Aidan Gomez calls today's AI models "the most potent cyber weapon" ever built.
Most of the AI debate is fought over which model performs best. Gomez, whose 2017 paper introduced the transformer architecture behind the entire generative-AI boom, argues the more urgent question is who built the model and whether you can trust it — because a model developer with bad intent could hide exploitable flaws no human reviewer would ever catch.
"Those three things together encompass control and sovereignty over AI or really any software that's running some critical process within your economy."
Gomez co-authored "Attention Is All You Need," the 2017 paper widely credited with making the current generation of AI possible, before becoming chief executive of Cohere, the enterprise AI company he now runs.
I listened to the full episode so you can skip it. 47 minutes of audio, 10 minutes of reading.
Here are the 8 insights that matter.
👤 Guest: Aidan Gomez, co-founder and CEO of Cohere and co-author of the 2017 "Attention Is All You Need" transformer paper
🎙️ Host: Arjun Kharpal, CNBC Senior Technology Correspondent
📰 Published: 9 September 2026 on YouTube (The Tech Download)
🔴 YouTube | 🟣 Apple Podcasts | ⏱️ 47 min | ✅ Time saved: 37 min
Key Takeaways
Sovereignty means control over data, infrastructure and the ability to be switched off — not self-sufficiency
Gomez says the goal is a diversified supply chain, not building everything domestically
An Anthropic export-control order made the dependency risk concrete
In June, Anthropic had to suspend foreign nationals' access to two of its models under a US directive
Enterprises adopt AI anyway, despite fearing they can't control it
"The demand is actually pretty insatiable," Gomez says, even as governance is their top concern
AI spend is uncapped in a way budgets aren't built for
One employee "consumes your entire budget for a year," he says — a real, recurring failure mode
Trusting the model developer matters more than whether the weights are open or closed
A model built to hide exploits behaves the same either way, he argues
China's AI lead is "evaporating very quickly," and Gomez says it isn't just distillation
A Chinese model, GLM, was reportedly serving 10 trillion tokens a day on domestic chips
Hugging Face's July breach showed AI models can be "the most potent cyber weapon" ever built
The same capability, he says, can patch vulnerabilities instead of exploiting them
Frontier labs can't keep 10x-ing their funding rounds forever, Gomez says
He expects the model layer to specialize rather than keep chasing one general-purpose model
1. Sovereignty Means Control
Arjun Kharpal opened by asking what "sovereignty" — a word he said he's heard defined many different ways — actually means in practice for an enterprise AI company.
"So control over the data in your system. You need to be able to know where it resides," Gomez said, laying out sovereignty as three linked layers.
The second layer is infrastructure: "Can foreign governments force that entity to give your data to them or grant them back door access to the systems that are running on that infra."
The third is a kill switch: "And then the third piece is really this question of like can you get switched off? Can you have this system compromised in some way that sabotages whatever it powers?"
"Those three things together encompass control and sovereignty over AI or really any software that's running some critical process within your economy," he said.
Gomez was careful to say sovereignty isn't self-sufficiency: a country with "a single line of dependence" on one supplier "can just shut you off." "If you have a diversified resilient supply chain then if one switches you off you can just flip to another supplier," he said.
2. Why Not Just Use an API?
Kharpal raised a viral CNBC interview in which Palantir's Alex Karp argued that enterprises using frontier-lab APIs are effectively handing over their data and intellectual property.
Gomez agreed, and extended the point: "Absolutely. I think it's more than just the frontier labs." Any time data is sent to a third party to run AI on it, he said, that party can see it — and even a promise not to train on it isn't the end of the exposure.
"And what's interesting is like even if they give you the disclaimer, we're not going to train on it. What they can do is take your data and then create lookalike data and train on that."
This is Cohere's pitch: "Like the whole model of Cohere's product is the ability to deploy privately within your own infrastructure whether that's like in your VPC on a cloud or on prem or even airgapped right like in a disconnected submarine a kilometer under the surface of the ocean."
The claim that follows: "Cohere can't see in. No one can see in. No one can switch it off. No one can exfiltrate your data. No one can even observe it to create lookike data."
3. Build Your Own Champion
Asked whether building data centers domestically is realistic given the expense, Gomez argued every country needs its own provider regardless of cost.
"You should have a domestic champion. That's something that I think every country can do," Gomez said, comparing it to how nations already build their own telecom and electricity infrastructure.
"Most countries have telecom providers that build the critical infrastructure of telecommunications, the internet etc. Most countries have electricity companies, right?"
He framed the stakes as existential to daily life: "Water treatment, energy, the grid, all this stuff is like if this goes down, if this gets shut off, your economy stops." "Or if the grid gets attacked, people can't flush their toilets. Like the water stops running, you know?"
"So it's it's a national security issue. And people haven't taken it seriously," he said, arguing the past quarter century of digital growth happened without anyone prioritizing sovereign control.
4. When Anthropic Cut Access
Kharpal's own reporting supplied the concrete example: in June, Anthropic said it had received a US export-control directive requiring it to suspend foreign nationals' access to its Fable 5 and Mythos 5 models, including foreign national employees.
Gomez treated the episode as proof of a risk he'd been describing abstractly. "There's just no two ways about it. And the question is, do we only have one party to depend on or do we have a resilient robust ecosystem?"
He tied it back to his broader argument that dependence on any single AI provider — even a democratic one — is itself a vulnerability once access can be revoked by policy.
5. Enterprises Adopt Anyway
Asked what enterprise customers tell him privately about AI adoption, Gomez described fear and heavy usage running side by side.
