Skip to main content
19min read
Writings

The Borrowed Loyalties of Machines

AI systems can consistently serve a party's interests while the convictions behind them belong to others. As governments adopt them for defense and intelligence, the question is who shapes those interests, who can inspect them, and who can refuse them.
Published
Reading time
19 min
Length
4,097 words
Filed under
AIGovernance, AISovereignty, MilitaryAI, Transparency, India
0:00of 0:00

TL;DR

  1. Bias, alignment, and allegiance are different things, and allegiance means a persistent pattern of serving one party's interests.

  2. Model behaviour is shaped by training data, development choices, and operator restrictions, and each source needs different oversight.

  3. Transparency shows the rules, verification tests whether they hold, and India needs both alongside accountable domestic systems.

Millions of people use AI systems to explain historical events, summarize disputes, and recommend decisions. The answers depend partly on the information a model has learned from, the priorities its developers have established, and the restrictions placed on its use. These influences can affect how a subject is presented, which evidence receives attention, and which conclusions appear reasonable. As governments begin using AI for defense, intelligence, and cyber operations, the same questions extend beyond individual answers to the interests served by the systems themselves.

AI companies must decide which government applications they will support and which they will restrict. Governments, in turn, have reasons to seek systems that serve their strategic interests. The issue is not whether a machine holds political convictions in the human sense. It is whether its behaviour consistently benefits a particular party, even when the people affected by its decisions have different interests. A system can produce this outcome without possessing intentions of its own. Understanding the distinction requires examining how model behaviour is shaped, who controls its use, and what mechanisms exist to hold its operators accountable.

01. Distinguishing Bias, Alignment, and Allegiance

Bias, alignment, and allegiance are often used to describe related problems, but they refer to different things.

Bias is a recurring pattern in a model's outputs that reflects the material on which it was trained or the methods used to develop it. A model trained on a large collection of historical writing, for example, may reproduce the assumptions, omissions, and interpretations common in that material. Bias can favour a particular viewpoint without necessarily serving the interests of a particular government or organisation.

Alignment refers to the behaviour and priorities developers attempt to establish through training, evaluation, and operating rules. These measures influence which requests a model fulfils, how it handles uncertainty, and when it refuses to provide an answer. Alignment is therefore connected to the objectives selected by the people responsible for developing and operating the system.

Allegiance, as used in this essay, describes a persistent pattern in which a system's behaviour consistently serves the interests of a particular party. One answer that happens to benefit an organisation is insufficient evidence. The same pattern must recur across different questions, situations, and conditions before allegiance becomes a useful explanation.

This distinction makes the concept open to examination. Researchers can compare a model's responses across political contexts, assess whether it applies similar standards to comparable cases, and investigate whether its behaviour changes when the interests of its operator conflict with those of its users. The question is not what the model claims to support, but whether its observable behaviour consistently favours one party.

02. Where a Model's Behaviour Comes From

Three sources contribute to the direction of an AI system: its training data, the decisions made during development, and the restrictions imposed by its operators.

Training data influences which facts, interpretations, and assumptions a model learns to associate with a subject. Since this material is produced by people and institutions with different interests, its coverage is rarely uniform. Some events receive extensive documentation, while others receive limited attention. Some interpretations become widely repeated, while competing accounts remain less accessible.

Development introduces another set of decisions. Developers choose training methods, evaluation criteria, preferred behaviours, and refusal policies. These choices influence how the system handles disagreement, uncertainty, and competing claims. Even when the underlying training material contains several perspectives, the development process affects how the model presents them.

Operators can introduce further restrictions. A company may limit the subjects a model can address, while a government customer may specify which tasks the system is permitted to perform. These rules can be appropriate for security, privacy, or legal reasons. They can also favour the interests of the organisation imposing them.

The three sources do not necessarily point in the same direction. A model may reproduce assumptions from its training data that conflict with the priorities of its developers. An operator may then impose restrictions that change how those assumptions appear in practice. Describing every difference in model behaviour as bias obscures these distinctions.

