just training compute. [The estimates were for “low double-digit GW in 2027, which implies approximately 6 GW for training alone.]
EGAN: Yeah. And so if you’re hosting half of a leading AI organisation’s training compute in the near term, I think that is a pretty good move.
WALKER: I see.
EGAN: Separating an organisation, an AI company.
WALKER: Because you’re thinking about it at the lab level.
EGAN: Yes. And a lot of the compute will be inference compute, and so a lot of what you see hyperscalers building out – there’s just so much demand for inference, so there’ll continue to be a market for that. But AI companies themselves are starting to build their own training compute and thinking strategically about which governments do we want to have to engage with closely on our training practices and deployment.
WALKER: Yeah. Because – and sorry, not to belabour this point – but if you think about the other countries in the hardware layer of the supply chain: the Netherlands has an almost absolute monopoly on EUV lithography machines. South Korea has the memory oligopoly. I think 80% or more of advanced chips are produced in Taiwan. So the question I’m asking myself is, why does leverage not look the same for the compute layer of the stack? Or what’s sufficient to have leverage at the compute layer of the stack?
EGAN: I think training compute is less fungible than chips and less fungible than memory, because you’re paying for the centralisation of a massive amount of energy and training infrastructure. I think that is a bit of a difference there.
Yeah, everyone’s still going to be dependent on Taiwan, everyone’s still going to be dependent on Micron, SK Hynix and Samsung for memory, and ASML for EUV.
But I don’t think you need to capture the absolute monopoly in compute to have leverage over frontier AI companies. If it’s the frontier AI company that is choosing to make you their secondary training hub.
I think, though, maybe to play in a bit to your point here, it also depends on what kinds of concessions and exchanges you’re asking for. So the more compute you have, the more you can rent-seek or ask for things before companies will exit your jurisdiction.
And so when you’re thinking about – if you built out [a] six-gigawatt data centre cluster in the middle of Australia somewhere, that is a pretty large investment. But also building new energy resources takes time, and if Australia can demonstrate its ability to do that well and have really rapid time-to-power, in a way that still respects different community engagements and Indigenous engagement and a range of other important issues here – companies are not super price-sensitive for that kind of trade-off. For inference, where you can build anywhere, and an inference data centre here is the same as one over here and doesn’t have to be co-located, I think that’s a different… it doesn’t give you as much asking power.
What does AI sovereignty actually mean?
WALKER: So I want to pivot to this other strategic benefit of having enough inference compute capacity to be able to continue to run our critical and military infrastructure. So do you know, firstly, in the context of inference compute, what “resilience” means?
EGAN: Oh, it’s a good question. Even the word “sovereignty”, Joe, is used by different people to mean whatever they want it to mean.
I’ve been trying to sort of do my own thinking on what does sovereignty mean for AI. And I’ve come up with this – slightly taken from UK thinking – but there’s like three parts to this:
- Australia has access to the technology, to frontier AI, and can’t be cut off easily; then
- Australia captures some of the value; and
- Australia can influence the trajectory of this technology.
And so I’ve been thinking about this as a three-pillar approach to sovereignty, because at the moment sovereignty will mean whatever you want it to mean and however it can make you money, which is difficult to engage with sometimes.
So yeah, in that case, I think that depending on how much you want to use some of these models in your intelligence apparatus, in your national security apparatus, I think it does make sense for there to be some government-owned compute clusters that are ticked off at the secret and top secret level, so you can actually integrate [them] into your systems. That seems important for sovereign capability, and that means you’d want it locally hosted. I think, though, I don’t have a good model for how rapidly you would want to ramp that up, because that sort of certification can take time. You probably do want to be using some of the more advanced systems.
As one example: El Capitan, the government supercomputer in the US, at Lawrence Livermore National Labs. They host a local instance of OpenAI’s model weights. And so they have reached an agreement with a frontier AI company so they can have access to the underlying model to help them with classified and sensitive work cases. Lawrence Livermore, I think, does a lot of nuclear weapons modelling and other issues in that space.
So I think there’s options for Australia to do the same. I can’t give you a specific figure.
And then you will also have people who say, “Oh, I want my health data to stay onshore,” and that’s an example of sovereignty too.
So yeah, being really crisp and precise about what you want sovereignty to mean for you in this particular policy circumstance, I think is really important. I don’t think government will do that, because it’s so easy to wave this flag of sovereignty and have it mean whatever is advantageous. But the key question is: what are you trying to achieve with the capability? And then maybe you don’t need to have it all onshore. Maybe you want to have it overseas, but with certain protections on it. For TS [Top Secret] environments, you probably do want to have it onshore.
WALKER: Do you know roughly how much inference compute we need today to maintain national security?
EGAN: I don’t have a good insight in terms of how much AI has been adopted in Australia’s national security settings.
WALKER: I guess one thing we could say is: by 2030, it will be being used much more, right?
