Washington’s new cybersecurity assistance for Central Asia is modest in financial terms. Its strategic significance is larger. As the United States, China and Russia compete over infrastructure, artificial intelligence, security relationships and digital governance, cyber capacity building is becoming an instrument of foreign policy.
By Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)
Five million dollars is not a large amount of money in international geopolitics.
It is smaller than the cost of many individual infrastructure projects.
It will not transform Central Asia’s digital economy.
It will not determine whether Kazakhstan, Uzbekistan, Kyrgyzstan, Tajikistan or Turkmenistan ultimately align technologically with Washington, Beijing or Moscow.
But sometimes the significance of foreign assistance lies less in the amount than in the relationship it creates.
The United States has committed $5 million in assistance for cybersecurity and digital-sector development across the five Central Asian states.
The funding, announced during the C5+1 Super Intelligence conference in Astana and administered through CRDF Global, is intended to support areas including cyber hygiene, incident response, protection of critical infrastructure and financial systems, as well as elements of digital and artificial-intelligence development.
Taken alone, this is a relatively small capacity-building program.
Placed inside the political geography of Central Asia, it looks different.
The region lies between Russia and China.
It contains strategically important energy resources, transport corridors and critical minerals.
It connects Europe and Asia.
Its governments maintain relationships with Moscow, Beijing, Washington, Ankara, Brussels and other centers of power while generally attempting to avoid exclusive dependence on any one of them.
Now another layer is being added to that geopolitical balancing act.
Digital infrastructure.
Cybersecurity.
Cloud systems.
Artificial intelligence.
Data governance.
And the technological standards through which the next generation of Central Asian economies will operate.
The twenty-first-century competition for Central Asia will not be fought only over pipelines, railways, military bases and minerals.
Increasingly, it will also concern networks.
From the Great Game to the Digital Great Game
Central Asia has repeatedly occupied an unusual position in the international system.
During the nineteenth century, the region became associated with the “Great Game” between the Russian and British empires.
The phrase simplified a much more complicated regional history, but it captured an enduring geopolitical reality.
Central Asia sits at the intersection of major powers.
After the collapse of the Soviet Union in 1991, Kazakhstan, Kyrgyzstan, Tajikistan, Turkmenistan and Uzbekistan became independent states while retaining deep economic, linguistic, institutional and security connections with Russia.
Moscow remained a major political and security actor.
Russian infrastructure, labor markets and institutions continued to matter enormously.
China’s rise gradually changed the regional balance.
Energy relationships expanded.
Trade increased.
Infrastructure investment grew.
The Belt and Road Initiative gave Central Asia renewed importance as a continental corridor connecting China with markets to its west.
The United States occupied a different position.
Washington never possessed the geographical proximity of Russia or the economic scale of China.
Its regional engagement instead combined diplomacy, security assistance, economic development, sovereignty support and, during the Afghanistan war, logistical and counterterrorism considerations.
For much of the post-Soviet period, these relationships could be understood primarily through traditional geopolitics.
That is becoming insufficient.
The infrastructure determining political influence is increasingly digital.
C5+1 Was Not Originally a Digital Alliance
The history of C5+1 illustrates the transformation.
The United States and the five Central Asian governments established the format in 2015.
Its original agenda focused on three broad areas:
security;
economic connectivity;
and environmental challenges.
At the first ministerial meeting in Samarkand, terrorism and foreign terrorist fighters were prominent security concerns.
Subsequent C5+1 projects addressed counterterrorism, transportation, trade competitiveness, energy and environmental resilience.
This reflected the strategic environment of the time.
Artificial intelligence was not yet a central geopolitical issue.
Cloud infrastructure was not generally discussed as an instrument of international alignment.
Cybersecurity had strategic importance, but it had not yet become as deeply connected to economic and foreign policy as it is today.
A decade later, the C5+1 conversation looks different.
Cybersecurity, AI, data centers and digital infrastructure are moving closer to the center.
That change reflects something larger than technological modernization.
It reflects the changing definition of strategic influence.
Cyber Assistance Creates Relationships
Cybersecurity capacity building is often presented as technical assistance.
That description is correct but incomplete.
Consider what effective cyber assistance actually requires.
Experts train government officials.
Security teams establish professional relationships.
Incident-response organizations exchange contacts.
Technical standards are introduced.
