Secretary-General Ismail Ould Cheikh Ahmed assumes leadership of the Organisation of Islamic Cooperation at a moment of acute technological emergency. The fifty-seven member states of the OIC are not merely confronting an economic development gap or a governance deficit. They are operating under a structural condition in which the digital systems governing their communications, their critical infrastructure, and increasingly their physical security are owned, operated, and increasingly their physical security are owned, operated, and, when politically convenient, disabled by foreign powers. This paper is addressed to the incoming Secretary-General and to the OIC’s technical and policy leadership because the window for meaningful structural action is narrow, and the cost of continued inaction is now measurable in civilian lives.
The Operational Reality of Algorithmic Warfare
The conflict that has reshaped global security calculations since February 2026 was not decided by troop concentrations or naval deployments. It was decided by data architecture. When the United States and Israel launched Operation Epic Fury against Iran on 28 February 2026, the targeting system that identified over 2,000 Iranian sites in under four days was Palantir’s AI-powered targeting platform, “Maven”, operating under a $1.3 billion Pentagon contract. The system fused satellite imagery, drone feeds, radar data, and signals intelligence into automated strike packages. Within the first 24 hours, it generated approximately 1,000 prioritised targets; by mid-April, that figure had exceeded 11,000. This is the documented operational record, confirmed by CENTCOM Commander Admiral Brad Cooper and reported across multiple major international outlets.
The implications for every OIC member state are immediate and structural. Any government whose critical communications, administrative functions, or defence networks rely on foreign cloud infrastructure is, in a military or political crisis, dependent on the continued goodwill of the powers deploying these same systems offensively. That goodwill is conditional, politically variable, and revocable without notice.
Decision Compression and the Erosion of Legal Accountability
The defining technical characteristic of contemporary AI-assisted targeting is what military analysts term decision compression: the radical contraction of the interval between target detection, algorithmic classification, and kinetic strike. In these systems, a large language model operates as the analytical layer, ranking targets by assessed strategic value and generating automated legal justifications for each strike recommendation. Human operators nominally review these outputs, but at volumes and speeds that render meaningful independent scrutiny structurally impractical. The consequence, documented across the academic literature on human-machine decision-making, is automation bias: operators defer to machine-generated outputs not because they have verified them, but because the system generates information faster than human cognition can evaluate it.
The civilian cost of this compression has been documented by multiple international human rights bodies. The AI targeting system’s detection accuracy in desert terrain fell below 30 per cent during the Iran operation, as rapidly shifting environmental conditions caused it to misidentify civilian objects and decoys as valid military targets, including an Iranian girls school, resulting in the deaths of 170 school children. The principle of distinction under international humanitarian law, which prohibits the direct targeting of civilians, was not only violated by an individual operational decision. It was violated algorithmically, at scale, and at a pace that rendered post-hoc accountability structurally difficult.
The Infrastructure Dependency Problem
The military dimensions of this crisis are inseparable from a structural technological one. The global digital order is not neutral shared infrastructure. It is divided between two competing hegemonic architectures: the US-led commercial platform model and the Chinese state-driven surveillance model. Most OIC member states occupy a subordinate position within both. They are, in practical terms, infrastructure renters, relying on hardware, cloud hosting, and enterprise software designed, owned, and regulated by Washington or Beijing, with no meaningful control over the underlying systems or the conditions under which access to those systems may be revoked.
The practical consequences of this dependency were demonstrated in May 2025, when US sanctions imposed on ICC Chief Prosecutor Karim Khan rendered his institutional Microsoft account inaccessible. Whether access was terminated by Microsoft’s compliance procedures or by the ICC’s own administrators responding to legal pressure remains formally disputed. The institutional response, however, was unambiguous: on 31 October 2025, the ICC announced a full pre-emptive migration from Microsoft to the open-source OpenDesk suite, explicitly to eliminate the structural vulnerability the incident had exposed. The episode illustrates a dynamic that is more consequential than a simple kill switch: dependency on foreign cloud infrastructure subjects an institution to the coercive potential of foreign sanctions law, regardless of whether that potential is ever formally exercised.
The dependency is further compounded by the extraterritorial reach of the US Bureau of Industry and Security Affiliates Rule, under which any foreign entity that is 50 per cent or more owned by a restricted Chinese firm is automatically subject to US sanctions. For governments attempting to diversify technology procurement across American and Chinese suppliers, this creates a compliance tripwire of considerable operational risk. The presence of Huawei Ascend processors anywhere within a national network architecture can trigger the immediate revocation of US software licences, security update pathways, and database access. The structural result is that the attempt to reduce dependency on one superpower simultaneously increases vulnerability to the other.
The Technical Requirements of Digital Sovereignty
The appropriate institutional response to this condition is not declaratory. It is architectural. Digital sovereignty is not a legal designation. It is a technical capacity determined by the design of the systems a state actually controls. Where any external control plane is required for a national system to function, the dependency is operationally real regardless of the contractual terms governing the relationship.
