Most talk of AI power counts assets: chips, clusters, parameters, capital. On that count India and Russia will trail Washington and Beijing for years. But counting assets mistakes the nature of the contest. In every technological order, the decisive moment comes not when capacity peaks, but when the rules become expensive to change. Railway gauges, container dimensions and payment messaging standards were not the product of the strongest economies. They were the product of whoever had a working artifact in place when everyone else still had a position paper.

AI governance is in that phase now. Incident-reporting protocols, evaluation thresholds, model-provenance conventions and the definition of a “dangerous capability” are being drafted, mostly by a few labs and the two states that host them. Each convention adopted becomes a default, and each default becomes a constraint on later entrants. The window is closing much faster than any industrial programme can be built. A fab takes a decade. A norm can set in eighteen months. Power is a position in time.

This reframes the strategic question. India and Russia cannot win the race for capacity. They can contest the race for standing, and standing has a shorter clock.

Three currencies

Power in this domain is paid in three currencies.

Capacity is the ability to build and run frontier systems. The two leaders are rich in it, and it cannot be bought quickly.

Continuity is the ability to keep functioning when a supplier, a licence or a cloud region is withdrawn. Sovereignty is properly measured here. A state that can degrade gracefully cannot be coerced cheaply, whatever its rank in capacity.

Credibility is the ability to be believed as an evaluator, host or mediator by parties who trust neither giant. It is the scarcest currency, and the only one that can be minted in under three years.

The two leading powers are overdrawn on credibility. They distrust each other, and much of the rest of the world distrusts both. Their hotline is a deterrence device between rivals. It is not an institution that a third country could rely on, join or appeal to. That vacancy is the opening.

The duopoly’s hidden need

Any durable US-China arrangement will eventually require a verifier neither side has captured: someone to test a claimed capability, attest that a model was not stolen, or examine a disputed incident. Neither government will accept an evaluator aligned with the other. Neutral expertise is, therefore, a functional requirement of stability, not a courtesy to the sidelined.

An honest analysis must say what this implies for the India-Russia axis, because it cuts against the easy version of the story. Russia cannot be the neutral witness. Regarded as a “belligerent” and/or “aggressor” in a major war by most Western governments, though not by some of its closest partners, and the target of the most extensive sanctions regime in modern history, it is a party, not a referee. Any assurance body visibly anchored in Moscow would be discounted at birth, and worse, would taint its Indian host. India can be the witness, because it is non-aligned, populous, technically deep and trusted across the Global South, the Gulf and Southeast Asia. Russia’s role must be that of a contributor under firewall: formal methods, verification mathematics, safety-critical engineering, and adversarial testing talent, delivered through open, auditable work whose provenance is public.

Conviction is not the same as indulgence. If the partnership is to carry weight abroad, Russia must accept terms that constrain it: no hardware channels, no sanctions-evasion functions, published results, and independent audit of everything that touches the shared institution. A partnership that cannot survive that scrutiny is not worth the exposure. One that can is a rare thing: a Russia-linked project the world can inspect.

Working artifacts, not declarations

The repeating failure of middle-power AI diplomacy is the communiqué. Centres of excellence are announced and staffed with a dozen people, and years later there is a brochure. The remedy is to reverse the order: produce the artifact first and let the institution form around it.

Within eighteen months, India and its partners should publish three things, complete and free to adopt:

  • An open evaluation suite for frontier and open-weight models, covering robustness, cyber-misuse, multilingual failure and critical-infrastructure behaviour, with methods documented well enough that any regulator can reproduce results.
  • A reference incident-reporting protocol, a third-country counterpart to the bilateral hotline that any state or lab can plug into.
  • A provenance and attestation standard for training data, weights and inference, allowing verifiable claims about where a model came from.

The aim is adoption, not authorship: twenty governments running the suite, several labs submitting to it, and, most usefully, at least one dispute in which the two giants find it convenient to cite it. Standards won this way are hard to displace because they are already installed.

Turning the market into a lever

The second leverage is India’s own scale, and it has been consistently underused. Frontier systems are enormously expensive, and their returns depend on deployment among billions of people, in languages and contexts where they perform poorly. India is the largest such proving ground outside China’s walls. A state that is the indispensable market for a technology can set terms for entering it.

Government procurement should be treated as strategy, not administration. Sovereign deployment terms would apply to any model used in public systems: local inference, weight escrow for critical uses, independent evaluation access, and portability guarantees. A market that speaks with one voice can turn “access to India” into a bargaining chip, exactly as the leading powers use chips and minerals. Russia’s version of this is narrower, but it holds a similar position in its own sphere. The point is that leverage need not be a chokepoint in hardware. It can be a chokepoint in legitimacy and demand.

What conviction costs

Seriousness is measured by what one is willing to forgo. Three commitments distinguish a strategy from an aspiration.

Pay for continuity: Substitutable compute, domestic redundancy and open-weight fallbacks for critical systems will cost more than buying whatever is best. That is the premium on autonomy, and it should be budgeted openly, not hidden in press releases.

Retain the people: The binding constraint is talent, not money. A public research cadre with real compute, competitive pay and freedom to publish will matter more than any facility. The countries that lose their best evaluators and mathematicians to a handful of foreign labs are not sovereign, whatever their statutes say.

Accept friction with Washington: A meaningful programme with Russia will draw sanctions attention. India should not pretend otherwise, nor abandon the effort. It should structure the work so that it is legally defensible, transparent and unambiguously non-military in its Russian components, and make clear that the institution is open to any state willing to meet its standards, including America’s allies. An institution that excludes no one who accepts its rules is far harder to sanction than a bloc.

The failure modes

There are three ways this fails. It becomes another symbolic forum, endlessly launched and never used. It becomes a channel for the sanctions evasion its critics predict, destroying its credibility in a single scandal. Or it is captured by one partner’s agenda and loses the neutrality that is its only real asset. Each is preventable by design, and each will happen by default.

The window and the witness

The measure of success is not a ranking of compute, a declaration of partnership or a place at someone else’s table. It is a single question, answerable in 2028: when a serious AI incident occurs and the two great powers disagree about what happened, does anyone turn to an institution in Delhi to find out?

If yes, India and its partners are counted, not because they held the largest stack, but because they held the one thing the largest stacks could not supply: a witness the world believes. If no, the norms will have hardened without them, and everything built afterwards will be built to someone else’s specification.

The window is open. It will not stay so.