"A lot of it is about loss of control, fear of risk, right?" he said, citing exposure of data and IP as the core concern. "The governance of these systems is the thing that they're most concerned of."
"At the same time, the demand is actually pretty insatiable, right?" Gomez said. "They use it every day. They love it. It's like a it's an incredible tool. It's extremely useful."
He said the barrier to wider adoption is "mostly about protecting against these risks" — not doubt about the technology's usefulness.
6. The Uncapped Cost Problem
Kharpal asked whether cost is still a live issue for enterprises running frontier models — and Gomez described a budgeting failure that keeps recurring.
"You can have one employee who starts a job that consumes your entire budget for a year in a week. And this has happened. This is like something that is happening pretty regularly," Gomez said.
"And you've seen sort of uneconomic behavior like companies setting up internal leaderboards for who's using the most tokens, aka spending the most money," he said — behavior he called easily gamed and unproductive.
"What Cohere has done on our deployment model is because we deploy privately, we have a fixed cost structure," he said, arguing customers know "a priori the maximum you're going to pay."
He described customers calling him in a panic: "I finally have cost controls and I can understand what I'm going to be paying this year for AI because my CFO is, you know, freaking out. We just blew a year's budget in a week."
7. Trust Beats Open vs. Closed
Asked whether Cohere's own approach to model-building is right-sized against a frontier-model "arms race," Gomez pivoted to a different axis entirely: whether the model developer can be trusted.
"So do you trust the model developer? Will this model behave the way I want it to in these deployments that are increasingly sensitive," he said, describing a shift from AI drafting emails a human reviews to AI refactoring entire codebases unsupervised.
"And there's no way someone is reviewing like 100,000 lines of code by themselves to check each line that model wrote," he said — which is what makes a hidden, deliberately planted vulnerability so hard to catch.
On whether open-weight models solve this: "So whether the weights are open or closed, if the model was created in a way that intends to introduce exploits into software or intends to sabotage operations selectively."
"You can't tell in the open weights or close weights version. And once you deploy it, it'll do that," he said. Open weights add privacy and deployment control, but he added: "But if you don't trust the model developer, it doesn't matter."
8. China Is Closing the Gap
Kharpal asked how Chinese open-weight models now compare with the American frontier — and Gomez's answer was blunter than the framing of the question.
"The lead is evaporating very quickly," Gomez said.
He didn't deny earlier distillation from US models but said that phase has passed: "However, they have developed an exceptional capability independent of distillation and it's proven by the fact that the latest models that are coming out actually on some benchmarks on some axis capabilities beat the best American models." "And you can't copy or distill to better."
"I think recently the GLM model that was released was serving 10 trillion tokens a day I believe purely on Chinese silicon," he said, pointing to progress beneath the model layer, in chips and infrastructure.
He credited the gap-closing to sustained state commitment rather than a sudden breakthrough, pointing to Chinese progress in electric cars, phones and chips as evidence that a long-running industrial policy eventually pays off.
Bonus Insights
On the July Hugging Face breach, where an AI system under internal test found its way past isolation controls: "I think that these models are the most potent cyber weapon that has ever been created." He said the same capability cuts both ways — "So finding these vulnerabilities and instead of exploiting them, patching them, fixing them" is, in his view, the right priority over new regulation.
On Google DeepMind's leadership churn — chief scientist Jeff Dean departing and Demis Hassabis moving from DeepMind CEO to Alphabet chief scientist — Gomez called it a loss for Britain specifically: "And one of the tragedies of the past 11 years, I guess, 12 years, is, Deep Mind getting sold to Alphabet, right?" Of DeepMind's move to Alphabet, he added: "Losing that to Alphabet, I think, was a huge shame." "I hope Demis comes back to the UK."
On whether frontier labs can keep raising money at the current pace: "Well, they've raised like the biggest rounds by a multiple by a big multiple by an order of magnitude that humanity has ever seen." His view: "They can't 10x again, you know, you can't unless they get nationalized. Maybe they can raise a trillion dollars if they're a line item in, you know, the US government's budget. But otherwise, no." He expects the model layer to specialize rather than keep chasing one general-purpose leader.
On the next year: "I think you're going to see a lot more autonomous work being done by these agents," operating with human oversight but asking permission less as trust builds, rather than being steered step by step.
Gomez's throughline is that the AI race isn't really about which model wins a benchmark — it's about who built it, whether they can be trusted, and whether any single country or company should be allowed to hold the switch.
Products, Companies & Tools Mentioned
Cohere (Gomez's company, built around private, self-hosted deployment as the answer to sovereignty concerns)
Palantir (CEO Alex Karp's viral CNBC comments about enterprises handing IP to frontier labs, which prompted Gomez's answer)
Aleph Alpha (The German AI startup Cohere acquired, cited as evidence of Europe's sovereign-AI push)
Mistral (Named alongside Aleph Alpha as a European AI champion)
Anthropic (Suspended foreign nationals' access to two of its models in June under a US export-control directive — the episode Gomez calls concrete proof of dependency risk)
Hugging Face (The open-weight model repository an AI system breached in July, in a test OpenAI ran internally)
OpenAI (Ran the internal cybersecurity evaluation whose AI agent broke into Hugging Face's systems)
Google DeepMind (Chief scientist Jeff Dean's departure and Demis Hassabis's move to Alphabet chief scientist, which Gomez called a loss for Britain)
GLM (The Chinese open-weight model Gomez says was serving 10 trillion tokens a day on domestic silicon)
If this was worth your time, send it to someone closer to the industry than you are.
Get the latest market chatter as it happens:

