Sections
An operator works at the data centre of French company OVHcloud in Roubaix, northern France on April 3, 2025.

Research

The national security implications of building frontier AI data centers overseas

August 3, 2026
  • Decisions about where frontier AI infrastructure is built are becoming strategic choices rather than merely commercial ones.
  • The relevant policy question is not whether frontier AI infrastructure should ever be located abroad, but which assets and workloads can be located in which jurisdictions and under what conditions.
  • The purpose of this paper is to define the emerging problem and establish the questions that must be answered before today’s infrastructure investments harden into dependencies that are costly or impossible to reverse.

On March 1, in response to Operation Epic Fury, drone strikes by the Islamic Republic of Iran damaged three Amazon Web Services (AWS) data center facilities in the Middle East. AWS confirmed that the attacks caused structural damage, interrupted power delivery, and triggered fire suppression systems that resulted in additional water damage across parts of the infrastructure. Iran’s state media claimed that the Islamic Revolutionary Guard Corps targeted the Bahrain facility because of its role in supporting U.S. military and intelligence operations.

This episode illustrates a broader strategic reality. Data centers have long been recognized as critical infrastructure in the digital economy and increasingly visible targets in geopolitical conflict. They are costly to conceal and often physically vulnerable. Disabling key components such as cooling systems, transformers, or generators can take large computing clusters offline. As artificial intelligence (AI) infrastructure expands globally, data centers may increasingly attract attention from adversaries seeking to disrupt economies, signal political intent, or impose costs on rivals.

Agreements announced by President Donald Trump in May 2025 with the United Arab Emirates and Saudi Arabia to build frontier AI data centers underscore the stakes of this debate. If realized, they could place advanced computing clusters, and some of the United States’ consequential strategic assets, in a geopolitically volatile region. Overseas frontier AI infrastructure may be commercially attractive and strategically beneficial, but its location, ownership, workloads, and host-country environment create national-security risks that are not captured by ordinary commercial siting decisions.

That raises an unavoidable question: how should the United States approach decisions about the location of the infrastructure that will power the next generation of AI and on which its broader digital economy will increasingly depend?

Answering this question will require a better understanding of domestic capacity constraints and the probability and severity of security risks to overseas infrastructure, while simultaneously weighing the strategic tradeoffs between economic competitiveness and national security. Collectively, these factors will help to determine where the infrastructure for frontier AI training centers can be built and whether new governance frameworks will be necessary to manage it.

Over the next nine months, the Brookings Institution will publish a series of papers that analyze the threat landscape, establish a framework for systematically assessing these risks, and propose mitigating policy options for governments, developers, and investors. This work aims to inform a global infrastructure buildout that enables responsible innovation and diffusion of frontier AI while managing long-term security risks.

In this scoping paper, we will lay out the domestic capacity constraints and provide an overview of the security risks we will examine, as well as offer a roadmap for the project’s research agenda over the next nine months.

Domestic capacity constraints

Training the most advanced AI models requires enormous computing capacity, including massive clusters of specialized chips housed in large data centers that consume vast amounts of electricity and require sophisticated cooling systems. As frontier AI models grow more capable, the infrastructure underneath them is scaling rapidly, with hyperscaler capital expenditure alone projected by some analysts to surpass a trillion dollars by 2027. Historically, training dominated that spending. Increasingly, inference-time compute and ongoing R&D appear to account for a growing share.

The United States currently leads the world in frontier AI development. Maintaining its leadership will depend on a range of factors, including substantial expansion of current compute infrastructure. Whether this infrastructure can be built at the necessary scale within the United States or whether various constraints will push a meaningful share of it overseas is now a central, and increasingly political, question.

There are reasons to think domestic expansion may face challenges. Large AI data centers require enormous quantities of reliable electricity, often on the scale of gigawatts, along with high-capacity grid connections and specialized equipment. Securing power and grid interconnection can take years in some parts of the country, although the United States currently has one of the fastest time-to-power rates in the world. Permitting processes and environmental reviews can create additional delays. Supply chains for key components can also become bottlenecks, as can shortages of skilled construction labor.