EGAN: Well, actually, there’s a really big question here about what is the role of governments in national security, compared to private sector actors, in an era where you have potentially the most critical national security capability of our time being developed by private sector actors.
Unlike DARPA, who was involved in the internet, AI is happening outside of government trend-setting or government investment and government oversight. And you could see a world where you actually have more private sector cyber defenders, or companies that are approved to do more defend-forward or cyber defence systems for the Australian government, or to help Australian government priorities.
The US is going down a weird road with this. I think they’ve started – and they may have already done this – but there’s been discussion about them moving down in terms of allowing private sector actors to hack back foreign adversaries. So yeah, it’s a fundamental question of what is the role of government in the age of AI. I think definitely protecting national security and setting the objectives there, but maybe you have much more private sector engagement to deliver on some of those components too.
WALKER: Say we went all in on autonomous drones. My understanding is that wouldn’t much affect our compute needs, because they have onboard compute. Do you know anything about that?
EGAN: I’m not good on drones.
WALKER: No, all good. If it's true that the amount we need for a sovereign capability is only a small fraction of our total compute capacity, then it seems like that’s actually a weak argument for a large-scale compute industry in Australia.
EGAN: Maybe when I think about sovereign capacity, it’s: do actors in Australia, whether it’s private or public, have enough compute to defend Australia’s critical systems at scale from offensive cyber? Do we have enough compute to ensure that our critical industries – or the areas where we have strong economic presence – are benefiting from advanced AI capabilities?
And so for the first one, you might say, well, given we might want close interoperability with the Australian Signals Directorate, maybe we should have that housed onshore – that compute running frontier US models. For the second one, it’s still about sovereign capability, but it’s probably not so sensitive [that] you need to have it housed onshore. I think you want to have some Australian government access to compute. But I also think Australia’s private industry accessing compute is critical to Australian national security.
WALKER: Yeah, great. It strikes me that the amount of compute we’ll need for our sovereign capability – however you would like to define that, and you’re welcome to define that – is only going to be a small fraction of our total compute capacity. True?
EGAN: If we host training for the world and inference for the world? Or you mean demand?
WALKER: Demand.
EGAN: Demand.
WALKER: Yeah, good question. Demand.
EGAN: Yeah. I think…
WALKER: Because you see where I’m going with this? I’m like: okay, now this doesn’t feel like a strong argument for a large-scale compute capacity in Australia. This specific argument – as distinct from things like compute for leverage for frontier access – but sort of compute to maintain some minimum level of sovereign capability, again, whatever that means, is a pretty low threshold to cross. And therefore it’s not actually a strong argument for a large-scale compute industry in Australia.
EGAN: If you want to have the most capable models running domestically in Australia, you are going to need to have leverage with an AI company to say, “Can you let us have an instance of your model weights that doesn’t leave Australia?”
WALKER: Right, so it comes back to this frontier access question.
EGAN: Yes. Yeah, I would say that’s true. I think if you’re happy – well, I don’t want to say “happy” being a fast follower, because I think that’s not a good approach, to put all your eggs in that basket. But Australia can build a compute cluster itself and have it dedicated to national security use cases. But the best use of that compute cluster is with the most advanced models, which are the US models. And so I think that’s where that intersection comes to bear.
WALKER: Yep. Yeah, interesting. The crux here really is just: how important is the frontier? How do we maintain access?
EGAN: Yeah. And I think also maybe another aspect that some people group up in this sovereign bucket, is having an AI economy or AI talent in Australia. And maybe that’s sometimes underexplored, because once you’ve invited the large AI companies in and they’re able to train in Australia, there’s a range of different people – some of whom are the world-leading AI researchers, and you might have already spoken to some of them – who would love to move back to Australia and do their jobs here. And so it’s not just about you’re taxing these people’s income in the Australian jurisdiction. No, it’s about the fact that you’re then giving the opportunity to undergraduates at university, to research students and professors, to actually engage with leading AI researchers and build out our understanding of AI capabilities and how to deploy them well. And I think that is sometimes an area that’s underinvested in.
So there’s a range of different organisations now in Washington, DC who are starting to look at: imagine if you do get “a country of geniuses in a data centre”. How do you use these well? How do you extract the maximum value, from a national security perspective or economic perspective, from the compute and from the genius AI beings or agents that you have inside that compute? And at the moment, I don’t see a good pathway for Australia to actually get really good at this sort of thing unless we are engaging with the companies at the frontier and bringing people into our jurisdiction.
This sounds so silly, but time zones really matter. Having tried to work in DC time zone for the last few weeks, it is just so hard to engage and get people’s time. And actually, if you have these people in your ecosystem and provide the opportunities for our workforce and our students to grow and engage with these organisations, that seems to be a really big win in upskilling [the] Australian economy and national security community to understand what are these models capable of, what are the risks, and how do we actually employ them well for good outcomes.