Genuine sovereignty requires control over four distinct infrastructure layers. The identity and communications layer must transition away from foreign proprietary platforms towards self-hosted, federated systems built on open protocols. Inter-agency communications, cabinet-level deliberations, and administrative workflows must operate on locally administered servers, protected by end-to-end encryption, and immune to remote suspension by foreign corporate or governmental actors. The network management layer requires locally hosted Domain Name System root server instances and Border Gateway Protocol Anycast routing, ensuring that regional internet traffic can be resolved internally even under conditions of severed global fibre connectivity or external distributed denial-of-service attack. The data and compute layer requires sovereign-backed, in-region hyperscale data infrastructure. Dubai’s Moro Hub and Saudi Arabia’s $1.2 billion HUMAIN data centre investment represent the beginning of the required capacity, not its fulfilment; model training data, inference execution environments, and the resulting algorithmic weights must remain within the sovereign perimeter, governed exclusively by national law. Finally, the physical network layer requires routing diversification to bypass chokepoints under foreign administrative control, of which Pakistan’s integration of the PEACE submarine cable and Algeria’s partnership with Italy’s Sparkle and Medusa Submarine Cable Systems are the operational template.
The OIC as a Coordination Platform: Independence First
The OIC (Organisation for Islamic Cooperation) is an institutional platform through which these requirements can be aggregated, standardised, and collectively financed without inheriting the technical assumptions or regulatory frameworks of either superpower. The OIC’s value in this context is its unmatched geographic and demographic footprint. Fifty-seven member states spanning three continents, a combined population exceeding 2 billion, and a collective GDP that dwarfs any comparable bloc in the Global South create the conditions for a compute and infrastructure grid of genuine strategic scale, if the political will to pool resources can be mobilised around a concrete technical agenda rather than a declaratory one
The critical strategic precondition is sequencing. There is a legitimate debate in technology policy literature about whether developing regions should align with external regulatory frameworks before or after building domestic operational capacity. Those who favour early alignment argue that frameworks such as the EU AI Act provide a tested architecture and facilitate market access without the cost of building from scratch. That argument has merit in contexts where the primary objective is trade integration. It has considerably less merit where the primary objective is strategic autonomy. Adopting regulatory frameworks designed by and for other actors, before the region has the technical capacity to evaluate their embedded assumptions or contest their terms, means accepting legal liabilities, compliance architectures, and definitional choices that reflect the interests of their authors rather than those of their adopters. The strategic mandate is therefore independence first: not as a permanent posture of isolation, but as a sequencing discipline that ensures external alignment, when it comes, occurs from a position of informed capacity rather than structural dependency
The OIC’s Standing Committee on Scientific and Technological Cooperation (COMSTECH) is the appropriate institutional vehicle for operationalising this agenda. A regional scholarship pipeline, scaling existing programmes such as the COMSTECH-University of Lahore initiatives, must be funded to produce graduates in artificial intelligence, applied cryptography, and network security engineering at volumes commensurate with regional requirements. Early career return grants, modelled on the CRP-ICGEB mechanism, must create the financial and institutional conditions necessary for diaspora scientists and engineers to establish independent research laboratories within the region. A unified OIC regional AI forum must concentrate R&D investment on domain-specific, energy-efficient inference models designed for AgriTech, HealthTech, and GovTech applications, systems that require a fraction of the computational and energy resources demanded by Western-scale generative architectures, and that can be built, owned, and maintained by regional institutions.
Policy Recommendations
- Mandate Software Bills of Materials for critical national infrastructure: OIC member state governments should enact legislation requiring comprehensive, auditable records of all software and hardware components deployed within critical national systems. This is the foundational step towards identifying concealed technical dependencies, unauthorised telemetry pathways, and potential remote disablement mechanisms before operational conditions demand their identification.
- Establish a Pan-OIC Compute and Cloud Grid: Member states should pool sovereign capital to co-develop shared high-performance computing infrastructure, distributing the energy and capital requirements of gigawatt-scale data facilities across multiple national jurisdictions rather than concentrating them within a single state or delegating them to foreign commercial operators.
- Develop standardised regional data exchange environments: Sovereign data holdings must be maintained in model-agnostic, open-source formats that enable public-sector entities to migrate workloads across providers without operational disruption or punitive contractual penalties. Portability is a precondition of sovereignty; vendor lock-in is its negation.
- Institutionalise geopolitical technology risk assessment: Ministries of Defence and Information Technology must establish dedicated analytical functions to model the operational and security consequences of sudden loss of access to specific hardware or software stacks, and to maintain tested, deployable analogue and open-source contingency protocols in advance of any crisis that might necessitate their use.
The OIC has, across its fifty-seven-year institutional history, demonstrated a consistent capacity to align member states around shared political and diplomatic positions. What the present technological emergency requires is a more demanding form of alignment: the coordination of engineering capacity, capital allocation, and technical standards around a shared infrastructure that no foreign power can unilaterally disable. The precedents established by Operation Epic Fury and the ICC cloud termination demonstrate that this is not a theoretical risk. The window within which that infrastructure can be built, before the next crisis makes the dependency catastrophic, remains open. It will not do so indefinitely.
Muhammad Amen Ehsan is an emerging researcher specializing in Digital Governance, Cybersecurity, and the strategic deployment of Artificial Intelligence. He is currently pursuing an MSci in Computer Science at King’s College London, where he was recently elected as President of the King’s College London AI Society for the 2026–2027 term.