Government agencies learn particular methods for assessing risk.
Critical-infrastructure operators adopt security tools.
Threat intelligence begins moving through institutional channels.
Officials participate in exercises.
Universities and private companies become involved.
Over time, these relationships can become durable.
A country receiving cybersecurity assistance is not simply receiving software.
It is learning how another country’s security institutions understand cyberspace.
That is why cyber capacity building should increasingly be understood as a form of diplomacy.
It builds networks of trust.
And in cybersecurity, trust itself is infrastructure.
The Trusted Technology Question
The United States is increasingly connecting cybersecurity with the idea of trusted digital infrastructure.
That concept has substantial geopolitical implications.
A government choosing a telecommunications provider is not simply purchasing equipment.
It may be determining who maintains critical components of national communications.
A country choosing cloud infrastructure may determine where sensitive data is processed and which legal jurisdictions can potentially affect access.
A government adopting AI infrastructure may become dependent on foreign chips, cloud providers, models and software ecosystems.
Cybersecurity products themselves can require extraordinary levels of trust because they operate deep inside sensitive networks.
Technology procurement therefore increasingly resembles foreign policy.
Central Asian governments understand this.
They are not choosing merely between American and Chinese products.
They are managing relationships between competing technological ecosystems.
China Arrived With Infrastructure
China possesses major advantages in this competition.
Its economic relationship with Central Asia is substantial and long-standing.
Chinese companies have participated in telecommunications, transportation, energy and digital infrastructure across the region.
The Belt and Road Initiative reinforced these connections.
The Digital Silk Road extended the logic into telecommunications, digital services and technology.
More recently, Beijing has increasingly promoted its own ideas about data security, artificial intelligence and the governance of cyberspace.
This matters because infrastructure carries norms.
A digital system is never entirely politically neutral.
Technical architecture determines what can be monitored.
Data rules determine where information can travel.
Cybersecurity laws define government authority.
Identity systems determine access.
Cloud architecture creates dependencies.
AI governance determines which models can be deployed and under what conditions.
When a country adopts technology, it often adopts portions of the institutional logic surrounding that technology.
Infrastructure can therefore become a mechanism for norm diffusion.
The Shanghai Cooperation Organisation Matters
China’s regional influence also operates through institutions.
The Shanghai Cooperation Organisation has gradually expanded its agenda beyond traditional security issues.
Information security and cyber governance became significant areas of cooperation.
The organization historically promoted concepts of information security emphasizing state sovereignty, political stability and government authority over information environments.
Those ideas do not always align with the more open, multi-stakeholder model historically favored by the United States and many Western governments.
This distinction is important.
The geopolitical competition over cyberspace is not only about who sells routers.
It is also about how cyberspace should be governed.
Should governments possess extensive authority over national information environments?
How should data move across borders?
What responsibilities should technology companies have?
How should online information be regulated?
What constitutes interference in another state’s information space?
Who should establish international cyber norms?
Central Asian states participate in these debates while maintaining close relationships with China and Russia.
American cyber engagement therefore enters a region where alternative governance models already possess institutional foundations.
Russia Still Matters
Any analysis portraying Central Asia simply as a U.S.–China competition would be incomplete.
Russia remains deeply embedded in the region.
Historical ties are extensive.
Russian remains widely used.
Millions of Central Asians have economic and family connections to Russia.
Moscow maintains security relationships through bilateral arrangements and institutions including the Collective Security Treaty Organization.
Russia also promotes its own approach to international information security.
That approach traditionally places considerable emphasis on state sovereignty over information space and on a broader definition of information security than the narrower Western focus on network and system security.
Central Asian governments therefore operate inside overlapping institutional environments.
C5+1.
The SCO.
The CSTO for several states.
China-Central Asia mechanisms.
Bilateral relationships with Russia.
Growing relationships with Europe, Türkiye and other actors.
The result is not a simple geopolitical chessboard.
It is a network of overlapping relationships.
Central Asia Is Not Merely a Prize
This is where the traditional “Great Game” metaphor becomes dangerous if taken too literally.
Central Asian states are not passive territories waiting to be divided among outside powers.
They have agency.
Kazakhstan, Uzbekistan and their neighbors have increasingly pursued multi-vector foreign policies designed to maintain relationships with several powers simultaneously.
That strategy has rational foundations.
