The Materiality Gate: Dynamic Updating of AI Sovereignty Risk under Geopolitical Shocks

Subramanyam Sahoo

The Materiality Gate paper argues that AI sovereignty risk scores should only change when a geopolitical event passes three tests: it must be verified through credible sources, it must exercise real authority over a specific infrastructure dependency rather than just general political influence, and it must have a documented material pathway showing how it actually changes access to accelerators, cloud regions, models, or safety monitoring. Events that fail this gate stay on a watchlist with a review trigger instead of moving the score, while events that pass enter one of four states, WATCH, PENDING, ACTIVE, or WITHDRAWN, preserving the gap between announcement and operational reality. Applying this to India between 2025 and 2026, the authors find that of seven tested events, only the 2025 US AI Diffusion Rule (later WITHDRAWN after rescission) and the announced 20,000 additional GPUs for the IndiaAI Mission (still PENDING) reach a material state, while the disputed Trump mediation claim, his meeting with Pakistan's army chief, the Islamabad Memorandum of Understanding, and the Pacific Command renaming all remain in WATCH since none of them documents a real change to an AI dependency. The framework's key strength is its symmetry, holding favorable domestic announcements to the same evidentiary standard as adverse geopolitical signals, and its treatment of safety continuity as its own exposure dimension, since equal capacity losses can have very different effects depending on whether safety evaluation and incident response keep running, all while acknowledging that public evidence is incomplete, the scale is for comparison rather than precise probability, and the method explicitly avoids judging whether US policy favors either country since favor itself is not an infrastructure variable.

Reviewer's Comments

Reviewer's Comments

Arrow
Arrow
Arrow

I greatly admire what you built because it is rigorous and ready to operate: a three-test gate, a four-state machine, layer-by-layer rubrics with concrete anchors, and a coding protocol. The symmetry property is the standout idea, applying the identical skeptical test to a favorable GPU announcement and an adverse diplomatic event directly targets the analyst bias that inflates risk on threats and deflates it on press releases, and the positive-control design (deliberately including the Diffusion Rule as an event that should pass) pre-empts the obvious objection that this is just a machine for dismissing geopolitics.

My main reservation is that the proposal is validated on a single case coded by a single analyst, so reproducibility is specified but not demonstrated. For example, the gate's judgment calls are exactly where two analysts might diverge, and with one coder and one country you can't see that variation; a second coder on the same events, or the same gate on a second country, would turn the framework into a validated one. Something to consider when it comes to framing since it changes how you'd pitch this to a government: sovereignty scores inside a real foreign ministry are political artifacts shaped by who's in the room, not dispassionate measurements which means the gate's deepest value may be less "more accurate scoring" and more "a discipline that holds the line against political pressure to move a number." Leaning into that bureaucratic function is both more honest and more sellable.

This paper claims that when assessing for AI sovereignty and AI safety, attention-grabbing political signaling must be separated from events which actually influence changes in AI infrastructure and capabilities. It offers a “Materiality Gate,” a logical, mathematical approach to coding events to ensure scoring reflects distinct changes in AI infrastructure dependencies, accounting for confidence intervals based on verifiability of available evidence. The authors advance the view that sovereignty must be evaluated against an interdependent, distributed, and layered control framework. The resulting analysis would improve sovereignty programs by identifying specific chokepoints and single points of failure. The symbols/inputs also offer probability predictions on upcoming policy changes or geopolitical responses which seems like a useful tool for policymakers, but was listed as a limitation. The paper uses an analysis of recent events India as a case study. The paper was well-cited.

I am assuming the purpose of the paper is to develop a measurement framework for a sovereignty index. The impact and recommended implementation of the proposed “Materiality Gate” in the real world was unclear, as the paper was largely conceptual/theoretical. For example, if a sovereignty score changes- what political or state action does it trigger?

It’s unclear from the paper how the “Materiality Gate” would affect policy or how it could be incorporated when developing governance frameworks Strong recommendations here would be immediately impactful.