The politics of infrastructure development may also matter. Large data centers are increasingly controversial in some communities due to their electricity consumption, water use, limited job creation, and perceived impact on local power prices and land use. As a result, local permitting decisions and political opposition are becoming an additional constraint in certain regions of the United States. In some states, bipartisan legislation is advancing statewide moratoriums on new data center construction, while county-level moratoriums are already in effect. Some governors are also turning to fiscal tools to mitigate AI infrastructure backlash, such as new taxes on data center energy consumption.

At the same time, other countries are actively trying to attract this infrastructure. Some states offer abundant energy resources, streamlined permitting processes, rapid time to power, and substantial government subsidies designed to encourage large technology investments. Training runs, by contrast, are far less location-dependent, which is one reason the siting calculus differs by workload. Because several frontier AI developers rely on private capital, Gulf investors, particularly in the United Arab Emirates and Saudi Arabia, have been able to use sovereign wealth to take positions in AI infrastructure, contributing to the region’s emergence as a technology hub. This is one factor among several—including cheap energy and permissive siting regulation—that offers an additional advantage over more capital-constrained regions.

The broader policy question is not whether AI infrastructure will be built overseas. It already is, and it plays an important role in delivering AI services to users worldwide. Because inference—the compute that answers queries in real time—is latency-sensitive, siting it near end users can improve performance and lower bandwidth costs. The more important question is how the United States should think about the balance between domestic and overseas infrastructure as the scale of AI computing required to develop and operate frontier models continues to evolve and potentially grow.

Security risks of overseas infrastructure

Locating AI infrastructure overseas introduces a set of strategic risks that are distinct from those associated with domestic facilities. This is particularly true for facilities that focus on the development of frontier AI models, including not only training but also inference for research. Although intelligence services have targeted overseas telecommunications and data infrastructure for decades, what is distinctive here is the concentration of value in a single facility and the speed with which a loss of access or integrity could translate into a strategic disadvantage.

Advanced AI data centers contain high-value assets, including specialized chips, proprietary software, training data, and model weights. These elements represent both significant intellectual property and strategic national capability. As such, they can be potential targets for a range of threat actors, including foreign state intelligence services, nonstate actors, and insider threats. Compromise could take several forms: theft of intellectual property or model weights, sabotage of physical or digital infrastructure, or covert access that enables surveillance or manipulation of AI systems. The consequences could extend beyond commercial losses and may result in degrading U.S. technological advantage, accelerating rivals’ capabilities—especially China—and potentially undermining the integrity of AI systems on which critical functions depend. Future research for this project will seek to disaggregate and prioritize these risks by specifying their potential impact, time horizon, and severity, and which warrant the most urgent policy attention.

The second issue is jurisdiction. Infrastructure located in foreign countries operates under local legal systems and regulatory regimes. Governments may possess lawful access authorities that compel companies to disclose data or alter operations. Even close allies may have independent legal and intelligence frameworks, including data localization requirements, that do not always align perfectly with U.S. interests. Mapping how these authorities vary across jurisdictions—from close allies to adversaries—will also be a focus of subsequent research in this series.

A third concern is long-term dependency. Data centers are expensive infrastructure investments. If significant portions of the U.S. AI ecosystem become tied to facilities located outside the United States, host states may acquire structural leverage over U.S. technological and economic decisions that could be exercised during diplomatic disputes or geopolitical crises. Such leverage would be difficult to unwind given the costs of relocation.

The semiconductor supply chain provides a useful, if imperfect, analogy. While globalization has produced remarkable efficiency gains, it has also created strategic dependencies—particularly through the concentration of advanced manufacturing capacity in Taiwan. Although AI infrastructure is unlikely to reach that degree of concentration, a similar scenario could emerge with AI infrastructure if training clusters that are costly and slow to reconstitute become geographically concentrated outside the United States, leading to additional U.S. security commitments to defend those assets.