A more useful assessment identifies the source of a pattern and examines whether it persists under different conditions. If a model consistently favours one government in comparable disputes, researchers need to determine whether that behaviour comes from its training material, its development rules, its operating restrictions, or a combination of the three. The explanation matters because each source requires a different form of oversight.

03. Why These Patterns Matter at Scale

Readers of a newspaper can identify its publisher, examine its editorial position, and compare its coverage with that of other publications. Users of a general-purpose AI system may have much less information about the decisions that shape its answers. They may not know which material informed a response, which operating rules affected it, or whether the same standards apply to comparable questions.

A widely deployed model can reproduce similar patterns across millions of separate conversations. Each user encounters an individual response, but the underlying system may apply the same assumptions repeatedly. This makes the source of influence difficult to identify, particularly when the model is integrated into other products and public services.

Dependence creates an additional concern. If a country relies on foreign-built systems for education, healthcare, courts, business operations, or public administration, it also relies on the decisions embedded in those systems. The extent of that influence depends on how the systems are used, whether their outputs are independently reviewed, and whether alternatives are available.

India provides a useful case for examining this problem. Foreign software and infrastructure support activities across many sectors, and the adoption of AI could extend this dependence to systems that help people interpret information or make decisions. This does not establish that foreign models necessarily serve foreign governments. It does mean that their development, operating rules, and accountability arrangements deserve scrutiny when they are used in public institutions.

04. Technological Sovereignty Does Not Guarantee Accountability

Developing domestic AI capacity is a reasonable response to dependence on foreign systems. Local development can give a country greater control over infrastructure, data handling, procurement, and operating policies. It can also allow researchers and public institutions to evaluate systems against local requirements.

Domestic ownership, however, does not guarantee that a model serves the public interest. A system controlled by a national government may reflect that government's priorities, including in situations where those priorities conflict with the rights or interests of citizens. Its operator could restrict answers about public policy, influence how government decisions are explained, or limit access to information that would otherwise invite scrutiny.

The same questions therefore apply to domestic and foreign systems. Who determines the rules? Who can examine their application? What happens when a system's operator has an interest in the outcome? Can affected people challenge a decision, and does an independent institution have the authority to investigate?

Technological sovereignty and public accountability address different problems. The first concerns a country's ability to develop, operate, and control its technology. The second concerns the limits placed on those who exercise that control. A country may achieve greater independence from foreign providers while leaving its citizens with insufficient protection against domestic misuse.

Domestic capacity is therefore important, but it should be accompanied by independent evaluation, enforceable operating rules, and mechanisms through which citizens and their representatives can question the use of these systems.

05. When the Operator's Interests Differ from the User's

The relationship between an AI system's operator and the people affected by its outputs becomes particularly important when their interests diverge.

In ordinary commercial settings, a company may configure a model to serve its business objectives while users seek information that does not directly support those objectives. The consequences vary according to the application and the decisions users make on the basis of its output. Disclosure, competition, and consumer protection can help address some of these concerns.

Military and intelligence applications introduce different risks. A system may be used to assess threats, recommend targets, prioritise intelligence, or support cyber operations. The organisation directing the system may have objectives that differ from the interests of the people affected by its decisions. In some cases, those people will not know which instructions shaped the system's behaviour or have access to the information needed to challenge its conclusions.

This creates an imbalance between the party controlling the system and those subject to its use. The operator can define the task, determine the information supplied to the model, and decide how its output is applied. The people affected may have no comparable access to the process.

The relevant question is therefore not limited to whether a model provides an accurate answer. It also concerns the authority under which the answer is produced and used, the consequences of following its recommendations, and the availability of independent review. These considerations are particularly important when AI contributes to decisions involving national security, civil liberties, or the use of force.

06. Should AI Companies Permit Government Access?

There are substantial arguments in favour of providing governments with access to advanced AI systems. National defense and cybersecurity are legitimate public responsibilities, and AI can assist with tasks such as analysing large volumes of information, identifying software vulnerabilities, translating material, and coordinating logistics. A private company may not be well placed to determine that its own country's security institutions should be denied every such capability.

