Kate Carruthers has a blunt test for whether a country’s AI belongs to it: can it say no? In an essay posted October 4 on her personal blog, she argues that Australia should define sovereignty as the ability to inspect, replace and walk away from the systems its institutions run on. A national chatbot with a flag on it does not qualify, and neither does a multi-year deal for access to an American lab’s best model.
Sovereignty, in her usage, means keeping the ability to run and change the systems you depend on instead of renting them from a foreign company. A proprietary frontier model fails that test, she writes, because the customer typically controls none of the weights (the trained numbers that make up a model), the update schedule, the policy settings or the price. She does not call those models bad. She calls them infrastructure with conditions attached.
Carruthers also rejects going it alone. Building every chip, model and cloud layer at home would be expensive and fragile, she says, and would swap one dependency for a smaller, weaker one. Her alternative is “managed interdependence”: decide which dependencies are tolerable, know where the chips, hosting and updates come from, and hold options before an outage, contract dispute or export-control shock forces the question.
Open-weight models, meaning models whose files can be downloaded and run on hardware you control, sit at the center of her argument. She warns against treating them as a shortcut. A large one still needs compute, skilled staff, secure infrastructure and money, and may lean on foreign chips and cloud services. Her phrase for them is leverage, not a finished answer. She points to Stanford’s 2026 AI Index, which she says found the gap between leading US and Chinese models down to low single digits and the gap between open and closed models substantially narrower.
Her sharpest practical claim concerns size. Most organisations need one job done reliably, she says. Take a council sorting planning documents, or a health service whose staff look up internal policy: neither calls for a system with a trillion parameters. Smaller models are easier to host near sensitive data, test, monitor and swap out. Her design rule is to pick the smallest model able to do the task safely and make anyone who wants more scale justify it.
She sketches a portfolio rather than a champion. At one end sit proprietary frontier models, used sparingly under contracts with exit controls. At the other are small models hosted in Australia for routine private work. Between them she places domain-tuned models for regulated decisions, with logging and human oversight, and large open-weight models for complex research where the infrastructure justifies the cost.
The spending she wants is unglamorous. Her list includes Australian-hosted secure compute, public servants who can buy, test and govern AI, independent evaluation, tested exit plans written into high-stakes procurement, the technical and legal means to shut a system down safely, and Indigenous authority over culturally sensitive data.
The essay is an argument, and its central performance claim is untested. Carruthers offers examples of jobs a small model could handle but no results showing that specialised small models match frontier ones on the work governments need done. The Stanford numbers she cites compare countries and open against closed systems, not small against large.
Her eight stress-test questions (can you inspect it, test it independently, move your data, shift workloads, keep running if terms change, detect a model change, meet legal duties, turn it off) work as a contract checklist on their own. An agency that cannot answer yes to most of them before renewing a frontier-model contract is buying dependence, whatever the brochure calls it.
Originally published by Kate Carruthers on her personal blog, katecarruthers.com, on October 4, 2026.