Why Frontier AI Data Centers Are Becoming a National Security Imperative
Executive Summary
In March, drone strikes attributed to Iran damaged three Amazon Web Services data center facilities in the Middle East, confirming that the physical infrastructure behind frontier AI is now a target in geopolitical conflict. The attacks occurred amid rising tensions and illustrate a new reality: data centers, once purely commercial assets, are now strategic military targets.
The rapid global expansion of frontier AI data centers — accelerated by agreements between the United States and Gulf nations — has opened a complex debate about location, ownership, and the security of the compute infrastructure that underpins AI development. This article examines the domestic capacity pressures forcing compute overseas, the national security threats to overseas AI infrastructure, and the governance frameworks needed to balance innovation and security.
Introduction
AI models depend on enormous clusters of specialized processors housed in data centers that consume gigawatts of electricity and require complex cooling systems. As frontier AI grows more powerful, the infrastructure underneath it is expanding at unprecedented scale. Hyperscaler capital expenditure could surpass $1 trillion by 2027, according to some analysts. Historically, training dominated AI compute demand; increasingly, inference-time compute and ongoing R&D are taking over.
The United States currently leads in frontier AI development. Sustaining that lead requires substantial compute expansion. But the United States is not immune to constraints, including electricity availability, grid interconnection timelines, and permitting. As a result, frontier AI infrastructure is beginning to go overseas, often through bilateral agreements. In May 2025, the U.S. administration announced agreements with the UAE and Saudi Arabia to build frontier AI data centers, placing advanced computing clusters in a geopolitically volatile region. This development raises an unavoidable question: how should governments and enterprises evaluate the national security risks of building the most consequential digital infrastructure outside their borders?
Technology Context
Frontier AI training clusters are not ordinary data centers. They require high-density computing, advanced cooling architectures, and interconnection bandwidth capable of moving enormous datasets. They also require stable, massive power supplies. The physical plant includes transformers, uninterruptible power supplies, backup generation, and fire suppression systems — components that are both expensive and, crucially, difficult to defend.
Data centers are costly to conceal and often physically vulnerable. Disabling critical components such as transformers or cooling systems can force large computing systems offline for extended periods. This physical vulnerability has gained new strategic significance as AI models become central to military, economic, and intelligence operations.
The trend toward internationalization is not uniform. While the United States still has some of the fastest time-to-power rates globally, grid interconnection and permitting can consume years in certain regions. This has made overseas locations with fast-track authorizations, access to energy, and strategic partnerships attractive for enterprises under pressure to secure compute capacity.
Main Analysis
The Brookings Institution’s research project, which will unfold over nine months, intends to systematically assess the threat landscape for overseas AI infrastructure. Its scoping paper identifies domestic capacity constraints and a security risk framework that includes physical attacks, supply chain compromise, and host-country environment considerations.
Physical security is the first exposure. The AWS incident in the Middle East demonstrated that nation-state adversaries can target data centers with precision drones, affecting electricity, causing water damage from fire suppression, and compelling service disruptions. In a conflict, adversaries may view AI-capable data centers as high-value targets, whether to disrupt the digital economy, degrade military enablement, or send political signals.
A second layer of risk is operational and regulatory. When data centers are hosted in foreign territory, host countries can impose controls on equipment access, data handling, and software updates. They can also nationalize or inspect hardware under legal frameworks not present in the home jurisdiction. Ownership and control structures become complicated when foreign direct investment and sovereign wealth funds are involved. In the Gulf agreements, for example, the line between commercial and state interests can be deliberately blurred.
Third, the geopolitical posture of the host country matters. Even 'friendly' nations may have conflicting foreign policy objectives. Infrastructure can become a potential target because of its location, not just its owner. In the Bahrain case, the facility was attacked because of its perceived connection to U.S. military operations. This points to an essential truth: the strategic benefits of hosting AI infrastructure overseas can be offset by security risks not present in domestic siting decisions.
