惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Jina AI
Jina AI
小众软件
小众软件
GbyAI
GbyAI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 【当耐特】
D
DataBreaches.Net
腾讯CDC
V
Visual Studio Blog
博客园 - 叶小钗
B
Blog
Apple Machine Learning Research
Apple Machine Learning Research
T
The Blog of Author Tim Ferriss
S
SegmentFault 最新的问题
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
The Cloudflare Blog
MongoDB | Blog
MongoDB | Blog
有赞技术团队
有赞技术团队
U
Unit 42
博客园 - 司徒正美
博客园 - 聂微东

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
AI sovereignty makes data centers strategic targets for c...
Sinisa Markovic · 2026-06-12 · via Help Net Security

Data centers built for frontier AI draw hundreds of megawatts of electricity and large volumes of cooling water from fixed locations with known addresses. Each one concentrates tens of thousands of graphics processors, liquid cooling systems, and high-density power equipment inside a single building. This physical footprint turns a nation’s AI capability into something an adversary can locate, measure, and degrade.

AI sovereignty

Mechanisms determining AI sovereignty at the micro, meso, and macro levels

AI sovereignty is the extent to which a nation independently controls its AI technologies. Researchers from the University of Maryland and Sandia National Laboratory use that definition in a model that treats agentic AI as an instrument of national power.

The model maps the resources a country needs to build and sustain that capability: accelerators, electricity, water, data sets, and a skilled workforce. Each resource becomes a point an adversary can pull on. The authors compare the situation to combat airpower, where a nation that buys aircraft it cannot design or build stays dependent on a supplier that can cut off access.

A capability with a physical footprint

The model measures AI capability in zettaFLOPS, a unit of compute performance, and tracks it down to server cabinets and racks. A standard cabinet holds four AI servers with 32 graphics processors that together produce about 128 petaFLOPS. Estimates for eleven frontier AI data centers in the United States and China cover power, water, and floor space.

The Anthropic-Amazon Project Rainier site in New Carlisle, Indiana, runs the equivalent of about 471,000 high-end processors, draws an estimated 751 megawatts of direct power, and uses an estimated 458,000 liters of cooling water. The OpenAI-Oracle Stargate site in Abilene, Texas, draws about 295 megawatts. Racks holding AI accelerators consume between 30 and 250 kilowatts each, and any rack above 100 kilowatts requires liquid cooling. Older data centers designed for lower densities cannot run this equipment without rebuilding.

The levers of degradation

The model is symmetrical between two competing nations. Each one works to grow its own compute, power, water, data, and workforce, and each one can work to degrade the same resources held by the other. The levers connect to physical equipment and data center sites, and pulling them changes a rival’s national power in AI. The methods fall into two groups: direct kinetic actions and indirect effects delivered through cyber operations, space, information campaigns, economic coercion, and diplomacy.

Data poisoning and the supply chain

Two of the degradation levers sit inside the cyber domain. Research on poisoning attacks found that corrupting a large language model during training takes a near-constant number of poisoned samples, regardless of how large the training set is. That finding makes targeted contamination of a rival’s training data a low-cost method of sabotage. Compromising the supply chain for AI accelerators forms a second lever, because a nation that cannot design or build its own chips depends on foreign suppliers who can cut off access. The researchers place both methods outside the current model and list them for later work.

Drones, denial, and public sentiment

One kinetic example comes from 2026. Iran targeted two Amazon data centers in the United Arab Emirates on March 1, and debris from a downed drone in Bahrain damaged a third, causing regional outages. About a month later, Iran named US technology firms including Microsoft, Google, Apple, Meta, and Nvidia as possible military targets in the Gulf, listing them alongside the defense contractors Boeing and GE and the software firm Palantir. Iran then threatened a $30 billion Stargate data center in the UAE. The threatened strike did not occur. The episode showed that costly buildings packed with sensitive hardware sit within range of low-cost drones and ballistic missiles.

Non-kinetic methods reach the same targets without a physical strike. Cyber intrusions, attacks on data center cooling and power controls, and disruption of the supply chain degrade a rival’s compute and leave less evidence of who acted. Information operations form another method. Public opposition to AI and to data center construction gives an adversary material to amplify, including resentment of the electrical and water projects that supply the sites. Because agentic AI serves both military and commercial uses, these operations can target research in fields such as quantum computing, biochemistry, and materials science.

What the model leaves for later

The model is qualitative. It maps relationships and feedback loops without numerical simulation, and the researchers describe their forecasts as notional and directional. Some values come from assumption, including the count of five frontier models needed to reach a new generation of capability and a ten percent gap between theoretical and delivered compute. A quantitative simulation that supports scenario analysis and sensitivity testing remains planned work.

The combined picture gives defenders a wide perimeter. A nation’s standing in AI rests on equipment, buildings, utilities, supply chains, and software that span physical, logistical, and digital security at the same time. A country that sources models, chips, or hosting from abroad carries that dependency as a supply chain risk. The methods an adversary would reach for first sit largely in the cyber domain.

Download: The IT and security field guide to AI adoption