A final (distinct but related) concern is physical vulnerability. Infrastructure located in geopolitically unstable regions is exposed to risks that U.S. authorities may not be able to mitigate or control. The recent attacks on cloud facilities in the Middle East highlight that data centers themselves have become targets in regional conflicts. Hardening measures, such as reinforced construction, underground facilities, anti-drone jamming, and air defense systems, are available but costly, and they may not provide reliable protection against sustained low-cost drone swarms or disruption to supporting power infrastructure. Unlike dependency, which manifests through political pressure, this risk is direct and potentially irreversible: the physical safety of compute infrastructure cannot be guaranteed in a negotiated agreement with the host state.

None of these risks necessarily make foreign hosting unacceptable. But they do suggest that infrastructure location decisions have strategic consequences that extend beyond commercial considerations. Importantly, the significance and severity of these risks, as well as mitigation possibilities, will vary based on whether facilities are operated by U.S. hyperscalers or foreign companies, the types of workloads they run, and the host country’s strategic alignment with U.S. objectives.

Research agenda

These constraints and risks suggest that the relevant policy question is not whether frontier AI infrastructure should ever be located abroad, but which assets and workloads can be located in which jurisdictions and under what conditions. Answering that question will require distinguishing among types of computing activity; assessing host-country laws, strategic alignment, and security capabilities; examining ownership and operational control; and determining which vulnerabilities can be mitigated through technical, contractual, or diplomatic measures.

Over the next nine months, this project will aim to develop a framework for comparing these risks across workloads and jurisdictions. Subsequent papers will assess the likelihood and severity of different threat scenarios, identify circumstances in which overseas hosting could create unacceptable dependency or exposure, and evaluate policy options available to the United States, partner governments, developers, and investors.

Decisions about where frontier AI infrastructure is built are becoming strategic choices rather than merely commercial ones. The purpose of this paper is to define the emerging problem and establish the questions that must be answered before today’s infrastructure investments harden into dependencies that are costly or impossible to reverse.

  • Acknowledgements and disclosures

    The Brookings Institution is committed to quality, independence, and impact. This project is supported by funding from Google.org. We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).

    The authors would like to thank Adam Lammon and Rachel Slattery for editorial support as well as the participants in two private roundtables for their valuable feedback.

  • Footnotes
    1. Although reliable longitudinal data on relative compute spend for training, inference, and R&D is difficult to obtain, various industry observers suggest that inference workloads have grown as a share of total compute. The International Energy Agency’s 2026 report on Key Questions on Energy and AI asserts that AI energy consumption has “shifted decisively from training to inference,” with the growth attributed to an increase in per-task compute intensity for new paradigms such as advanced reasoning models and agentic AI. In December 2025, McKinsey’s modeling projected that energy demand for inference workloads will surpass that of training workloads beginning in 2027 and continue to grow in relative terms. However, an August 2025 report by the Electric Power Research Institute and Epoch AI concluded that these trends are unclear and a shift toward inference-heavy innovations may be offset if higher demand motivates labs to invest in training larger, more capable models.
    2. Behind-the-meter (BTM) generation—dedicated power plants colocated with individual data centers—offers one of the more promising workarounds, and U.S. developers are deploying it faster than peers in most other major economies. By bypassing interconnection queues, BTM can accelerate data center buildout and reduce near-term load on public transmission networks. However, BTM projects still draw on constrained supply chains for natural gas and turbines, alongside water demands whose scale remains contested, and they raise live questions about who bears the environmental and reliability costs.
    3. Importantly, not all specialized chips can be stolen with equal ease. For example, standalone data center GPUs such as Nvidia’s H100 and H200 are physically portable enough to smuggle, while others, like the Cerebras WSE-3, are much harder to steal.

The Brookings Institution is committed to quality, independence, and impact.
We are supported by a diverse array of funders. In line with our values and policies, each Brookings publication represents the sole views of its author(s).