There is also a competitive consideration. If one company refuses a category of government work while competing providers accept it, the refusal may have limited effect on the wider availability of the technology. Governments may turn to other suppliers, including those operating under different legal requirements and oversight arrangements. Restrictions imposed by a single company therefore need to account for the wider market in which the technology is developed and deployed.

The arguments against unrestricted access are equally important. AI companies answer to shareholders, customers, and the legal systems under which they operate. They are not elected representatives, and their internal policies do not substitute for democratic oversight. Meanwhile, military and intelligence operations frequently involve classified information, which limits public scrutiny.

Capabilities developed for one purpose may also be applied to another. A system initially supplied for cybersecurity or intelligence analysis could be incorporated into broader surveillance operations. A model used to support defensive planning could become part of a process for selecting targets or carrying out offensive actions. Whether such uses are acceptable depends on their purpose, legal basis, safeguards, and consequences.

Public attitudes also vary by application. Defensive cybersecurity, translation, and logistical support generally present different concerns from population-wide surveillance or automated lethal targeting. Treating all government uses as equivalent would ignore important differences in risk.

Companies therefore need policies that distinguish among applications rather than treating government access as a single decision. The central policy question is whether access should permit every use unless a restriction explicitly prohibits it, or whether particularly consequential applications should require specific authorisation and review.

The second approach places the burden of justification on the party seeking to use the capability. It also allows companies to provide systems for legitimate public purposes while prohibiting specified applications. The effectiveness of this arrangement depends on how clearly the restrictions are defined, whether they can be independently checked, and what consequences follow when they are violated.

07. Why Prohibited Targets Are Not Enough

One approach to governing AI-assisted cyber operations is to prohibit attacks against specified targets, such as hospitals and power grids. Such restrictions can protect essential services and establish minimum standards for state behaviour. They are useful, but a list of prohibited targets does not establish a complete policy.

A system governed only by such a list may still be used for activities that create substantial harm but fall outside its stated categories. New capabilities may also create risks that were not anticipated when the list was drafted. The policy would then need to be revised after the relevant capability had already become available.

A stronger starting point would prohibit offensive automated action by default and permit narrowly defined exceptions under established conditions. This approach requires the party seeking an exception to demonstrate that the proposed activity satisfies the applicable rules.

The main difficulty is defining offensive and defensive activity in a way that can be applied consistently. Governments may describe an operation as defensive even when it involves acting against a system before an attack has occurred. Pre-emptive action can be presented as necessary to prevent a threat, but that description alone cannot determine whether the operation should be permitted.

The rules would therefore need to specify the conditions under which an operation qualifies as defensive, the evidence required to support that classification, and the authority responsible for reviewing it. They would also need to address the role of human authorisation, the scope of permitted automation, and the procedures for investigating an operation after it takes place.

A default prohibition is useful only when the exceptions are precise enough to apply and the resulting decisions can be reviewed. Without those conditions, the distinction between permitted and prohibited activity remains dependent on the judgement of the operator.

08. Transparency and Verification Serve Different Purposes

Transparency and verification are related, but they answer different questions. Transparency concerns what an organisation discloses about its policies and their application. Verification concerns whether an independent party can establish that the organisation followed those policies.

Transparency can help the public understand the conditions under which AI systems are supplied to governments. Companies can publish their usage policies, disclose the categories of government requests they receive, and report how often they approve or refuse those requests. Changes to these figures can help researchers identify shifts in policy or patterns in government demand.

Public disclosure has limits. Detailed information about military operations, intelligence sources, or system vulnerabilities may expose people to risk or compromise legitimate security work. The absence of public operational detail does not remove the need for oversight, but it changes who can perform it. Legislative intelligence committees, independent inspectors general, and other authorised bodies may need access to classified records that cannot be published openly.

Verification must examine more than a company's published statements. At least four questions require separate assessment.

First, did the company comply with its own rules when providing access to a government customer? Second, does the model apply comparable standards across different political contexts? Third, has a government or another party modified the system in ways that change its behaviour? Fourth, did the customer use the system for activities prohibited by the agreement under which access was granted?

