TCS, Infosys and Wipro bought 300k US agent seats; India's lock-in sits above the model

2026-09-03

Kapur and Narayanan argue India's AI-sovereignty risk has moved to agents: TCS, Infosys and Wipro bought over 300,000 US office-agent licenses in under six months.

What problem this solves

Most national AI-sovereignty programs still treat chips, data centers, and home-grown large language models as the prize. India has put sovereignty at the center of its strategy and has opened public supercomputers for research. In a one-page Science editorial, Princeton visiting fellow Akash Kapur and computer-science professor Arvind Narayanan argue that this map is already out of date.

Open-source models are spreading. Training a single frontier model now approaches $1 billion, but owning that run no longer decides who controls AI. The lock is forming one layer up, in AI agents: software that does real office work, writes code, and handles administration, and that is writing Indian institutions' workflows and tacit knowledge into foreign systems those institutions neither own nor control.

Method

There is no experiment. The argument has three moves.

Sovereignty is defined as the ability to build, run, and govern a country's own AI systems. The public debate has stayed on infrastructure. India has made progress there, treating supercomputers as a shared public asset. Staying at the frontier still costs real money.

That layer may matter less than it looks. Indian firms already fine-tune and use open-source models. Compute and models are likely to keep getting cheaper and more widely available. Dependence on foreign software, hardware, and expertise is not solved. It has moved.

The new layer is applications. Many of the agents now sitting in Indian banks, universities, and government offices are imported or proprietary. They keep ingesting organizational data. Encoding core operations into systems you do not own is, in this telling, a heavier form of dependence than sitting on someone else's chips. The proposed fix is not another sovereign foundation model. It is to reuse India Stack: more than a decade of open digital rails for payments, biometric identity, data exchange, and commerce, serving over a billion users and designed against lock-in. The AI version would be universal rules so that agents can talk to each other and move information across institutions without being trapped in one vendor.

Results

The editorial offers few numbers, and they all point the same way.

FactFigureRole in the argument
Cost of one frontier training runapproaches $1 billionwhy infrastructure sovereignty is hard
AI-agent licenses bought by India's three largest IT firmsmore than 300,000 in under 6 monthsTCS, Infosys, Wipro, for office tasks, from US vendors
India Stack usersmore than 1 billionpayments, identity, data exchange, commerce

The 300,000 seats are the sharpest evidence. These tools do not merely store documents; they absorb workflows and institutional knowledge. Agents are already doing administration and writing code. The editorial does not name the products behind the licenses, does not report usage, and does not compare against organizations that built agents in-house.

India Stack is offered as an exportable template, already studied across the Global South. Repeating that trick for AI is possible only if the country first treats dependence above the infrastructure layer as the live risk.

Why it matters

For people who train models, the contest is shifting from who can afford a billion-dollar run to whose agents eat the customer's process. Open weights are catching up. Lock-in now lives in workflows, data, and institutional memory.

For countries that will not win the training race, public supercomputers and a sovereign LLM are not enough. TCS, Infosys, and Wipro buying 300,000 US office-agent seats in half a year means the world's largest IT-services exporters handed over their own office layer first. If their clients copy that procurement, the lock spreads from those firms into the enterprises they serve.

The actionable piece is interoperability rules. Open payments rails worked because interchange was mandatory. Agents have no equivalent yet. Whoever writes enforceable rules for how agents communicate and how they move data between institutions occupies the application-layer position that open payment rails occupy in finance.

This is a policy claim, not an algorithmic result. Connecting digital public infrastructure to agents is incremental. Naming the three IT majors as accelerators of lock-in is the cold water.

Limitations

This is a one-page editorial, not an empirical study. Office-task licenses are counted as AI agents. A copilot that drafts email is not the same object as a production agent that rewrites a core system, and the text does not separate them.

"Encoding core operations" is a mechanism, not a measured case. There is no bank, university, or ministry whose un-migratable workflow is documented, and no switching-cost estimate.

The claim that proliferating open-source models makes infrastructural sovereignty less important is optimistic. Downloadable weights do not cancel chip export controls, cloud jurisdiction, or the cost of local inference. The editorial itself notes that the drive to cut dependence on foreign software, hardware, and expertise is not resolved.

The India Stack analogy is only half transferred. Payment rails move transaction instructions. Agents write lasting institutional memory. Interoperability can lower switching costs; it cannot retrieve workflows already absorbed by a foreign system. Who sets the universal rules, and how procurement is forced to obey them, is unspecified.

The publisher's PDF is paywalled. This reading uses the abstract plus the article body indexed from the Science page. There are no figures.

Terms

Source

All paper explainers