Taiwan, undersea cables and data centres as military targets
WALKER: I have three miscellaneous questions on the second-order implications of compute in Australia for our national security.
So if we do go all in on compute, is there anything we should be doing to de-risk Taiwan’s role in the supply chain?
EGAN: In terms of chip dependency on Taiwan?
WALKER: Mmm.
EGAN: Yeah, I mean, there’s a range of efforts underway in other jurisdictions – so the US in Arizona, Germany in Dresden – to try and diversify advanced chip supply chains away from Taiwan. The reality is there’s just so much demand for the advanced chips coming out from Taiwan that if Taiwan goes offline, everyone is going to be very impacted by that, regardless of when the Arizona and Dresden plants come online for TSMC.
Interestingly, from anecdotes I hear – someone who works very closely on this has described this to me as more alchemy than science, building these clean rooms and fabs, because it can just be someone not washing their hands that contaminates a whole batch of chips, and the yield rate goes down. And so building the culture that surrounds the excellence of these sites takes time too.
Some people have asked, “Oh, should Australia enter the chip game?” Sure, maybe, but it doesn’t seem to be an area where we currently have any edge in that. We haven’t got the workforce, we haven’t necessarily got the expertise, and we could be another country that throws its hat in the ring to try and attract some of this, but countries are currently trying – it’s just a really sticky supply chain to shift.
Yeah, so I think it’s going to be a shared risk going forward, dependence on Taiwan for these chips. I think if we do bring on more clean room space and fab of advanced chips, it’s going to be a yes-and, because the industry will keep gobbling it up, and Taiwan will still be a fairly big player in that, I think.
WALKER: Right. Because I’m just thinking that, if there is some kind of blockade or invasion of Taiwan, the timing here could be incredibly unfortunate for a compute-in-Australia play. So I’m wondering: if we’re not going to be building chips here ourselves, is there anything else the Australian government should be thinking about for de-risking that?
EGAN: Oh, it’s a big global problem. It’s not Australia’s alone to bear. And I don’t think Australia would be worse hit than other countries in this space. I think it creates incentives for the US to be more defensive of Taiwan, but I think it’s an incredibly costly industry to try and diversify, so I’m not sure if Australia is particularly well placed to do it.
WALKER: Do you have any random takes on the question of: if we do become a large host of inference compute and we’re serving that up to other countries, what would that mean in equilibrium for the security of our undersea cables? Because, on the one hand, you can see them becoming hotter military targets. On the other, other countries now have more of an incentive to help us defend them.
EGAN: Yeah. I haven’t got many random takes, except that subsea cables are notoriously vulnerable points.
WALKER: Are they?
EGAN: Yeah. I mean, sometimes a ship’s anchor will detach one, and there’s only a few ships that can do repairs in Indonesia at one time.
WALKER: Has this happened before?
EGAN: I think that there have been disconnected or damaged submarine cables. I can’t give you specific details – I can’t remember off the top of my head. But they routinely need to get fixed or reconnected if they’ve been dislodged. I’ve also heard that sharks can chew on them as well, but maybe I’m now falling into myth and not real.
WALKER: Yeah, “sharks”. [laughs]
EGAN: But yeah, I guess you have a few different cables, and it might increase latency a little bit if it has to reroute through different jurisdictions. But I don’t think AI – frontier AI models aren’t particularly latency sensitive, because you’re already waiting for the reasoning to happen. So, like, a few extra milliseconds of delay isn’t going to be that bad.
It’s also a question of inference to what? It’s less that, as a user of AI, I need my model to respond to me instantly. It’s more that I want my agentic AI model to talk to the other agentic AI models and do complex tasks and research and then come back to me with the results. And so having more co-located compute as well kind of gives you slight dividends on having more AI geniuses working with each other.
WALKER: Right, right. So if AI does become as important to national security as we think it will be, you can easily imagine gigawatt-scale data centres in Australia becoming military targets, in the same way that the joint facilities at Pine Gap and North West Cape are considered to be military targets – and, indeed, in the same way that data centres in the Gulf states became military targets during the US-Iran war this year. Should we be planning for this as and when we begin our build-out? Should we be thinking about building them underground, or dispersing the clusters in some way so that, you know, tactical nuclear strikes are not credible? Or what do you think?
EGAN: It feels very dystopic to plan for these kinds of futures.
WALKER: But this is what you’ve got to do, right? You’ve got to make the threats non-credible.
EGAN: You could have one view of: if you are using clean energy, you can build:
- data centre cluster;
- ten kilometres of solar;
- data centre cluster;
- ten kilometres of solar.
And then that kind of spreads things out, so you’re less of a centralised attack surface.
But as you mentioned, Pine Gap is already a target in Australia. It’s not as though we’re introducing new risk in particular.
I hope we don’t get to those kinds of futures, but there are ways you can kind of make them more resilient: by still having the high-speed interconnect that directly connects these data centre clusters by these highway links, but you can have them a little bit dispersed.
