A Hudson Institute senior fellow is urging lawmakers to treat AI data centers as major cybersecurity targets for foreign adversaries, warning that the concentration of sensitive technology in private cloud infrastructure creates a vulnerability that did not exist in previous eras.
The shift from government to private infrastructure
During the Cold War and the period following the September 11 attacks, the most sensitive technology in the United States lived inside government laboratories, military facilities, classified programs, and a relatively bounded defense-industrial base. The infrastructure was owned and operated by the government or its direct contractors, and the security perimeter, while imperfect, was well defined.
That perimeter no longer holds. The most capable AI models, the training data behind them, and the compute infrastructure that runs them are now operated by private companies. The data centers that house this infrastructure are owned by cloud providers, not the government. The security of those facilities depends on corporate security teams, not military or intelligence personnel.
The testimony before the House Intelligence Committee frames this shift as a strategic vulnerability. Adversaries who targeted government networks in the past now have a different set of targets: the data centers where AI models are trained, the networks that connect them, and the supply chains that supply their hardware.
Why AI data centers are attractive targets
AI data centers concentrate several things that adversaries want. The training data used to build frontier models includes proprietary information, government datasets, and intellectual property from across the economy. The models themselves represent years of research and billions of dollars in investment. The compute infrastructure, particularly GPU clusters, is scarce and expensive.
A successful attack on a data center could exfiltrate training data, steal model weights, disrupt training runs, or degrade inference capabilities. The effects would be felt across every customer that depends on that infrastructure, which increasingly includes government agencies themselves.
The 25-year retrospective since September 11 provides context. The attacks exposed gaps in physical security and intelligence sharing. The current moment exposes gaps in cybersecurity and infrastructure resilience. The threat is different, but the pattern of critical infrastructure concentrating in ways that create single points of failure is the same.
What lawmakers are hearing
The testimony asks the Intelligence Committee to consider data centers as part of the national security landscape, not just commercial infrastructure. That framing matters because it determines what resources and authorities are available for protection. If data centers are treated as private property with standard cybersecurity requirements, the protection is limited. If they are treated as critical infrastructure analogous to power grids or telecommunications networks, the federal government has broader authority to mandate security standards and provide support.
The committee is surveying the threat landscape at a moment when AI capabilities are advancing rapidly and the infrastructure that supports them is expanding just as fast. New data centers are being built to meet the demand for AI training and inference. Each new facility represents a new target, and the security of those facilities varies widely across providers and geographies.
What this means for the AI industry
For companies building and operating AI infrastructure, the testimony signals that congressional attention is turning toward the security of data centers as a matter of national security, not just corporate risk management. That attention could result in new requirements, new standards, or new federal involvement in the security of private AI infrastructure.
For developers and organizations building on top of cloud AI services, the practical implication is that the security of the infrastructure you depend on is now a policy question, not just a technical one. The data centers that host your models, store your data, and run your inference workloads are part of a national security conversation that may produce new regulations, new oversight, or new constraints on how that infrastructure operates.
The testimony does not propose specific solutions. It asks the committee to recognize the problem and consider what role the government should play in protecting AI infrastructure. The answer to that question will shape the security requirements, cost structure, and operational constraints of the AI industry for years to come.