惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

I
InfoQ
博客园_首页
美团技术团队
M
MIT News - Artificial intelligence
人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
H
Help Net Security
J
Java Code Geeks
T
Tailwind CSS Blog
Jina AI
Jina AI
量子位
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
爱范儿
爱范儿
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
宝玉的分享
宝玉的分享
小众软件
小众软件
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
V
Visual Studio Blog
博客园 - Franky
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
AI sovereignty makes data centers strategic targets for c...
Sinisa Markovic · 2026-06-12 · via Help Net Security

Data centers built for frontier AI draw hundreds of megawatts of electricity and large volumes of cooling water from fixed locations with known addresses. Each one concentrates tens of thousands of graphics processors, liquid cooling systems, and high-density power equipment inside a single building. This physical footprint turns a nation’s AI capability into something an adversary can locate, measure, and degrade.

AI sovereignty

Mechanisms determining AI sovereignty at the micro, meso, and macro levels

AI sovereignty is the extent to which a nation independently controls its AI technologies. Researchers from the University of Maryland and Sandia National Laboratory use that definition in a model that treats agentic AI as an instrument of national power.

The model maps the resources a country needs to build and sustain that capability: accelerators, electricity, water, data sets, and a skilled workforce. Each resource becomes a point an adversary can pull on. The authors compare the situation to combat airpower, where a nation that buys aircraft it cannot design or build stays dependent on a supplier that can cut off access.

A capability with a physical footprint

The model measures AI capability in zettaFLOPS, a unit of compute performance, and tracks it down to server cabinets and racks. A standard cabinet holds four AI servers with 32 graphics processors that together produce about 128 petaFLOPS. Estimates for eleven frontier AI data centers in the United States and China cover power, water, and floor space.

The Anthropic-Amazon Project Rainier site in New Carlisle, Indiana, runs the equivalent of about 471,000 high-end processors, draws an estimated 751 megawatts of direct power, and uses an estimated 458,000 liters of cooling water. The OpenAI-Oracle Stargate site in Abilene, Texas, draws about 295 megawatts. Racks holding AI accelerators consume between 30 and 250 kilowatts each, and any rack above 100 kilowatts requires liquid cooling. Older data centers designed for lower densities cannot run this equipment without rebuilding.

The levers of degradation

The model is symmetrical between two competing nations. Each one works to grow its own compute, power, water, data, and workforce, and each one can work to degrade the same resources held by the other. The levers connect to physical equipment and data center sites, and pulling them changes a rival’s national power in AI. The methods fall into two groups: direct kinetic actions and indirect effects delivered through cyber operations, space, information campaigns, economic coercion, and diplomacy.

Data poisoning and the supply chain

Two of the degradation levers sit inside the cyber domain. Research on poisoning attacks found that corrupting a large language model during training takes a near-constant number of poisoned samples, regardless of how large the training set is. That finding makes targeted contamination of a rival’s training data a low-cost method of sabotage. Compromising the supply chain for AI accelerators forms a second lever, because a nation that cannot design or build its own chips depends on foreign suppliers who can cut off access. The researchers place both methods outside the current model and list them for later work.

Drones, denial, and public sentiment

One kinetic example comes from 2026. Iran targeted two Amazon data centers in the United Arab Emirates on March 1, and debris from a downed drone in Bahrain damaged a third, causing regional outages. About a month later, Iran named US technology firms including Microsoft, Google, Apple, Meta, and Nvidia as possible military targets in the Gulf, listing them alongside the defense contractors Boeing and GE and the software firm Palantir. Iran then threatened a $30 billion Stargate data center in the UAE. The threatened strike did not occur. The episode showed that costly buildings packed with sensitive hardware sit within range of low-cost drones and ballistic missiles.

Non-kinetic methods reach the same targets without a physical strike. Cyber intrusions, attacks on data center cooling and power controls, and disruption of the supply chain degrade a rival’s compute and leave less evidence of who acted. Information operations form another method. Public opposition to AI and to data center construction gives an adversary material to amplify, including resentment of the electrical and water projects that supply the sites. Because agentic AI serves both military and commercial uses, these operations can target research in fields such as quantum computing, biochemistry, and materials science.

What the model leaves for later

The model is qualitative. It maps relationships and feedback loops without numerical simulation, and the researchers describe their forecasts as notional and directional. Some values come from assumption, including the count of five frontier models needed to reach a new generation of capability and a ten percent gap between theoretical and delivered compute. A quantitative simulation that supports scenario analysis and sensitivity testing remains planned work.

The combined picture gives defenders a wide perimeter. A nation’s standing in AI rests on equipment, buildings, utilities, supply chains, and software that span physical, logistical, and digital security at the same time. A country that sources models, chips, or hosting from abroad carries that dependency as a supply chain risk. The methods an adversary would reach for first sit largely in the cyber domain.

Download: The IT and security field guide to AI adoption