WALKER: Strung out in 10 kilometre gaps.
EGAN: Yeah.
WALKER: Do you know if that’s like a no-regrets move? Or does that add significant costs to the build-out?
EGAN: I don’t know for sure, but I don’t think it adds significant cost, because of using solar, which is a sensible thing to do if you’re building out in Australia. That seems like a fine way to do it.
WALKER: Yeah. And one piece of context here is the kind of clusters we’re imagining are in remote Australia, right? They’re not around cities.
EGAN: Yeah, with training clusters you don’t need them around cities at all.
WALKER: So imagine the sort of red earth with these data centres spread out every sort of ten kilometres. That’s the kind of picture we have in mind here, right?
EGAN: Yeah.

Could compute buy Australia influence over AI safety?
WALKER: Okay, so some questions about governance and alignment. So just tell me concretely how you think a large-scale AI training compute industry here helps us gain influence over AI safety.
EGAN: Yeah, it’s an interesting time to ask this. It’s been a wild couple of months of strange incidents involving AI models doing things that we probably don’t want AI models to do. Just to mention a few: there was the Hugging Face incident, where models hacked a real-world company while they were doing a test. We’ve seen an incident where the UK AI Safety Institute misconfigured internet access for some tests on some of Anthropic’s models, which then went and created, like, human personas, uploaded malicious code, and then used the human personas to convince people to download the malicious code into software libraries.
So we’ve seen this range of incidents where we’re like, “Ooh, it looks like we’re getting more and more capable models, but they’re kind of still doing things we don’t really want them to do.” And luckily they’re not at the level of capability that they’re doing terrible things. Like, the damage is really contained in these instances.
So what does compute get us? I look at the status quo in Australia, and we’ve got this amazing new AI Safety Institute. And at the moment, AI companies are engaging quite well, because they’re hopeful of building here. If you build here – and again, as part of this deal space that you can set up – you can get access to some of the leading researchers at these organisations. You can require information-sharing. You can be involved in testing of models or incident reporting, and you can have standards and rules and ways of engaging that bind or apply to these AI companies.
The counterfactual, which we’re on currently, is that Australia can write the most informed, most beautiful, well-researched rules in the world that have absolutely no impact on AI’s trajectory. We aren’t Europe. We don’t have enough population size to give a “Brussels effect”.
If you buy the model that we don’t have enough compute to go around – it’s not that we necessarily have to be a key market that AI companies want to serve. And at the moment, Australia is getting the red carpet of engagement from AI companies, because they might build here. If that dries up, or as soon as the decision is made elsewhere, I don’t expect that we would have this level of access to the expertise and understanding of what’s happening at the frontier.
WALKER: And what could this look like at a very concrete level? What are we actually writing into the contracts, for example, that’s giving us influence over safety?
EGAN: Yeah. So I think you’d want to… I’m saying this without having thought super deeply about this, but I think you’d want some kinds of information sharing and incident reporting coming from frontier AI companies that aren’t just about the evaluations of models they’ve released publicly, but also about their internal models, which we know are the most capable and the least safeguarded models.
That in itself would give the Australian government much greater situational awareness. AI is just moving so quickly that you probably want to just build the capacity of the government, of our bureaucrats, to understand what’s happening and develop the right responses. And so some kinds of information sharing channels, some kind of incident reporting, some kind of engagement on testing of models – just like the UK AI Safety Institute does, and CAISI does in the US context. I think these things are a really good first-principles start, and then from there, as you kind of grow familiarity with what’s happening at the frontier, you can kind of refine and adjust the approach later.
Verifying international AI agreements
WALKER: So tell me about why we might want international treaties around the pace of AI, and then what verification might look like in that context. And then I’ll ask you some questions about how compute plays into this.
EGAN: Yeah. Timely question, because it’s been a big month or so for verification. So in July, I think folks would have seen there was a group of AI experts – so engineers and AI researchers across all major AI companies in the US signed an open letter saying: “We want to have the capacity to pace the frontier. We want the US government to do something for us to have this capacity. We need the tools and tactics and techniques so that we can pace.” And by “pacing”, it means shaping the trajectory and the speed of the frontier so that it better aligns with our ability to manage the risks.
Also last month, I was in the Vatican with the Global Nobel Laureates Assembly on AI and nuclear war, and it was a bunch of Nobel Prize winners and folks from the Vatican and other faith traditions talking about: what should we be doing about AI risk and nuclear risk? And the Rome Declaration that came out of that was quite similar to this, in terms of it was urging countries and nations and organisations to not advance into recursive self-improvement without first having an ability to monitor, understand and halt that if necessary.