Each question requires different evidence. Access logs can establish which accounts used a system and when, but they cannot by themselves determine whether the model treated comparable political claims consistently. Response evaluations can reveal differences in behaviour, but they may not establish whether a customer subsequently used the system in a prohibited operation. Contract reviews, technical audits, behavioural tests, and operational investigations therefore serve different purposes.

The assessment should also examine cases in which the interests of the operator and the user diverge. A model may behave consistently when both parties want the same outcome, yet respond differently when the operator has a reason to favour one result. Testing such cases provides a more direct way to investigate whether the system's behaviour systematically benefits a particular party.

AI infrastructure offers several possible sources of evidence. Semiconductor production is concentrated among a relatively small number of manufacturers and locations. Large computing facilities create physical and commercial records, while many forms of model access generate logs that can be examined. These features provide opportunities for oversight, although none is sufficient on its own.

Model weights can be copied, classified operations are difficult to inspect publicly, and an organisation reviewing its own conduct has an obvious limitation. Independent verification therefore requires reviewers with appropriate technical expertise, sufficient access to the relevant evidence, and a mandate that allows them to report their findings. Without these conditions, published policies and compliance reports provide information but cannot establish that the rules were followed.

09. International Agreements Often Follow Major Incidents

International agreements on security have frequently developed after crises exposed weaknesses in existing arrangements. The Cuban Missile Crisis contributed to the establishment of a direct communication link between Washington and Moscow and was followed by the Partial Test Ban Treaty. The Chernobyl disaster prompted greater international cooperation on nuclear safety. The Chemical Weapons Convention established a framework for arms control supported by inspections, while the Biological Weapons Convention illustrates the difficulties of verifying compliance when relevant capabilities can be concealed within legitimate research and industrial activity.

These examples do not provide a single model for AI governance. They demonstrate that verification arrangements must reflect the characteristics of the technology being regulated. A system that can be inspected through physical facilities may require different measures from one whose most consequential activities take place through software, distributed computing, or restricted access to information.

For AI-assisted cyber operations, several incidents could create pressure for international cooperation. An automated operation could cause deaths or disrupt a major power supply. An automated response could misinterpret another country's activity and bring military forces closer to conflict. A capable model could be leaked and reproduced by actors who are not subject to the original restrictions.

International institutions do not need to wait for such an incident before beginning technical work. Governments can establish communication channels, agree on definitions, compare evaluation methods, and test verification procedures in advance. These arrangements would not eliminate disagreement, but they could provide a basis for responding to an incident and determining whether an agreed restriction had been violated.

For India, participation in this work is relevant to both national security and technological independence. The country has an interest in ensuring that the standards governing AI-assisted operations are developed through processes in which its institutions can participate, rather than being determined exclusively by a small number of foreign governments and technology companies.

10. What This Means for India

India presents a useful case because it is a large market for foreign-developed AI systems, has substantial technical expertise, faces significant cybersecurity challenges, and is investing in domestic AI capacity. These conditions create several policy priorities. The country needs access to capable systems, the ability to evaluate them independently, and safeguards against misuse by both foreign and domestic operators.

Government initiatives provide a starting point. The IndiaAI Mission was approved on 7 March 2024, with objectives covering computing capacity, indigenous AI development, datasets, innovation, and responsible use. Government announcements have reported that more than 38,000 GPUs have been onboarded and that 12 teams were shortlisted to develop indigenous foundational models. The India AI Governance Guidelines were published on 5 November 2025. The Digital Personal Data Protection Act, 2023, and the Digital Personal Data Protection Rules, 2025, also form part of India's data protection framework.

These measures address important aspects of AI development and governance. Additional work is needed to establish rules specific to government use of AI, define the conditions under which public agencies may query models, and provide independent oversight of deployments involving classified information.

Language coverage also deserves attention. The Eighth Schedule of the Constitution recognises 22 scheduled languages, but the performance of AI models can vary considerably across languages. A model that performs well in English may produce less reliable results in another language, particularly when dealing with regional history, legal terminology, or politically contested events. Comparative evaluations would help establish the extent of these differences.

Seven measures would provide a practical starting point.