From an engineering standpoint, frontier data centers are some of the most complex digital infrastructure projects ever built. The supply chain for AI chips, networking equipment, power systems, and cooling hardware is globally distributed, making hardware provenance, firmware integrity, and tamper resistance central concerns. Securing an overseas site requires additional investments in physical barriers, active defense, redundancy, and secure supply chains.
Industry Impact
For enterprises, cloud providers, and AI developers, the location of AI infrastructure is becoming a board-level decision. Cloud providers who internationalize their frontier data centers need to align with national security interests while continuing to serve commercial customers. New enterprise governance processes must assess geopolitical exposure, legal jurisdiction, and operational resilience.
These concerns are not confined to governments. The global AI infrastructure market is an emerging asset class for institutional investors. Sovereign and private capital backing billion-dollar data center projects may need to price security risk explicitly. The U.S.-UAE and U.S.-Saudi agreements will accelerate investment flows, but they could create architecture that is economically attractive but vulnerable to regional conflict, retaliation, or regulatory disruption.
Startups and scaleups building on foundation models may be increasingly dependent on compute located in multiple regions. If a geopolitical event disrupts availability, their entire operating posture changes. The concentration risk associated with large AI compute clusters means that enterprises must now model cyber-physical threats as part of their resilience strategy.
Strategic Insights
The key strategic challenge is balancing economic competitiveness and national security. U.S. leadership in frontier AI depends on access to massive compute, but if compute is deployed in ways that create strategic vulnerabilities, the longer-term position of trusted AI ecosystems could be harmed.
Policy responses are evolving but incomplete. The Brookings series will analyze options, which may include:
- Domestic capacity acceleration: Shortening the time to power for AI data centers in the U.S. while enhancing energy infrastructure.
- Allied infrastructure pacts: Building data centers only in trusted allied countries with transparent and aligned security postures.
- Conditional approvals: Government review of overseas frontier AI infrastructure, tying project approval to controls on where data travels, who runs the hardware, and what workloads can be hosted.
- Security requirements: Mandating physical security standards, tamper-evident supply chains, and rapid isolation capabilities.
Industry and government should share a framework that evaluates risk in terms of location, ownership, workloads, and host-country dynamics. A purely commercial siting process cannot internalize national security externalities. Enterprises may need to consult with security agencies before finalizing strategic locations.
Setting objective criteria for 'trusted jurisdictions' will be central to future governance. The U.S. is under pressure to define what constitutes safe and secure AI infrastructure hubs. This may be more about interoperability, transparency and security standards than simple geographical boundaries.
For investors, the implication is that political risk and security risk are now potentially material components of AI infrastructure asset valuations. Security risk assessments must be built into due diligence and underwriting.
Future Outlook
Over the next 5–10 years, frontier AI’s compute demand will likely continue to grow exponentially. Global AI data center capacity will expand to serve sovereign AI agendas from Europe to Asia, raising the stakes for international governance.
The physical security of data centers is becoming more complex. AI operations, which can be paused through physical destruction of power and cooling systems, require substantial resilience. Future designs will integrate physical security with cybersecurity, active defense mechanisms, and autonomous response capabilities, perhaps leveraging AI itself to detect and mitigate threats.
International frameworks may emerge for 'compute security' analogous to nuclear nonproliferation provisions. Governments may negotiate limits or transparency measures around the most advanced frontier training sites to prevent cross-border security complications. We may also see increased 'reshoring' of compute for national security reasons, mirroring supply chain shifts in semiconductors.
The Brookings research agenda over the next nine months will play a critical role in shaping this debate by establishing evidence on threat profiles and mitigation approaches. For the technology industry, the question is no longer whether to build frontier AI infrastructure, but how to build it responsibly and securely.
Conclusion
The attacks on AWS data centers are a vivid reminder that digital infrastructure is physical, exposed, and strategically attractive as a target. As frontier AI data centers expand across the globe, their location, ownership, and governance have emerged as high-stakes national security decisions.
The United States and its allies must act now to create a governance architecture that preserves AI leadership, supports commercial innovation, and protects the digital infrastructure on which the next century of economic and military power will depend. For enterprises, investors, and engineers, integrating national security considerations into infrastructure development will be a defining challenge of the AI era.