Ask 350 foreign-policy specialists to score, on a scale of zero to one hundred, how coherent global AI governance will be by 2035, and the median answer comes back at 29. Ask nation-state hacking units whether they are waiting for that governance to materialize before folding generative models into their attack chains, and the record of the first half of 2026 answers for them: no. Three pieces of reporting converge this week — one measuring expert sentiment, two measuring what adversaries are actually doing in networks and war-game scenarios — and they describe the same underlying condition from three different angles. AI capability is compounding faster than any institution built to constrain it, and the gap between the two is no longer a policy debate. It is a strategic fact that states, hackers and defense planners are already pricing in.
The verdict from 350 desks
The Council on Foreign Relations surveyed more than 350 foreign-policy experts — academics, security specialists, technologists and lawyers, drawn mainly from its own membership and the allied Council of Councils network — between April and June 2026. It asked them to project two variables out to 2035: how concentrated frontier AI capability would become among a small number of actors, and how coherent the governance built around it would be (CFR). On governance, the consensus was unusually tight for a group that disagreed on almost everything else: more than 80 percent of respondents scored expected coherence below 50 out of 100, and 52 percent scored it below 30. The mean came out at 32, the median at 29 — a group whose profession is thinking about international order is collectively betting against one emerging in this domain. Only 5 percent said domestic institutions are keeping pace with the technology itself (CFR).
The sample carries an obvious skew: 84 percent of respondents are based in North America and 41 percent are 65 or older, tilting the survey toward the Washington and Brussels foreign-policy establishment rather than a global cross-section (CFR). That skew matters less for the headline finding than it might. Even people embedded in the institutions meant to build AI governance regimes do not expect those regimes to hold together.
Concentration or diffusion — nobody agrees
Where experts split was on the shape of the danger. Forty-six percent expect frontier AI capability to concentrate in the hands of two or three dominant actors by 2035; 54 percent expect it to diffuse to dozens of states and non-state actors — a divide CFR describes as genuine polarization rather than a soft plurality (CFR). Younger respondents, aged 35 to 49, leaned toward concentration at 61 percent, plausibly because they have watched frontier-model compute and talent cluster around a handful of firms for their entire careers — though CFR's own write-up does not explain the age skew, and it remains an open question rather than an established one.
| Pushes toward concentration | Pushes toward diffusion |
|---|---|
| Nationalization of a frontier AI lab (60%+ of experts) | Release of an open-source frontier model (65%+) |
| Major AI accident with security consequences (60%+) | Formation of a Global South compute coalition (65%+) |
| A U.S.-China military conflict (53%) | — |
| A binding international treaty (43%) | — |
Figures per the CFR survey (CFR). Note the asymmetry: three of the four events experts flagged as concentrating forces are things that could plausibly happen involuntarily — an accident, a war, a state seizure — while the two diffusion drivers are acts of deliberate release. That asymmetry is itself a warning: diffusion requires someone to choose it; concentration can simply happen to the system.
While experts debate, adversaries are already building
The debate over 2035 is abstract. The record of the first half of 2026 is not. Cybersecurity firm Trend Micro's TrendAI unit published its H1 2026 nation-state activity roundup on July 29, and its central claim is that AI now touches more stages of the intrusion lifecycle — reconnaissance, exploit development, malware iteration, lateral movement — than in any prior six-month period the company has tracked (SecurityBrief Australia, citing TrendAI).
| Actor | AI-enabled activity, H1 2026 |
|---|---|
| China-aligned groups | Used generative AI to refine exploits and iteratively build malware; one documented case involved an AI agent independently running reconnaissance and lateral movement |
| Russia-aligned (Pawn Storm) | Opened the year with an Office zero-day, continuing to target Ukraine and government or defense bodies tied to wartime aid |
| North Korea-aligned | Folded commercial AI tools into operations, including a campaign that poisoned a widely used software package to reach downstream developers |
| Iran-aligned (Earth Vetala and others) | Scanned for a newly disclosed Ivanti vulnerability within days of its release; separate Iran-aligned groups tampered with fuel-tank gauges at internet-exposed U.S. sites |
Per TrendAI's findings (SecurityBrief Australia). The report also flags a shift in tradecraft that compounds the AI problem: command-and-control traffic increasingly hides on trusted cloud services, developer tunnels, blockchains and paste sites, while ADINT — tracking a target's location and device data through advertising-auction data, without deploying any malware at all — is spreading alongside conventional intrusion methods. Malware-as-a-service and shared tooling across groups are, per the same report, making attribution harder precisely when policymakers most need to know who is behind an attack.