Exclusive alignment creates dependency.
Multiple partnerships create options.
A government may purchase Chinese technology, participate in Russian security structures, seek American investment, cooperate with the European Union and develop relationships with Türkiye simultaneously.
Digital policy increasingly follows the same logic.
Central Asian governments may not want to choose one technological bloc.
They may prefer interoperability.
American cloud infrastructure.
Chinese hardware.
Domestic data centers.
Russian-linked systems.
European standards.
Locally developed AI.
The geopolitical question is whether growing technological rivalry will continue allowing that flexibility.
Kazakhstan Shows the Problem Clearly
Kazakhstan provides perhaps the most revealing example.
Its geography alone encourages strategic balancing.
It shares a long border with Russia.
China is a major economic partner.
The country maintains significant relationships with the United States and Europe.
Kazakhstan has also become increasingly relevant to emerging AI diplomacy.
In 2026, it found itself participating in initiatives associated with both American and Chinese visions of international AI cooperation.
That position illustrates Central Asia’s broader preference:
engagement without exclusive alignment.
But Washington’s technology strategy is increasingly built around the concept of trusted ecosystems.
That creates pressure.
If advanced technologies become divided into competing blocs, maintaining simultaneous participation becomes harder.
The choice may eventually concern more than diplomacy.
Access to AI infrastructure, advanced chips, cloud platforms, investment or technical cooperation could depend on alignment with particular security standards.
That is where digital geopolitics becomes tangible.
The $5 Million Is About Presence
Against this background, Washington’s new cybersecurity assistance looks less trivial.
The money itself will not counterbalance China’s regional economic weight.
Nor will it replace Russia’s historical security relationships.
Its strategic value lies elsewhere.
Presence.
Cybersecurity assistance gives American institutions a reason to maintain sustained technical relationships.
Training creates networks.
Incident-response cooperation creates trusted contacts.
Critical-infrastructure programs create institutional access.
Startup grants create commercial relationships.
AI programs connect emerging technology communities.
CRDF Global already operates a Central Asia regional hub in Almaty, giving the program an institutional base rather than requiring every initiative to be managed remotely from Washington.
The objective need not be geopolitical exclusivity to produce strategic value.
Being present inside the development of a country’s digital institutions matters.
Cyber Diplomacy Is Moving From Norms to Infrastructure
This reflects an important evolution in cyber diplomacy.
The first generation of cyber diplomacy concentrated heavily on international norms.
Diplomats debated responsible state behavior.
Governments negotiated confidence-building measures.
The United Nations developed frameworks concerning state conduct in cyberspace.
Those efforts remain important.
But a second dimension has become increasingly visible.
Infrastructure diplomacy.
Countries are competing over who builds networks.
Who provides cloud services.
Who supplies cybersecurity technology.
Who trains government officials.
Who develops AI systems.
Who finances data centers.
Who controls semiconductor supply chains.
And whose technical standards become embedded inside national institutions.
Cyber diplomacy therefore increasingly concerns material capability as well as diplomatic norms.
A country may endorse a particular international cyber principle.
But its practical digital sovereignty can still depend on foreign infrastructure.
AI Makes the Competition More Consequential
Artificial intelligence intensifies this dynamic.
AI requires infrastructure.
Compute.
Energy.
Data centers.
Semiconductors.
Cloud platforms.
Networks.
Models.
Talent.
Cybersecurity.
Countries unable to build the entire stack domestically must choose international partners.
That creates dependency.
The question of who helps Central Asian states build AI capacity is therefore not merely about technological development.
It concerns future strategic relationships.
An American AI ecosystem may create dependencies on U.S. cloud providers, chips, security standards and commercial platforms.
A Chinese ecosystem may rely more heavily on Chinese infrastructure, open-weight models, hardware and governance frameworks.
Domestic approaches may reduce some dependencies while creating others.
The technology stack becomes a geopolitical stack.
China’s AI Diplomacy Raises the Stakes
China has increasingly presented itself as a provider of AI capabilities to developing countries.
Beijing emphasizes access, open-source technology and opposition to what it portrays as attempts by technologically advanced states to monopolize AI.
President Xi Jinping has explicitly promoted Chinese AI cooperation with the Global South and international institutions.
This strategy has obvious appeal.
Many countries do not want the future of artificial intelligence determined exclusively by a small number of American companies.