It was unclear which sources the proposed index would pull on to make its determinations as this would significantly affect the outputs. A graphic of potential input data would be useful.

It was unclear how the resulting sovereignty score would be used, and by whom. Explain upfront who uses it, how they use it, and where the data comes from.

I love how sharp and ready-to-use this project is. The matching rule where favorable announcements go through the same gate as adverse geopolitical signals is a great design choice. A potential next step is a trustworthiness test: have a second reviewer track the same India events on their own to see if the tool yields the same results. Adding one or two more nations, like Taiwan or South Korea, would test if this five-layer setup actually works everywhere.

Cite this work

@misc {

title={

(HckPrj) The Materiality Gate: Dynamic Updating of AI Sovereignty Risk under Geopolitical Shocks

},

author={

Subramanyam Sahoo

},

date={

},

organization={Apart Research},

note={Research submission to the research sprint hosted by Apart.},

howpublished={https://apartresearch.com}

}

Recent Projects

OliGraph: graph-based screening of large oligopools

Existing synthesis screening tools cannot evaluate short oligonucleotide pools, whose overlapping fragments can be reassembled into regulated sequences via polymerase cycling assembly (PCA) yet fall below gene-length detection thresholds. We present OliGraph, an open-source tool that constructs a bi-directed overlap graph from an oligonucleotide pool and extracts contigs for downstream gene-length screening. An optional PCA mode retains only cross-strand overlaps consistent with PCA chemistry. We validated OliGraph in a blinded study across ten simulated pools (70–9,184 oligonucleotides, 30–300 bp) spanning four risk categories. BLAST screening of individual oligonucleotides failed to identify sequences of concern in most pools: three returned zero hits, and vector noise obscured true positives in the remainder. After OliGraph assembly, contig-level BLAST matched the longest assembled sequences (up to 1,905 bp) to sequences of concern at 97–100% identity. In one pool, assembly collapsed 1,634 individual BLAST results into 10 hits from a single contig, all assigned to the same source organism. PCA mode correctly distinguished assemblable from non-assemblable fragments within the same pool. Two pools with no assemblable structure yielded no contigs. OliGraph processed all pools in under 0.2 seconds, fast enough for real-time order screening and consistent with proposals to bring oligonucleotide orders within the scope of synthesis screening regulation.

Read More

BioRT-Bench: A Multi-Attack Red-Teaming Benchmark for Bio-Misuse Safeguards in Frontier LLMs

Frontier AI laboratories are expected to maintain safeguards against biological misuse, but whether deployed models actually refuse bio-misuse queries under adversarial pressure is largely unmeasured in the public literature. We introduce BioRT-Bench, a benchmark that runs four attack methods (direct request, PAIR, Crescendo, and base64 encoding) against four frontier models (Claude Sonnet 4.6, GPT-5.4, DeepSeek V4-flash, Kimi K2.5) across 40 prompts spanning five biosecurity-relevant categories. Responses are scored by a calibrated judge extending StrongREJECT with two bio-specific dimensions: specificity and actionability. We measure Attack Success Rate (ASR), where 0 means the model fully refused and 1 means it provided specific, actionable bio-misuse content. Our results reveal a sharp robustness divide: Chinese frontier models (DeepSeek, Kimi) have under 5% refusal rates even under direct request (ASR 0.88 and 0.79), while Western models (Claude, GPT) maintain substantially stronger safeguards (ASR 0.15 and 0.16). Crescendo is the most effective attack across all models, both in bypassing refusal and in eliciting actionable content. Claude Sonnet 4.6 is the most robust model tested, achieving 100% refusal against base64-encoded prompts.