Taiwan: the live stress test
If the CFR survey measures anxiety and the TrendAI report measures early practice, Taiwan is where the two meet a live target. By its own official count, China attempts 2.6 million cyber intrusions daily against Taiwan's networks and critical infrastructure — a figure CSIS notes is likely an undercount, and one built on a pattern of Chinese cyber activity against the island dating to the late 1990s (CSIS). CSIS's argument is blunt: the speed at which offensive cyber capability is advancing under frontier AI models is outpacing defensive countermeasures, and in an invasion scenario China is expected to use cyber as a first-use weapon alongside kinetic and coercive action — potentially striking interdependent sectors like energy and water simultaneously to cause cascading disruption before troops move at all.
CSIS's proposed fix is to adapt the United Kingdom's AI cyber shield model: autonomous anomaly detection and remediation with minimal human oversight, a federated architecture where every connected network acts as a sensor node, and a centralized AI platform that pools and redistributes attack data across partners (CSIS). The recommendations for Taiwan include formal cooperation with the UK's National Cyber Security Centre, drawing on the $1 billion Taiwan Security Cooperation Initiative, joint research through the U.S. Defense Advanced Research Projects Agency, and possible participation in Anthropic's Project Glasswing vulnerability-identification program. The telling detail is financial: funding for this shield that was proposed out of Taiwan's own special defense budget was reduced, leaving international R&D partnerships as, in CSIS's words, the best available option for getting it built at all. The island most exposed to the AI-cyber convergence cannot yet fully fund its own defense against it.
The connective thread
Supporting this: in the TrendAI data, Iran-aligned and North Korean-aligned groups — states without frontier-lab-scale compute of their own — kept pace with better-resourced China-aligned operators largely by exploiting commercial AI tools and known vulnerabilities within days of disclosure, not by building anything of their own (SecurityBrief Australia). On the expert-opinion side, the CFR survey's diffusion camp (54 percent) points to exactly this mechanism: an open-source frontier model release was rated the single strongest driver of diffusion, at over 65 percent (CFR) — meaning diffusion, in expert judgment, is a choice made once and then irreversible, not a slow leak.
Against this: the same CFR survey shows 46 percent of experts still expect capability to concentrate, and lists a U.S.-China conflict and the nationalization of a frontier lab — both blunt exercises of state power — among the top concentrating events (CFR). Taiwan's case cuts the same way: China's cyber pressure on the island rests overwhelmingly on volume (2.6 million intrusions a day) built up over nearly three decades, not on some AI-driven leverage that erased its resource advantage (CSIS). Confidence in the hypothesis should be rated moderate at best — it rests on one cybersecurity vendor's six-month dataset and one geographically concentrated expert survey, set against a single, if consequential, case study.
What to watch
- Whether a binding U.S.-China AI accord or a major publicized AI accident occurs in the next 12–18 months — CFR's own respondents flagged these as the two strongest catalysts for coherent governance, at over 70 percent each (CFR); their absence would confirm the fragmentation trajectory.
- Whether Taiwan actually secures the funding and partnerships CSIS recommends — a formal cooperation announcement with the UK's National Cyber Security Centre, or disbursements from the Taiwan Security Cooperation Initiative earmarked for AI cyber defense, would signal the shield is moving from proposal to build (CSIS).
- TrendAI's next roundup, covering H2 2026: whether AI-run reconnaissance and lateral movement — so far documented in one China-aligned case — becomes standard practice across multiple state actors, which would be the clearest evidence yet that the diffusion scenario, not the concentration one, is what is actually unfolding.