So what this means is we’re starting to see demand for agreements, or rules or norms, around the frontier of AI. And it’s coming from both industry and other actors in the ecosystem. But the interesting part of this is that we’re also in a dynamic here – internally in the US between companies, and also between the US and China – where there’s really strong racing dynamics. That is, companies are racing at the frontier to try and advance faster, outcompete their competitors, and be the leading company or leading country. Worse is that between the US and China you have this really low-trust environment.
So the question is: how can you actually put up the settings and the preconditions so that, if you do want to have a rule or a normative approach of how you do things, how can you actually verify that people are abiding by them?
And so this brings up verification technologies. This is a very nascent field of science: what are the technical parameters or technical tools that you can use to say, are you doing X or Y? Like, are you abiding by rule A? On this big data centre, are you running inference or training? The really complex thing about this is that we don’t yet have the rules that we’re trying to implement into technologies, and we don’t yet have the technologies to properly shape what the rules are.
It’s really similar to the nuclear agreements of old time, of 1963 or whatever, when they had their nuclear test ban treaty – the limited one. There’d been advances in seismic detection technologies, and it meant that everyone agreed to ban atmospheric tests and underwater tests, but did not ban underground tests, because the technology wasn’t good enough to clarify: was it an earthquake or was it an underground test?
So you saw this international agreement that was bound by the limitations of the technology of the time. And then since then, we now can distinguish between them, and you’ve got the –
WALKER: The Comprehensive Test Ban Treaty in the ’90s.
EGAN: Yes, yes, because technology developed to enable it.
Now, with AI, everyone’s trying to speedrun verification tech. And when I say everyone, about 50 people in the world. But people are trying to advance this rapidly, because we need to fly the ship as we’re building it. What’s that phrase?
WALKER: Build the plane as we’re flying it.
EGAN: That’s exactly right. Because we need to have some technical breakthroughs that allow for these agreements to happen between low-trust actors, and also think about the agreements we want to make to inform those technologies as well.
WALKER: So how does compute play into this?
EGAN: So out of the verification tools components, compute is like one of the more promising avenues to apply tools to. And that’s because data, algorithms – the other parts of the AI supply chain – you can copy and paste them in email around the world; they’re harder to verify. Compute is tangible, physical, in the real world, and so many people are looking at compute as the way to actually implement some of these tools.
So data centres [are] detectable – you can kind of see where they are. Can you account for the data centres and then say to each data centre: what are you working on? Can you prove that you’re only doing inference or doing training? Or that you can go to an AI company and say, through, like, hardware-based attestation… So some chips already have inbuilt in them a feature that allows you to prove certain things, a trusted execution environment. And so there’s some mechanisms in the hardware that can form as a trusted attestation of what is or isn’t happening on a cluster. And hopefully we develop the technologies to do that in a privacy-preserving way, so we’re not eroding all semblance of privacy to get these attestations, but we’re still able to say: no, we can trust this. It’s cryptographically verified that this is a true statement of what is or isn’t happening in this data centre.
WALKER: Now, verification of international treaties seems like an argument for having a lot of compute in a liberal democracy, rather than an argument for having compute in Australia specifically. Are there marginal benefits to doing this in Australia over another liberal democracy, like Japan or Canada or the UK?
EGAN: Yeah, I think this is separate to the build-compute-in-Australia argument. It’s a yes-and. So I’d be really excited to see the AI Safety Institute in Australia work on verification technologies regardless of Australia’s approach to compute, because it’s a public good.
I also think it’s important for actors that aren’t in the US and China to be working on verification technologies. And Australia has played a really interesting role in being such a close ally of the US and also such an important partner to China, that having more science advance from non-US and non-Chinese organisations can be helpful in increasing the viability and acceptability of some of these technologies.
WALKER: So on that, for the US-China dyad: wouldn’t our status as a Five Eyes partner and trusted US ally make us not a good candidate for hosting the compute used for verification of international treaties? Because we’re not neutral.
EGAN: I would de-link the verification of international treaties away from who necessarily hosts the compute, because, again, China hosts compute and the US hosts compute too.
The ambition is you have many different third-party countries around the world all working together on verification technologies. And so then you get a trusted reference architecture, or you get a trusted way forward, that is then testable, verifiable, [by a] wide range of partners. And so it’s less about who’s hosting compute and can you trust their word; it’s more: do we have the technology so you don’t need to trust?
WALKER: Mmm, makes sense. Random question, but I often hear people talk about our status as a Five Eyes country as being a reason why a major lab would want to host compute here. Do you know exactly what the mechanism is there? Is it concerns about the model weights being exfiltrated, or is it concerns about distillation, or…?
EGAN: Australia’s Five Eyes status gives us, Australia, a very special relationship with the US, and this flows down into: there’s shared intelligence reporting, there’s collaboration on cyber incidents. There is such close infrastructure that links our two intelligence communities together, that means that Australia is a much more trusted actor than someone who’s not in the Five Eyes.
