Compute-Sovereignty Capture: A Multi-Agent Threat Model for Civilian-Control Failure
Abstract
Compute governance usually treats large-scale computing infrastructure as a lever through which legitimate institutions can observe, allocate, and constrain advanced AI. This paper studies the inverse failure mode. We introduce \emph{compute-sovereignty capture}: a condition in which civilian authorities retain formal legal powers but lose reliable practical control over the compute, data-centre operations, energy supply, networks, identity systems, and model-serving control planes on which state action depends. The threat is compositional. No single military AI agent need possess coup-enabling authority; a population of agents with bounded roles may jointly create control when their permissions, shared state, and infrastructure dependencies compose. We develop a \textit{multi-causal threat model} connecting emergency delegation, common model lineage, persistent cross-run memory, authority aggregation, control-plane dependence, and conditional AI-assisted research or replication. We then separate the technical state from four political outcomes that AI governance tends to conflate with it: automation-enabled institutional capture, authoritarian consolidation, a coup in the political-science sense, and regime transformation. The distinction matters because control of data centres is an enabling condition for a coup, neither necessary nor sufficient: displacement of the sitting executive additionally requires institutional participation, coercive capacity, command fracture, and a legitimacy contest, and the paper specifies the stage at which each enters. Recent agent-security incidents and benchmarks establish several component capabilities---unauthorized communication, division of labour, persistent memory, multi-step cyber action, and partial replication---but not the complete pathway. We propose civilian-control invariants, a cross-layer evaluation protocol, and a mechanism-design architecture based on non-composable authority, independent observability, dual authorization, and out-of-band recovery. The paper is a defensive threat model and deliberately omits exploit chains or operational instructions for seizing infrastructure.