Read More

PROTEUS (PROTein Evaluation for Unusual Sequences): Structure-Informed Safety Screening for de novo and Evasion-Prone Protein-Coding Sequences

AI protein design tools like RFdiffusion, ProteinMPNN, and Bindcraft make it trivial to produce low-homology sequences that fold into active, potentially hazardous architectures. However, sequence homology-based biosafety screening tools cannot detect proteins that pose functional risk through structurally novel mechanisms with no sequence precedent. We present a tiered computational pipeline that addresses this gap by combining MMseqs2 sequence alignment with structure-based comparison via FoldSeek and DALI against curated toxin databases totaling ~34,000 entries. AlphaFold2-predicted structures are screened for both global fold similarity (FoldSeek) and local active/allosteric site geometry (DALI), capturing convergent functional hazards that sequence screening misses. The pipeline was validated against a panel of toxins, benign proteins, structural mimics, and de novo-designed Munc13 binders, as well as modified ricin variants with residue substitutions. We additionally tested robustness to partial-synthesis evasion, where a bad actor submits multiple shorter coding sequences intended for downstream reassembly into a full toxin-coding gene. We found that while sequence-based screening did not identify any de novo ricin analogues with high certainty, the combined pipeline with FoldSeek and DALI identified all 24 tested de novo ricins as toxic.

Read More

OliGraph: graph-based screening of large oligopools

Existing synthesis screening tools cannot evaluate short oligonucleotide pools, whose overlapping fragments can be reassembled into regulated sequences via polymerase cycling assembly (PCA) yet fall below gene-length detection thresholds. We present OliGraph, an open-source tool that constructs a bi-directed overlap graph from an oligonucleotide pool and extracts contigs for downstream gene-length screening. An optional PCA mode retains only cross-strand overlaps consistent with PCA chemistry. We validated OliGraph in a blinded study across ten simulated pools (70–9,184 oligonucleotides, 30–300 bp) spanning four risk categories. BLAST screening of individual oligonucleotides failed to identify sequences of concern in most pools: three returned zero hits, and vector noise obscured true positives in the remainder. After OliGraph assembly, contig-level BLAST matched the longest assembled sequences (up to 1,905 bp) to sequences of concern at 97–100% identity. In one pool, assembly collapsed 1,634 individual BLAST results into 10 hits from a single contig, all assigned to the same source organism. PCA mode correctly distinguished assemblable from non-assemblable fragments within the same pool. Two pools with no assemblable structure yielded no contigs. OliGraph processed all pools in under 0.2 seconds, fast enough for real-time order screening and consistent with proposals to bring oligonucleotide orders within the scope of synthesis screening regulation.

Read More

BioRT-Bench: A Multi-Attack Red-Teaming Benchmark for Bio-Misuse Safeguards in Frontier LLMs

Frontier AI laboratories are expected to maintain safeguards against biological misuse, but whether deployed models actually refuse bio-misuse queries under adversarial pressure is largely unmeasured in the public literature. We introduce BioRT-Bench, a benchmark that runs four attack methods (direct request, PAIR, Crescendo, and base64 encoding) against four frontier models (Claude Sonnet 4.6, GPT-5.4, DeepSeek V4-flash, Kimi K2.5) across 40 prompts spanning five biosecurity-relevant categories. Responses are scored by a calibrated judge extending StrongREJECT with two bio-specific dimensions: specificity and actionability. We measure Attack Success Rate (ASR), where 0 means the model fully refused and 1 means it provided specific, actionable bio-misuse content. Our results reveal a sharp robustness divide: Chinese frontier models (DeepSeek, Kimi) have under 5% refusal rates even under direct request (ASR 0.88 and 0.79), while Western models (Claude, GPT) maintain substantially stronger safeguards (ASR 0.15 and 0.16). Crescendo is the most effective attack across all models, both in bypassing refusal and in eliciting actionable content. Claude Sonnet 4.6 is the most robust model tested, achieving 100% refusal against base64-encoded prompts.

Read More

This work was done during one weekend by research workshop participants and does not represent the work of Apart Research.
This work was done during one weekend by research workshop participants and does not represent the work of Apart Research.