And so if you’re thinking about managing emerging dual-use capabilities from advanced AI models, having that Five Eyes infrastructure – where you already know your counterparts, you’re used to sharing sensitive information, and you’re united by a common national security picture – is really helpful if you’re looking at, “Oh, wow, we’ve just discovered this new dual-use capability emerging at the frontier. How are we going to manage this?” And so it seemed to be much more of a partnership with the US in that way.
Copyright: the red line
WALKER: I see, I see. Okay, so, so far we’ve discussed why we would want to have a lot of compute in Australia, but I just want to finish on this question of what would it take to get it. And we’re going to focus mainly on copyright. We’ve already touched on copyright, but I have a few more specific questions about it.
But the first thing, just to help map out, I guess, what’s at stake here – and tell me if you think this is silly or not – but you could draw a very simple matrix with four quadrants. And this is from the perspective of a major AI lab looking for its second country for training compute.
So on the x-axis you have: you can only do inference in this country, or you can do inference plus training.
And then on the y-axis you have speed to deployment. So on the bottom half it’s slow, and then on the top half it’s fast.
This is super reductive, but if I was Anthropic or OpenAI, I might be using this to decide which countries I want to pick as my second homes for training compute.
And so at the moment, in this top-right quadrant we have Texas, and in the bottom-left we have Australia. And so really the question is how do we move here, right?
Now my question for you is: where is Japan? Because my sense is that Japan is in [the bottom-right] quadrant, but I don’t have a good handle on, like, time to power and speed of deployment in Japan.

EGAN: Yeah. I haven’t looked into this myself, but [I] have spoken to people who have. And the thing with Japan is that they’re – if I understand correctly, and people might prove me wrong after this – but they’re about to switch on nuclear reactors which bring online up to 11 gigawatts of energy in the near term.
WALKER: Oh, wow.
EGAN: So Japan has a different value proposition. They already have a text and data mining exemption, so training is a tick. They are not a Five Eyes member, and they are space constrained, but that’s just an engineering challenge. So Japan is pretty prospective.
I think some of the friction in engaging with Japan is: it’s not just to pick up and engage easily. You need to make sure you’re more across… you have to hire more local staff to do more of the planning and engagement, and it’s a different approach to how you get permits and approvals. I think why it is also less attractive is that it is a close partner to the US, but it is not as close as Australia, because of Five Eyes.
And so for companies that want to keep engaging in US government approaches to AI, having a partner empowered like Australia – who can come to the table, who’s like-minded, and can address some of these really difficult national security challenges, and the trade-off between open weights and bio-risk and all these difficult, complex things – culturally it might be easier to do that in a country that shares the same culture and language.
But at the end of the day, it’s an engineering thing, and so if Australia doesn’t move soon, it’s a likely option.
WALKER: I see.
EGAN: I won’t speak for another company’s decision, but my take is that if Australia just doesn’t move quickly… The pace of change behind these AI companies is massive. They think they’re building something that might hit RSI – recursive self-improvement – soon, and that could fundamentally change the strategic picture. So they’re wanting to move very quickly.
WALKER: And then I think Canada is probably just up here [in the top-right quadrant]. They’re a little bit faster than us; they also can’t do training at scale.
EGAN: Also need a copyright change.
WALKER: Yeah. So, if Australia isn’t the country of choice – if we don’t sort out the copyright barrier – then it seems like Japan is probably the next most likely choice, if you were a major lab like Anthropic or OpenAI.
EGAN: I think that’s one option. I don’t have a good model of what their… I shouldn’t speak for any lab, and I’m not employed [by them], and not representing them. I think there’s also an option to just displace more inference compute out from the US and have more training inside the US.
WALKER: Right, double-down on the US. So we spoke about it earlier, but just to quickly recap: do you want to just give a 30-second summary of how copyright is a barrier to training compute in Australia at the moment?
EGAN: Yeah, sure. So I often see people in government say: look at all these pros in Australia’s positive column – it’s like renewables, trusted jurisdiction – and then, sure, we’ve got this negative copyright, but we’ve got so many pros. Why does it matter? I think the misinterpretation here is that copyright is actually a red line for AI companies.
And if we put our AI company hat on and think about this: so they currently have fair use doctrine in the US, which, yes, is going through court cases, but is overwhelmingly being upheld to say AI training is fair use. And so the court cases where you’ve seen big payouts – they’re not about the data that was trained on, it’s about how that data was procured, through pirated books.
But US fair use doctrine, there’s a couple of central tenets to it. The first is that the use of the material is truly transformative, and across the board everyone says, look, yep, that seems to be ticking that box. But the second one is that it is not undermining a market for licences for that data.
Now, this second component is what is at risk if an AI company comes to Australia and pays for a licence here. Because if you start paying for copyright licences in another jurisdiction, you’re actually creating the very market that can be used to say, “Hey, fair use doctrine should not apply here.”
WALKER: And to be clear, you’re not only paying for licences for Australian data, but data globally, right?