Affordable Chinese models and infrastructure can provide alternatives.
The United States therefore cannot compete solely by restricting Chinese technology.
It must offer something.
Cybersecurity assistance is part of that answer.
So are investment, infrastructure, training and access to American technology ecosystems.
The competition increasingly concerns which system appears more useful, reliable and politically acceptable to partner states.
Russia Faces a Different Challenge
Russia’s position is structurally different.
Moscow retains major political, security and cultural influence in Central Asia.
But the digital competition increasingly rewards economic scale, advanced technology companies, cloud infrastructure and AI capability.
Those are areas where the United States and China possess advantages.
Russia can remain a significant security actor while losing relative influence over the technological architecture of the region.
That distinction matters.
Traditional security influence does not automatically translate into digital influence.
A country may cooperate militarily with Moscow while building telecommunications infrastructure with China and cloud or AI relationships with the United States.
The future geopolitical map of Central Asia may therefore contain several overlapping spheres rather than one dominant alignment.
Cyber Capacity Building Is Soft Power With Technical Consequences
Traditional soft power operates through culture, education, diplomacy and political attraction.
Cyber capacity building adds another mechanism.
Technical competence.
If a government helps another country establish an incident-response capability, it creates practical value.
If it trains cybersecurity professionals, those professionals may maintain relationships for decades.
If it helps protect critical infrastructure during a crisis, trust deepens.
If it provides useful threat intelligence, cooperation becomes operational rather than ceremonial.
This form of influence is subtle.
It does not produce dramatic photographs of military deployments.
But it can shape institutions.
That is why cyber capacity building deserves greater attention in foreign-policy analysis.
It creates influence through capability.
The Security Assistance Model Is Changing
There is a historical parallel.
During the Cold War and the decades that followed, security assistance frequently meant military training, equipment, intelligence cooperation and defense institution building.
Those instruments remain important.
But the definition of national security has expanded.
A state unable to protect its banking networks is vulnerable.
A state whose government systems can be disrupted remotely is vulnerable.
A state dependent on foreign digital infrastructure without understanding its risks is vulnerable.
A state without an effective incident-response capability is vulnerable.
Cybersecurity assistance therefore increasingly performs functions once associated primarily with conventional security assistance.
It strengthens state capacity.
It builds relationships with security institutions.
It creates interoperability.
And it can influence strategic orientation.
But Washington Should Avoid a Forced Choice
There is a danger in turning this competition into an ultimatum.
Central Asian states have strong incentives to maintain diversified foreign relationships.
Forcing governments to choose exclusively between American and Chinese technology ecosystems could produce resistance rather than alignment.
The region’s diplomatic tradition increasingly emphasizes strategic autonomy.
A more durable American strategy would therefore focus on principles rather than loyalty tests.
Security.
Transparency.
Interoperability.
Resilience.
Data protection.
Commercial choice.
Institutional capacity.
The strongest argument for an American technology partnership is not that countries must reject China.
It is that diversified digital systems built on transparent and secure standards provide greater sovereignty.
That argument is particularly relevant in Central Asia.
Digital Sovereignty Has Two Meanings
The concept of digital sovereignty is frequently used by governments around the world.
But it can mean different things.
One interpretation emphasizes state control over information, infrastructure and data.
Another emphasizes reducing dependency on foreign technology providers.
Central Asian governments may pursue both.
This creates an interesting tension.
Chinese and Russian cyber-governance traditions often emphasize state sovereignty and government authority.
Western governments increasingly emphasize trusted infrastructure, resilience and security partnerships.
But dependence on Western cloud or AI providers can itself raise sovereignty concerns.
No external power therefore possesses a monopoly on the language of digital sovereignty.
The political contest will concern which relationships allow Central Asian states to preserve the greatest practical autonomy.
Critical Infrastructure Is Where Theory Becomes Reality
The most consequential portion of the American assistance may therefore be critical-infrastructure cybersecurity.
Critical infrastructure creates long-term technological relationships.
Energy systems.
Financial networks.
Telecommunications.
Government platforms.
Transportation.
Water.
Digital identity.
Once technologies and security practices become embedded inside these systems, replacing them can be difficult and expensive.
Decisions made during the early stages of digital transformation can therefore create dependencies lasting decades.
This is why infrastructure standards matter geopolitically.
