The Infrastructure of AI Is a Weapon Now. The Policy Isn’t Ready.

08/25/2026
By Natalie Balents

In March 2026, Iranian drones struck Amazon-owned data centers in the United Arab Emirates and a third facility in Bahrain — retaliation for the U.S.-Israeli campaign against Iran. It was the first time in military history that private-sector data centers came under deliberate physical attack. Iran’s Revolutionary Guard Corps followed up with a target list naming dozens of facilities run by Microsoft, Google, and other American firms. The message was unambiguous: the servers running the world’s AI are now strategic terrain.

The data center industry spent years describing itself as neutral commercial infrastructure. That no longer holds. Once military significance attaches to a workload, neutrality is decided by physical infrastructure — and physical infrastructure can be hit. Securing that terrain isn’t a job defense can do alone, and the U.S. response is split across three levers — defense, diplomacy, and development — that aren’t well coordinated and sometimes undercut one another. Defense is racing to harden and expand American computing capacity. Diplomacy is exporting the American AI stack to allies, unevenly. Development is quietly building the power and regulatory groundwork that makes new markets investable. None of the three works without the other two, and right now, none is fully working.

That gap isn’t just overseas. The same vulnerability the Gulf strikes exposed abroad exists, at greater concentration, on American soil — a few miles from the Pentagon.

Why This Is a Security Issue Now

Three things changed at once. The legal ground shifted: once a facility contributes meaningfully to military activity, colocated commercial and military workloads become a liability rather than an efficiency. The physical math changed: AI training and inference are pushing data center power demand toward a doubling or tripling by 2028, and grid operators warn the system was never built to absorb the sudden loss of one massive facility. And Washington noticed: this year’s defense authorization act directs the Pentagon to stand up an AI Futures Steering Committee to assess adversary AI developments and infrastructure risk.

The Defense Response

The Department of War’s January 2026 AI strategy commits substantial resources to expanding computing power “from datacenters to the edge,” leaning on the hundreds of billions in private capital already flowing into American AI infrastructure, and frames computing power itself as a warfighting resource tied to intelligence, battle management, and campaign planning — not a back-office concern.

Congress is institutionalizing oversight of that buildout. The FY26 defense authorization act creates the AI Futures Steering Committee, co-chaired by the Deputy Secretary of Defense and the Vice Chairman of the Joint Chiefs, reporting to Congress by January 2027, alongside a department-wide AI cybersecurity policy addressing model tampering and data leakage.

The infrastructure itself is being rearchitected for distribution, not just scale. The Pentagon’s next-generation cloud contract, the Joint Warfighting Cloud Capability Unified Cloud Marketplace, is built as a tiered structure explicitly designed to extend AI into denied, disrupted, and contested environments rather than concentrating capability in a handful of fixed facilities — the logic AWS and Anduril are already building toward with a jointly listed tactical data center offering. The same resilience-by-design thinking shapes Golden Dome, the administration’s missile-defense initiative; applying it fully to AI data centers is the logical next step, and one the Department hasn’t yet taken. Underpinning all of it is power — quiet Pentagon–Department of Energy coordination to protect electricity at defense-critical sites is under real strain as AI-scale demand collides with an aging grid.

The Diplomatic Dimension

Defense secures infrastructure, but it doesn’t decide who builds it, or with whose technology — nowhere clearer than in the Gulf. Washington’s authorization of chip sales to Saudi Arabia’s HUMAIN and the UAE’s G42 was framed as a template for anchoring regions to the American AI stack over a Chinese alternative, backed by the State Department’s digital solidarity strategy.

But tech diplomacy isn’t one template. Estonia arrived at digital statecraft from the opposite direction, building sovereign capacity — Wise, Skype’s Jaan Tallinn, and, after the 2007 cyberattack, NATO’s Cooperative Cyber Defence Centre of Excellence — into a defense doctrine that treats digital infrastructure as inseparable from territorial security.

Nor does security automatically pull with diplomacy. In June 2026, Washington ordered Anthropic to cut off foreign-national access to its most capable models, briefly taking them offline worldwide. European officials read it as a warning about who controls the AI they depend on, and some demand reportedly shifted to Chinese open-source alternatives — the opposite of the intended effect. Around the same time, the Pentagon labeled that same American company a supply chain risk, a designation historically reserved for adversaries.

The Development Dimension

Development is the least understood leg of this stool, and with USAID dissolved in 2025, the most in flux. What remains runs through the Development Finance Corporation — reauthorized for six years with its lending cap potentially rising to $200 billion, building an “AI Horizon Fund” for power and grid financing abroad — and the State Department’s capacity-building mandate for partner nations’ digital governance. Together, this is market-making: building the baseline that makes an immature digital environment investable, and only then operable for American vendors, completing what defense and diplomacy alone cannot.

Closer to Home

Everything above reads as an international story. But the same calculus applies on American soil, nowhere more than Northern Virginia’s “Data Center Alley.” Loudoun, Fairfax, and Prince William counties host the densest concentration of data centers on Earth — more than 300 facilities carrying an estimated 70 percent of global internet traffic — a short drive from CIA headquarters and the Pentagon. If adversaries strike data centers abroad, there’s no reason that logic stops at the water’s edge. That’s a domestic policy conversation the United States has barely started having.

Natalie Balents is a foreign affairs professional specializing in technology policy and security sector technical assistance. For the majority of her career, she served the U.S. Department of State in both consulting and civil service capacities, working at the intersection of diplomacy, emerging technology, and security cooperation. She has also advised various international organizations in Estonia, Malta, and Austria. Natalie holds a Master’s degree from The Fletcher School of Law and Diplomacy at Tufts University. She currently lives in the far reaches of Northern Virginia with her Basset hounds.