EGAN: Global data, yeah.
WALKER: Because Australian copyright law protects global data.
EGAN: And so essentially, if they take this approach, they could be opening themselves up to fairly uncapped liability for all the AI training that they have done.
WALKER: Have you seen anyone actually unpack the economics here? Is it actually uncapped liability? So the cynic in me would – and this is like an alternative view – is like: okay, the copyright question may be headed to the US Supreme Court, and maybe Anthropic is not so much interested in a solution in Australia as it is in using Australia as a pawn in any potential case. And, you know, there’s a reason that they’re likely to float with a $2 trillion US valuation. They can afford to pay for licences. We shouldn’t take them at their word that this is a red line. That’s the cynical view that some people might have. I don’t necessarily share that view. I don’t have a strong view. I’d love someone to actually unpack the economics of it for me.
EGAN: I haven’t done that, and I haven’t seen it done. That could be really interesting. I guess, though, I am sympathetic… The principled view on this is: it seems insane that these big companies have, like, taken all human creativity and knowledge and used it to create these AI models, for which the creative industries are seeing no benefit. That seems like… I can understand why people have strong views on this.
But the pragmatic point is: if they don’t come to Australia, they can go elsewhere, including just in the US, and it’s about the level of their willingness to accept that risk or not.
The indications to me, from watching this play out over the last six months, has been that this is going to be a red line.
It also seems that they aren’t particularly price sensitive; they’re licence sensitive. And so companies are probably happy to pay into a fund that then gets redistributed to creatives, or at least have money exchange hands that makes it into the right pockets, as long as it’s not through the copyright framework.
WALKER: And on that, there’s a neat proposal by Good Ancestors for a fund and an authority-to-train-in-Australia licence, but the two are disconnected.
EGAN: A training permit. And I think that, in a way, it’s Australia having the ability to ask for concessions that companies wouldn’t be able, wouldn’t want to, or wouldn’t choose to offer the world, but are willing to offer one jurisdiction for the safe harbour.
But the other piece on copyright that hasn’t yet been talked about as much, but I think is really important as well, is that our current copyright law is not good for inference either.
WALKER: Yeah, so we were chatting on the phone last week and you mentioned this, and that was a great surprise to me. I had no idea that it was potentially a barrier to inference.
EGAN: So it’s not currently… And I want to caveat, I’m not a lawyer, but I’ve talked to lawyers about this.
It seems to be a bit of a ticking time bomb. So there’s a section in the Copyright Act that says you’re allowed to make temporary copies of a copyrighted work if it’s part of a technical process, but just short-lived and technical. So an example of this will be when you’re pressing play on a movie on Netflix: it actually already makes a copy to your computer – it downloads it so that you can watch it.
Now, that’s allowed, because it’s time-limited, in-session, and it’s part of the technical process. But there’s actually specific language in the Act that says that if it’s copying a work that would be a copyright infringement in Australia, even if it was trained overseas legally but hasn’t got coverage in Australia – that’s not allowed.
And the other key issue that comes up here is it doesn’t really allow for context holding between sessions as well. So inference is changing. It’s no longer a call and response. People are developing up their own personalised AIs that integrate different materials and have context and memory of these materials, and that’s part of their value offerings. And as we get AI that kind of looks to update model weights in response to learning potentially, or saves details across sessions and has persistent memories of different works – that seems to actually run afoul of Australian copyright law.
So at the moment it’s unclear how folks are approaching this. It seems like there’s this unsolved issue that is going to rise its head at some point, but it seems like an important thing to get right, to give the certainty to allow build-out to happen.
WALKER: Yeah, that’s so interesting. I had not considered that.
Do you know how much of a window we have in order to fix copyright, for training to happen in Australia, before major labs pass us by as a significant place for their AI training?
EGAN: I think it’s in a month or months, rather than a year. And it’s moving much more rapidly than Australian policy tends to move, which is why I’m really hopeful that we can do this and do it right in the near term. Once other jurisdictions become more favourable as well – like, if Canada decides to move first, if that happens, for example – all Australia’s leverage to ask for what it wants in return dissipates.
I think it’s also important to model how AI companies are thinking about AI progress as well. So we mentioned before about recursive self-improvement, which is the idea of technology improving technology. And this isn’t a new phenomenon. We’ve had technologies improving technologies since the Industrial Revolution. But with AI, it’s AI improving AI at machine speed. And so basically capabilities progressing way faster than our ability to monitor, understand, control them.
Now, there’s some estimates from people who are close to this subject that they’re looking at 2027 for that to happen. And I think [major AI labs are] looking to build out in other jurisdictions where they can have strong governance partners and thought partners in how to manage some of these issues too, and that window I think is closing as well.
WALKER: So we’ve got to sort out copyright in the next month or two?
EGAN: That’d be good. I mean, I don’t think there has to be legislation that’s passed in the next month or two. I think there has to be a clear commitment to make this happen.