The competition is not necessarily about controlling infrastructure.
It is about becoming the trusted partner involved in protecting it.
Central Asia Could Become a Laboratory for Multi-Alignment
There is another possibility.
Central Asia may not eventually choose between technological blocs at all.
The region could become a laboratory for multi-alignment.
Governments could deliberately diversify technology providers.
Domestic AI ecosystems could grow.
Regional cybersecurity cooperation could deepen.
Countries could participate in competing international initiatives while resisting exclusive alignment.
If successful, that strategy could provide greater autonomy.
It also creates cybersecurity complexity.
Multiple technology ecosystems mean multiple supply chains.
Different standards.
Different security assumptions.
Different legal jurisdictions.
Different intelligence relationships.
Interoperability itself becomes a security challenge.
Central Asian states may therefore discover that strategic diversification requires stronger domestic cyber capacity.
Paradoxically, that makes foreign cybersecurity assistance more valuable.
The Real Competition Is Over Institutional Memory
Infrastructure can be replaced.
Institutional relationships are harder to replace.
A cybersecurity professional trained through an American program may maintain those professional networks.
An official who regularly participates in Chinese digital-governance forums develops another set of relationships.
A security officer working through Russian institutions develops another.
Over time, these networks influence how governments understand threats.
They affect whom officials call during a crisis.
They shape which standards appear familiar.
They influence procurement decisions.
They create institutional memory.
This is why relatively inexpensive capacity-building programs can have strategic consequences disproportionate to their budgets.
The geopolitical return is measured in relationships, not simply dollars.
Cyber Diplomacy Has Become Development Policy
There is also a broader international lesson.
Cyber diplomacy can no longer be separated cleanly from development.
Countries need digital infrastructure to grow.
They need cybersecurity to protect that infrastructure.
They need skilled professionals to operate it.
They need regulatory frameworks.
They need incident-response capabilities.
They increasingly need AI strategies.
Development assistance and cybersecurity assistance therefore overlap.
The state that helps build digital capacity may gain influence over the standards and institutions surrounding that capacity.
This dynamic will extend far beyond Central Asia.
Africa.
Southeast Asia.
The Western Balkans.
Latin America.
The Middle East.
The geopolitical competition over digital development is becoming global.
Central Asia simply makes the trend unusually visible.
Bottom Line Assessment
The United States’ $5 million cybersecurity commitment to Central Asia is financially modest.
It should not be exaggerated into a geopolitical transformation.
China’s economic position in the region is much larger.
Russia’s historical and security relationships remain substantial.
Central Asian governments themselves retain agency and will continue pursuing their own interests.
But the announcement is significant because it illustrates how the instruments of geopolitical competition are changing.
Cyber hygiene is foreign policy.
Incident response is foreign policy.
Critical-infrastructure security is foreign policy.
AI development is foreign policy.
Cloud infrastructure is foreign policy.
Technical standards are foreign policy.
The competition for influence increasingly occurs through the systems that states depend upon every day.
This is the Digital Great Game.
But unlike the nineteenth-century metaphor, Central Asia is not simply the territory over which outside powers compete.
Its governments are participants capable of balancing, combining and rejecting competing technological offers.
Their objective is unlikely to be choosing a permanent digital patron.
It is maximizing sovereignty while gaining access to the infrastructure required for economic development.
For Washington, that means cybersecurity assistance should not be understood primarily as a tool for pushing China or Russia out of Central Asia.
Its more sustainable purpose is creating relationships in which the United States remains a credible technological and security partner.
For Beijing, infrastructure and increasingly AI provide powerful mechanisms for maintaining influence.
For Moscow, the challenge is preserving traditional security influence as technological power becomes more important.
And for Central Asian states, the strategic problem is increasingly clear:
The infrastructure of the digital age creates opportunities for development.
It also creates dependencies.
The countries that help build, secure and govern that infrastructure will acquire influence extending far beyond technology.
The geopolitical map of Central Asia was once drawn around territory, railways, pipelines and military power.
The next one will also be drawn through data centers, cybersecurity partnerships, AI systems and networks.
The new Great Game is digital.
And this time, the most consequential territory may be the infrastructure no one can see.
Vladimir Tsakanyan, Ph.D.
Center for Cyber Diplomacy and International Security (CCD-IS)


Leave a comment