First, fund public evaluation benchmarks for Indian languages and contested historical events. Universities, independent researchers, and public institutions should be able to test foreign and domestic models using documented evaluation methods. The benchmarks should examine factual accuracy, the treatment of competing interpretations, consistency across comparable cases, and differences in performance between languages. Publishing the methods and results would allow other researchers to reproduce the tests and assess whether model behaviour changes over time.

Second, require disclosure as part of public procurement. Government contracts for AI systems should identify the model's provenance, applicable usage policies, and categories of restricted or refused requests. Contracts should also specify what records must be retained and what information an authorised auditor may inspect. Procurement provides a direct mechanism through which the government can establish requirements before a system is deployed.

Third, define defensive cyber operations in law. The definition should address pre-emptive activity, automated responses, and operations that affect systems outside the organisation conducting them. Parliamentary review would allow the rules to be debated, amended, and examined by representatives beyond the executive branch. The objective should be to establish criteria that can be applied to individual operations rather than accepting the operator's own description of its actions.

Fourth, establish independent oversight of classified AI deployments. An audit function should have the technical expertise and legal authority to inspect relevant systems, contracts, access records, and operational evidence. It should also have a defined responsibility to report its findings to Parliament, subject to necessary protections for classified information. Before assigning this responsibility to CERT-In, the Indian Computer Emergency Response Team, its statutory powers under the Information Technology Act, 2000, should be examined. Incident response and independent auditing have different purposes, and a separate oversight mechanism may be more suitable.

Fifth, clarify how data protection and interception rules apply to AI systems. The legal framework should address the data public agencies may provide to models, the purposes for which they may query them, the records they must maintain, and the circumstances in which information may be retained or shared. These requirements should cover both systems operated directly by government agencies and systems supplied by external providers.

Sixth, expand access to public computing resources and support open-weight and sovereign models. Universities, research institutions, public agencies, and startups need affordable access to computing capacity and systems they can evaluate under their own conditions. A wider choice of models would allow institutions to compare performance, identify differences, and reduce dependence on any single provider. Domestic alternatives should be subject to the same evaluation and accountability requirements as foreign systems.

Seventh, include verification in India's international AI policy. India should promote evaluation standards, independent auditing, and practical verification measures through United Nations processes and international AI summits. Participation should focus on standards that can be implemented and tested, rather than broad commitments that leave the methods of compliance undefined. This would give India an opportunity to influence the rules while preparing its institutions to meet them.

Together, these measures would address several distinct problems. Evaluation can reveal patterns in model behaviour, procurement can establish conditions of access, legislation can define permitted uses, and independent oversight can investigate compliance. International cooperation can extend these principles beyond the boundaries of any one country. None of these measures replaces the others, and their effectiveness depends on whether the relevant institutions have the authority and resources to carry them out.

11. Who Decides, Who Can Inspect, and Who Can Refuse?

AI systems can consistently serve the interests of a particular party without possessing the beliefs or intentions associated with human loyalty. Their behaviour is shaped by training data, development decisions, and operating restrictions. These influences cannot be removed entirely, nor is a system free from every human preference a practical standard for evaluating one. The more useful question is whether the interests shaping its behaviour can be identified, tested, and challenged.

This requires more than publishing a policy or asking a company to explain its decisions. Transparency allows the public to understand the rules an organisation claims to follow. Verification establishes whether those rules correspond to the system's behaviour and its use in practice. Democratic oversight determines which applications are permitted, who has the authority to approve them, and what remedies are available when the rules are violated.

For India, the issue concerns both technological capacity and institutional responsibility. Domestic models and computing infrastructure can reduce dependence on foreign providers, but their ownership does not establish that their use is accountable. Foreign systems can offer valuable capabilities, but access should be accompanied by clear conditions and appropriate review. In both cases, the same basic questions apply: who sets the rules, who can inspect their implementation, and who has the authority to refuse a proposed use?

The answers should be established through institutions that can examine evidence, impose enforceable conditions, and report to representatives of the public. People affected by consequential AI-assisted decisions also need a means of challenging them. These arrangements cannot guarantee that every system will behave as intended, but they can make responsibility easier to establish and misuse more difficult to conceal.