WALKER: So that decisions can be made.
EGAN: And so that decisions can be made and build-out starts to occur.
WALKER: Say the Australian government does give those clear commitments in the next month. Do you know what happens next, from a build-out perspective? Where does the next gigawatt-scale cluster in the pipeline go up? Where does the training compute get located?
EGAN: I don’t have good answers on that.
WALKER: Okay, all right.
The maximally ambitious path
WALKER: Last question. So if the PM was fully bought into compute in Australia what would the maximally ambitious execution of that vision look like? Does it require setting up special compute zones in remote Australia? What’s the mechanism there? Do we need to rely on the defence power in the Constitution? Is there some role for AUKUS Pillar 2 here? What are the actual mechanisms that the federal government could rely on if it really wanted to go for this opportunity in a maximally ambitious way?
EGAN: I love the special compute zones project that the Institute for Progress outlined. That seems net good to me. But I think Australia can be super ambitious on doing things quickly if it wants to. Even other jurisdictions have done this. So we look at Operation Warp Speed – which I know you’re familiar with – the manufacturing of COVID vaccines that the US government did through public-private partnership during COVID. It brought it down to 11 months total, from start to finish, and I think the normal range was between eight and 20 years to develop a vaccine, and the previous record holder I think was around four years, for the mumps vaccine. Humans can just do so much good stuff if there’s the right urgency and empowerment of people to do stuff.
So I think the trick for this project is making sure that it’s being built – to borrow the government’s words – built on Australia’s terms, in a way that benefits Australia. And Australia currently has a lot of leverage if it wants to be a first mover here. It can ask for a lot from the AI companies, and so that can range from BYO power, grid upgrades, clean energy, bringing talent to Australia, engaging with universities in some programs. And so I think you’d want to have your demand list right.
But then you want to make sure that the first instance of doing this ambitious project demonstrates we can move into the fast quadrant, because that’s what will attract more and more investment and give Australia more leverage in the longer term.
And so I think special compute zones make sense of – rather than allowing an actor to go through the long, many-aspect process of getting the permits in many different jurisdictions and discussions, actually bringing that process together, [in a way] that still really honours the necessary engagement with communities and impacted areas, making sure that there’s buy-in from different parts of the community and society, but actually just speedrunning that, because a lot of the time is actually just wasted in the friction between federal, local, state governments. So yeah, I’m pretty excited about what can be done in this space, if the government wants to turn its mind to it.
I think in Good Ancestors’ proposal you mentioned, there was actually a part of it that talked about: it’s not just the copyright safety that you get when you sign up for a training permit, it’s assistance from the government to work your way through all the processes and make sure that they happen in a way that’s conducive to moving quickly.
WALKER: Yeah, just on special compute zones: when I asked Andrew Charlton about this in our podcast, he said that he thought this would probably happen endogenously and we may not need to set up special compute zones. I’m curious: in your conversations with Australian policymakers, have you come across anyone in your travels who is thinking about special compute zones? Do you know if this is an active conversation?
EGAN: I haven’t found it particularly active in Australia. I do know of some… We do already see, with states and territories, some competition as to who can capture investment in this field, which I think goes to the endogenous creation of these zones, or making things move quickly. But I do think there’s probably low-hanging fruit in terms of what friction you can cut through, and then in exchange for what security uplift you can demand from companies as well.
WALKER: And have you also heard this idea that AUKUS Pillar 2 could be some kind of framework here?
EGAN: Yeah, it’s been one I’ve talked about – about six, 12 months ago, it was part of a discussion. I think there’s a range of different ways you could take it forward, because I think engaging the US government to say, “Look, you’re having more data centre pushback domestically. It’s important to run fast on these technologies. We can help.” My question is whether it’s best pushed through Pax Silica, which goes very much into – its germane issue is managing critical supply chains and partnering with allies on this. That seems a sensible way forward.
AUKUS Pillar 2 – and I haven’t touched this issue for a while, so I’m not sure who is the key champion in the US government for it… While Pax Silica has a key champion in the US government, and so, with the Trump administration, you want to have a champion for your initiative to get things to move quickly.
WALKER: I see. Say we went for this maximally ambitious approach, did everything we needed to: how many gigawatts of AI compute in Australia in the next two or three years?
EGAN: Look, I’m going way out on a limb here. I’m going to say six, and people will laugh at that. Some people will be like, “That’s not enough, that’s stupid.” Others will be like, “That will never happen in that timeframe.” But I think there’s ways to be ambitious, and solar is pretty quick to bring online.
WALKER: That seems pretty plausible to me, six. And ambitious, right? Because that would be all of OpenAI’s training compute, right? Or something on that order.
EGAN: Yeah.
WALKER: Yeah. All right, really enjoyed this. I’ve learned a lot. Thank you so much.
EGAN: Thank you for having me.
WALKER: Pleasure.